Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 212

Количество 314 212

github логотип

GHSA-3vh9-8p9q-8wmw

больше 3 лет назад

Open Web Analytics (OWA) before 1.5.6 improperly generates random nonce values, which makes it easier for remote attackers to bypass a CSRF protection mechanism by leveraging knowledge of an OWA user name.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3vh8-f4xf-hgr4

почти 4 года назад

The (1) dupatch and (2) setld utilities in HP Tru64 UNIX 5.1B PK1 and earlier allows local users to overwrite files and possibly gain root privileges via a symlink attack.

EPSS: Низкий
github логотип

GHSA-3vh8-3f6g-98cq

больше 3 лет назад

The examapp plugin 1.0 for WordPress has XSS via exam input text fields.

EPSS: Низкий
github логотип

GHSA-3vh7-ff9w-cqhq

почти 2 года назад

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.7.4, watchOS 10.3, tvOS 17.3, macOS Ventura 13.6.5, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3. An app may be able to cause a denial-of-service.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-3vh6-pp7q-5xhf

7 месяцев назад

A cross-site scripting (XSS) vulnerability in the Admin Login page of Allworx System Software v9.1.9.12 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the SessionID parameter at query.asp.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3vh6-2h2q-2g33

больше 1 года назад

BTS is affected by information disclosure vulnerability where mobile network operator personnel connected over BTS Web Element Manager, regardless of the access privileges, having a possibility to read BTS service operation details performed by Nokia Care service personnel via SSH.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-3vh5-vw4x-2894

больше 3 лет назад

A lack of CORS checks, after a Service Worker redirected to a cross-origin PDF, in Service Worker in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak limited cross-origin data via a crafted HTML page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3vh5-qrqh-8pj5

больше 3 лет назад

The ColorMania - Color Quiz Game (aka com.ColormaniaColoringGames) application 1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-3vh5-9778-57cq

больше 3 лет назад

74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company/view_be_browsed/total.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3vh5-5fv5-286r

почти 4 года назад

Vtun 2.5b1 allows remote attackers to inject data into user sessions by sniffing and replaying packets.

EPSS: Низкий
github логотип

GHSA-3vh3-xm22-984m

около 1 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webcreations907 WBC907 Core allows Stored XSS.This issue affects WBC907 Core: from n/a through 3.4.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3vh3-mqwm-fjh6

почти 2 года назад

An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in AP4_SubStream::~AP4_SubStream at Ap4ByteStream.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42ts.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-3vh3-h94g-wh9r

больше 3 лет назад

UPR-Kernel in Ubuntu Privacy Remix (UPR) before 8.04_r1 includes kernel support for mounting RAID arrays, which might allow remote attackers to bypass intended isolation mechanisms by (1) reading from or (2) writing to these arrays.

EPSS: Низкий
github логотип

GHSA-3vh2-xgxr-xw99

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Allomani Weblinks 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) default URI to admin.php or the (2) id parameter to admin.php or (3) go.php.

EPSS: Низкий
github логотип

GHSA-3vh2-mmqw-p57m

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in XMB Forum 1.9.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Mood or (2) "Send To" fields.

EPSS: Низкий
github логотип

GHSA-3vh2-7wc2-pg3v

больше 3 лет назад

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1256.

EPSS: Низкий
github логотип

GHSA-3vgx-qgcc-j6g8

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in Magento 1.2.0 and 1.2.1.1 allow remote attackers to inject arbitrary web script or HTML via (1) the username field in an admin/ request to index.php, possibly related to the login[username] parameter and the app/code/core/Mage/Admin/Model/Session.php login function; (2) the email address field in an admin/index/forgotpassword/ request to index.php, possibly related to the email parameter and the app/code/core/Mage/Adminhtml/controllers/IndexController.php forgotpasswordAction function; or (3) the return parameter to the default URI under downloader/.

EPSS: Низкий
github логотип

GHSA-3vgw-p3fg-cj52

больше 3 лет назад

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Buffer overread may occur due to non-null terminated strings while processing vsprintf in camera jpeg driver.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3vgw-chq8-wqp9

больше 3 лет назад

IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially crafted file, a remote attacker could exploit this vulnerability to execute arbitrary code on the system or cause the application to crash. IBM X-Force ID: 180167.

EPSS: Низкий
github логотип

GHSA-3vgw-967p-w66j

больше 3 лет назад

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3vh9-8p9q-8wmw

Open Web Analytics (OWA) before 1.5.6 improperly generates random nonce values, which makes it easier for remote attackers to bypass a CSRF protection mechanism by leveraging knowledge of an OWA user name.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vh8-f4xf-hgr4

The (1) dupatch and (2) setld utilities in HP Tru64 UNIX 5.1B PK1 and earlier allows local users to overwrite files and possibly gain root privileges via a symlink attack.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3vh8-3f6g-98cq

The examapp plugin 1.0 for WordPress has XSS via exam input text fields.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vh7-ff9w-cqhq

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.7.4, watchOS 10.3, tvOS 17.3, macOS Ventura 13.6.5, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3. An app may be able to cause a denial-of-service.

CVSS3: 6.2
0%
Низкий
почти 2 года назад
github логотип
GHSA-3vh6-pp7q-5xhf

A cross-site scripting (XSS) vulnerability in the Admin Login page of Allworx System Software v9.1.9.12 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the SessionID parameter at query.asp.

CVSS3: 6.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-3vh6-2h2q-2g33

BTS is affected by information disclosure vulnerability where mobile network operator personnel connected over BTS Web Element Manager, regardless of the access privileges, having a possibility to read BTS service operation details performed by Nokia Care service personnel via SSH.

CVSS3: 3.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-3vh5-vw4x-2894

A lack of CORS checks, after a Service Worker redirected to a cross-origin PDF, in Service Worker in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak limited cross-origin data via a crafted HTML page.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3vh5-qrqh-8pj5

The ColorMania - Color Quiz Game (aka com.ColormaniaColoringGames) application 1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vh5-9778-57cq

74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company/view_be_browsed/total.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vh5-5fv5-286r

Vtun 2.5b1 allows remote attackers to inject data into user sessions by sniffing and replaying packets.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3vh3-xm22-984m

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webcreations907 WBC907 Core allows Stored XSS.This issue affects WBC907 Core: from n/a through 3.4.1.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3vh3-mqwm-fjh6

An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in AP4_SubStream::~AP4_SubStream at Ap4ByteStream.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42ts.

CVSS3: 2.7
0%
Низкий
почти 2 года назад
github логотип
GHSA-3vh3-h94g-wh9r

UPR-Kernel in Ubuntu Privacy Remix (UPR) before 8.04_r1 includes kernel support for mounting RAID arrays, which might allow remote attackers to bypass intended isolation mechanisms by (1) reading from or (2) writing to these arrays.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3vh2-xgxr-xw99

Multiple cross-site scripting (XSS) vulnerabilities in Allomani Weblinks 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) default URI to admin.php or the (2) id parameter to admin.php or (3) go.php.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vh2-mmqw-p57m

Multiple cross-site scripting (XSS) vulnerabilities in XMB Forum 1.9.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Mood or (2) "Send To" fields.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3vh2-7wc2-pg3v

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1256.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vgx-qgcc-j6g8

Multiple cross-site scripting (XSS) vulnerabilities in Magento 1.2.0 and 1.2.1.1 allow remote attackers to inject arbitrary web script or HTML via (1) the username field in an admin/ request to index.php, possibly related to the login[username] parameter and the app/code/core/Mage/Admin/Model/Session.php login function; (2) the email address field in an admin/index/forgotpassword/ request to index.php, possibly related to the email parameter and the app/code/core/Mage/Adminhtml/controllers/IndexController.php forgotpasswordAction function; or (3) the return parameter to the default URI under downloader/.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3vgw-p3fg-cj52

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Buffer overread may occur due to non-null terminated strings while processing vsprintf in camera jpeg driver.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vgw-chq8-wqp9

IBM i2 Intelligent Analyis Platform 9.2.1 could allow a remote attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially crafted file, a remote attacker could exploit this vulnerability to execute arbitrary code on the system or cause the application to crash. IBM X-Force ID: 180167.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3vgw-967p-w66j

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVSS3: 8.8
3%
Низкий
больше 3 лет назад

Уязвимостей на страницу