Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3wjp-mcmp-h4xw

больше 3 лет назад

Directory traversal vulnerability in filesys in Cisco NX-OS 6.1(2) and earlier allows local users to access arbitrary files via crafted command-line arguments during a delete action, aka Bug IDs CSCty07270, CSCty07271, CSCty07273, and CSCty07275.

EPSS: Низкий
github логотип

GHSA-3wjp-7h53-cfv8

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix hang in usb_kill_urb by adding memory barriers The syzbot fuzzer has identified a bug in which processes hang waiting for usb_kill_urb() to return. It turns out the issue is not unlinking the URB; that works just fine. Rather, the problem arises when the wakeup notification that the URB has completed is not received. The reason is memory-access ordering on SMP systems. In outline form, usb_kill_urb() and __usb_hcd_giveback_urb() operating concurrently on different CPUs perform the following actions: CPU 0 CPU 1 ---------------------------- --------------------------------- usb_kill_urb(): __usb_hcd_giveback_urb(): ... ... atomic_inc(&urb->reject); atomic_dec(&urb->use_count); ... ... wait_event(usb_kill_urb_queue, atomic_read(&urb->use_count) == 0); if (atomic_read(&urb->reject)) wake_up(&usb_kill_urb_queue); Confining your attention to urb->reject ...

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3wjm-qx5r-4845

почти 2 года назад

Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by an invalid character code in a Type 1 font. The root problem was a bounds check that was being optimized away by modern compilers.

CVSS3: 2.9
EPSS: Низкий
github логотип

GHSA-3wjm-33mw-h388

больше 5 лет назад

Malicious Package in s3asy

EPSS: Низкий
github логотип

GHSA-3wjh-xpx4-2h8c

почти 4 года назад

PHP remote file inclusion vulnerability in survey.inc.php for nabopoll 1.2 allows remote attackers to execute arbitrary PHP code via the path parameter.

EPSS: Низкий
github логотип

GHSA-3wjh-qhxw-f3h6

больше 3 лет назад

Simple Machines Forum (SMF) 2.0.4 allows local file inclusion, with resultant remote code execution, in install.php via ../ directory traversal in the db_type parameter if install.php remains present after installation.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3wjh-7493-7f9f

больше 3 лет назад

Annke N48PBB (Network Video Recorder) products of version 3.4.106 build 200422 and prior are vulnerable to a stack-based buffer overflow, which allows an unauthorized remote attacker to execute arbitrary code with the same privileges as the server user (root).

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3wjh-5vc5-vjrv

около 1 месяца назад

Missing Authorization vulnerability in Extend Themes Vireo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Vireo: from n/a through 1.0.24.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3wjg-cv7j-pjw6

больше 1 года назад

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3wjg-5c66-hpr4

почти 4 года назад

Google Chrome before 2.0.172.37 allows attackers to leverage renderer access to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors that trigger excessive memory allocation.

EPSS: Низкий
github логотип

GHSA-3wjf-h5p8-gcg3

около 2 лет назад

Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3wjc-g785-xjp8

почти 2 года назад

Missing Authorization vulnerability in InspiryThemes RealHomes.This issue affects RealHomes: from n/a through 4.0.2.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3wjc-73w5-99qg

больше 3 лет назад

Unspecified vulnerability in Oracle Java SE 7u97, 8u73, and 8u74 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to the Hotspot sub-component.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3wjc-53m5-ffxg

больше 3 лет назад

IBM Tealeaf Customer Experience 8.7, 8.8, and 9.0.2 could allow a remote attacker under unusual circumstances to read operational data or TLS session state for any active sessions, cause denial of service, or bypass security. IBM X-Force ID: 113999.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3wj9-3xp2-288x

больше 3 лет назад

XSS exists in zzcms v8.3 via the /uploadimg_form.php noshuiyin parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3wj8-vp9h-rm6m

почти 5 лет назад

total.js Remote Code Execution Vulnerability

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3wj8-4g9x-8c59

почти 4 года назад

Cross-site scripting (XSS) vulnerability in SaralBlog 1.0 allows remote attackers to inject arbitrary web script or HTML via a website field in a new comment to view.php, which is not properly handled in the comment function in functions.php.

EPSS: Низкий
github логотип

GHSA-3wj7-jcqx-7j5f

почти 4 года назад

graph_image.php in Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to cause a denial of service (CPU consumption) via a large value of the (1) graph_start or (2) graph_end parameter, different vectors than CVE-2007-3113.

EPSS: Низкий
github логотип

GHSA-3wj7-hv5w-6f2m

больше 3 лет назад

Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Cross-Site Scripting vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3wj7-9qg6-8h3x

больше 3 лет назад

A smart proxy that provides a restful API to various sub-systems of the Foreman is affected by the flaw which can cause a Man-in-the-Middle attack. The FreeIPA module of Foreman smart proxy does not check the SSL certificate, thus, an unauthenticated attacker can perform actions in FreeIPA if certain conditions are met. The highest threat from this flaw is to system confidentiality. This flaw affects Foreman versions before 2.5.0.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3wjp-mcmp-h4xw

Directory traversal vulnerability in filesys in Cisco NX-OS 6.1(2) and earlier allows local users to access arbitrary files via crafted command-line arguments during a delete action, aka Bug IDs CSCty07270, CSCty07271, CSCty07273, and CSCty07275.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wjp-7h53-cfv8

In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix hang in usb_kill_urb by adding memory barriers The syzbot fuzzer has identified a bug in which processes hang waiting for usb_kill_urb() to return. It turns out the issue is not unlinking the URB; that works just fine. Rather, the problem arises when the wakeup notification that the URB has completed is not received. The reason is memory-access ordering on SMP systems. In outline form, usb_kill_urb() and __usb_hcd_giveback_urb() operating concurrently on different CPUs perform the following actions: CPU 0 CPU 1 ---------------------------- --------------------------------- usb_kill_urb(): __usb_hcd_giveback_urb(): ... ... atomic_inc(&urb->reject); atomic_dec(&urb->use_count); ... ... wait_event(usb_kill_urb_queue, atomic_read(&urb->use_count) == 0); if (atomic_read(&urb->reject)) wake_up(&usb_kill_urb_queue); Confining your attention to urb->reject ...

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-3wjm-qx5r-4845

Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by an invalid character code in a Type 1 font. The root problem was a bounds check that was being optimized away by modern compilers.

CVSS3: 2.9
0%
Низкий
почти 2 года назад
github логотип
GHSA-3wjm-33mw-h388

Malicious Package in s3asy

больше 5 лет назад
github логотип
GHSA-3wjh-xpx4-2h8c

PHP remote file inclusion vulnerability in survey.inc.php for nabopoll 1.2 allows remote attackers to execute arbitrary PHP code via the path parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3wjh-qhxw-f3h6

Simple Machines Forum (SMF) 2.0.4 allows local file inclusion, with resultant remote code execution, in install.php via ../ directory traversal in the db_type parameter if install.php remains present after installation.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3wjh-7493-7f9f

Annke N48PBB (Network Video Recorder) products of version 3.4.106 build 200422 and prior are vulnerable to a stack-based buffer overflow, which allows an unauthorized remote attacker to execute arbitrary code with the same privileges as the server user (root).

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3wjh-5vc5-vjrv

Missing Authorization vulnerability in Extend Themes Vireo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Vireo: from n/a through 1.0.24.

CVSS3: 4.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3wjg-cv7j-pjw6

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVSS3: 7.8
7%
Низкий
больше 1 года назад
github логотип
GHSA-3wjg-5c66-hpr4

Google Chrome before 2.0.172.37 allows attackers to leverage renderer access to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors that trigger excessive memory allocation.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3wjf-h5p8-gcg3

Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-3wjc-g785-xjp8

Missing Authorization vulnerability in InspiryThemes RealHomes.This issue affects RealHomes: from n/a through 4.0.2.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-3wjc-73w5-99qg

Unspecified vulnerability in Oracle Java SE 7u97, 8u73, and 8u74 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to the Hotspot sub-component.

CVSS3: 8.1
8%
Низкий
больше 3 лет назад
github логотип
GHSA-3wjc-53m5-ffxg

IBM Tealeaf Customer Experience 8.7, 8.8, and 9.0.2 could allow a remote attacker under unusual circumstances to read operational data or TLS session state for any active sessions, cause denial of service, or bypass security. IBM X-Force ID: 113999.

CVSS3: 8.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3wj9-3xp2-288x

XSS exists in zzcms v8.3 via the /uploadimg_form.php noshuiyin parameter.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wj8-vp9h-rm6m

total.js Remote Code Execution Vulnerability

CVSS3: 9.8
7%
Низкий
почти 5 лет назад
github логотип
GHSA-3wj8-4g9x-8c59

Cross-site scripting (XSS) vulnerability in SaralBlog 1.0 allows remote attackers to inject arbitrary web script or HTML via a website field in a new comment to view.php, which is not properly handled in the comment function in functions.php.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3wj7-jcqx-7j5f

graph_image.php in Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to cause a denial of service (CPU consumption) via a large value of the (1) graph_start or (2) graph_end parameter, different vectors than CVE-2007-3113.

3%
Низкий
почти 4 года назад
github логотип
GHSA-3wj7-hv5w-6f2m

Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Cross-Site Scripting vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3wj7-9qg6-8h3x

A smart proxy that provides a restful API to various sub-systems of the Foreman is affected by the flaw which can cause a Man-in-the-Middle attack. The FreeIPA module of Foreman smart proxy does not check the SSL certificate, thus, an unauthenticated attacker can perform actions in FreeIPA if certain conditions are met. The highest threat from this flaw is to system confidentiality. This flaw affects Foreman versions before 2.5.0.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу