Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 288 896

Количество 288 896

github логотип

GHSA-22h9-2mpf-7588

больше 2 лет назад

An issue found in POWERAMP audioplayer build 925 bundle play and build 954 allows a remote attacker to gain privileges via the reverb and EQ preset parameters.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-22h8-jh78-8mgh

больше 3 лет назад

A vulnerability has been identified in JT2Go (All versions < V13.2.0.5), Teamcenter Visualization (All versions < V13.2.0.5). The DL180pdfl.dll contains an out of bounds write past the end of an allocated structure while parsing specially crafted JT files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-15103)

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-22h8-5mmq-pgx3

около 3 лет назад

Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-22h7-7wwg-qmgg

почти 5 лет назад

Prototype Pollution in @hapi/hoek

EPSS: Низкий
github логотип

GHSA-22h6-v894-7cgq

больше 3 лет назад

Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.4, 12.1.0, 12.3.0 and 12.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle FLEXCUBE Investor Servicing accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle FLEXCUBE Investor Servicing. CVSS 3.0 Base Score 5.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L).

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-22h6-79rc-rj5g

около 3 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies SynaMan before 3.5 Build 1451, Syncrify before 3.7 Build 856, and SynTail before 1.5 Build 567

EPSS: Низкий
github логотип

GHSA-22h5-pq3x-2gf2

5 месяцев назад

URI allows for userinfo Leakage in URI#join, URI#merge, and URI#+

CVSS3: 3.2
EPSS: Низкий
github логотип

GHSA-22gx-8v7p-9g9p

около 3 лет назад

A memory corruption vulnerability exists in the PNG png_palette_process functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to a heap buffer overflow. An attacker can provide malicious inputs to trigger this vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-22gx-4xv7-xwjg

3 месяца назад

FiveCo RAP dissector infinite loop in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-22gv-43vq-fhjw

6 месяцев назад

Due to missing authorization check in an RFC enabled function module in transaction SDCCN, an unauthenticated attacker could generate technical meta-data. This leads to a low impact on integrity. There is no impact on confidentiality or availability.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-22gr-gpph-j2c5

около 3 лет назад

An information disclosure vulnerability exists in the ACEManager authentication functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The ACEManager authentication functionality is done in plaintext XML to the web server. An attacker can listen to network traffic upstream from the device to capitalize on this vulnerability.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-22gq-x6pg-752j

почти 7 лет назад

openssl.js is malware

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-22gp-w9xj-6wwq

7 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alexander Weleczka FontAwesome.io ShortCodes allows Stored XSS.This issue affects FontAwesome.io ShortCodes: from n/a through 1.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-22gp-8432-2xp8

около 3 лет назад

The Parallel Mafia MMORPG (aka com.perblue.pm.client) application @7F070000 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-22gp-7w9x-c2xx

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: drm/ast: Fix soft lockup There is a while-loop in ast_dp_set_on_off() that could lead to infinite-loop. This is because the register, VGACRI-Dx, checked in this API is a scratch register actually controlled by a MCU, named DPMCU, in BMC. These scratch registers are protected by scu-lock. If suc-lock is not off, DPMCU can not update these registers and then host will have soft lockup due to never updated status. DPMCU is used to control DP and relative registers to handshake with host's VGA driver. Even the most time-consuming task, DP's link training, is less than 100ms. 200ms should be enough.

EPSS: Низкий
github логотип

GHSA-22gj-rr23-9xgc

около 3 лет назад

A non-persistent XSS (cross-site scripting) vulnerability exists in eWON Flexy and Cosy (all firmware versions prior to 14.1s0). An attacker could send a specially crafted URL to initiate a password change for the device. The target must introduce the credentials to the gateway before the attack can be successful.

EPSS: Низкий
github логотип

GHSA-22gj-8qj2-fj46

больше 2 лет назад

Moodle External Control of File Name or Path vulnerability

CVSS3: 5.3
EPSS: Средний
github логотип

GHSA-22gj-5cj3-9837

около 3 лет назад

SQL injection vulnerability in viewnews.php in 2daybiz Multi Level Marketing (MLM) Software allows remote attackers to execute arbitrary SQL commands via the nwsid parameter.

EPSS: Низкий
github логотип

GHSA-22gh-3r9q-xf38

почти 4 года назад

Lacking Protection against HTTP Request Smuggling in mitmproxy

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-22gf-f5w4-hrfq

больше 3 лет назад

A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.

CVSS3: 9.1
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-22h9-2mpf-7588

An issue found in POWERAMP audioplayer build 925 bundle play and build 954 allows a remote attacker to gain privileges via the reverb and EQ preset parameters.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-22h8-jh78-8mgh

A vulnerability has been identified in JT2Go (All versions < V13.2.0.5), Teamcenter Visualization (All versions < V13.2.0.5). The DL180pdfl.dll contains an out of bounds write past the end of an allocated structure while parsing specially crafted JT files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-15103)

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-22h8-5mmq-pgx3

Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.

CVSS3: 7.5
29%
Средний
около 3 лет назад
github логотип
GHSA-22h7-7wwg-qmgg

Prototype Pollution in @hapi/hoek

почти 5 лет назад
github логотип
GHSA-22h6-v894-7cgq

Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.4, 12.1.0, 12.3.0 and 12.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle FLEXCUBE Investor Servicing accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle FLEXCUBE Investor Servicing. CVSS 3.0 Base Score 5.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L).

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-22h6-79rc-rj5g

Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies SynaMan before 3.5 Build 1451, Syncrify before 3.7 Build 856, and SynTail before 1.5 Build 567

0%
Низкий
около 3 лет назад
github логотип
GHSA-22h5-pq3x-2gf2

URI allows for userinfo Leakage in URI#join, URI#merge, and URI#+

CVSS3: 3.2
0%
Низкий
5 месяцев назад
github логотип
GHSA-22gx-8v7p-9g9p

A memory corruption vulnerability exists in the PNG png_palette_process functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to a heap buffer overflow. An attacker can provide malicious inputs to trigger this vulnerability.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-22gx-4xv7-xwjg

FiveCo RAP dissector infinite loop in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file

CVSS3: 5.5
0%
Низкий
3 месяца назад
github логотип
GHSA-22gv-43vq-fhjw

Due to missing authorization check in an RFC enabled function module in transaction SDCCN, an unauthenticated attacker could generate technical meta-data. This leads to a low impact on integrity. There is no impact on confidentiality or availability.

CVSS3: 5.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-22gr-gpph-j2c5

An information disclosure vulnerability exists in the ACEManager authentication functionality of Sierra Wireless AirLink ES450 FW 4.9.3. The ACEManager authentication functionality is done in plaintext XML to the web server. An attacker can listen to network traffic upstream from the device to capitalize on this vulnerability.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-22gq-x6pg-752j

openssl.js is malware

CVSS3: 7.5
0%
Низкий
почти 7 лет назад
github логотип
GHSA-22gp-w9xj-6wwq

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alexander Weleczka FontAwesome.io ShortCodes allows Stored XSS.This issue affects FontAwesome.io ShortCodes: from n/a through 1.0.

CVSS3: 6.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-22gp-8432-2xp8

The Parallel Mafia MMORPG (aka com.perblue.pm.client) application @7F070000 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
около 3 лет назад
github логотип
GHSA-22gp-7w9x-c2xx

In the Linux kernel, the following vulnerability has been resolved: drm/ast: Fix soft lockup There is a while-loop in ast_dp_set_on_off() that could lead to infinite-loop. This is because the register, VGACRI-Dx, checked in this API is a scratch register actually controlled by a MCU, named DPMCU, in BMC. These scratch registers are protected by scu-lock. If suc-lock is not off, DPMCU can not update these registers and then host will have soft lockup due to never updated status. DPMCU is used to control DP and relative registers to handshake with host's VGA driver. Even the most time-consuming task, DP's link training, is less than 100ms. 200ms should be enough.

0%
Низкий
около 1 года назад
github логотип
GHSA-22gj-rr23-9xgc

A non-persistent XSS (cross-site scripting) vulnerability exists in eWON Flexy and Cosy (all firmware versions prior to 14.1s0). An attacker could send a specially crafted URL to initiate a password change for the device. The target must introduce the credentials to the gateway before the attack can be successful.

0%
Низкий
около 3 лет назад
github логотип
GHSA-22gj-8qj2-fj46

Moodle External Control of File Name or Path vulnerability

CVSS3: 5.3
18%
Средний
больше 2 лет назад
github логотип
GHSA-22gj-5cj3-9837

SQL injection vulnerability in viewnews.php in 2daybiz Multi Level Marketing (MLM) Software allows remote attackers to execute arbitrary SQL commands via the nwsid parameter.

0%
Низкий
около 3 лет назад
github логотип
GHSA-22gh-3r9q-xf38

Lacking Protection against HTTP Request Smuggling in mitmproxy

CVSS3: 8.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-22gf-f5w4-hrfq

A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.

CVSS3: 9.1
79%
Высокий
больше 3 лет назад

Уязвимостей на страницу