Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-xrpq-63mp-9vcw

почти 4 года назад

phpMyAdmin HTTP Response Splitting Vulnerability

EPSS: Низкий
github логотип

GHSA-xrpq-4g9w-qrwj

9 месяцев назад

Jenkins Health Advisor by CloudBees Plugin Vulnerable to Cross-Site Scripting

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xrpp-vwp4-q9hp

больше 3 лет назад

An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the bootp_input() function and could occur while processing a udp packet that is smaller than the size of the 'bootp_t' structure. A malicious guest could use this flaw to leak 10 bytes of uninitialized heap memory from the host. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-xrpp-vm79-f74q

больше 3 лет назад

Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Oct-2021 Release 1 allows attackers to write file as system UID via BT remote socket.

EPSS: Низкий
github логотип

GHSA-xrpp-3rf6-w42j

больше 2 лет назад

Docker Desktop before 4.12.0 is vulnerable to RCE via a crafted extension description or changelog. This issue affects Docker Desktop: before 4.12.0.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xrpm-hccg-28x7

больше 2 лет назад

Improper Input Validation in nocodb

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xrpm-74v3-f6fq

почти 4 года назад

The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1; and Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2; does not properly restrict use of OleLoadFromStream in instantiating objects from data streams, which allows remote attackers to execute arbitrary code via a crafted HTML document with an ATL (1) component or (2) control, related to ATL headers and bypassing security policies, aka "ATL COM Initialization Vulnerability."

EPSS: Средний
github логотип

GHSA-xrpj-f9v6-2332

больше 4 лет назад

CSV injection in Craft CMS

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xrph-fg7m-g22g

почти 4 года назад

NDMP server in Veritas NetBackup 5.1 allows attackers to cause a denial of service via a CONFIG message with an out-of-range timestamp, which triggers a null dereference.

EPSS: Низкий
github логотип

GHSA-xrph-cp3c-jgmh

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Fix a race between readers and resize checks The reader code in rb_get_reader_page() swaps a new reader page into the ring buffer by doing cmpxchg on old->list.prev->next to point it to the new page. Following that, if the operation is successful, old->list.next->prev gets updated too. This means the underlying doubly-linked list is temporarily inconsistent, page->prev->next or page->next->prev might not be equal back to page for some page in the ring buffer. The resize operation in ring_buffer_resize() can be invoked in parallel. It calls rb_check_pages() which can detect the described inconsistency and stop further tracing: [ 190.271762] ------------[ cut here ]------------ [ 190.271771] WARNING: CPU: 1 PID: 6186 at kernel/trace/ring_buffer.c:1467 rb_check_pages.isra.0+0x6a/0xa0 [ 190.271789] Modules linked in: [...] [ 190.271991] Unloaded tainted modules: intel_uncore_frequency(E):1 skx_edac(...

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-xrph-4qjj-gj25

больше 3 лет назад

parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disabled, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted XML document containing a large number of nested entity references, a variant of the "billion laughs" attack.

EPSS: Низкий
github логотип

GHSA-xrpg-qv3x-v75v

около 4 лет назад

An issue was discovered in COINS Construction Cloud 11.12. In several locations throughout the application, JavaScript code is passed as a URL parameter. Attackers can trivially alter this code to cause malicious behaviour. The application is therefore vulnerable to reflected XSS via malicious URLs.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xrpf-jjp4-8pmh

больше 3 лет назад

Spoon::Cookie in the Spoon module 0.24 for Perl does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via a crafted request, which is not properly handled when it is deserialized.

EPSS: Низкий
github логотип

GHSA-xrpf-f2q9-273m

больше 3 лет назад

While processing a debug log event from firmware in all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-07-05, an integer underflow and/or buffer over-read can occur.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xrpf-8365-6mrj

почти 3 года назад

Adobe Animate versions 22.0.8 (and earlier) and 23.0.0 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xrpf-2c53-3fmg

почти 4 года назад

Buffer overflow in the process_font_table function in convert.c for unrtf 0.19.3 allows remote attackers to execute arbitrary code via a crafted RTF file.

EPSS: Низкий
github логотип

GHSA-xrpc-hpq7-f7wx

около 1 года назад

Missing Authorization vulnerability in WP Travel WP Travel allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Travel: from n/a through 7.8.0.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xrpc-f6j4-wmx4

больше 3 лет назад

In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products utilized hard coded SMB credentials, which may allow an attacker to remotely execute arbitrary code.

EPSS: Низкий
github логотип

GHSA-xrp9-v7m5-2gw6

больше 3 лет назад

An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that is mishandled during parent-tab processing.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xrp8-mw8v-p6mq

почти 4 года назад

Liblouis through 3.21.0 has a buffer overflow in compilePassOpcode in compileTranslationTable.c (called, indirectly, by tools/lou_checktable.c).

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xrpq-63mp-9vcw

phpMyAdmin HTTP Response Splitting Vulnerability

1%
Низкий
почти 4 года назад
github логотип
GHSA-xrpq-4g9w-qrwj

Jenkins Health Advisor by CloudBees Plugin Vulnerable to Cross-Site Scripting

CVSS3: 8.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-xrpp-vwp4-q9hp

An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the bootp_input() function and could occur while processing a udp packet that is smaller than the size of the 'bootp_t' structure. A malicious guest could use this flaw to leak 10 bytes of uninitialized heap memory from the host. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.

CVSS3: 3.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xrpp-vm79-f74q

Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Oct-2021 Release 1 allows attackers to write file as system UID via BT remote socket.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xrpp-3rf6-w42j

Docker Desktop before 4.12.0 is vulnerable to RCE via a crafted extension description or changelog. This issue affects Docker Desktop: before 4.12.0.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xrpm-hccg-28x7

Improper Input Validation in nocodb

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xrpm-74v3-f6fq

The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1; and Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2; does not properly restrict use of OleLoadFromStream in instantiating objects from data streams, which allows remote attackers to execute arbitrary code via a crafted HTML document with an ATL (1) component or (2) control, related to ATL headers and bypassing security policies, aka "ATL COM Initialization Vulnerability."

42%
Средний
почти 4 года назад
github логотип
GHSA-xrpj-f9v6-2332

CSV injection in Craft CMS

CVSS3: 8.8
больше 4 лет назад
github логотип
GHSA-xrph-fg7m-g22g

NDMP server in Veritas NetBackup 5.1 allows attackers to cause a denial of service via a CONFIG message with an out-of-range timestamp, which triggers a null dereference.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xrph-cp3c-jgmh

In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Fix a race between readers and resize checks The reader code in rb_get_reader_page() swaps a new reader page into the ring buffer by doing cmpxchg on old->list.prev->next to point it to the new page. Following that, if the operation is successful, old->list.next->prev gets updated too. This means the underlying doubly-linked list is temporarily inconsistent, page->prev->next or page->next->prev might not be equal back to page for some page in the ring buffer. The resize operation in ring_buffer_resize() can be invoked in parallel. It calls rb_check_pages() which can detect the described inconsistency and stop further tracing: [ 190.271762] ------------[ cut here ]------------ [ 190.271771] WARNING: CPU: 1 PID: 6186 at kernel/trace/ring_buffer.c:1467 rb_check_pages.isra.0+0x6a/0xa0 [ 190.271789] Modules linked in: [...] [ 190.271991] Unloaded tainted modules: intel_uncore_frequency(E):1 skx_edac(...

CVSS3: 4.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-xrph-4qjj-gj25

parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disabled, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted XML document containing a large number of nested entity references, a variant of the "billion laughs" attack.

4%
Низкий
больше 3 лет назад
github логотип
GHSA-xrpg-qv3x-v75v

An issue was discovered in COINS Construction Cloud 11.12. In several locations throughout the application, JavaScript code is passed as a URL parameter. Attackers can trivially alter this code to cause malicious behaviour. The application is therefore vulnerable to reflected XSS via malicious URLs.

CVSS3: 6.1
0%
Низкий
около 4 лет назад
github логотип
GHSA-xrpf-jjp4-8pmh

Spoon::Cookie in the Spoon module 0.24 for Perl does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via a crafted request, which is not properly handled when it is deserialized.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-xrpf-f2q9-273m

While processing a debug log event from firmware in all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-07-05, an integer underflow and/or buffer over-read can occur.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xrpf-8365-6mrj

Adobe Animate versions 22.0.8 (and earlier) and 23.0.0 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-xrpf-2c53-3fmg

Buffer overflow in the process_font_table function in convert.c for unrtf 0.19.3 allows remote attackers to execute arbitrary code via a crafted RTF file.

8%
Низкий
почти 4 года назад
github логотип
GHSA-xrpc-hpq7-f7wx

Missing Authorization vulnerability in WP Travel WP Travel allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Travel: from n/a through 7.8.0.

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-xrpc-f6j4-wmx4

In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products utilized hard coded SMB credentials, which may allow an attacker to remotely execute arbitrary code.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xrp9-v7m5-2gw6

An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that is mishandled during parent-tab processing.

CVSS3: 6.1
4%
Низкий
больше 3 лет назад
github логотип
GHSA-xrp8-mw8v-p6mq

Liblouis through 3.21.0 has a buffer overflow in compilePassOpcode in compileTranslationTable.c (called, indirectly, by tools/lou_checktable.c).

CVSS3: 7.8
0%
Низкий
почти 4 года назад

Уязвимостей на страницу