Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3qx8-772m-x3f3

больше 1 года назад

Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3qx8-4pqg-rc5h

больше 3 лет назад

A certain ActiveX control in ienipp.ocx in the browser plugin in Novell iPrint Client before 5.42 does not properly restrict the set of files to be deleted, which allows remote attackers to cause a denial of service (recursive file deletion) via unspecified vectors related to a "logic flaw" in the CleanUploadFiles method in the nipplib.dll module.

EPSS: Низкий
github логотип

GHSA-3qx7-r2pf-8cwr

больше 3 лет назад

All versions of package github.com/tyktechnologies/tyk/gateway are vulnerable to Directory Traversal via the handleAddOrUpdateApi function. This function is able to delete arbitrary JSON files on the disk where Tyk is running via the management API. The APIID is provided by the user and this value is then used to create a file on disk. If there is a file found with the same name then it will be deleted and then re-created with the contents of the API creation request.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3qx7-ff8p-6j2r

больше 1 года назад

A flaw was found in the virtio-net device in QEMU. When enabling the RSS feature on the virtio-net network card, the indirections_table data within RSS becomes controllable. Setting excessively large values may cause an index out-of-bounds issue, potentially resulting in heap overflow access. This flaw allows a privileged user in the guest to crash the QEMU process on the host.

CVSS3: 6
EPSS: Низкий
github логотип

GHSA-3qx7-92qm-xvhr

больше 3 лет назад

The self-extracting installer in the vSphere Client Installer package in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1, VMware ESXi 4.x before 4.1 Update 1, and VMware ESX 4.x before 4.1 Update 1 does not have a digital signature, which might make it easier for remote attackers to spoof the software distribution via a Trojan horse installer.

EPSS: Низкий
github логотип

GHSA-3qx6-96c8-pv99

9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Fix isochronous Ring Underrun/Overrun event handling The TRB pointer of these events points at enqueue at the time of error occurrence on xHCI 1.1+ HCs or it's NULL on older ones. By the time we are handling the event, a new TD may be queued at this ring position. I can trigger this race by rising interrupt moderation to increase IRQ handling delay. Similar delay may occur naturally due to system load. If this ever happens after a Missed Service Error, missed TDs will be skipped and the new TD processed as if it matched the event. It could be given back prematurely, risking data loss or buffer UAF by the xHC. Don't complete TDs on xrun events and don't warn if queued TDs don't match the event's TRB pointer, which can be NULL or a link/no-op TRB. Don't warn if there are no queued TDs at all. Now that it's safe, also handle xrun events if the skip flag is clear. This ensures completion of any TD stuck...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3qx5-mr88-qhv7

больше 3 лет назад

Directory traversal vulnerability in ServiceDesk Plus and Plus MSP v5 through v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4 allows remote authenticated users to execute arbitrary code.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-3qx4-pq69-7jwx

9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: net: ti: icss-iep: Fix possible NULL pointer dereference for perout request The ICSS IEP driver tracks perout and pps enable state with flags. Currently when disabling pps and perout signals during icss_iep_exit(), results in NULL pointer dereference for perout. To fix the null pointer dereference issue, the icss_iep_perout_enable_hw function can be modified to directly clear the IEP CMP registers when disabling PPS or PEROUT, without referencing the ptp_perout_request structure, as its contents are irrelevant in this case.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3qx4-gwgh-93vc

около 1 года назад

An access control issue in the component form2WlanBasicSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G wlan service of the device via a crafted POST request.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3qx3-xhmf-4jcc

около 2 лет назад

A server-side request forgery vulnerability in ESM prior to version 11.6.8 allows a low privileged authenticated user to upload arbitrary content, potentially altering configuration. This is possible through the certificate validation functionality where the API accepts uploaded content and doesn't parse for invalid data

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3qx3-hfrr-jjwj

9 месяцев назад

A vulnerability classified as critical has been found in Weitong Mall 1.0.0. This affects an unknown part of the file /historyList of the component Product History Handler. The manipulation of the argument isDelete with the input 1 leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3qx3-6hxr-j2ch

почти 2 года назад

eza Potential Heap Overflow Vulnerability for AArch64

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-3qx3-5cfw-9wfr

больше 3 лет назад

Windows Hyper-V Denial of Service Vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3qx2-hpvr-h63q

больше 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThimPress Eduma allows Reflected XSS.This issue affects Eduma: from n/a through 5.4.7.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3qx2-9vj8-qmjf

около 2 лет назад

In drm driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-3qx2-6f78-w2j2

около 2 лет назад

Denial of service caused by infinite recursion when parsing SVG images

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3qwx-xqv6-5w8m

7 месяцев назад

A vulnerability, which was classified as critical, was found in PHPGurukul Online Library Management System 3.0. This affects an unknown part of the file /admin/student-history.php. The manipulation of the argument stdid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3qwx-q6x9-637h

почти 2 года назад

Vulnerability of incorrect service logic in the WindowManagerServices module.Successful exploitation of this vulnerability may cause features to perform abnormally.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3qwx-fr6j-m6r7

больше 3 лет назад

Format string vulnerability in GNU a2ps 4.14 allows remote attackers to execute arbitrary code.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3qwx-85qr-mvqm

почти 4 года назад

Cross-site scripting (XSS) vulnerability in OcoMon 1.20, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3qx8-772m-x3f3

Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.

CVSS3: 7.2
1%
Низкий
больше 1 года назад
github логотип
GHSA-3qx8-4pqg-rc5h

A certain ActiveX control in ienipp.ocx in the browser plugin in Novell iPrint Client before 5.42 does not properly restrict the set of files to be deleted, which allows remote attackers to cause a denial of service (recursive file deletion) via unspecified vectors related to a "logic flaw" in the CleanUploadFiles method in the nipplib.dll module.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-3qx7-r2pf-8cwr

All versions of package github.com/tyktechnologies/tyk/gateway are vulnerable to Directory Traversal via the handleAddOrUpdateApi function. This function is able to delete arbitrary JSON files on the disk where Tyk is running via the management API. The APIID is provided by the user and this value is then used to create a file on disk. If there is a file found with the same name then it will be deleted and then re-created with the contents of the API creation request.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3qx7-ff8p-6j2r

A flaw was found in the virtio-net device in QEMU. When enabling the RSS feature on the virtio-net network card, the indirections_table data within RSS becomes controllable. Setting excessively large values may cause an index out-of-bounds issue, potentially resulting in heap overflow access. This flaw allows a privileged user in the guest to crash the QEMU process on the host.

CVSS3: 6
0%
Низкий
больше 1 года назад
github логотип
GHSA-3qx7-92qm-xvhr

The self-extracting installer in the vSphere Client Installer package in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1, VMware ESXi 4.x before 4.1 Update 1, and VMware ESX 4.x before 4.1 Update 1 does not have a digital signature, which might make it easier for remote attackers to spoof the software distribution via a Trojan horse installer.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3qx6-96c8-pv99

In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Fix isochronous Ring Underrun/Overrun event handling The TRB pointer of these events points at enqueue at the time of error occurrence on xHCI 1.1+ HCs or it's NULL on older ones. By the time we are handling the event, a new TD may be queued at this ring position. I can trigger this race by rising interrupt moderation to increase IRQ handling delay. Similar delay may occur naturally due to system load. If this ever happens after a Missed Service Error, missed TDs will be skipped and the new TD processed as if it matched the event. It could be given back prematurely, risking data loss or buffer UAF by the xHC. Don't complete TDs on xrun events and don't warn if queued TDs don't match the event's TRB pointer, which can be NULL or a link/no-op TRB. Don't warn if there are no queued TDs at all. Now that it's safe, also handle xrun events if the skip flag is clear. This ensures completion of any TD stuck...

CVSS3: 7.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-3qx5-mr88-qhv7

Directory traversal vulnerability in ServiceDesk Plus and Plus MSP v5 through v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4 allows remote authenticated users to execute arbitrary code.

CVSS3: 8.8
54%
Средний
больше 3 лет назад
github логотип
GHSA-3qx4-pq69-7jwx

In the Linux kernel, the following vulnerability has been resolved: net: ti: icss-iep: Fix possible NULL pointer dereference for perout request The ICSS IEP driver tracks perout and pps enable state with flags. Currently when disabling pps and perout signals during icss_iep_exit(), results in NULL pointer dereference for perout. To fix the null pointer dereference issue, the icss_iep_perout_enable_hw function can be modified to directly clear the IEP CMP registers when disabling PPS or PEROUT, without referencing the ptp_perout_request structure, as its contents are irrelevant in this case.

CVSS3: 5.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-3qx4-gwgh-93vc

An access control issue in the component form2WlanBasicSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G wlan service of the device via a crafted POST request.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-3qx3-xhmf-4jcc

A server-side request forgery vulnerability in ESM prior to version 11.6.8 allows a low privileged authenticated user to upload arbitrary content, potentially altering configuration. This is possible through the certificate validation functionality where the API accepts uploaded content and doesn't parse for invalid data

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-3qx3-hfrr-jjwj

A vulnerability classified as critical has been found in Weitong Mall 1.0.0. This affects an unknown part of the file /historyList of the component Product History Handler. The manipulation of the argument isDelete with the input 1 leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-3qx3-6hxr-j2ch

eza Potential Heap Overflow Vulnerability for AArch64

CVSS3: 8.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-3qx3-5cfw-9wfr

Windows Hyper-V Denial of Service Vulnerability

CVSS3: 7.5
8%
Низкий
больше 3 лет назад
github логотип
GHSA-3qx2-hpvr-h63q

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThimPress Eduma allows Reflected XSS.This issue affects Eduma: from n/a through 5.4.7.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-3qx2-9vj8-qmjf

In drm driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

CVSS3: 4.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-3qx2-6f78-w2j2

Denial of service caused by infinite recursion when parsing SVG images

CVSS3: 5.3
6%
Низкий
около 2 лет назад
github логотип
GHSA-3qwx-xqv6-5w8m

A vulnerability, which was classified as critical, was found in PHPGurukul Online Library Management System 3.0. This affects an unknown part of the file /admin/student-history.php. The manipulation of the argument stdid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-3qwx-q6x9-637h

Vulnerability of incorrect service logic in the WindowManagerServices module.Successful exploitation of this vulnerability may cause features to perform abnormally.

CVSS3: 9.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-3qwx-fr6j-m6r7

Format string vulnerability in GNU a2ps 4.14 allows remote attackers to execute arbitrary code.

CVSS3: 7.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3qwx-85qr-mvqm

Cross-site scripting (XSS) vulnerability in OcoMon 1.20, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу