Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3mpv-g3cv-rx7h

больше 3 лет назад

Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a security bypass vulnerability. Successful exploitation could lead to arbitrary folder creation.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3mpv-3cfr-mgjj

больше 3 лет назад

With MariaDB running on Windows, when local clients connect to the server over named pipes, it's possible for an unprivileged user with an ability to run code on the server machine to intercept the named pipe connection and act as a man-in-the-middle, gaining access to all the data passed between the client and the server, and getting the ability to run SQL commands on behalf of the connected user. This occurs because of an incorrect security descriptor. This affects MariaDB Server before 10.1.48, 10.2.x before 10.2.35, 10.3.x before 10.3.26, 10.4.x before 10.4.16, and 10.5.x before 10.5.7. NOTE: this issue exists because certain details of the MariaDB CVE-2019-2503 fix did not comprehensively address attack variants against MariaDB. This situation is specific to MariaDB, and thus CVE-2020-28912 does NOT apply to other vendors that were originally affected by CVE-2019-2503.

EPSS: Низкий
github логотип

GHSA-3mpr-vw5v-hq89

больше 3 лет назад

In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3mpr-qj98-wfp9

больше 3 лет назад

The UberMedia UberSocial (com.twidroid) application 7.x before 7.2.4 for Android does not properly protect data, which allows remote attackers to read or modify Twitter information via a crafted application.

EPSS: Низкий
github логотип

GHSA-3mpr-hq3p-49h9

больше 7 лет назад

Prototype Pollution in mixin-deep

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3mpr-9r86-mfv2

почти 2 года назад

Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the pwd parameter at /aprocess.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3mpq-x397-f3cg

почти 4 года назад

FreeBit ServersMan 3.1.5 on Apple iPhone OS 3.1.2, and iPhone OS for iPod touch, allows remote attackers to cause a denial of service (daemon crash) via a HEAD request for the / URI.

EPSS: Низкий
github логотип

GHSA-3mpq-f59x-83gx

почти 4 года назад

Array index error in gd_gif_in.c in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash and heap corruption) via large color index values in crafted image data, which results in a segmentation fault.

EPSS: Низкий
github логотип

GHSA-3mpq-55rm-gc7g

почти 4 года назад

SQL injection vulnerability in post.php for MercuryBoard 1.1.1 allows remote attackers to execute arbitrary SQL commands via a reply post action for index.php with (1) the t parameter or (2) the qu parameter.

EPSS: Низкий
github логотип

GHSA-3mpp-xhfx-rv7h

почти 3 года назад

Adobe Substance 3D Stager version 2.0.1 (and earlier) is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3mpp-xh9p-vf59

почти 4 года назад

Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via a long user name.

EPSS: Средний
github логотип

GHSA-3mpp-xfvh-qh37

почти 4 года назад

node-ipc behavior change

EPSS: Низкий
github логотип

GHSA-3mpm-jx38-9m8w

5 месяцев назад

sassdoc-extras vulnerable to prototype pollution

EPSS: Низкий
github логотип

GHSA-3mpm-5q2w-wr7w

больше 2 лет назад

HCL Commerce Remote Store server could allow a remote attacker, using a specially-crafted URL, to read arbitrary files on the system.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-3mpj-wgvw-fw9v

около 2 лет назад

SQL Injection vulnerability in HiPresta "Gift Wrapping Pro" (hiadvancedgiftwrapping) module for PrestaShop before version 1.4.1, allows remote attackers to escalate privileges and obtain sensitive information via the HiAdvancedGiftWrappingGiftWrappingModuleFrontController::addGiftWrappingCartValue() method.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3mpj-h64q-x7gf

больше 3 лет назад

In CODESYS EtherNetIP before 4.1.0.0, specific EtherNet/IP requests may cause a null pointer dereference in the downloaded vulnerable EtherNet/IP stack that is executed by the CODESYS Control runtime system.

EPSS: Низкий
github логотип

GHSA-3mpj-g9cw-f3hj

больше 3 лет назад

A null pointer dereference issue was discovered in fs/io_uring.c in the Linux kernel before 5.15.62. A local user could use this flaw to crash the system or potentially cause a denial of service.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3mpj-92q9-pvw2

почти 4 года назад

Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used.

EPSS: Низкий
github логотип

GHSA-3mpj-8j86-c69j

больше 3 лет назад

The Google Email application 4.2.2.0200 for Android allows remote attackers to cause a denial of service (persistent application crash) via a "Content-Disposition: ;" header in an e-mail message.

EPSS: Низкий
github логотип

GHSA-3mph-xfrg-5928

4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: block: Fix the maximum minor value is blk_alloc_ext_minor() ida_alloc_range(..., min, max, ...) returns values from min to max, inclusive. So, NR_EXT_DEVT is a valid idx returned by blk_alloc_ext_minor(). This is an issue because in device_add_disk(), this value is used in: ddev->devt = MKDEV(disk->major, disk->first_minor); and NR_EXT_DEVT is '(1 << MINORBITS)'. So, should 'disk->first_minor' be NR_EXT_DEVT, it would overflow.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3mpv-g3cv-rx7h

Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a security bypass vulnerability. Successful exploitation could lead to arbitrary folder creation.

CVSS3: 5.3
5%
Низкий
больше 3 лет назад
github логотип
GHSA-3mpv-3cfr-mgjj

With MariaDB running on Windows, when local clients connect to the server over named pipes, it's possible for an unprivileged user with an ability to run code on the server machine to intercept the named pipe connection and act as a man-in-the-middle, gaining access to all the data passed between the client and the server, and getting the ability to run SQL commands on behalf of the connected user. This occurs because of an incorrect security descriptor. This affects MariaDB Server before 10.1.48, 10.2.x before 10.2.35, 10.3.x before 10.3.26, 10.4.x before 10.4.16, and 10.5.x before 10.5.7. NOTE: this issue exists because certain details of the MariaDB CVE-2019-2503 fix did not comprehensively address attack variants against MariaDB. This situation is specific to MariaDB, and thus CVE-2020-28912 does NOT apply to other vendors that were originally affected by CVE-2019-2503.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mpr-vw5v-hq89

In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mpr-qj98-wfp9

The UberMedia UberSocial (com.twidroid) application 7.x before 7.2.4 for Android does not properly protect data, which allows remote attackers to read or modify Twitter information via a crafted application.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mpr-hq3p-49h9

Prototype Pollution in mixin-deep

CVSS3: 8.8
1%
Низкий
больше 7 лет назад
github логотип
GHSA-3mpr-9r86-mfv2

Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the pwd parameter at /aprocess.php.

CVSS3: 9.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-3mpq-x397-f3cg

FreeBit ServersMan 3.1.5 on Apple iPhone OS 3.1.2, and iPhone OS for iPod touch, allows remote attackers to cause a denial of service (daemon crash) via a HEAD request for the / URI.

5%
Низкий
почти 4 года назад
github логотип
GHSA-3mpq-f59x-83gx

Array index error in gd_gif_in.c in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash and heap corruption) via large color index values in crafted image data, which results in a segmentation fault.

5%
Низкий
почти 4 года назад
github логотип
GHSA-3mpq-55rm-gc7g

SQL injection vulnerability in post.php for MercuryBoard 1.1.1 allows remote attackers to execute arbitrary SQL commands via a reply post action for index.php with (1) the t parameter or (2) the qu parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3mpp-xhfx-rv7h

Adobe Substance 3D Stager version 2.0.1 (and earlier) is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-3mpp-xh9p-vf59

Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via a long user name.

18%
Средний
почти 4 года назад
github логотип
GHSA-3mpp-xfvh-qh37

node-ipc behavior change

почти 4 года назад
github логотип
GHSA-3mpm-jx38-9m8w

sassdoc-extras vulnerable to prototype pollution

0%
Низкий
5 месяцев назад
github логотип
GHSA-3mpm-5q2w-wr7w

HCL Commerce Remote Store server could allow a remote attacker, using a specially-crafted URL, to read arbitrary files on the system.

CVSS3: 5.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3mpj-wgvw-fw9v

SQL Injection vulnerability in HiPresta "Gift Wrapping Pro" (hiadvancedgiftwrapping) module for PrestaShop before version 1.4.1, allows remote attackers to escalate privileges and obtain sensitive information via the HiAdvancedGiftWrappingGiftWrappingModuleFrontController::addGiftWrappingCartValue() method.

CVSS3: 9.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-3mpj-h64q-x7gf

In CODESYS EtherNetIP before 4.1.0.0, specific EtherNet/IP requests may cause a null pointer dereference in the downloaded vulnerable EtherNet/IP stack that is executed by the CODESYS Control runtime system.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mpj-g9cw-f3hj

A null pointer dereference issue was discovered in fs/io_uring.c in the Linux kernel before 5.15.62. A local user could use this flaw to crash the system or potentially cause a denial of service.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mpj-92q9-pvw2

Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3mpj-8j86-c69j

The Google Email application 4.2.2.0200 for Android allows remote attackers to cause a denial of service (persistent application crash) via a "Content-Disposition: ;" header in an e-mail message.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-3mph-xfrg-5928

In the Linux kernel, the following vulnerability has been resolved: block: Fix the maximum minor value is blk_alloc_ext_minor() ida_alloc_range(..., min, max, ...) returns values from min to max, inclusive. So, NR_EXT_DEVT is a valid idx returned by blk_alloc_ext_minor(). This is an issue because in device_add_disk(), this value is used in: ddev->devt = MKDEV(disk->major, disk->first_minor); and NR_EXT_DEVT is '(1 << MINORBITS)'. So, should 'disk->first_minor' be NR_EXT_DEVT, it would overflow.

CVSS3: 5.5
0%
Низкий
4 месяца назад

Уязвимостей на страницу