Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3wp7-mj2q-x6q3

больше 3 лет назад

RIOT-OS 2021.01 before commit 85da504d2dc30188b89f44c3276fc5a25b31251f contains a buffer overflow which could allow attackers to obtain sensitive information.

EPSS: Низкий
github логотип

GHSA-3wp7-47p5-gxmr

почти 4 года назад

Clearswift MAILsweeper for SMTP before 4.3_13 allows remote attackers to cause a denial of service (infinite loop) via an e-mail with a crafted RAR archive attached.

EPSS: Низкий
github логотип

GHSA-3wp6-w2rj-8433

больше 3 лет назад

Crypto++ 5.6.4 incorrectly uses Microsoft's stack-based _malloca and _freea functions. The library will request a block of memory to align a table in memory. If the table is later reallocated, then the wrong pointer could be freed.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3wp6-9w98-mc5j

больше 3 лет назад

The Mollom module 6.x-2.7 before 6.x-2.15 for Drupal allows remote attackers to bypass intended access restrictions and modify the mollom blacklist via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3wp5-gwjr-7mpv

9 дней назад

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow a local user to cause a denial of service due to improper neutralization of special elements in data query logic.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3wp5-cvp4-5h42

больше 3 лет назад

The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3wp4-6pwm-vcxj

почти 4 года назад

Buffer overflow in the polymorphic opcode support in the Regular Expression Engine (regcomp.c) in Perl 5.8 allows context-dependent attackers to execute arbitrary code by switching from byte to Unicode (UTF) characters in a regular expression.

EPSS: Средний
github логотип

GHSA-3wp3-9r5c-77fc

больше 3 лет назад

IBM Maximo Asset Management 7.6.1.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 170961.

EPSS: Низкий
github логотип

GHSA-3wp3-9f4h-fqwh

почти 4 года назад

IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.2 and IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the Admin Console to become unresponsive. IBM X-Force ID: 220485.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3wmx-fc2q-p8g5

больше 3 лет назад

A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition when the device unexpectedly reloads. The vulnerability is due to improper input validation of certain type, length, value (TLV) fields of the LLDP frame header. An attacker could exploit this vulnerability by sending a crafted LLDP packet to an interface on the targeted device. A successful exploit could allow the attacker to cause the switch to reload unexpectedly.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3wmx-9qwp-h363

больше 2 лет назад

Duplicate Advisory: EVE Doesn't Protect Config Partition with Measured Boot

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3wmx-48g3-x66g

больше 1 года назад

Backdrop CMS does not sufficiently sanitize field labels before they are displayed in certain places

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3wmw-g879-9gp5

почти 4 года назад

SQL injection vulnerability in escribir.php in Foro Domus 2.10 allows remote attackers to execute arbitrary SQL commands via the email parameter. NOTE: the provenance of this information is unknown, although it may be based on post-disclosure analysis of CVE-2006-0110; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-3wmv-phhj-q327

больше 3 лет назад

A CWE-787: Out-of-bounds Write vulnerability exists that could cause a denial of service of the webserver due to improper parsing of the HTTP Headers. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V1.0), OPC UA Modicon Communication Module (BMENUA0100) (V1.10 and prior)

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3wmv-7php-rhg5

больше 3 лет назад

Jenkins Vulnerable to Cross-Site Request Forgery (CSRF) Attack

EPSS: Низкий
github логотип

GHSA-3wmv-527f-7jxv

больше 3 лет назад

An exploitable use of an uninitialized pointer vulnerability exists in the JavaScript engine in Foxit PDF Reader version 9.0.1.1049. A specially crafted PDF document can lead to a dereference of an uninitialized pointer which, if under attacker control, can result in arbitrary code execution. An attacker needs to trick the user to open a malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3wmq-h2jq-wfgw

около 4 лет назад

The SupportCandy WordPress plugin before 2.2.7 does not have CSRF check in the wpsc_tickets AJAX action, nor has any sanitisation or escaping in some of the filter fields which could allow attackers to make a logged in user having access to the ticket lists dashboard set an arbitrary filter (stored in their cookies) with an XSS payload in it.

EPSS: Низкий
github логотип

GHSA-3wmq-8jfx-8qrm

больше 3 лет назад

The get_results() and get_items() functions in the Survey Maker WordPress plugin before 1.5.6 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard

EPSS: Низкий
github логотип

GHSA-3wmp-g7x5-v6hv

около 3 лет назад

In all versions, BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-3wmp-c58m-j32f

больше 3 лет назад

OTRS 3.1.x before 3.1.21, 3.2.x before 3.2.16, and 3.3.x before 3.3.6 allows remote attackers to conduct clickjacking attacks via an IFRAME element.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3wp7-mj2q-x6q3

RIOT-OS 2021.01 before commit 85da504d2dc30188b89f44c3276fc5a25b31251f contains a buffer overflow which could allow attackers to obtain sensitive information.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wp7-47p5-gxmr

Clearswift MAILsweeper for SMTP before 4.3_13 allows remote attackers to cause a denial of service (infinite loop) via an e-mail with a crafted RAR archive attached.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3wp6-w2rj-8433

Crypto++ 5.6.4 incorrectly uses Microsoft's stack-based _malloca and _freea functions. The library will request a block of memory to align a table in memory. If the table is later reallocated, then the wrong pointer could be freed.

CVSS3: 7.5
3%
Низкий
больше 3 лет назад
github логотип
GHSA-3wp6-9w98-mc5j

The Mollom module 6.x-2.7 before 6.x-2.15 for Drupal allows remote attackers to bypass intended access restrictions and modify the mollom blacklist via unspecified vectors.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wp5-gwjr-7mpv

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow a local user to cause a denial of service due to improper neutralization of special elements in data query logic.

CVSS3: 6.5
0%
Низкий
9 дней назад
github логотип
GHSA-3wp5-cvp4-5h42

The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can be triggered by an unrelated self-signed CA certificate sent by an initiator. Remote code execution cannot occur.

CVSS3: 7.5
3%
Низкий
больше 3 лет назад
github логотип
GHSA-3wp4-6pwm-vcxj

Buffer overflow in the polymorphic opcode support in the Regular Expression Engine (regcomp.c) in Perl 5.8 allows context-dependent attackers to execute arbitrary code by switching from byte to Unicode (UTF) characters in a regular expression.

11%
Средний
почти 4 года назад
github логотип
GHSA-3wp3-9r5c-77fc

IBM Maximo Asset Management 7.6.1.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 170961.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3wp3-9f4h-fqwh

IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.2 and IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the Admin Console to become unresponsive. IBM X-Force ID: 220485.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-3wmx-fc2q-p8g5

A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition when the device unexpectedly reloads. The vulnerability is due to improper input validation of certain type, length, value (TLV) fields of the LLDP frame header. An attacker could exploit this vulnerability by sending a crafted LLDP packet to an interface on the targeted device. A successful exploit could allow the attacker to cause the switch to reload unexpectedly.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wmx-9qwp-h363

Duplicate Advisory: EVE Doesn't Protect Config Partition with Measured Boot

CVSS3: 8.8
больше 2 лет назад
github логотип
GHSA-3wmx-48g3-x66g

Backdrop CMS does not sufficiently sanitize field labels before they are displayed in certain places

CVSS3: 4.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3wmw-g879-9gp5

SQL injection vulnerability in escribir.php in Foro Domus 2.10 allows remote attackers to execute arbitrary SQL commands via the email parameter. NOTE: the provenance of this information is unknown, although it may be based on post-disclosure analysis of CVE-2006-0110; the details are obtained solely from third party information.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3wmv-phhj-q327

A CWE-787: Out-of-bounds Write vulnerability exists that could cause a denial of service of the webserver due to improper parsing of the HTTP Headers. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V1.0), OPC UA Modicon Communication Module (BMENUA0100) (V1.10 and prior)

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3wmv-7php-rhg5

Jenkins Vulnerable to Cross-Site Request Forgery (CSRF) Attack

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wmv-527f-7jxv

An exploitable use of an uninitialized pointer vulnerability exists in the JavaScript engine in Foxit PDF Reader version 9.0.1.1049. A specially crafted PDF document can lead to a dereference of an uninitialized pointer which, if under attacker control, can result in arbitrary code execution. An attacker needs to trick the user to open a malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

CVSS3: 8.8
4%
Низкий
больше 3 лет назад
github логотип
GHSA-3wmq-h2jq-wfgw

The SupportCandy WordPress plugin before 2.2.7 does not have CSRF check in the wpsc_tickets AJAX action, nor has any sanitisation or escaping in some of the filter fields which could allow attackers to make a logged in user having access to the ticket lists dashboard set an arbitrary filter (stored in their cookies) with an XSS payload in it.

0%
Низкий
около 4 лет назад
github логотип
GHSA-3wmq-8jfx-8qrm

The get_results() and get_items() functions in the Survey Maker WordPress plugin before 1.5.6 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3wmp-g7x5-v6hv

In all versions, BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 8.8
70%
Средний
около 3 лет назад
github логотип
GHSA-3wmp-c58m-j32f

OTRS 3.1.x before 3.1.21, 3.2.x before 3.2.16, and 3.3.x before 3.3.6 allows remote attackers to conduct clickjacking attacks via an IFRAME element.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу