Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 289 610

Количество 289 610

github логотип

GHSA-2868-jvjx-qxr9

больше 3 лет назад

Vulnerability in the Siebel Engineering - Installer and Deployment component of Oracle Siebel CRM (subcomponent: Siebel Approval Manager). Supported versions that are affected are 16.0 and 17.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Engineering - Installer and Deployment. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Siebel Engineering - Installer and Deployment accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2868-gw76-97vq

около 2 лет назад

When adding a remote backup location, an authenticated user can pass arbitrary OS commands through the username field. The username is passed without sanitization into CMD running as NT/Authority System. An authenticated attacker can leverage this vulnerability to execute arbitrary code with system-level access to the CyberPower PowerPanel Enterprise server.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-2868-ff44-43qv

около 2 лет назад

Liferay portal unauthorized access to objects via OAuth 2 scope

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2867-6rrm-38gr

больше 1 года назад

Laravel Cookie serialization vulnerability

EPSS: Низкий
github логотип

GHSA-2866-fxpg-497j

около 3 лет назад

An issue was discovered in Viki Vera 4.9.1.26180. A user without access to a project could download or upload project files by opening the Project URL directly in the browser after logging in.

EPSS: Низкий
github логотип

GHSA-2865-jgr8-fxmw

больше 1 года назад

Leave Management System Project v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'setsickleave' parameter of the admin/setleaves.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2865-hh9g-w894

5 месяцев назад

Microsoft Security Advisory CVE-2025-24070: .NET Elevation of Privilege Vulnerability

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-2865-989q-255f

больше 3 лет назад

A flaw was found in the Linux kernels implementation of audit rules, where a syscall can unexpectedly not be correctly not be logged by the audit subsystem

CVSS3: 3.4
EPSS: Низкий
github логотип

GHSA-2864-f23c-87xc

больше 3 лет назад

Buffer overflow in BEA WebLogic Server and WebLogic Express 6.1 Service Pack 4 allows remote attackers to cause a denial of service (CPU consumption from thread looping).

EPSS: Низкий
github логотип

GHSA-2863-x4gc-m9xw

больше 3 лет назад

Directory traversal vulnerability in frontend/x3/stats/lastvisit.html in cPanel allows remote attackers to read arbitrary files via a .. (dot dot) in the domain parameter.

EPSS: Низкий
github логотип

GHSA-2863-w2j8-vfhc

больше 3 лет назад

Cisco IOS before 12.2(33)SXI allows remote authenticated users to cause a denial of service (device reboot).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2863-j7v4-23fv

около 3 лет назад

Adobe Acrobat and Reader versions, 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2017.011.30142 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

EPSS: Средний
github логотип

GHSA-2862-gpw6-r482

6 месяцев назад

A Cross Site Scripting (XSS) vulnerability in GitLab-EE affecting all versions from 16.6 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows an attacker to bypass security controls and execute arbitrary scripts in a users browser under specific conditions.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-2862-5xjv-8phr

12 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: ice: fix concurrent reset and removal of VFs Commit c503e63200c6 ("ice: Stop processing VF messages during teardown") introduced a driver state flag, ICE_VF_DEINIT_IN_PROGRESS, which is intended to prevent some issues with concurrently handling messages from VFs while tearing down the VFs. This change was motivated by crashes caused while tearing down and bringing up VFs in rapid succession. It turns out that the fix actually introduces issues with the VF driver caused because the PF no longer responds to any messages sent by the VF during its .remove routine. This results in the VF potentially removing its DMA memory before the PF has shut down the device queues. Additionally, the fix doesn't actually resolve concurrency issues within the ice driver. It is possible for a VF to initiate a reset just prior to the ice driver removing VFs. This can result in the remove task concurrently operating while the VF is b...

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-2862-59r4-c989

больше 1 года назад

Request smuggling vulnerability in HTTP server in Apache bRPC 0.9.5~1.7.0 on all platforms allows attacker to smuggle request. Vulnerability Cause Description: The http_parser does not comply with the RFC-7230 HTTP 1.1 specification. Attack scenario: If a message is received with both a Transfer-Encoding and a Content-Length header field, such a message might indicate an attempt to perform request smuggling or response splitting. One particular attack scenario is that a bRPC made http server on the backend receiving requests in one persistent connection from frontend server that uses TE to parse request with the logic that 'chunk' is contained in the TE field. in that case an attacker can smuggle a request into the connection to the backend server.  Solution: You can choose one solution from below: 1. Upgrade bRPC to version 1.8.0, which fixes this issue. Download link: https://github.com/apache/brpc/releases/tag/1.8.0 2. Apply this patch:  https://github.com/apache/brpc/...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2862-4mgm-j6fv

больше 3 лет назад

** DISPUTED ** The validateInputImageSize function in modules/imgcodecs/src/loadsave.cpp in OpenCV 3.4.1 allows remote attackers to cause a denial of service (assertion failure) because (pixels <= (1<<30)) may be false. Note: “OpenCV CV_Assert is not an assertion (C-like assert()), it is regular C++ exception which can raised in case of invalid or non-supported parameters.”

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-285w-5q64-gvjx

больше 3 лет назад

A remote denial of service vulnerability in libvpx in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34360591.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-285v-m5qf-m8fp

больше 2 лет назад

In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-285v-3c4r-gxww

больше 3 лет назад

Unspecified vulnerability in the MOUNT dissector in Wireshark (aka Ethereal) 0.9.4 to 0.99.0 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.

EPSS: Средний
github логотип

GHSA-285r-jf89-jj3c

больше 3 лет назад

The IBM Stax XMLStreamWriter in the Web Services component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 does not properly process XML encoding, which allows remote attackers to bypass intended access restrictions and possibly modify data via "XML fuzzing attacks" sent through SOAP requests.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2868-jvjx-qxr9

Vulnerability in the Siebel Engineering - Installer and Deployment component of Oracle Siebel CRM (subcomponent: Siebel Approval Manager). Supported versions that are affected are 16.0 and 17.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Engineering - Installer and Deployment. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Siebel Engineering - Installer and Deployment accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2868-gw76-97vq

When adding a remote backup location, an authenticated user can pass arbitrary OS commands through the username field. The username is passed without sanitization into CMD running as NT/Authority System. An authenticated attacker can leverage this vulnerability to execute arbitrary code with system-level access to the CyberPower PowerPanel Enterprise server.

CVSS3: 9.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-2868-ff44-43qv

Liferay portal unauthorized access to objects via OAuth 2 scope

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-2867-6rrm-38gr

Laravel Cookie serialization vulnerability

больше 1 года назад
github логотип
GHSA-2866-fxpg-497j

An issue was discovered in Viki Vera 4.9.1.26180. A user without access to a project could download or upload project files by opening the Project URL directly in the browser after logging in.

0%
Низкий
около 3 лет назад
github логотип
GHSA-2865-jgr8-fxmw

Leave Management System Project v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'setsickleave' parameter of the admin/setleaves.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2865-hh9g-w894

Microsoft Security Advisory CVE-2025-24070: .NET Elevation of Privilege Vulnerability

CVSS3: 7
0%
Низкий
5 месяцев назад
github логотип
GHSA-2865-989q-255f

A flaw was found in the Linux kernels implementation of audit rules, where a syscall can unexpectedly not be correctly not be logged by the audit subsystem

CVSS3: 3.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2864-f23c-87xc

Buffer overflow in BEA WebLogic Server and WebLogic Express 6.1 Service Pack 4 allows remote attackers to cause a denial of service (CPU consumption from thread looping).

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2863-x4gc-m9xw

Directory traversal vulnerability in frontend/x3/stats/lastvisit.html in cPanel allows remote attackers to read arbitrary files via a .. (dot dot) in the domain parameter.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2863-w2j8-vfhc

Cisco IOS before 12.2(33)SXI allows remote authenticated users to cause a denial of service (device reboot).

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2863-j7v4-23fv

Adobe Acrobat and Reader versions, 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2017.011.30142 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

24%
Средний
около 3 лет назад
github логотип
GHSA-2862-gpw6-r482

A Cross Site Scripting (XSS) vulnerability in GitLab-EE affecting all versions from 16.6 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows an attacker to bypass security controls and execute arbitrary scripts in a users browser under specific conditions.

CVSS3: 7.7
0%
Низкий
6 месяцев назад
github логотип
GHSA-2862-5xjv-8phr

In the Linux kernel, the following vulnerability has been resolved: ice: fix concurrent reset and removal of VFs Commit c503e63200c6 ("ice: Stop processing VF messages during teardown") introduced a driver state flag, ICE_VF_DEINIT_IN_PROGRESS, which is intended to prevent some issues with concurrently handling messages from VFs while tearing down the VFs. This change was motivated by crashes caused while tearing down and bringing up VFs in rapid succession. It turns out that the fix actually introduces issues with the VF driver caused because the PF no longer responds to any messages sent by the VF during its .remove routine. This results in the VF potentially removing its DMA memory before the PF has shut down the device queues. Additionally, the fix doesn't actually resolve concurrency issues within the ice driver. It is possible for a VF to initiate a reset just prior to the ice driver removing VFs. This can result in the remove task concurrently operating while the VF is b...

CVSS3: 4.7
0%
Низкий
12 месяцев назад
github логотип
GHSA-2862-59r4-c989

Request smuggling vulnerability in HTTP server in Apache bRPC 0.9.5~1.7.0 on all platforms allows attacker to smuggle request. Vulnerability Cause Description: The http_parser does not comply with the RFC-7230 HTTP 1.1 specification. Attack scenario: If a message is received with both a Transfer-Encoding and a Content-Length header field, such a message might indicate an attempt to perform request smuggling or response splitting. One particular attack scenario is that a bRPC made http server on the backend receiving requests in one persistent connection from frontend server that uses TE to parse request with the logic that 'chunk' is contained in the TE field. in that case an attacker can smuggle a request into the connection to the backend server.  Solution: You can choose one solution from below: 1. Upgrade bRPC to version 1.8.0, which fixes this issue. Download link: https://github.com/apache/brpc/releases/tag/1.8.0 2. Apply this patch:  https://github.com/apache/brpc/...

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2862-4mgm-j6fv

** DISPUTED ** The validateInputImageSize function in modules/imgcodecs/src/loadsave.cpp in OpenCV 3.4.1 allows remote attackers to cause a denial of service (assertion failure) because (pixels <= (1<<30)) may be false. Note: “OpenCV CV_Assert is not an assertion (C-like assert()), it is regular C++ exception which can raised in case of invalid or non-supported parameters.”

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-285w-5q64-gvjx

A remote denial of service vulnerability in libvpx in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34360591.

CVSS3: 5.5
3%
Низкий
больше 3 лет назад
github логотип
GHSA-285v-m5qf-m8fp

In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-285v-3c4r-gxww

Unspecified vulnerability in the MOUNT dissector in Wireshark (aka Ethereal) 0.9.4 to 0.99.0 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.

11%
Средний
больше 3 лет назад
github логотип
GHSA-285r-jf89-jj3c

The IBM Stax XMLStreamWriter in the Web Services component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 does not properly process XML encoding, which allows remote attackers to bypass intended access restrictions and possibly modify data via "XML fuzzing attacks" sent through SOAP requests.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу