Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3p99-663g-4p22

почти 4 года назад

Use-after-free vulnerability in the Sb.SuperBuddy.1 ActiveX control (sb.dll) in America Online (AOL) 9.5.0.1 allows remote attackers to trigger memory corruption or possibly execute arbitrary code via a malformed argument to the SetSuperBuddy method.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-3p98-p9mv-8p9f

4 месяца назад

Incorrect Privilege Assignment vulnerability in N-Media Simple User Registration wp-registration allows Privilege Escalation.This issue affects Simple User Registration: from n/a through <= 6.4.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3p98-cw2j-96xf

больше 1 года назад

A reflected cross-site scripting (XSS) vulnerability in "ccHandlerResource.ashx" in CADClick <= 1.11.0 allows remote attackers to inject arbitrary web script or HTML via the "res_url" parameter.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3p98-4wm7-qj6w

5 месяцев назад

Missing Authorization vulnerability in ThimPress WP Events Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Events Manager: from n/a through 2.2.1.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3p97-hgvq-jvxr

больше 3 лет назад

The backtrack compilation code in the Irregex package (aka IrRegular Expressions) before 0.9.6 for Scheme allows remote attackers to cause a denial of service (memory consumption) via a crafted regular expression with a repeating pattern.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3p96-wrm7-xc3m

больше 1 года назад

An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlaceMetaData of Public CMS v.4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3p95-q82m-f2fv

3 месяца назад

ELOG allows an authenticated user to modify or overwrite the configuration file, resulting in denial of service. If the execute facility is specifically enabled with the "-x" command line flag, attackers could execute OS commands on the host machine. By default, ELOG is not configured to allow shell commands or self-registration.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3p95-fjgp-pggx

больше 3 лет назад

Unspecified vulnerability in Adobe Flash Player 11.1.102.55 on Windows and Mac OS X allows remote attackers to execute arbitrary code via a crafted SWF file, as demonstrated by the second of two vulnerabilities exploited by the Intevydis vd_adobe_fp module in VulnDisco Step Ahead (SA). NOTE: as of 20111207, this disclosure has no actionable information. However, because the module author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

EPSS: Низкий
github логотип

GHSA-3p95-f3g8-fcgq

около 4 лет назад

The BPF subsystem in the Linux kernel before 4.17 mishandles situations with a long jump over an instruction sequence where inner instructions require substantial expansions into multiple BPF instructions, leading to an overflow. This affects kernel/bpf/core.c and net/core/filter.c.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3p94-vj97-fm4q

около 4 лет назад

OS Command Injection in fsa

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3p93-j4fw-gpx2

больше 3 лет назад

Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 or earlier allows untrusted applets and applications to read arbitrary memory via a crafted ZIP file.

EPSS: Низкий
github логотип

GHSA-3p92-jw9p-xx95

почти 4 года назад

The PPP wvdial.lxdialog script in wvdial 1.4 and earlier creates a .config file with world readable permissions, which allows a local attacker in the dialout group to access login and password information.

EPSS: Низкий
github логотип

GHSA-3p92-886g-qxpq

больше 6 лет назад

Remote Memory Exposure in floody

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-3p92-26vx-7f7j

больше 2 лет назад

A vulnerability was found in SourceCodester Free Hospital Management System for Small Practices 1.0. It has been classified as critical. This affects an unknown part of the file appointment.php. The manipulation of the argument sheduledate leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-237561 was assigned to this vulnerability.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3p92-24w5-4jr6

больше 3 лет назад

SQL injection vulnerability in the Seed Coupon plugin before 1.6 for EC-CUBE allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3p8x-pc99-4p67

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to handling of .nessus files.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3p8x-c3hm-xmp2

2 месяца назад

An improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.1, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow information disclosure to an authenticated attacker via crafted requests

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3p8v-w8mr-m3x8

больше 1 года назад

Butterfly has path/URL confusion in resource handling leading to multiple weaknesses

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-3p8v-593f-mgx8

4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: tcp: fix skb_copy_ubufs() vs BIG TCP David Ahern reported crashes in skb_copy_ubufs() caused by TCP tx zerocopy using hugepages, and skb length bigger than ~68 KB. skb_copy_ubufs() assumed it could copy all payload using up to MAX_SKB_FRAGS order-0 pages. This assumption broke when BIG TCP was able to put up to 512 KB per skb. We did not hit this bug at Google because we use CONFIG_MAX_SKB_FRAGS=45 and limit gso_max_size to 180000. A solution is to use higher order pages if needed. v2: add missing __GFP_COMP, or we leak memory.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3p8r-p4q5-mc44

больше 3 лет назад

Violation Comments to GitLab Plugin has Insufficiently Protected Credentials

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3p99-663g-4p22

Use-after-free vulnerability in the Sb.SuperBuddy.1 ActiveX control (sb.dll) in America Online (AOL) 9.5.0.1 allows remote attackers to trigger memory corruption or possibly execute arbitrary code via a malformed argument to the SetSuperBuddy method.

CVSS3: 8.8
22%
Средний
почти 4 года назад
github логотип
GHSA-3p98-p9mv-8p9f

Incorrect Privilege Assignment vulnerability in N-Media Simple User Registration wp-registration allows Privilege Escalation.This issue affects Simple User Registration: from n/a through <= 6.4.

CVSS3: 8.8
0%
Низкий
4 месяца назад
github логотип
GHSA-3p98-cw2j-96xf

A reflected cross-site scripting (XSS) vulnerability in "ccHandlerResource.ashx" in CADClick <= 1.11.0 allows remote attackers to inject arbitrary web script or HTML via the "res_url" parameter.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-3p98-4wm7-qj6w

Missing Authorization vulnerability in ThimPress WP Events Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Events Manager: from n/a through 2.2.1.

CVSS3: 5.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-3p97-hgvq-jvxr

The backtrack compilation code in the Irregex package (aka IrRegular Expressions) before 0.9.6 for Scheme allows remote attackers to cause a denial of service (memory consumption) via a crafted regular expression with a repeating pattern.

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3p96-wrm7-xc3m

An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlaceMetaData of Public CMS v.4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.

CVSS3: 8.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-3p95-q82m-f2fv

ELOG allows an authenticated user to modify or overwrite the configuration file, resulting in denial of service. If the execute facility is specifically enabled with the "-x" command line flag, attackers could execute OS commands on the host machine. By default, ELOG is not configured to allow shell commands or self-registration.

CVSS3: 7.1
0%
Низкий
3 месяца назад
github логотип
GHSA-3p95-fjgp-pggx

Unspecified vulnerability in Adobe Flash Player 11.1.102.55 on Windows and Mac OS X allows remote attackers to execute arbitrary code via a crafted SWF file, as demonstrated by the second of two vulnerabilities exploited by the Intevydis vd_adobe_fp module in VulnDisco Step Ahead (SA). NOTE: as of 20111207, this disclosure has no actionable information. However, because the module author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

4%
Низкий
больше 3 лет назад
github логотип
GHSA-3p95-f3g8-fcgq

The BPF subsystem in the Linux kernel before 4.17 mishandles situations with a long jump over an instruction sequence where inner instructions require substantial expansions into multiple BPF instructions, leading to an overflow. This affects kernel/bpf/core.c and net/core/filter.c.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-3p94-vj97-fm4q

OS Command Injection in fsa

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-3p93-j4fw-gpx2

Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 or earlier allows untrusted applets and applications to read arbitrary memory via a crafted ZIP file.

4%
Низкий
больше 3 лет назад
github логотип
GHSA-3p92-jw9p-xx95

The PPP wvdial.lxdialog script in wvdial 1.4 and earlier creates a .config file with world readable permissions, which allows a local attacker in the dialout group to access login and password information.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3p92-886g-qxpq

Remote Memory Exposure in floody

CVSS3: 5.1
больше 6 лет назад
github логотип
GHSA-3p92-26vx-7f7j

A vulnerability was found in SourceCodester Free Hospital Management System for Small Practices 1.0. It has been classified as critical. This affects an unknown part of the file appointment.php. The manipulation of the argument sheduledate leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-237561 was assigned to this vulnerability.

CVSS3: 6.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3p92-24w5-4jr6

SQL injection vulnerability in the Seed Coupon plugin before 1.6 for EC-CUBE allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS3: 9.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-3p8x-pc99-4p67

Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to handling of .nessus files.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3p8x-c3hm-xmp2

An improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.1, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow information disclosure to an authenticated attacker via crafted requests

CVSS3: 6.5
0%
Низкий
2 месяца назад
github логотип
GHSA-3p8v-w8mr-m3x8

Butterfly has path/URL confusion in resource handling leading to multiple weaknesses

CVSS3: 9.1
2%
Низкий
больше 1 года назад
github логотип
GHSA-3p8v-593f-mgx8

In the Linux kernel, the following vulnerability has been resolved: tcp: fix skb_copy_ubufs() vs BIG TCP David Ahern reported crashes in skb_copy_ubufs() caused by TCP tx zerocopy using hugepages, and skb length bigger than ~68 KB. skb_copy_ubufs() assumed it could copy all payload using up to MAX_SKB_FRAGS order-0 pages. This assumption broke when BIG TCP was able to put up to 512 KB per skb. We did not hit this bug at Google because we use CONFIG_MAX_SKB_FRAGS=45 and limit gso_max_size to 180000. A solution is to use higher order pages if needed. v2: add missing __GFP_COMP, or we leak memory.

CVSS3: 5.5
0%
Низкий
4 месяца назад
github логотип
GHSA-3p8r-p4q5-mc44

Violation Comments to GitLab Plugin has Insufficiently Protected Credentials

CVSS3: 4.3
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу