Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 288 225

Количество 288 225

github логотип

GHSA-2234-4vjh-rwjg

больше 3 лет назад

Stack-based buffer overflow in Maxthon Browser 2.0 and earlier allows remote attackers to execute arbitrary code via a long Content-type HTTP header.

EPSS: Низкий
github логотип

GHSA-2233-xwf8-rr7q

около 3 лет назад

Insufficient input validation in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 potentially enables a privileged user to execute arbitrary code via local access via local access.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-2233-6ppj-hjvq

около 3 лет назад

A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-2233-5gm5-6q44

около 3 лет назад

Koozali Foundation SME Server versions 8.x, 9.x, 10.x are vulnerable to an open URL redirect vulnerability in the user web login function resulting in unauthorized account access.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2232-3wg2-9j36

около 3 лет назад

The fill_input_buffer function in jdatasrc.c in libjpeg-turbo 1.5.1 allows remote attackers to cause a denial of service (invalid memory access and application crash) or possibly have unspecified other impact via a crafted jpg file.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-222x-xv7v-2jfv

больше 3 лет назад

Directory traversal vulnerability in FtpXQ FTP server 2.0.93 allows remote attackers to read arbitrary files via a .. (dot dot) in the GET command.

EPSS: Низкий
github логотип

GHSA-222x-w66m-px4x

8 месяцев назад

This vulnerability exists in the TP-Link Archer C50 due to improper signature verification mechanism in the firmware upgrade process at its web interface. An attacker with administrative privileges within the router’s Wi-Fi range could exploit this vulnerability by uploading and executing malicious firmware which could lead to complete compromise of the targeted device.

EPSS: Низкий
github логотип

GHSA-222x-r452-4688

больше 1 года назад

Vulnerability of permission verification in some APIs in the ActivityTaskManagerService module. Impact: Successful exploitation of this vulnerability will affect availability.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-222x-q267-pmwg

7 месяцев назад

The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_protocol_configuration_options function at /3gpp/3gpp_24.008_sm_ies.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-222x-p874-5j5q

больше 3 лет назад

Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\employee_delete.php.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-222x-4qhm-7h5f

больше 2 лет назад

There is a use-after-free vulnerability in the Linux Kernel which can be exploited to achieve local privilege escalation. To reach the vulnerability kernel configuration flag CONFIG_TLS or CONFIG_XFRM_ESPINTCP has to be configured, but the operation does not require any privilege. There is a use-after-free bug of icsk_ulp_data of a struct inet_connection_sock. When CONFIG_TLS is enabled, user can install a tls context (struct tls_context) on a connected tcp socket. The context is not cleared if this socket is disconnected and reused as a listener. If a new socket is created from the listener, the context is inherited and vulnerable. The setsockopt TCP_ULP operation does not require any privilege. We recommend upgrading past commit 2c02d41d71f90a5168391b6a5f2954112ba2307c

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-222w-39qf-5f2w

около 3 лет назад

The s3bubble-amazon-s3-html-5-video-with-adverts plugin 0.7 for WordPress has directory traversal via the adverts/assets/plugins/ultimate/content/downloader.php path parameter.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-222v-cx2c-q2f5

7 месяцев назад

phpMyAdmin XSS when checking tables

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-222r-jmhg-vqvf

3 месяца назад

Cross-Site Request Forgery (CSRF) vulnerability in bundgaard Martins Free Monetized Ad Exchange Network allows Reflected XSS. This issue affects Martins Free Monetized Ad Exchange Network: from n/a through 1.0.5.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-222r-h4fw-7xv3

около 3 лет назад

Vulnerability in the Oracle Financial Services Asset Liability Management component of Oracle Financial Services Applications (subcomponent: User Interface). Supported versions that are affected are 6.1.x and 8.0.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Asset Liability Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Asset Liability Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Financial Services Asset Liability Management accessible data. CVSS 3.0 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-222r-5h2g-hwf2

около 3 лет назад

SGIN.CN xiangyun platform V9.4.10 has XSS via the login_url parameter to /login.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-222r-4v3h-874c

больше 3 лет назад

Buffer overflow in the SHTML logging functionality of iPlanet Web Server 4.x allows remote attackers to execute arbitrary commands via a long filename with a .shtml extension.

EPSS: Низкий
github логотип

GHSA-222q-2853-6fvc

больше 3 лет назад

DeluxeBB 1.07 and earlier does not properly handle a username composed of a single space character, which allows remote authenticated users to login as the "space" user, post as the guest user, and block the ability of an administrator to ban the "space" user.

EPSS: Низкий
github логотип

GHSA-222p-ppph-c5v8

около 3 лет назад

A Missing Authentication in Critical Function in Bosch IP cameras allows an unauthenticated remote attacker to extract sensitive information or change settings of the camera by sending crafted requests to the device. Only devices of the CPP6, CPP7 and CPP7.3 family with firmware 7.70, 7.72, and 7.80 prior to B128 are affected by this vulnerability. Versions 7.62 or lower and INTEOX cameras are not affected.

EPSS: Низкий
github логотип

GHSA-222p-485j-75xg

около 3 лет назад

ZTE ZXV10 B860AV2.1 product ChinaMobile branch with the ICNT versions up to V1.3.3, the BESTV versions up to V1.2.2, the WASU versions up to V1.1.7 and the MGTV versions up to V1.4.6 have an authentication bypass vulnerability, which may allows an unauthorized user to perform unauthorized operations.

CVSS3: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2234-4vjh-rwjg

Stack-based buffer overflow in Maxthon Browser 2.0 and earlier allows remote attackers to execute arbitrary code via a long Content-type HTTP header.

5%
Низкий
больше 3 лет назад
github логотип
GHSA-2233-xwf8-rr7q

Insufficient input validation in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 potentially enables a privileged user to execute arbitrary code via local access via local access.

CVSS3: 8.2
0%
Низкий
около 3 лет назад
github логотип
GHSA-2233-6ppj-hjvq

A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5.

CVSS3: 8.6
0%
Низкий
около 3 лет назад
github логотип
GHSA-2233-5gm5-6q44

Koozali Foundation SME Server versions 8.x, 9.x, 10.x are vulnerable to an open URL redirect vulnerability in the user web login function resulting in unauthorized account access.

CVSS3: 6.1
2%
Низкий
около 3 лет назад
github логотип
GHSA-2232-3wg2-9j36

The fill_input_buffer function in jdatasrc.c in libjpeg-turbo 1.5.1 allows remote attackers to cause a denial of service (invalid memory access and application crash) or possibly have unspecified other impact via a crafted jpg file.

CVSS3: 8.8
5%
Низкий
около 3 лет назад
github логотип
GHSA-222x-xv7v-2jfv

Directory traversal vulnerability in FtpXQ FTP server 2.0.93 allows remote attackers to read arbitrary files via a .. (dot dot) in the GET command.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-222x-w66m-px4x

This vulnerability exists in the TP-Link Archer C50 due to improper signature verification mechanism in the firmware upgrade process at its web interface. An attacker with administrative privileges within the router’s Wi-Fi range could exploit this vulnerability by uploading and executing malicious firmware which could lead to complete compromise of the targeted device.

0%
Низкий
8 месяцев назад
github логотип
GHSA-222x-r452-4688

Vulnerability of permission verification in some APIs in the ActivityTaskManagerService module. Impact: Successful exploitation of this vulnerability will affect availability.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-222x-q267-pmwg

The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_protocol_configuration_options function at /3gpp/3gpp_24.008_sm_ies.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.

CVSS3: 7.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-222x-p874-5j5q

Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\employee_delete.php.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-222x-4qhm-7h5f

There is a use-after-free vulnerability in the Linux Kernel which can be exploited to achieve local privilege escalation. To reach the vulnerability kernel configuration flag CONFIG_TLS or CONFIG_XFRM_ESPINTCP has to be configured, but the operation does not require any privilege. There is a use-after-free bug of icsk_ulp_data of a struct inet_connection_sock. When CONFIG_TLS is enabled, user can install a tls context (struct tls_context) on a connected tcp socket. The context is not cleared if this socket is disconnected and reused as a listener. If a new socket is created from the listener, the context is inherited and vulnerable. The setsockopt TCP_ULP operation does not require any privilege. We recommend upgrading past commit 2c02d41d71f90a5168391b6a5f2954112ba2307c

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-222w-39qf-5f2w

The s3bubble-amazon-s3-html-5-video-with-adverts plugin 0.7 for WordPress has directory traversal via the adverts/assets/plugins/ultimate/content/downloader.php path parameter.

CVSS3: 7.5
6%
Низкий
около 3 лет назад
github логотип
GHSA-222v-cx2c-q2f5

phpMyAdmin XSS when checking tables

CVSS3: 6.4
0%
Низкий
7 месяцев назад
github логотип
GHSA-222r-jmhg-vqvf

Cross-Site Request Forgery (CSRF) vulnerability in bundgaard Martins Free Monetized Ad Exchange Network allows Reflected XSS. This issue affects Martins Free Monetized Ad Exchange Network: from n/a through 1.0.5.

CVSS3: 7.1
0%
Низкий
3 месяца назад
github логотип
GHSA-222r-h4fw-7xv3

Vulnerability in the Oracle Financial Services Asset Liability Management component of Oracle Financial Services Applications (subcomponent: User Interface). Supported versions that are affected are 6.1.x and 8.0.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Asset Liability Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Asset Liability Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Financial Services Asset Liability Management accessible data. CVSS 3.0 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

CVSS3: 8.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-222r-5h2g-hwf2

SGIN.CN xiangyun platform V9.4.10 has XSS via the login_url parameter to /login.php.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-222r-4v3h-874c

Buffer overflow in the SHTML logging functionality of iPlanet Web Server 4.x allows remote attackers to execute arbitrary commands via a long filename with a .shtml extension.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-222q-2853-6fvc

DeluxeBB 1.07 and earlier does not properly handle a username composed of a single space character, which allows remote authenticated users to login as the "space" user, post as the guest user, and block the ability of an administrator to ban the "space" user.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-222p-ppph-c5v8

A Missing Authentication in Critical Function in Bosch IP cameras allows an unauthenticated remote attacker to extract sensitive information or change settings of the camera by sending crafted requests to the device. Only devices of the CPP6, CPP7 and CPP7.3 family with firmware 7.70, 7.72, and 7.80 prior to B128 are affected by this vulnerability. Versions 7.62 or lower and INTEOX cameras are not affected.

0%
Низкий
около 3 лет назад
github логотип
GHSA-222p-485j-75xg

ZTE ZXV10 B860AV2.1 product ChinaMobile branch with the ICNT versions up to V1.3.3, the BESTV versions up to V1.2.2, the WASU versions up to V1.1.7 and the MGTV versions up to V1.4.6 have an authentication bypass vulnerability, which may allows an unauthorized user to perform unauthorized operations.

CVSS3: 6.8
0%
Низкий
около 3 лет назад

Уязвимостей на страницу