Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 290 844

Количество 290 844

github логотип

GHSA-2g5f-4p47-mx3m

5 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: nvmem: core: fix cleanup after dev_set_name() If dev_set_name() fails, we leak nvmem->wp_gpio as the cleanup does not put this. While a minimal fix for this would be to add the gpiod_put() call, we can do better if we split device_register(), and use the tested nvmem_release() cleanup code by initialising the device early, and putting the device. This results in a slightly larger fix, but results in clear code. Note: this patch depends on "nvmem: core: initialise nvmem->id early" and "nvmem: core: remove nvmem_config wp_gpio". [Srini: Fixed subject line and error code handing with wp_gpio while applying.]

EPSS: Низкий
github логотип

GHSA-2g5c-228j-p52x

почти 3 года назад

XWiki Platform Applications Tag and XWiki Platform Tag UI vulnerable to Eval Injection

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-2g59-pjjw-j55p

больше 3 лет назад

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, an authenticated attacker (via the admin web interface) can send a specially crafted message resulting in a stack buffer overflow.

CVSS3: 7.2
EPSS: Средний
github логотип

GHSA-2g58-j9wc-pg3h

больше 3 лет назад

The Passcode Lock implementation in Apple iOS before 6.0.1 does not properly manage the lock state, which allows physically proximate attackers to bypass an intended passcode requirement and access Passbook passes via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2g58-2x39-qh45

больше 1 года назад

OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2g58-2r94-f674

около 1 года назад

A vulnerability classified as problematic was found in itsourcecode Online Blood Bank Management System 1.0. This vulnerability affects unknown code of the file signup.php of the component User Registration Handler. The manipulation of the argument user leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273232.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2g56-7jv7-wxxq

больше 3 лет назад

Missing Cryptographic Step in OWASP Enterprise Security API for Java

EPSS: Низкий
github логотип

GHSA-2g55-8535-gp6f

больше 1 года назад

Splicecom Maximiser Soft PBX v1.5 and before was discovered to contain a cross-site scripting (XSS) vulnerability via the CLIENT_NAME and DEVICE_GUID fields in the login component.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2g55-7wqw-h2c5

больше 3 лет назад

Heap-based buffer overflow in the __zzip_get32 function in fetch.c in zziplib 0.13.62, 0.13.61, 0.13.60, 0.13.59, 0.13.58, 0.13.57, 0.13.56 allows remote attackers to cause a denial of service (crash) via a crafted ZIP file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2g54-42rw-p43x

больше 3 лет назад

The specific function in ASUS BMC’s firmware Web management page (Modify user’s information function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

EPSS: Низкий
github логотип

GHSA-2g53-pmw3-ccp9

больше 3 лет назад

CheckSec Canopy 3.x before 3.0.7 has stored XSS via the Login Page Disclaimer, allowing attacks by low-privileged users against higher-privileged users.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2g53-3pj8-qvxv

больше 3 лет назад

Use-after-free vulnerability in the path_openat function in fs/namei.c in the Linux kernel 3.x and 4.x before 4.0.4 allows local users to cause a denial of service or possibly have unspecified other impact via O_TMPFILE filesystem operations that leverage a duplicate cleanup operation.

EPSS: Низкий
github логотип

GHSA-2g52-qw8q-wfr9

8 месяцев назад

Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed. This vulnerability affects Firefox < 134.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-2g4x-xxrm-h5mw

больше 3 лет назад

Dell Encryption (formerly Dell Data Protection | Encryption) v10.1.0 and earlier contain an information disclosure vulnerability. A malicious user with physical access to the machine could potentially exploit this vulnerability to access the unencrypted RegBack folder that contains back-ups of sensitive system files.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2g4x-p9qv-phcg

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Gallery 3 before 3.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) movie title to modules/gallery/controllers/movies.php or (2) key variable to modules/gallery/views/error_admin.html.php.

EPSS: Низкий
github логотип

GHSA-2g4x-fv7q-8jrf

больше 3 лет назад

Insufficient data validation in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.

EPSS: Низкий
github логотип

GHSA-2g4x-3mj5-gvj6

больше 3 лет назад

Multiple buffer overflows in the Broderbund Expressit 3DGreetings Player ActiveX control could allow remote attackers to execute arbitrary code via unspecified vectors.

EPSS: Средний
github логотип

GHSA-2g4w-xqhx-j2x8

больше 3 лет назад

OpenSource Moddable v10.5.0 was discovered to contain a stack overflow via the component /moddable/xs/sources/xsScript.c.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2g4w-fv9w-h3mm

больше 3 лет назад

SQL injection vulnerability in ArrayOS before AG 9.4.0.135, when the portal bookmark function is enabled, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2g4w-cqhh-m9w9

больше 1 года назад

VMware SD-WAN Edge contains a missing authentication and protection mechanism vulnerability. A malicious actor with physical access to the SD-WAN Edge appliance during activation can potentially exploit this vulnerability to access the BIOS configuration. In addition, the malicious actor may be able to exploit the default boot priority configured.

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2g5f-4p47-mx3m

In the Linux kernel, the following vulnerability has been resolved: nvmem: core: fix cleanup after dev_set_name() If dev_set_name() fails, we leak nvmem->wp_gpio as the cleanup does not put this. While a minimal fix for this would be to add the gpiod_put() call, we can do better if we split device_register(), and use the tested nvmem_release() cleanup code by initialising the device early, and putting the device. This results in a slightly larger fix, but results in clear code. Note: this patch depends on "nvmem: core: initialise nvmem->id early" and "nvmem: core: remove nvmem_config wp_gpio". [Srini: Fixed subject line and error code handing with wp_gpio while applying.]

0%
Низкий
5 месяцев назад
github логотип
GHSA-2g5c-228j-p52x

XWiki Platform Applications Tag and XWiki Platform Tag UI vulnerable to Eval Injection

CVSS3: 9.9
8%
Низкий
почти 3 года назад
github логотип
GHSA-2g59-pjjw-j55p

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, an authenticated attacker (via the admin web interface) can send a specially crafted message resulting in a stack buffer overflow.

CVSS3: 7.2
43%
Средний
больше 3 лет назад
github логотип
GHSA-2g58-j9wc-pg3h

The Passcode Lock implementation in Apple iOS before 6.0.1 does not properly manage the lock state, which allows physically proximate attackers to bypass an intended passcode requirement and access Passbook passes via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2g58-2x39-qh45

OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function.

CVSS3: 9.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2g58-2r94-f674

A vulnerability classified as problematic was found in itsourcecode Online Blood Bank Management System 1.0. This vulnerability affects unknown code of the file signup.php of the component User Registration Handler. The manipulation of the argument user leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273232.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-2g56-7jv7-wxxq

Missing Cryptographic Step in OWASP Enterprise Security API for Java

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2g55-8535-gp6f

Splicecom Maximiser Soft PBX v1.5 and before was discovered to contain a cross-site scripting (XSS) vulnerability via the CLIENT_NAME and DEVICE_GUID fields in the login component.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-2g55-7wqw-h2c5

Heap-based buffer overflow in the __zzip_get32 function in fetch.c in zziplib 0.13.62, 0.13.61, 0.13.60, 0.13.59, 0.13.58, 0.13.57, 0.13.56 allows remote attackers to cause a denial of service (crash) via a crafted ZIP file.

CVSS3: 5.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2g54-42rw-p43x

The specific function in ASUS BMC’s firmware Web management page (Modify user’s information function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2g53-pmw3-ccp9

CheckSec Canopy 3.x before 3.0.7 has stored XSS via the Login Page Disclaimer, allowing attacks by low-privileged users against higher-privileged users.

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2g53-3pj8-qvxv

Use-after-free vulnerability in the path_openat function in fs/namei.c in the Linux kernel 3.x and 4.x before 4.0.4 allows local users to cause a denial of service or possibly have unspecified other impact via O_TMPFILE filesystem operations that leverage a duplicate cleanup operation.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2g52-qw8q-wfr9

Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed. This vulnerability affects Firefox < 134.

CVSS3: 3.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-2g4x-xxrm-h5mw

Dell Encryption (formerly Dell Data Protection | Encryption) v10.1.0 and earlier contain an information disclosure vulnerability. A malicious user with physical access to the machine could potentially exploit this vulnerability to access the unencrypted RegBack folder that contains back-ups of sensitive system files.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2g4x-p9qv-phcg

Multiple cross-site scripting (XSS) vulnerabilities in Gallery 3 before 3.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) movie title to modules/gallery/controllers/movies.php or (2) key variable to modules/gallery/views/error_admin.html.php.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2g4x-fv7q-8jrf

Insufficient data validation in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-2g4x-3mj5-gvj6

Multiple buffer overflows in the Broderbund Expressit 3DGreetings Player ActiveX control could allow remote attackers to execute arbitrary code via unspecified vectors.

11%
Средний
больше 3 лет назад
github логотип
GHSA-2g4w-xqhx-j2x8

OpenSource Moddable v10.5.0 was discovered to contain a stack overflow via the component /moddable/xs/sources/xsScript.c.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2g4w-fv9w-h3mm

SQL injection vulnerability in ArrayOS before AG 9.4.0.135, when the portal bookmark function is enabled, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2g4w-cqhh-m9w9

VMware SD-WAN Edge contains a missing authentication and protection mechanism vulnerability. A malicious actor with physical access to the SD-WAN Edge appliance during activation can potentially exploit this vulnerability to access the BIOS configuration. In addition, the malicious actor may be able to exploit the default boot priority configured.

CVSS3: 4.8
0%
Низкий
больше 1 года назад

Уязвимостей на страницу