Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 324 648

Количество 324 648

github логотип

GHSA-xrgf-qp7c-883g

около 2 лет назад

This issue was addressed by improving Face ID anti-spoofing models. This issue is fixed in iOS 17 and iPadOS 17. A 3D model constructed to look like the enrolled user may authenticate via Face ID.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xrgf-45jw-vmmp

почти 4 года назад

Xen 4.6.x and earlier allows local guest administrators to cause a denial of service (host reboot) via vectors related to multiple mappings of MMIO pages with different cachability settings.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-xrgc-rm8q-pjrp

больше 1 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Designinvento DirectoryPress allows SQL Injection.This issue affects DirectoryPress: from n/a through 3.6.10.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-xrgc-r968-f934

почти 4 года назад

Cross-site scripting (XSS) vulnerability in index.php in MarmaraWeb E-commerce allows remote attackers to inject arbitrary web script or HTML via the page parameter to index.php. NOTE: this might be resultant from CVE-2005-4287.

EPSS: Низкий
github логотип

GHSA-xrg9-xjhp-934h

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: nvdimm: Fix firmware activation deadlock scenarios Lockdep reports the following deadlock scenarios for CXL root device power-management, device_prepare(), operations, and device_shutdown() operations for 'nd_region' devices: Chain exists of: &nvdimm_region_key --> &nvdimm_bus->reconfig_mutex --> system_transition_mutex Possible unsafe locking scenario: CPU0 CPU1 ---- ---- lock(system_transition_mutex); lock(&nvdimm_bus->reconfig_mutex); lock(system_transition_mutex); lock(&nvdimm_region_key); Chain exists of: &cxl_nvdimm_bridge_key --> acpi_scan_lock --> &cxl_root_key Possible unsafe locking scenario: CPU0 CPU1 ---- ---- lock(&cxl_root_key); lock(acpi_scan_lock); ...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xrg9-wwrq-xmx9

почти 5 лет назад

Missing Authorization in Jenkins Kubernetes CLI Plugin

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xrg9-2q4w-gf5c

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: ASoC: dapm: fix bounds checker error in dapm_widget_list_create The widgets array in the snd_soc_dapm_widget_list has a __counted_by attribute attached to it, which points to the num_widgets variable. This attribute is used in bounds checking, and if it is not set before the array is filled, then the bounds sanitizer will issue a warning or a kernel panic if CONFIG_UBSAN_TRAP is set. This patch sets the size of the widgets list calculated with list_for_each as the initial value for num_widgets as it is used for allocating memory for the array. It is updated with the actual number of added elements after the array is filled.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xrg8-rx83-pg44

почти 2 года назад

Missing Authorization vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.1.8.

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-xrg8-r4mg-6g2x

12 месяцев назад

After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xrg8-2wfr-qxc5

почти 4 года назад

Unknown vulnerability in the CUPS printing system in Mac OS X 10.3.3 and Mac OS X 10.2.8 with unknown impact, possibly related to a configuration file setting.

EPSS: Низкий
github логотип

GHSA-xrg7-wh2g-5jmq

почти 4 года назад

Format string vulnerabilities in (1) inews or (2) rnews for INN 2.2.3 and earlier allow local users and remote malicious NNTP servers to gain privileges via format string specifiers in NTTP responses.

EPSS: Низкий
github логотип

GHSA-xrg7-hhwv-8fc8

почти 4 года назад

Insufficient access control in the firmware of the Intel(R) Ethernet 700 Series Controllers before version 7.3 may allow a privileged user to potentially enable escalation of privilege and/or denial of service via local access.

EPSS: Низкий
github логотип

GHSA-xrg6-2px8-pv79

почти 4 года назад

A vulnerability in the web management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct directory traversal attacks and obtain read and write access to sensitive files on a targeted system. The vulnerability is due to a lack of proper validation of files that are uploaded to an affected device. An attacker could exploit this vulnerability by uploading a crafted file to an affected system. An exploit could allow the attacker to view or modify arbitrary files on the targeted system.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xrg5-hv44-2h7r

почти 4 года назад

Pixel-Apes SafeHTML before 1.2.1 allows remote attackers to bypass cross-site scripting (XSS) protection via "hexadecimal HTML entities."

EPSS: Низкий
github логотип

GHSA-xrg5-9qxv-fc56

около 3 лет назад

In Malwarebytes before 4.5.23, a symbolic link may be used delete any arbitrary file on the system by exploiting the local quarantine system. It can also lead to privilege escalation in certain scenarios.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xrg5-3www-67qf

почти 4 года назад

JNews Joomla Component before 8.5.0 has XSS via the mailingsearch parameter.

EPSS: Низкий
github логотип

GHSA-xrg5-2wx9-gc8m

почти 4 года назад

Unrestricted file upload vulnerability in PhotoPost vBGallery before 2.4.2 allows remote attackers to upload and execute arbitrary files via unknown vectors.

EPSS: Низкий
github логотип

GHSA-xrg4-h4p3-4856

9 месяцев назад

A vulnerability was found in coldfunction qCUDA up to db0085400c2f2011eed46fbc04fdc0873141688e. It has been rated as problematic. Affected by this issue is the function qcow_make_empty of the file qCUDA/qcu-device/block/qcow.c. The manipulation of the argument s->l1_size leads to integer overflow. The attack needs to be approached locally. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xrg3-hmf3-rvgw

около 4 лет назад

Path Traversal in rust-embed

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xrg3-35mw-8rhg

больше 3 лет назад

A vulnerability in the SSL/TLS implementation of Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to alter communications with associated controllers or view sensitive information. This vulnerability exists because SSL server certificates are not validated when Cisco Nexus Dashboard is establishing a connection to Cisco Application Policy Infrastructure Controller (APIC), Cisco Cloud APIC, or Cisco Nexus Dashboard Fabric Controller, formerly Data Center Network Manager (DCNM) controllers. An attacker could exploit this vulnerability by using man-in-the-middle techniques to intercept the traffic between the affected device and the controllers, and then using a crafted certificate to impersonate the controllers. A successful exploit could allow the attacker to alter communications between devices or view sensitive information, including Administrator credentials for these controllers.

CVSS3: 7.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xrgf-qp7c-883g

This issue was addressed by improving Face ID anti-spoofing models. This issue is fixed in iOS 17 and iPadOS 17. A 3D model constructed to look like the enrolled user may authenticate via Face ID.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-xrgf-45jw-vmmp

Xen 4.6.x and earlier allows local guest administrators to cause a denial of service (host reboot) via vectors related to multiple mappings of MMIO pages with different cachability settings.

CVSS3: 6.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xrgc-rm8q-pjrp

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Designinvento DirectoryPress allows SQL Injection.This issue affects DirectoryPress: from n/a through 3.6.10.

CVSS3: 8.5
6%
Низкий
больше 1 года назад
github логотип
GHSA-xrgc-r968-f934

Cross-site scripting (XSS) vulnerability in index.php in MarmaraWeb E-commerce allows remote attackers to inject arbitrary web script or HTML via the page parameter to index.php. NOTE: this might be resultant from CVE-2005-4287.

2%
Низкий
почти 4 года назад
github логотип
GHSA-xrg9-xjhp-934h

In the Linux kernel, the following vulnerability has been resolved: nvdimm: Fix firmware activation deadlock scenarios Lockdep reports the following deadlock scenarios for CXL root device power-management, device_prepare(), operations, and device_shutdown() operations for 'nd_region' devices: Chain exists of: &nvdimm_region_key --> &nvdimm_bus->reconfig_mutex --> system_transition_mutex Possible unsafe locking scenario: CPU0 CPU1 ---- ---- lock(system_transition_mutex); lock(&nvdimm_bus->reconfig_mutex); lock(system_transition_mutex); lock(&nvdimm_region_key); Chain exists of: &cxl_nvdimm_bridge_key --> acpi_scan_lock --> &cxl_root_key Possible unsafe locking scenario: CPU0 CPU1 ---- ---- lock(&cxl_root_key); lock(acpi_scan_lock); ...

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-xrg9-wwrq-xmx9

Missing Authorization in Jenkins Kubernetes CLI Plugin

CVSS3: 4.3
0%
Низкий
почти 5 лет назад
github логотип
GHSA-xrg9-2q4w-gf5c

In the Linux kernel, the following vulnerability has been resolved: ASoC: dapm: fix bounds checker error in dapm_widget_list_create The widgets array in the snd_soc_dapm_widget_list has a __counted_by attribute attached to it, which points to the num_widgets variable. This attribute is used in bounds checking, and if it is not set before the array is filled, then the bounds sanitizer will issue a warning or a kernel panic if CONFIG_UBSAN_TRAP is set. This patch sets the size of the widgets list calculated with list_for_each as the initial value for num_widgets as it is used for allocating memory for the array. It is updated with the actual number of added elements after the array is filled.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xrg8-rx83-pg44

Missing Authorization vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.1.8.

CVSS3: 8.3
1%
Низкий
почти 2 года назад
github логотип
GHSA-xrg8-r4mg-6g2x

After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-xrg8-2wfr-qxc5

Unknown vulnerability in the CUPS printing system in Mac OS X 10.3.3 and Mac OS X 10.2.8 with unknown impact, possibly related to a configuration file setting.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xrg7-wh2g-5jmq

Format string vulnerabilities in (1) inews or (2) rnews for INN 2.2.3 and earlier allow local users and remote malicious NNTP servers to gain privileges via format string specifiers in NTTP responses.

4%
Низкий
почти 4 года назад
github логотип
GHSA-xrg7-hhwv-8fc8

Insufficient access control in the firmware of the Intel(R) Ethernet 700 Series Controllers before version 7.3 may allow a privileged user to potentially enable escalation of privilege and/or denial of service via local access.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xrg6-2px8-pv79

A vulnerability in the web management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct directory traversal attacks and obtain read and write access to sensitive files on a targeted system. The vulnerability is due to a lack of proper validation of files that are uploaded to an affected device. An attacker could exploit this vulnerability by uploading a crafted file to an affected system. An exploit could allow the attacker to view or modify arbitrary files on the targeted system.

CVSS3: 8.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-xrg5-hv44-2h7r

Pixel-Apes SafeHTML before 1.2.1 allows remote attackers to bypass cross-site scripting (XSS) protection via "hexadecimal HTML entities."

0%
Низкий
почти 4 года назад
github логотип
GHSA-xrg5-9qxv-fc56

In Malwarebytes before 4.5.23, a symbolic link may be used delete any arbitrary file on the system by exploiting the local quarantine system. It can also lead to privilege escalation in certain scenarios.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-xrg5-3www-67qf

JNews Joomla Component before 8.5.0 has XSS via the mailingsearch parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xrg5-2wx9-gc8m

Unrestricted file upload vulnerability in PhotoPost vBGallery before 2.4.2 allows remote attackers to upload and execute arbitrary files via unknown vectors.

3%
Низкий
почти 4 года назад
github логотип
GHSA-xrg4-h4p3-4856

A vulnerability was found in coldfunction qCUDA up to db0085400c2f2011eed46fbc04fdc0873141688e. It has been rated as problematic. Affected by this issue is the function qcow_make_empty of the file qCUDA/qcu-device/block/qcow.c. The manipulation of the argument s->l1_size leads to integer overflow. The attack needs to be approached locally. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.

CVSS3: 5.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-xrg3-hmf3-rvgw

Path Traversal in rust-embed

CVSS3: 7.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-xrg3-35mw-8rhg

A vulnerability in the SSL/TLS implementation of Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to alter communications with associated controllers or view sensitive information. This vulnerability exists because SSL server certificates are not validated when Cisco Nexus Dashboard is establishing a connection to Cisco Application Policy Infrastructure Controller (APIC), Cisco Cloud APIC, or Cisco Nexus Dashboard Fabric Controller, formerly Data Center Network Manager (DCNM) controllers. An attacker could exploit this vulnerability by using man-in-the-middle techniques to intercept the traffic between the affected device and the controllers, and then using a crafted certificate to impersonate the controllers. A successful exploit could allow the attacker to alter communications between devices or view sensitive information, including Administrator credentials for these controllers.

CVSS3: 7.4
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу