Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3x5c-cv6h-7vvm

1 день назад

A flaw has been found in SourceCodester Online Class Record System 1.0. Affected by this issue is some unknown functionality of the file /admin/login.php. This manipulation of the argument user_email causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3x59-vrmc-5mx6

больше 2 лет назад

@webiny/react-rich-text-renderer vulnerable to insecure rendering of rich text content

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3x59-4xhf-3r9c

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CBB Team Content Blocks Builder allows Stored XSS.This issue affects Content Blocks Builder: from n/a through 2.7.6.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3x58-xr87-2fcj

больше 4 лет назад

Cross-site scripting in bluemonday

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3x58-92jg-qfcg

почти 4 года назад

Vulnerability in HP MPE/iX 6.0 through 7.0 allows attackers to cause a denial of service (system failure with "SA1457 out of i_port_timeout.fix_up_message_frame") via malformed IP packets.

EPSS: Низкий
github логотип

GHSA-3x58-8qmv-wqw5

больше 3 лет назад

Aubio is vulnerable to out of bound read when samplerate > 50kHz

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3x57-vf53-p26m

больше 3 лет назад

Microsoft Excel 2010 SP2 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-3x57-pm7m-x59f

почти 4 года назад

Multiple unspecified vulnerabilities in Oracle Database 10.2.0.3 have unknown impact and remote authenticated attack vectors related to (1) Rules Manager and Expression Filter components (DB02) and (2) Oracle Streams (DB06). Note: as of 20070424, Oracle has not disputed reliable claims that DB02 is for a race condition in the RLMGR_TRUNCATE_MAINT trigger in the Rules Manager and Expression Filter components changing the AUTHID of a package from DEFINER to CURRENT_USER after a TRUNCATE call, and DB06 is for SQL injection in the DBMS_APPLY_USER_AGENT.SET_REGISTRATION_HANDLER procedure, which is later passed to the DBMS_APPLY_ADM_INTERNAL.ALTER_APPLY procedure, aka "Oracle Streams".

EPSS: Низкий
github логотип

GHSA-3x57-m985-pg67

больше 3 лет назад

Tor before 0.2.4.20, when OpenSSL 1.x is used in conjunction with a certain HardwareAccel setting on Intel Sandy Bridge and Ivy Bridge platforms, does not properly generate random numbers for (1) relay identity keys and (2) hidden-service identity keys, which might make it easier for remote attackers to bypass cryptographic protection mechanisms via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3x57-m5p4-rgh4

больше 1 года назад

ZendOpenID potential security issue in login mechanism

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3x57-7r9m-7xwv

около 4 лет назад

A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iService 1.1.7. A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3x56-fp32-hw97

больше 3 лет назад

If the Remote Debugging via USB feature was enabled in Firefox for Android on an Android version prior to Android 6.0, untrusted apps could have connected to the feature and operated with the privileges of the browser to read and interact with web content. The feature was implemented as a unix domain socket, protected by the Android SELinux policy; however, SELinux was not enforced for versions prior to 6.0. This was fixed by removing the Remote Debugging via USB feature from affected devices. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83.

EPSS: Низкий
github логотип

GHSA-3x55-g2vp-hv3w

4 месяца назад

When decoding a frame for a SANM file (ANIM v0 variant), the decoded data can be larger than the buffer allocated for it. Frames encoded with codec 48 can specify their resolution (width x height). A buffer of appropriate size is allocated depending on the resolution. This codec can encode the frame contents using a run-length encoding algorithm. There are no checks that the decoded frame fits in the allocated buffer, leading to a heap-buffer-overflow. process_frame_obj initializes the buffers based on the frame resolution: We recommend upgrading to version 8.0 or beyond.

EPSS: Низкий
github логотип

GHSA-3x55-c27p-j46v

больше 3 лет назад

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9607, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, SD 850, and SDX20, if a negative value is passed as argument "max" to qurt_qdi_state_local_new_handle_from_obj, an buffer overflow occurs, due to typecasting the signed integer to unsigned.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3x55-3v35-wg88

около 1 года назад

IBM ICP - Voice Gateway 1.0.2, 1.0.2.4, 1.0.3, 1.0.4, 1.0.5, 1.0.6. 1.0.7, 1.0.7.1, and 1.0.8 could allow remote attacker to send specially crafted XML statements, which would allow them to attacker to view or modify information in the XML document.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3x55-2c2w-5c9f

больше 1 года назад

An issue in Wavlink WN551K1 allows a remote attacker to obtain sensitive information via the ExportAllSettings.sh component.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3x54-hx35-g26f

около 2 лет назад

Adobe Experience Manager versions 6.5.18 and earlier are affected by an Improper Access Control vulnerability. An attacker could leverage this vulnerability to achieve a low-confidentiality impact within the application. Exploitation of this issue does not require user interaction.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3x54-79xc-w2f4

больше 3 лет назад

net/rds/sysctl.c in the Linux kernel before 3.19 uses an incorrect data type in a sysctl table, which allows local users to obtain potentially sensitive information from kernel memory or possibly have unspecified other impact by accessing a sysctl entry.

EPSS: Низкий
github логотип

GHSA-3x54-4rx9-hwj2

больше 3 лет назад

Directory traversal vulnerability in servlet/downloadReport in McAfee Asset Manager 6.6 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the reportFileName parameter.

EPSS: Средний
github логотип

GHSA-3x54-355x-xrjh

около 1 месяца назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3x5c-cv6h-7vvm

A flaw has been found in SourceCodester Online Class Record System 1.0. Affected by this issue is some unknown functionality of the file /admin/login.php. This manipulation of the argument user_email causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.

CVSS3: 7.3
1 день назад
github логотип
GHSA-3x59-vrmc-5mx6

@webiny/react-rich-text-renderer vulnerable to insecure rendering of rich text content

CVSS3: 4.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3x59-4xhf-3r9c

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CBB Team Content Blocks Builder allows Stored XSS.This issue affects Content Blocks Builder: from n/a through 2.7.6.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-3x58-xr87-2fcj

Cross-site scripting in bluemonday

CVSS3: 6.1
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3x58-92jg-qfcg

Vulnerability in HP MPE/iX 6.0 through 7.0 allows attackers to cause a denial of service (system failure with "SA1457 out of i_port_timeout.fix_up_message_frame") via malformed IP packets.

2%
Низкий
почти 4 года назад
github логотип
GHSA-3x58-8qmv-wqw5

Aubio is vulnerable to out of bound read when samplerate > 50kHz

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x57-vf53-p26m

Microsoft Excel 2010 SP2 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."

CVSS3: 7.8
20%
Средний
больше 3 лет назад
github логотип
GHSA-3x57-pm7m-x59f

Multiple unspecified vulnerabilities in Oracle Database 10.2.0.3 have unknown impact and remote authenticated attack vectors related to (1) Rules Manager and Expression Filter components (DB02) and (2) Oracle Streams (DB06). Note: as of 20070424, Oracle has not disputed reliable claims that DB02 is for a race condition in the RLMGR_TRUNCATE_MAINT trigger in the Rules Manager and Expression Filter components changing the AUTHID of a package from DEFINER to CURRENT_USER after a TRUNCATE call, and DB06 is for SQL injection in the DBMS_APPLY_USER_AGENT.SET_REGISTRATION_HANDLER procedure, which is later passed to the DBMS_APPLY_ADM_INTERNAL.ALTER_APPLY procedure, aka "Oracle Streams".

4%
Низкий
почти 4 года назад
github логотип
GHSA-3x57-m985-pg67

Tor before 0.2.4.20, when OpenSSL 1.x is used in conjunction with a certain HardwareAccel setting on Intel Sandy Bridge and Ivy Bridge platforms, does not properly generate random numbers for (1) relay identity keys and (2) hidden-service identity keys, which might make it easier for remote attackers to bypass cryptographic protection mechanisms via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x57-m5p4-rgh4

ZendOpenID potential security issue in login mechanism

CVSS3: 7.5
больше 1 года назад
github логотип
GHSA-3x57-7r9m-7xwv

A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iService 1.1.7. A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-3x56-fp32-hw97

If the Remote Debugging via USB feature was enabled in Firefox for Android on an Android version prior to Android 6.0, untrusted apps could have connected to the feature and operated with the privileges of the browser to read and interact with web content. The feature was implemented as a unix domain socket, protected by the Android SELinux policy; however, SELinux was not enforced for versions prior to 6.0. This was fixed by removing the Remote Debugging via USB feature from affected devices. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x55-g2vp-hv3w

When decoding a frame for a SANM file (ANIM v0 variant), the decoded data can be larger than the buffer allocated for it. Frames encoded with codec 48 can specify their resolution (width x height). A buffer of appropriate size is allocated depending on the resolution. This codec can encode the frame contents using a run-length encoding algorithm. There are no checks that the decoded frame fits in the allocated buffer, leading to a heap-buffer-overflow. process_frame_obj initializes the buffers based on the frame resolution: We recommend upgrading to version 8.0 or beyond.

0%
Низкий
4 месяца назад
github логотип
GHSA-3x55-c27p-j46v

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9607, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, SD 850, and SDX20, if a negative value is passed as argument "max" to qurt_qdi_state_local_new_handle_from_obj, an buffer overflow occurs, due to typecasting the signed integer to unsigned.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x55-3v35-wg88

IBM ICP - Voice Gateway 1.0.2, 1.0.2.4, 1.0.3, 1.0.4, 1.0.5, 1.0.6. 1.0.7, 1.0.7.1, and 1.0.8 could allow remote attacker to send specially crafted XML statements, which would allow them to attacker to view or modify information in the XML document.

CVSS3: 8.1
0%
Низкий
около 1 года назад
github логотип
GHSA-3x55-2c2w-5c9f

An issue in Wavlink WN551K1 allows a remote attacker to obtain sensitive information via the ExportAllSettings.sh component.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3x54-hx35-g26f

Adobe Experience Manager versions 6.5.18 and earlier are affected by an Improper Access Control vulnerability. An attacker could leverage this vulnerability to achieve a low-confidentiality impact within the application. Exploitation of this issue does not require user interaction.

CVSS3: 5.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-3x54-79xc-w2f4

net/rds/sysctl.c in the Linux kernel before 3.19 uses an incorrect data type in a sysctl table, which allows local users to obtain potentially sensitive information from kernel memory or possibly have unspecified other impact by accessing a sysctl entry.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3x54-4rx9-hwj2

Directory traversal vulnerability in servlet/downloadReport in McAfee Asset Manager 6.6 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the reportFileName parameter.

18%
Средний
больше 3 лет назад
github логотип
GHSA-3x54-355x-xrjh

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

около 1 месяца назад

Уязвимостей на страницу