Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3qf3-2r2j-47g4

больше 3 лет назад

The ASPEED ast2400 and ast2500 Baseband Management Controller (BMC) hardware and firmware implement Advanced High-performance Bus (AHB) bridges, which allow arbitrary read and write access to the BMC's physical address space from the host (or from the network in unusual cases where the BMC console uart is attached to a serial concentrator). This CVE applies to the specific cases of iLPC2AHB bridge Pt I, iLPC2AHB bridge Pt II, PCIe VGA P2A bridge, DMA from/to arbitrary BMC memory via X-DMA, UART-based SoC Debug interface, LPC2AHB bridge, PCIe BMC P2A bridge, and Watchdog setup.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3qf2-xr2w-rc3p

больше 3 лет назад

Unspecified vulnerability in IBM Tivoli Monitoring Agent (ITMA), as used in IBM DB2 9.5 before FP9 on UNIX, allows local users to gain privileges via unknown vectors.

EPSS: Низкий
github логотип

GHSA-3qf2-m7p9-w73v

больше 3 лет назад

Brocade BigIron RX switches allow remote attackers to bypass ACL rules by using 179 as the source port of a packet.

EPSS: Низкий
github логотип

GHSA-3qf2-c4pc-rv85

больше 3 лет назад

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate project keys via an Information Disclosure vulnerability in the /browse.PROJECTKEY endpoint. The affected versions are before version 7.13.7, from version 8.0.0 before 8.5.8, and from version 8.6.0 before 8.12.0.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3qf2-7xvh-j2fx

почти 4 года назад

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web ...

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3qcx-rj23-g86q

10 месяцев назад

A vulnerability classified as critical has been found in thautwarm vscode-diana 0.0.1. Affected is an unknown function of the file Gen.py of the component Jinja2 Template Handler. The manipulation leads to injection. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3qcx-c93v-59hr

больше 1 года назад

Windows Secure Kernel Mode Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3qcx-4983-xfxp

больше 3 лет назад

HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer series (before v. 20190426) may have embedded web server attributes which may be potentially vulnerable to Buffer Overflow.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3qcw-xpj5-x29h

больше 3 лет назад

Microsoft Dynamics 365 (on-premises) Spoofing Vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3qcw-gv72-ccfg

почти 4 года назад

Safari 1.2.4 on Mac OS X 10.3.6 allows remote attackers to cause a denial of service (application crash from memory exhaustion), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays.

EPSS: Низкий
github логотип

GHSA-3qcw-5j3f-5872

больше 3 лет назад

Use-after-free vulnerability in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers to execute arbitrary code via unspecified vectors related to an unspecified "image type within a certain function."

EPSS: Низкий
github логотип

GHSA-3qcv-2mv7-28qv

почти 4 года назад

DUware DUpoll 3.0 and 3.1 stores _private/Dupoll.mdb under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames and passwords.

EPSS: Низкий
github логотип

GHSA-3qcr-p3xq-5c4r

больше 3 лет назад

RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve a pool overflow (leading to Escalation of Privileges, Denial of Service, and Code Execution) via a crafted Device IO Control packet to a device.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3qcq-w2m6-vwwx

почти 4 года назад

An interaction between the AS/400 shared folders feature and Microsoft SNA Server 3.0 and earlier allows users to view each other's folders when the users share the same Local APPC LU.

EPSS: Средний
github логотип

GHSA-3qcq-p3m2-3c4p

17 дней назад

Missing Authorization vulnerability in Select-Themes Don Peppe donpeppe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Don Peppe: from n/a through <= 1.3.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3qcq-28jc-g3f4

около 2 лет назад

The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receiving an invalid one.

CVSS3: 7.5
EPSS: Высокий
github логотип

GHSA-3qcp-g78m-7jv9

больше 3 лет назад

A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-3qcp-9v8c-6jp7

4 месяца назад

Piranha CMS vulnerable to stored cross-site scripting (XSS)

EPSS: Низкий
github логотип

GHSA-3qcj-r6mr-vw7f

17 дней назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows DOM-Based XSS.This issue affects tagDiv Composer: from n/a through <= 5.4.2.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3qch-fgcw-x72h

больше 3 лет назад

In phNxpNciHal_ext_process_nfc_init_rsp of phNxpNciHal_ext.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the NFC server with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-169258455

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3qf3-2r2j-47g4

The ASPEED ast2400 and ast2500 Baseband Management Controller (BMC) hardware and firmware implement Advanced High-performance Bus (AHB) bridges, which allow arbitrary read and write access to the BMC's physical address space from the host (or from the network in unusual cases where the BMC console uart is attached to a serial concentrator). This CVE applies to the specific cases of iLPC2AHB bridge Pt I, iLPC2AHB bridge Pt II, PCIe VGA P2A bridge, DMA from/to arbitrary BMC memory via X-DMA, UART-based SoC Debug interface, LPC2AHB bridge, PCIe BMC P2A bridge, and Watchdog setup.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3qf2-xr2w-rc3p

Unspecified vulnerability in IBM Tivoli Monitoring Agent (ITMA), as used in IBM DB2 9.5 before FP9 on UNIX, allows local users to gain privileges via unknown vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3qf2-m7p9-w73v

Brocade BigIron RX switches allow remote attackers to bypass ACL rules by using 179 as the source port of a packet.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3qf2-c4pc-rv85

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate project keys via an Information Disclosure vulnerability in the /browse.PROJECTKEY endpoint. The affected versions are before version 7.13.7, from version 8.0.0 before 8.5.8, and from version 8.6.0 before 8.12.0.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3qf2-7xvh-j2fx

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web ...

CVSS3: 5.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-3qcx-rj23-g86q

A vulnerability classified as critical has been found in thautwarm vscode-diana 0.0.1. Affected is an unknown function of the file Gen.py of the component Jinja2 Template Handler. The manipulation leads to injection. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-3qcx-c93v-59hr

Windows Secure Kernel Mode Elevation of Privilege Vulnerability

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3qcx-4983-xfxp

HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer series (before v. 20190426) may have embedded web server attributes which may be potentially vulnerable to Buffer Overflow.

CVSS3: 7.2
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3qcw-xpj5-x29h

Microsoft Dynamics 365 (on-premises) Spoofing Vulnerability

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3qcw-gv72-ccfg

Safari 1.2.4 on Mac OS X 10.3.6 allows remote attackers to cause a denial of service (application crash from memory exhaustion), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3qcw-5j3f-5872

Use-after-free vulnerability in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers to execute arbitrary code via unspecified vectors related to an unspecified "image type within a certain function."

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3qcv-2mv7-28qv

DUware DUpoll 3.0 and 3.1 stores _private/Dupoll.mdb under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames and passwords.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3qcr-p3xq-5c4r

RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve a pool overflow (leading to Escalation of Privileges, Denial of Service, and Code Execution) via a crafted Device IO Control packet to a device.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3qcq-w2m6-vwwx

An interaction between the AS/400 shared folders feature and Microsoft SNA Server 3.0 and earlier allows users to view each other's folders when the users share the same Local APPC LU.

14%
Средний
почти 4 года назад
github логотип
GHSA-3qcq-p3m2-3c4p

Missing Authorization vulnerability in Select-Themes Don Peppe donpeppe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Don Peppe: from n/a through <= 1.3.

CVSS3: 4.3
0%
Низкий
17 дней назад
github логотип
GHSA-3qcq-28jc-g3f4

The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receiving an invalid one.

CVSS3: 7.5
81%
Высокий
около 2 лет назад
github логотип
GHSA-3qcp-g78m-7jv9

A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.

CVSS3: 8.8
53%
Средний
больше 3 лет назад
github логотип
GHSA-3qcp-9v8c-6jp7

Piranha CMS vulnerable to stored cross-site scripting (XSS)

0%
Низкий
4 месяца назад
github логотип
GHSA-3qcj-r6mr-vw7f

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows DOM-Based XSS.This issue affects tagDiv Composer: from n/a through <= 5.4.2.

CVSS3: 6.1
0%
Низкий
17 дней назад
github логотип
GHSA-3qch-fgcw-x72h

In phNxpNciHal_ext_process_nfc_init_rsp of phNxpNciHal_ext.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the NFC server with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-169258455

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу