Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3r2p-96rp-68vh

около 4 лет назад

In stopVpnProfile of Vpn.java, there is a possible VPN profile reset due to a permissions bypass. This could lead to local escalation of privilege CONTROL_ALWAYS_ON_VPN with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-191382886

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3r2p-7j7f-fc8q

около 1 года назад

A vulnerability in the firewall component of HPE Aruba Networking CX 10000 Series Switches exists. It could allow an unauthenticated adjacent attacker to conduct a packet forwarding attack against the ICMP and UDP protocol. For this attack to be successful an attacker requires a switch configuration that allows packets routing (at layer 3). Configurations that do not allow network traffic routing are not impacted. Successful exploitation could allow an attacker to bypass security policies, potentially leading to unauthorized data exposure.

CVSS3: 3.4
EPSS: Низкий
github логотип

GHSA-3r2p-69f5-2hp9

почти 4 года назад

Buffer overflow in JustSystems JSFC.DLL, as used in multiple JustSystems products such as Ichitaro, allows remote attackers to execute arbitrary code via a crafted .JTD file.

EPSS: Средний
github логотип

GHSA-3r2m-6v2h-6jqr

больше 3 лет назад

Monitorix 3.13.0 allows remote attackers to bypass Basic Authentication in a default installation (i.e., an installation without a hosts_deny option). This issue occurred because a new access-control feature was introduced without considering that some exiting installations became unsafe, upon an update to 3.13.0, unless the new feature was immediately configured.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3r2j-3937-77fv

больше 3 лет назад

ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) on /CWEBNET/* authenticated pages. A successful CSRF attack can force the user to modify state: creating users, changing an email address, and so forth. If the victim is an administrative account, CSRF can compromise the entire web application.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3r2j-2m96-x2cp

больше 3 лет назад

Privilege Escalation vulnerability in the command line interface in McAfee Advanced Threat Defense (ATD) 4.x prior to 4.8.2 allows local users to execute arbitrary code via improper access controls on the sudo command.

EPSS: Низкий
github логотип

GHSA-3r2j-2686-wg8h

6 месяцев назад

A vulnerability was determined in NASM Netwide Assember 2.17rc0. This vulnerability affects the function parse_smacro_template of the file preproc.c. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-3r2h-wc6v-vjgm

7 месяцев назад

IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26223.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3r2h-q88m-pxmp

больше 3 лет назад

Out of bound read in adm call back function due to incorrect boundary check for payload in command response in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8053, APQ8098, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909W, MSM8917, MSM8953, QCS605, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM670, SDM710, SDM845, SDX20, SDX24

EPSS: Низкий
github логотип

GHSA-3r2h-p7c8-w9jw

больше 3 лет назад

An unrestricted file upload vulnerability in importuser.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to upload supplied data to a specified filename. This can be used to place attacker controlled code on the file system that is then executed.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3r2h-9pcp-cj9v

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vfthemes StorePress allows DOM-Based XSS.This issue affects StorePress: from n/a through 1.0.12.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3r2g-rwx7-4qwp

больше 3 лет назад

Windows DCOM Server Security Feature Bypass

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-3r2f-rpgw-83gm

больше 3 лет назад

Insufficient input sanitization in Mermaid markdown in GitLab CE/EE version 11.4 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown

EPSS: Низкий
github логотип

GHSA-3r2c-w822-3j3f

больше 3 лет назад

IBM Security Guardium Insights 2.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 174406.

EPSS: Низкий
github логотип

GHSA-3r2c-p78w-vg88

около 1 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unauthenticated user to execute arbitrary code in the context of an authenticated user's browser by convincing the legitimate user to visit a specially crafted webpage.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-3r2c-g2rm-78cq

почти 4 года назад

Buffer overflow in AnalogX SimpleServer 1.05 allows a remote attacker to cause a denial of service via a long GET request for a program in the cgi-bin directory.

EPSS: Низкий
github логотип

GHSA-3r28-rgp9-qgv4

больше 2 лет назад

pf4j vulnerable to remote code execution via the zippluginPath parameter

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3r28-q7qr-3hmj

около 2 лет назад

Incomplete cleanup for some Intel Unison software may allow a privileged user to potentially enable denial of service via local access.

CVSS3: 1.9
EPSS: Низкий
github логотип

GHSA-3r28-hhhx-hfjf

около 2 месяцев назад

In bigo_worker_thread of private/google-modules/video/gchips/bigo.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3r27-2vg8-fjmx

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: block: Fix page refcounts for unaligned buffers in __bio_release_pages() Fix an incorrect number of pages being released for buffers that do not start at the beginning of a page.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3r2p-96rp-68vh

In stopVpnProfile of Vpn.java, there is a possible VPN profile reset due to a permissions bypass. This could lead to local escalation of privilege CONTROL_ALWAYS_ON_VPN with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-191382886

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-3r2p-7j7f-fc8q

A vulnerability in the firewall component of HPE Aruba Networking CX 10000 Series Switches exists. It could allow an unauthenticated adjacent attacker to conduct a packet forwarding attack against the ICMP and UDP protocol. For this attack to be successful an attacker requires a switch configuration that allows packets routing (at layer 3). Configurations that do not allow network traffic routing are not impacted. Successful exploitation could allow an attacker to bypass security policies, potentially leading to unauthorized data exposure.

CVSS3: 3.4
0%
Низкий
около 1 года назад
github логотип
GHSA-3r2p-69f5-2hp9

Buffer overflow in JustSystems JSFC.DLL, as used in multiple JustSystems products such as Ichitaro, allows remote attackers to execute arbitrary code via a crafted .JTD file.

12%
Средний
почти 4 года назад
github логотип
GHSA-3r2m-6v2h-6jqr

Monitorix 3.13.0 allows remote attackers to bypass Basic Authentication in a default installation (i.e., an installation without a hosts_deny option). This issue occurred because a new access-control feature was introduced without considering that some exiting installations became unsafe, upon an update to 3.13.0, unless the new feature was immediately configured.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3r2j-3937-77fv

ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) on /CWEBNET/* authenticated pages. A successful CSRF attack can force the user to modify state: creating users, changing an email address, and so forth. If the victim is an administrative account, CSRF can compromise the entire web application.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3r2j-2m96-x2cp

Privilege Escalation vulnerability in the command line interface in McAfee Advanced Threat Defense (ATD) 4.x prior to 4.8.2 allows local users to execute arbitrary code via improper access controls on the sudo command.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3r2j-2686-wg8h

A vulnerability was determined in NASM Netwide Assember 2.17rc0. This vulnerability affects the function parse_smacro_template of the file preproc.c. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

CVSS3: 3.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-3r2h-wc6v-vjgm

IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26223.

CVSS3: 7.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-3r2h-q88m-pxmp

Out of bound read in adm call back function due to incorrect boundary check for payload in command response in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8053, APQ8098, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909W, MSM8917, MSM8953, QCS605, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM670, SDM710, SDM845, SDX20, SDX24

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3r2h-p7c8-w9jw

An unrestricted file upload vulnerability in importuser.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to upload supplied data to a specified filename. This can be used to place attacker controlled code on the file system that is then executed.

CVSS3: 7.2
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3r2h-9pcp-cj9v

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vfthemes StorePress allows DOM-Based XSS.This issue affects StorePress: from n/a through 1.0.12.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-3r2g-rwx7-4qwp

Windows DCOM Server Security Feature Bypass

CVSS3: 6.5
23%
Средний
больше 3 лет назад
github логотип
GHSA-3r2f-rpgw-83gm

Insufficient input sanitization in Mermaid markdown in GitLab CE/EE version 11.4 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown

2%
Низкий
больше 3 лет назад
github логотип
GHSA-3r2c-w822-3j3f

IBM Security Guardium Insights 2.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 174406.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3r2c-p78w-vg88

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unauthenticated user to execute arbitrary code in the context of an authenticated user's browser by convincing the legitimate user to visit a specially crafted webpage.

CVSS3: 8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3r2c-g2rm-78cq

Buffer overflow in AnalogX SimpleServer 1.05 allows a remote attacker to cause a denial of service via a long GET request for a program in the cgi-bin directory.

4%
Низкий
почти 4 года назад
github логотип
GHSA-3r28-rgp9-qgv4

pf4j vulnerable to remote code execution via the zippluginPath parameter

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3r28-q7qr-3hmj

Incomplete cleanup for some Intel Unison software may allow a privileged user to potentially enable denial of service via local access.

CVSS3: 1.9
0%
Низкий
около 2 лет назад
github логотип
GHSA-3r28-hhhx-hfjf

In bigo_worker_thread of private/google-modules/video/gchips/bigo.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 6.7
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3r27-2vg8-fjmx

In the Linux kernel, the following vulnerability has been resolved: block: Fix page refcounts for unaligned buffers in __bio_release_pages() Fix an incorrect number of pages being released for buffers that do not start at the beginning of a page.

CVSS3: 5.5
0%
Низкий
больше 1 года назад

Уязвимостей на страницу