Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 288 388

Количество 288 388

github логотип

GHSA-252h-69rw-g2rp

около 3 лет назад

The str_buf_cat function in string.c in Ruby 1.9.3, 2.0.0, and 2.1 allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string.

EPSS: Низкий
github логотип

GHSA-252h-2cmq-pmr6

больше 2 лет назад

easywebpack-cli Path Traversal vulnerability

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-252g-gw8q-x2cc

около 3 лет назад

OpenShift Container Platform before version 4.1.3 writes OAuth tokens in plaintext to the audit logs for the Kubernetes API server and OpenShift API server. A user with sufficient privileges could recover OAuth tokens from these audit logs and use them to access other resources.

EPSS: Низкий
github логотип

GHSA-252g-9rpq-c6xw

больше 3 лет назад

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis VSS Doctor (Windows) before build 53

EPSS: Низкий
github логотип

GHSA-252f-47x2-rgxx

около 3 лет назад

A SQL injection vulnerability in a Trend Micro Email Encryption Gateway 5.5 policy script could allow an attacker to execute SQL commands to upload and execute arbitrary code that may harm the target system.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-252c-46fv-6xqv

около 3 лет назад

ServerManagement master branch as of commit 49491cc6f94980e6be7791d17be947c27071eb56 is affected by a directory traversal vulnerability. This vulnerability can be used to extract credentials which can in turn be used to execute code.

EPSS: Низкий
github логотип

GHSA-2529-rwp4-75f6

около 3 лет назад

It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed article -> Website" or in the standard format of "View -> Feed article -> default format". This vulnerability affects Thunderbird < 52.5.2.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2529-cmp4-x7vg

больше 3 лет назад

HP-UX aserver program allows local users to gain privileges via a symlink attack.

EPSS: Низкий
github логотип

GHSA-2528-h86j-954v

около 3 лет назад

In JetBrains TeamCity before 2021.1.3, a newly created project could take settings from an already deleted project.

EPSS: Низкий
github логотип

GHSA-2527-g53r-vw26

больше 3 лет назад

In HarmfulAppWarningActivity of HarmfulAppWarningActivity.java, there is a possible way to trick victim to install harmful app due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-205595291

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2526-24jx-77pp

около 3 лет назад

Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file. This is achieved through running a malicious script or program on the target machine.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2524-6f4r-2jq9

около 3 лет назад

SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious commands with root privileges in SAP Host Agent via SAP Landscape Management.

EPSS: Низкий
github логотип

GHSA-2524-2jp2-r468

около 1 года назад

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2523-xvgc-mmh8

10 месяцев назад

Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2523-vcxw-6v95

около 3 лет назад

In libhidcommand_jni, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the USB service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111363077

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-2523-v9j2-g44c

больше 3 лет назад

Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6) Vulnerable parameters: &post_title, &downloadable_file_version[0].

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2523-mx65-hm92

больше 2 лет назад

NASM 2.16 (development) is vulnerable to 476: Null Pointer Dereference via output/outaout.c.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2522-v35m-2r22

больше 3 лет назад

jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2522-mrjc-m688

больше 1 года назад

Apache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config used

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2522-8f97-8gg8

больше 3 лет назад

Unspecified vulnerability in Adobe Breeze 5 Licensed Server and Breeze 5.1 Licensed Server allows attackers to read arbitrary files via unknown vectors related to "URL parsing."

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-252h-69rw-g2rp

The str_buf_cat function in string.c in Ruby 1.9.3, 2.0.0, and 2.1 allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string.

0%
Низкий
около 3 лет назад
github логотип
GHSA-252h-2cmq-pmr6

easywebpack-cli Path Traversal vulnerability

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-252g-gw8q-x2cc

OpenShift Container Platform before version 4.1.3 writes OAuth tokens in plaintext to the audit logs for the Kubernetes API server and OpenShift API server. A user with sufficient privileges could recover OAuth tokens from these audit logs and use them to access other resources.

0%
Низкий
около 3 лет назад
github логотип
GHSA-252g-9rpq-c6xw

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis VSS Doctor (Windows) before build 53

0%
Низкий
больше 3 лет назад
github логотип
GHSA-252f-47x2-rgxx

A SQL injection vulnerability in a Trend Micro Email Encryption Gateway 5.5 policy script could allow an attacker to execute SQL commands to upload and execute arbitrary code that may harm the target system.

CVSS3: 9.8
4%
Низкий
около 3 лет назад
github логотип
GHSA-252c-46fv-6xqv

ServerManagement master branch as of commit 49491cc6f94980e6be7791d17be947c27071eb56 is affected by a directory traversal vulnerability. This vulnerability can be used to extract credentials which can in turn be used to execute code.

1%
Низкий
около 3 лет назад
github логотип
GHSA-2529-rwp4-75f6

It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed article -> Website" or in the standard format of "View -> Feed article -> default format". This vulnerability affects Thunderbird < 52.5.2.

CVSS3: 8.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-2529-cmp4-x7vg

HP-UX aserver program allows local users to gain privileges via a symlink attack.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2528-h86j-954v

In JetBrains TeamCity before 2021.1.3, a newly created project could take settings from an already deleted project.

0%
Низкий
около 3 лет назад
github логотип
GHSA-2527-g53r-vw26

In HarmfulAppWarningActivity of HarmfulAppWarningActivity.java, there is a possible way to trick victim to install harmful app due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-205595291

CVSS3: 7.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2526-24jx-77pp

Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file. This is achieved through running a malicious script or program on the target machine.

CVSS3: 6.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-2524-6f4r-2jq9

SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious commands with root privileges in SAP Host Agent via SAP Landscape Management.

0%
Низкий
около 3 лет назад
github логотип
GHSA-2524-2jp2-r468

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

CVSS3: 8.8
5%
Низкий
около 1 года назад
github логотип
GHSA-2523-xvgc-mmh8

Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability

CVSS3: 7.8
1%
Низкий
10 месяцев назад
github логотип
GHSA-2523-vcxw-6v95

In libhidcommand_jni, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the USB service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111363077

CVSS3: 6.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-2523-v9j2-g44c

Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6) Vulnerable parameters: &post_title, &downloadable_file_version[0].

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2523-mx65-hm92

NASM 2.16 (development) is vulnerable to 476: Null Pointer Dereference via output/outaout.c.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2522-v35m-2r22

jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-2522-mrjc-m688

Apache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config used

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2522-8f97-8gg8

Unspecified vulnerability in Adobe Breeze 5 Licensed Server and Breeze 5.1 Licensed Server allows attackers to read arbitrary files via unknown vectors related to "URL parsing."

3%
Низкий
больше 3 лет назад

Уязвимостей на страницу