Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 289 529

Количество 289 529

github логотип

GHSA-299c-jvhc-gxj8

больше 1 года назад

Issue summary: Some non-default TLS server configurations can cause unbounded memory growth when processing TLSv1.3 sessions Impact summary: An attacker may exploit certain server configurations to trigger unbounded memory growth that would lead to a Denial of Service This problem can occur in TLSv1.3 if the non-default SSL_OP_NO_TICKET option is being used (but not if early_data support is also configured and the default anti-replay protection is in use). In this case, under certain conditions, the session cache can get into an incorrect state and it will fail to flush properly as it fills. The session cache will continue to grow in an unbounded manner. A malicious client could deliberately create the scenario for this failure to force a Denial of Service. It may also happen by accident in normal operation. This issue only affects TLS servers supporting TLSv1.3. It does not affect TLS clients. The FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue. OpenSSL 1.0.2 is...

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2999-fgm6-2cf3

около 1 года назад

The Houzez Theme - Functionality plugin for WordPress is vulnerable to SQL Injection via the ‘currency_code’ parameter in all versions up to, and including, 3.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Custom-level (seller) access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2998-9vr3-8cqh

7 месяцев назад

Multiple buffer overflow vulnerabilities exist in the internet.cgi set_qos() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.This vulnerability exists in the `cli_mac` POST parameter.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-2997-qmg6-h7g4

около 3 лет назад

SQL Injection vulnerability in MetInfo 7.0.0beta via admin/?n=language&c=language_web&a=doAddLanguage.

EPSS: Низкий
github логотип

GHSA-2997-6fq4-wwch

почти 3 года назад

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, an attacker with local network access could exploit this vulnerability to obtain sensitive data.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2996-wwjj-qp22

около 3 лет назад

OMICARD EDM’s mail image relay function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to by-pass authentication and access arbitrary system files.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2995-x6wq-mq67

около 3 лет назад

NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

EPSS: Низкий
github логотип

GHSA-2995-qwmm-cm3p

больше 2 лет назад

Inappropriate implementation in in iframe Sandbox in Google Chrome prior to 109.0.5414.74 allowed a remote attacker to bypass file download restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2994-xw3p-6772

больше 3 лет назад

Format string vulnerability in the Log_Flush function in Weex 2.6.1.5, 2.6.1, and possibly other versions allows remote FTP servers to execute arbitrary code via format strings in filenames.

EPSS: Низкий
github логотип

GHSA-2994-j274-2gjp

больше 1 года назад

TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to arbitrary command execution in the ‘host_time’ parameter of the NTPSyncWithHost interface of the cstecgi .cgi.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2994-cf23-4hmp

больше 3 лет назад

Mingw-w64 version 5.0.3 and earlier, 5.0.4, 6.0.0 and 7.0.0 contains an Improper Null Termination (CWE-170) vulnerability in mingw-w64-crt (libc)->(v)snprintf that can result in The bug may be used to corrupt subsequent string functions. This attack appear to be exploitable via Depending on the usage, worst case: network.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2993-5qvm-pg7x

около 3 лет назад

In Xpdf 4.01.01, there is a heap-based buffer over-read in the function JBIG2Stream::readTextRegionSeg() located at JBIG2Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It might allow an attacker to cause Information Disclosure.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2992-vffv-8399

больше 3 лет назад

The Inmobi library for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-2992-6547-hhfp

около 3 лет назад

In MB connect line mbDIALUP versions <= 3.9R0.0 a low privileged local attacker can send a command to the service running with NT AUTHORITY\SYSTEM instructing it to execute a malicous OpenVPN configuration resulting in arbitrary code execution with the privileges of the service.

EPSS: Низкий
github логотип

GHSA-2992-3j6w-22hh

почти 2 года назад

Tenda AX3 v16.03.12.11 has a stack buffer overflow vulnerability detected at function form_fast_setting_wifi_set. This vulnerability allows attackers to cause a Denial of Service (DoS) via the ssid parameter.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-298w-pg84-p7jw

6 месяцев назад

The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid. (CWE-502)   Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.9, including 8.3.x, deserialize untrusted JSON data without constraining the parser to approved classes and methods.   When developers place no restrictions on "gadget chains," or series of instances and method invocations that can self-execute during the deserialization process (i.e., before the object is returned to the caller), it is sometimes possible for attackers to leverage them to perform unauthorized actions.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-298v-7gc3-86vj

больше 3 лет назад

UCMS 1.4.7 allows remote authenticated users to change the administrator password because $_COOKIE['admin_'.cookiehash] is used for arbitrary cookie values that are set and not empty.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-298r-5c48-7q2r

почти 3 года назад

Jenkins JUnit Plugin subject to Cross-site Scripting via URL conversion

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-298q-wv2h-v5vw

около 3 лет назад

Magento 2 Community Edition XSS Vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-298q-w9qh-3r99

больше 1 года назад

XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to administer styles, and uses a ZIP archive for Styles Import.

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-299c-jvhc-gxj8

Issue summary: Some non-default TLS server configurations can cause unbounded memory growth when processing TLSv1.3 sessions Impact summary: An attacker may exploit certain server configurations to trigger unbounded memory growth that would lead to a Denial of Service This problem can occur in TLSv1.3 if the non-default SSL_OP_NO_TICKET option is being used (but not if early_data support is also configured and the default anti-replay protection is in use). In this case, under certain conditions, the session cache can get into an incorrect state and it will fail to flush properly as it fills. The session cache will continue to grow in an unbounded manner. A malicious client could deliberately create the scenario for this failure to force a Denial of Service. It may also happen by accident in normal operation. This issue only affects TLS servers supporting TLSv1.3. It does not affect TLS clients. The FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue. OpenSSL 1.0.2 is...

CVSS3: 5.9
2%
Низкий
больше 1 года назад
github логотип
GHSA-2999-fgm6-2cf3

The Houzez Theme - Functionality plugin for WordPress is vulnerable to SQL Injection via the ‘currency_code’ parameter in all versions up to, and including, 3.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Custom-level (seller) access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 8.8
1%
Низкий
около 1 года назад
github логотип
GHSA-2998-9vr3-8cqh

Multiple buffer overflow vulnerabilities exist in the internet.cgi set_qos() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.This vulnerability exists in the `cli_mac` POST parameter.

CVSS3: 9.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-2997-qmg6-h7g4

SQL Injection vulnerability in MetInfo 7.0.0beta via admin/?n=language&c=language_web&a=doAddLanguage.

0%
Низкий
около 3 лет назад
github логотип
GHSA-2997-6fq4-wwch

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, an attacker with local network access could exploit this vulnerability to obtain sensitive data.

CVSS3: 6.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-2996-wwjj-qp22

OMICARD EDM’s mail image relay function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to by-pass authentication and access arbitrary system files.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-2995-x6wq-mq67

NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

0%
Низкий
около 3 лет назад
github логотип
GHSA-2995-qwmm-cm3p

Inappropriate implementation in in iframe Sandbox in Google Chrome prior to 109.0.5414.74 allowed a remote attacker to bypass file download restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2994-xw3p-6772

Format string vulnerability in the Log_Flush function in Weex 2.6.1.5, 2.6.1, and possibly other versions allows remote FTP servers to execute arbitrary code via format strings in filenames.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2994-j274-2gjp

TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to arbitrary command execution in the ‘host_time’ parameter of the NTPSyncWithHost interface of the cstecgi .cgi.

CVSS3: 9.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2994-cf23-4hmp

Mingw-w64 version 5.0.3 and earlier, 5.0.4, 6.0.0 and 7.0.0 contains an Improper Null Termination (CWE-170) vulnerability in mingw-w64-crt (libc)->(v)snprintf that can result in The bug may be used to corrupt subsequent string functions. This attack appear to be exploitable via Depending on the usage, worst case: network.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2993-5qvm-pg7x

In Xpdf 4.01.01, there is a heap-based buffer over-read in the function JBIG2Stream::readTextRegionSeg() located at JBIG2Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It might allow an attacker to cause Information Disclosure.

CVSS3: 5.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-2992-vffv-8399

The Inmobi library for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2992-6547-hhfp

In MB connect line mbDIALUP versions <= 3.9R0.0 a low privileged local attacker can send a command to the service running with NT AUTHORITY\SYSTEM instructing it to execute a malicous OpenVPN configuration resulting in arbitrary code execution with the privileges of the service.

0%
Низкий
около 3 лет назад
github логотип
GHSA-2992-3j6w-22hh

Tenda AX3 v16.03.12.11 has a stack buffer overflow vulnerability detected at function form_fast_setting_wifi_set. This vulnerability allows attackers to cause a Denial of Service (DoS) via the ssid parameter.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-298w-pg84-p7jw

The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid. (CWE-502)   Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.9, including 8.3.x, deserialize untrusted JSON data without constraining the parser to approved classes and methods.   When developers place no restrictions on "gadget chains," or series of instances and method invocations that can self-execute during the deserialization process (i.e., before the object is returned to the caller), it is sometimes possible for attackers to leverage them to perform unauthorized actions.

CVSS3: 9.9
0%
Низкий
6 месяцев назад
github логотип
GHSA-298v-7gc3-86vj

UCMS 1.4.7 allows remote authenticated users to change the administrator password because $_COOKIE['admin_'.cookiehash] is used for arbitrary cookie values that are set and not empty.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-298r-5c48-7q2r

Jenkins JUnit Plugin subject to Cross-site Scripting via URL conversion

CVSS3: 8
1%
Низкий
почти 3 года назад
github логотип
GHSA-298q-wv2h-v5vw

Magento 2 Community Edition XSS Vulnerability

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-298q-w9qh-3r99

XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to administer styles, and uses a ZIP archive for Styles Import.

CVSS3: 8.1
0%
Низкий
больше 1 года назад

Уязвимостей на страницу