Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 305 434

Количество 305 434

github логотип

GHSA-3f93-cwjr-ppr2

больше 3 лет назад

Adobe After Effects version 18.2 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

EPSS: Низкий
github логотип

GHSA-3f93-cvr2-mcrh

11 дней назад

In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10196993; Issue ID: MSV-4805.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3f92-q4c5-7ppr

больше 3 лет назад

Espruino before 1.99 allows attackers to cause a denial of service (application crash) with a user crafted input file via a Buffer Overflow during syntax parsing because of a missing check for stack exhaustion with many '{' characters in jsparse.c.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3f92-pgj5-j64j

больше 3 лет назад

Arbitrary memory write issue in video driver while setting the internal buffers in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

EPSS: Низкий
github логотип

GHSA-3f92-cwf9-rgvq

около 1 года назад

The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.8.11. This is due to plugin not properly restricting what users have access to set the default role on registration forms. This makes it possible for authenticated attackers, with contributor-level access and above, to create a registration form with a custom role that allows them to register as administrators.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3f92-7xfr-mgpx

4 месяца назад

Out-of-bounds write vulnerability in the skia module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3f92-4q6m-m3rv

8 месяцев назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-3f8w-p3m8-mpjx

больше 3 лет назад

VMware Unified Access Gateway (2.5.x, 2.7.x, 2.8.x prior to 2.8.1) and Horizon View (7.x prior to 7.1.0, 6.x prior to 6.2.4) contain a heap buffer-overflow vulnerability which may allow a remote attacker to execute code on the security gateway.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3f8v-r6fv-2xv4

больше 3 лет назад

The accurate-form-data-real-time-form-validation plugin 1.2 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=Accu_Data_WP.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3f8r-x482-8qpg

почти 2 года назад

Sametime is impacted by a failure to invalidate sessions. The application is setting sensitive cookie values in a persistent manner in Sametime Web clients. When this happens, cookie values can remain valid even after a user has closed out their session.  

CVSS3: 3.9
EPSS: Низкий
github логотип

GHSA-3f8r-8g29-hh32

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.760-RC4b allows remote attackers to inject arbitrary web script or HTML via (1) the moderate parameter to the Comments module or (2) htmltext parameter to html/user.php.

EPSS: Низкий
github логотип

GHSA-3f8r-4qwm-r7jf

больше 4 лет назад

Improper Authentication in Apache Traffic Control

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3f8r-37x3-r4g8

больше 3 лет назад

Integer overflow in the HwpApp::CHncSDS_Manager function in Hancom Office HanWord processor, as used in Hwp 2014 VP before 9.1.0.2342, HanWord Viewer 2007 and Viewer 2010 8.5.6.1158, and HwpViewer 2014 VP 9.1.0.2186, allows remote attackers to cause a denial of service (crash) and possibly "influence the program's execution flow" via a document with a large paragraph size, which triggers heap corruption.

EPSS: Низкий
github логотип

GHSA-3f8q-6q6f-h89r

больше 3 лет назад

GLPI before 9.1.5.1 has SQL Injection in the condition rule field, exploitable via front/rulesengine.test.php.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3f8p-g8f8-x3r3

больше 3 лет назад

NetCat 5.01 and earlier allows remote attackers to obtain the installation path via the redirect_url parameter to netshop/post.php.

EPSS: Низкий
github логотип

GHSA-3f8p-77gw-5f5c

больше 3 лет назад

Heap-based buffer overflow in the ecommunity_ecom2str function in bgp_ecommunity.c in bgpd in Quagga before 0.99.19 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code by sending a crafted BGP UPDATE message over IPv4.

EPSS: Средний
github логотип

GHSA-3f8m-mr6h-cch4

больше 1 года назад

A vulnerability, which was classified as critical, was found in MAGESH-K21 Online-College-Event-Hall-Reservation-System 1.0. This affects an unknown part of the file home.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-256953 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3f8j-hxpw-f275

больше 1 года назад

The DOP Shortcodes WordPress plugin through 1.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3f8j-c578-3q4f

больше 3 лет назад

CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=rootpwd, as demonstrated by changing the root password.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3f8j-8ww3-q7v6

больше 3 лет назад

Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3f93-cwjr-ppr2

Adobe After Effects version 18.2 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3f93-cvr2-mcrh

In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10196993; Issue ID: MSV-4805.

CVSS3: 7.8
0%
Низкий
11 дней назад
github логотип
GHSA-3f92-q4c5-7ppr

Espruino before 1.99 allows attackers to cause a denial of service (application crash) with a user crafted input file via a Buffer Overflow during syntax parsing because of a missing check for stack exhaustion with many '{' characters in jsparse.c.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3f92-pgj5-j64j

Arbitrary memory write issue in video driver while setting the internal buffers in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3f92-cwf9-rgvq

The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.8.11. This is due to plugin not properly restricting what users have access to set the default role on registration forms. This makes it possible for authenticated attackers, with contributor-level access and above, to create a registration form with a custom role that allows them to register as administrators.

CVSS3: 8.8
0%
Низкий
около 1 года назад
github логотип
GHSA-3f92-7xfr-mgpx

Out-of-bounds write vulnerability in the skia module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS3: 8.8
0%
Низкий
4 месяца назад
github логотип
GHSA-3f92-4q6m-m3rv

Rejected reason: Not used

8 месяцев назад
github логотип
GHSA-3f8w-p3m8-mpjx

VMware Unified Access Gateway (2.5.x, 2.7.x, 2.8.x prior to 2.8.1) and Horizon View (7.x prior to 7.1.0, 6.x prior to 6.2.4) contain a heap buffer-overflow vulnerability which may allow a remote attacker to execute code on the security gateway.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3f8v-r6fv-2xv4

The accurate-form-data-real-time-form-validation plugin 1.2 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=Accu_Data_WP.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3f8r-x482-8qpg

Sametime is impacted by a failure to invalidate sessions. The application is setting sensitive cookie values in a persistent manner in Sametime Web clients. When this happens, cookie values can remain valid even after a user has closed out their session.  

CVSS3: 3.9
0%
Низкий
почти 2 года назад
github логотип
GHSA-3f8r-8g29-hh32

Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.760-RC4b allows remote attackers to inject arbitrary web script or HTML via (1) the moderate parameter to the Comments module or (2) htmltext parameter to html/user.php.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3f8r-4qwm-r7jf

Improper Authentication in Apache Traffic Control

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3f8r-37x3-r4g8

Integer overflow in the HwpApp::CHncSDS_Manager function in Hancom Office HanWord processor, as used in Hwp 2014 VP before 9.1.0.2342, HanWord Viewer 2007 and Viewer 2010 8.5.6.1158, and HwpViewer 2014 VP 9.1.0.2186, allows remote attackers to cause a denial of service (crash) and possibly "influence the program's execution flow" via a document with a large paragraph size, which triggers heap corruption.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-3f8q-6q6f-h89r

GLPI before 9.1.5.1 has SQL Injection in the condition rule field, exploitable via front/rulesengine.test.php.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3f8p-g8f8-x3r3

NetCat 5.01 and earlier allows remote attackers to obtain the installation path via the redirect_url parameter to netshop/post.php.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3f8p-77gw-5f5c

Heap-based buffer overflow in the ecommunity_ecom2str function in bgp_ecommunity.c in bgpd in Quagga before 0.99.19 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code by sending a crafted BGP UPDATE message over IPv4.

17%
Средний
больше 3 лет назад
github логотип
GHSA-3f8m-mr6h-cch4

A vulnerability, which was classified as critical, was found in MAGESH-K21 Online-College-Event-Hall-Reservation-System 1.0. This affects an unknown part of the file home.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-256953 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-3f8j-hxpw-f275

The DOP Shortcodes WordPress plugin through 1.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVSS3: 5.4
1%
Низкий
больше 1 года назад
github логотип
GHSA-3f8j-c578-3q4f

CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=rootpwd, as demonstrated by changing the root password.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3f8j-8ww3-q7v6

Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад

Уязвимостей на страницу