Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3whq-m5gj-947w

больше 3 лет назад

A vulnerability was found when an attacker, while communicating with the ClearPass management interface, is able to intercept and change parameters in the HTTP packets resulting in the compromise of some of ClearPass' service accounts. Resolution: Fixed in 6.7.10, 6.8.1, 6.9.0 and higher.

EPSS: Низкий
github логотип

GHSA-3whq-64q2-qfj6

почти 2 года назад

vyper performs double eval of raw_args in create_from_blueprint

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3whp-4394-49gc

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: tools/power turbostat: Fix offset overflow issue in index converting The idx_to_offset() function returns type int (32-bit signed), but MSR_PKG_ENERGY_STAT is u32 and would be interpreted as a negative number. The end result is that it hits the if (offset < 0) check in update_msr_sum() which prevents the timer callback from updating the stat in the background when long durations are used. The similar issue exists in offset_to_idx() and update_msr_sum(). Fix this issue by converting the 'int' to 'off_t' accordingly.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3whm-j4xm-rv8x

около 1 года назад

Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Due to the way this function is used, we do not believe this leakage is enough to allow recovery of the private key when P-256 is used in any well known protocols.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-3whj-7m92-7898

почти 4 года назад

SQL injection vulnerability in artreplydelete.asp in ASP EDGE 1.3a and earlier allows remote attackers to execute arbitrary SQL commands via a username cookie, a different vector than CVE-2007-0560.

EPSS: Низкий
github логотип

GHSA-3whc-pgh2-hhm5

5 месяцев назад

In multiple locations, there is a possible way to record audio via a background app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3whc-2jm3-w8gr

больше 2 лет назад

Code Injection in GitHub repository openemr/openemr prior to 7.0.1.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-3wh9-2fg7-9h5g

около 2 лет назад

Information disclosure in Audio while accessing AVCS services from ADSP payload.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3wh7-f7pv-9353

больше 3 лет назад

In OpenNMS Horizon, versions opennms-17.0.0-1 through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.7-1 are vulnerable to Stored Cross-Site Scripting, since the function `add()` performs improper validation checks on the input sent to the `foreign-source` parameter. Due to this flaw an attacker could bypass the existing regex validation and inject an arbitrary script which will be stored in the database.

EPSS: Низкий
github логотип

GHSA-3wh7-58hp-h69w

больше 3 лет назад

The Reviews Module before 2019-06-14 for OpenSource Table allows SQL injection in database/index.js.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3wh6-j4g5-pq88

около 1 года назад

Insertion of Sensitive Information Into Sent Data vulnerability in Code for Recovery 12 Step Meeting List allows Retrieve Embedded Sensitive Data. This issue affects 12 Step Meeting List: from n/a through 3.16.5.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3wh6-h4gj-wjr7

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: spi: bcm2835: Fix out-of-bounds access with more than 4 slaves Commit 571e31fa60b3 ("spi: bcm2835: Cache CS register value for ->prepare_message()") limited the number of slaves to 3 at compile-time. The limitation was necessitated by a statically-sized array prepare_cs[] in the driver private data which contains a per-slave register value. The commit sought to enforce the limitation at run-time by setting the controller's num_chipselect to 3: Slaves with a higher chipselect are rejected by spi_add_device(). However the commit neglected that num_chipselect only limits the number of *native* chipselects. If GPIO chipselects are specified in the device tree for more than 3 slaves, num_chipselect is silently raised by of_spi_get_gpio_numbers() and the result are out-of-bounds accesses to the statically-sized array prepare_cs[]. As a bandaid fix which is backportable to stable, raise the number of allowed slaves ...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3wh6-ghqv-v6wx

около 2 лет назад

IrfanView B3D PlugIns before version 4.56 has a B3d.dll!+214f heap-based out-of-bounds write.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3wh6-3gw8-2734

почти 4 года назад

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic was found in WEKA INTEREST Security Scanner up to 1.8. Affected by this vulnerability is the Stresstest Configuration Handler. A manipulation leads to a local denial of service. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3wh5-mq76-rf8p

больше 3 лет назад

Object lifecycle issue in WebAssembly in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

EPSS: Низкий
github логотип

GHSA-3wh5-4rmj-5jxh

почти 4 года назад

R2 Newsletter Lite, Pro, and Stats stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for admin.mdb.

EPSS: Низкий
github логотип

GHSA-3wh4-9fpj-4gx2

почти 4 года назад

Directory traversal vulnerability in p.php in SlideShowPro Director 1.1 through 1.3.8 allows remote attackers to read arbitrary files via directory traversal sequences in the a parameter.

EPSS: Низкий
github логотип

GHSA-3wh4-59gj-xv6c

больше 3 лет назад

Use-after-free vulnerability in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via run-in styling in an element, related to object pointers.

EPSS: Низкий
github логотип

GHSA-3wh3-p2p8-722q

больше 3 лет назад

The Custom 404 Pro plugin 3.2.8 for WordPress has XSS via the wp-admin/admin.php?page=c4p-main page parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3wh2-rmg9-wx2r

больше 2 лет назад

In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07453589; Issue ID: ALPS07453589.

CVSS3: 6.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3whq-m5gj-947w

A vulnerability was found when an attacker, while communicating with the ClearPass management interface, is able to intercept and change parameters in the HTTP packets resulting in the compromise of some of ClearPass' service accounts. Resolution: Fixed in 6.7.10, 6.8.1, 6.9.0 and higher.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3whq-64q2-qfj6

vyper performs double eval of raw_args in create_from_blueprint

CVSS3: 5.3
1%
Низкий
почти 2 года назад
github логотип
GHSA-3whp-4394-49gc

In the Linux kernel, the following vulnerability has been resolved: tools/power turbostat: Fix offset overflow issue in index converting The idx_to_offset() function returns type int (32-bit signed), but MSR_PKG_ENERGY_STAT is u32 and would be interpreted as a negative number. The end result is that it hits the if (offset < 0) check in update_msr_sum() which prevents the timer callback from updating the stat in the background when long durations are used. The similar issue exists in offset_to_idx() and update_msr_sum(). Fix this issue by converting the 'int' to 'off_t' accordingly.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-3whm-j4xm-rv8x

Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Due to the way this function is used, we do not believe this leakage is enough to allow recovery of the private key when P-256 is used in any well known protocols.

CVSS3: 8.4
0%
Низкий
около 1 года назад
github логотип
GHSA-3whj-7m92-7898

SQL injection vulnerability in artreplydelete.asp in ASP EDGE 1.3a and earlier allows remote attackers to execute arbitrary SQL commands via a username cookie, a different vector than CVE-2007-0560.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3whc-pgh2-hhm5

In multiple locations, there is a possible way to record audio via a background app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-3whc-2jm3-w8gr

Code Injection in GitHub repository openemr/openemr prior to 7.0.1.

CVSS3: 4.6
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3wh9-2fg7-9h5g

Information disclosure in Audio while accessing AVCS services from ADSP payload.

CVSS3: 6.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-3wh7-f7pv-9353

In OpenNMS Horizon, versions opennms-17.0.0-1 through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.7-1 are vulnerable to Stored Cross-Site Scripting, since the function `add()` performs improper validation checks on the input sent to the `foreign-source` parameter. Due to this flaw an attacker could bypass the existing regex validation and inject an arbitrary script which will be stored in the database.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wh7-58hp-h69w

The Reviews Module before 2019-06-14 for OpenSource Table allows SQL injection in database/index.js.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wh6-j4g5-pq88

Insertion of Sensitive Information Into Sent Data vulnerability in Code for Recovery 12 Step Meeting List allows Retrieve Embedded Sensitive Data. This issue affects 12 Step Meeting List: from n/a through 3.16.5.

CVSS3: 5.3
0%
Низкий
около 1 года назад
github логотип
GHSA-3wh6-h4gj-wjr7

In the Linux kernel, the following vulnerability has been resolved: spi: bcm2835: Fix out-of-bounds access with more than 4 slaves Commit 571e31fa60b3 ("spi: bcm2835: Cache CS register value for ->prepare_message()") limited the number of slaves to 3 at compile-time. The limitation was necessitated by a statically-sized array prepare_cs[] in the driver private data which contains a per-slave register value. The commit sought to enforce the limitation at run-time by setting the controller's num_chipselect to 3: Slaves with a higher chipselect are rejected by spi_add_device(). However the commit neglected that num_chipselect only limits the number of *native* chipselects. If GPIO chipselects are specified in the device tree for more than 3 slaves, num_chipselect is silently raised by of_spi_get_gpio_numbers() and the result are out-of-bounds accesses to the statically-sized array prepare_cs[]. As a bandaid fix which is backportable to stable, raise the number of allowed slaves ...

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3wh6-ghqv-v6wx

IrfanView B3D PlugIns before version 4.56 has a B3d.dll!+214f heap-based out-of-bounds write.

CVSS3: 9.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-3wh6-3gw8-2734

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic was found in WEKA INTEREST Security Scanner up to 1.8. Affected by this vulnerability is the Stresstest Configuration Handler. A manipulation leads to a local denial of service. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-3wh5-mq76-rf8p

Object lifecycle issue in WebAssembly in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wh5-4rmj-5jxh

R2 Newsletter Lite, Pro, and Stats stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for admin.mdb.

4%
Низкий
почти 4 года назад
github логотип
GHSA-3wh4-9fpj-4gx2

Directory traversal vulnerability in p.php in SlideShowPro Director 1.1 through 1.3.8 allows remote attackers to read arbitrary files via directory traversal sequences in the a parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3wh4-59gj-xv6c

Use-after-free vulnerability in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via run-in styling in an element, related to object pointers.

5%
Низкий
больше 3 лет назад
github логотип
GHSA-3wh3-p2p8-722q

The Custom 404 Pro plugin 3.2.8 for WordPress has XSS via the wp-admin/admin.php?page=c4p-main page parameter.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3wh2-rmg9-wx2r

In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07453589; Issue ID: ALPS07453589.

CVSS3: 6.7
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу