Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3xg6-wqv2-7vrf

почти 2 года назад

Sante DICOM Viewer Pro DCM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante DICOM Viewer Pro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DCM files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-21125.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3xg6-vwqg-3wvg

больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Training Center allows remote attackers to hijack the authentication of unspecified victims via unknown vectors, aka Bug ID CSCul25567.

EPSS: Низкий
github логотип

GHSA-3xg6-m2m6-mr95

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Correct the migration DMA map direction The SVM DMA device map direction should be set the same as the DMA unmap setting, otherwise the DMA core will report the following warning. Before finialize this solution, there're some discussion on the DMA mapping type(stream-based or coherent) in this KFD migration case, followed by https://lore.kernel.org/all/04d4ab32 -45a1-4b88-86ee-fb0f35a0ca40@amd.com/T/. As there's no dma_sync_single_for_*() in the DMA buffer accessed that because this migration operation should be sync properly and automatically. Give that there's might not be a performance problem in various cache sync policy of DMA sync. Therefore, in order to simplify the DMA direction setting alignment, let's set the DMA map direction as BIDIRECTIONAL. [ 150.834218] WARNING: CPU: 8 PID: 1812 at kernel/dma/debug.c:1028 check_unmap+0x1cc/0x930 [ 150.834225] Modules linked in: amdgpu(OE) amdxcp drm...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3xg6-cw8q-mq66

12 дней назад

Out-of-bounds Read vulnerability in Rinnegatamante lpp-vita.This issue affects lpp-vita: before lpp-vita r6.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3xg5-v3r3-xvcq

почти 4 года назад

In JetBrains TeamCity before 2021.2, health items of pull requests were shown to users who lacked appropriate permissions.

EPSS: Низкий
github логотип

GHSA-3xg5-c7vw-7549

почти 4 года назад

Buffer overflow in Tuniac 090517c allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long URL in a .m3u playlist file.

EPSS: Средний
github логотип

GHSA-3xg5-7r36-7647

больше 3 лет назад

A Denial of Service vulnerability allowed exhausting the system resources in GitLab CE/EE 12.0 and later through 13.0.1

EPSS: Низкий
github логотип

GHSA-3xg5-7p4x-v3wx

около 1 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in brandtoss WP Mailster allows Blind SQL Injection.This issue affects WP Mailster: from n/a through 1.8.16.0.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-3xg5-6c3j-vp8x

больше 4 лет назад

Improper Restriction of XML External Entity Reference in Quokka

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3xg5-4v8v-pf6w

около 1 месяца назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Lekker lekker allows PHP Local File Inclusion.This issue affects Lekker: from n/a through <= 1.8.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3xg5-3w6j-4vf8

больше 3 лет назад

SQL injection vulnerability in archivebot.py in docmarionum1 Slack ArchiveBot (aka slack-archive-bot) before 2018-09-19 allows remote attackers to execute arbitrary SQL commands via the text parameter to cursor.execute().

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3xg4-q8gj-25fp

больше 3 лет назад

In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, sensitive information is transmitted over some web applications in clear text.

EPSS: Низкий
github логотип

GHSA-3xg4-jv8r-rx3h

около 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Camunda Services GmbH bpmn.Io allows Stored XSS.This issue affects bpmn.Io: from n/a through 1.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3xg4-9379-gq7p

около 1 года назад

NULL pointer dereference in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition in the context of the process using the image codec.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3xg4-2966-c7r4

11 месяцев назад

Telesquare TLR-2005KSH 1.1.4 has an Information Disclosure vulnerability when requesting systemutilit.cgi.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3xg3-qffw-vc65

больше 3 лет назад

Improper input validation for some Intel(R) Xeon(R) Processors may allow a privileged user to potentially enable denial of service via local access.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3xg3-cgvq-2xwr

около 1 года назад

Twig security issue where escaping was missing when using null coalesce operator

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3xg2-xc64-45gg

почти 4 года назад

Multiple buffer overflows in EMC AutoStart 5.3.x and 5.4.x before 5.4.3 allow remote attackers to cause a denial of service (agent crash) or possibly execute arbitrary code via crafted packets.

EPSS: Низкий
github логотип

GHSA-3xfx-8jgm-xxv8

больше 2 лет назад

D-LINK DIR-806 1200M11AC wireless router DIR806A1_FW100CNb11 is vulnerable to command injection due to lax filtering of REMOTE_PORT parameters.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3xfw-592p-fx76

9 месяцев назад

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM stack to accept binary Java objects in specific encoding format. On successful exploitation, an authenticated attacker with high privileges could send malicious payload request and receive an outbound DNS request, resulting in deserialization of data in the application. This vulnerability has low impact on confidentiality, integrity and availability of the application.

CVSS3: 3.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3xg6-wqv2-7vrf

Sante DICOM Viewer Pro DCM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante DICOM Viewer Pro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DCM files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-21125.

CVSS3: 7.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-3xg6-vwqg-3wvg

Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Training Center allows remote attackers to hijack the authentication of unspecified victims via unknown vectors, aka Bug ID CSCul25567.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3xg6-m2m6-mr95

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Correct the migration DMA map direction The SVM DMA device map direction should be set the same as the DMA unmap setting, otherwise the DMA core will report the following warning. Before finialize this solution, there're some discussion on the DMA mapping type(stream-based or coherent) in this KFD migration case, followed by https://lore.kernel.org/all/04d4ab32 -45a1-4b88-86ee-fb0f35a0ca40@amd.com/T/. As there's no dma_sync_single_for_*() in the DMA buffer accessed that because this migration operation should be sync properly and automatically. Give that there's might not be a performance problem in various cache sync policy of DMA sync. Therefore, in order to simplify the DMA direction setting alignment, let's set the DMA map direction as BIDIRECTIONAL. [ 150.834218] WARNING: CPU: 8 PID: 1812 at kernel/dma/debug.c:1028 check_unmap+0x1cc/0x930 [ 150.834225] Modules linked in: amdgpu(OE) amdxcp drm...

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-3xg6-cw8q-mq66

Out-of-bounds Read vulnerability in Rinnegatamante lpp-vita.This issue affects lpp-vita: before lpp-vita r6.

CVSS3: 7.8
0%
Низкий
12 дней назад
github логотип
GHSA-3xg5-v3r3-xvcq

In JetBrains TeamCity before 2021.2, health items of pull requests were shown to users who lacked appropriate permissions.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3xg5-c7vw-7549

Buffer overflow in Tuniac 090517c allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long URL in a .m3u playlist file.

26%
Средний
почти 4 года назад
github логотип
GHSA-3xg5-7r36-7647

A Denial of Service vulnerability allowed exhausting the system resources in GitLab CE/EE 12.0 and later through 13.0.1

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3xg5-7p4x-v3wx

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in brandtoss WP Mailster allows Blind SQL Injection.This issue affects WP Mailster: from n/a through 1.8.16.0.

CVSS3: 8.5
0%
Низкий
около 1 года назад
github логотип
GHSA-3xg5-6c3j-vp8x

Improper Restriction of XML External Entity Reference in Quokka

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-3xg5-4v8v-pf6w

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Lekker lekker allows PHP Local File Inclusion.This issue affects Lekker: from n/a through <= 1.8.

CVSS3: 8.1
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3xg5-3w6j-4vf8

SQL injection vulnerability in archivebot.py in docmarionum1 Slack ArchiveBot (aka slack-archive-bot) before 2018-09-19 allows remote attackers to execute arbitrary SQL commands via the text parameter to cursor.execute().

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3xg4-q8gj-25fp

In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, sensitive information is transmitted over some web applications in clear text.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3xg4-jv8r-rx3h

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Camunda Services GmbH bpmn.Io allows Stored XSS.This issue affects bpmn.Io: from n/a through 1.0.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-3xg4-9379-gq7p

NULL pointer dereference in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition in the context of the process using the image codec.

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-3xg4-2966-c7r4

Telesquare TLR-2005KSH 1.1.4 has an Information Disclosure vulnerability when requesting systemutilit.cgi.

CVSS3: 7.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-3xg3-qffw-vc65

Improper input validation for some Intel(R) Xeon(R) Processors may allow a privileged user to potentially enable denial of service via local access.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3xg3-cgvq-2xwr

Twig security issue where escaping was missing when using null coalesce operator

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-3xg2-xc64-45gg

Multiple buffer overflows in EMC AutoStart 5.3.x and 5.4.x before 5.4.3 allow remote attackers to cause a denial of service (agent crash) or possibly execute arbitrary code via crafted packets.

4%
Низкий
почти 4 года назад
github логотип
GHSA-3xfx-8jgm-xxv8

D-LINK DIR-806 1200M11AC wireless router DIR806A1_FW100CNb11 is vulnerable to command injection due to lax filtering of REMOTE_PORT parameters.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3xfw-592p-fx76

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM stack to accept binary Java objects in specific encoding format. On successful exploitation, an authenticated attacker with high privileges could send malicious payload request and receive an outbound DNS request, resulting in deserialization of data in the application. This vulnerability has low impact on confidentiality, integrity and availability of the application.

CVSS3: 3.9
1%
Низкий
9 месяцев назад

Уязвимостей на страницу