Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3x83-whxw-pvmg

почти 4 года назад

Liferay Portal and Liferay DXP vulnerable to cross-site scripting (XSS)

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3x83-p476-vv95

почти 7 лет назад

Downloads Resources over HTTP in selenium-standalone-painful

EPSS: Низкий
github логотип

GHSA-3x83-2prq-r4mq

почти 4 года назад

Eval injection vulnerability in system/services/init.php in Movie PHP Script 2.0 allows remote attackers to execute arbitrary PHP code via the anticode parameter.

EPSS: Низкий
github логотип

GHSA-3x82-hxvx-2rv2

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: net: bcmasp: fix potential memory leak in bcmasp_xmit() The bcmasp_xmit() returns NETDEV_TX_OK without freeing skb in case of mapping fails, add dev_kfree_skb() to fix it.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3x82-g63q-53gm

около 2 лет назад

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). The supported version that is affected is 13.5.0.0. Easily exploitable vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Enterprise Manager Base Platform executes to compromise Oracle Enterprise Manager Base Platform. While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Manager Base Platform accessible data as well as unauthorized access to critical data or complete access to all Oracle Enterprise Manager Base Platform accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Enterprise...

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-3x82-3mp6-5r7h

больше 3 лет назад

The init script in kbd, possibly 1.14.1 and earlier, allows local users to overwrite arbitrary files via a symlink attack on /dev/shm/defkeymap.map.

EPSS: Низкий
github логотип

GHSA-3x7x-cqwg-66jm

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in HP AssetManager 5.20, 5.21, 5.22, and 9.30 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3x7w-vvg2-w6r8

больше 2 лет назад

Local users are able to execute scripts under root privileges.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3x7v-wjr7-jrcm

больше 3 лет назад

SChannel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 lacks the required extended master-secret binding support to ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which allows man-in-the-middle attackers to obtain sensitive information or modify TLS session data via a "triple handshake attack," aka "Schannel TLS Triple Handshake Vulnerability."

EPSS: Низкий
github логотип

GHSA-3x7r-v44p-242p

больше 3 лет назад

Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to discover full pathnames via an application tag.

EPSS: Низкий
github логотип

GHSA-3x7r-r5xh-2v32

почти 4 года назад

Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 on Mac OS X allow remote attackers to bypass the Same Origin Policy and create arbitrary socket connections via a crafted Java applet, related to the Java Embedding Plugin (JEP) and Java LiveConnect.

EPSS: Низкий
github логотип

GHSA-3x7r-h96m-8m94

почти 4 года назад

Weak web transport security (Weak TLS): An attacker may be able to decrypt the data using attacks

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3x7r-cvw4-596j

почти 2 года назад

File upload restriction evasion vulnerability in AMSS++ version 4.31. This vulnerability could allow an authenticated user to potentially obtain RCE through webshell, compromising the entire infrastructure.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-3x7p-q29c-47qm

больше 3 лет назад

In Jingyun Antivirus v2.4.2.39, the driver file (ZySandbox.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x12364020.

EPSS: Низкий
github логотип

GHSA-3x7p-3vvq-9qr7

7 месяцев назад

Improper handling of insufficient permissions or privileges in Microsoft Teams allows an authorized attacker to elevate privileges over a network.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-3x7j-rf7h-c58q

больше 3 лет назад

Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Tasks). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Common Applications Calendar. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Common Applications Calendar, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Common Applications Calendar accessible data as well as unauthorized update, insert or delete access to some of Oracle Common Applications Calendar accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).

EPSS: Низкий
github логотип

GHSA-3x7j-9p25-v8r6

почти 3 года назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Client programs). Supported versions that are affected are 5.7.41 and prior and 8.0.32 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Server. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H).

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3x7h-rc2j-gvx2

больше 3 лет назад

WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors involving form menus.

EPSS: Низкий
github логотип

GHSA-3x7h-7xqw-rj45

больше 3 лет назад

Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging the CAP_NET_RAW capability to change a socket version, related to the packet_set_ring and packet_setsockopt functions.

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-3x7h-5hfr-hvjm

больше 7 лет назад

Moderate severity vulnerability that affects io.undertow:undertow-core

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3x83-whxw-pvmg

Liferay Portal and Liferay DXP vulnerable to cross-site scripting (XSS)

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-3x83-p476-vv95

Downloads Resources over HTTP in selenium-standalone-painful

1%
Низкий
почти 7 лет назад
github логотип
GHSA-3x83-2prq-r4mq

Eval injection vulnerability in system/services/init.php in Movie PHP Script 2.0 allows remote attackers to execute arbitrary PHP code via the anticode parameter.

2%
Низкий
почти 4 года назад
github логотип
GHSA-3x82-hxvx-2rv2

In the Linux kernel, the following vulnerability has been resolved: net: bcmasp: fix potential memory leak in bcmasp_xmit() The bcmasp_xmit() returns NETDEV_TX_OK without freeing skb in case of mapping fails, add dev_kfree_skb() to fix it.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3x82-g63q-53gm

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). The supported version that is affected is 13.5.0.0. Easily exploitable vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Enterprise Manager Base Platform executes to compromise Oracle Enterprise Manager Base Platform. While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Manager Base Platform accessible data as well as unauthorized access to critical data or complete access to all Oracle Enterprise Manager Base Platform accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Enterprise...

CVSS3: 8.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-3x82-3mp6-5r7h

The init script in kbd, possibly 1.14.1 and earlier, allows local users to overwrite arbitrary files via a symlink attack on /dev/shm/defkeymap.map.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x7x-cqwg-66jm

Multiple cross-site scripting (XSS) vulnerabilities in HP AssetManager 5.20, 5.21, 5.22, and 9.30 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3x7w-vvg2-w6r8

Local users are able to execute scripts under root privileges.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3x7v-wjr7-jrcm

SChannel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 lacks the required extended master-secret binding support to ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which allows man-in-the-middle attackers to obtain sensitive information or modify TLS session data via a "triple handshake attack," aka "Schannel TLS Triple Handshake Vulnerability."

7%
Низкий
больше 3 лет назад
github логотип
GHSA-3x7r-v44p-242p

Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to discover full pathnames via an application tag.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3x7r-r5xh-2v32

Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 on Mac OS X allow remote attackers to bypass the Same Origin Policy and create arbitrary socket connections via a crafted Java applet, related to the Java Embedding Plugin (JEP) and Java LiveConnect.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3x7r-h96m-8m94

Weak web transport security (Weak TLS): An attacker may be able to decrypt the data using attacks

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-3x7r-cvw4-596j

File upload restriction evasion vulnerability in AMSS++ version 4.31. This vulnerability could allow an authenticated user to potentially obtain RCE through webshell, compromising the entire infrastructure.

CVSS3: 9.9
0%
Низкий
почти 2 года назад
github логотип
GHSA-3x7p-q29c-47qm

In Jingyun Antivirus v2.4.2.39, the driver file (ZySandbox.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x12364020.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x7p-3vvq-9qr7

Improper handling of insufficient permissions or privileges in Microsoft Teams allows an authorized attacker to elevate privileges over a network.

CVSS3: 3.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-3x7j-rf7h-c58q

Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Tasks). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Common Applications Calendar. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Common Applications Calendar, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Common Applications Calendar accessible data as well as unauthorized update, insert or delete access to some of Oracle Common Applications Calendar accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).

2%
Низкий
больше 3 лет назад
github логотип
GHSA-3x7j-9p25-v8r6

Vulnerability in the MySQL Server product of Oracle MySQL (component: Client programs). Supported versions that are affected are 5.7.41 and prior and 8.0.32 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Server. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H).

CVSS3: 7.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-3x7h-rc2j-gvx2

WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors involving form menus.

5%
Низкий
больше 3 лет назад
github логотип
GHSA-3x7h-7xqw-rj45

Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging the CAP_NET_RAW capability to change a socket version, related to the packet_set_ring and packet_setsockopt functions.

CVSS3: 7.8
31%
Средний
больше 3 лет назад
github логотип
GHSA-3x7h-5hfr-hvjm

Moderate severity vulnerability that affects io.undertow:undertow-core

CVSS3: 7.5
6%
Низкий
больше 7 лет назад

Уязвимостей на страницу