Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 315 253

Количество 315 253

github логотип

GHSA-xrr8-23jx-fjvc

почти 2 года назад

An information disclosure flaw was found in OpenShift Virtualization. The DownwardMetrics feature was introduced to expose host metrics to virtual machine guests and is enabled by default. This issue could expose limited host metrics of a node to any guest in any namespace without being explicitly enabled by an administrator.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xrr7-3cjg-r4vj

почти 4 года назад

Unspecified vulnerability in Apple QuickTime 7.2 on Windows XP allows remote attackers to execute arbitrary code via unknown attack vectors, probably a different vulnerability than CVE-2007-6166. NOTE: this information is based upon a vague advisory by a vulnerability information sales organization that does not coordinate with vendors or release advisories with actionable information. A CVE has been assigned for tracking purposes, but duplicates with other CVEs are difficult to determine. However, the organization has stated that this is different than CVE-2007-6166.

EPSS: Низкий
github логотип

GHSA-xrr6-r4jq-rrhc

больше 3 лет назад

On Juniper Networks EX Series Ethernet Switches running affected Junos OS versions, a vulnerability in IPv6 processing has been discovered that may allow a specially crafted IPv6 Neighbor Discovery (ND) packet destined to an EX Series Ethernet Switch to cause a slow memory leak. A malicious network-based packet flood of these crafted IPv6 NDP packets may eventually lead to resource exhaustion and a denial of service. The affected Junos OS versions are: 12.3 prior to 12.3R12-S4, 12.3R13; 13.3 prior to 13.3R10; 14.1 prior to 14.1R8-S3, 14.1R9; 14.1X53 prior ro 14.1X53-D12, 14.1X53-D40; 14.1X55 prior to 14.1X55-D35; 14.2 prior to 14.2R6-S4, 14.2R7-S6, 14.2R8; 15.1 prior to 15.1R5; 16.1 before 16.1R3; 16.2 before 16.2R1-S3, 16.2R2. 17.1R1 and all subsequent releases have a resolution for this vulnerability.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xrr6-c8rc-c2wp

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in the HTTP server in Cisco IOS 11.0 through 12.4 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to the ping program or (2) unspecified other aspects of the URI.

EPSS: Низкий
github логотип

GHSA-xrr6-6ww3-f3qm

больше 5 лет назад

Sandbox Breakout / Arbitrary Code Execution in value-censorship

EPSS: Низкий
github логотип

GHSA-xrr6-69ww-5ggj

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in clickstream.js in Y! Toolbar plugin for FireFox 3.1.0.20130813024103 for Mac, and 2.5.9.2013418100420 for Windows, allows remote attackers to inject arbitrary web script or HTML via a crafted URL that is stored by the victim.

EPSS: Низкий
github логотип

GHSA-xrr6-3pc4-m447

больше 8 лет назад

Active Record Improper Access Control

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xrr5-3hrr-35jx

около 3 лет назад

CRYSTALS-DILITHIUM (in Post-Quantum Cryptography Selected Algorithms 2022) in PQClean d03da30 may allow universal forgeries of digital signatures via a template side-channel attack because of intermediate data leakage of one vector.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xrr4-p6fq-hjg7

больше 8 лет назад

Directory traversal vulnerability in Action View in Ruby on Rails

CVSS3: 7.5
EPSS: Критический
github логотип

GHSA-xrr4-j32g-hj8m

почти 2 года назад

A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow an authenticated user to print the Auth, Priv, and SSL key store passwords in unencrypted logs by manipulating command variables.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xrr4-74mc-rpjc

больше 7 лет назад

Pyro mishandles pid files in temporary directory locations and opening the pid file as root

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xrr3-cmxq-9jq6

почти 4 года назад

SQL injection vulnerability in index.php for Lighthouse Squirrelcart allows remote attackers to execute arbitrary SQL commands via the (1) crn parameter in a show action or (2) rn parameter in a show_detail action.

EPSS: Низкий
github логотип

GHSA-xrr2-rvc6-5mhw

3 месяца назад

Sogexia Android App Compile Affected SDK v35, Max SDK 32 and fixed in v36, was discovered to contain hardcoded encryption keys in the encryption_helper.dart file

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xrr2-rr4f-w9p3

больше 2 лет назад

The VK Blocks plugin for WordPress is vulnerable to improper authorization via the REST 'update_vk_blocks_options' function in versions up to, and including, 1.57.0.5. This allows authenticated attackers, with contributor-level permissions or above, to change plugin settings including default icons.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xrqx-mp2q-94fc

больше 3 лет назад

/opt/vyatta/bin/sudo-users/vyatta-clear-dhcp-lease.pl on the Brocade Vyatta 5400 vRouter 6.4R(x), 6.6R(x), and 6.7R1 does not properly validate parameters, which allows local users to gain privileges by leveraging the sudo configuration.

EPSS: Низкий
github логотип

GHSA-xrqx-j38x-m6pj

больше 3 лет назад

A remote code execution vulnerability exists when Windows Media Audio Decoder improperly handles objects, aka 'Windows Media Audio Decoder Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1508.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-xrqw-7396-fjm2

больше 3 лет назад

Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3 , contain an insertion of sensitive information in log files vulnerability. A remote unprivileged attacker could potentially exploit this vulnerability, leading to exposure of this sensitive data.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xrqw-4q5c-x35c

больше 3 лет назад

Integer overflow in the in_nsv plugin in Winamp before 5.6 allows remote attackers to have an unspecified impact via vectors related to improper allocation of memory for NSV metadata, a different vulnerability than CVE-2010-2586.

EPSS: Низкий
github логотип

GHSA-xrqv-3gq7-88qw

больше 3 лет назад

Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.

EPSS: Низкий
github логотип

GHSA-xrqq-wqh4-5hg2

почти 3 года назад

svg-sanitizer has Cross-site Scripting Bypass

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xrr8-23jx-fjvc

An information disclosure flaw was found in OpenShift Virtualization. The DownwardMetrics feature was introduced to expose host metrics to virtual machine guests and is enabled by default. This issue could expose limited host metrics of a node to any guest in any namespace without being explicitly enabled by an administrator.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-xrr7-3cjg-r4vj

Unspecified vulnerability in Apple QuickTime 7.2 on Windows XP allows remote attackers to execute arbitrary code via unknown attack vectors, probably a different vulnerability than CVE-2007-6166. NOTE: this information is based upon a vague advisory by a vulnerability information sales organization that does not coordinate with vendors or release advisories with actionable information. A CVE has been assigned for tracking purposes, but duplicates with other CVEs are difficult to determine. However, the organization has stated that this is different than CVE-2007-6166.

3%
Низкий
почти 4 года назад
github логотип
GHSA-xrr6-r4jq-rrhc

On Juniper Networks EX Series Ethernet Switches running affected Junos OS versions, a vulnerability in IPv6 processing has been discovered that may allow a specially crafted IPv6 Neighbor Discovery (ND) packet destined to an EX Series Ethernet Switch to cause a slow memory leak. A malicious network-based packet flood of these crafted IPv6 NDP packets may eventually lead to resource exhaustion and a denial of service. The affected Junos OS versions are: 12.3 prior to 12.3R12-S4, 12.3R13; 13.3 prior to 13.3R10; 14.1 prior to 14.1R8-S3, 14.1R9; 14.1X53 prior ro 14.1X53-D12, 14.1X53-D40; 14.1X55 prior to 14.1X55-D35; 14.2 prior to 14.2R6-S4, 14.2R7-S6, 14.2R8; 15.1 prior to 15.1R5; 16.1 before 16.1R3; 16.2 before 16.2R1-S3, 16.2R2. 17.1R1 and all subsequent releases have a resolution for this vulnerability.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xrr6-c8rc-c2wp

Multiple cross-site scripting (XSS) vulnerabilities in the HTTP server in Cisco IOS 11.0 through 12.4 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to the ping program or (2) unspecified other aspects of the URI.

9%
Низкий
почти 4 года назад
github логотип
GHSA-xrr6-6ww3-f3qm

Sandbox Breakout / Arbitrary Code Execution in value-censorship

больше 5 лет назад
github логотип
GHSA-xrr6-69ww-5ggj

Cross-site scripting (XSS) vulnerability in clickstream.js in Y! Toolbar plugin for FireFox 3.1.0.20130813024103 for Mac, and 2.5.9.2013418100420 for Windows, allows remote attackers to inject arbitrary web script or HTML via a crafted URL that is stored by the victim.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xrr6-3pc4-m447

Active Record Improper Access Control

CVSS3: 5.3
1%
Низкий
больше 8 лет назад
github логотип
GHSA-xrr5-3hrr-35jx

CRYSTALS-DILITHIUM (in Post-Quantum Cryptography Selected Algorithms 2022) in PQClean d03da30 may allow universal forgeries of digital signatures via a template side-channel attack because of intermediate data leakage of one vector.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-xrr4-p6fq-hjg7

Directory traversal vulnerability in Action View in Ruby on Rails

CVSS3: 7.5
93%
Критический
больше 8 лет назад
github логотип
GHSA-xrr4-j32g-hj8m

A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow an authenticated user to print the Auth, Priv, and SSL key store passwords in unencrypted logs by manipulating command variables.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-xrr4-74mc-rpjc

Pyro mishandles pid files in temporary directory locations and opening the pid file as root

CVSS3: 7.5
0%
Низкий
больше 7 лет назад
github логотип
GHSA-xrr3-cmxq-9jq6

SQL injection vulnerability in index.php for Lighthouse Squirrelcart allows remote attackers to execute arbitrary SQL commands via the (1) crn parameter in a show action or (2) rn parameter in a show_detail action.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xrr2-rvc6-5mhw

Sogexia Android App Compile Affected SDK v35, Max SDK 32 and fixed in v36, was discovered to contain hardcoded encryption keys in the encryption_helper.dart file

CVSS3: 9.1
0%
Низкий
3 месяца назад
github логотип
GHSA-xrr2-rr4f-w9p3

The VK Blocks plugin for WordPress is vulnerable to improper authorization via the REST 'update_vk_blocks_options' function in versions up to, and including, 1.57.0.5. This allows authenticated attackers, with contributor-level permissions or above, to change plugin settings including default icons.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xrqx-mp2q-94fc

/opt/vyatta/bin/sudo-users/vyatta-clear-dhcp-lease.pl on the Brocade Vyatta 5400 vRouter 6.4R(x), 6.6R(x), and 6.7R1 does not properly validate parameters, which allows local users to gain privileges by leveraging the sudo configuration.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xrqx-j38x-m6pj

A remote code execution vulnerability exists when Windows Media Audio Decoder improperly handles objects, aka 'Windows Media Audio Decoder Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1508.

CVSS3: 7.6
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xrqw-7396-fjm2

Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3 , contain an insertion of sensitive information in log files vulnerability. A remote unprivileged attacker could potentially exploit this vulnerability, leading to exposure of this sensitive data.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xrqw-4q5c-x35c

Integer overflow in the in_nsv plugin in Winamp before 5.6 allows remote attackers to have an unspecified impact via vectors related to improper allocation of memory for NSV metadata, a different vulnerability than CVE-2010-2586.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xrqv-3gq7-88qw

Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xrqq-wqh4-5hg2

svg-sanitizer has Cross-site Scripting Bypass

CVSS3: 5.3
почти 3 года назад

Уязвимостей на страницу