Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 289 610

Количество 289 610

github логотип

GHSA-28m3-jxqr-cj5w

около 3 лет назад

WriteOnePNGImage() from coders/png.c (the PNG coder) has a for loop with an improper exit condition that can allow an out-of-bounds READ via heap-buffer-overflow. This occurs because it is possible for the colormap to have less than 256 valid values but the loop condition will loop 256 times, attempting to pass invalid colormap data to the event logger. The patch replaces the hardcoded 256 value with a call to MagickMin() to ensure the proper value is used. This could impact application availability when a specially crafted input file is processed by ImageMagick. This flaw affects ImageMagick versions prior to 7.0.8-68.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-28m3-c955-h29j

около 2 лет назад

Inappropriate implementation in Downloads in Google Chrome prior to 114.0.5735.90 allowed an attacker who convinced a user to install a malicious extension to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-28m3-8469-832v

больше 3 лет назад

Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4172, CVE-2016-4175, CVE-2016-4179, CVE-2016-4180, CVE-2016-4181, CVE-2016-4182, CVE-2016-4183, CVE-2016-4184, CVE-2016-4186, CVE-2016-4187, CVE-2016-4188, CVE-2016-4189, CVE-2016-4190, CVE-2016-4217, CVE-2016-4218, CVE-2016-4219, CVE-2016-4220, CVE-2016-4221, CVE-2016-4233, CVE-2016-4234, CVE-2016-4235, CVE-2016-4236, CVE-2016-4237, CVE-2016-4238, CVE-2016-4239, CVE-2016-4240, CVE-2016-4241, CVE-2016-4242, CVE-2016-4243, CVE-2016-4244, CVE-2016-4245, and CVE-2016-4246.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-28m2-fhxm-fxx6

около 2 лет назад

fast-poster v2.15.0 is vulnerable to Cross Site Scripting (XSS). File upload check binary of img, but without strictly check file suffix at /server/fast.py -> ApiUploadHandler.post causes stored XSS

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-28m2-22hr-gx8q

9 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in P. Roy WP Revisions Manager allows Cross Site Request Forgery.This issue affects WP Revisions Manager: from n/a through 1.0.2.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-28jx-5cwg-xq36

больше 3 лет назад

Reflected Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.

CVSS3: 3.5
EPSS: Средний
github логотип

GHSA-28jw-6mhj-hjwx

около 3 лет назад

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data as well as unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 5.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N).

EPSS: Низкий
github логотип

GHSA-28jw-278j-42f5

около 2 лет назад

Fujitsu Software Infrastructure Manager (ISM) stores sensitive information at the product's maintenance data (ismsnap) in cleartext form. As a result, the password for the proxy server that is configured in ISM may be retrieved. Affected products and versions are as follows: Fujitsu Software Infrastructure Manager Advanced Edition V2.8.0.060, Fujitsu Software Infrastructure Manager Advanced Edition for PRIMEFLEX V2.8.0.060, and Fujitsu Software Infrastructure Manager Essential Edition V2.8.0.060.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-28jr-36gh-qwvh

больше 3 лет назад

The WP Mailster plugin before 1.5.5 for WordPress has XSS in the unsubscribe handler via the mes parameter to view/subscription/unsubscribe2.php.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-28jq-qqpg-7xm4

около 3 лет назад

Adobe Bridge versions 10.0.1 and earlier version have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-28jq-f9q3-32fc

больше 3 лет назад

SQL injection vulnerability in the SetsucoCMS all versions allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-28jp-g4gg-47fp

больше 3 лет назад

On BIG-IP APM 11.6.0-11.6.3.1, 12.1.0-12.1.3.3, 13.0.0, and 13.1.0-13.1.0.3, APMD may core when processing SAML Assertion or response containing certain elements.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-28jp-5r9q-jh8r

больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere BigInsights 2.0 through 2.1 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.

EPSS: Низкий
github логотип

GHSA-28jm-hff2-853w

больше 3 лет назад

Directory traversal vulnerability in classes/imgsize.php in Gelato 0.95 allows remote attackers to read arbitrary files via (1) a .. (dot dot) and possibly (2) a full pathname in the img parameter. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-28jm-h53g-x4fr

около 1 месяца назад

Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-28jj-p35h-662j

больше 3 лет назад

Sonatype Nexus Repository Manager 3.x before 3.38.0 allows SSRF.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-28jj-97w4-wxm3

больше 1 года назад

Cross Site Scripting (XSS) vulnerability in Code-Projects Exam Form Submission 1.0 allows attackers to run arbitrary code via "Subject Name" and "Subject Code" section.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-28jh-gp7h-pj6v

больше 3 лет назад

Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0278 and CVE-2014-0279.

EPSS: Средний
github логотип

GHSA-28jh-5pxq-q92w

7 месяцев назад

Memory corruption may occour while generating test pattern due to negative indexing of display ID.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-28jg-wmv9-mfgw

больше 2 лет назад

In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767870; Issue ID: ALPS07767870.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-28m3-jxqr-cj5w

WriteOnePNGImage() from coders/png.c (the PNG coder) has a for loop with an improper exit condition that can allow an out-of-bounds READ via heap-buffer-overflow. This occurs because it is possible for the colormap to have less than 256 valid values but the loop condition will loop 256 times, attempting to pass invalid colormap data to the event logger. The patch replaces the hardcoded 256 value with a call to MagickMin() to ensure the proper value is used. This could impact application availability when a specially crafted input file is processed by ImageMagick. This flaw affects ImageMagick versions prior to 7.0.8-68.

CVSS3: 5.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-28m3-c955-h29j

Inappropriate implementation in Downloads in Google Chrome prior to 114.0.5735.90 allowed an attacker who convinced a user to install a malicious extension to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-28m3-8469-832v

Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4172, CVE-2016-4175, CVE-2016-4179, CVE-2016-4180, CVE-2016-4181, CVE-2016-4182, CVE-2016-4183, CVE-2016-4184, CVE-2016-4186, CVE-2016-4187, CVE-2016-4188, CVE-2016-4189, CVE-2016-4190, CVE-2016-4217, CVE-2016-4218, CVE-2016-4219, CVE-2016-4220, CVE-2016-4221, CVE-2016-4233, CVE-2016-4234, CVE-2016-4235, CVE-2016-4236, CVE-2016-4237, CVE-2016-4238, CVE-2016-4239, CVE-2016-4240, CVE-2016-4241, CVE-2016-4242, CVE-2016-4243, CVE-2016-4244, CVE-2016-4245, and CVE-2016-4246.

CVSS3: 9.8
5%
Низкий
больше 3 лет назад
github логотип
GHSA-28m2-fhxm-fxx6

fast-poster v2.15.0 is vulnerable to Cross Site Scripting (XSS). File upload check binary of img, but without strictly check file suffix at /server/fast.py -> ApiUploadHandler.post causes stored XSS

CVSS3: 5.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-28m2-22hr-gx8q

Cross-Site Request Forgery (CSRF) vulnerability in P. Roy WP Revisions Manager allows Cross Site Request Forgery.This issue affects WP Revisions Manager: from n/a through 1.0.2.

CVSS3: 5.4
0%
Низкий
9 месяцев назад
github логотип
GHSA-28jx-5cwg-xq36

Reflected Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.

CVSS3: 3.5
19%
Средний
больше 3 лет назад
github логотип
GHSA-28jw-6mhj-hjwx

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data as well as unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 5.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N).

1%
Низкий
около 3 лет назад
github логотип
GHSA-28jw-278j-42f5

Fujitsu Software Infrastructure Manager (ISM) stores sensitive information at the product's maintenance data (ismsnap) in cleartext form. As a result, the password for the proxy server that is configured in ISM may be retrieved. Affected products and versions are as follows: Fujitsu Software Infrastructure Manager Advanced Edition V2.8.0.060, Fujitsu Software Infrastructure Manager Advanced Edition for PRIMEFLEX V2.8.0.060, and Fujitsu Software Infrastructure Manager Essential Edition V2.8.0.060.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-28jr-36gh-qwvh

The WP Mailster plugin before 1.5.5 for WordPress has XSS in the unsubscribe handler via the mes parameter to view/subscription/unsubscribe2.php.

CVSS3: 6.1
16%
Средний
больше 3 лет назад
github логотип
GHSA-28jq-qqpg-7xm4

Adobe Bridge versions 10.0.1 and earlier version have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

CVSS3: 7.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-28jq-f9q3-32fc

SQL injection vulnerability in the SetsucoCMS all versions allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-28jp-g4gg-47fp

On BIG-IP APM 11.6.0-11.6.3.1, 12.1.0-12.1.3.3, 13.0.0, and 13.1.0-13.1.0.3, APMD may core when processing SAML Assertion or response containing certain elements.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-28jp-5r9q-jh8r

Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere BigInsights 2.0 through 2.1 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-28jm-hff2-853w

Directory traversal vulnerability in classes/imgsize.php in Gelato 0.95 allows remote attackers to read arbitrary files via (1) a .. (dot dot) and possibly (2) a full pathname in the img parameter. NOTE: some of these details are obtained from third party information.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-28jm-h53g-x4fr

Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.

CVSS3: 6.2
0%
Низкий
около 1 месяца назад
github логотип
GHSA-28jj-p35h-662j

Sonatype Nexus Repository Manager 3.x before 3.38.0 allows SSRF.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-28jj-97w4-wxm3

Cross Site Scripting (XSS) vulnerability in Code-Projects Exam Form Submission 1.0 allows attackers to run arbitrary code via "Subject Name" and "Subject Code" section.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-28jh-gp7h-pj6v

Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0278 and CVE-2014-0279.

39%
Средний
больше 3 лет назад
github логотип
GHSA-28jh-5pxq-q92w

Memory corruption may occour while generating test pattern due to negative indexing of display ID.

CVSS3: 7.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-28jg-wmv9-mfgw

In apu, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767870; Issue ID: ALPS07767870.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу