Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3vm4-9f77-mj2x

около 1 года назад

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to gain higher access levels than they should have by exploiting improper authorization checks, resulting in privilege escalation. While authorizations for import and export are distinguished, a single authorization is applied for both, which may contribute to these risks. On successful exploitation, this can result in potential security concerns. However, it has no impact on the integrity and availability of the application and may have only a low impact on data confidentiality.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3vm4-857h-6jjc

больше 3 лет назад

SQL injection vulnerability in Runtime/Runtime/AjaxCall.ashx in K2 blackpearl, smartforms, and K2 for SharePoint 4.6.7 allows remote attackers to execute arbitrary SQL commands via the xml parameter.

EPSS: Низкий
github логотип

GHSA-3vm4-73fj-2j43

4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: powerpc: Fix virt_addr_valid() for 64-bit Book3E & 32-bit mpe: On 64-bit Book3E vmalloc space starts at 0x8000000000000000. Because of the way __pa() works we have: __pa(0x8000000000000000) == 0, and therefore virt_to_pfn(0x8000000000000000) == 0, and therefore virt_addr_valid(0x8000000000000000) == true Which is wrong, virt_addr_valid() should be false for vmalloc space. In fact all vmalloc addresses that alias with a valid PFN will return true from virt_addr_valid(). That can cause bugs with hardened usercopy as described below by Kefeng Wang: When running ethtool eth0 on 64-bit Book3E, a BUG occurred: usercopy: Kernel memory exposure attempt detected from SLUB object not in SLUB page?! (offset 0, size 1048)! kernel BUG at mm/usercopy.c:99 ... usercopy_abort+0x64/0xa0 (unreliable) __check_heap_object+0x168/0x190 __check_object_size+0x1a0/0x200 dev_ethtool+0x2494/0x2b20 ...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3vm4-3xxh-8fg2

больше 2 лет назад

Insertion of Sensitive Information into Log File vulnerability in Hitachi Ops Center Administrator on Linux allows local users  to gain sensive information.This issue affects Hitachi Ops Center Administrator: before 10.9.3-00.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3vm4-22fp-5rfm

больше 3 лет назад

golang.org/x/crypto/ssh NULL Pointer Dereference vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3vm3-7j4f-rg76

больше 3 лет назад

The RealTime RWR-3G-100 Router Firmware Version : Ver1.0.56 is affected by CSRF an attack that forces an end user to execute unwanted actions on a web application in which they're currently authenticated.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3vm3-6fcq-mrpx

больше 3 лет назад

DirectWrite Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3vm2-3vf9-9j39

около 1 года назад

A security issue exists in Vertex Gemini API for customers using VPC-SC. By utilizing a custom crafted file URI for image input, data exfiltration is possible due to requests being routed outside the VPC-SC security perimeter, circumventing the intended security restrictions of VPC-SC. No further fix actions are needed. Google Cloud Platform implemented a fix to return an error message when a media file URL is specified in the fileUri parameter and VPC Service Controls is enabled. Other use cases are unaffected.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3vjv-ww5h-3x77

9 дней назад

Tryton 5.4 contains a persistent cross-site scripting vulnerability in the user profile name input that allows remote attackers to inject malicious scripts. Attackers can exploit the vulnerability by inserting script payloads in the name field, which execute in the frontend and backend user interfaces.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-3vjv-rwr9-f593

больше 3 лет назад

Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Monitoring and Diagnostics). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Tools accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3vjv-c88x-5rh5

почти 4 года назад

Cross-site scripting (XSS) vulnerability in addentry.cgi in ZAP 1.0.3 allows remote attackers to inject arbitrary SSi directives, web script, and HTML via the entry field.

EPSS: Низкий
github логотип

GHSA-3vjv-6jp4-c68f

больше 3 лет назад

The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 does not properly check for folder-to-object association, which allows remote authenticated users to delete arbitrary tasks via the task id in a delete action to api/tasks.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3vjr-rgw8-j4h3

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in RSSOwl before 2.1.1 allows remote attackers to inject arbitrary web script or HTML via a feed, a different vulnerability than CVE-2006-4760.

EPSS: Низкий
github логотип

GHSA-3vjq-pfvj-cq2x

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldThemes Bold Page Builder allows Stored XSS.This issue affects Bold Page Builder: from n/a through 5.2.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3vjq-5v9v-h7rq

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows Information Exposure.

EPSS: Низкий
github логотип

GHSA-3vjm-36rr-7qrq

больше 4 лет назад

NULL Pointer Dereference in cbox

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3vjj-f6mx-v6mf

больше 2 лет назад

In ForegroundUtils of ForegroundUtils.java, there is a possible way to read NFC tag data while the app is still in the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-235863754

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3vjj-28j9-w324

больше 3 лет назад

The Maccabi Tel Aviv (aka com.monkeytech.maccabi) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-3vjh-xrhf-v9xh

около 1 года назад

Improper Restriction of XML External Entity Reference in dompdf/dompdf

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3vjg-xrj8-3qhh

больше 3 лет назад

Buffer overflow in the ATAS32 processing functionality in the Cisco WebEx Recording Format (WRF) player T26 before SP49 EP40 and T27 before SP28 allows remote attackers to execute arbitrary code via a crafted WRF file.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3vm4-9f77-mj2x

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to gain higher access levels than they should have by exploiting improper authorization checks, resulting in privilege escalation. While authorizations for import and export are distinguished, a single authorization is applied for both, which may contribute to these risks. On successful exploitation, this can result in potential security concerns. However, it has no impact on the integrity and availability of the application and may have only a low impact on data confidentiality.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-3vm4-857h-6jjc

SQL injection vulnerability in Runtime/Runtime/AjaxCall.ashx in K2 blackpearl, smartforms, and K2 for SharePoint 4.6.7 allows remote attackers to execute arbitrary SQL commands via the xml parameter.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3vm4-73fj-2j43

In the Linux kernel, the following vulnerability has been resolved: powerpc: Fix virt_addr_valid() for 64-bit Book3E & 32-bit mpe: On 64-bit Book3E vmalloc space starts at 0x8000000000000000. Because of the way __pa() works we have: __pa(0x8000000000000000) == 0, and therefore virt_to_pfn(0x8000000000000000) == 0, and therefore virt_addr_valid(0x8000000000000000) == true Which is wrong, virt_addr_valid() should be false for vmalloc space. In fact all vmalloc addresses that alias with a valid PFN will return true from virt_addr_valid(). That can cause bugs with hardened usercopy as described below by Kefeng Wang: When running ethtool eth0 on 64-bit Book3E, a BUG occurred: usercopy: Kernel memory exposure attempt detected from SLUB object not in SLUB page?! (offset 0, size 1048)! kernel BUG at mm/usercopy.c:99 ... usercopy_abort+0x64/0xa0 (unreliable) __check_heap_object+0x168/0x190 __check_object_size+0x1a0/0x200 dev_ethtool+0x2494/0x2b20 ...

CVSS3: 5.5
0%
Низкий
4 месяца назад
github логотип
GHSA-3vm4-3xxh-8fg2

Insertion of Sensitive Information into Log File vulnerability in Hitachi Ops Center Administrator on Linux allows local users  to gain sensive information.This issue affects Hitachi Ops Center Administrator: before 10.9.3-00.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3vm4-22fp-5rfm

golang.org/x/crypto/ssh NULL Pointer Dereference vulnerability

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vm3-7j4f-rg76

The RealTime RWR-3G-100 Router Firmware Version : Ver1.0.56 is affected by CSRF an attack that forces an end user to execute unwanted actions on a web application in which they're currently authenticated.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vm3-6fcq-mrpx

DirectWrite Remote Code Execution Vulnerability

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3vm2-3vf9-9j39

A security issue exists in Vertex Gemini API for customers using VPC-SC. By utilizing a custom crafted file URI for image input, data exfiltration is possible due to requests being routed outside the VPC-SC security perimeter, circumventing the intended security restrictions of VPC-SC. No further fix actions are needed. Google Cloud Platform implemented a fix to return an error message when a media file URL is specified in the fileUri parameter and VPC Service Controls is enabled. Other use cases are unaffected.

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-3vjv-ww5h-3x77

Tryton 5.4 contains a persistent cross-site scripting vulnerability in the user profile name input that allows remote attackers to inject malicious scripts. Attackers can exploit the vulnerability by inserting script payloads in the name field, which execute in the frontend and backend user interfaces.

CVSS3: 6.4
0%
Низкий
9 дней назад
github логотип
GHSA-3vjv-rwr9-f593

Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Monitoring and Diagnostics). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Tools accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3vjv-c88x-5rh5

Cross-site scripting (XSS) vulnerability in addentry.cgi in ZAP 1.0.3 allows remote attackers to inject arbitrary SSi directives, web script, and HTML via the entry field.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3vjv-6jp4-c68f

The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 does not properly check for folder-to-object association, which allows remote authenticated users to delete arbitrary tasks via the task id in a delete action to api/tasks.

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3vjr-rgw8-j4h3

Cross-site scripting (XSS) vulnerability in RSSOwl before 2.1.1 allows remote attackers to inject arbitrary web script or HTML via a feed, a different vulnerability than CVE-2006-4760.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vjq-pfvj-cq2x

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldThemes Bold Page Builder allows Stored XSS.This issue affects Bold Page Builder: from n/a through 5.2.1.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-3vjq-5v9v-h7rq

An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows Information Exposure.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vjm-36rr-7qrq

NULL Pointer Dereference in cbox

CVSS3: 9.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3vjj-f6mx-v6mf

In ForegroundUtils of ForegroundUtils.java, there is a possible way to read NFC tag data while the app is still in the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-235863754

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3vjj-28j9-w324

The Maccabi Tel Aviv (aka com.monkeytech.maccabi) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vjh-xrhf-v9xh

Improper Restriction of XML External Entity Reference in dompdf/dompdf

CVSS3: 9.8
3%
Низкий
около 1 года назад
github логотип
GHSA-3vjg-xrj8-3qhh

Buffer overflow in the ATAS32 processing functionality in the Cisco WebEx Recording Format (WRF) player T26 before SP49 EP40 and T27 before SP28 allows remote attackers to execute arbitrary code via a crafted WRF file.

3%
Низкий
больше 3 лет назад

Уязвимостей на страницу