Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3x6f-9g7f-wqvm

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in LWS LWS Tools plugin <= 2.4.1 versions.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3x6c-xfwc-qp7m

почти 2 года назад

An XML external entity (XXE) vulnerability was found in Stilog Visual Planning 8. It allows an authenticated attacker to access local server files and exfiltrate data to an external server.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3x6c-8mj8-xj2q

больше 3 лет назад

The nextvar function in NTP before 4.2.8p6 and 4.3.x before 4.3.90 does not properly validate the length of its input, which allows an attacker to cause a denial of service (application crash).

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-3x69-vfm2-92j8

3 месяца назад

A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 26.1, iOS 26.1 and iPadOS 26.1, Safari 26.1, visionOS 26.1. Processing maliciously crafted web content may lead to an unexpected Safari crash.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3x69-qg6m-7562

больше 3 лет назад

A vulnerability in the Cisco Fabric Services component of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause process crashes, which can result in a denial of service (DoS) condition on an affected system. The vulnerability is due to insufficient validation of TCP packets when processed by the Cisco Fabric Services over IP (CFSoIP) feature. An attacker could exploit this vulnerability by sending a malicious Cisco Fabric Services TCP packet to an affected device. A successful exploit could allow the attacker to cause process crashes, resulting in a device reload and a DoS condition. Note: There are three distribution methods that can be configured for Cisco Fabric Services. This vulnerability affects only distribution method CFSoIP, which is disabled by default. See the Details section for more information.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3x69-mjh4-vwh4

почти 4 года назад

The SERVICE.DNS signature engine in the Intrusion Prevention System (IPS) in Cisco IOS 12.3 and 12.4 allows remote attackers to cause a denial of service (device crash or hang) via network traffic that triggers unspecified IPS signatures, a different vulnerability than CVE-2008-1447.

EPSS: Низкий
github логотип

GHSA-3x69-95v2-m4qp

почти 4 года назад

Cross-site scripting (XSS) vulnerability in WoltLab Community Framework (WCF) 1.0.6 in WoltLab Burning Board 3.0.5 allows remote attackers to inject arbitrary web script or HTML via the (1) page and (2) form parameters, which are not properly handled when they are reflected back in an error message.

EPSS: Низкий
github логотип

GHSA-3x67-44wh-mrgf

9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in kerberos authentication Setting sess->user = NULL was introduced to fix the dangling pointer created by ksmbd_free_user. However, it is possible another thread could be operating on the session and make use of sess->user after it has been passed to ksmbd_free_user but before sess->user is set to NULL.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3x66-mfv9-gf9p

больше 2 лет назад

In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3x66-jhf4-g79q

5 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Remove unused nvme_ls_waitq wait queue System crash when qla2x00_start_sp(sp) returns error code EGAIN and wake_up gets called for uninitialized wait queue sp->nvme_ls_waitq. qla2xxx [0000:37:00.1]-2121:5: Returning existing qpair of ffff8ae2c0513400 for idx=0 qla2xxx [0000:37:00.1]-700e:5: qla2x00_start_sp failed = 11 BUG: unable to handle kernel NULL pointer dereference at 0000000000000000 PGD 0 P4D 0 Oops: 0000 [#1] SMP NOPTI Hardware name: HPE ProLiant DL360 Gen10/ProLiant DL360 Gen10, BIOS U32 09/03/2021 Workqueue: nvme-wq nvme_fc_connect_ctrl_work [nvme_fc] RIP: 0010:__wake_up_common+0x4c/0x190 RSP: 0018:ffff95f3e0cb7cd0 EFLAGS: 00010086 RAX: 0000000000000000 RBX: ffff8b08d3b26328 RCX: 0000000000000000 RDX: 0000000000000001 RSI: 0000000000000003 RDI: ffff8b08d3b26320 RBP: 0000000000000001 R08: 0000000000000000 R09: ffffffffffffffe8 R10: 0000...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3x65-x797-c3v9

около 2 лет назад

In TBD of TBD, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3x65-293m-45mc

почти 4 года назад

In Telecomm, there is a possible way to determine whether an app is installed, without query permissions, due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-196406138

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3x63-355f-wqjh

почти 4 года назад

SQL injection vulnerability in news_page.asp in Martyn Kilbryde Newsposter Script (aka makit news/blog poster) 3 and earlier allows remote attackers to execute arbitrary SQL commands via the uid parameter.

EPSS: Низкий
github логотип

GHSA-3x62-x456-q2vm

почти 4 года назад

OS Command Injection in git-pull-or-clone

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-3x62-9v4c-683c

больше 3 лет назад

Memory corruption in audio while playing record due to improper list handling in two threads in Snapdragon Connectivity, Snapdragon Mobile, Snapdragon Wearables

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3x62-5wxc-9c6p

больше 3 лет назад

Roxy-WI through 5.2.2.0 allows authenticated SQL injection via select_servers.

EPSS: Низкий
github логотип

GHSA-3x5x-xcjx-p3hh

почти 4 года назад

Multiple PHP remote file inclusion vulnerabilities in ACGV News 0.9.1 allow remote attackers to execute arbitrary PHP code via a URL in the PathNews parameter in (1) header.php or (2) news.php. NOTE: portions of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-3x5x-fw77-g54c

11 месяцев назад

dmlc/dgl Vulnerable to Remote Code Execution by Pickle Deserialization via rpc.recv_request()

EPSS: Низкий
github логотип

GHSA-3x5x-7q5j-v688

больше 3 лет назад

NetIQ iManager, versions prior to 3.1, under some circumstances could be susceptible to an elevation of privilege attack.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3x5x-62pf-8jpr

3 месяца назад

Policy bypass in Extensions in Google Chrome prior to 142.0.7444.59 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Low)

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3x6f-9g7f-wqvm

Cross-Site Request Forgery (CSRF) vulnerability in LWS LWS Tools plugin <= 2.4.1 versions.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3x6c-xfwc-qp7m

An XML external entity (XXE) vulnerability was found in Stilog Visual Planning 8. It allows an authenticated attacker to access local server files and exfiltrate data to an external server.

CVSS3: 6.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-3x6c-8mj8-xj2q

The nextvar function in NTP before 4.2.8p6 and 4.3.x before 4.3.90 does not properly validate the length of its input, which allows an attacker to cause a denial of service (application crash).

CVSS3: 6.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x69-vfm2-92j8

A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 26.1, iOS 26.1 and iPadOS 26.1, Safari 26.1, visionOS 26.1. Processing maliciously crafted web content may lead to an unexpected Safari crash.

CVSS3: 4.3
0%
Низкий
3 месяца назад
github логотип
GHSA-3x69-qg6m-7562

A vulnerability in the Cisco Fabric Services component of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause process crashes, which can result in a denial of service (DoS) condition on an affected system. The vulnerability is due to insufficient validation of TCP packets when processed by the Cisco Fabric Services over IP (CFSoIP) feature. An attacker could exploit this vulnerability by sending a malicious Cisco Fabric Services TCP packet to an affected device. A successful exploit could allow the attacker to cause process crashes, resulting in a device reload and a DoS condition. Note: There are three distribution methods that can be configured for Cisco Fabric Services. This vulnerability affects only distribution method CFSoIP, which is disabled by default. See the Details section for more information.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3x69-mjh4-vwh4

The SERVICE.DNS signature engine in the Intrusion Prevention System (IPS) in Cisco IOS 12.3 and 12.4 allows remote attackers to cause a denial of service (device crash or hang) via network traffic that triggers unspecified IPS signatures, a different vulnerability than CVE-2008-1447.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3x69-95v2-m4qp

Cross-site scripting (XSS) vulnerability in WoltLab Community Framework (WCF) 1.0.6 in WoltLab Burning Board 3.0.5 allows remote attackers to inject arbitrary web script or HTML via the (1) page and (2) form parameters, which are not properly handled when they are reflected back in an error message.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3x67-44wh-mrgf

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in kerberos authentication Setting sess->user = NULL was introduced to fix the dangling pointer created by ksmbd_free_user. However, it is possible another thread could be operating on the session and make use of sess->user after it has been passed to ksmbd_free_user but before sess->user is set to NULL.

CVSS3: 7.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-3x66-mfv9-gf9p

In Messaging, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3x66-jhf4-g79q

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Remove unused nvme_ls_waitq wait queue System crash when qla2x00_start_sp(sp) returns error code EGAIN and wake_up gets called for uninitialized wait queue sp->nvme_ls_waitq. qla2xxx [0000:37:00.1]-2121:5: Returning existing qpair of ffff8ae2c0513400 for idx=0 qla2xxx [0000:37:00.1]-700e:5: qla2x00_start_sp failed = 11 BUG: unable to handle kernel NULL pointer dereference at 0000000000000000 PGD 0 P4D 0 Oops: 0000 [#1] SMP NOPTI Hardware name: HPE ProLiant DL360 Gen10/ProLiant DL360 Gen10, BIOS U32 09/03/2021 Workqueue: nvme-wq nvme_fc_connect_ctrl_work [nvme_fc] RIP: 0010:__wake_up_common+0x4c/0x190 RSP: 0018:ffff95f3e0cb7cd0 EFLAGS: 00010086 RAX: 0000000000000000 RBX: ffff8b08d3b26328 RCX: 0000000000000000 RDX: 0000000000000001 RSI: 0000000000000003 RDI: ffff8b08d3b26320 RBP: 0000000000000001 R08: 0000000000000000 R09: ffffffffffffffe8 R10: 0000...

CVSS3: 5.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-3x65-x797-c3v9

In TBD of TBD, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-3x65-293m-45mc

In Telecomm, there is a possible way to determine whether an app is installed, without query permissions, due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-196406138

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-3x63-355f-wqjh

SQL injection vulnerability in news_page.asp in Martyn Kilbryde Newsposter Script (aka makit news/blog poster) 3 and earlier allows remote attackers to execute arbitrary SQL commands via the uid parameter.

2%
Низкий
почти 4 года назад
github логотип
GHSA-3x62-x456-q2vm

OS Command Injection in git-pull-or-clone

CVSS3: 9.8
10%
Средний
почти 4 года назад
github логотип
GHSA-3x62-9v4c-683c

Memory corruption in audio while playing record due to improper list handling in two threads in Snapdragon Connectivity, Snapdragon Mobile, Snapdragon Wearables

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x62-5wxc-9c6p

Roxy-WI through 5.2.2.0 allows authenticated SQL injection via select_servers.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x5x-xcjx-p3hh

Multiple PHP remote file inclusion vulnerabilities in ACGV News 0.9.1 allow remote attackers to execute arbitrary PHP code via a URL in the PathNews parameter in (1) header.php or (2) news.php. NOTE: portions of these details are obtained from third party information.

3%
Низкий
почти 4 года назад
github логотип
GHSA-3x5x-fw77-g54c

dmlc/dgl Vulnerable to Remote Code Execution by Pickle Deserialization via rpc.recv_request()

11 месяцев назад
github логотип
GHSA-3x5x-7q5j-v688

NetIQ iManager, versions prior to 3.1, under some circumstances could be susceptible to an elevation of privilege attack.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x5x-62pf-8jpr

Policy bypass in Extensions in Google Chrome prior to 142.0.7444.59 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Low)

CVSS3: 6.5
0%
Низкий
3 месяца назад

Уязвимостей на страницу