Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-3prq-6ph3-8hgv

больше 3 лет назад

In rw_i93_process_sys_info of rw_i93.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-121259048.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3prp-hmjp-8qm4

около 2 лет назад

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-3prm-h683-4rg5

больше 3 лет назад

An issue was discovered in Suricata 4.1.3. If the function filetracker_newchunk encounters an unsafe "Some(sfcm) => { ft.new_chunk }" item, then the program enters an smb/files.rs error condition and crashes.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3prm-9q6j-rf6p

5 месяцев назад

The All in one Minifier plugin for WordPress is vulnerable to SQL Injection via the 'post_id' parameter in all versions up to, and including, 3.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3prh-hhv2-x5qr

больше 3 лет назад

A use-after-free vulnerability in SMIL animation functions occurs when pointers to animation elements in an array are dropped from the animation controller while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3prf-xhv6-xgm8

около 1 года назад

Uncontrolled search path for some Intel(R) IPP software for Windows before version 2021.12.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3prf-q3vf-746c

больше 3 лет назад

In Kooboo CMS 2.1.1.0, it is possible to upload a remote shell (e.g., aspx) to the server and then call upon it to receive a reverse shell from the victim server. The files are uploaded to /Content/Template/root/reverse-shell.aspx and can be simply triggered by browsing that URL.

EPSS: Низкий
github логотип

GHSA-3prf-2gpr-5j48

почти 2 года назад

Dell RecoverPoint for Virtual Machines 5.3.x contains an OS Command injection vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to execute arbitrary operating system commands, which will get executed in the context of the root user, resulting in a complete system compromise.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3prc-rhm4-9vg8

почти 4 года назад

Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands.

EPSS: Высокий
github логотип

GHSA-3prc-hp8x-jp9c

почти 4 года назад

Remote attackers can crash Lynx and Internet Explorer using an IMG tag with a large width parameter.

EPSS: Низкий
github логотип

GHSA-3prc-c43p-xf25

больше 1 года назад

Improper Privilege Management vulnerability in Membership Software WishList Member X allows Privilege Escalation.This issue affects WishList Member X: from n/a through 3.25.1.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3pr9-fm6f-mq6g

почти 4 года назад

A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.2.14 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web components are used). The COMOS Web component of COMOS allows to upload and store arbitrary files at the webserver. This could allow an attacker to store malicious files.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3pr9-7mjx-7r2v

больше 3 лет назад

In wlan driver, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Patch ID: ALPS05412917.

EPSS: Низкий
github логотип

GHSA-3pr9-66rq-v5rm

больше 3 лет назад

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. While the vulnerability is in MySQL Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 7.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H).

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-3pr9-2fjg-j2x8

больше 3 лет назад

Insecure permissions in Confluent Ansible (cp-ansible) 5.5.0, 5.5.1, 5.5.2 and 6.0.0 allows local attackers to access some sensitive information (private keys, state database).

EPSS: Низкий
github логотип

GHSA-3pr9-266p-66h8

больше 3 лет назад

The netease movie (aka com.netease.movie) application 4.7.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-3pr8-rf62-g893

больше 3 лет назад

Path Traversal in Jenkins

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-3pr7-mf88-fxm3

больше 3 лет назад

The MsIo64.sys and MsIo32.sys drivers in Patriot Viper RGB before 1.1 allow local users (including low integrity processes) to read and write to arbitrary memory locations, and consequently gain NT AUTHORITY\SYSTEM privileges, by mapping \Device\PhysicalMemory into the calling process via ZwOpenSection and ZwMapViewOfSection.

EPSS: Низкий
github логотип

GHSA-3pr7-m23m-xgmq

больше 3 лет назад

SQL injection vulnerability in inc/lib/Control/Backend/menus.control.php in GeniXCMS through 1.0.2 allows remote authenticated users to execute arbitrary SQL commands via the order parameter.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3pr6-q8r5-4wq6

больше 3 лет назад

In Rockwell Automation PanelView 5510 (all versions manufactured before March 13, 2019 that have never been updated to v4.003, v5.002, or later), a remote, unauthenticated threat actor with access to an affected PanelView 5510 Graphic Display, upon successful exploit, may boot-up the terminal and gain root-level access to the device?s file system.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3prq-6ph3-8hgv

In rw_i93_process_sys_info of rw_i93.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-121259048.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3prp-hmjp-8qm4

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVSS3: 9.6
1%
Низкий
около 2 лет назад
github логотип
GHSA-3prm-h683-4rg5

An issue was discovered in Suricata 4.1.3. If the function filetracker_newchunk encounters an unsafe "Some(sfcm) => { ft.new_chunk }" item, then the program enters an smb/files.rs error condition and crashes.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3prm-9q6j-rf6p

The All in one Minifier plugin for WordPress is vulnerable to SQL Injection via the 'post_id' parameter in all versions up to, and including, 3.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-3prh-hhv2-x5qr

A use-after-free vulnerability in SMIL animation functions occurs when pointers to animation elements in an array are dropped from the animation controller while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3prf-xhv6-xgm8

Uncontrolled search path for some Intel(R) IPP software for Windows before version 2021.12.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 6.7
0%
Низкий
около 1 года назад
github логотип
GHSA-3prf-q3vf-746c

In Kooboo CMS 2.1.1.0, it is possible to upload a remote shell (e.g., aspx) to the server and then call upon it to receive a reverse shell from the victim server. The files are uploaded to /Content/Template/root/reverse-shell.aspx and can be simply triggered by browsing that URL.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3prf-2gpr-5j48

Dell RecoverPoint for Virtual Machines 5.3.x contains an OS Command injection vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to execute arbitrary operating system commands, which will get executed in the context of the root user, resulting in a complete system compromise.

CVSS3: 7.2
1%
Низкий
почти 2 года назад
github логотип
GHSA-3prc-rhm4-9vg8

Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands.

86%
Высокий
почти 4 года назад
github логотип
GHSA-3prc-hp8x-jp9c

Remote attackers can crash Lynx and Internet Explorer using an IMG tag with a large width parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3prc-c43p-xf25

Improper Privilege Management vulnerability in Membership Software WishList Member X allows Privilege Escalation.This issue affects WishList Member X: from n/a through 3.25.1.

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3pr9-fm6f-mq6g

A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.2.14 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web components are used). The COMOS Web component of COMOS allows to upload and store arbitrary files at the webserver. This could allow an attacker to store malicious files.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-3pr9-7mjx-7r2v

In wlan driver, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Patch ID: ALPS05412917.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3pr9-66rq-v5rm

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. While the vulnerability is in MySQL Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 7.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H).

CVSS3: 7.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3pr9-2fjg-j2x8

Insecure permissions in Confluent Ansible (cp-ansible) 5.5.0, 5.5.1, 5.5.2 and 6.0.0 allows local attackers to access some sensitive information (private keys, state database).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3pr9-266p-66h8

The netease movie (aka com.netease.movie) application 4.7.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3pr8-rf62-g893

Path Traversal in Jenkins

CVSS3: 6.5
11%
Средний
больше 3 лет назад
github логотип
GHSA-3pr7-mf88-fxm3

The MsIo64.sys and MsIo32.sys drivers in Patriot Viper RGB before 1.1 allow local users (including low integrity processes) to read and write to arbitrary memory locations, and consequently gain NT AUTHORITY\SYSTEM privileges, by mapping \Device\PhysicalMemory into the calling process via ZwOpenSection and ZwMapViewOfSection.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3pr7-m23m-xgmq

SQL injection vulnerability in inc/lib/Control/Backend/menus.control.php in GeniXCMS through 1.0.2 allows remote authenticated users to execute arbitrary SQL commands via the order parameter.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3pr6-q8r5-4wq6

In Rockwell Automation PanelView 5510 (all versions manufactured before March 13, 2019 that have never been updated to v4.003, v5.002, or later), a remote, unauthenticated threat actor with access to an affected PanelView 5510 Graphic Display, upon successful exploit, may boot-up the terminal and gain root-level access to the device?s file system.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу