Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 324 081

Количество 324 081

github логотип

GHSA-xv7j-wg82-2r7g

почти 2 года назад

The Bookster WordPress plugin through 1.1.0 allows adding sensitive parameters when validating appointments allowing attackers to manipulate the data sent when booking an appointment (the request body) to change its status from pending to approved.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xv7j-v722-h5vx

около 2 лет назад

Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability located in the deviceName parameter of the formSetDeviceName function.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xv7j-qvp8-927h

почти 4 года назад

Bitrix Site Manager 4.1.x stores updater.log under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information.

EPSS: Низкий
github логотип

GHSA-xv7j-jr8q-mhmm

почти 4 года назад

Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling.

EPSS: Низкий
github логотип

GHSA-xv7j-8v8v-h429

почти 4 года назад

The ELF file parser in eSafe 7.0.17.0, Prevx 3.0, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified abiversion field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

EPSS: Низкий
github логотип

GHSA-xv7j-2v4w-cjvh

почти 4 года назад

OpenStack Glance logs user name and password in cleartext

EPSS: Низкий
github логотип

GHSA-xv7h-qpjm-g3jp

почти 4 года назад

In NetworkStackNotifier, there is a possible permissions bypass due to an unsafe implicit PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157475111

EPSS: Низкий
github логотип

GHSA-xv7h-95r7-595j

больше 3 лет назад

Incorrect implementation of lockout feature in Keycloak

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xv7h-8h3f-m34f

почти 4 года назад

Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 allows remote attackers to affect integrity via unknown vectors related to Fluid Core.

EPSS: Низкий
github логотип

GHSA-xv7h-524v-h227

8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: ksmbd: not allow guest user on multichannel This patch return STATUS_NOT_SUPPORTED if binding session is guest.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xv7g-x679-jf4c

почти 4 года назад

A potential security vulnerability has been identified for the HP OfficeJet 7110 Wide Format ePrinter that enables Cross-Site Scripting (XSS).

EPSS: Низкий
github логотип

GHSA-xv7f-hrp6-5mhh

почти 4 года назад

Stack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges via an application that leverages /dev/msm_acdb access and provides a large size value in an ioctl argument.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-xv7f-73w8-27qj

почти 4 года назад

Buffer overflow in the gopherToHTML function in gopher.cc in the Gopher reply parser in Squid 3.0 before 3.0.STABLE26, 3.1 before 3.1.15, and 3.2 before 3.2.0.11 allows remote Gopher servers to cause a denial of service (memory corruption and daemon restart) or possibly have unspecified other impact via a long line in a response. NOTE: This issue exists because of a CVE-2005-0094 regression.

EPSS: Высокий
github логотип

GHSA-xv7c-g3v3-rjqw

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: During vport delete send async logout explicitly During vport delete, it is observed that during unload we hit a crash because of stale entries in outstanding command array. For all these stale I/O entries, eh_abort was issued and aborted (fast_fail_io = 2009h) but I/Os could not complete while vport delete is in process of deleting. BUG: kernel NULL pointer dereference, address: 000000000000001c #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page PGD 0 P4D 0 Oops: 0000 [#1] PREEMPT SMP NOPTI Workqueue: qla2xxx_wq qla_do_work [qla2xxx] RIP: 0010:dma_direct_unmap_sg+0x51/0x1e0 RSP: 0018:ffffa1e1e150fc68 EFLAGS: 00010046 RAX: 0000000000000000 RBX: 0000000000000021 RCX: 0000000000000001 RDX: 0000000000000021 RSI: 0000000000000000 RDI: ffff8ce208a7a0d0 RBP: ffff8ce208a7a0d0 R08: 0000000000000000 R09: ffff8ce378aac9c8 R10: ffff8ce378aac8a0 R11: ...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xv78-4qjf-hjxf

больше 2 лет назад

In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain unauthorized access to the MOVEit Transfer database. An attacker could submit a crafted payload to a MOVEit Transfer application endpoint that could result in modification and disclosure of MOVEit database content.

CVSS3: 9.1
EPSS: Критический
github логотип

GHSA-xv76-pqh9-f864

почти 4 года назад

Inappropriate implementation in autofill in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to obtain autofill data with insufficient user gestures via a crafted HTML page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xv76-8jhj-2c53

почти 4 года назад

The DEC UDK processing feature in the xterm terminal emulator in XFree86 4.2.99.4 and earlier allows attackers to cause a denial of service via a certain character escape sequence that causes the terminal to enter a tight loop.

EPSS: Низкий
github логотип

GHSA-xv76-4vwq-rw6h

почти 4 года назад

When a device connects only over WiFi VPN, the device may not receive security updates due to some incorrect checks. This could lead to a local denial of service of security updates with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-8.1 Android ID: A-78644887.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-xv75-c298-2v8f

почти 4 года назад

iked in OpenIKED, as used in OpenBSD through 6.7, allows authentication bypass because ca.c has the wrong logic for checking whether a public key matches.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xv75-3499-88v3

почти 4 года назад

The nsZipArchive function in Mozilla Firefox before 44.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging incorrect use of a pointer during processing of a ZIP archive.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xv7j-wg82-2r7g

The Bookster WordPress plugin through 1.1.0 allows adding sensitive parameters when validating appointments allowing attackers to manipulate the data sent when booking an appointment (the request body) to change its status from pending to approved.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-xv7j-v722-h5vx

Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability located in the deviceName parameter of the formSetDeviceName function.

CVSS3: 9.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-xv7j-qvp8-927h

Bitrix Site Manager 4.1.x stores updater.log under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xv7j-jr8q-mhmm

Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling.

9%
Низкий
почти 4 года назад
github логотип
GHSA-xv7j-8v8v-h429

The ELF file parser in eSafe 7.0.17.0, Prevx 3.0, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified abiversion field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xv7j-2v4w-cjvh

OpenStack Glance logs user name and password in cleartext

1%
Низкий
почти 4 года назад
github логотип
GHSA-xv7h-qpjm-g3jp

In NetworkStackNotifier, there is a possible permissions bypass due to an unsafe implicit PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157475111

0%
Низкий
почти 4 года назад
github логотип
GHSA-xv7h-95r7-595j

Incorrect implementation of lockout feature in Keycloak

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xv7h-8h3f-m34f

Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 allows remote attackers to affect integrity via unknown vectors related to Fluid Core.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xv7h-524v-h227

In the Linux kernel, the following vulnerability has been resolved: ksmbd: not allow guest user on multichannel This patch return STATUS_NOT_SUPPORTED if binding session is guest.

CVSS3: 5.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-xv7g-x679-jf4c

A potential security vulnerability has been identified for the HP OfficeJet 7110 Wide Format ePrinter that enables Cross-Site Scripting (XSS).

0%
Низкий
почти 4 года назад
github логотип
GHSA-xv7f-hrp6-5mhh

Stack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges via an application that leverages /dev/msm_acdb access and provides a large size value in an ioctl argument.

CVSS3: 8.4
7%
Низкий
почти 4 года назад
github логотип
GHSA-xv7f-73w8-27qj

Buffer overflow in the gopherToHTML function in gopher.cc in the Gopher reply parser in Squid 3.0 before 3.0.STABLE26, 3.1 before 3.1.15, and 3.2 before 3.2.0.11 allows remote Gopher servers to cause a denial of service (memory corruption and daemon restart) or possibly have unspecified other impact via a long line in a response. NOTE: This issue exists because of a CVE-2005-0094 regression.

75%
Высокий
почти 4 года назад
github логотип
GHSA-xv7c-g3v3-rjqw

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: During vport delete send async logout explicitly During vport delete, it is observed that during unload we hit a crash because of stale entries in outstanding command array. For all these stale I/O entries, eh_abort was issued and aborted (fast_fail_io = 2009h) but I/Os could not complete while vport delete is in process of deleting. BUG: kernel NULL pointer dereference, address: 000000000000001c #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page PGD 0 P4D 0 Oops: 0000 [#1] PREEMPT SMP NOPTI Workqueue: qla2xxx_wq qla_do_work [qla2xxx] RIP: 0010:dma_direct_unmap_sg+0x51/0x1e0 RSP: 0018:ffffa1e1e150fc68 EFLAGS: 00010046 RAX: 0000000000000000 RBX: 0000000000000021 RCX: 0000000000000001 RDX: 0000000000000021 RSI: 0000000000000000 RDI: ffff8ce208a7a0d0 RBP: ffff8ce208a7a0d0 R08: 0000000000000000 R09: ffff8ce378aac9c8 R10: ffff8ce378aac8a0 R11: ...

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xv78-4qjf-hjxf

In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain unauthorized access to the MOVEit Transfer database. An attacker could submit a crafted payload to a MOVEit Transfer application endpoint that could result in modification and disclosure of MOVEit database content.

CVSS3: 9.1
91%
Критический
больше 2 лет назад
github логотип
GHSA-xv76-pqh9-f864

Inappropriate implementation in autofill in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to obtain autofill data with insufficient user gestures via a crafted HTML page.

CVSS3: 6.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-xv76-8jhj-2c53

The DEC UDK processing feature in the xterm terminal emulator in XFree86 4.2.99.4 and earlier allows attackers to cause a denial of service via a certain character escape sequence that causes the terminal to enter a tight loop.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xv76-4vwq-rw6h

When a device connects only over WiFi VPN, the device may not receive security updates due to some incorrect checks. This could lead to a local denial of service of security updates with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-8.1 Android ID: A-78644887.

CVSS3: 5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xv75-c298-2v8f

iked in OpenIKED, as used in OpenBSD through 6.7, allows authentication bypass because ca.c has the wrong logic for checking whether a public key matches.

CVSS3: 9.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xv75-3499-88v3

The nsZipArchive function in Mozilla Firefox before 44.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging incorrect use of a pointer during processing of a ZIP archive.

CVSS3: 8.8
1%
Низкий
почти 4 года назад

Уязвимостей на страницу