Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 375

Количество 314 375

github логотип

GHSA-3xc3-235x-7q23

больше 3 лет назад

HP Linux Imaging and Printing (HPLIP) through 3.12.4 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/hpcupsfilterc_#.bmp, (2) /tmp/hpcupsfilterk_#.bmp, (3) /tmp/hpcups_job#.out, (4) /tmp/hpijs_#####.out, or (5) /tmp/hpps_job#.out temporary file, a different vulnerability than CVE-2011-2722.

EPSS: Низкий
github логотип

GHSA-3xc2-jvpw-rv79

около 1 года назад

CWE-862: Missing Authorization vulnerability exists that could cause unauthorized access when enabled on the network and potentially impacting connected devices.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3x9x-vhqj-cv27

больше 3 лет назад

Magento XML Injection vulnerability in the Widgets Update Layout

CVSS3: 7.2
EPSS: Средний
github логотип

GHSA-3x9w-fg96-5j98

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Fix VP8 stateless decoder smatch warning Fix a smatch static checker warning on vdec_vp8_req_if.c. Which leads to a kernel crash when fb is NULL.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3x9v-m7wh-wv6x

больше 3 лет назад

Use-after-free vulnerability in the Zend engine in PHP before 5.2.15 and 5.3.x before 5.3.4 might allow context-dependent attackers to cause a denial of service (heap memory corruption) or have unspecified other impact via vectors related to use of __set, __get, __isset, and __unset methods on objects accessed by a reference.

EPSS: Низкий
github логотип

GHSA-3x9v-482c-32cf

больше 3 лет назад

In macOS High Sierra before 10.13.5, a privacy issue in the handling of Open Directory records was addressed with improved indexing.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3x9v-3chp-c9cc

3 месяца назад

Use after free in V8 in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-3x9q-xwx4-hhr3

4 месяца назад

Cross-Site Request Forgery (CSRF) vulnerability in Tusko Trush Advanced Custom Fields : CPT Options Pages acf-cpt-options-pages allows Object Injection.This issue affects Advanced Custom Fields : CPT Options Pages: from n/a through <= 2.0.9.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3x9p-x3q5-7j89

больше 3 лет назад

Huawei AppGallery versions before 8.0.4.301 has an arbitrary Javascript running vulnerability. An attacker may set up a malicious network environment and trick user into accessing a malicious web page to bypass the whitelist mechanism, which make the malicious Javascript loaded and run in the smart phone.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3x9p-wvg6-r63g

больше 3 лет назад

U-Office Force UserDefault page has insufficient filtering for special characters in the HTTP header fields. A remote attacker with general user privilege can exploit this vulnerability to inject JavaScript and perform XSS (Stored Cross-Site Scripting) attack.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3x9p-6xxq-5rhj

больше 3 лет назад

The name_parse function in evdns.c in libevent before 2.1.6-beta allows remote attackers to have unspecified impact via vectors involving the label_len variable, which triggers an out-of-bounds stack read.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3x9p-453g-p8w7

больше 3 лет назад

Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the urls parameter at /goform/saveParentControlInfo.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3x9m-x83w-55fq

больше 3 лет назад

The issue was addressed with improved UI handling. This issue is fixed in iOS 14.5 and iPadOS 14.5. A local user may be able to view sensitive information in the app switcher.

EPSS: Низкий
github логотип

GHSA-3x9m-w4fr-frg2

почти 4 года назад

OpenBSD 3.3 and 3.4 does not properly parse Accept and Deny rules without netmasks on big-endian 64-bit platforms such as SPARC64, which may allow remote attackers to bypass access restrictions.

EPSS: Низкий
github логотип

GHSA-3x9m-qxj4-gff3

больше 2 лет назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks Database for Contact Form 7, WPforms, Elementor forms contact-form-entries allows SQL Injection.This issue affects Database for Contact Form 7, WPforms, Elementor forms: from n/a through 1.3.0.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3x9m-3vf5-jwp2

больше 3 лет назад

The "Query Compiler, Rewrite, Optimizer" component in IBM DB2 UDB 9.5 before FP6a allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted query involving certain UNION ALL views, leading to an indefinitely large amount of compilation time.

EPSS: Низкий
github логотип

GHSA-3x9j-wcg8-q9vx

больше 3 лет назад

IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e6e.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3x9j-7f53-54f5

около 1 года назад

This vulnerability exists in the Tinxy mobile app due to storage of logged-in user information in plaintext on the device database. An attacker with physical access to the rooted device could exploit this vulnerability by accessing its database leading to unauthorized access of user information such as username, email address and mobile number.

EPSS: Низкий
github логотип

GHSA-3x9h-3p7m-33m7

больше 3 лет назад

Jenkins SonarQube Plugin Stores Passwords in Cleartext

EPSS: Низкий
github логотип

GHSA-3x9g-xfj5-fq84

почти 2 года назад

Duplicate Advisory: Cross-Site Request Forgery in Gradio

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3xc3-235x-7q23

HP Linux Imaging and Printing (HPLIP) through 3.12.4 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/hpcupsfilterc_#.bmp, (2) /tmp/hpcupsfilterk_#.bmp, (3) /tmp/hpcups_job#.out, (4) /tmp/hpijs_#####.out, or (5) /tmp/hpps_job#.out temporary file, a different vulnerability than CVE-2011-2722.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3xc2-jvpw-rv79

CWE-862: Missing Authorization vulnerability exists that could cause unauthorized access when enabled on the network and potentially impacting connected devices.

CVSS3: 9.8
0%
Низкий
около 1 года назад
github логотип
GHSA-3x9x-vhqj-cv27

Magento XML Injection vulnerability in the Widgets Update Layout

CVSS3: 7.2
11%
Средний
больше 3 лет назад
github логотип
GHSA-3x9w-fg96-5j98

In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Fix VP8 stateless decoder smatch warning Fix a smatch static checker warning on vdec_vp8_req_if.c. Which leads to a kernel crash when fb is NULL.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3x9v-m7wh-wv6x

Use-after-free vulnerability in the Zend engine in PHP before 5.2.15 and 5.3.x before 5.3.4 might allow context-dependent attackers to cause a denial of service (heap memory corruption) or have unspecified other impact via vectors related to use of __set, __get, __isset, and __unset methods on objects accessed by a reference.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3x9v-482c-32cf

In macOS High Sierra before 10.13.5, a privacy issue in the handling of Open Directory records was addressed with improved indexing.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x9v-3chp-c9cc

Use after free in V8 in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 3.1
0%
Низкий
3 месяца назад
github логотип
GHSA-3x9q-xwx4-hhr3

Cross-Site Request Forgery (CSRF) vulnerability in Tusko Trush Advanced Custom Fields : CPT Options Pages acf-cpt-options-pages allows Object Injection.This issue affects Advanced Custom Fields : CPT Options Pages: from n/a through <= 2.0.9.

CVSS3: 5.3
0%
Низкий
4 месяца назад
github логотип
GHSA-3x9p-x3q5-7j89

Huawei AppGallery versions before 8.0.4.301 has an arbitrary Javascript running vulnerability. An attacker may set up a malicious network environment and trick user into accessing a malicious web page to bypass the whitelist mechanism, which make the malicious Javascript loaded and run in the smart phone.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x9p-wvg6-r63g

U-Office Force UserDefault page has insufficient filtering for special characters in the HTTP header fields. A remote attacker with general user privilege can exploit this vulnerability to inject JavaScript and perform XSS (Stored Cross-Site Scripting) attack.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x9p-6xxq-5rhj

The name_parse function in evdns.c in libevent before 2.1.6-beta allows remote attackers to have unspecified impact via vectors involving the label_len variable, which triggers an out-of-bounds stack read.

CVSS3: 9.8
7%
Низкий
больше 3 лет назад
github логотип
GHSA-3x9p-453g-p8w7

Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the urls parameter at /goform/saveParentControlInfo.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x9m-x83w-55fq

The issue was addressed with improved UI handling. This issue is fixed in iOS 14.5 and iPadOS 14.5. A local user may be able to view sensitive information in the app switcher.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x9m-w4fr-frg2

OpenBSD 3.3 and 3.4 does not properly parse Accept and Deny rules without netmasks on big-endian 64-bit platforms such as SPARC64, which may allow remote attackers to bypass access restrictions.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3x9m-qxj4-gff3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks Database for Contact Form 7, WPforms, Elementor forms contact-form-entries allows SQL Injection.This issue affects Database for Contact Form 7, WPforms, Elementor forms: from n/a through 1.3.0.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3x9m-3vf5-jwp2

The "Query Compiler, Rewrite, Optimizer" component in IBM DB2 UDB 9.5 before FP6a allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted query involving certain UNION ALL views, leading to an indefinitely large amount of compilation time.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x9j-wcg8-q9vx

IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e6e.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x9j-7f53-54f5

This vulnerability exists in the Tinxy mobile app due to storage of logged-in user information in plaintext on the device database. An attacker with physical access to the rooted device could exploit this vulnerability by accessing its database leading to unauthorized access of user information such as username, email address and mobile number.

0%
Низкий
около 1 года назад
github логотип
GHSA-3x9h-3p7m-33m7

Jenkins SonarQube Plugin Stores Passwords in Cleartext

5%
Низкий
больше 3 лет назад
github логотип
GHSA-3x9g-xfj5-fq84

Duplicate Advisory: Cross-Site Request Forgery in Gradio

CVSS3: 4.3
почти 2 года назад

Уязвимостей на страницу