Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3qg7-2p3j-xrqp

больше 2 лет назад

Product: AndroidVersions: Android SoCAndroid ID: A-278156680

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3qg6-gw2x-w9cq

больше 3 лет назад

Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
EPSS: Высокий
github логотип

GHSA-3qg6-cc82-q3g9

больше 3 лет назад

epan/dissectors/packet-x509af.c in the X.509AF dissector in Wireshark 2.0.x before 2.0.2 mishandles the algorithm ID, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3qg5-qhw5-vc9x

около 1 года назад

In mayAdminGrantPermission of AdminRestrictedPermissionsUtils.java, there is a possible way to access the microphone due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3qg5-3wgr-h9mq

почти 4 года назад

The 64-bit versions of Microsoft Visual C++ 8.0 standard library (MSVCR80.DLL) time functions, including (1) localtime, (2) localtime_s, (3) gmtime, (4) gmtime_s, (5) ctime, (6) ctime_s, (7) wctime, (8) wctime_s, and (9) fstat, trigger an assertion error instead of a NULL pointer or EINVAL when processing a time argument later than Jan 1, 3000, which might allow context-dependent attackers to cause a denial of service (application exit) via large time values. NOTE: it could be argued that this is a design limitation of the functions, and the vulnerability lies with any application that does not validate arguments to these functions. However, this behavior is inconsistent with documentation, which does not list assertions as a possible result of an error condition.

EPSS: Средний
github логотип

GHSA-3qg4-vrhv-p2hp

больше 3 лет назад

Integer overflow in calculating estimated output buffer size when getting a list of installed Feature IDs, Serial Numbers or checking Feature ID status in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in Kamorta, MDM9205, MDM9607, Nicobar, QCS404, QCS405, Rennell, SA6155P, SC7180, SC8180X, SDX55, SM6150, SM7150, SXR2130

EPSS: Низкий
github логотип

GHSA-3qg4-2rww-w8jv

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the MIME e-mail functionality in iNotes in IBM Domino 9.0 before IF3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN986NAA.

EPSS: Низкий
github логотип

GHSA-3qg4-2fcm-c8f9

больше 3 лет назад

Moodle does not recogniz configuration setting that makes e-mail addresses visible only to course members

EPSS: Низкий
github логотип

GHSA-3qg3-2pmj-x4hh

6 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in Jordy Meow Photo Engine allows Cross Site Request Forgery. This issue affects Photo Engine: from n/a through 6.4.3.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3qg2-hgm3-r76h

больше 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Beaver Addons PowerPack Lite for Beaver Builder allows Stored XSS.This issue affects PowerPack Lite for Beaver Builder: from n/a through 1.3.0.4.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3qfx-cxcm-pc2c

больше 3 лет назад

Several heap-based buffer overflow vulnerabilities in WECON LeviStudioU version 1.8.56 and prior have been identified, which may allow arbitrary code execution. Mat Powell, Ziad Badawi, and Natnael Samson working with Trend Micro's Zero Day Initiative, reported these vulnerabilities to NCCIC.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3qfx-62r9-w7q6

больше 3 лет назад

Absolute path traversal vulnerability in the org.debian.apt.UpdateCachePartially method in worker.py in Aptdaemon 0.40 in Ubuntu 10.10 and 11.04 allows local users to read arbitrary files via a full pathname in the sources_list argument, related to the D-Bus interface.

EPSS: Низкий
github логотип

GHSA-3qfx-4gmg-xcwx

больше 3 лет назад

An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3qfw-xv6h-ff5g

больше 3 лет назад

DMA Softlab Radius Manager 4.4.0 allows CSRF with impacts such as adding new manager accounts via admin.php.

EPSS: Низкий
github логотип

GHSA-3qfw-jw7m-r96c

больше 3 лет назад

Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-3qfw-fw67-fvr8

почти 4 года назад

Heap-based buffer overflow in the Rendezvous / Extensible Messaging and Presence Protocol (XMPP) component (plugins\rendezvous.dll) for Cerulean Studios Trillian Pro before 3.1.5.1 allows remote attackers to execute arbitrary code via a message that triggers the overflow from expansion that occurs during encoding.

EPSS: Средний
github логотип

GHSA-3qfw-5g24-8pmq

больше 1 года назад

The devices are vulnerable to session hijacking due to insufficient entropy in its session ID generation algorithm. The session IDs are predictable, with only 32,768 possible values per user, which allows attackers to pre-generate valid session IDs, leading to unauthorized access to user sessions. This is not only due to the use of an (insecure) rand() function call but also because of missing initialization via srand(). As a result only the PIDs are effectively used as seed.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-3qfv-q2rr-vg2v

больше 3 лет назад

An issue was discovered in arcms through 2018-03-19. No authentication is required for index/main, user/useradd, or img/images.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3qfr-v3x2-fhx2

больше 3 лет назад

Directory traversal vulnerability in Dell EqualLogic PS4000 with firmware 6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the default URI.

EPSS: Средний
github логотип

GHSA-3qfm-m53j-9vq3

почти 2 года назад

Missing Authorization vulnerability in Extend Themes Pathway, Extend Themes Hugo WP, Extend Themes Althea WP, Extend Themes Elevate WP, Extend Themes Brite, Extend Themes Colibri WP, Extend Themes Vertice.This issue affects Pathway: from n/a through 1.0.15; Hugo WP: from n/a through 1.0.8; Althea WP: from n/a through 1.0.13; Elevate WP: from n/a through 1.0.15; Brite: from n/a through 1.0.11; Colibri WP: from n/a through 1.0.94; Vertice: from n/a through 1.0.7.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3qg7-2p3j-xrqp

Product: AndroidVersions: Android SoCAndroid ID: A-278156680

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3qg6-gw2x-w9cq

Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
88%
Высокий
больше 3 лет назад
github логотип
GHSA-3qg6-cc82-q3g9

epan/dissectors/packet-x509af.c in the X.509AF dissector in Wireshark 2.0.x before 2.0.2 mishandles the algorithm ID, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

CVSS3: 5.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3qg5-qhw5-vc9x

In mayAdminGrantPermission of AdminRestrictedPermissionsUtils.java, there is a possible way to access the microphone due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-3qg5-3wgr-h9mq

The 64-bit versions of Microsoft Visual C++ 8.0 standard library (MSVCR80.DLL) time functions, including (1) localtime, (2) localtime_s, (3) gmtime, (4) gmtime_s, (5) ctime, (6) ctime_s, (7) wctime, (8) wctime_s, and (9) fstat, trigger an assertion error instead of a NULL pointer or EINVAL when processing a time argument later than Jan 1, 3000, which might allow context-dependent attackers to cause a denial of service (application exit) via large time values. NOTE: it could be argued that this is a design limitation of the functions, and the vulnerability lies with any application that does not validate arguments to these functions. However, this behavior is inconsistent with documentation, which does not list assertions as a possible result of an error condition.

11%
Средний
почти 4 года назад
github логотип
GHSA-3qg4-vrhv-p2hp

Integer overflow in calculating estimated output buffer size when getting a list of installed Feature IDs, Serial Numbers or checking Feature ID status in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in Kamorta, MDM9205, MDM9607, Nicobar, QCS404, QCS405, Rennell, SA6155P, SC7180, SC8180X, SDX55, SM6150, SM7150, SXR2130

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3qg4-2rww-w8jv

Cross-site scripting (XSS) vulnerability in the MIME e-mail functionality in iNotes in IBM Domino 9.0 before IF3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN986NAA.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3qg4-2fcm-c8f9

Moodle does not recogniz configuration setting that makes e-mail addresses visible only to course members

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3qg3-2pmj-x4hh

Cross-Site Request Forgery (CSRF) vulnerability in Jordy Meow Photo Engine allows Cross Site Request Forgery. This issue affects Photo Engine: from n/a through 6.4.3.

CVSS3: 4.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-3qg2-hgm3-r76h

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Beaver Addons PowerPack Lite for Beaver Builder allows Stored XSS.This issue affects PowerPack Lite for Beaver Builder: from n/a through 1.3.0.4.

CVSS3: 5.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-3qfx-cxcm-pc2c

Several heap-based buffer overflow vulnerabilities in WECON LeviStudioU version 1.8.56 and prior have been identified, which may allow arbitrary code execution. Mat Powell, Ziad Badawi, and Natnael Samson working with Trend Micro's Zero Day Initiative, reported these vulnerabilities to NCCIC.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3qfx-62r9-w7q6

Absolute path traversal vulnerability in the org.debian.apt.UpdateCachePartially method in worker.py in Aptdaemon 0.40 in Ubuntu 10.10 and 11.04 allows local users to read arbitrary files via a full pathname in the sources_list argument, related to the D-Bus interface.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3qfx-4gmg-xcwx

An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3qfw-xv6h-ff5g

DMA Softlab Radius Manager 4.4.0 allows CSRF with impacts such as adding new manager accounts via admin.php.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3qfw-jw7m-r96c

Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."

CVSS3: 8.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3qfw-fw67-fvr8

Heap-based buffer overflow in the Rendezvous / Extensible Messaging and Presence Protocol (XMPP) component (plugins\rendezvous.dll) for Cerulean Studios Trillian Pro before 3.1.5.1 allows remote attackers to execute arbitrary code via a message that triggers the overflow from expansion that occurs during encoding.

28%
Средний
почти 4 года назад
github логотип
GHSA-3qfw-5g24-8pmq

The devices are vulnerable to session hijacking due to insufficient entropy in its session ID generation algorithm. The session IDs are predictable, with only 32,768 possible values per user, which allows attackers to pre-generate valid session IDs, leading to unauthorized access to user sessions. This is not only due to the use of an (insecure) rand() function call but also because of missing initialization via srand(). As a result only the PIDs are effectively used as seed.

CVSS3: 9.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-3qfv-q2rr-vg2v

An issue was discovered in arcms through 2018-03-19. No authentication is required for index/main, user/useradd, or img/images.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3qfr-v3x2-fhx2

Directory traversal vulnerability in Dell EqualLogic PS4000 with firmware 6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the default URI.

14%
Средний
больше 3 лет назад
github логотип
GHSA-3qfm-m53j-9vq3

Missing Authorization vulnerability in Extend Themes Pathway, Extend Themes Hugo WP, Extend Themes Althea WP, Extend Themes Elevate WP, Extend Themes Brite, Extend Themes Colibri WP, Extend Themes Vertice.This issue affects Pathway: from n/a through 1.0.15; Hugo WP: from n/a through 1.0.8; Althea WP: from n/a through 1.0.13; Elevate WP: from n/a through 1.0.15; Brite: from n/a through 1.0.11; Colibri WP: from n/a through 1.0.94; Vertice: from n/a through 1.0.7.

CVSS3: 4.3
0%
Низкий
почти 2 года назад

Уязвимостей на страницу