Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 324 360

Количество 324 360

github логотип

GHSA-xv4p-4459-7rgr

почти 4 года назад

Unspecified vulnerability in the Edit Contact scene in Ultra-light Mode in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.241 for Domino 8.0.2 FP3 has unknown impact and attack vectors, aka SPR LSHR7TBLY5.

EPSS: Низкий
github логотип

GHSA-xv4p-3xwj-7c58

почти 4 года назад

An authentication issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. A local attacker may be able to login to the account of a previously logged in user without valid credentials..

EPSS: Низкий
github логотип

GHSA-xv4m-3w46-f9wh

больше 3 лет назад

In zulip before 1.3.12, bot API keys were accessible to other users in the same realm.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xv4j-6mfg-j9p6

около 1 года назад

Out-of-bounds Read vulnerability (CWE-125) was found in CX-Programmer. Attackers may be able to read sensitive information or cause an application crash by abusing this vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xv4h-w5rx-q9c8

почти 4 года назад

Improper input validation bug in DNS resolver component of Knot Resolver before 2.4.1 allows remote attacker to poison cache.

CVSS3: 6.8
EPSS: Средний
github логотип

GHSA-xv4h-rw6f-p655

почти 4 года назад

Hitachi Super-H architecture in NetBSD 1.5 and 1.4.1 allows a local user to gain privileges via modified Status Register contents, which are not properly handled by (1) the sigreturn system call or (2) the process_write_regs kernel routine.

EPSS: Низкий
github логотип

GHSA-xv4g-hqvg-vp5w

почти 4 года назад

The mintToken function of a smart contract implementation for ALEX, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xv4g-g9fh-fqrj

больше 1 года назад

The GEO my WP WordPress plugin before 4.5.0.2 does not prevent unauthenticated attackers from including arbitrary files in PHP's execution context, which leads to Remote Code Execution.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xv4c-h899-8cjv

5 месяцев назад

A vulnerability was found in code-projects E-Commerce Website 1.0. Affected is an unknown function of the file /pages/product_add.php. The manipulation of the argument prod_name/prod_desc/prod_cost results in cross site scripting. It is possible to launch the attack remotely. The exploit has been made public and could be used.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xv4c-82gx-6p8g

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in N8cms 1.1 and 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) dir and (2) page_id parameter to (a) index.php and (3) userid parameter to (b) mailto.php. NOTE: it is possible that issues 1 and 2 are resultant from SQL injection.

EPSS: Низкий
github логотип

GHSA-xv4c-2443-pc28

около 1 года назад

Due to a lack of access control, unauthorized users are able to view and modify information pertaining to other users.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xv49-pvqx-8xr6

больше 3 лет назад

A flaw was found in the Linux kernel Traffic Control (TC) subsystem. Using a specific networking configuration (redirecting egress packets to ingress using TC action "mirred") a local unprivileged user could trigger a CPU soft lockup (ABBA deadlock) when the transport protocol in use (TCP or SCTP) does a retransmission, resulting in a denial of service condition.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xv49-pqwv-x2hc

около 1 месяца назад

In __host_check_page_state_range of mem_protect.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-xv49-7846-mhm4

почти 4 года назад

Adobe Media Encoder version 15.1 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

EPSS: Низкий
github логотип

GHSA-xv49-34rf-rqv4

около 2 месяцев назад

A flaw was found in libsoup, an HTTP client/server library. This HTTP Request Smuggling vulnerability arises from non-RFC-compliant parsing in the soup_filter_input_stream_read_line() logic, where libsoup accepts malformed chunk headers, such as lone line feed (LF) characters instead of the required carriage return and line feed (CRLF). A remote attacker can exploit this without authentication or user interaction by sending specially crafted chunked requests. This allows libsoup to parse and process multiple HTTP requests from a single network message, potentially leading to information disclosure.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xv49-2wgv-qvc2

почти 4 года назад

Cross-site scripting (XSS) vulnerability in index.php in the hosted_signup module in NetArt Media iBoutique.MALL 1.2 allows remote attackers to inject arbitrary web script or HTML via the tmpl parameter. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-xv48-qfxm-rc53

3 месяца назад

An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500. A race condition in the issimian device driver results in an out-of-bounds access, leading to a denial of service.

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-xv46-hhwp-vf34

почти 4 года назад

A vulnerability in the internal Kubernetes agent api in GitLab CE/EE version 13.3 and above allows unauthorized access to private projects. Affected versions are: >=13.4, <13.4.5,>=13.3, <13.3.9,>=13.5, <13.5.2.

EPSS: Низкий
github логотип

GHSA-xv46-47mw-9vxc

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: add RCU protection to mld_newpack() mld_newpack() can be called without RTNL or RCU being held. Note that we no longer can use sock_alloc_send_skb() because ipv6.igmp_sk uses GFP_KERNEL allocations which can sleep. Instead use alloc_skb() and charge the net->ipv6.igmp_sk socket under RCU protection.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xv45-rrwp-wgf4

почти 4 года назад

The official rabbitmq docker images before 3.7.13-beta.1-management-alpine (Alpine specific) contain a blank password for a root user. System using the rabbitmq docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xv4p-4459-7rgr

Unspecified vulnerability in the Edit Contact scene in Ultra-light Mode in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.241 for Domino 8.0.2 FP3 has unknown impact and attack vectors, aka SPR LSHR7TBLY5.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xv4p-3xwj-7c58

An authentication issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. A local attacker may be able to login to the account of a previously logged in user without valid credentials..

0%
Низкий
почти 4 года назад
github логотип
GHSA-xv4m-3w46-f9wh

In zulip before 1.3.12, bot API keys were accessible to other users in the same realm.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xv4j-6mfg-j9p6

Out-of-bounds Read vulnerability (CWE-125) was found in CX-Programmer. Attackers may be able to read sensitive information or cause an application crash by abusing this vulnerability.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-xv4h-w5rx-q9c8

Improper input validation bug in DNS resolver component of Knot Resolver before 2.4.1 allows remote attacker to poison cache.

CVSS3: 6.8
12%
Средний
почти 4 года назад
github логотип
GHSA-xv4h-rw6f-p655

Hitachi Super-H architecture in NetBSD 1.5 and 1.4.1 allows a local user to gain privileges via modified Status Register contents, which are not properly handled by (1) the sigreturn system call or (2) the process_write_regs kernel routine.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xv4g-hqvg-vp5w

The mintToken function of a smart contract implementation for ALEX, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xv4g-g9fh-fqrj

The GEO my WP WordPress plugin before 4.5.0.2 does not prevent unauthenticated attackers from including arbitrary files in PHP's execution context, which leads to Remote Code Execution.

CVSS3: 9.8
44%
Средний
больше 1 года назад
github логотип
GHSA-xv4c-h899-8cjv

A vulnerability was found in code-projects E-Commerce Website 1.0. Affected is an unknown function of the file /pages/product_add.php. The manipulation of the argument prod_name/prod_desc/prod_cost results in cross site scripting. It is possible to launch the attack remotely. The exploit has been made public and could be used.

CVSS3: 4.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-xv4c-82gx-6p8g

Multiple cross-site scripting (XSS) vulnerabilities in N8cms 1.1 and 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) dir and (2) page_id parameter to (a) index.php and (3) userid parameter to (b) mailto.php. NOTE: it is possible that issues 1 and 2 are resultant from SQL injection.

2%
Низкий
почти 4 года назад
github логотип
GHSA-xv4c-2443-pc28

Due to a lack of access control, unauthorized users are able to view and modify information pertaining to other users.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-xv49-pvqx-8xr6

A flaw was found in the Linux kernel Traffic Control (TC) subsystem. Using a specific networking configuration (redirecting egress packets to ingress using TC action "mirred") a local unprivileged user could trigger a CPU soft lockup (ABBA deadlock) when the transport protocol in use (TCP or SCTP) does a retransmission, resulting in a denial of service condition.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xv49-pqwv-x2hc

In __host_check_page_state_range of mem_protect.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 8.4
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xv49-7846-mhm4

Adobe Media Encoder version 15.1 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xv49-34rf-rqv4

A flaw was found in libsoup, an HTTP client/server library. This HTTP Request Smuggling vulnerability arises from non-RFC-compliant parsing in the soup_filter_input_stream_read_line() logic, where libsoup accepts malformed chunk headers, such as lone line feed (LF) characters instead of the required carriage return and line feed (CRLF). A remote attacker can exploit this without authentication or user interaction by sending specially crafted chunked requests. This allows libsoup to parse and process multiple HTTP requests from a single network message, potentially leading to information disclosure.

CVSS3: 5.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xv49-2wgv-qvc2

Cross-site scripting (XSS) vulnerability in index.php in the hosted_signup module in NetArt Media iBoutique.MALL 1.2 allows remote attackers to inject arbitrary web script or HTML via the tmpl parameter. NOTE: some of these details are obtained from third party information.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xv48-qfxm-rc53

An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500. A race condition in the issimian device driver results in an out-of-bounds access, leading to a denial of service.

CVSS3: 5.1
0%
Низкий
3 месяца назад
github логотип
GHSA-xv46-hhwp-vf34

A vulnerability in the internal Kubernetes agent api in GitLab CE/EE version 13.3 and above allows unauthorized access to private projects. Affected versions are: >=13.4, <13.4.5,>=13.3, <13.3.9,>=13.5, <13.5.2.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xv46-47mw-9vxc

In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: add RCU protection to mld_newpack() mld_newpack() can be called without RTNL or RCU being held. Note that we no longer can use sock_alloc_send_skb() because ipv6.igmp_sk uses GFP_KERNEL allocations which can sleep. Instead use alloc_skb() and charge the net->ipv6.igmp_sk socket under RCU protection.

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-xv45-rrwp-wgf4

The official rabbitmq docker images before 3.7.13-beta.1-management-alpine (Alpine specific) contain a blank password for a root user. System using the rabbitmq docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.

2%
Низкий
почти 4 года назад

Уязвимостей на страницу