Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-4332-wp3g-6j7g

почти 4 года назад

SQL injection vulnerability in vir_login.asp in iExpress Property Pro allows remote attackers to execute arbitrary SQL commands via the Password parameter. NOTE: the Username parameter is covered by CVE-2006-6029. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-4332-pv86-8249

4 месяца назад

Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access sensitive data. User interaction is required for triggering this vulnerability.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-432x-cpjh-37f7

больше 3 лет назад

A flaw was found in Privoxy in versions before 3.0.29. Memory leaks in the show-status CGI handler when memory allocations fail can lead to a system crash.

EPSS: Низкий
github логотип

GHSA-432w-hgxc-f9cx

больше 3 лет назад

The Management Console in WSO2 Application Server 5.3.0, WSO2 Business Process Server 3.6.0, WSO2 Business Rules Server 2.2.0, WSO2 Complex Event Processor 4.2.0, WSO2 Dashboard Server 2.0.0, WSO2 Data Analytics Server 3.1.0, WSO2 Data Services Server 3.5.1, and WSO2 Machine Learner 1.2.0 is affected by stored XSS.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-432v-2wp5-hhr2

больше 3 лет назад

Graphics in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to the way it handles objects in memory, aka "Win32k Elevation of Privilege Vulnerability".

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-432v-2h2g-hp33

8 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OceanWP Ocean Extra allows Stored XSS.This issue affects Ocean Extra: from n/a through 2.4.8.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-432r-vhq4-vhjx

почти 4 года назад

Red Hat Linux 7.1 sets insecure permissions on swap files created during installation, which can allow a local attacker to gain additional privileges by reading sensitive information from the swap file, such as passwords.

EPSS: Низкий
github логотип

GHSA-432r-m3pj-m766

больше 3 лет назад

The GetPrinterURLList2 method in the ActiveX control in Novell iPrint Client before 5.78 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2008-2431 and CVE-2008-2436.

EPSS: Средний
github логотип

GHSA-432r-553m-gq3p

больше 3 лет назад

Multiple buffer overflows in (1) internal/XMLReader.cpp, (2) util/XMLURL.cpp, and (3) util/XMLUri.cpp in the XML Parser library in Apache Xerces-C before 3.1.3 allow remote attackers to cause a denial of service (segmentation fault or memory corruption) or possibly execute arbitrary code via a crafted document.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-432q-7x98-83cg

больше 3 лет назад

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-432q-3g9r-5rr6

почти 4 года назад

Multiple buffer overflows in WS_FTP Server 5.03 2004.10.14 allow remote attackers to cause a denial of service (service crash) via long (1) SITE, (2) XMKD, (3) MKD, and (4) RNFR commands.

EPSS: Средний
github логотип

GHSA-432p-g7rx-g388

больше 3 лет назад

In Apache Fineract 0.4.0-incubating, 0.5.0-incubating, and 0.6.0-incubating, an authenticated user with client/loan/center/staff/group read permissions is able to inject malicious SQL into SELECT queries. The 'sqlSearch' parameter on a number of endpoints is not sanitized and appended directly to the query.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-432m-fhgv-3568

почти 4 года назад

PHP remote file inclusion vulnerability in pda_projects.php in WebDynamite ProjectButler 1.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the offset parameter.

EPSS: Низкий
github логотип

GHSA-432m-34f7-gx5j

больше 3 лет назад

There is a Credentials Management Errors Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect service confidentiality.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-432m-25cj-wjgv

больше 3 лет назад

Use After Free in GitHub repository vim/vim prior to 9.0.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-432j-m9p2-95fc

больше 3 лет назад

Google Chrome before 15.0.874.102 does not properly handle history data, which allows user-assisted remote attackers to spoof the URL bar via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-432j-87hp-h33w

около 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Woopy Plugins SmartLink Dynamic URLs allows Stored XSS.This issue affects SmartLink Dynamic URLs: from n/a through 1.1.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-432j-4fw9-2g6f

почти 7 лет назад

libsbml downloads Resources over HTTP

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-432h-j3jm-6982

около 2 месяцев назад

A Reflected Cross-Site Scripting (XSS) vulnerability in yohanawi Hotel Management System (commit 87e004a) allows a remote attacker to execute arbitrary web script via the 'error' parameter in pages/room.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-432h-4cw6-prpw

больше 3 лет назад

In ng_pkt in transports/smart_pkt.c in libgit2 before 0.26.6 and 0.27.x before 0.27.4, a remote attacker can send a crafted smart-protocol "ng" packet that lacks a '\0' byte to trigger an out-of-bounds read that leads to DoS.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4332-wp3g-6j7g

SQL injection vulnerability in vir_login.asp in iExpress Property Pro allows remote attackers to execute arbitrary SQL commands via the Password parameter. NOTE: the Username parameter is covered by CVE-2006-6029. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

0%
Низкий
почти 4 года назад
github логотип
GHSA-4332-pv86-8249

Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access sensitive data. User interaction is required for triggering this vulnerability.

CVSS3: 7.1
0%
Низкий
4 месяца назад
github логотип
GHSA-432x-cpjh-37f7

A flaw was found in Privoxy in versions before 3.0.29. Memory leaks in the show-status CGI handler when memory allocations fail can lead to a system crash.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-432w-hgxc-f9cx

The Management Console in WSO2 Application Server 5.3.0, WSO2 Business Process Server 3.6.0, WSO2 Business Rules Server 2.2.0, WSO2 Complex Event Processor 4.2.0, WSO2 Dashboard Server 2.0.0, WSO2 Data Analytics Server 3.1.0, WSO2 Data Services Server 3.5.1, and WSO2 Machine Learner 1.2.0 is affected by stored XSS.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-432v-2wp5-hhr2

Graphics in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to the way it handles objects in memory, aka "Win32k Elevation of Privilege Vulnerability".

CVSS3: 7
1%
Низкий
больше 3 лет назад
github логотип
GHSA-432v-2h2g-hp33

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OceanWP Ocean Extra allows Stored XSS.This issue affects Ocean Extra: from n/a through 2.4.8.

CVSS3: 6.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-432r-vhq4-vhjx

Red Hat Linux 7.1 sets insecure permissions on swap files created during installation, which can allow a local attacker to gain additional privileges by reading sensitive information from the swap file, such as passwords.

0%
Низкий
почти 4 года назад
github логотип
GHSA-432r-m3pj-m766

The GetPrinterURLList2 method in the ActiveX control in Novell iPrint Client before 5.78 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2008-2431 and CVE-2008-2436.

15%
Средний
больше 3 лет назад
github логотип
GHSA-432r-553m-gq3p

Multiple buffer overflows in (1) internal/XMLReader.cpp, (2) util/XMLURL.cpp, and (3) util/XMLUri.cpp in the XML Parser library in Apache Xerces-C before 3.1.3 allow remote attackers to cause a denial of service (segmentation fault or memory corruption) or possibly execute arbitrary code via a crafted document.

CVSS3: 9.8
23%
Средний
больше 3 лет назад
github логотип
GHSA-432q-7x98-83cg

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 7.2
1%
Низкий
больше 3 лет назад
github логотип
GHSA-432q-3g9r-5rr6

Multiple buffer overflows in WS_FTP Server 5.03 2004.10.14 allow remote attackers to cause a denial of service (service crash) via long (1) SITE, (2) XMKD, (3) MKD, and (4) RNFR commands.

51%
Средний
почти 4 года назад
github логотип
GHSA-432p-g7rx-g388

In Apache Fineract 0.4.0-incubating, 0.5.0-incubating, and 0.6.0-incubating, an authenticated user with client/loan/center/staff/group read permissions is able to inject malicious SQL into SELECT queries. The 'sqlSearch' parameter on a number of endpoints is not sanitized and appended directly to the query.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-432m-fhgv-3568

PHP remote file inclusion vulnerability in pda_projects.php in WebDynamite ProjectButler 1.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the offset parameter.

3%
Низкий
почти 4 года назад
github логотип
GHSA-432m-34f7-gx5j

There is a Credentials Management Errors Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect service confidentiality.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-432m-25cj-wjgv

Use After Free in GitHub repository vim/vim prior to 9.0.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-432j-m9p2-95fc

Google Chrome before 15.0.874.102 does not properly handle history data, which allows user-assisted remote attackers to spoof the URL bar via unspecified vectors.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-432j-87hp-h33w

Cross-Site Request Forgery (CSRF) vulnerability in Woopy Plugins SmartLink Dynamic URLs allows Stored XSS.This issue affects SmartLink Dynamic URLs: from n/a through 1.1.0.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-432j-4fw9-2g6f

libsbml downloads Resources over HTTP

CVSS3: 8.1
1%
Низкий
почти 7 лет назад
github логотип
GHSA-432h-j3jm-6982

A Reflected Cross-Site Scripting (XSS) vulnerability in yohanawi Hotel Management System (commit 87e004a) allows a remote attacker to execute arbitrary web script via the 'error' parameter in pages/room.php.

CVSS3: 6.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-432h-4cw6-prpw

In ng_pkt in transports/smart_pkt.c in libgit2 before 0.26.6 and 0.27.x before 0.27.4, a remote attacker can send a crafted smart-protocol "ng" packet that lacks a '\0' byte to trigger an out-of-bounds read that leads to DoS.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу