Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3x8m-r3mg-qw2f

почти 4 года назад

Buffer overflow in passwd in BSD based operating systems 4.3 and earlier allows local users to gain root privileges by specifying a long shell or GECOS field.

EPSS: Низкий
github логотип

GHSA-3x8m-mcw2-vhx7

почти 2 года назад

Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3x8j-5c5c-jh43

около 2 лет назад

A race condition in System Management Mode (SMM) code may allow an attacker using a compromised user space to leverage CVE-2018-8897 potentially resulting in privilege escalation.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3x8h-v4j3-pvc2

больше 3 лет назад

The Twitter module 6.x-5.x before 6.x-5.2, 7.x-5.x before 7.x-5.9, and 7.x-6.x before 7.x-6.0 for Drupal does not properly check access permissions, which allows remote authenticated users to post tweets to arbitrary accounts by leveraging the (1) "post to twitter" permission or change the options for arbitrary attached accounts by leveraging the (2) "add twitter accounts" or (3) "add authenticated twitter accounts" permission.

EPSS: Низкий
github логотип

GHSA-3x8g-wg8m-8443

почти 4 года назад

Cross-site scripting (XSS) vulnerability in Cisco Router and Security Device Manager (SDM) allows remote attackers to inject arbitrary web script or HTML via unknown vectors, aka Bug ID CSCtb38467.

EPSS: Низкий
github логотип

GHSA-3x8g-vpq9-jv7h

2 месяца назад

In the Linux kernel, the following vulnerability has been resolved: gve: Implement gettimex64 with -EOPNOTSUPP gve implemented a ptp_clock for sole use of do_aux_work at this time. ptp_clock_gettime() and ptp_sys_offset() assume every ptp_clock has implemented either gettimex64 or gettime64. Stub gettimex64 and return -EOPNOTSUPP to prevent NULL dereferencing.

EPSS: Низкий
github логотип

GHSA-3x8g-fh7w-4466

больше 3 лет назад

The Deltin Suites (aka com.DeltinSuites) application 3.4.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-3x8c-g2gj-p9rg

7 месяцев назад

Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-3x8c-fmpc-5rmq

больше 5 лет назад

Cross-site scripting (XSS) vulnerability in the fallback authentication endpoint

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3x89-mv2j-86mr

больше 3 лет назад

Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) because properties of Annotation objects are mishandled. This relates to one of five distinct types of Annotation objects.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3x89-96hq-8v55

больше 3 лет назад

Directory traversal vulnerability in PHPJabbers Appointment Scheduler 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter in a pjActionDownload action to the pjBackup controller.

EPSS: Низкий
github логотип

GHSA-3x88-xvgr-m6fg

почти 4 года назад

OpenID allows remote attackers to forcibly log a user into an OpenID enabled site, divulge the user's personal information to this site, and add it site to the trusted sites list via a crafted web page, related to cached tokens.

EPSS: Низкий
github логотип

GHSA-3x88-87x6-rhc4

больше 3 лет назад

An issue was discovered in Form Tools through 3.0.20. SQL Injection can occur via the export_group_id field when a low-privileged user (client) tries to export a form with data, e.g., manipulation of modules/export_manager/export.php?export_group_id=1&export_group_1_results=all&export_type_id=1.

EPSS: Низкий
github логотип

GHSA-3x87-pjpc-6c9c

около 2 лет назад

A race condition was found in the Linux kernel's media/dvb-core in dvbdmx_write() function. This can result in a null pointer dereference issue, possibly leading to a kernel panic or denial of service issue.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3x87-43vv-824j

11 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mrdenny My Default Post Content allows Stored XSS. This issue affects My Default Post Content: from n/a through 0.7.3.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3x86-xwf6-ffcp

больше 3 лет назад

The recovery module has a vulnerability of bypassing the verification of an update package before use. Successful exploitation of this vulnerability may affect system stability.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3x85-qhhf-2pm5

больше 3 лет назад

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Possibility of accessing out of bound vector index When updating some GNSS configurations.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3x85-87vg-8622

почти 4 года назад

Juniper NetScreen-Security Manager (NSM) 2004 FP2 and FP3 allow remote attackers to cause a denial of service (crash or hang of server components that are automatically restarted) via a long crafted string on (1) port 7800 (the GUI Server port) or (2) port 7801 (the Device Server port).

EPSS: Низкий
github логотип

GHSA-3x85-6f44-2gm6

больше 3 лет назад

The CP_RC_TRANSACTION_CALL_BY_SET function in the Engineering Workbench component in SAP Production Planning and Control allows remote authenticated users to bypass intended transaction restrictions via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3x84-f4p2-cmpp

больше 3 лет назад

IBM Security Identity Manager Virtual Appliance 7.0.2 writes information to log files which can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information. IBM X-Force ID: 172016.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3x8m-r3mg-qw2f

Buffer overflow in passwd in BSD based operating systems 4.3 and earlier allows local users to gain root privileges by specifying a long shell or GECOS field.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3x8m-mcw2-vhx7

Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-3x8j-5c5c-jh43

A race condition in System Management Mode (SMM) code may allow an attacker using a compromised user space to leverage CVE-2018-8897 potentially resulting in privilege escalation.

CVSS3: 8.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-3x8h-v4j3-pvc2

The Twitter module 6.x-5.x before 6.x-5.2, 7.x-5.x before 7.x-5.9, and 7.x-6.x before 7.x-6.0 for Drupal does not properly check access permissions, which allows remote authenticated users to post tweets to arbitrary accounts by leveraging the (1) "post to twitter" permission or change the options for arbitrary attached accounts by leveraging the (2) "add twitter accounts" or (3) "add authenticated twitter accounts" permission.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x8g-wg8m-8443

Cross-site scripting (XSS) vulnerability in Cisco Router and Security Device Manager (SDM) allows remote attackers to inject arbitrary web script or HTML via unknown vectors, aka Bug ID CSCtb38467.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3x8g-vpq9-jv7h

In the Linux kernel, the following vulnerability has been resolved: gve: Implement gettimex64 with -EOPNOTSUPP gve implemented a ptp_clock for sole use of do_aux_work at this time. ptp_clock_gettime() and ptp_sys_offset() assume every ptp_clock has implemented either gettimex64 or gettime64. Stub gettimex64 and return -EOPNOTSUPP to prevent NULL dereferencing.

0%
Низкий
2 месяца назад
github логотип
GHSA-3x8g-fh7w-4466

The Deltin Suites (aka com.DeltinSuites) application 3.4.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x8c-g2gj-p9rg

Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.

CVSS3: 8.2
0%
Низкий
7 месяцев назад
github логотип
GHSA-3x8c-fmpc-5rmq

Cross-site scripting (XSS) vulnerability in the fallback authentication endpoint

CVSS3: 6.1
1%
Низкий
больше 5 лет назад
github логотип
GHSA-3x89-mv2j-86mr

Foxit PhantomPDF and Reader before 9.3 allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) because properties of Annotation objects are mishandled. This relates to one of five distinct types of Annotation objects.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x89-96hq-8v55

Directory traversal vulnerability in PHPJabbers Appointment Scheduler 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter in a pjActionDownload action to the pjBackup controller.

7%
Низкий
больше 3 лет назад
github логотип
GHSA-3x88-xvgr-m6fg

OpenID allows remote attackers to forcibly log a user into an OpenID enabled site, divulge the user's personal information to this site, and add it site to the trusted sites list via a crafted web page, related to cached tokens.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3x88-87x6-rhc4

An issue was discovered in Form Tools through 3.0.20. SQL Injection can occur via the export_group_id field when a low-privileged user (client) tries to export a form with data, e.g., manipulation of modules/export_manager/export.php?export_group_id=1&export_group_1_results=all&export_type_id=1.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-3x87-pjpc-6c9c

A race condition was found in the Linux kernel's media/dvb-core in dvbdmx_write() function. This can result in a null pointer dereference issue, possibly leading to a kernel panic or denial of service issue.

CVSS3: 5.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-3x87-43vv-824j

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mrdenny My Default Post Content allows Stored XSS. This issue affects My Default Post Content: from n/a through 0.7.3.

CVSS3: 5.9
0%
Низкий
11 месяцев назад
github логотип
GHSA-3x86-xwf6-ffcp

The recovery module has a vulnerability of bypassing the verification of an update package before use. Successful exploitation of this vulnerability may affect system stability.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x85-qhhf-2pm5

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Possibility of accessing out of bound vector index When updating some GNSS configurations.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x85-87vg-8622

Juniper NetScreen-Security Manager (NSM) 2004 FP2 and FP3 allow remote attackers to cause a denial of service (crash or hang of server components that are automatically restarted) via a long crafted string on (1) port 7800 (the GUI Server port) or (2) port 7801 (the Device Server port).

1%
Низкий
почти 4 года назад
github логотип
GHSA-3x85-6f44-2gm6

The CP_RC_TRANSACTION_CALL_BY_SET function in the Engineering Workbench component in SAP Production Planning and Control allows remote authenticated users to bypass intended transaction restrictions via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x84-f4p2-cmpp

IBM Security Identity Manager Virtual Appliance 7.0.2 writes information to log files which can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information. IBM X-Force ID: 172016.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу