Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-42gv-77f4-r3j9

больше 3 лет назад

Shopware SQL Injection

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-42gq-h7xj-33r4

почти 4 года назад

Features file injection vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-42gq-6jpg-qgvv

больше 3 лет назад

yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.

EPSS: Низкий
github логотип

GHSA-42gq-297f-29c4

почти 4 года назад

The cadbd RPC service in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows remote attackers to (1) execute arbitrary code via stack-based buffer overflows in unspecified RPC procedures, and (2) trigger memory corruption related to the use of "handle" RPC arguments as pointers.

EPSS: Средний
github логотип

GHSA-42gp-78x8-7p5j

около 2 лет назад

Improper access control for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via network access.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-42gm-5937-wx6g

больше 3 лет назад

Garage Management System 1.0 is vulnerable to the Remote Code Execution (RCE) due to the lack of filtering from the file upload function. The vulnerability exist during adding parts and from the upload function, the attacker can upload PHP Reverse Shell straight away to gain RCE.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-42gj-vxw3-2cfr

почти 4 года назад

Use-after-free vulnerability in the servePendingRequests function in WebCore in WebKit in Apple Safari 4.0 and 4.0.1 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted HTML document that references a zero-length .js file and the JavaScript reload function. NOTE: some of these details are obtained from third party information.

EPSS: Средний
github логотип

GHSA-42gj-pw36-ccpv

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: i3c: master: Fix miss free init_dyn_addr at i3c_master_put_i3c_addrs() if (dev->boardinfo && dev->boardinfo->init_dyn_addr) ^^^ here check "init_dyn_addr" i3c_bus_set_addr_slot_status(&master->bus, dev->info.dyn_addr, ...) ^^^^ free "dyn_addr" Fix copy/paste error "dyn_addr" by replacing it with "init_dyn_addr".

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-42gj-c2xf-3m98

почти 3 года назад

A stack overfow in SoftMaker Software GmbH FlexiPDF v3.0.3.0 allows attackers to execute arbitrary code after opening a crafted PDF file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-42gh-8g4f-4x6c

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: crypto: sun8i-ss - Fix memory leak of pad It appears there are several failure return paths that don't seem to be free'ing pad. Fix these. Addresses-Coverity: ("Resource leak")

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-42gh-7xp2-q72c

больше 3 лет назад

The SaveUserSettings service in Content Manager in SDL Web 8.5.0 has an XXE Vulnerability that allows reading sensitive files from the system.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-42gg-rrg8-33cj

больше 3 лет назад

The WebTools component on Canon Oce ColorWave 3500 5.1.1.0 devices allows attackers to retrieve stored SMB credentials via the export feature, even though these are intentionally inaccessible in the UI.

EPSS: Низкий
github логотип

GHSA-42gg-98x6-j389

больше 1 года назад

SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_editplayer.php imposes restrictions on edited files, attackers can still bypass these restrictions and write code, allowing authenticated attackers to exploit the vulnerability to execute arbitrary commands and gain system privileges.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-42gc-pq7v-4hjr

около 2 лет назад

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.2.2533 build 20230926 and later QuTS hero h5.1.2.2534 build 20230927 and later QuTScloud c5.1.5.2651 and later

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-42gc-crr9-84r9

больше 3 лет назад

Multiple PHP remote file inclusion vulnerabilities in RobotStats 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter to (1) graph.php and (2) robotstats.inc.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-42g9-595g-jfg4

больше 3 лет назад

A Remote Escalation of Privilege vulnerability in HPE Helion Eucalyptus version 3.3.0 through 4.3.1 was found.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-42g9-27rx-76cj

почти 2 года назад

An issue discovered in Thesycon Software Solutions Gmbh & Co. KG TUSBAudio MSI-based installers before 5.68.0 allows a local attacker to execute arbitrary code via the msiexec.exe repair mode.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-42g8-vhhw-vw3f

больше 3 лет назад

It was found in libtiff 4.4.0rc1 that there is an invalid pointer free operation in TIFFClose() at tif_close.c:131 called by tiffcrop.c:2522 that can cause a program crash and denial of service while processing crafted input.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-42g8-pfx7-f6gp

больше 2 лет назад

A path traversal exists in a specific dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an authenticated remote attacker to delete arbitrary files. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-42g8-62v3-2jg8

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.6. Under a special condition it was possible to access data of an internal repository through a public project fork as an anonymous user.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-42gv-77f4-r3j9

Shopware SQL Injection

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-42gq-h7xj-33r4

Features file injection vulnerability

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-42gq-6jpg-qgvv

yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-42gq-297f-29c4

The cadbd RPC service in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows remote attackers to (1) execute arbitrary code via stack-based buffer overflows in unspecified RPC procedures, and (2) trigger memory corruption related to the use of "handle" RPC arguments as pointers.

25%
Средний
почти 4 года назад
github логотип
GHSA-42gp-78x8-7p5j

Improper access control for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via network access.

CVSS3: 5.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-42gm-5937-wx6g

Garage Management System 1.0 is vulnerable to the Remote Code Execution (RCE) due to the lack of filtering from the file upload function. The vulnerability exist during adding parts and from the upload function, the attacker can upload PHP Reverse Shell straight away to gain RCE.

CVSS3: 8.8
4%
Низкий
больше 3 лет назад
github логотип
GHSA-42gj-vxw3-2cfr

Use-after-free vulnerability in the servePendingRequests function in WebCore in WebKit in Apple Safari 4.0 and 4.0.1 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted HTML document that references a zero-length .js file and the JavaScript reload function. NOTE: some of these details are obtained from third party information.

25%
Средний
почти 4 года назад
github логотип
GHSA-42gj-pw36-ccpv

In the Linux kernel, the following vulnerability has been resolved: i3c: master: Fix miss free init_dyn_addr at i3c_master_put_i3c_addrs() if (dev->boardinfo && dev->boardinfo->init_dyn_addr) ^^^ here check "init_dyn_addr" i3c_bus_set_addr_slot_status(&master->bus, dev->info.dyn_addr, ...) ^^^^ free "dyn_addr" Fix copy/paste error "dyn_addr" by replacing it with "init_dyn_addr".

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-42gj-c2xf-3m98

A stack overfow in SoftMaker Software GmbH FlexiPDF v3.0.3.0 allows attackers to execute arbitrary code after opening a crafted PDF file.

CVSS3: 7.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-42gh-8g4f-4x6c

In the Linux kernel, the following vulnerability has been resolved: crypto: sun8i-ss - Fix memory leak of pad It appears there are several failure return paths that don't seem to be free'ing pad. Fix these. Addresses-Coverity: ("Resource leak")

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-42gh-7xp2-q72c

The SaveUserSettings service in Content Manager in SDL Web 8.5.0 has an XXE Vulnerability that allows reading sensitive files from the system.

CVSS3: 6.5
6%
Низкий
больше 3 лет назад
github логотип
GHSA-42gg-rrg8-33cj

The WebTools component on Canon Oce ColorWave 3500 5.1.1.0 devices allows attackers to retrieve stored SMB credentials via the export feature, even though these are intentionally inaccessible in the UI.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-42gg-98x6-j389

SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_editplayer.php imposes restrictions on edited files, attackers can still bypass these restrictions and write code, allowing authenticated attackers to exploit the vulnerability to execute arbitrary commands and gain system privileges.

CVSS3: 6.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-42gc-pq7v-4hjr

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.2.2533 build 20230926 and later QuTS hero h5.1.2.2534 build 20230927 and later QuTScloud c5.1.5.2651 and later

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-42gc-crr9-84r9

Multiple PHP remote file inclusion vulnerabilities in RobotStats 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter to (1) graph.php and (2) robotstats.inc.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-42g9-595g-jfg4

A Remote Escalation of Privilege vulnerability in HPE Helion Eucalyptus version 3.3.0 through 4.3.1 was found.

CVSS3: 8.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-42g9-27rx-76cj

An issue discovered in Thesycon Software Solutions Gmbh & Co. KG TUSBAudio MSI-based installers before 5.68.0 allows a local attacker to execute arbitrary code via the msiexec.exe repair mode.

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-42g8-vhhw-vw3f

It was found in libtiff 4.4.0rc1 that there is an invalid pointer free operation in TIFFClose() at tif_close.c:131 called by tiffcrop.c:2522 that can cause a program crash and denial of service while processing crafted input.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-42g8-pfx7-f6gp

A path traversal exists in a specific dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an authenticated remote attacker to delete arbitrary files. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

CVSS3: 8.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-42g8-62v3-2jg8

An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.6. Under a special condition it was possible to access data of an internal repository through a public project fork as an anonymous user.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу