Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-3qjg-973r-4w6w

почти 4 года назад

Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530 and CVE-2009-2531.

EPSS: Средний
github логотип

GHSA-3qjf-w8wq-4wwh

больше 3 лет назад

Multiple unspecified vulnerabilities in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0 allow remote attackers to execute arbitrary code via unknown vectors related to "input validation errors."

EPSS: Средний
github логотип

GHSA-3qjf-qh38-x73v

10 месяцев назад

Unauthenticated Miniflux user can bypass allowed networks check to obtain Prometheus metrics

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3qjf-f83f-x2pm

больше 3 лет назад

XML external entity (XXE) vulnerability in bkr/server/jobs.py in Beaker before 20.1 allows remote authenticated users to obtain sensitive information via submitting job XML to the server containing entity references which reference files from the Beaker server's file system.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3qjc-qh2q-vhxr

больше 2 лет назад

An issue found in FlightAware v.5.8.0 for Android allows unauthorized apps to cause a persistent denial of service by manipulating the database files.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3qjc-52vw-gmrg

почти 4 года назад

CoreAudio in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted audio content with QDM2 encoding, which triggers a buffer overflow due to inconsistent length fields, related to QDCA.

EPSS: Низкий
github логотип

GHSA-3qj9-m33f-45xw

больше 3 лет назад

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS 12.0 through 12.4 and 15.0 through 15.6 and IOS XE 2.2 through 3.17 contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Only traffic directed to an affected system can be used to exploit these vulnerabilities. The vulnerabilities are due to a buffer overflow condition in the SNMP subsystem of the affected software. The vulnerabilities affect all versions of SNMP: Versions 1, 2c, and 3. To exploit these vulnerabilities via SNMP Version 2c or earlier, the attacker must know the SNMP read-only community string for the affected system. To exploit these vulnerabilities via SNMP Version 3, the attacker must have user credentials for the affected system. All devices that have enabled SN...

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-3qj9-j5xp-hc3j

больше 2 лет назад

Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3qj9-cmfx-7v94

5 месяцев назад

A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN Gateways Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute arbitrary commands as root on the underlying operating system.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3qj9-54q8-j8jq

больше 1 года назад

A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0016), Tecnomatix Plant Simulation V2404 (All versions < V2404.0005). The affected application is vulnerable to memory corruption while parsing specially crafted WRL files. An attacker could leverage this in conjunction with other vulnerabilities to execute code in the context of the current process.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3qj9-29x6-pfxc

около 2 лет назад

Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3qj8-w38x-qmxh

почти 4 года назад

Cross-site request forgery (CSRF) vulnerability in Invision Gallery before 1.3.1 allows remote attackers to delete albums and images as another user via a link or IMG tag to the (1) albums or (2) delimg actions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3qj8-93xh-pwh2

почти 3 года назад

Duplicate Advisory: Starlette allows an unauthenticated and remote attacker to specify any number of form fields or files

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3qj7-pxvp-mv87

больше 3 лет назад

A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, which could cause the disclosure of sensitive information when using specific Modbus services provided by the REST API of the controller/communication module.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3qj7-2xc7-mxqw

2 месяца назад

In the Linux kernel, the following vulnerability has been resolved: io_uring/rw: ensure allocated iovec gets cleared for early failure A previous commit reused the recyling infrastructure for early cleanup, but this is not enough for the case where our internal caches have overflowed. If this happens, then the allocated iovec can get leaked if the request is also aborted early. Reinstate the previous forced free of the iovec for that situation.

EPSS: Низкий
github логотип

GHSA-3qj5-4m44-45xw

больше 1 года назад

The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the tc_dl_delete_tickets AJAX action in all versions up to, and including, 3.5.2.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete all tickets associated with events.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3qj4-m2gc-99m9

больше 2 лет назад

WebPlus Pro v1.4.7.8.4-01 is vulnerable to Incorrect Access Control.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3qj4-chqg-q336

больше 3 лет назад

Adobe Bridge version 11.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious Bridge file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

EPSS: Низкий
github логотип

GHSA-3qj4-9cvg-gv2q

почти 2 года назад

Missing Authorization vulnerability in ShortPixel ShortPixel Adaptive Images.This issue affects ShortPixel Adaptive Images: from n/a through 3.8.2.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3qj2-j553-x73q

больше 3 лет назад

The management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 does not properly implement RADIUS authentication, which allows remote attackers to execute arbitrary code by leveraging access to the login prompt.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3qjg-973r-4w6w

Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530 and CVE-2009-2531.

36%
Средний
почти 4 года назад
github логотип
GHSA-3qjf-w8wq-4wwh

Multiple unspecified vulnerabilities in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0 allow remote attackers to execute arbitrary code via unknown vectors related to "input validation errors."

48%
Средний
больше 3 лет назад
github логотип
GHSA-3qjf-qh38-x73v

Unauthenticated Miniflux user can bypass allowed networks check to obtain Prometheus metrics

CVSS3: 7.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-3qjf-f83f-x2pm

XML external entity (XXE) vulnerability in bkr/server/jobs.py in Beaker before 20.1 allows remote authenticated users to obtain sensitive information via submitting job XML to the server containing entity references which reference files from the Beaker server's file system.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3qjc-qh2q-vhxr

An issue found in FlightAware v.5.8.0 for Android allows unauthorized apps to cause a persistent denial of service by manipulating the database files.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3qjc-52vw-gmrg

CoreAudio in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted audio content with QDM2 encoding, which triggers a buffer overflow due to inconsistent length fields, related to QDCA.

5%
Низкий
почти 4 года назад
github логотип
GHSA-3qj9-m33f-45xw

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS 12.0 through 12.4 and 15.0 through 15.6 and IOS XE 2.2 through 3.17 contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Only traffic directed to an affected system can be used to exploit these vulnerabilities. The vulnerabilities are due to a buffer overflow condition in the SNMP subsystem of the affected software. The vulnerabilities affect all versions of SNMP: Versions 1, 2c, and 3. To exploit these vulnerabilities via SNMP Version 2c or earlier, the attacker must know the SNMP read-only community string for the affected system. To exploit these vulnerabilities via SNMP Version 3, the attacker must have user credentials for the affected system. All devices that have enabled SN...

CVSS3: 8.8
29%
Средний
больше 3 лет назад
github логотип
GHSA-3qj9-j5xp-hc3j

Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3qj9-cmfx-7v94

A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN Gateways Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute arbitrary commands as root on the underlying operating system.

CVSS3: 7.2
0%
Низкий
5 месяцев назад
github логотип
GHSA-3qj9-54q8-j8jq

A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0016), Tecnomatix Plant Simulation V2404 (All versions < V2404.0005). The affected application is vulnerable to memory corruption while parsing specially crafted WRL files. An attacker could leverage this in conjunction with other vulnerabilities to execute code in the context of the current process.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3qj9-29x6-pfxc

Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-3qj8-w38x-qmxh

Cross-site request forgery (CSRF) vulnerability in Invision Gallery before 1.3.1 allows remote attackers to delete albums and images as another user via a link or IMG tag to the (1) albums or (2) delimg actions.

CVSS3: 4.3
1%
Низкий
почти 4 года назад
github логотип
GHSA-3qj8-93xh-pwh2

Duplicate Advisory: Starlette allows an unauthenticated and remote attacker to specify any number of form fields or files

CVSS3: 7.5
почти 3 года назад
github логотип
GHSA-3qj7-pxvp-mv87

A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, which could cause the disclosure of sensitive information when using specific Modbus services provided by the REST API of the controller/communication module.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3qj7-2xc7-mxqw

In the Linux kernel, the following vulnerability has been resolved: io_uring/rw: ensure allocated iovec gets cleared for early failure A previous commit reused the recyling infrastructure for early cleanup, but this is not enough for the case where our internal caches have overflowed. If this happens, then the allocated iovec can get leaked if the request is also aborted early. Reinstate the previous forced free of the iovec for that situation.

0%
Низкий
2 месяца назад
github логотип
GHSA-3qj5-4m44-45xw

The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the tc_dl_delete_tickets AJAX action in all versions up to, and including, 3.5.2.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete all tickets associated with events.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-3qj4-m2gc-99m9

WebPlus Pro v1.4.7.8.4-01 is vulnerable to Incorrect Access Control.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3qj4-chqg-q336

Adobe Bridge version 11.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious Bridge file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-3qj4-9cvg-gv2q

Missing Authorization vulnerability in ShortPixel ShortPixel Adaptive Images.This issue affects ShortPixel Adaptive Images: from n/a through 3.8.2.

CVSS3: 5.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-3qj2-j553-x73q

The management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 does not properly implement RADIUS authentication, which allows remote attackers to execute arbitrary code by leveraging access to the login prompt.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу