Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-3x43-8h7p-m97w

больше 3 лет назад

IBM DataPower Gateway 2018.4.1.0, 7.6.0.0 through 7.6.0.11, 7.5.2.0 through 7.5.2.18, 7.5.1.0 through 7.5.1.18, 7.5.0.0 through 7.5.0.19, and 7.7.0.0 through 7.7.1.3 could allow an authenticated user to inject arbitrary messages that would be displayed on the UI. IBM X-Force ID: 144892.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3x42-vgc3-7f6c

больше 3 лет назад

An exploitable integer overflow vulnerability exists when creating a new RGB Surface in SDL 2.0.5. A specially crafted file can cause an integer overflow resulting in too little memory being allocated which can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3x3x-vjcr-56cc

больше 2 лет назад

The Linux kernel before 6.5.4 has an es1 use-after-free in fs/ext4/extents_status.c, related to ext4_es_insert_extent.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3x3x-gvp4-q59h

больше 3 лет назад

SAP NetWeaver AS ABAP (Banking Services), versions - 710, 711, 740, 750, 751, 752, 75A, 75B, 75C, 75D, 75E, does not perform necessary authorization checks for an authenticated user due to Missing Authorization Check, allowing wrong and unexpected change of individual conditions by a malicious user leading to wrong prices.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3x3x-fgf2-hxxv

больше 3 лет назад

Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.2, 6.3, 6.3.1, 6.3.2, 6.3.3, and 6.3.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Data, Domain, and Function Security.

EPSS: Низкий
github логотип

GHSA-3x3w-vcjx-7796

больше 3 лет назад

Cross-Site Request Forgery in easyii CMS

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3x3w-ffg6-mp27

больше 3 лет назад

Cisco NX-OS 7.1(1)N1(1) on Nexus 5500, 5600, and 6000 devices does not properly validate PDUs in SNMP packets, which allows remote attackers to cause a denial of service (SNMP application restart) via a crafted packet, aka Bug ID CSCut84645.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3x3w-849q-423v

около 2 лет назад

Xnx3 Wangmarket Cross-Site Scripting vulnerability

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-3x3v-84v2-gwh2

больше 3 лет назад

A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3x3r-mcv6-277v

почти 4 года назад

The WiMAX dissector in Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (crash) via unknown vectors related to "unaligned access on some platforms."

EPSS: Низкий
github логотип

GHSA-3x3q-ghcp-whf7

6 месяцев назад

Template Secret leakage in logs in Scaffolder when using `fetch:template`

CVSS3: 2.6
EPSS: Низкий
github логотип

GHSA-3x3q-3ch4-c25f

около 4 лет назад

A Privilege Escalation vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. Staff account users can access the admin resources and perform CRUD Operations.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3x3q-3c9j-4x72

9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: Input: iforce - invert valid length check when fetching device IDs syzbot is reporting uninitialized value at iforce_init_device() [1], for commit 6ac0aec6b0a6 ("Input: iforce - allow callers supply data buffer when fetching device IDs") is checking that valid length is shorter than bytes to read. Since iforce_get_id_packet() stores valid length when returning 0, the caller needs to check that valid length is longer than or equals to bytes to read.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3x3p-75r6-3954

почти 4 года назад

Stack consumption vulnerability in the ChildProcessSecurityPolicy::CanRequestURL function in browser/child_process_security_policy.cc in Google Chrome before 4.0.249.78 allows remote attackers to cause a denial of service (memory consumption and application crash) via a URL that specifies multiple protocols, as demonstrated by a URL that begins with many repetitions of the view-source: substring.

EPSS: Низкий
github логотип

GHSA-3x3p-2fwv-2ppj

почти 3 года назад

The HwPCAssistant module has the out-of-bounds read/write vulnerability. Successful exploitation of this vulnerability may affect confidentiality and integrity.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-3x3m-p2wx-g7cw

больше 3 лет назад

Unauthenticated File Read in PHP Proxy

CVSS3: 7.5
EPSS: Высокий
github логотип

GHSA-3x3m-9vp5-g9xh

больше 3 лет назад

Google Chrome before 30.0.1599.66 uses incorrect function calls to determine the values of NavigationEntry objects, which allows remote attackers to spoof the address bar via vectors involving a response with a 204 (aka No Content) status code.

EPSS: Низкий
github логотип

GHSA-3x3m-4c79-cmv9

больше 3 лет назад

Memory leak in the megasas_handle_dcmd function in hw/scsi/megasas.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption) via MegaRAID Firmware Interface (MFI) commands with the sglist size set to a value over 2 Gb.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3x3m-47h5-73m3

больше 3 лет назад

A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Mojave 10.14.6. An application may be able to read restricted memory.

EPSS: Низкий
github логотип

GHSA-3x3j-vpj2-43h2

больше 1 года назад

The Events Calendar Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.0.2 via deserialization of untrusted input from the 'filters' parameter in widgets. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. The additional presence of a POP chain allows attackers to execute code remotely. In certain configurations, this can be exploitable by lower level users. We confirmed that this plugin installed with Elementor makes it possible for users with contributor-level access and above to exploit this issue.

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3x43-8h7p-m97w

IBM DataPower Gateway 2018.4.1.0, 7.6.0.0 through 7.6.0.11, 7.5.2.0 through 7.5.2.18, 7.5.1.0 through 7.5.1.18, 7.5.0.0 through 7.5.0.19, and 7.7.0.0 through 7.7.1.3 could allow an authenticated user to inject arbitrary messages that would be displayed on the UI. IBM X-Force ID: 144892.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x42-vgc3-7f6c

An exploitable integer overflow vulnerability exists when creating a new RGB Surface in SDL 2.0.5. A specially crafted file can cause an integer overflow resulting in too little memory being allocated which can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability.

CVSS3: 8.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-3x3x-vjcr-56cc

The Linux kernel before 6.5.4 has an es1 use-after-free in fs/ext4/extents_status.c, related to ext4_es_insert_extent.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3x3x-gvp4-q59h

SAP NetWeaver AS ABAP (Banking Services), versions - 710, 711, 740, 750, 751, 752, 75A, 75B, 75C, 75D, 75E, does not perform necessary authorization checks for an authenticated user due to Missing Authorization Check, allowing wrong and unexpected change of individual conditions by a malicious user leading to wrong prices.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x3x-fgf2-hxxv

Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.2, 6.3, 6.3.1, 6.3.2, 6.3.3, and 6.3.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Data, Domain, and Function Security.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3x3w-vcjx-7796

Cross-Site Request Forgery in easyii CMS

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x3w-ffg6-mp27

Cisco NX-OS 7.1(1)N1(1) on Nexus 5500, 5600, and 6000 devices does not properly validate PDUs in SNMP packets, which allows remote attackers to cause a denial of service (SNMP application restart) via a crafted packet, aka Bug ID CSCut84645.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x3w-849q-423v

Xnx3 Wangmarket Cross-Site Scripting vulnerability

CVSS3: 4.7
0%
Низкий
около 2 лет назад
github логотип
GHSA-3x3v-84v2-gwh2

A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1.

CVSS3: 7.5
10%
Низкий
больше 3 лет назад
github логотип
GHSA-3x3r-mcv6-277v

The WiMAX dissector in Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (crash) via unknown vectors related to "unaligned access on some platforms."

1%
Низкий
почти 4 года назад
github логотип
GHSA-3x3q-ghcp-whf7

Template Secret leakage in logs in Scaffolder when using `fetch:template`

CVSS3: 2.6
0%
Низкий
6 месяцев назад
github логотип
GHSA-3x3q-3ch4-c25f

A Privilege Escalation vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. Staff account users can access the admin resources and perform CRUD Operations.

CVSS3: 7.2
2%
Низкий
около 4 лет назад
github логотип
GHSA-3x3q-3c9j-4x72

In the Linux kernel, the following vulnerability has been resolved: Input: iforce - invert valid length check when fetching device IDs syzbot is reporting uninitialized value at iforce_init_device() [1], for commit 6ac0aec6b0a6 ("Input: iforce - allow callers supply data buffer when fetching device IDs") is checking that valid length is shorter than bytes to read. Since iforce_get_id_packet() stores valid length when returning 0, the caller needs to check that valid length is longer than or equals to bytes to read.

CVSS3: 5.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-3x3p-75r6-3954

Stack consumption vulnerability in the ChildProcessSecurityPolicy::CanRequestURL function in browser/child_process_security_policy.cc in Google Chrome before 4.0.249.78 allows remote attackers to cause a denial of service (memory consumption and application crash) via a URL that specifies multiple protocols, as demonstrated by a URL that begins with many repetitions of the view-source: substring.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3x3p-2fwv-2ppj

The HwPCAssistant module has the out-of-bounds read/write vulnerability. Successful exploitation of this vulnerability may affect confidentiality and integrity.

CVSS3: 9.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-3x3m-p2wx-g7cw

Unauthenticated File Read in PHP Proxy

CVSS3: 7.5
80%
Высокий
больше 3 лет назад
github логотип
GHSA-3x3m-9vp5-g9xh

Google Chrome before 30.0.1599.66 uses incorrect function calls to determine the values of NavigationEntry objects, which allows remote attackers to spoof the address bar via vectors involving a response with a 204 (aka No Content) status code.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3x3m-4c79-cmv9

Memory leak in the megasas_handle_dcmd function in hw/scsi/megasas.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption) via MegaRAID Firmware Interface (MFI) commands with the sglist size set to a value over 2 Gb.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x3m-47h5-73m3

A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Mojave 10.14.6. An application may be able to read restricted memory.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x3j-vpj2-43h2

The Events Calendar Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.0.2 via deserialization of untrusted input from the 'filters' parameter in widgets. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. The additional presence of a POP chain allows attackers to execute code remotely. In certain configurations, this can be exploitable by lower level users. We confirmed that this plugin installed with Elementor makes it possible for users with contributor-level access and above to exploit this issue.

CVSS3: 9.1
5%
Низкий
больше 1 года назад

Уязвимостей на страницу