Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3r39-mw8c-6g5f

12 месяцев назад

A vulnerability, which was classified as problematic, was found in radare2 5.9.9 33286. Affected is an unknown function in the library /libr/main/rasm2.c of the component rasm2. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 6.0.0 is able to address this issue. The patch is identified as c6c772d2eab692ce7ada5a4227afd50c355ad545. It is recommended to upgrade the affected component.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-3r38-g3wv-x66q

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in admin/webservice/forms.php in the web services implementation in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the name field (aka the service name) to admin/webservice/service.php.

EPSS: Низкий
github логотип

GHSA-3r38-cfr7-4765

больше 3 лет назад

A memory leak in the af9005_identify_state() function in drivers/media/usb/dvb-usb/af9005.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-2289adbfa559.

EPSS: Низкий
github логотип

GHSA-3r37-p8j6-6wp6

почти 3 года назад

European Chemicals Agency IUCLID before 6.27.6 allows remote authenticated users to execute arbitrary code via Server Side Template Injection (SSTI) with a crafted template file. The attacker must have template manager permission.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3r37-c7r6-833v

почти 4 года назад

YzmCMS v6.3 is affected by Cross Site Request Forgery (CSRF) in /admin.add

EPSS: Низкий
github логотип

GHSA-3r35-cqqr-pjjf

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in Brad Fears phpCodeCabinet 0.4 and earlier allow remote attackers to inject arbitrary web script or HTML via multiple parameters, including (1) the sid parameter to comments.php, (2) the cid, cf, or rfd parameters to category.php, or the cid parameter to (3) input.php, (4) browse.php, (5) themes/facade/header.php, or (6) themes/phpcc/header.php.

EPSS: Низкий
github логотип

GHSA-3r35-352r-wrcc

около 4 лет назад

LibTIFF 4.3.0 has an out-of-bounds read in _TIFFmemcpy in tif_unix.c in certain situations involving a custom tag and 0x0200 as the second word of the DE field.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3r34-xx92-673h

почти 3 года назад

The issue was addressed with improved UI handling. This issue is fixed in Safari 16, tvOS 16, watchOS 9, iOS 16. Visiting a website that frames malicious content may lead to UI spoofing.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3r34-w4xc-wf2m

почти 4 года назад

Buffer overflow in Computalynx CMail POP3 mail server 2.4.9 allows remote attackers to run arbitrary code via a long HELO command.

EPSS: Низкий
github логотип

GHSA-3r34-vmwj-2j86

больше 3 лет назад

In the DaalaBitReader constructor of entropy_decoder.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure in the media server with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-147234020

EPSS: Низкий
github логотип

GHSA-3r34-r6w3-fqp6

больше 1 года назад

Microsoft Security Advisory CVE-2024-38167 | .NET Information Disclosure Vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3r33-mvpm-6mqf

почти 4 года назад

The SMTP service in MERCUR Messaging 2005 before Service Pack 4 allows remote attackers to cause a denial of service (infinite loop) via a message in which neither the originator nor recipient address is known.

EPSS: Низкий
github логотип

GHSA-3r32-ggmf-p3vp

около 4 лет назад

Leostream Connection Broker 9.0.40.17 allows administrators to conduct directory traversal attacks by uploading z ZIP file that contains a symbolic link.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-3r32-cp7v-5wq4

больше 2 лет назад

Code injection in ansible semaphore

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3r2v-v8vm-3g58

больше 3 лет назад

QEMU (aka Quick Emulator) built with the NE2000 device emulation support is vulnerable to an OOB r/w access issue. It could occur while performing 'ioport' r/w operations. A privileged (CAP_SYS_RAWIO) user/process could use this flaw to leak or corrupt QEMU memory bytes.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3r2v-rgxm-vr46

4 месяца назад

A vulnerability was found in Tenda AC23 up to 16.03.07.52. Affected by this issue is the function sscanf of the file /goform/SetStaticRouteCfg. The manipulation of the argument list results in buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and could be used.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3r2v-8348-hx3r

около 1 года назад

An issue was discovered in LemonLDAP::NG before 2.20.1. An Improper Check during session refresh allows an authenticated user to raise their authentication level if the admin configured an "Adaptative authentication rule" with an increment instead of an absolute value.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3r2v-4fp3-8g3h

6 месяцев назад

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2024 release Versions 7.13.1.0 through 7.13.1.25, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain an Authentication Bypass by Spoofing vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. Remote unauthenticated user can create account that potentially expose customer info, affect system integrity and availability.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3r2p-c9r5-pw6w

больше 2 лет назад

All versions of the package crow are vulnerable to HTTP Response Splitting when untrusted user input is used to build header values. Header values are not properly sanitized against CRLF Injection in the set_header and add_header functions. An attacker can add the \r\n (carriage return line feeds) characters to end the HTTP response headers and inject malicious content.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3r2p-99p3-62vg

больше 2 лет назад

Online Examination System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'email' parameter of the feed.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3r39-mw8c-6g5f

A vulnerability, which was classified as problematic, was found in radare2 5.9.9 33286. Affected is an unknown function in the library /libr/main/rasm2.c of the component rasm2. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 6.0.0 is able to address this issue. The patch is identified as c6c772d2eab692ce7ada5a4227afd50c355ad545. It is recommended to upgrade the affected component.

CVSS3: 3.3
0%
Низкий
12 месяцев назад
github логотип
GHSA-3r38-g3wv-x66q

Cross-site scripting (XSS) vulnerability in admin/webservice/forms.php in the web services implementation in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the name field (aka the service name) to admin/webservice/service.php.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3r38-cfr7-4765

A memory leak in the af9005_identify_state() function in drivers/media/usb/dvb-usb/af9005.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-2289adbfa559.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3r37-p8j6-6wp6

European Chemicals Agency IUCLID before 6.27.6 allows remote authenticated users to execute arbitrary code via Server Side Template Injection (SSTI) with a crafted template file. The attacker must have template manager permission.

CVSS3: 8.8
8%
Низкий
почти 3 года назад
github логотип
GHSA-3r37-c7r6-833v

YzmCMS v6.3 is affected by Cross Site Request Forgery (CSRF) in /admin.add

0%
Низкий
почти 4 года назад
github логотип
GHSA-3r35-cqqr-pjjf

Multiple cross-site scripting (XSS) vulnerabilities in Brad Fears phpCodeCabinet 0.4 and earlier allow remote attackers to inject arbitrary web script or HTML via multiple parameters, including (1) the sid parameter to comments.php, (2) the cid, cf, or rfd parameters to category.php, or the cid parameter to (3) input.php, (4) browse.php, (5) themes/facade/header.php, or (6) themes/phpcc/header.php.

3%
Низкий
почти 4 года назад
github логотип
GHSA-3r35-352r-wrcc

LibTIFF 4.3.0 has an out-of-bounds read in _TIFFmemcpy in tif_unix.c in certain situations involving a custom tag and 0x0200 as the second word of the DE field.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-3r34-xx92-673h

The issue was addressed with improved UI handling. This issue is fixed in Safari 16, tvOS 16, watchOS 9, iOS 16. Visiting a website that frames malicious content may lead to UI spoofing.

CVSS3: 6.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-3r34-w4xc-wf2m

Buffer overflow in Computalynx CMail POP3 mail server 2.4.9 allows remote attackers to run arbitrary code via a long HELO command.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3r34-vmwj-2j86

In the DaalaBitReader constructor of entropy_decoder.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure in the media server with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-147234020

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3r34-r6w3-fqp6

Microsoft Security Advisory CVE-2024-38167 | .NET Information Disclosure Vulnerability

CVSS3: 6.5
2%
Низкий
больше 1 года назад
github логотип
GHSA-3r33-mvpm-6mqf

The SMTP service in MERCUR Messaging 2005 before Service Pack 4 allows remote attackers to cause a denial of service (infinite loop) via a message in which neither the originator nor recipient address is known.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3r32-ggmf-p3vp

Leostream Connection Broker 9.0.40.17 allows administrators to conduct directory traversal attacks by uploading z ZIP file that contains a symbolic link.

CVSS3: 4.9
0%
Низкий
около 4 лет назад
github логотип
GHSA-3r32-cp7v-5wq4

Code injection in ansible semaphore

CVSS3: 8.8
2%
Низкий
больше 2 лет назад
github логотип
GHSA-3r2v-v8vm-3g58

QEMU (aka Quick Emulator) built with the NE2000 device emulation support is vulnerable to an OOB r/w access issue. It could occur while performing 'ioport' r/w operations. A privileged (CAP_SYS_RAWIO) user/process could use this flaw to leak or corrupt QEMU memory bytes.

CVSS3: 7.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3r2v-rgxm-vr46

A vulnerability was found in Tenda AC23 up to 16.03.07.52. Affected by this issue is the function sscanf of the file /goform/SetStaticRouteCfg. The manipulation of the argument list results in buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and could be used.

CVSS3: 8.8
0%
Низкий
4 месяца назад
github логотип
GHSA-3r2v-8348-hx3r

An issue was discovered in LemonLDAP::NG before 2.20.1. An Improper Check during session refresh allows an authenticated user to raise their authentication level if the admin configured an "Adaptative authentication rule" with an increment instead of an absolute value.

CVSS3: 8.8
0%
Низкий
около 1 года назад
github логотип
GHSA-3r2v-4fp3-8g3h

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2024 release Versions 7.13.1.0 through 7.13.1.25, LTS 2023 release versions 7.10.1.0 through 7.10.1.60, contain an Authentication Bypass by Spoofing vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. Remote unauthenticated user can create account that potentially expose customer info, affect system integrity and availability.

CVSS3: 9.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-3r2p-c9r5-pw6w

All versions of the package crow are vulnerable to HTTP Response Splitting when untrusted user input is used to build header values. Header values are not properly sanitized against CRLF Injection in the set_header and add_header functions. An attacker can add the \r\n (carriage return line feeds) characters to end the HTTP response headers and inject malicious content.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3r2p-99p3-62vg

Online Examination System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'email' parameter of the feed.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу