Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3wf8-8777-h28j

больше 2 лет назад

An issue was discovered Binutils objdump before 2.39.3 allows attackers to cause a denial of service or other unspecified impacts via function compare_symbols.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3wf8-838v-4qxv

больше 3 лет назад

The PPB_Flash_MessageLoop_Impl::InternalRun function in content/renderer/pepper/ppb_flash_message_loop_impl.cc in the Pepper plugin in Google Chrome before 49.0.2623.75 mishandles nested message loops, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3wf7-ph6r-pvj6

почти 4 года назад

page.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the url parameter.

EPSS: Низкий
github логотип

GHSA-3wf7-83q3-948c

12 месяцев назад

Remote code execution in alextselegidis/easyappointments

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3wf6-qrm5-g4cj

больше 3 лет назад

Off-by-one error in named in ISC BIND 9.x before 9.7.3-P1, 9.8.x before 9.8.0-P2, 9.4-ESV before 9.4-ESV-R4-P1, and 9.6-ESV before 9.6-ESV-R4-P1 allows remote DNS servers to cause a denial of service (assertion failure and daemon exit) via a negative response containing large RRSIG RRsets.

EPSS: Средний
github логотип

GHSA-3wf6-phm6-xcr4

больше 3 лет назад

The Network Threat Protection module in the Manager component in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.700x on Windows Server 2003 allows remote attackers to cause a denial of service (web-server outage, or daemon crash or hang) via a flood of packets that triggers automated blocking of network traffic.

EPSS: Низкий
github логотип

GHSA-3wf6-gcrx-pm3g

почти 4 года назад

Untrusted search path vulnerability in day5datacopier in SGI IRIX 6.2 allows local users to execute arbitrary commands via a modified PATH environment variable that points to a malicious cp program.

EPSS: Низкий
github логотип

GHSA-3wf6-8fcq-f34q

около 2 лет назад

The Biteship: Plugin Ongkos Kirim Kurir Instant, Reguler, Kargo WordPress plugin before 2.2.25 does not sanitise and escape the biteship_error and biteship_message parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3wf5-cgv3-f3xm

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: wifi: carl9170: re-fix fortified-memset warning The carl9170_tx_release() function sometimes triggers a fortified-memset warning in my randconfig builds: In file included from include/linux/string.h:254, from drivers/net/wireless/ath/carl9170/tx.c:40: In function 'fortify_memset_chk', inlined from 'carl9170_tx_release' at drivers/net/wireless/ath/carl9170/tx.c:283:2, inlined from 'kref_put' at include/linux/kref.h:65:3, inlined from 'carl9170_tx_put_skb' at drivers/net/wireless/ath/carl9170/tx.c:342:9: include/linux/fortify-string.h:493:25: error: call to '__write_overflow_field' declared with attribute warning: detected write beyond size of field (1st parameter); maybe use struct_group()? [-Werror=attribute-warning] 493 | __write_overflow_field(p_size_field, size); Kees previously tried to avoid this by using memset_after(), but it seems this does not fully...

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-3wf5-983h-ccwq

больше 3 лет назад

An Origin Validation Error vulnerability in Bitdefender Safepay allows an attacker to manipulate the browser's file upload capability into accessing other files in the same directory or sub-directories. This issue affects: Bitdefender Safepay versions prior to 25.0.7.29.

EPSS: Низкий
github логотип

GHSA-3wf4-68gx-mph8

около 1 года назад

Firebase JavaScript SDK allows attackers to manipulate the "_authTokenSyncURL" to point to their own server

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3wf3-9vwr-cm6w

больше 1 года назад

A vulnerability, which was classified as critical, was found in Kashipara College Management System 1.0. Affected is an unknown function of the file delete_faculty.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263928.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3wf3-3cc5-7887

больше 3 лет назад

An issue was discovered in cmft through 2017-09-24. The cmft::rwReadFile function in image.cpp allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3wf3-2hqv-7qjg

почти 4 года назад

Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that HTML pathnames are located in a registered help book, which allows remote attackers to execute arbitrary code via a help: URL that triggers invocation of AppleScript files.

EPSS: Низкий
github логотип

GHSA-3wf2-vcwv-gqjp

больше 3 лет назад

Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."

EPSS: Средний
github логотип

GHSA-3wf2-8r42-5jxv

больше 3 лет назад

SQL injection vulnerability in reports.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the delreport parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3wf2-2pq4-4rvc

больше 1 года назад

Woodpecker's custom environment variables allow to alter execution flow of plugins

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3wcx-x5mh-phrw

около 1 года назад

The Custom Login Page Styler – Limit Login Attempts – Restrict Content With Login – Redirect After Login – Change Login URL – Sign in , Sign out plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the lps_handle_delete_all_logs(), lps_handle_delete_login_log(), and lps_handle_end_session() functions in all versions up to, and including, 7.1.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete login logs and end user sessions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3wcx-w5qh-8gcx

около 3 лет назад

The WP VR WordPress plugin before 8.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3wcx-6cxr-rw7f

почти 4 года назад

Unspecified vulnerability in Sybase/Financial Fusion Consumer Banking Suite versions before 20060706 has unknown impact and remote attack vectors.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3wf8-8777-h28j

An issue was discovered Binutils objdump before 2.39.3 allows attackers to cause a denial of service or other unspecified impacts via function compare_symbols.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3wf8-838v-4qxv

The PPB_Flash_MessageLoop_Impl::InternalRun function in content/renderer/pepper/ppb_flash_message_loop_impl.cc in the Pepper plugin in Google Chrome before 49.0.2623.75 mishandles nested message loops, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3wf7-ph6r-pvj6

page.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the url parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3wf7-83q3-948c

Remote code execution in alextselegidis/easyappointments

CVSS3: 6.1
0%
Низкий
12 месяцев назад
github логотип
GHSA-3wf6-qrm5-g4cj

Off-by-one error in named in ISC BIND 9.x before 9.7.3-P1, 9.8.x before 9.8.0-P2, 9.4-ESV before 9.4-ESV-R4-P1, and 9.6-ESV before 9.6-ESV-R4-P1 allows remote DNS servers to cause a denial of service (assertion failure and daemon exit) via a negative response containing large RRSIG RRsets.

34%
Средний
больше 3 лет назад
github логотип
GHSA-3wf6-phm6-xcr4

The Network Threat Protection module in the Manager component in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.700x on Windows Server 2003 allows remote attackers to cause a denial of service (web-server outage, or daemon crash or hang) via a flood of packets that triggers automated blocking of network traffic.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-3wf6-gcrx-pm3g

Untrusted search path vulnerability in day5datacopier in SGI IRIX 6.2 allows local users to execute arbitrary commands via a modified PATH environment variable that points to a malicious cp program.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3wf6-8fcq-f34q

The Biteship: Plugin Ongkos Kirim Kurir Instant, Reguler, Kargo WordPress plugin before 2.2.25 does not sanitise and escape the biteship_error and biteship_message parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVSS3: 6.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-3wf5-cgv3-f3xm

In the Linux kernel, the following vulnerability has been resolved: wifi: carl9170: re-fix fortified-memset warning The carl9170_tx_release() function sometimes triggers a fortified-memset warning in my randconfig builds: In file included from include/linux/string.h:254, from drivers/net/wireless/ath/carl9170/tx.c:40: In function 'fortify_memset_chk', inlined from 'carl9170_tx_release' at drivers/net/wireless/ath/carl9170/tx.c:283:2, inlined from 'kref_put' at include/linux/kref.h:65:3, inlined from 'carl9170_tx_put_skb' at drivers/net/wireless/ath/carl9170/tx.c:342:9: include/linux/fortify-string.h:493:25: error: call to '__write_overflow_field' declared with attribute warning: detected write beyond size of field (1st parameter); maybe use struct_group()? [-Werror=attribute-warning] 493 | __write_overflow_field(p_size_field, size); Kees previously tried to avoid this by using memset_after(), but it seems this does not fully...

CVSS3: 8.2
0%
Низкий
больше 1 года назад
github логотип
GHSA-3wf5-983h-ccwq

An Origin Validation Error vulnerability in Bitdefender Safepay allows an attacker to manipulate the browser's file upload capability into accessing other files in the same directory or sub-directories. This issue affects: Bitdefender Safepay versions prior to 25.0.7.29.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wf4-68gx-mph8

Firebase JavaScript SDK allows attackers to manipulate the "_authTokenSyncURL" to point to their own server

CVSS3: 5.3
0%
Низкий
около 1 года назад
github логотип
GHSA-3wf3-9vwr-cm6w

A vulnerability, which was classified as critical, was found in Kashipara College Management System 1.0. Affected is an unknown function of the file delete_faculty.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263928.

CVSS3: 6.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-3wf3-3cc5-7887

An issue was discovered in cmft through 2017-09-24. The cmft::rwReadFile function in image.cpp allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wf3-2hqv-7qjg

Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that HTML pathnames are located in a registered help book, which allows remote attackers to execute arbitrary code via a help: URL that triggers invocation of AppleScript files.

4%
Низкий
почти 4 года назад
github логотип
GHSA-3wf2-vcwv-gqjp

Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."

18%
Средний
больше 3 лет назад
github логотип
GHSA-3wf2-8r42-5jxv

SQL injection vulnerability in reports.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the delreport parameter.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3wf2-2pq4-4rvc

Woodpecker's custom environment variables allow to alter execution flow of plugins

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3wcx-x5mh-phrw

The Custom Login Page Styler – Limit Login Attempts – Restrict Content With Login – Redirect After Login – Change Login URL – Sign in , Sign out plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the lps_handle_delete_all_logs(), lps_handle_delete_login_log(), and lps_handle_end_session() functions in all versions up to, and including, 7.1.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete login logs and end user sessions.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-3wcx-w5qh-8gcx

The WP VR WordPress plugin before 8.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-3wcx-6cxr-rw7f

Unspecified vulnerability in Sybase/Financial Fusion Consumer Banking Suite versions before 20060706 has unknown impact and remote attack vectors.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу