Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3mwm-gvjc-9x56

больше 3 лет назад

app/operator_panel/index_inc.php in the Operator Panel module in FreePBX 4.4.3 suffers from an information disclosure vulnerability due to excessive debug information, which allows authenticated administrative attackers to obtain credentials and other sensitive information.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3mwj-wx8p-p57v

больше 3 лет назад

Race condition in iMessage in Apple iOS before 8 allows attackers to obtain sensitive information by leveraging the presence of an attachment after the deletion of its parent (1) iMessage or (2) MMS.

EPSS: Низкий
github логотип

GHSA-3mwj-prww-7q68

больше 3 лет назад

Magnolia CMS From 6.1.3 to 6.2.3 contains a stored cross-site scripting (XSS) vulnerability in the setText parameter of /magnoliaAuthor/.magnolia/.

EPSS: Низкий
github логотип

GHSA-3mwj-7vmq-w43p

больше 3 лет назад

Stored XSS vulnerability in Jenkins Yet Another Build Visualizer Plugin

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-3mwj-25mw-j4g4

почти 4 года назад

Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted QuickTime movie file.

EPSS: Средний
github логотип

GHSA-3mwh-xgcp-8q55

больше 3 лет назад

An Arbitrary File Upload in the Upload Image component in Sourcecodester Online Bike Rental v1.0 allows authenticated administrator to conduct remote code execution.

EPSS: Низкий
github логотип

GHSA-3mwh-qccg-vxm7

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: apparmor: fix possible NULL pointer dereference profile->parent->dents[AAFS_PROF_DIR] could be NULL only if its parent is made from __create_missing_ancestors(..) and 'ent->old' is NULL in aa_replace_profiles(..). In that case, it must return an error code and the code, -ENOENT represents its state that the path of its parent is not existed yet. BUG: kernel NULL pointer dereference, address: 0000000000000030 PGD 0 P4D 0 PREEMPT SMP PTI CPU: 4 PID: 3362 Comm: apparmor_parser Not tainted 6.8.0-24-generic #24 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.15.0-1 04/01/2014 RIP: 0010:aafs_create.constprop.0+0x7f/0x130 Code: 4c 63 e0 48 83 c4 18 4c 89 e0 5b 41 5c 41 5d 41 5e 41 5f 5d 31 d2 31 c9 31 f6 31 ff 45 31 c0 45 31 c9 45 31 d2 c3 cc cc cc cc <4d> 8b 55 30 4d 8d ba a0 00 00 00 4c 89 55 c0 4c 89 ff e8 7a 6a ae RSP: 0018:ffffc9000b2c7c98 EFLAGS: 00010246 RAX: 0000000000000000 RBX: 00000000000041ed RCX:...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3mwh-p3hq-rrh2

больше 3 лет назад

Microsoft Win32k in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability".

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-3mwh-2gfv-6wv5

около 2 лет назад

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause heap overflow through integer overflow.

CVSS3: 2.9
EPSS: Низкий
github логотип

GHSA-3mwg-wvg9-ghpc

почти 4 года назад

The (1) address.html and possibly (2) calendar.html pages in Merak Mail Server 5.2.7 allow remote attackers to gain sensitive information via an invalid HTTP request, which reveals the installation path. NOTE: it is unclear whether the calendar.html is an exposure, since the path is leaked in web logs that may only be available to the administrators, who would have access to the path through legitimate means.

EPSS: Низкий
github логотип

GHSA-3mwg-gp5g-fv3q

почти 4 года назад

feedparser Cross-site Scripting vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3mwf-xhc6-4rgf

больше 3 лет назад

A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), reflective DLL, vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20), Modicon M580 (all versions prior to V3.10), which, if exploited, could allow attackers to transfer malicious code to the controller.

EPSS: Низкий
github логотип

GHSA-3mwf-8hp6-9vxf

больше 3 лет назад

An issue was discovered in xpdf 4.00. An infinite loop in XRef::Xref allows an attacker to cause denial of service because loop detection exists only for tables, not streams.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3mwc-76p7-h288

больше 3 лет назад

DCR.sys driver in SecurStar DriveCrypt 5.4, 5.3, and earlier allows local users to execute arbitrary code via a crafted argument to the 0x00073800 IOCTL.

EPSS: Низкий
github логотип

GHSA-3mwc-2cj7-gx8c

больше 1 года назад

lunary-ai/lunary Access Control Vulnerability in Prompt Variation Management

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-3mw9-8v7p-8v82

почти 4 года назад

Cross-site scripting (XSS) vulnerability in Chatbox Plugin 1.0 in e107 0.7.2 allows remote attackers to inject arbitrary HTML or web script via a Chatbox, as demonstrated using a SCRIPT element.

EPSS: Низкий
github логотип

GHSA-3mw8-p9vq-vwxw

почти 4 года назад

The Migration, Backup, Staging WordPress plugin before 0.9.69 does not have authorisation when adding remote storages, and does not sanitise as well as escape a parameter from such unauthenticated requests before outputting it in admin page, leading to a Stored Cross-Site Scripting issue

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3mw8-jr69-x96w

около 3 лет назад

Improper File Permissions in NetScout nGeniusONE 6.3.2 build 904 allows authenticated remote users to gain permissions via a crafted payload.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3mw8-88mv-4wcm

больше 3 лет назад

The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not properly check for administrative privileges during creation of machine accounts, which allows remote authenticated users to bypass intended access restrictions by leveraging the existence of a domain with both a Samba DC and a Windows DC, a similar issue to CVE-2015-2535.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3mw7-6cqh-vgc6

больше 3 лет назад

Heap-based buffer overflow in Unitronics VisiLogic OPLC IDE before 9.8.09 allows remote attackers to execute arbitrary code via a long vlp filename.

CVSS3: 9.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3mwm-gvjc-9x56

app/operator_panel/index_inc.php in the Operator Panel module in FreePBX 4.4.3 suffers from an information disclosure vulnerability due to excessive debug information, which allows authenticated administrative attackers to obtain credentials and other sensitive information.

CVSS3: 7.2
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3mwj-wx8p-p57v

Race condition in iMessage in Apple iOS before 8 allows attackers to obtain sensitive information by leveraging the presence of an attachment after the deletion of its parent (1) iMessage or (2) MMS.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mwj-prww-7q68

Magnolia CMS From 6.1.3 to 6.2.3 contains a stored cross-site scripting (XSS) vulnerability in the setText parameter of /magnoliaAuthor/.magnolia/.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mwj-7vmq-w43p

Stored XSS vulnerability in Jenkins Yet Another Build Visualizer Plugin

CVSS3: 8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mwj-25mw-j4g4

Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted QuickTime movie file.

12%
Средний
почти 4 года назад
github логотип
GHSA-3mwh-xgcp-8q55

An Arbitrary File Upload in the Upload Image component in Sourcecodester Online Bike Rental v1.0 allows authenticated administrator to conduct remote code execution.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-3mwh-qccg-vxm7

In the Linux kernel, the following vulnerability has been resolved: apparmor: fix possible NULL pointer dereference profile->parent->dents[AAFS_PROF_DIR] could be NULL only if its parent is made from __create_missing_ancestors(..) and 'ent->old' is NULL in aa_replace_profiles(..). In that case, it must return an error code and the code, -ENOENT represents its state that the path of its parent is not existed yet. BUG: kernel NULL pointer dereference, address: 0000000000000030 PGD 0 P4D 0 PREEMPT SMP PTI CPU: 4 PID: 3362 Comm: apparmor_parser Not tainted 6.8.0-24-generic #24 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.15.0-1 04/01/2014 RIP: 0010:aafs_create.constprop.0+0x7f/0x130 Code: 4c 63 e0 48 83 c4 18 4c 89 e0 5b 41 5c 41 5d 41 5e 41 5f 5d 31 d2 31 c9 31 f6 31 ff 45 31 c0 45 31 c9 45 31 d2 c3 cc cc cc cc <4d> 8b 55 30 4d 8d ba a0 00 00 00 4c 89 55 c0 4c 89 ff e8 7a 6a ae RSP: 0018:ffffc9000b2c7c98 EFLAGS: 00010246 RAX: 0000000000000000 RBX: 00000000000041ed RCX:...

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3mwh-p3hq-rrh2

Microsoft Win32k in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability".

CVSS3: 7
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3mwh-2gfv-6wv5

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause heap overflow through integer overflow.

CVSS3: 2.9
0%
Низкий
около 2 лет назад
github логотип
GHSA-3mwg-wvg9-ghpc

The (1) address.html and possibly (2) calendar.html pages in Merak Mail Server 5.2.7 allow remote attackers to gain sensitive information via an invalid HTTP request, which reveals the installation path. NOTE: it is unclear whether the calendar.html is an exposure, since the path is leaked in web logs that may only be available to the administrators, who would have access to the path through legitimate means.

9%
Низкий
почти 4 года назад
github логотип
GHSA-3mwg-gp5g-fv3q

feedparser Cross-site Scripting vulnerability

CVSS3: 6.1
7%
Низкий
почти 4 года назад
github логотип
GHSA-3mwf-xhc6-4rgf

A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), reflective DLL, vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20), Modicon M580 (all versions prior to V3.10), which, if exploited, could allow attackers to transfer malicious code to the controller.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3mwf-8hp6-9vxf

An issue was discovered in xpdf 4.00. An infinite loop in XRef::Xref allows an attacker to cause denial of service because loop detection exists only for tables, not streams.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mwc-76p7-h288

DCR.sys driver in SecurStar DriveCrypt 5.4, 5.3, and earlier allows local users to execute arbitrary code via a crafted argument to the 0x00073800 IOCTL.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mwc-2cj7-gx8c

lunary-ai/lunary Access Control Vulnerability in Prompt Variation Management

CVSS3: 9.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-3mw9-8v7p-8v82

Cross-site scripting (XSS) vulnerability in Chatbox Plugin 1.0 in e107 0.7.2 allows remote attackers to inject arbitrary HTML or web script via a Chatbox, as demonstrated using a SCRIPT element.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3mw8-p9vq-vwxw

The Migration, Backup, Staging WordPress plugin before 0.9.69 does not have authorisation when adding remote storages, and does not sanitise as well as escape a parameter from such unauthenticated requests before outputting it in admin page, leading to a Stored Cross-Site Scripting issue

CVSS3: 6.1
4%
Низкий
почти 4 года назад
github логотип
GHSA-3mw8-jr69-x96w

Improper File Permissions in NetScout nGeniusONE 6.3.2 build 904 allows authenticated remote users to gain permissions via a crafted payload.

CVSS3: 8.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-3mw8-88mv-4wcm

The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not properly check for administrative privileges during creation of machine accounts, which allows remote authenticated users to bypass intended access restrictions by leveraging the existence of a domain with both a Samba DC and a Windows DC, a similar issue to CVE-2015-2535.

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3mw7-6cqh-vgc6

Heap-based buffer overflow in Unitronics VisiLogic OPLC IDE before 9.8.09 allows remote attackers to execute arbitrary code via a long vlp filename.

CVSS3: 9.6
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу