Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-3w2w-5pxh-222c

больше 3 лет назад

dirapi.dll in Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2581, CVE-2010-4085, CVE-2010-4086, and CVE-2010-4088.

EPSS: Низкий
github логотип

GHSA-3w2w-4v6h-c6q9

больше 3 лет назад

The xfs_fs_geometry function in fs/xfs/xfs_fsops.c in the Linux kernel before 2.6.38-rc6-git3 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an FSGEOMETRY_V1 ioctl call.

EPSS: Низкий
github логотип

GHSA-3w2v-v5mv-qqrj

больше 2 лет назад

A command injection vulnerability exists in the download and convert report feature of the ScienceLogic SL1 that takes unsanitized user?controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3w2v-f8x7-qc92

около 1 года назад

Missing Authorization vulnerability in rtCamp rtMedia for WordPress, BuddyPress and bbPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects rtMedia for WordPress, BuddyPress and bbPress: from n/a through 4.6.14.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3w2m-22gp-wc5v

почти 4 года назад

phpProfiles before 2.1.1 uses world writable permissions for certain profile files and directories, which allows local users to modify or delete files, related to (1) users/include/do_makeprofile.inc.php and (2) users/include/copy.inc.php.

EPSS: Низкий
github логотип

GHSA-3w2j-mvmp-4vx3

почти 2 года назад

Transient DOS while processing DL NAS Transport message, as specified in 3GPP 24.501 v16.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3w2j-jf2v-w2v3

больше 3 лет назад

The vivid_fb_ioctl function in drivers/media/platform/vivid/vivid-osd.c in the Linux kernel through 4.3.3 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory via a crafted application.

CVSS3: 2.3
EPSS: Низкий
github логотип

GHSA-3w2h-f87x-m6vp

больше 3 лет назад

Memory safety bugs present in Firefox 60 and Firefox ESR 60. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, and Firefox < 61.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3w2h-8364-7v9m

9 месяцев назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

EPSS: Низкий
github логотип

GHSA-3w2h-6gvg-jj2v

больше 1 года назад

Use after free in Extensions in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3w2f-j9r3-9h89

больше 2 лет назад

Microsoft Outlook Security Feature Bypass Vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3w2f-3jp8-6mj6

больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in Vesta Control Panel before 0.9.8-14 allows remote attackers to hijack the authentication of arbitrary users.

EPSS: Низкий
github логотип

GHSA-3w2c-34cm-pfvc

больше 2 лет назад

A vulnerability has been found in Simple Design Daily Journal 1.012.GP.B on Android and classified as problematic. Affected by this vulnerability is an unknown functionality of the component SQLite Database. The manipulation leads to cleartext storage in a file or on disk. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-229819.

CVSS3: 2.3
EPSS: Низкий
github логотип

GHSA-3w29-9x4p-299p

больше 1 года назад

Adobe Experience Manager versions 6.5.20 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser session. Exploitation of this issue typically requires user interaction, such as convincing a user to click on a specially crafted link or to submit a malicious form.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3w29-4qp5-cwmc

больше 3 лет назад

Use after free in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

EPSS: Низкий
github логотип

GHSA-3w28-qcgr-pffg

почти 4 года назад

Cocktail 3.5.4 and possibly earlier in Mac OS X passes the administrative password on the command line to sudo in cleartext, which allows local users to gain sensitive information by running listing processes.

EPSS: Низкий
github логотип

GHSA-3w28-fqx3-7jv2

больше 3 лет назад

In Cloud Foundry Foundation Credhub-release version 1.1.0, access control lists (ACLs) enforce whether an authenticated user can perform an operation on a credential. For installations using ACLs, the ACL was bypassed for the CredHub interpolate endpoint, allowing authenticated applications to view any credential within the CredHub installation.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3w28-c3v9-22gp

3 месяца назад

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege (when OceReducedNeighborReport is disabled). User interaction is not needed for exploitation. Patch ID: WCNCR00441511; Issue ID: MSV-4140.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3w28-7ffm-4xcg

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Phorum before 5.2.16 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3w26-vfvh-2v33

почти 2 года назад

A potential memory leakage vulnerability was reported in some Lenovo Notebook products that may allow a local attacker with elevated privileges to write to NVRAM variables.

CVSS3: 6.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3w2w-5pxh-222c

dirapi.dll in Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2581, CVE-2010-4085, CVE-2010-4086, and CVE-2010-4088.

6%
Низкий
больше 3 лет назад
github логотип
GHSA-3w2w-4v6h-c6q9

The xfs_fs_geometry function in fs/xfs/xfs_fsops.c in the Linux kernel before 2.6.38-rc6-git3 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an FSGEOMETRY_V1 ioctl call.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3w2v-v5mv-qqrj

A command injection vulnerability exists in the download and convert report feature of the ScienceLogic SL1 that takes unsanitized user?controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3w2v-f8x7-qc92

Missing Authorization vulnerability in rtCamp rtMedia for WordPress, BuddyPress and bbPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects rtMedia for WordPress, BuddyPress and bbPress: from n/a through 4.6.14.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-3w2m-22gp-wc5v

phpProfiles before 2.1.1 uses world writable permissions for certain profile files and directories, which allows local users to modify or delete files, related to (1) users/include/do_makeprofile.inc.php and (2) users/include/copy.inc.php.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3w2j-mvmp-4vx3

Transient DOS while processing DL NAS Transport message, as specified in 3GPP 24.501 v16.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-3w2j-jf2v-w2v3

The vivid_fb_ioctl function in drivers/media/platform/vivid/vivid-osd.c in the Linux kernel through 4.3.3 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory via a crafted application.

CVSS3: 2.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3w2h-f87x-m6vp

Memory safety bugs present in Firefox 60 and Firefox ESR 60. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, and Firefox < 61.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3w2h-8364-7v9m

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

9 месяцев назад
github логотип
GHSA-3w2h-6gvg-jj2v

Use after free in Extensions in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-3w2f-j9r3-9h89

Microsoft Outlook Security Feature Bypass Vulnerability

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3w2f-3jp8-6mj6

Cross-site request forgery (CSRF) vulnerability in Vesta Control Panel before 0.9.8-14 allows remote attackers to hijack the authentication of arbitrary users.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3w2c-34cm-pfvc

A vulnerability has been found in Simple Design Daily Journal 1.012.GP.B on Android and classified as problematic. Affected by this vulnerability is an unknown functionality of the component SQLite Database. The manipulation leads to cleartext storage in a file or on disk. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-229819.

CVSS3: 2.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3w29-9x4p-299p

Adobe Experience Manager versions 6.5.20 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser session. Exploitation of this issue typically requires user interaction, such as convincing a user to click on a specially crafted link or to submit a malicious form.

CVSS3: 5.4
2%
Низкий
больше 1 года назад
github логотип
GHSA-3w29-4qp5-cwmc

Use after free in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

4%
Низкий
больше 3 лет назад
github логотип
GHSA-3w28-qcgr-pffg

Cocktail 3.5.4 and possibly earlier in Mac OS X passes the administrative password on the command line to sudo in cleartext, which allows local users to gain sensitive information by running listing processes.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3w28-fqx3-7jv2

In Cloud Foundry Foundation Credhub-release version 1.1.0, access control lists (ACLs) enforce whether an authenticated user can perform an operation on a credential. For installations using ACLs, the ACL was bypassed for the CredHub interpolate endpoint, allowing authenticated applications to view any credential within the CredHub installation.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3w28-c3v9-22gp

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege (when OceReducedNeighborReport is disabled). User interaction is not needed for exploitation. Patch ID: WCNCR00441511; Issue ID: MSV-4140.

CVSS3: 5.3
0%
Низкий
3 месяца назад
github логотип
GHSA-3w28-7ffm-4xcg

Cross-site scripting (XSS) vulnerability in Phorum before 5.2.16 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3w26-vfvh-2v33

A potential memory leakage vulnerability was reported in some Lenovo Notebook products that may allow a local attacker with elevated privileges to write to NVRAM variables.

CVSS3: 6.7
0%
Низкий
почти 2 года назад

Уязвимостей на страницу