Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3p2x-p2h6-wp37

больше 3 лет назад

Improper initialization in the Intel(R) Data Center Manager software before version 4.1 may allow an authenticated user to potentially enable denial of service via local access.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3p2x-hfrr-wj4w

10 месяцев назад

Denial of service due to allocation of resources without limits. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39904.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3p2x-fgmw-32pv

около 2 лет назад

Windows Subsystem for Linux Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3p2x-2cfv-p7xm

почти 4 года назад

Multiple vulnerabilities in Midnight Commander (mc) before 4.6.0, with unknown impact, related to "Insecure temporary file and directory creations."

EPSS: Низкий
github логотип

GHSA-3p2w-3263-9gr3

больше 3 лет назад

Uncontrolled recursion in Decoder.Skip in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a deeply nested XML document.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3p2v-w863-5q4c

около 2 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: i2c: cadence: cdns_i2c_master_xfer(): Fix runtime PM leak on error path The cdns_i2c_master_xfer() function gets a runtime PM reference when the function is entered. This reference is released when the function is exited. There is currently one error path where the function exits directly, which leads to a leak of the runtime PM reference. Make sure that this error path also releases the runtime PM reference.

EPSS: Низкий
github логотип

GHSA-3p2v-4qj8-6w5f

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: media: v4l2-core: explicitly clear ioctl input data As seen from a recent syzbot bug report, mistakes in the compat ioctl implementation can lead to uninitialized kernel stack data getting used as input for driver ioctl handlers. The reported bug is now fixed, but it's possible that other related bugs are still present or get added in the future. As the drivers need to check user input already, the possible impact is fairly low, but it might still cause an information leak. To be on the safe side, always clear the entire ioctl buffer before calling the conversion handler functions that are meant to initialize them.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3p2r-ffrh-j979

2 дня назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Xerox CentreWare on Windows allows Stored XSS.This issue affects CentreWare: through 7.0.6.  Consider upgrading Xerox® CentreWare Web® to v7.2.2.25 via the software available on Xerox.com

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3p2r-95j5-h86j

около 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPZOOM Beaver Builder Addons by WPZOOM allows Stored XSS.This issue affects Beaver Builder Addons by WPZOOM: from n/a through 1.3.4.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3p2q-mh7q-9pxj

больше 2 лет назад

Duplicate Advisory: elFinder vulnerable to path traversal in LocalVolumeDriver connector

EPSS: Низкий
github логотип

GHSA-3p2q-4jpq-m2x2

почти 4 года назад

The default installation of Ultraboard 2000 2.11 creates the Skins, Database, and Backups directories with world-writeable permissions, which could allow local users to modify sensitive information or possibly insert and execute CGI programs.

EPSS: Низкий
github логотип

GHSA-3p2p-cj2p-f89p

больше 3 лет назад

A stored cross-site scripting (XSS) vulnerability in /scas/?page=clubs/application_form&id=7 of School Club Application System v0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the firstname parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3p2p-55rm-xcvw

2 месяца назад

A vulnerability has been identified in COMOS V10.6 (All versions), COMOS V10.6 (All versions), JT Bi-Directional Translator for STEP (All versions), NX V2412 (All versions < V2412.8900 with Cloud Entitlement (bundled as NX X)), NX V2506 (All versions < V2506.6000 with Cloud Entitlement (bundled as NX X)), Simcenter 3D (All versions < V2506.6000 with Cloud Entitlement (bundled as Simcenter X Mechanical)), Simcenter Femap (All versions < V2506.0002 with Cloud Entitlement (bundled as Simcenter X Mechanical)), Simcenter Studio (All versions), Simcenter System Architect (All versions), Tecnomatix Plant Simulation (All versions < V2504.0007). The SALT SDK is missing server certificate validation while establishing TLS connections to the authorization server. This could allow an attacker to perform a man-in-the-middle attack.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3p2m-vxm4-c34h

больше 3 лет назад

BarnOwl before 1.6.2 does not check the return code of calls to the (1) ZPending and (2) ZReceiveNotice functions in libzephyr, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.

EPSS: Низкий
github логотип

GHSA-3p2m-574v-v257

6 месяцев назад

Liferay Portal Vulnerable to Cross-Site Scripting

EPSS: Низкий
github логотип

GHSA-3p2j-q62h-27w3

6 месяцев назад

A security issue exists due to improper handling of malformed CIP Forward Close packets during fuzzing. The controller enters a solid red Fault LED state and becomes unresponsive. Upon power cycle, the controller will enter recoverable fault where the MS LED and Fault LED become flashing red and reports fault code 0xF015. To recover, clear the fault.

EPSS: Низкий
github логотип

GHSA-3p2j-4mpr-385w

3 месяца назад

Inappropriate implementation in Extensions in Google Chrome prior to 142.0.7444.59 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severity: High)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3p2h-wqq4-wf4h

10 месяцев назад

Apache Tomcat Denial of Service via invalid HTTP priority header

EPSS: Средний
github логотип

GHSA-3p2h-8x46-gvg6

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: fix null-ptr-deref in l2cap_chan_timeout There is a race condition between l2cap_chan_timeout() and l2cap_chan_del(). When we use l2cap_chan_del() to delete the channel, the chan->conn will be set to null. But the conn could be dereferenced again in the mutex_lock() of l2cap_chan_timeout(). As a result the null pointer dereference bug will happen. The KASAN report triggered by POC is shown below: [ 472.074580] ================================================================== [ 472.075284] BUG: KASAN: null-ptr-deref in mutex_lock+0x68/0xc0 [ 472.075308] Write of size 8 at addr 0000000000000158 by task kworker/0:0/7 [ 472.075308] [ 472.075308] CPU: 0 PID: 7 Comm: kworker/0:0 Not tainted 6.9.0-rc5-00356-g78c0094a146b #36 [ 472.075308] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.14.0-0-g155821a1990b-prebuilt.qemu4 [ 472.075308] Workqueue: events l2cap_chan_timeout [ 47...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3p2g-r477-j4fj

больше 3 лет назад

ABB PCM600 before 2.7 improperly stores the main application password after a password change, which allows local users to obtain sensitive information via unspecified vectors.

CVSS3: 3.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3p2x-p2h6-wp37

Improper initialization in the Intel(R) Data Center Manager software before version 4.1 may allow an authenticated user to potentially enable denial of service via local access.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3p2x-hfrr-wj4w

Denial of service due to allocation of resources without limits. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39904.

CVSS3: 5.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-3p2x-fgmw-32pv

Windows Subsystem for Linux Elevation of Privilege Vulnerability

CVSS3: 7.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-3p2x-2cfv-p7xm

Multiple vulnerabilities in Midnight Commander (mc) before 4.6.0, with unknown impact, related to "Insecure temporary file and directory creations."

0%
Низкий
почти 4 года назад
github логотип
GHSA-3p2w-3263-9gr3

Uncontrolled recursion in Decoder.Skip in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a deeply nested XML document.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3p2v-w863-5q4c

In the Linux kernel, the following vulnerability has been resolved: i2c: cadence: cdns_i2c_master_xfer(): Fix runtime PM leak on error path The cdns_i2c_master_xfer() function gets a runtime PM reference when the function is entered. This reference is released when the function is exited. There is currently one error path where the function exits directly, which leads to a leak of the runtime PM reference. Make sure that this error path also releases the runtime PM reference.

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3p2v-4qj8-6w5f

In the Linux kernel, the following vulnerability has been resolved: media: v4l2-core: explicitly clear ioctl input data As seen from a recent syzbot bug report, mistakes in the compat ioctl implementation can lead to uninitialized kernel stack data getting used as input for driver ioctl handlers. The reported bug is now fixed, but it's possible that other related bugs are still present or get added in the future. As the drivers need to check user input already, the possible impact is fairly low, but it might still cause an information leak. To be on the safe side, always clear the entire ioctl buffer before calling the conversion handler functions that are meant to initialize them.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3p2r-ffrh-j979

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Xerox CentreWare on Windows allows Stored XSS.This issue affects CentreWare: through 7.0.6.  Consider upgrading Xerox® CentreWare Web® to v7.2.2.25 via the software available on Xerox.com

CVSS3: 5.3
0%
Низкий
2 дня назад
github логотип
GHSA-3p2r-95j5-h86j

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPZOOM Beaver Builder Addons by WPZOOM allows Stored XSS.This issue affects Beaver Builder Addons by WPZOOM: from n/a through 1.3.4.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-3p2q-mh7q-9pxj

Duplicate Advisory: elFinder vulnerable to path traversal in LocalVolumeDriver connector

больше 2 лет назад
github логотип
GHSA-3p2q-4jpq-m2x2

The default installation of Ultraboard 2000 2.11 creates the Skins, Database, and Backups directories with world-writeable permissions, which could allow local users to modify sensitive information or possibly insert and execute CGI programs.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3p2p-cj2p-f89p

A stored cross-site scripting (XSS) vulnerability in /scas/?page=clubs/application_form&id=7 of School Club Application System v0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the firstname parameter.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3p2p-55rm-xcvw

A vulnerability has been identified in COMOS V10.6 (All versions), COMOS V10.6 (All versions), JT Bi-Directional Translator for STEP (All versions), NX V2412 (All versions < V2412.8900 with Cloud Entitlement (bundled as NX X)), NX V2506 (All versions < V2506.6000 with Cloud Entitlement (bundled as NX X)), Simcenter 3D (All versions < V2506.6000 with Cloud Entitlement (bundled as Simcenter X Mechanical)), Simcenter Femap (All versions < V2506.0002 with Cloud Entitlement (bundled as Simcenter X Mechanical)), Simcenter Studio (All versions), Simcenter System Architect (All versions), Tecnomatix Plant Simulation (All versions < V2504.0007). The SALT SDK is missing server certificate validation while establishing TLS connections to the authorization server. This could allow an attacker to perform a man-in-the-middle attack.

CVSS3: 8.1
0%
Низкий
2 месяца назад
github логотип
GHSA-3p2m-vxm4-c34h

BarnOwl before 1.6.2 does not check the return code of calls to the (1) ZPending and (2) ZReceiveNotice functions in libzephyr, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-3p2m-574v-v257

Liferay Portal Vulnerable to Cross-Site Scripting

0%
Низкий
6 месяцев назад
github логотип
GHSA-3p2j-q62h-27w3

A security issue exists due to improper handling of malformed CIP Forward Close packets during fuzzing. The controller enters a solid red Fault LED state and becomes unresponsive. Upon power cycle, the controller will enter recoverable fault where the MS LED and Fault LED become flashing red and reports fault code 0xF015. To recover, clear the fault.

0%
Низкий
6 месяцев назад
github логотип
GHSA-3p2j-4mpr-385w

Inappropriate implementation in Extensions in Google Chrome prior to 142.0.7444.59 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severity: High)

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-3p2h-wqq4-wf4h

Apache Tomcat Denial of Service via invalid HTTP priority header

11%
Средний
10 месяцев назад
github логотип
GHSA-3p2h-8x46-gvg6

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: fix null-ptr-deref in l2cap_chan_timeout There is a race condition between l2cap_chan_timeout() and l2cap_chan_del(). When we use l2cap_chan_del() to delete the channel, the chan->conn will be set to null. But the conn could be dereferenced again in the mutex_lock() of l2cap_chan_timeout(). As a result the null pointer dereference bug will happen. The KASAN report triggered by POC is shown below: [ 472.074580] ================================================================== [ 472.075284] BUG: KASAN: null-ptr-deref in mutex_lock+0x68/0xc0 [ 472.075308] Write of size 8 at addr 0000000000000158 by task kworker/0:0/7 [ 472.075308] [ 472.075308] CPU: 0 PID: 7 Comm: kworker/0:0 Not tainted 6.9.0-rc5-00356-g78c0094a146b #36 [ 472.075308] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.14.0-0-g155821a1990b-prebuilt.qemu4 [ 472.075308] Workqueue: events l2cap_chan_timeout [ 47...

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3p2g-r477-j4fj

ABB PCM600 before 2.7 improperly stores the main application password after a password change, which allows local users to obtain sensitive information via unspecified vectors.

CVSS3: 3.3
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу