Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 289 392

Количество 289 392

github логотип

GHSA-273r-v888-vgc6

около 3 лет назад

Magento Cross-site Scripting (XSS)

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-273r-rm8g-7f3x

больше 3 лет назад

Uncaught Exception in mercurius

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-273r-q5cp-p9c2

около 3 лет назад

A memory leak was discovered in image_buffer_resize in fromsixel.c in libsixel 1.8.4.

EPSS: Низкий
github логотип

GHSA-273r-mgr4-v34f

больше 3 лет назад

Uncaught Exception in engine.io

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-273r-f986-fq9q

15 дней назад

Stored cross-site scripting vulnerability exists in multiple versions of PowerCMS. If a product user accesses a malicious page, an arbitrary script may be executed on the browser.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-273m-fmw2-8c3p

больше 3 лет назад

Multiple buffer overflows in Miranda before 0.7.1 allow remote attackers to execute arbitrary code via unspecified vectors involving (1) IRC options, (2) Jabber forms, and unspecified aspects of the (3) ICQ and (4) Yahoo! instant messaging functionality. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-273m-f252-4rf8

больше 3 лет назад

Sugar Suite Open Source (SugarCRM) 4.2 and earlier, when register_globals is enabled, does not protect critical variables such as $_GLOBALS and $_SESSION from modification, which allows remote attackers to conduct attacks such as directory traversal or PHP remote file inclusion, as demonstrated by modifying the GLOBALS[sugarEntry] parameter.

EPSS: Низкий
github логотип

GHSA-273j-j8fx-2wqf

около 3 лет назад

The Device Model in ACRN through 2.5 has a devicemodel/core/mem.c use-after-free for a freed rb_entry.

EPSS: Низкий
github логотип

GHSA-273j-fjrx-gf2f

больше 1 года назад

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Oracle Java SE: 8u401, 8u401-perf, 11.0.22; Oracle GraalVM Enterprise Edition: 20.3.13 and 21.3.9. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely...

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-273j-3w9c-cwgw

больше 2 лет назад

Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the funcpara1 parameter in the formSetCfm function.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-273h-mfpf-cvq6

около 1 года назад

An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos 1280, Exynos 1380, Exynos 1330, Exynos W920, Exynos W930. The mobile processor lacks proper memory deallocation checking, which can result in a UAF (Use-After-Free) vulnerability.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-273h-28gx-8f5j

больше 1 года назад

A format string issue in the Controller 6000's optional diagnostic web interface can be used to write/read from memory, and in some instances crash the Controller 6000 leading to a Denial of Service. This issue affects: Gallagher Controller 6000 8.60 prior to vCR8.60.231116a (distributed in 8.60.2550 (MR7)), all versions of 8.50 and prior.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-273g-rphj-ghmm

около 3 лет назад

Heap-buffer overflow in the randomize_iparp function in edit_packet.c. of Tcpreplay v4.3.2 allows attackers to cause a denial of service (DOS) via a crafted pcap.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-273g-8x52-9gmv

около 1 года назад

Cross-site scripting vulnerability exists in sysinfo.cgi of Webmin versions prior to 1.910. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product. As a result, a session ID may be obtained, a webpage may be altered, or a server may be halted.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-273f-xq73-5xpg

около 3 лет назад

Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/classes/Master.php?f=delete_service.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-273f-pp2q-7h53

около 1 года назад

A vulnerability classified as critical was found in itsourcecode Alton Management System 1.0. This vulnerability affects unknown code of the file search.php. The manipulation of the argument rcode leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-273142 is the identifier assigned to this vulnerability.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-273f-4jvc-r526

больше 3 лет назад

** DISPUTED ** Integer signedness error in the pmcraid_ioctl_passthrough function in drivers/scsi/pmcraid.c in the Linux kernel before 3.1 might allow local users to cause a denial of service (memory consumption or memory corruption) via a negative size value in an ioctl call. NOTE: this may be a vulnerability only in unusual environments that provide a privileged program for obtaining the required file descriptor.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-273f-4hpp-885q

около 3 лет назад

A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0650, CVE-2020-0651.

EPSS: Средний
github логотип

GHSA-273c-fjw8-v2w8

около 3 лет назад

Jenkins OpsGenie Plugin Plaintext Storage of a Password vulnerability

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-273c-f2cx-c649

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: efi/fdt: fix panic when no valid fdt found setup_arch() would invoke efi_init()->efi_get_fdt_params(). If no valid fdt found then initial_boot_params will be null. So we should stop further fdt processing here. I encountered this issue on risc-v.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-273r-v888-vgc6

Magento Cross-site Scripting (XSS)

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-273r-rm8g-7f3x

Uncaught Exception in mercurius

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-273r-q5cp-p9c2

A memory leak was discovered in image_buffer_resize in fromsixel.c in libsixel 1.8.4.

0%
Низкий
около 3 лет назад
github логотип
GHSA-273r-mgr4-v34f

Uncaught Exception in engine.io

CVSS3: 7.5
4%
Низкий
больше 3 лет назад
github логотип
GHSA-273r-f986-fq9q

Stored cross-site scripting vulnerability exists in multiple versions of PowerCMS. If a product user accesses a malicious page, an arbitrary script may be executed on the browser.

CVSS3: 5.4
0%
Низкий
15 дней назад
github логотип
GHSA-273m-fmw2-8c3p

Multiple buffer overflows in Miranda before 0.7.1 allow remote attackers to execute arbitrary code via unspecified vectors involving (1) IRC options, (2) Jabber forms, and unspecified aspects of the (3) ICQ and (4) Yahoo! instant messaging functionality. NOTE: some of these details are obtained from third party information.

9%
Низкий
больше 3 лет назад
github логотип
GHSA-273m-f252-4rf8

Sugar Suite Open Source (SugarCRM) 4.2 and earlier, when register_globals is enabled, does not protect critical variables such as $_GLOBALS and $_SESSION from modification, which allows remote attackers to conduct attacks such as directory traversal or PHP remote file inclusion, as demonstrated by modifying the GLOBALS[sugarEntry] parameter.

7%
Низкий
больше 3 лет назад
github логотип
GHSA-273j-j8fx-2wqf

The Device Model in ACRN through 2.5 has a devicemodel/core/mem.c use-after-free for a freed rb_entry.

0%
Низкий
около 3 лет назад
github логотип
GHSA-273j-fjrx-gf2f

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Oracle Java SE: 8u401, 8u401-perf, 11.0.22; Oracle GraalVM Enterprise Edition: 20.3.13 and 21.3.9. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely...

CVSS3: 3.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-273j-3w9c-cwgw

Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the funcpara1 parameter in the formSetCfm function.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-273h-mfpf-cvq6

An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos 1280, Exynos 1380, Exynos 1330, Exynos W920, Exynos W930. The mobile processor lacks proper memory deallocation checking, which can result in a UAF (Use-After-Free) vulnerability.

CVSS3: 8.4
0%
Низкий
около 1 года назад
github логотип
GHSA-273h-28gx-8f5j

A format string issue in the Controller 6000's optional diagnostic web interface can be used to write/read from memory, and in some instances crash the Controller 6000 leading to a Denial of Service. This issue affects: Gallagher Controller 6000 8.60 prior to vCR8.60.231116a (distributed in 8.60.2550 (MR7)), all versions of 8.50 and prior.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-273g-rphj-ghmm

Heap-buffer overflow in the randomize_iparp function in edit_packet.c. of Tcpreplay v4.3.2 allows attackers to cause a denial of service (DOS) via a crafted pcap.

CVSS3: 5.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-273g-8x52-9gmv

Cross-site scripting vulnerability exists in sysinfo.cgi of Webmin versions prior to 1.910. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product. As a result, a session ID may be obtained, a webpage may be altered, or a server may be halted.

CVSS3: 5.4
0%
Низкий
около 1 года назад
github логотип
GHSA-273f-xq73-5xpg

Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/classes/Master.php?f=delete_service.

CVSS3: 9.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-273f-pp2q-7h53

A vulnerability classified as critical was found in itsourcecode Alton Management System 1.0. This vulnerability affects unknown code of the file search.php. The manipulation of the argument rcode leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-273142 is the identifier assigned to this vulnerability.

CVSS3: 6.3
0%
Низкий
около 1 года назад
github логотип
GHSA-273f-4jvc-r526

** DISPUTED ** Integer signedness error in the pmcraid_ioctl_passthrough function in drivers/scsi/pmcraid.c in the Linux kernel before 3.1 might allow local users to cause a denial of service (memory consumption or memory corruption) via a negative size value in an ioctl call. NOTE: this may be a vulnerability only in unusual environments that provide a privileged program for obtaining the required file descriptor.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-273f-4hpp-885q

A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0650, CVE-2020-0651.

33%
Средний
около 3 лет назад
github логотип
GHSA-273c-fjw8-v2w8

Jenkins OpsGenie Plugin Plaintext Storage of a Password vulnerability

CVSS3: 4.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-273c-f2cx-c649

In the Linux kernel, the following vulnerability has been resolved: efi/fdt: fix panic when no valid fdt found setup_arch() would invoke efi_init()->efi_get_fdt_params(). If no valid fdt found then initial_boot_params will be null. So we should stop further fdt processing here. I encountered this issue on risc-v.

CVSS3: 5.5
0%
Низкий
больше 1 года назад

Уязвимостей на страницу