Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 289 610

Количество 289 610

github логотип

GHSA-28fq-p2c7-42px

около 3 лет назад

Secom Co. Dr.ID, a Door Access Control and Personnel Attendance Management system, stores users’ information by cleartext in the cookie, which divulges password to attackers.

EPSS: Низкий
github логотип

GHSA-28fp-mw8j-xfc5

почти 2 года назад

The issue was addressed with improved handling of protocols. This issue is fixed in tvOS 17, iOS 16.7 and iPadOS 16.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. A remote attacker may be able to break out of Web Content sandbox.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-28fm-qh2h-3mch

почти 3 года назад

html2xhtml v1.3 was discovered to contain an Out-Of-Bounds read in the function static void elm_close(tree_node_t *nodo) at procesador.c. This vulnerability allows attackers to access sensitive files or cause a Denial of Service (DoS) via a crafted html file.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-28fj-h7cm-23g6

больше 3 лет назад

The default configuration of the DVI print filter (dvips) in Red Hat Linux 7.0 and earlier does not run dvips in secure mode when dvips is executed by lpd, which could allow remote attackers to gain privileges by printing a DVI file that contains malicious commands.

EPSS: Низкий
github логотип

GHSA-28fh-4j57-cc4w

около 3 лет назад

A vulnerability in Trend Micro Apex One and OfficeScan XG SP1 on Microsoft Windows may allow an attacker to create a hard link to any file on the system, which then could be manipulated to gain a privilege escalation and code execution. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. Please note that version 1909 (OS Build 18363.719) of Microsoft Windows 10 mitigates hard links, but previous versions are affected.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-28fh-3r6h-cgpw

около 3 лет назад

A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka 'Microsoft PowerPoint Remote Code Execution Vulnerability'.

EPSS: Средний
github логотип

GHSA-28fg-r93m-m726

около 2 лет назад

The SupportCandy WordPress plugin before 3.1.7 does not properly sanitise and escape the `id` parameter for an Agent in the REST API before using it in an SQL statement, leading to an SQL Injection exploitable by users with a role as low as Subscriber.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-28ff-x3xj-mx7q

больше 3 лет назад

An information disclosure vulnerability in libstagefright in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Android ID: A-31091777.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-28fc-gvjg-5f4h

около 3 лет назад

** UNSUPPORTED WHEN ASSIGNED ** The unofficial vscode-sass-lint (aka Sass Lint) extension through 1.0.7 for Visual Studio Code allows attackers to execute arbitrary binaries if the user opens a crafted workspace. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-28f9-43w8-v45c

больше 3 лет назад

Buffer overflow in the ILASM assembler in the Microsoft .NET 1.0 and 1.1 Framework might allow user-assisted attackers to execute arbitrary code via a .il file that calls a function with a long name.

EPSS: Средний
github логотип

GHSA-28f8-hqmc-7ph8

почти 5 лет назад

Malicious Package in ember-power-timepicker

EPSS: Низкий
github логотип

GHSA-28f7-mc45-4x8m

около 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gordon Böhme, Antonio Leutsch Structured Content allows Stored XSS.This issue affects Structured Content: from n/a through 1.6.2.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-28f7-g5r5-mpx5

больше 2 лет назад

In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-28f6-9xpw-pwcr

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in core/summary_api.php in MantisBT before 1.2.3 allows remote attackers to inject arbitrary web script or HTML via the Summary field, a different vector than CVE-2010-3303.

EPSS: Низкий
github логотип

GHSA-28f6-647f-xq87

около 3 лет назад

Buffer overflow in SonicWall SMA100 allows an authenticated user to execute arbitrary code in DEARegister CGI script. This vulnerability impacted SMA100 version 9.0.0.3 and earlier.

EPSS: Низкий
github логотип

GHSA-28f5-mg2c-r34c

больше 3 лет назад

Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScript API execution via unspecified vectors, a different vulnerability than CVE-2015-3060, CVE-2015-3061, CVE-2015-3062, CVE-2015-3063, CVE-2015-3064, CVE-2015-3065, CVE-2015-3066, CVE-2015-3067, CVE-2015-3068, CVE-2015-3069, CVE-2015-3071, CVE-2015-3072, and CVE-2015-3074.

EPSS: Средний
github логотип

GHSA-28f5-7mw6-mfmc

около 3 лет назад

In AccountManager, there is a possible bypass of a permissions check due to a confused deputy. This could lead to local information disclosure, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-123700107

EPSS: Низкий
github логотип

GHSA-28f5-7fwx-xrf3

больше 3 лет назад

When SWFTools 0.9.2 processes a crafted file in png2swf, it can lead to a Segmentation Violation in the png_load() function in lib/png.c.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-28f5-3rf2-gpm8

около 3 лет назад

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.

EPSS: Низкий
github логотип

GHSA-28f4-mjfq-qrvf

почти 5 лет назад

Malicious Package in buffes-xor

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-28fq-p2c7-42px

Secom Co. Dr.ID, a Door Access Control and Personnel Attendance Management system, stores users’ information by cleartext in the cookie, which divulges password to attackers.

0%
Низкий
около 3 лет назад
github логотип
GHSA-28fp-mw8j-xfc5

The issue was addressed with improved handling of protocols. This issue is fixed in tvOS 17, iOS 16.7 and iPadOS 16.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. A remote attacker may be able to break out of Web Content sandbox.

CVSS3: 8.6
2%
Низкий
почти 2 года назад
github логотип
GHSA-28fm-qh2h-3mch

html2xhtml v1.3 was discovered to contain an Out-Of-Bounds read in the function static void elm_close(tree_node_t *nodo) at procesador.c. This vulnerability allows attackers to access sensitive files or cause a Denial of Service (DoS) via a crafted html file.

CVSS3: 8.1
2%
Низкий
почти 3 года назад
github логотип
GHSA-28fj-h7cm-23g6

The default configuration of the DVI print filter (dvips) in Red Hat Linux 7.0 and earlier does not run dvips in secure mode when dvips is executed by lpd, which could allow remote attackers to gain privileges by printing a DVI file that contains malicious commands.

5%
Низкий
больше 3 лет назад
github логотип
GHSA-28fh-4j57-cc4w

A vulnerability in Trend Micro Apex One and OfficeScan XG SP1 on Microsoft Windows may allow an attacker to create a hard link to any file on the system, which then could be manipulated to gain a privilege escalation and code execution. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. Please note that version 1909 (OS Build 18363.719) of Microsoft Windows 10 mitigates hard links, but previous versions are affected.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-28fh-3r6h-cgpw

A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka 'Microsoft PowerPoint Remote Code Execution Vulnerability'.

21%
Средний
около 3 лет назад
github логотип
GHSA-28fg-r93m-m726

The SupportCandy WordPress plugin before 3.1.7 does not properly sanitise and escape the `id` parameter for an Agent in the REST API before using it in an SQL statement, leading to an SQL Injection exploitable by users with a role as low as Subscriber.

CVSS3: 8.8
3%
Низкий
около 2 лет назад
github логотип
GHSA-28ff-x3xj-mx7q

An information disclosure vulnerability in libstagefright in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Android ID: A-31091777.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-28fc-gvjg-5f4h

** UNSUPPORTED WHEN ASSIGNED ** The unofficial vscode-sass-lint (aka Sass Lint) extension through 1.0.7 for Visual Studio Code allows attackers to execute arbitrary binaries if the user opens a crafted workspace. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 8.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-28f9-43w8-v45c

Buffer overflow in the ILASM assembler in the Microsoft .NET 1.0 and 1.1 Framework might allow user-assisted attackers to execute arbitrary code via a .il file that calls a function with a long name.

29%
Средний
больше 3 лет назад
github логотип
GHSA-28f8-hqmc-7ph8

Malicious Package in ember-power-timepicker

почти 5 лет назад
github логотип
GHSA-28f7-mc45-4x8m

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gordon Böhme, Antonio Leutsch Structured Content allows Stored XSS.This issue affects Structured Content: from n/a through 1.6.2.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-28f7-g5r5-mpx5

In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-28f6-9xpw-pwcr

Cross-site scripting (XSS) vulnerability in core/summary_api.php in MantisBT before 1.2.3 allows remote attackers to inject arbitrary web script or HTML via the Summary field, a different vector than CVE-2010-3303.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-28f6-647f-xq87

Buffer overflow in SonicWall SMA100 allows an authenticated user to execute arbitrary code in DEARegister CGI script. This vulnerability impacted SMA100 version 9.0.0.3 and earlier.

1%
Низкий
около 3 лет назад
github логотип
GHSA-28f5-mg2c-r34c

Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScript API execution via unspecified vectors, a different vulnerability than CVE-2015-3060, CVE-2015-3061, CVE-2015-3062, CVE-2015-3063, CVE-2015-3064, CVE-2015-3065, CVE-2015-3066, CVE-2015-3067, CVE-2015-3068, CVE-2015-3069, CVE-2015-3071, CVE-2015-3072, and CVE-2015-3074.

31%
Средний
больше 3 лет назад
github логотип
GHSA-28f5-7mw6-mfmc

In AccountManager, there is a possible bypass of a permissions check due to a confused deputy. This could lead to local information disclosure, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-123700107

0%
Низкий
около 3 лет назад
github логотип
GHSA-28f5-7fwx-xrf3

When SWFTools 0.9.2 processes a crafted file in png2swf, it can lead to a Segmentation Violation in the png_load() function in lib/png.c.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-28f5-3rf2-gpm8

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.

0%
Низкий
около 3 лет назад
github логотип
GHSA-28f4-mjfq-qrvf

Malicious Package in buffes-xor

CVSS3: 9.8
почти 5 лет назад

Уязвимостей на страницу