Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3v6h-hqm4-2rg6

больше 7 лет назад

Arbitrary File Write in adm-zip

CVSS3: 5.5
EPSS: Средний
github логотип

GHSA-3v6h-4jjq-8c6c

6 месяцев назад

A weakness has been identified in elunez eladmin up to 2.7. This affects the function exportUser. This manipulation causes csv injection. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3v6f-r45v-h8fj

больше 2 лет назад

When reading a file, an uninitialized value could have been used as read limit. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3v6f-955w-932h

больше 3 лет назад

In Apache HTTP Server versions 2.4.0 to 2.4.23, malicious input to mod_auth_digest can cause the server to crash, and each instance continues to crash even for subsequently valid requests.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-3v69-r3x2-qgp5

около 4 лет назад

When running with FIPS mode enabled, Mirantis Container Runtime 20.10.8 leaks memory during TLS Handshakes which could be abused to cause a denial of service.

EPSS: Низкий
github логотип

GHSA-3v69-q96q-wq6c

больше 3 лет назад

Pydio Cells 2.0.4 allows XSS. A malicious user can either upload or create a new file that contains potentially malicious HTML and JavaScript code to personal folders or accessible cells.

EPSS: Низкий
github логотип

GHSA-3v69-2vx2-cxcc

около 1 года назад

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_mppi_controller.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3v69-2jfv-2mr2

больше 3 лет назад

An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar via a crafted web site.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3v68-xjhw-g33j

больше 3 лет назад

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.4.1.16828. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the resetForm method when processing AcroForms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-8229.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3v68-wgp5-q8w6

9 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay Top 10 allows Stored XSS. This issue affects Top 10: from n/a through 4.1.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3v68-r58v-m4c2

почти 4 года назад

The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as exploited in the wild by Gimmiv.A in October 2008, aka "Server Service Vulnerability."

EPSS: Критический
github логотип

GHSA-3v68-phv5-4j3p

7 месяцев назад

A vulnerability, which was classified as critical, has been found in Tenda FH451 1.0.0.9. Affected by this issue is the function fromP2pListFilter of the file /goform/P2pListFilter. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-3v68-hp3q-c376

около 3 лет назад

Out-of-bounds read was discovered in YDB server. An attacker could construct a query with insert statement that would allow him to read sensitive information from other memory locations or cause a crash.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-3v68-4wh3-g8fg

больше 3 лет назад

Race condition in providers/telephony/MmsProvider.java in Telephony in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows attackers to gain privileges via a crafted application that modifies a database between two open operations, aka internal bug 30481342.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3v67-94rm-j953

больше 3 лет назад

IBM Security Directory Server 6.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 165815.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3v67-76rr-2qc3

около 4 лет назад

Use after free in developer tools in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3v67-545x-ffc3

11 месяцев назад

Apache Kylin Server-Side Request Forgery (SSRF) via `/kylin/api/xxx/diag` Endpoint

EPSS: Низкий
github логотип

GHSA-3v66-h3rq-pj5p

почти 4 года назад

drupal6 version 6.16 has open redirection

EPSS: Низкий
github логотип

GHSA-3v66-3586-p5rh

больше 3 лет назад

** DISPUTED ** An issue was discovered in SMA Solar Technology products. If a user simultaneously has Sunny Explorer running and visits a malicious host, cross-site request forgery can be used to change settings in the inverters (for example, issuing a POST request to change the user password). All Sunny Explorer settings available to the authenticated user are also available to the attacker. (In some cases, this also includes changing settings that the user has no access to.) This may result in complete compromise of the device. NOTE: the vendor reports that exploitation is unlikely because Sunny Explorer is used only rarely. Also, only Sunny Boy TLST-21 and TL-21 and Sunny Tripower TL-10 and TL-30 could potentially be affected.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3v65-m7jv-mqrv

10 месяцев назад

Missing Authorization vulnerability in Andy Stratton Append Content allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Append Content: from n/a through 2.1.1.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3v6h-hqm4-2rg6

Arbitrary File Write in adm-zip

CVSS3: 5.5
18%
Средний
больше 7 лет назад
github логотип
GHSA-3v6h-4jjq-8c6c

A weakness has been identified in elunez eladmin up to 2.7. This affects the function exportUser. This manipulation causes csv injection. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.

CVSS3: 6.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-3v6f-r45v-h8fj

When reading a file, an uninitialized value could have been used as read limit. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3v6f-955w-932h

In Apache HTTP Server versions 2.4.0 to 2.4.23, malicious input to mod_auth_digest can cause the server to crash, and each instance continues to crash even for subsequently valid requests.

CVSS3: 7.5
40%
Средний
больше 3 лет назад
github логотип
GHSA-3v69-r3x2-qgp5

When running with FIPS mode enabled, Mirantis Container Runtime 20.10.8 leaks memory during TLS Handshakes which could be abused to cause a denial of service.

0%
Низкий
около 4 лет назад
github логотип
GHSA-3v69-q96q-wq6c

Pydio Cells 2.0.4 allows XSS. A malicious user can either upload or create a new file that contains potentially malicious HTML and JavaScript code to personal folders or accessible cells.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3v69-2vx2-cxcc

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_mppi_controller.

CVSS3: 9.8
0%
Низкий
около 1 года назад
github логотип
GHSA-3v69-2jfv-2mr2

An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar via a crafted web site.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3v68-xjhw-g33j

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.4.1.16828. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the resetForm method when processing AcroForms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-8229.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3v68-wgp5-q8w6

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay Top 10 allows Stored XSS. This issue affects Top 10: from n/a through 4.1.0.

CVSS3: 6.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-3v68-r58v-m4c2

The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as exploited in the wild by Gimmiv.A in October 2008, aka "Server Service Vulnerability."

94%
Критический
почти 4 года назад
github логотип
GHSA-3v68-phv5-4j3p

A vulnerability, which was classified as critical, has been found in Tenda FH451 1.0.0.9. Affected by this issue is the function fromP2pListFilter of the file /goform/P2pListFilter. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
11%
Средний
7 месяцев назад
github логотип
GHSA-3v68-hp3q-c376

Out-of-bounds read was discovered in YDB server. An attacker could construct a query with insert statement that would allow him to read sensitive information from other memory locations or cause a crash.

CVSS3: 9.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-3v68-4wh3-g8fg

Race condition in providers/telephony/MmsProvider.java in Telephony in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows attackers to gain privileges via a crafted application that modifies a database between two open operations, aka internal bug 30481342.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3v67-94rm-j953

IBM Security Directory Server 6.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 165815.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3v67-76rr-2qc3

Use after free in developer tools in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-3v67-545x-ffc3

Apache Kylin Server-Side Request Forgery (SSRF) via `/kylin/api/xxx/diag` Endpoint

0%
Низкий
11 месяцев назад
github логотип
GHSA-3v66-h3rq-pj5p

drupal6 version 6.16 has open redirection

1%
Низкий
почти 4 года назад
github логотип
GHSA-3v66-3586-p5rh

** DISPUTED ** An issue was discovered in SMA Solar Technology products. If a user simultaneously has Sunny Explorer running and visits a malicious host, cross-site request forgery can be used to change settings in the inverters (for example, issuing a POST request to change the user password). All Sunny Explorer settings available to the authenticated user are also available to the attacker. (In some cases, this also includes changing settings that the user has no access to.) This may result in complete compromise of the device. NOTE: the vendor reports that exploitation is unlikely because Sunny Explorer is used only rarely. Also, only Sunny Boy TLST-21 and TL-21 and Sunny Tripower TL-10 and TL-30 could potentially be affected.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3v65-m7jv-mqrv

Missing Authorization vulnerability in Andy Stratton Append Content allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Append Content: from n/a through 2.1.1.

CVSS3: 6.5
0%
Низкий
10 месяцев назад

Уязвимостей на страницу