Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 289 610

Количество 289 610

github логотип

GHSA-29mq-6jwf-w4hx

больше 3 лет назад

Heap-based buffer overflow in SW3eng.exe in the eID Engine service in CA (formerly Computer Associates) eTrust Intrusion Detection 3.0.5.57 and earlier allows remote attackers to cause a denial of service (application crash) via a long key length value to the remote administration port (9191/tcp).

EPSS: Низкий
github логотип

GHSA-29mq-29c5-43rg

больше 3 лет назад

The authentication-proxy implementation on Cisco Adaptive Security Appliances (ASA) devices with software 7.x before 7.2(5.10), 8.0 before 8.0(5.31), 8.1 and 8.2 before 8.2(5.38), 8.3 before 8.3(2.37), 8.4 before 8.4(5.3), 8.5 and 8.6 before 8.6(1.10), 8.7 before 8.7(1.4), 9.0 before 9.0(1.1), and 9.1 before 9.1(1.2) allows remote attackers to cause a denial of service (device reload) via a crafted URL, aka Bug ID CSCud16590.

EPSS: Низкий
github логотип

GHSA-29mp-vjf6-73c4

больше 3 лет назад

Buffer overflow in Red Faction client 1.20 and earlier allows remote servers to execute arbitrary code via a long server name.

EPSS: Низкий
github логотип

GHSA-29mp-2hx5-9mm4

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in customreport.jsp in IBM Maximo Asset Management 7.5.x before 7.5.0.5 IFIX006 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified parameters.

EPSS: Низкий
github логотип

GHSA-29mm-w894-gvhw

больше 3 лет назад

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have an integer overflow vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-29mm-6j7g-rc29

5 месяцев назад

The Export and Import Users and Customers plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.6.2 via the download_file() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary log files on the server, which can contain sensitive information.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-29mj-gxqm-6x8c

больше 3 лет назад

ServerAdmin in Mac OS X 10.2.8 through 10.3.5 uses the same example self-signed certificate on each system, which allows remote attackers to decrypt sessions.

EPSS: Низкий
github логотип

GHSA-29mh-w3r4-79cm

почти 3 года назад

Auth. (subscriber+) Cross-Site Scripting (XSS) vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-29mh-jw46-2rf9

около 3 лет назад

A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root. Using their membership to the "adm" group, users with this role are able to read the DHCP XID from the systemd journal. Using the DHCP XID, it is then possible to set the IP address and hostname of the instance to any value, which is then stored in /etc/hosts. An attacker can then point metadata.google.internal to an arbitrary IP address and impersonate the GCE metadata server which make it is possible to instruct the OS Login PAM module to grant administrative privileges. All images created after 2020-May-07 (20200507) are fixed, and if you cannot update, we recommend you edit /etc/group/security.conf and remove the "adm" user from the OS Login entry.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-29mh-h3mm-7r6h

больше 3 лет назад

The HPRulesEngine.ContentCollection.1 ActiveX Control in RulesEngine.dll for HP Software Update 4.000.005.007 and earlier, including 3.0.8.4, allows remote attackers to (1) overwrite and corrupt arbitrary files via arguments to the SaveToFile method, and possibly (2) access arbitrary files via the LoadDataFromFile method.

EPSS: Средний
github логотип

GHSA-29mh-8gx9-q2h8

4 месяца назад

Process residence vulnerability in abnormal scenarios in the print module Impact: Successful exploitation of this vulnerability may affect availability.

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-29mf-g5hc-vfvc

5 месяцев назад

This issue was addressed through improved state management. This issue is fixed in visionOS 1.3, macOS Sonoma 14.6, iOS 17.6 and iPadOS 17.6. A file received from AirDrop may not have the quarantine flag applied.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-29mf-62xx-28jq

около 2 лет назад

buffered-reader vulnerable to out-of-bounds array access leading to panic

CVSS3: 2.9
EPSS: Низкий
github логотип

GHSA-29mc-g84r-w9hv

больше 3 лет назад

Cross-site scripting vulnerability in web administration interface for NetGear RT314 and RT311 Gateway Routers allows remote attackers to execute arbitrary script on another client via a URL that contains the script.

EPSS: Низкий
github логотип

GHSA-29m9-xcwg-fcpv

больше 3 лет назад

Cross-site scripting (XSS) vulnerability on the HP Color LaserJet CM3530 with firmware before 53.190.9, Color LaserJet CM60xx with firmware before 52.210.9, Color LaserJet CP3525 with firmware before 06.140.3 18, Color LaserJet CP4xxx with firmware before 07.120.6, Color LaserJet CP6015 with firmware before 04.160.3, LaserJet P3015 with firmware before 07.140.3, and LaserJet P4xxx with firmware before 04.170.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-29m9-v5vv-jgr7

больше 3 лет назад

A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33818500.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-29m8-wh9p-5wc4

5 месяцев назад

Apache Kylin Code Injection via JDBC Configuration Alteration

EPSS: Низкий
github логотип

GHSA-29m8-q2f8-5742

6 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in jgwhite33 WP Yelp Review Slider allows Blind SQL Injection. This issue affects WP Yelp Review Slider: from n/a through 8.1.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-29m8-hp2v-37qc

около 3 лет назад

The decentraminds/umbral repository through 2020-01-15 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-29m8-fq8p-5fcw

около 3 лет назад

Azure Site Recovery Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-35824.

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-29mq-6jwf-w4hx

Heap-based buffer overflow in SW3eng.exe in the eID Engine service in CA (formerly Computer Associates) eTrust Intrusion Detection 3.0.5.57 and earlier allows remote attackers to cause a denial of service (application crash) via a long key length value to the remote administration port (9191/tcp).

3%
Низкий
больше 3 лет назад
github логотип
GHSA-29mq-29c5-43rg

The authentication-proxy implementation on Cisco Adaptive Security Appliances (ASA) devices with software 7.x before 7.2(5.10), 8.0 before 8.0(5.31), 8.1 and 8.2 before 8.2(5.38), 8.3 before 8.3(2.37), 8.4 before 8.4(5.3), 8.5 and 8.6 before 8.6(1.10), 8.7 before 8.7(1.4), 9.0 before 9.0(1.1), and 9.1 before 9.1(1.2) allows remote attackers to cause a denial of service (device reload) via a crafted URL, aka Bug ID CSCud16590.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-29mp-vjf6-73c4

Buffer overflow in Red Faction client 1.20 and earlier allows remote servers to execute arbitrary code via a long server name.

5%
Низкий
больше 3 лет назад
github логотип
GHSA-29mp-2hx5-9mm4

Cross-site scripting (XSS) vulnerability in customreport.jsp in IBM Maximo Asset Management 7.5.x before 7.5.0.5 IFIX006 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified parameters.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-29mm-w894-gvhw

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have an integer overflow vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 6.5
3%
Низкий
больше 3 лет назад
github логотип
GHSA-29mm-6j7g-rc29

The Export and Import Users and Customers plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.6.2 via the download_file() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary log files on the server, which can contain sensitive information.

CVSS3: 4.9
0%
Низкий
5 месяцев назад
github логотип
GHSA-29mj-gxqm-6x8c

ServerAdmin in Mac OS X 10.2.8 through 10.3.5 uses the same example self-signed certificate on each system, which allows remote attackers to decrypt sessions.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-29mh-w3r4-79cm

Auth. (subscriber+) Cross-Site Scripting (XSS) vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress.

CVSS3: 6.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-29mh-jw46-2rf9

A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root. Using their membership to the "adm" group, users with this role are able to read the DHCP XID from the systemd journal. Using the DHCP XID, it is then possible to set the IP address and hostname of the instance to any value, which is then stored in /etc/hosts. An attacker can then point metadata.google.internal to an arbitrary IP address and impersonate the GCE metadata server which make it is possible to instruct the OS Login PAM module to grant administrative privileges. All images created after 2020-May-07 (20200507) are fixed, and if you cannot update, we recommend you edit /etc/group/security.conf and remove the "adm" user from the OS Login entry.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-29mh-h3mm-7r6h

The HPRulesEngine.ContentCollection.1 ActiveX Control in RulesEngine.dll for HP Software Update 4.000.005.007 and earlier, including 3.0.8.4, allows remote attackers to (1) overwrite and corrupt arbitrary files via arguments to the SaveToFile method, and possibly (2) access arbitrary files via the LoadDataFromFile method.

18%
Средний
больше 3 лет назад
github логотип
GHSA-29mh-8gx9-q2h8

Process residence vulnerability in abnormal scenarios in the print module Impact: Successful exploitation of this vulnerability may affect availability.

CVSS3: 5.1
0%
Низкий
4 месяца назад
github логотип
GHSA-29mf-g5hc-vfvc

This issue was addressed through improved state management. This issue is fixed in visionOS 1.3, macOS Sonoma 14.6, iOS 17.6 and iPadOS 17.6. A file received from AirDrop may not have the quarantine flag applied.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-29mf-62xx-28jq

buffered-reader vulnerable to out-of-bounds array access leading to panic

CVSS3: 2.9
0%
Низкий
около 2 лет назад
github логотип
GHSA-29mc-g84r-w9hv

Cross-site scripting vulnerability in web administration interface for NetGear RT314 and RT311 Gateway Routers allows remote attackers to execute arbitrary script on another client via a URL that contains the script.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-29m9-xcwg-fcpv

Cross-site scripting (XSS) vulnerability on the HP Color LaserJet CM3530 with firmware before 53.190.9, Color LaserJet CM60xx with firmware before 52.210.9, Color LaserJet CP3525 with firmware before 06.140.3 18, Color LaserJet CP4xxx with firmware before 07.120.6, Color LaserJet CP6015 with firmware before 04.160.3, LaserJet P3015 with firmware before 07.140.3, and LaserJet P4xxx with firmware before 04.170.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-29m9-v5vv-jgr7

A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33818500.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-29m8-wh9p-5wc4

Apache Kylin Code Injection via JDBC Configuration Alteration

0%
Низкий
5 месяцев назад
github логотип
GHSA-29m8-q2f8-5742

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in jgwhite33 WP Yelp Review Slider allows Blind SQL Injection. This issue affects WP Yelp Review Slider: from n/a through 8.1.

CVSS3: 7.6
0%
Низкий
6 месяцев назад
github логотип
GHSA-29m8-hp2v-37qc

The decentraminds/umbral repository through 2020-01-15 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

CVSS3: 9.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-29m8-fq8p-5fcw

Azure Site Recovery Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-35824.

CVSS3: 7.2
2%
Низкий
около 3 лет назад

Уязвимостей на страницу