Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 375

Количество 314 375

github логотип

GHSA-3v7r-5qj8-2v68

больше 3 лет назад

redhat-certification does not properly sanitize paths in rhcertStore.py:__saveResultsFile. A remote attacker could use this flaw to overwrite any file, potentially gaining remote code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3v7q-6w55-588c

больше 3 лет назад

lisp/gnus/gnus-fun.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on the /tmp/gnus.face.ppm temporary file.

EPSS: Низкий
github логотип

GHSA-3v7p-mx8w-xf2h

около 2 лет назад

Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'id' parameter of the partner_preference.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3v7p-2jr8-qj72

4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: x86/speculation: Fill RSB on vmexit for IBRS Prevent RSB underflow/poisoning attacks with RSB. While at it, add a bunch of comments to attempt to document the current state of tribal knowledge about RSB attacks and what exactly is being mitigated.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3v7m-rv2r-mcp9

около 3 лет назад

A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to cause a Denial of Service by Rebooting the router through " /mgm_dev_reboot.asp."

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3v7m-2jrh-vc93

около 3 лет назад

Froxlor vulnerable to Argument Injection

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3v7g-82fr-x624

почти 4 года назад

Cross-site scripting (XSS) vulnerability in KnowledgeTree Open Source 3.4 and 3.4.1 allows remote attackers to inject arbitrary web script or HTML via the login field on the login page, and other unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3v7g-4pg3-7r6j

почти 4 года назад

OS Command injection in Apache Airflow

CVSS3: 8.8
EPSS: Критический
github логотип

GHSA-3v7f-rjgx-9grq

больше 2 лет назад

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. When nf_tables_delrule() is flushing table rules, it is not checked whether the chain is bound and the chain's owner rule can also release the objects in certain circumstances. We recommend upgrading past commit 6eaf41e87a223ae6f8e7a28d6e78384ad7e407f8.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3v7f-ppjx-349f

почти 4 года назад

Ziproxy 2.6.0, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header.

EPSS: Низкий
github логотип

GHSA-3v7c-xw2c-76j5

больше 1 года назад

ZWX-2000CSW2-HN firmware versions prior to Ver.0.3.15 uses hard-coded credentials, which may allow a network-adjacent attacker with an administrative privilege to alter the configuration of the device.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3v7c-v9wf-3c7v

около 2 лет назад

There is a Cross-site scripting (XSS)  vulnerability in ZTE MF258. Due to insufficient input validation of SMS interface parameter, an XSS attack will be triggered.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-3v7c-p24m-p9gr

больше 3 лет назад

Juniper Networks Junos OS 16.1R1, and services releases based off of 16.1R1, are vulnerable to the receipt of a crafted BGP Protocol Data Unit (PDU) sent directly to the router, which can cause the RPD routing process to crash and restart. Unlike BGP UPDATEs, which are transitive in nature, this issue can only be triggered by a packet sent directly to the IP address of the router. Repeated crashes of the rpd daemon can result in an extended denial of service condition. This issue only affects devices running Junos OS 16.1R1 and services releases based off of 16.1R1 (e.g. 16.1R1-S1, 16.1R1-S2, 16.1R1-S3). No prior versions of Junos OS are affected by this vulnerability, and this issue was resolved in Junos OS 16.2 prior to 16.2R1. No other Juniper Networks products or platforms are affected by this issue. This issue was found during internal product security testing.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3v79-q7ph-j75h

почти 2 года назад

MLFlow Cross-site Scripting vulnerability leads to client-side Remote Code Execution

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-3v79-p2r2-6744

почти 2 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Reilly Configure SMTP allows Reflected XSS.This issue affects Configure SMTP: from n/a through 3.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3v79-5f35-jq7j

больше 3 лет назад

Multiple buffer overflows in kernel in Intel Trusted Execution Engine Firmware 3.0 allow attacker with local access to the system to execute arbitrary code.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3v78-x6p4-8r93

12 месяцев назад

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in MarketingFire Widget Options allows OS Command Injection.This issue affects Widget Options: from n/a through 4.1.0.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-3v77-c57x-prrv

больше 3 лет назад

ChakraCore and Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11792, CVE-2017-11793, CVE-2017-11796, CVE-2017-11797, CVE-2017-11798, CVE-2017-11799, CVE-2017-11800, CVE-2017-11801, CVE-2017-11802, CVE-2017-11804, CVE-2017-11805, CVE-2017-11806, CVE-2017-11807, CVE-2017-11808, CVE-2017-11809, CVE-2017-11810, CVE-2017-11812, and CVE-2017-11821.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-3v76-qg7g-rx9c

около 2 лет назад

OpenSIS Classic Community Edition version 9.0 lacks cross-site request forgery (CSRF) protection throughout the whole app. This may allow an attacker to trick an authenticated user into performing any kind of state changing request.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3v76-jmwq-837x

больше 3 лет назад

Local file inclusion vulnerability in Zenphoto 1.4.14 and earlier allows a remote attacker with an administrative privilege to execute arbitrary code or obtain sensitive information.

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3v7r-5qj8-2v68

redhat-certification does not properly sanitize paths in rhcertStore.py:__saveResultsFile. A remote attacker could use this flaw to overwrite any file, potentially gaining remote code execution.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3v7q-6w55-588c

lisp/gnus/gnus-fun.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on the /tmp/gnus.face.ppm temporary file.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3v7p-mx8w-xf2h

Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'id' parameter of the partner_preference.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-3v7p-2jr8-qj72

In the Linux kernel, the following vulnerability has been resolved: x86/speculation: Fill RSB on vmexit for IBRS Prevent RSB underflow/poisoning attacks with RSB. While at it, add a bunch of comments to attempt to document the current state of tribal knowledge about RSB attacks and what exactly is being mitigated.

CVSS3: 5.5
0%
Низкий
4 месяца назад
github логотип
GHSA-3v7m-rv2r-mcp9

A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to cause a Denial of Service by Rebooting the router through " /mgm_dev_reboot.asp."

CVSS3: 6.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-3v7m-2jrh-vc93

Froxlor vulnerable to Argument Injection

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-3v7g-82fr-x624

Cross-site scripting (XSS) vulnerability in KnowledgeTree Open Source 3.4 and 3.4.1 allows remote attackers to inject arbitrary web script or HTML via the login field on the login page, and other unspecified vectors.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3v7g-4pg3-7r6j

OS Command injection in Apache Airflow

CVSS3: 8.8
90%
Критический
почти 4 года назад
github логотип
GHSA-3v7f-rjgx-9grq

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. When nf_tables_delrule() is flushing table rules, it is not checked whether the chain is bound and the chain's owner rule can also release the objects in certain circumstances. We recommend upgrading past commit 6eaf41e87a223ae6f8e7a28d6e78384ad7e407f8.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3v7f-ppjx-349f

Ziproxy 2.6.0, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3v7c-xw2c-76j5

ZWX-2000CSW2-HN firmware versions prior to Ver.0.3.15 uses hard-coded credentials, which may allow a network-adjacent attacker with an administrative privilege to alter the configuration of the device.

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3v7c-v9wf-3c7v

There is a Cross-site scripting (XSS)  vulnerability in ZTE MF258. Due to insufficient input validation of SMS interface parameter, an XSS attack will be triggered.

CVSS3: 5.7
0%
Низкий
около 2 лет назад
github логотип
GHSA-3v7c-p24m-p9gr

Juniper Networks Junos OS 16.1R1, and services releases based off of 16.1R1, are vulnerable to the receipt of a crafted BGP Protocol Data Unit (PDU) sent directly to the router, which can cause the RPD routing process to crash and restart. Unlike BGP UPDATEs, which are transitive in nature, this issue can only be triggered by a packet sent directly to the IP address of the router. Repeated crashes of the rpd daemon can result in an extended denial of service condition. This issue only affects devices running Junos OS 16.1R1 and services releases based off of 16.1R1 (e.g. 16.1R1-S1, 16.1R1-S2, 16.1R1-S3). No prior versions of Junos OS are affected by this vulnerability, and this issue was resolved in Junos OS 16.2 prior to 16.2R1. No other Juniper Networks products or platforms are affected by this issue. This issue was found during internal product security testing.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3v79-q7ph-j75h

MLFlow Cross-site Scripting vulnerability leads to client-side Remote Code Execution

CVSS3: 9.6
0%
Низкий
почти 2 года назад
github логотип
GHSA-3v79-p2r2-6744

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Reilly Configure SMTP allows Reflected XSS.This issue affects Configure SMTP: from n/a through 3.1.

CVSS3: 7.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-3v79-5f35-jq7j

Multiple buffer overflows in kernel in Intel Trusted Execution Engine Firmware 3.0 allow attacker with local access to the system to execute arbitrary code.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3v78-x6p4-8r93

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in MarketingFire Widget Options allows OS Command Injection.This issue affects Widget Options: from n/a through 4.1.0.

CVSS3: 9.9
1%
Низкий
12 месяцев назад
github логотип
GHSA-3v77-c57x-prrv

ChakraCore and Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11792, CVE-2017-11793, CVE-2017-11796, CVE-2017-11797, CVE-2017-11798, CVE-2017-11799, CVE-2017-11800, CVE-2017-11801, CVE-2017-11802, CVE-2017-11804, CVE-2017-11805, CVE-2017-11806, CVE-2017-11807, CVE-2017-11808, CVE-2017-11809, CVE-2017-11810, CVE-2017-11812, and CVE-2017-11821.

CVSS3: 7.5
42%
Средний
больше 3 лет назад
github логотип
GHSA-3v76-qg7g-rx9c

OpenSIS Classic Community Edition version 9.0 lacks cross-site request forgery (CSRF) protection throughout the whole app. This may allow an attacker to trick an authenticated user into performing any kind of state changing request.

CVSS3: 8.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-3v76-jmwq-837x

Local file inclusion vulnerability in Zenphoto 1.4.14 and earlier allows a remote attacker with an administrative privilege to execute arbitrary code or obtain sensitive information.

CVSS3: 7.2
2%
Низкий
больше 3 лет назад

Уязвимостей на страницу