Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-42m6-5vm7-fjv2

6 месяцев назад

Mattermost Confluence Plugin has Missing Authorization vulnerability

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-42m5-rf78-8h9x

больше 2 лет назад

Potential Cross-Site Scripting in ArcSight Logger versions prior to 7.3.0

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-42m5-g3g4-g4j9

больше 3 лет назад

The mintToken function of a smart contract implementation for Carrot, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-42m5-3r2p-wr92

3 месяца назад

Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This flaw enables attackers to execute arbitrary code by uploading a specially crafted file from a malicious (S)FTP server.

EPSS: Средний
github логотип

GHSA-42m5-34mg-qrv6

больше 3 лет назад

cPanel before 60.0.25 allows file-overwrite operations during preparation for MySQL upgrades (SEC-161).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-42m4-q6r2-jh92

больше 2 лет назад

An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff in a re-opened Pull Request. To do so, an attacker would need write access to the repository. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in versions 3.6.17, 3.7.15, 3.8.8, 3.9.3, and 3.10.1. This vulnerability was reported via the GitHub Bug Bounty program.

CVSS3: 4.5
EPSS: Низкий
github логотип

GHSA-42m4-gw8j-vjvg

больше 1 года назад

A cross-site scripting (XSS) vulnerability in the component /managers/multiple_freeleech.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the torrents parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-42m3-r5g5-mfwp

больше 1 года назад

In set_secure_reg of sac_handler.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure of 4 bytes of stack memory with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-42m3-f876-5wvj

10 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in GhozyLab Popup Builder allows PHP Local File Inclusion. This issue affects Popup Builder: from n/a through 1.1.35.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-42m3-9326-hpxj

больше 3 лет назад

The BN_sqr implementation in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k does not properly calculate the square of a BIGNUM value, which might make it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors, related to crypto/bn/asm/mips.pl, crypto/bn/asm/x86_64-gcc.c, and crypto/bn/bn_asm.c.

EPSS: Низкий
github логотип

GHSA-42m2-ww59-87vv

почти 4 года назад

Employee Timeclock Software 0.99 places the database password on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.

EPSS: Низкий
github логотип

GHSA-42m2-q6mg-4c6v

почти 4 года назад

Unspecified vulnerability in the reports system in OpenBiblio before 0.6.0 allows attackers to gain privileges via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-42m2-m4h3-qr94

больше 3 лет назад

LibUtils in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 mishandles conversions between Unicode character encodings with different encoding widths, which allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via a crafted file, aka internal bug 29250543.

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-42m2-24p7-q2gq

10 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in riosisgroup Rio Video Gallery allows Stored XSS. This issue affects Rio Video Gallery: from n/a through 2.3.6.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-42jx-j5mh-g84j

больше 1 года назад

Sonos Era 100 SMB2 Message Handling Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos Era 100 smart speakers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of SMB2 messages. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-22459.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-42jw-v43h-79m9

11 месяцев назад

A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been rated as critical. Affected by this issue is some unknown functionality of the component Device Setting Handler. The manipulation leads to improper access control for register interface. The attack needs to be done within the local network. The complexity of an attack is rather high. The exploitation is known to be difficult. It was not possible to identify the current maintainer of the product. It must be assumed that the product is end-of-life.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-42jw-jp69-7hjr

почти 4 года назад

SOAP::Lite 0.50 through 0.52 allows remote attackers to load arbitrary Perl functions by suppling a non-existent function in a script using a SOAP::Lite module, which causes the AUTOLOAD subroutine to trigger.

EPSS: Низкий
github логотип

GHSA-42jw-237g-7j4r

больше 2 лет назад

XNSoft Nconvert 7.136 is vulnerable to Buffer Overflow via a crafted image file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-42jv-6664-mx8r

5 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: wc938x: fix accessing array out of bounds for enum type Accessing enums using integer would result in array out of bounds access on platforms like aarch64 where sizeof(long) is 8 compared to enum size which is 4 bytes. Fix this by using enumerated items instead of integers.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-42jr-fvmf-q363

6 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uvc: Initialize frame-based format color matching descriptor Fix NULL pointer crash in uvcg_framebased_make due to uninitialized color matching descriptor for frame-based format which was added in commit f5e7bdd34aca ("usb: gadget: uvc: Allow creating new color matching descriptors") that added handling for uncompressed and mjpeg format. Crash is seen when userspace configuration (via configfs) does not explicitly define the color matching descriptor. If color_matching is not found, config_group_find_item() returns NULL. The code then jumps to out_put_cm, where it calls config_item_put(color_matching);. If color_matching is NULL, this will dereference a null pointer, leading to a crash. [ 2.746440] Unable to handle kernel NULL pointer dereference at virtual address 000000000000008c [ 2.756273] Mem abort info: [ 2.760080] ESR = 0x0000000096000005 [ 2.764872] EC = 0x25: DABT (current E...

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-42m6-5vm7-fjv2

Mattermost Confluence Plugin has Missing Authorization vulnerability

CVSS3: 3.7
0%
Низкий
6 месяцев назад
github логотип
GHSA-42m5-rf78-8h9x

Potential Cross-Site Scripting in ArcSight Logger versions prior to 7.3.0

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-42m5-g3g4-g4j9

The mintToken function of a smart contract implementation for Carrot, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-42m5-3r2p-wr92

Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This flaw enables attackers to execute arbitrary code by uploading a specially crafted file from a malicious (S)FTP server.

60%
Средний
3 месяца назад
github логотип
GHSA-42m5-34mg-qrv6

cPanel before 60.0.25 allows file-overwrite operations during preparation for MySQL upgrades (SEC-161).

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-42m4-q6r2-jh92

An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff in a re-opened Pull Request. To do so, an attacker would need write access to the repository. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in versions 3.6.17, 3.7.15, 3.8.8, 3.9.3, and 3.10.1. This vulnerability was reported via the GitHub Bug Bounty program.

CVSS3: 4.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-42m4-gw8j-vjvg

A cross-site scripting (XSS) vulnerability in the component /managers/multiple_freeleech.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the torrents parameter.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-42m3-r5g5-mfwp

In set_secure_reg of sac_handler.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure of 4 bytes of stack memory with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-42m3-f876-5wvj

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in GhozyLab Popup Builder allows PHP Local File Inclusion. This issue affects Popup Builder: from n/a through 1.1.35.

CVSS3: 7.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-42m3-9326-hpxj

The BN_sqr implementation in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k does not properly calculate the square of a BIGNUM value, which might make it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors, related to crypto/bn/asm/mips.pl, crypto/bn/asm/x86_64-gcc.c, and crypto/bn/bn_asm.c.

7%
Низкий
больше 3 лет назад
github логотип
GHSA-42m2-ww59-87vv

Employee Timeclock Software 0.99 places the database password on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.

0%
Низкий
почти 4 года назад
github логотип
GHSA-42m2-q6mg-4c6v

Unspecified vulnerability in the reports system in OpenBiblio before 0.6.0 allows attackers to gain privileges via unspecified vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-42m2-m4h3-qr94

LibUtils in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 mishandles conversions between Unicode character encodings with different encoding widths, which allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via a crafted file, aka internal bug 29250543.

CVSS3: 7.8
12%
Средний
больше 3 лет назад
github логотип
GHSA-42m2-24p7-q2gq

Cross-Site Request Forgery (CSRF) vulnerability in riosisgroup Rio Video Gallery allows Stored XSS. This issue affects Rio Video Gallery: from n/a through 2.3.6.

CVSS3: 7.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-42jx-j5mh-g84j

Sonos Era 100 SMB2 Message Handling Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos Era 100 smart speakers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of SMB2 messages. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-22459.

CVSS3: 8.8
3%
Низкий
больше 1 года назад
github логотип
GHSA-42jw-v43h-79m9

A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been rated as critical. Affected by this issue is some unknown functionality of the component Device Setting Handler. The manipulation leads to improper access control for register interface. The attack needs to be done within the local network. The complexity of an attack is rather high. The exploitation is known to be difficult. It was not possible to identify the current maintainer of the product. It must be assumed that the product is end-of-life.

CVSS3: 5
0%
Низкий
11 месяцев назад
github логотип
GHSA-42jw-jp69-7hjr

SOAP::Lite 0.50 through 0.52 allows remote attackers to load arbitrary Perl functions by suppling a non-existent function in a script using a SOAP::Lite module, which causes the AUTOLOAD subroutine to trigger.

1%
Низкий
почти 4 года назад
github логотип
GHSA-42jw-237g-7j4r

XNSoft Nconvert 7.136 is vulnerable to Buffer Overflow via a crafted image file.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-42jv-6664-mx8r

In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: wc938x: fix accessing array out of bounds for enum type Accessing enums using integer would result in array out of bounds access on platforms like aarch64 where sizeof(long) is 8 compared to enum size which is 4 bytes. Fix this by using enumerated items instead of integers.

CVSS3: 7.1
0%
Низкий
5 месяцев назад
github логотип
GHSA-42jr-fvmf-q363

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uvc: Initialize frame-based format color matching descriptor Fix NULL pointer crash in uvcg_framebased_make due to uninitialized color matching descriptor for frame-based format which was added in commit f5e7bdd34aca ("usb: gadget: uvc: Allow creating new color matching descriptors") that added handling for uncompressed and mjpeg format. Crash is seen when userspace configuration (via configfs) does not explicitly define the color matching descriptor. If color_matching is not found, config_group_find_item() returns NULL. The code then jumps to out_put_cm, where it calls config_item_put(color_matching);. If color_matching is NULL, this will dereference a null pointer, leading to a crash. [ 2.746440] Unable to handle kernel NULL pointer dereference at virtual address 000000000000008c [ 2.756273] Mem abort info: [ 2.760080] ESR = 0x0000000096000005 [ 2.764872] EC = 0x25: DABT (current E...

CVSS3: 5.5
0%
Низкий
6 месяцев назад

Уязвимостей на страницу