Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 288 388

Количество 288 388

github логотип

GHSA-248v-346w-9cwc

около 1 года назад

Certifi removes GLOBALTRUST root certificate

EPSS: Низкий
github логотип

GHSA-248r-f975-ppfj

около 3 лет назад

Processing a maliciously crafted font may result in the disclosure of process memory. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5, iOS 14.6 and iPadOS 14.6. An out-of-bounds read was addressed with improved input validation.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-248r-745f-7p46

около 3 лет назад

Cross-site scripting (XSS) vulnerability in the themes_links function in template.php in the Amadou theme module 6.x-1.x before 6.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors related to class attributes in a list of links.

EPSS: Низкий
github логотип

GHSA-248r-2g9q-v634

около 3 лет назад

win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1 and Server 2008 R2 SP1 does not properly consider thread-owned objects during the processing of window handles, which allows local users to gain privileges via a crafted application, aka "Win32k Window Handle Vulnerability."

EPSS: Низкий
github логотип

GHSA-248q-qwj4-9945

больше 3 лет назад

D-Link DWL-G700AP with firmware 2.00 and 2.01 allows remote attackers to cause a denial of service (CAMEO HTTP service crash) via a request composed of "GET" followed by a space and two newlines, possibly triggering the crash due to missing arguments.

EPSS: Низкий
github логотип

GHSA-248q-88c9-6cq3

около 3 лет назад

Cross-site scripting (XSS) vulnerability in Opera before 9.63 allows remote attackers to inject arbitrary web script or HTML via built-in XSLT templates.

EPSS: Низкий
github логотип

GHSA-248p-qmc2-qc97

около 1 года назад

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Magarsus Consultancy SSO (Single Sign On) allows Manipulating Hidden Fields.This issue affects SSO (Single Sign On): from 1.0 before 1.1.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-248p-gq7w-24rp

около 3 лет назад

Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-0209, CVE-2010-2213, and CVE-2010-2214.

EPSS: Низкий
github логотип

GHSA-248j-xg68-6w85

больше 2 лет назад

The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. A remote user may be able to cause kernel code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-248j-q36m-hvq3

около 3 лет назад

imcat 4.4 allows remote attackers to obtain potentially sensitive configuration information via the root/tools/adbug/check.php URI.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-248j-6c4g-f66m

около 3 лет назад

server/notification/NotificationManagerService.java in the Notification Manager Service in Android 6.x before 2016-09-01 and 7.0 before 2016-09-01 lacks uid checks, which allows attackers to bypass intended restrictions on method calls via a crafted application, aka internal bug 29421441.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-248h-xgcm-3q77

около 3 лет назад

In Wireshark 3.2.0 to 3.2.2, 3.0.0 to 3.0.9, and 2.6.0 to 2.6.15, the BACapp dissector could crash. This was addressed in epan/dissectors/packet-bacapp.c by limiting the amount of recursion.

EPSS: Низкий
github логотип

GHSA-248g-v9x5-ppvq

больше 3 лет назад

Heap-based buffer overflow in Borland idsql32.dll 5.1.0.4, as used by RevilloC MailServer; 5.2.0.2 as used by Borland Developer Studio 2006; and possibly other versions allows remote attackers to execute arbitrary code via a long SQL statement, related to use of the DbiQExec function.

EPSS: Низкий
github логотип

GHSA-248g-g9j5-m344

около 3 лет назад

An elevation of privilege vulnerability in the Qualcomm ADSPRPC driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31695439. References: QC-CR#1086123, QC-CR#1100695.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-248c-9vj8-9325

больше 3 лет назад

Unspecified vulnerability in DCE in HP HP-UX B.11.11, B.11.23, and B.11.31 allows remote attackers to cause a denial of service via unknown vectors.

EPSS: Низкий
github логотип

GHSA-2489-xfhx-mcfj

больше 3 лет назад

Unrestricted file upload vulnerability in myaccount.php in Easy Scripts Answer and Question Script allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the uploads/[username] directory.

EPSS: Низкий
github логотип

GHSA-2489-fj5v-q8w2

около 3 лет назад

A configuration issue was addressed with additional restrictions. This issue affected versions prior to macOS Mojave 10.14.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2488-pfc2-g3x9

около 3 лет назад

The sell function of a smart contract implementation for ETHEREUMBLACK (ETCBK), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2488-7mjj-wx6f

больше 3 лет назад

Stack-based buffer overflow in the reply_netbios_packet function in nmbd/nmbd_packets.c in nmbd in Samba 3.0.0 through 3.0.26a, when operating as a WINS server, allows remote attackers to execute arbitrary code via crafted WINS Name Registration requests followed by a WINS Name Query request.

EPSS: Средний
github логотип

GHSA-2487-9f55-2vg9

3 месяца назад

OZI-Project/ozi-publish Code Injection vulnerability

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-248v-346w-9cwc

Certifi removes GLOBALTRUST root certificate

2%
Низкий
около 1 года назад
github логотип
GHSA-248r-f975-ppfj

Processing a maliciously crafted font may result in the disclosure of process memory. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5, iOS 14.6 and iPadOS 14.6. An out-of-bounds read was addressed with improved input validation.

CVSS3: 5.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-248r-745f-7p46

Cross-site scripting (XSS) vulnerability in the themes_links function in template.php in the Amadou theme module 6.x-1.x before 6.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors related to class attributes in a list of links.

1%
Низкий
около 3 лет назад
github логотип
GHSA-248r-2g9q-v634

win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1 and Server 2008 R2 SP1 does not properly consider thread-owned objects during the processing of window handles, which allows local users to gain privileges via a crafted application, aka "Win32k Window Handle Vulnerability."

2%
Низкий
около 3 лет назад
github логотип
GHSA-248q-qwj4-9945

D-Link DWL-G700AP with firmware 2.00 and 2.01 allows remote attackers to cause a denial of service (CAMEO HTTP service crash) via a request composed of "GET" followed by a space and two newlines, possibly triggering the crash due to missing arguments.

6%
Низкий
больше 3 лет назад
github логотип
GHSA-248q-88c9-6cq3

Cross-site scripting (XSS) vulnerability in Opera before 9.63 allows remote attackers to inject arbitrary web script or HTML via built-in XSLT templates.

0%
Низкий
около 3 лет назад
github логотип
GHSA-248p-qmc2-qc97

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Magarsus Consultancy SSO (Single Sign On) allows Manipulating Hidden Fields.This issue affects SSO (Single Sign On): from 1.0 before 1.1.

CVSS3: 6.1
0%
Низкий
около 1 года назад
github логотип
GHSA-248p-gq7w-24rp

Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-0209, CVE-2010-2213, and CVE-2010-2214.

2%
Низкий
около 3 лет назад
github логотип
GHSA-248j-xg68-6w85

The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. A remote user may be able to cause kernel code execution.

CVSS3: 9.8
2%
Низкий
больше 2 лет назад
github логотип
GHSA-248j-q36m-hvq3

imcat 4.4 allows remote attackers to obtain potentially sensitive configuration information via the root/tools/adbug/check.php URI.

CVSS3: 5.3
3%
Низкий
около 3 лет назад
github логотип
GHSA-248j-6c4g-f66m

server/notification/NotificationManagerService.java in the Notification Manager Service in Android 6.x before 2016-09-01 and 7.0 before 2016-09-01 lacks uid checks, which allows attackers to bypass intended restrictions on method calls via a crafted application, aka internal bug 29421441.

CVSS3: 5.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-248h-xgcm-3q77

In Wireshark 3.2.0 to 3.2.2, 3.0.0 to 3.0.9, and 2.6.0 to 2.6.15, the BACapp dissector could crash. This was addressed in epan/dissectors/packet-bacapp.c by limiting the amount of recursion.

2%
Низкий
около 3 лет назад
github логотип
GHSA-248g-v9x5-ppvq

Heap-based buffer overflow in Borland idsql32.dll 5.1.0.4, as used by RevilloC MailServer; 5.2.0.2 as used by Borland Developer Studio 2006; and possibly other versions allows remote attackers to execute arbitrary code via a long SQL statement, related to use of the DbiQExec function.

5%
Низкий
больше 3 лет назад
github логотип
GHSA-248g-g9j5-m344

An elevation of privilege vulnerability in the Qualcomm ADSPRPC driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31695439. References: QC-CR#1086123, QC-CR#1100695.

CVSS3: 7
0%
Низкий
около 3 лет назад
github логотип
GHSA-248c-9vj8-9325

Unspecified vulnerability in DCE in HP HP-UX B.11.11, B.11.23, and B.11.31 allows remote attackers to cause a denial of service via unknown vectors.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-2489-xfhx-mcfj

Unrestricted file upload vulnerability in myaccount.php in Easy Scripts Answer and Question Script allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the uploads/[username] directory.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-2489-fj5v-q8w2

A configuration issue was addressed with additional restrictions. This issue affected versions prior to macOS Mojave 10.14.

CVSS3: 9.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-2488-pfc2-g3x9

The sell function of a smart contract implementation for ETHEREUMBLACK (ETCBK), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-2488-7mjj-wx6f

Stack-based buffer overflow in the reply_netbios_packet function in nmbd/nmbd_packets.c in nmbd in Samba 3.0.0 through 3.0.26a, when operating as a WINS server, allows remote attackers to execute arbitrary code via crafted WINS Name Registration requests followed by a WINS Name Query request.

41%
Средний
больше 3 лет назад
github логотип
GHSA-2487-9f55-2vg9

OZI-Project/ozi-publish Code Injection vulnerability

0%
Низкий
3 месяца назад

Уязвимостей на страницу