Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-42jr-6c9q-58g2

2 месяца назад

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-42jr-443g-g58q

почти 4 года назад

nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to entries in the passwd map, which allows remote attackers to obtain the encrypted passwords of NIS accounts by calling the getpwnam function.

EPSS: Низкий
github логотип

GHSA-42jr-32cj-2c5c

больше 3 лет назад

Directory traversal vulnerability in the setuid root helper binary in S-nail (later S-mailx) before 14.8.16 allows local users to write to arbitrary files and consequently gain root privileges via a .. (dot dot) in the randstr argument.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-42jq-pvpx-7m8x

больше 3 лет назад

An issue was identified in GitLab EE 13.4 or later which leaked internal IP address via error messages.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-42jq-cg85-cj5g

10 месяцев назад

A vulnerability has been found in AMTT Hotel Broadband Operation System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /manager/system/nlog_down.php. The manipulation of the argument ProtocolType leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-42jq-8pvg-2649

около 4 лет назад

An unspecified version of tripexpress is affected by a path manipulation vulnerability in file system/helpers/dompdf/load_font.php. The variable src is coming from $_SERVER["argv"] then there is a path manipulation vulnerability.

EPSS: Низкий
github логотип

GHSA-42jq-7c3c-8rc3

больше 3 лет назад

Buffer overflow in FontParser in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows remote attackers to obtain sensitive information from process memory via a crafted font file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-42jp-h7gj-p5q8

почти 4 года назад

Multiple unspecified vulnerabilities in Robin Rawson-Tetley Animal Shelter Manager (ASM) before 2.2.2 have unknown impact and attack vectors, related to "various areas where security was missing."

EPSS: Низкий
github логотип

GHSA-42jp-5v4c-jj6v

больше 3 лет назад

A vulnerability classified as problematic has been found in AXIS P1204, P3225, P3367, M3045, M3005 and M3007. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. It is recommended to upgrade the affected component.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-42jm-wj7w-hx2w

больше 3 лет назад

An issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a stack-based buffer over-read in the function InflateDimensions() in inflate.c when called from ReadNextCell in mat5.c.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-42jm-px5r-4qxq

около 1 года назад

IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, and 6.1.0.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot dot" sequences (/.../) to view arbitrary files on the system.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-42jm-j2g5-xq6f

6 месяцев назад

An issue was discovered in TitanHQ SpamTitan Email Security Gateway 8.00.x before 8.00.101 and 8.01.x before 8.01.14. The file quarantine.php within the SpamTitan interface allows unauthenticated users to trigger account-level actions using a crafted GET request. Notably, when a non-existent email address is provided as part of the email parameter, SpamTitan will automatically create a user record and associate quarantine settings with it - all without requiring authentication.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-42jm-9m65-8ggq

больше 3 лет назад

The IOAcceleratorFamily2 interface in IOAcceleratorFamily in Apple OS X before 10.11.3 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-42jj-9j7q-98jv

почти 2 года назад

Script injection vulnerability in the email module.Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-42jj-4cc5-rm9v

9 месяцев назад

A vulnerability, which was classified as problematic, was found in SourceCodester Online Student Clearance System 1.0. This affects an unknown part. The manipulation leads to exposure of information through directory listing. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-42jh-6qqc-g99m

больше 1 года назад

An issue in GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, XE3000/X3000 v4, and B2200/MV1000/MV1000W/USB150/N300/SF1200 v3.216 allows attackers to intercept communications via a man-in-the-middle attack when DDNS clients are reporting data to the server.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-42jh-4jqc-82pf

почти 4 года назад

PHP remote file inclusion vulnerability in module.php for ezContents allows remote attackers to execute arbitrary PHP code by modifying the link parameter to reference a URL on a remote web server that contains the code.

EPSS: Низкий
github логотип

GHSA-42jg-f4qq-3gvm

больше 3 лет назад

An issue was discovered in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8. An Integer Overflow leads to a heap-based buffer over-read in exif_thumbnail_extract of exif.c.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-42jf-jcvf-jgrw

больше 3 лет назад

An improper link resolution vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local attacker to read files on the system with elevated privileges when generating a tech support file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-42jf-hmvx-6vm5

больше 3 лет назад

Vulnerability in the Hospitality WebSuite8 Cloud Service component of Oracle Hospitality Applications (subcomponent: General). Supported versions that are affected are 8.9.6 and 8.10.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Hospitality WebSuite8 Cloud Service. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Hospitality WebSuite8 Cloud Service accessible data as well as unauthorized update, insert or delete access to some of Hospitality WebSuite8 Cloud Service accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Hospitality WebSuite8 Cloud Service. CVSS 3.0 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L).

CVSS3: 7.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-42jr-6c9q-58g2

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVSS3: 7
0%
Низкий
2 месяца назад
github логотип
GHSA-42jr-443g-g58q

nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to entries in the passwd map, which allows remote attackers to obtain the encrypted passwords of NIS accounts by calling the getpwnam function.

2%
Низкий
почти 4 года назад
github логотип
GHSA-42jr-32cj-2c5c

Directory traversal vulnerability in the setuid root helper binary in S-nail (later S-mailx) before 14.8.16 allows local users to write to arbitrary files and consequently gain root privileges via a .. (dot dot) in the randstr argument.

CVSS3: 7
1%
Низкий
больше 3 лет назад
github логотип
GHSA-42jq-pvpx-7m8x

An issue was identified in GitLab EE 13.4 or later which leaked internal IP address via error messages.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-42jq-cg85-cj5g

A vulnerability has been found in AMTT Hotel Broadband Operation System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /manager/system/nlog_down.php. The manipulation of the argument ProtocolType leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.7
1%
Низкий
10 месяцев назад
github логотип
GHSA-42jq-8pvg-2649

An unspecified version of tripexpress is affected by a path manipulation vulnerability in file system/helpers/dompdf/load_font.php. The variable src is coming from $_SERVER["argv"] then there is a path manipulation vulnerability.

0%
Низкий
около 4 лет назад
github логотип
GHSA-42jq-7c3c-8rc3

Buffer overflow in FontParser in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows remote attackers to obtain sensitive information from process memory via a crafted font file.

CVSS3: 6.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-42jp-h7gj-p5q8

Multiple unspecified vulnerabilities in Robin Rawson-Tetley Animal Shelter Manager (ASM) before 2.2.2 have unknown impact and attack vectors, related to "various areas where security was missing."

0%
Низкий
почти 4 года назад
github логотип
GHSA-42jp-5v4c-jj6v

A vulnerability classified as problematic has been found in AXIS P1204, P3225, P3367, M3045, M3005 and M3007. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. It is recommended to upgrade the affected component.

CVSS3: 8.8
больше 3 лет назад
github логотип
GHSA-42jm-wj7w-hx2w

An issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a stack-based buffer over-read in the function InflateDimensions() in inflate.c when called from ReadNextCell in mat5.c.

CVSS3: 9.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-42jm-px5r-4qxq

IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, and 6.1.0.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot dot" sequences (/.../) to view arbitrary files on the system.

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-42jm-j2g5-xq6f

An issue was discovered in TitanHQ SpamTitan Email Security Gateway 8.00.x before 8.00.101 and 8.01.x before 8.01.14. The file quarantine.php within the SpamTitan interface allows unauthenticated users to trigger account-level actions using a crafted GET request. Notably, when a non-existent email address is provided as part of the email parameter, SpamTitan will automatically create a user record and associate quarantine settings with it - all without requiring authentication.

CVSS3: 9.1
0%
Низкий
6 месяцев назад
github логотип
GHSA-42jm-9m65-8ggq

The IOAcceleratorFamily2 interface in IOAcceleratorFamily in Apple OS X before 10.11.3 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.

CVSS3: 7.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-42jj-9j7q-98jv

Script injection vulnerability in the email module.Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.

CVSS3: 9.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-42jj-4cc5-rm9v

A vulnerability, which was classified as problematic, was found in SourceCodester Online Student Clearance System 1.0. This affects an unknown part. The manipulation leads to exposure of information through directory listing. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-42jh-6qqc-g99m

An issue in GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, XE3000/X3000 v4, and B2200/MV1000/MV1000W/USB150/N300/SF1200 v3.216 allows attackers to intercept communications via a man-in-the-middle attack when DDNS clients are reporting data to the server.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-42jh-4jqc-82pf

PHP remote file inclusion vulnerability in module.php for ezContents allows remote attackers to execute arbitrary PHP code by modifying the link parameter to reference a URL on a remote web server that contains the code.

2%
Низкий
почти 4 года назад
github логотип
GHSA-42jg-f4qq-3gvm

An issue was discovered in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8. An Integer Overflow leads to a heap-based buffer over-read in exif_thumbnail_extract of exif.c.

CVSS3: 7.5
20%
Средний
больше 3 лет назад
github логотип
GHSA-42jf-jcvf-jgrw

An improper link resolution vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local attacker to read files on the system with elevated privileges when generating a tech support file.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-42jf-hmvx-6vm5

Vulnerability in the Hospitality WebSuite8 Cloud Service component of Oracle Hospitality Applications (subcomponent: General). Supported versions that are affected are 8.9.6 and 8.10.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Hospitality WebSuite8 Cloud Service. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Hospitality WebSuite8 Cloud Service accessible data as well as unauthorized update, insert or delete access to some of Hospitality WebSuite8 Cloud Service accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Hospitality WebSuite8 Cloud Service. CVSS 3.0 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L).

CVSS3: 7.6
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу