Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3vvq-h94f-pm68

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: avoid using null object of framebuffer Instead of using state->fb->obj[0] directly, get object from framebuffer by calling drm_gem_fb_get_obj() and return error code when object is null to avoid using null object of framebuffer.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3vvq-2whw-xv59

больше 3 лет назад

A vulnerability in the configuration and management service of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to execute arbitrary code with vmanage user privileges or cause a denial of service (DoS) condition on an affected system. The vulnerability is due to insufficient access restrictions to the HTTP management interface of the affected solution. An attacker could exploit this vulnerability by sending a malicious HTTP request to the affected management service through an authenticated device. A successful exploit could allow the attacker to execute arbitrary code with vmanage user privileges or stop HTTP services on an affected system. This vulnerability affects the following Cisco products if they are running a release of the Cisco SD-WAN Solution prior to Release 18.3.0: vBond Orchestrator Software, vEdge 100 Series Routers, vEdge 1000 Series Routers, vEdge 2000 Series Routers, vEdge 5000 Series Routers, vEdge Cloud Router Platform, vManage Network Man...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3vvp-wwgp-m9wm

больше 3 лет назад

Stack-based overflow vulnerability in the logMess function in Open TFTP Server MT 1.65 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via a long TFTP error packet, a different vulnerability than CVE-2018-10387 and CVE-2019-12568.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3vvp-qmqj-rgmg

больше 3 лет назад

HTMLDoc v1.9.15 was discovered to contain a heap overflow via (write_header) /htmldoc/htmldoc/html.cxx:273.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3vvp-hjc4-47w5

около 2 лет назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Porto Theme Porto Theme - Functionality.This issue affects Porto Theme - Functionality: from n/a before 2.12.1.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-3vvp-9ghf-fqvw

почти 3 года назад

praecis_parse in ntpd/refclock_palisade.c in NTP 4.2.8p15 has an out-of-bounds write.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-3vvp-8645-4qmr

больше 3 лет назад

An issue was discovered in GNU gettext 0.19.8. There is a double free in default_add_message in read-catalog.c, related to an invalid free in po_gram_parse in po-gram-gen.y, as demonstrated by lt-msgfmt.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3vvm-w3xq-2xq2

больше 3 лет назад

The Star Girl: Colors of Spring (aka com.animoca.google.starGirlSpring) application 3.4.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-3vvm-pm5r-55f5

больше 3 лет назад

Failure to check error conditions in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3vvm-c22w-36hj

больше 3 лет назад

Chamilo LMS version 1.11.8 contains XSS in main/template/default/admin/gradebook_list.tpl in the gradebook dependencies tool, allowing authenticated users to affect other users, under specific conditions of permissions granted by administrators. This is considered "low risk" due to the nature of the feature it exploits.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3vvm-3j5j-gc9q

почти 4 года назад

Race condition in xterm allows local users to modify arbitrary files via the logging option.

EPSS: Низкий
github логотип

GHSA-3vvj-p2p8-pchq

больше 3 лет назад

Out of the wired and wireless interfaces within MiR100, MiR200 and other vehicles from the MiR fleet, it's possible to access the Control Dashboard on a hardcoded IP address. Credentials to such wireless interface default to well known and widely spread users (omitted) and passwords (omitted). This information is also available in past User Guides and manuals which the vendor distributed. This flaw allows cyber attackers to take control of the robot remotely and make use of the default user interfaces MiR has created, lowering the complexity of attacks and making them available to entry-level attackers. More elaborated attacks can also be established by clearing authentication and sending network requests directly. We have confirmed this flaw in MiR100 and MiR200 but according to the vendor, it might also apply to MiR250, MiR500 and MiR1000.

EPSS: Низкий
github логотип

GHSA-3vvj-hvh7-x4m7

больше 2 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in install/index.php of CSZ CMS v1.3.0 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Database Username or Database Host parameters.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3vvj-5p8f-5c28

11 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: tcp: Fix data-races around sysctl_tcp_base_mss. While reading sysctl_tcp_base_mss, it can be changed concurrently. Thus, we need to add READ_ONCE() to its readers.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-3vvh-rcx9-vcx3

больше 3 лет назад

Cloud Foundry CredHub CLI, versions prior to 2.2.1, inadvertently writes authentication credentials provided via environment variables to its persistent config file. A local authenticated malicious user with access to the CredHub CLI config file can use these credentials to retrieve and modify credentials stored in CredHub that are authorized to the targeted user.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3vvh-cqhq-ffrh

больше 3 лет назад

Atlassian Eucalyptus before 4.4.1, when in EDGE mode, allows remote authenticated users with certain privileges to cause a denial of service (E2 service outage) via unspecified vectors.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3vvh-8c65-32j4

около 2 лет назад

Mingsoft MCMS SQL injection

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-3vvh-6qrh-25vg

около 3 лет назад

Improper access control in the Intel(R) WAPI Security software for Windows 10/11 before version 22.2150.0.1 may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-3vvg-m9mw-32qv

почти 4 года назад

Dell PowerScale OneFS, versions 8.2.0-9.3.0, contains an Improper Handling of Insufficient Permissions vulnerability. An remote malicious user could potentially exploit this vulnerability, leading to gaining write permissions on read-only files.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3vvg-gmfw-pmm4

больше 1 года назад

The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'debug_data', 'debug_query', and 'debug_redirect' functions in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers to extract sensitive data including password, title, and content of password-protected posts.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3vvq-h94f-pm68

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: avoid using null object of framebuffer Instead of using state->fb->obj[0] directly, get object from framebuffer by calling drm_gem_fb_get_obj() and return error code when object is null to avoid using null object of framebuffer.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3vvq-2whw-xv59

A vulnerability in the configuration and management service of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to execute arbitrary code with vmanage user privileges or cause a denial of service (DoS) condition on an affected system. The vulnerability is due to insufficient access restrictions to the HTTP management interface of the affected solution. An attacker could exploit this vulnerability by sending a malicious HTTP request to the affected management service through an authenticated device. A successful exploit could allow the attacker to execute arbitrary code with vmanage user privileges or stop HTTP services on an affected system. This vulnerability affects the following Cisco products if they are running a release of the Cisco SD-WAN Solution prior to Release 18.3.0: vBond Orchestrator Software, vEdge 100 Series Routers, vEdge 1000 Series Routers, vEdge 2000 Series Routers, vEdge 5000 Series Routers, vEdge Cloud Router Platform, vManage Network Man...

CVSS3: 8.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3vvp-wwgp-m9wm

Stack-based overflow vulnerability in the logMess function in Open TFTP Server MT 1.65 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via a long TFTP error packet, a different vulnerability than CVE-2018-10387 and CVE-2019-12568.

CVSS3: 9.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-3vvp-qmqj-rgmg

HTMLDoc v1.9.15 was discovered to contain a heap overflow via (write_header) /htmldoc/htmldoc/html.cxx:273.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vvp-hjc4-47w5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Porto Theme Porto Theme - Functionality.This issue affects Porto Theme - Functionality: from n/a before 2.12.1.

CVSS3: 9.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-3vvp-9ghf-fqvw

praecis_parse in ntpd/refclock_palisade.c in NTP 4.2.8p15 has an out-of-bounds write.

CVSS3: 6.4
1%
Низкий
почти 3 года назад
github логотип
GHSA-3vvp-8645-4qmr

An issue was discovered in GNU gettext 0.19.8. There is a double free in default_add_message in read-catalog.c, related to an invalid free in po_gram_parse in po-gram-gen.y, as demonstrated by lt-msgfmt.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3vvm-w3xq-2xq2

The Star Girl: Colors of Spring (aka com.animoca.google.starGirlSpring) application 3.4.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vvm-pm5r-55f5

Failure to check error conditions in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3vvm-c22w-36hj

Chamilo LMS version 1.11.8 contains XSS in main/template/default/admin/gradebook_list.tpl in the gradebook dependencies tool, allowing authenticated users to affect other users, under specific conditions of permissions granted by administrators. This is considered "low risk" due to the nature of the feature it exploits.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vvm-3j5j-gc9q

Race condition in xterm allows local users to modify arbitrary files via the logging option.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3vvj-p2p8-pchq

Out of the wired and wireless interfaces within MiR100, MiR200 and other vehicles from the MiR fleet, it's possible to access the Control Dashboard on a hardcoded IP address. Credentials to such wireless interface default to well known and widely spread users (omitted) and passwords (omitted). This information is also available in past User Guides and manuals which the vendor distributed. This flaw allows cyber attackers to take control of the robot remotely and make use of the default user interfaces MiR has created, lowering the complexity of attacks and making them available to entry-level attackers. More elaborated attacks can also be established by clearing authentication and sending network requests directly. We have confirmed this flaw in MiR100 and MiR200 but according to the vendor, it might also apply to MiR250, MiR500 and MiR1000.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vvj-hvh7-x4m7

Multiple cross-site scripting (XSS) vulnerabilities in install/index.php of CSZ CMS v1.3.0 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Database Username or Database Host parameters.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3vvj-5p8f-5c28

In the Linux kernel, the following vulnerability has been resolved: tcp: Fix data-races around sysctl_tcp_base_mss. While reading sysctl_tcp_base_mss, it can be changed concurrently. Thus, we need to add READ_ONCE() to its readers.

CVSS3: 4.7
0%
Низкий
11 месяцев назад
github логотип
GHSA-3vvh-rcx9-vcx3

Cloud Foundry CredHub CLI, versions prior to 2.2.1, inadvertently writes authentication credentials provided via environment variables to its persistent config file. A local authenticated malicious user with access to the CredHub CLI config file can use these credentials to retrieve and modify credentials stored in CredHub that are authorized to the targeted user.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vvh-cqhq-ffrh

Atlassian Eucalyptus before 4.4.1, when in EDGE mode, allows remote authenticated users with certain privileges to cause a denial of service (E2 service outage) via unspecified vectors.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vvh-8c65-32j4

Mingsoft MCMS SQL injection

CVSS3: 8.8
32%
Средний
около 2 лет назад
github логотип
GHSA-3vvh-6qrh-25vg

Improper access control in the Intel(R) WAPI Security software for Windows 10/11 before version 22.2150.0.1 may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 3.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-3vvg-m9mw-32qv

Dell PowerScale OneFS, versions 8.2.0-9.3.0, contains an Improper Handling of Insufficient Permissions vulnerability. An remote malicious user could potentially exploit this vulnerability, leading to gaining write permissions on read-only files.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-3vvg-gmfw-pmm4

The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'debug_data', 'debug_query', and 'debug_redirect' functions in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers to extract sensitive data including password, title, and content of password-protected posts.

CVSS3: 5.3
1%
Низкий
больше 1 года назад

Уязвимостей на страницу