Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3mgm-63xg-j4r3

больше 3 лет назад

An error within the "nikon_coolscan_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause an out-of-bounds read memory access and subsequently cause a crash.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3mgm-628r-4cx7

почти 2 года назад

Cross-Site Request Forgery (CSRF) vulnerability in СleanTalk - Anti-Spam Protection Spam protection, Anti-Spam, FireWall by CleanTalk.This issue affects Spam protection, Anti-Spam, FireWall by CleanTalk: from n/a through 6.20.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3mgj-ppp2-8gvj

7 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: remove WARN on bad firmware input If the firmware gives bad input, that's nothing to do with the driver's stack at this point etc., so the WARN_ON() doesn't add any value. Additionally, this is one of the top syzbot reports now. Just print a message, and as an added bonus, print the sizes too.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3mgj-7ppj-9qfc

больше 3 лет назад

This issue was addressed with improved checks. This issue is fixed in watchOS 6.3, iOS 12.5, iOS 14.3 and iPadOS 14.3, watchOS 7.2. Unauthorized code execution may lead to an authentication policy violation.

EPSS: Низкий
github логотип

GHSA-3mgj-3vhp-rjgq

почти 4 года назад

StatCounteX 3.0 and 3.1 allows remote attackers to obtain sensitive information and edit configuration scripts via a direct request to admin.asp.

EPSS: Низкий
github логотип

GHSA-3mgj-2f83-wr3q

больше 3 лет назад

Battelle V2I Hub 2.5.1 could allow a remote attacker to bypass security restrictions, caused by the direct checking of the API key against a user-supplied value in PHP's GET global variable array using PHP's strcmp() function. By adding "[]" to the end of "key" in the URL when accessing API functions, an attacker could exploit this vulnerability to execute API functions.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3mgj-25w6-9vm6

около 4 лет назад

Unquoted service path vulnerability in the Gallagher Controller Service allows an unprivileged user to execute arbitrary code as the account that runs the Controller Service. This issue affects: Gallagher Command Centre 8.50 versions prior to 8.50.2048 (MR3) ;

EPSS: Низкий
github логотип

GHSA-3mgh-2cwf-8r9v

больше 3 лет назад

An information disclosure vulnerability in the Android system (rild). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37896655.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3mgg-hwvm-97qx

больше 3 лет назад

NetApp Clustered Data ONTAP 8.3.x before 8.3.2P12 allows remote authenticated users to execute arbitrary code on the storage controller via unspecified vectors.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3mgg-3hqg-jjq6

около 1 года назад

IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 could allow a privileged user to obtain highly sensitive user credentials from secret keys that are stored in clear text.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-3mgg-22gr-vqxv

больше 3 лет назад

Unspecified vulnerability in Twilight Frontier Touhou Hisouten 1.06 and earlier allows remote attackers to cause a denial of service (daemon crash) via unknown network traffic.

EPSS: Низкий
github логотип

GHSA-3mgf-v89w-rwvm

больше 3 лет назад

A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Create a new Design" parameter under the "Designs" module.

EPSS: Низкий
github логотип

GHSA-3mgf-mj76-7964

около 3 лет назад

Heap buffer overflow in Platform Apps in Google Chrome on Chrome OS prior to 109.0.5414.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3mgc-2x4f-gfqh

больше 3 лет назад

Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3mg9-wjxc-5593

больше 3 лет назад

MOStlyCE before 2.4, as used in Mambo 4.6.3 and earlier, allows remote attackers to obtain sensitive information via certain requests to mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php, which reveals the installation path in an error message.

EPSS: Низкий
github логотип

GHSA-3mg9-m3f6-v7fq

больше 3 лет назад

Proxy component of Apache Pulsar subject to abuse as Denial of Service endpoint

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3mg9-cvj8-qmx7

больше 3 лет назад

An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server. While processing the ssid parameter for a POST request, the value is directly used in a sprintf call to a local variable placed on the stack, which overrides the return address of the function, causing a buffer overflow.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3mg8-mw7w-wg96

больше 3 лет назад

389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to obtain user passwords.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3mg8-g497-8859

почти 2 года назад

A vulnerability has been found in iboss Secure Web Gateway up to 10.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /login of the component Login Portal. The manipulation of the argument redirectUrl leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 10.2.0.160 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-259501 was assigned to this vulnerability.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3mg8-59xx-v9rc

больше 3 лет назад

A null pointer dereference vulnerability in Fortinet FortiClientWindows 6.0.2 and earlier allows attacker to cause a denial of service via the NDIS miniport driver.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3mgm-63xg-j4r3

An error within the "nikon_coolscan_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause an out-of-bounds read memory access and subsequently cause a crash.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3mgm-628r-4cx7

Cross-Site Request Forgery (CSRF) vulnerability in СleanTalk - Anti-Spam Protection Spam protection, Anti-Spam, FireWall by CleanTalk.This issue affects Spam protection, Anti-Spam, FireWall by CleanTalk: from n/a through 6.20.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-3mgj-ppp2-8gvj

In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: remove WARN on bad firmware input If the firmware gives bad input, that's nothing to do with the driver's stack at this point etc., so the WARN_ON() doesn't add any value. Additionally, this is one of the top syzbot reports now. Just print a message, and as an added bonus, print the sizes too.

CVSS3: 5.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-3mgj-7ppj-9qfc

This issue was addressed with improved checks. This issue is fixed in watchOS 6.3, iOS 12.5, iOS 14.3 and iPadOS 14.3, watchOS 7.2. Unauthorized code execution may lead to an authentication policy violation.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mgj-3vhp-rjgq

StatCounteX 3.0 and 3.1 allows remote attackers to obtain sensitive information and edit configuration scripts via a direct request to admin.asp.

8%
Низкий
почти 4 года назад
github логотип
GHSA-3mgj-2f83-wr3q

Battelle V2I Hub 2.5.1 could allow a remote attacker to bypass security restrictions, caused by the direct checking of the API key against a user-supplied value in PHP's GET global variable array using PHP's strcmp() function. By adding "[]" to the end of "key" in the URL when accessing API functions, an attacker could exploit this vulnerability to execute API functions.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mgj-25w6-9vm6

Unquoted service path vulnerability in the Gallagher Controller Service allows an unprivileged user to execute arbitrary code as the account that runs the Controller Service. This issue affects: Gallagher Command Centre 8.50 versions prior to 8.50.2048 (MR3) ;

0%
Низкий
около 4 лет назад
github логотип
GHSA-3mgh-2cwf-8r9v

An information disclosure vulnerability in the Android system (rild). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37896655.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mgg-hwvm-97qx

NetApp Clustered Data ONTAP 8.3.x before 8.3.2P12 allows remote authenticated users to execute arbitrary code on the storage controller via unspecified vectors.

CVSS3: 8.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3mgg-3hqg-jjq6

IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 could allow a privileged user to obtain highly sensitive user credentials from secret keys that are stored in clear text.

CVSS3: 4.4
0%
Низкий
около 1 года назад
github логотип
GHSA-3mgg-22gr-vqxv

Unspecified vulnerability in Twilight Frontier Touhou Hisouten 1.06 and earlier allows remote attackers to cause a denial of service (daemon crash) via unknown network traffic.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3mgf-v89w-rwvm

A stored cross scripting (XSS) vulnerability in CMS Made Simple 2.2.14 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Create a new Design" parameter under the "Designs" module.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mgf-mj76-7964

Heap buffer overflow in Platform Apps in Google Chrome on Chrome OS prior to 109.0.5414.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 8.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-3mgc-2x4f-gfqh

Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

CVSS3: 8.8
4%
Низкий
больше 3 лет назад
github логотип
GHSA-3mg9-wjxc-5593

MOStlyCE before 2.4, as used in Mambo 4.6.3 and earlier, allows remote attackers to obtain sensitive information via certain requests to mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php, which reveals the installation path in an error message.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3mg9-m3f6-v7fq

Proxy component of Apache Pulsar subject to abuse as Denial of Service endpoint

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mg9-cvj8-qmx7

An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server. While processing the ssid parameter for a POST request, the value is directly used in a sprintf call to a local variable placed on the stack, which overrides the return address of the function, causing a buffer overflow.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3mg8-mw7w-wg96

389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to obtain user passwords.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3mg8-g497-8859

A vulnerability has been found in iboss Secure Web Gateway up to 10.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /login of the component Login Portal. The manipulation of the argument redirectUrl leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 10.2.0.160 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-259501 was assigned to this vulnerability.

CVSS3: 4.3
5%
Низкий
почти 2 года назад
github логотип
GHSA-3mg8-59xx-v9rc

A null pointer dereference vulnerability in Fortinet FortiClientWindows 6.0.2 and earlier allows attacker to cause a denial of service via the NDIS miniport driver.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу