Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 289 610

Количество 289 610

github логотип

GHSA-29m8-82c7-qqgx

больше 3 лет назад

Multiple SQL injection vulnerabilities in Avanset Visual CertExam Manager 3.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) Title, (2) File name, or (3) Candidate Name field.

EPSS: Низкий
github логотип

GHSA-29m7-frx3-67fg

около 3 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the Tomcat configuration file. The issue results from the lack of proper restriction to the Tomcat admin console. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-10799.

EPSS: Низкий
github логотип

GHSA-29m7-62mp-2jf6

больше 3 лет назад

Vulnerability in pppd on UnixWare 7.1.1 and Open UNIX 8.0.0 allows local users to gain root privileges via (1) ppptalk or (2) ppp, a different vulnerability than CVE-2002-0824.

EPSS: Низкий
github логотип

GHSA-29m7-5q7x-g3fr

почти 2 года назад

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ezoic AmpedSense – AdSense Split Tester plugin <= 4.68 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-29m6-68fv-pgx2

больше 3 лет назад

Apache Traffic Server before 2.0.1, and 2.1.x before 2.1.2-unstable, does not properly choose DNS source ports and transaction IDs, and does not properly use DNS query fields to validate responses, which makes it easier for man-in-the-middle attackers to poison the internal DNS cache via a crafted response.

EPSS: Низкий
github логотип

GHSA-29m4-mx89-3mjg

около 1 года назад

TYPO3 Denial of Service in Online Media Asset Handling

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-29m4-8vqj-fpfg

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in webmailaging.cgi in cPanel allows remote attackers to inject arbitrary web script or HTML via the numdays parameter.

EPSS: Низкий
github логотип

GHSA-29m3-xwpr-p76m

около 3 лет назад

In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in strncpy from FoFiType1::parse in fofi/FoFiType1.cc because it does not ensure the source string has a valid length before making a fixed-length copy. It can, for example, be triggered by sending a crafted PDF document to the pdftotext tool. It allows an attacker to use a crafted pdf file to cause Denial of Service or an information leak, or possibly have unspecified other impact.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-29m2-jvgj-wx83

около 3 лет назад

Tenda AC10 US_AC10V1.0RTL_V15.03.06.26_multi_TD01 was discovered to contain a remote code execution (RCE) vulnerability via the lanIp parameter.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-29m2-93j9-hrcp

больше 3 лет назад

VMware ESXi (6.7, 6.5, 6.0), Workstation (15.x and 14.x) and Fusion (11.x and 10.x) contain a denial-of-service vulnerability due to an infinite loop in a 3D-rendering shader. Successfully exploiting this issue may allow an attacker with normal user privileges in the guest to make the VM unresponsive, and in some cases, possibly result other VMs on the host or the host itself becoming unresponsive.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-29jx-h9vr-rw83

около 3 лет назад

In createSimSelectNotification of SimSelectNotification.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153556754

EPSS: Низкий
github логотип

GHSA-29jw-cm22-w2mv

больше 3 лет назад

regexp.c in Artifex Software, Inc. MuJS allows attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to regular expression compilation.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-29jw-9pjp-p7x2

больше 3 лет назад

An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a /dev/dtracehelper attack involving the dtrace_dif_variable and dtrace_getarg functions.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-29jw-6xvq-m442

больше 3 лет назад

The 'fmt' parameter of the '/common/run_cross_report.php' script in the the Quest KACE System Management Appliance 8.0.318 is vulnerable to cross-site scripting.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-29jr-vwj5-q6gc

5 месяцев назад

Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-29jr-72j5-7p98

около 3 лет назад

An exploitable SQL injection vulnerability exists in ‘manageServiceStocks.jsp’ page of OpenClinic GA 5.173.3. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-29jr-2926-3w9p

около 3 лет назад

A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root. Using the membership to the "lxd" group, an attacker can attach host devices and filesystems. Within an lxc container, it is possible to attach the host OS filesystem and modify /etc/sudoers to then gain administrative privileges. All images created after 2020-May-07 (20200507) are fixed, and if you cannot update, we recommend you edit /etc/group/security.conf and remove the "lxd" user from the OS Login entry.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-29jq-4wjw-g2qv

больше 3 лет назад

Jerryscript 3.0.0 was discovered to contain a stack overflow via ecma_op_object_find_own in /ecma/operations/ecma-objects.c.

EPSS: Низкий
github логотип

GHSA-29jj-q7xf-wj3r

5 месяцев назад

Generation of Error Message Containing Sensitive Information vulnerability in Hillstone Networks Hillstone Next Generation FireWall.This issue affects Hillstone Next Generation FireWall: from 5.5R8P1 before 5.5R8P23.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-29jj-q7hj-hfcf

больше 3 лет назад

An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php logo_width parameter.

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-29m8-82c7-qqgx

Multiple SQL injection vulnerabilities in Avanset Visual CertExam Manager 3.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) Title, (2) File name, or (3) Candidate Name field.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-29m7-frx3-67fg

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the Tomcat configuration file. The issue results from the lack of proper restriction to the Tomcat admin console. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-10799.

5%
Низкий
около 3 лет назад
github логотип
GHSA-29m7-62mp-2jf6

Vulnerability in pppd on UnixWare 7.1.1 and Open UNIX 8.0.0 allows local users to gain root privileges via (1) ppptalk or (2) ppp, a different vulnerability than CVE-2002-0824.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-29m7-5q7x-g3fr

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ezoic AmpedSense – AdSense Split Tester plugin <= 4.68 versions.

CVSS3: 7.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-29m6-68fv-pgx2

Apache Traffic Server before 2.0.1, and 2.1.x before 2.1.2-unstable, does not properly choose DNS source ports and transaction IDs, and does not properly use DNS query fields to validate responses, which makes it easier for man-in-the-middle attackers to poison the internal DNS cache via a crafted response.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-29m4-mx89-3mjg

TYPO3 Denial of Service in Online Media Asset Handling

CVSS3: 5.3
около 1 года назад
github логотип
GHSA-29m4-8vqj-fpfg

Cross-site scripting (XSS) vulnerability in webmailaging.cgi in cPanel allows remote attackers to inject arbitrary web script or HTML via the numdays parameter.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-29m3-xwpr-p76m

In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in strncpy from FoFiType1::parse in fofi/FoFiType1.cc because it does not ensure the source string has a valid length before making a fixed-length copy. It can, for example, be triggered by sending a crafted PDF document to the pdftotext tool. It allows an attacker to use a crafted pdf file to cause Denial of Service or an information leak, or possibly have unspecified other impact.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-29m2-jvgj-wx83

Tenda AC10 US_AC10V1.0RTL_V15.03.06.26_multi_TD01 was discovered to contain a remote code execution (RCE) vulnerability via the lanIp parameter.

CVSS3: 9.8
22%
Средний
около 3 лет назад
github логотип
GHSA-29m2-93j9-hrcp

VMware ESXi (6.7, 6.5, 6.0), Workstation (15.x and 14.x) and Fusion (11.x and 10.x) contain a denial-of-service vulnerability due to an infinite loop in a 3D-rendering shader. Successfully exploiting this issue may allow an attacker with normal user privileges in the guest to make the VM unresponsive, and in some cases, possibly result other VMs on the host or the host itself becoming unresponsive.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-29jx-h9vr-rw83

In createSimSelectNotification of SimSelectNotification.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153556754

0%
Низкий
около 3 лет назад
github логотип
GHSA-29jw-cm22-w2mv

regexp.c in Artifex Software, Inc. MuJS allows attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to regular expression compilation.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-29jw-9pjp-p7x2

An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a /dev/dtracehelper attack involving the dtrace_dif_variable and dtrace_getarg functions.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-29jw-6xvq-m442

The 'fmt' parameter of the '/common/run_cross_report.php' script in the the Quest KACE System Management Appliance 8.0.318 is vulnerable to cross-site scripting.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-29jr-vwj5-q6gc

Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-29jr-72j5-7p98

An exploitable SQL injection vulnerability exists in ‘manageServiceStocks.jsp’ page of OpenClinic GA 5.173.3. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVSS3: 8.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-29jr-2926-3w9p

A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root. Using the membership to the "lxd" group, an attacker can attach host devices and filesystems. Within an lxc container, it is possible to attach the host OS filesystem and modify /etc/sudoers to then gain administrative privileges. All images created after 2020-May-07 (20200507) are fixed, and if you cannot update, we recommend you edit /etc/group/security.conf and remove the "lxd" user from the OS Login entry.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-29jq-4wjw-g2qv

Jerryscript 3.0.0 was discovered to contain a stack overflow via ecma_op_object_find_own in /ecma/operations/ecma-objects.c.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-29jj-q7xf-wj3r

Generation of Error Message Containing Sensitive Information vulnerability in Hillstone Networks Hillstone Next Generation FireWall.This issue affects Hillstone Next Generation FireWall: from 5.5R8P1 before 5.5R8P23.

CVSS3: 5.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-29jj-q7hj-hfcf

An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php logo_width parameter.

CVSS3: 4.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу