Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 288 225

Количество 288 225

github логотип

GHSA-22c8-wr9r-qr3j

около 3 лет назад

Heap-based buffer overflow in the utf16_to_isolatin1 function in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allows remote attackers to execute arbitrary code via vectors that trigger a character-set conversion failure.

EPSS: Низкий
github логотип

GHSA-22c8-79jr-rvwg

10 месяцев назад

D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command injection vulnerabilities via the ExternalPort, InternalPort, ProtocolNumber, and LocalIPAddress parameters in the SetVirtualServerSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-22c7-f2c3-8h35

около 3 лет назад

A lack of CORS checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak limited cross-origin data via a crafted HTML page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-22c7-cppf-fmqm

больше 3 лет назад

Internet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when opening it, which allows remote attackers to cause a denial of service (crash) by triggering a heap-based buffer overflow using invalid length codes during decompression, aka "Malformed PNG Image File Failure."

EPSS: Средний
github логотип

GHSA-22c7-32gx-23fj

около 3 лет назад

Linear eMerge E3-Series devices have Cleartext Credentials in a Database.

EPSS: Низкий
github логотип

GHSA-22c6-pmf5-543m

около 3 лет назад

CRLF injection vulnerability in Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a MIME header.

EPSS: Низкий
github логотип

GHSA-22c6-jwp4-wc87

около 3 лет назад

Integer overflow in modules/MSADPCM.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-22c6-3h88-26m3

около 3 лет назад

Ignite Realtime Openfire allows Cross-site Scripting

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-22c5-cpvr-cfvq

8 месяцев назад

Withdrawn Advisory: undertow: information leakage via HTTP/2 request header reuse

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-22c4-4rv3-jj9h

больше 3 лет назад

Stack-based buffer overflow in the demux_nsf_send_chunk function in src/demuxers/demux_nsf.c in xine-lib 1.1.12 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long NSF title.

EPSS: Низкий
github логотип

GHSA-22c3-whjv-hrfm

почти 2 года назад

Jenkins Folders Plugin cross-site request forgery vulnerability

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-22c3-jmcx-576g

больше 3 лет назад

SQL injection vulnerability in login.asp for Cool Cafe (Cool Café) Chat 1.2.1 allows remote attackers to execute arbitrary SQL commands via the password.

EPSS: Низкий
github логотип

GHSA-22c2-9gwg-mj59

3 месяца назад

Langroid has a Code Injection vulnerability in LanceDocChatAgent through vector_store

EPSS: Низкий
github логотип

GHSA-229x-cgvj-5q56

около 3 лет назад

Cross-site scripting (XSS) vulnerability in apps/user_webdavauth/settings.php in ownCloud 4.5.x before 4.5.2 allows remote attackers to inject arbitrary web script or HTML via arbitrary POST parameters.

EPSS: Низкий
github логотип

GHSA-229x-53vm-m4f4

около 3 лет назад

kernel drivers before version 4.17-rc1 are vulnerable to a weakness in the Linux kernel's implementation of random seed data. Programs, early in the boot sequence, could use the data allocated for the seed before it was sufficiently generated.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-229x-22xc-2f2w

около 1 года назад

Zendframework Local file disclosure via XXE injection in Zend_XmlRpc

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-229w-w68g-gcf2

больше 3 лет назад

HP eSupportDiagnostics ActiveX control (hpediag.dll) 1.0.11.0 exports dangerous methods, which allows remote attackers to (1) read arbitrary files via the ReadTextFile method, or (2) read arbitrary registry values via the ReadValue method.

EPSS: Низкий
github логотип

GHSA-229w-c447-wm6p

больше 3 лет назад

The faxrunq and faxrunqd in the mgetty package allows local users to create or modify arbitrary files via a symlink attack which creates a symlink in from /var/spool/fax/outgoing/.last_run to the target file.

EPSS: Низкий
github логотип

GHSA-229w-7xcx-5jhf

около 3 лет назад

The Magic Balloonman Marty Boone (aka com.app_martyboone.layout) application 1.400 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-229v-p5vr-f583

около 3 лет назад

Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100 version 9.0.0.3 and earlier.

CVSS3: 7.5
EPSS: Критический

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-22c8-wr9r-qr3j

Heap-based buffer overflow in the utf16_to_isolatin1 function in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allows remote attackers to execute arbitrary code via vectors that trigger a character-set conversion failure.

6%
Низкий
около 3 лет назад
github логотип
GHSA-22c8-79jr-rvwg

D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command injection vulnerabilities via the ExternalPort, InternalPort, ProtocolNumber, and LocalIPAddress parameters in the SetVirtualServerSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.

CVSS3: 8
1%
Низкий
10 месяцев назад
github логотип
GHSA-22c7-f2c3-8h35

A lack of CORS checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak limited cross-origin data via a crafted HTML page.

CVSS3: 6.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-22c7-cppf-fmqm

Internet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when opening it, which allows remote attackers to cause a denial of service (crash) by triggering a heap-based buffer overflow using invalid length codes during decompression, aka "Malformed PNG Image File Failure."

29%
Средний
больше 3 лет назад
github логотип
GHSA-22c7-32gx-23fj

Linear eMerge E3-Series devices have Cleartext Credentials in a Database.

0%
Низкий
около 3 лет назад
github логотип
GHSA-22c6-pmf5-543m

CRLF injection vulnerability in Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a MIME header.

0%
Низкий
около 3 лет назад
github логотип
GHSA-22c6-jwp4-wc87

Integer overflow in modules/MSADPCM.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file.

CVSS3: 5.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-22c6-3h88-26m3

Ignite Realtime Openfire allows Cross-site Scripting

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-22c5-cpvr-cfvq

Withdrawn Advisory: undertow: information leakage via HTTP/2 request header reuse

CVSS3: 7.5
8 месяцев назад
github логотип
GHSA-22c4-4rv3-jj9h

Stack-based buffer overflow in the demux_nsf_send_chunk function in src/demuxers/demux_nsf.c in xine-lib 1.1.12 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long NSF title.

6%
Низкий
больше 3 лет назад
github логотип
GHSA-22c3-whjv-hrfm

Jenkins Folders Plugin cross-site request forgery vulnerability

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-22c3-jmcx-576g

SQL injection vulnerability in login.asp for Cool Cafe (Cool Café) Chat 1.2.1 allows remote attackers to execute arbitrary SQL commands via the password.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-22c2-9gwg-mj59

Langroid has a Code Injection vulnerability in LanceDocChatAgent through vector_store

0%
Низкий
3 месяца назад
github логотип
GHSA-229x-cgvj-5q56

Cross-site scripting (XSS) vulnerability in apps/user_webdavauth/settings.php in ownCloud 4.5.x before 4.5.2 allows remote attackers to inject arbitrary web script or HTML via arbitrary POST parameters.

0%
Низкий
около 3 лет назад
github логотип
GHSA-229x-53vm-m4f4

kernel drivers before version 4.17-rc1 are vulnerable to a weakness in the Linux kernel's implementation of random seed data. Programs, early in the boot sequence, could use the data allocated for the seed before it was sufficiently generated.

CVSS3: 5.9
0%
Низкий
около 3 лет назад
github логотип
GHSA-229x-22xc-2f2w

Zendframework Local file disclosure via XXE injection in Zend_XmlRpc

CVSS3: 8.6
около 1 года назад
github логотип
GHSA-229w-w68g-gcf2

HP eSupportDiagnostics ActiveX control (hpediag.dll) 1.0.11.0 exports dangerous methods, which allows remote attackers to (1) read arbitrary files via the ReadTextFile method, or (2) read arbitrary registry values via the ReadValue method.

9%
Низкий
больше 3 лет назад
github логотип
GHSA-229w-c447-wm6p

The faxrunq and faxrunqd in the mgetty package allows local users to create or modify arbitrary files via a symlink attack which creates a symlink in from /var/spool/fax/outgoing/.last_run to the target file.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-229w-7xcx-5jhf

The Magic Balloonman Marty Boone (aka com.app_martyboone.layout) application 1.400 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
около 3 лет назад
github логотип
GHSA-229v-p5vr-f583

Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100 version 9.0.0.3 and earlier.

CVSS3: 7.5
94%
Критический
около 3 лет назад

Уязвимостей на страницу