Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 289 392

Количество 289 392

github логотип

GHSA-28pv-xxcq-fr89

больше 2 лет назад

A flaw was found in rizin. The create_section_from_phdr function allocates space for ELF section data by processing the headers. Crafted values in the headers can cause out of bounds reads, which can lead to memory corruption and possibly code execution through the binary object's callback function.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-28pv-2j2h-fmhc

около 3 лет назад

TeamPass Cross-Site Scripting (XSS)

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-28pp-6j97-mmc8

8 месяцев назад

IBM MQ Appliance 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-28pp-675x-rf35

около 1 года назад

Dorsett Controls Central Server update server has potential information leaks with an unprotected file that contains passwords and API keys.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-28pm-frw8-mr59

больше 1 года назад

SQL injection vulnerability exists in GetDIAE_slogListParameters.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-28pm-98wm-6937

около 3 лет назад

In versions of NGINX Controller prior to 3.3.0, the helper.sh script, which is used optionally in NGINX Controller to change settings, uses sensitive items as command-line arguments.

EPSS: Низкий
github логотип

GHSA-28ph-pmjh-gwg9

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yooslider Yoo Slider allows Reflected XSS.This issue affects Yoo Slider: from n/a through 2.1.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-28ph-f7gx-fqj8

почти 4 года назад

Data races in rusqlite

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-28ph-8qph-7chx

больше 3 лет назад

An attacker can gain knowledge of a session temporary working folder where the getfile and putfile commands are used in MDT AutoSave versions prior to v6.02.06. An attacker can leverage this knowledge to provide a malicious command to the working directory where the read and write activity can be initiated.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-28ph-466h-7249

больше 3 лет назад

SQL Injection exists in the Pinterest Clone Social Pinboard 2.0 component for Joomla! via the pin_id or user_id parameter in a task=getlikeinfo action, the ends parameter in a view=gift action, the category parameter in a view=home action, the uid parameter in a view=pindisplay action, the searchVal parameter in a view=search action, or the uid parameter in a view=likes action.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-28pg-cfrw-qvp7

больше 3 лет назад

Unspecified vulnerability in Oracle Sun Convergence 1.0 allows remote attackers to affect confidentiality via unknown vectors related to Mail, Calendar, Address Book, and Instant Messaging.

EPSS: Низкий
github логотип

GHSA-28pg-93m7-9jmx

10 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: uprobe: avoid out-of-bounds memory access of fetching args Uprobe needs to fetch args into a percpu buffer, and then copy to ring buffer to avoid non-atomic context problem. Sometimes user-space strings, arrays can be very large, but the size of percpu buffer is only page size. And store_trace_args() won't check whether these data exceeds a single page or not, caused out-of-bounds memory access. It could be reproduced by following steps: 1. build kernel with CONFIG_KASAN enabled 2. save follow program as test.c ``` \#include <stdio.h> \#include <stdlib.h> \#include <string.h> // If string length large than MAX_STRING_SIZE, the fetch_store_strlen() // will return 0, cause __get_data_size() return shorter size, and // store_trace_args() will not trigger out-of-bounds access. // So make string length less than 4096. \#define STRLEN 4093 void generate_string(char *str, int n) { int i; for (i = 0; i < n; +...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-28pf-wwvx-8jx3

около 3 лет назад

IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x before 7.0.0.2 CF27, and 8.0.0.x before 8.0.0.1 CF10, when the wcm.path.traversal.security setting is enabled, allows remote attackers to bypass intended read restrictions on an item by accessing that item within search results.

EPSS: Низкий
github логотип

GHSA-28pf-m5g8-4rqm

5 месяцев назад

Server-Side Request Forgery (SSRF) vulnerability in WP Compress WP Compress for MainWP allows Server Side Request Forgery. This issue affects WP Compress for MainWP: from n/a through 6.30.03.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-28pf-jj6h-h694

почти 2 года назад

A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to upload arbitrary content (such as a web shell component) to the SQL database and execute it with SYSTEM privileges. This vulnerability requires authentication to be exploited but can be paired with another vulnerability in the platform (CVE-2023-39420, which grants access to hardcoded credentials) to carry the attack without having assigned credentials. 

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-28pc-jv2f-hv8j

больше 3 лет назад

An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A SIGSEGV occurs in left_adjust_char_head() during regular expression compilation. Invalid handling of reg->dmax in forward_search_range() could result in an invalid pointer dereference, normally as an immediate denial-of-service condition.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-28pc-jprh-qc56

около 3 лет назад

Origin validation error vulnerability in NeoRS’s ActiveX moudle allows attackers to download and execute arbitrary files. Remote attackers can use this vulerability to encourage users to access crafted web pages, causing damage such as malicious code infections.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-28pc-f543-jq2v

больше 2 лет назад

NVIDIA BMC contains a vulnerability in libwebsocket, where an authorized attacker can cause a buffer overflow and cause a denial of service or gain code execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-28pc-8r63-2vcq

около 3 лет назад

Cross-site scripting (XSS) vulnerability in the login script in the Wind Farm Portal on Nordex Control 2 (NC2) SCADA devices 15 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter.

EPSS: Низкий
github логотип

GHSA-28pc-7w77-pq29

больше 2 лет назад

The Easy Video Player WordPress plugin before 1.2.2.3 does not sanitize and escapes some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-28pv-xxcq-fr89

A flaw was found in rizin. The create_section_from_phdr function allocates space for ELF section data by processing the headers. Crafted values in the headers can cause out of bounds reads, which can lead to memory corruption and possibly code execution through the binary object's callback function.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-28pv-2j2h-fmhc

TeamPass Cross-Site Scripting (XSS)

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-28pp-6j97-mmc8

IBM MQ Appliance 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned.

CVSS3: 6.2
0%
Низкий
8 месяцев назад
github логотип
GHSA-28pp-675x-rf35

Dorsett Controls Central Server update server has potential information leaks with an unprotected file that contains passwords and API keys.

CVSS3: 5.3
0%
Низкий
около 1 года назад
github логотип
GHSA-28pm-frw8-mr59

SQL injection vulnerability exists in GetDIAE_slogListParameters.

CVSS3: 8.8
4%
Низкий
больше 1 года назад
github логотип
GHSA-28pm-98wm-6937

In versions of NGINX Controller prior to 3.3.0, the helper.sh script, which is used optionally in NGINX Controller to change settings, uses sensitive items as command-line arguments.

0%
Низкий
около 3 лет назад
github логотип
GHSA-28ph-pmjh-gwg9

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yooslider Yoo Slider allows Reflected XSS.This issue affects Yoo Slider: from n/a through 2.1.1.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-28ph-f7gx-fqj8

Data races in rusqlite

CVSS3: 9.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-28ph-8qph-7chx

An attacker can gain knowledge of a session temporary working folder where the getfile and putfile commands are used in MDT AutoSave versions prior to v6.02.06. An attacker can leverage this knowledge to provide a malicious command to the working directory where the read and write activity can be initiated.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-28ph-466h-7249

SQL Injection exists in the Pinterest Clone Social Pinboard 2.0 component for Joomla! via the pin_id or user_id parameter in a task=getlikeinfo action, the ends parameter in a view=gift action, the category parameter in a view=home action, the uid parameter in a view=pindisplay action, the searchVal parameter in a view=search action, or the uid parameter in a view=likes action.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-28pg-cfrw-qvp7

Unspecified vulnerability in Oracle Sun Convergence 1.0 allows remote attackers to affect confidentiality via unknown vectors related to Mail, Calendar, Address Book, and Instant Messaging.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-28pg-93m7-9jmx

In the Linux kernel, the following vulnerability has been resolved: uprobe: avoid out-of-bounds memory access of fetching args Uprobe needs to fetch args into a percpu buffer, and then copy to ring buffer to avoid non-atomic context problem. Sometimes user-space strings, arrays can be very large, but the size of percpu buffer is only page size. And store_trace_args() won't check whether these data exceeds a single page or not, caused out-of-bounds memory access. It could be reproduced by following steps: 1. build kernel with CONFIG_KASAN enabled 2. save follow program as test.c ``` \#include <stdio.h> \#include <stdlib.h> \#include <string.h> // If string length large than MAX_STRING_SIZE, the fetch_store_strlen() // will return 0, cause __get_data_size() return shorter size, and // store_trace_args() will not trigger out-of-bounds access. // So make string length less than 4096. \#define STRLEN 4093 void generate_string(char *str, int n) { int i; for (i = 0; i < n; +...

CVSS3: 7.8
0%
Низкий
10 месяцев назад
github логотип
GHSA-28pf-wwvx-8jx3

IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x before 7.0.0.2 CF27, and 8.0.0.x before 8.0.0.1 CF10, when the wcm.path.traversal.security setting is enabled, allows remote attackers to bypass intended read restrictions on an item by accessing that item within search results.

0%
Низкий
около 3 лет назад
github логотип
GHSA-28pf-m5g8-4rqm

Server-Side Request Forgery (SSRF) vulnerability in WP Compress WP Compress for MainWP allows Server Side Request Forgery. This issue affects WP Compress for MainWP: from n/a through 6.30.03.

CVSS3: 4.9
0%
Низкий
5 месяцев назад
github логотип
GHSA-28pf-jj6h-h694

A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to upload arbitrary content (such as a web shell component) to the SQL database and execute it with SYSTEM privileges. This vulnerability requires authentication to be exploited but can be paired with another vulnerability in the platform (CVE-2023-39420, which grants access to hardcoded credentials) to carry the attack without having assigned credentials. 

CVSS3: 9.9
0%
Низкий
почти 2 года назад
github логотип
GHSA-28pc-jv2f-hv8j

An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A SIGSEGV occurs in left_adjust_char_head() during regular expression compilation. Invalid handling of reg->dmax in forward_search_range() could result in an invalid pointer dereference, normally as an immediate denial-of-service condition.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-28pc-jprh-qc56

Origin validation error vulnerability in NeoRS’s ActiveX moudle allows attackers to download and execute arbitrary files. Remote attackers can use this vulerability to encourage users to access crafted web pages, causing damage such as malicious code infections.

CVSS3: 8.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-28pc-f543-jq2v

NVIDIA BMC contains a vulnerability in libwebsocket, where an authorized attacker can cause a buffer overflow and cause a denial of service or gain code execution.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-28pc-8r63-2vcq

Cross-site scripting (XSS) vulnerability in the login script in the Wind Farm Portal on Nordex Control 2 (NC2) SCADA devices 15 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter.

1%
Низкий
около 3 лет назад
github логотип
GHSA-28pc-7w77-pq29

The Easy Video Player WordPress plugin before 1.2.2.3 does not sanitize and escapes some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу