Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3jx3-rj5x-wr5c

больше 3 лет назад

NetApp SnapCenter Server 1.0 and 1.0P1 allows remote attackers to partially bypass authentication and then list and delete backups via unspecified vectors.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3jx3-8c88-w838

больше 1 года назад

InDesign Desktop versions ID19.4, ID18.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3jx2-x7xj-8x2c

больше 3 лет назад

A denial of service vulnerability was reported in Check Point Endpoint Security Client for Windows before E82.10, that could allow service log file to be written to non-standard locations.

EPSS: Низкий
github логотип

GHSA-3jwx-6387-468v

больше 2 лет назад

dpic 2021.01.01 has a Heap-based Buffer Overflow in thestorestring function in dpic.y.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3jwx-4xp9-65px

5 месяцев назад

glib-networking's OpenSSL backend fails to properly check the return value of a call to BIO_write(), resulting in an out of bounds read.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3jww-f8pj-hj29

11 месяцев назад

Illustrator versions 29.2.1, 28.7.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3jwv-cj2j-h5c7

почти 2 года назад

In OPTEE, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08522504; Issue ID: ALPS08522504.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-3jwq-498g-6473

больше 3 лет назад

A vulnerability in the Image Signature Verification feature used in an NX-OS CLI command in Cisco Nexus 3000 Series and 9000 Series Switches could allow an authenticated, local attacker with administrator-level credentials to install a malicious software image on an affected device. The vulnerability exists because software digital signatures are not properly verified during CLI command execution. An attacker could exploit this vulnerability to install an unsigned software image on an affected device. Note: If the device has not been patched for the vulnerability previously disclosed in the Cisco Security Advisory cisco-sa-20190306-nxos-sig-verif, a successful exploit could allow the attacker to boot a malicious software image.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3jwp-gjhp-77f3

больше 3 лет назад

The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application, aka "Windows GDI Elevation of Privilege Vulnerability." This vulnerability is different from those described in CVE-2017-0005, CVE-2017-0025, and CVE-2017-0047.

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-3jwm-v8r9-h7fv

больше 3 лет назад

IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileges to obtain root access. IBM X-Force ID: 128058.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3jwm-23jh-8fh8

больше 3 лет назад

Mozilla Firefox 3.6.x, 3.5.x, 3.0.19, and earlier, and SeaMonkey, executes a mail application in situations where an IFRAME element has a mailto: URL in its SRC attribute, which allows remote attackers to cause a denial of service (excessive application launches) via an HTML document with many IFRAME elements.

EPSS: Низкий
github логотип

GHSA-3jwj-m34m-4x34

почти 4 года назад

Multiple SQL injection vulnerabilities in index.php in HB-NS 1.1.6 allow remote attackers to execute arbitrary SQL commands via the (1) topic or (2) id parameter.

EPSS: Низкий
github логотип

GHSA-3jwh-q6hx-pvmh

больше 3 лет назад

Directory traversal vulnerability in the ZipArchive::extractTo function in PHP 5.2.6 and earlier allows context-dependent attackers to write arbitrary files via a ZIP file with a file whose name contains .. (dot dot) sequences.

EPSS: Низкий
github логотип

GHSA-3jwh-g84j-75mq

больше 3 лет назад

In all Qualcomm products with Android releases from CAF using the Linux kernel, playReady DRM failed to check a length potentially leading to unauthorized access to secure memory.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3jwh-g5rj-5hgj

больше 3 лет назад

Sonatype Nexus Repository Manager 2.x before 2.14.13 allows XSS.

EPSS: Низкий
github логотип

GHSA-3jwh-25gj-xrgf

10 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The Events Calendar Event Tickets allows Reflected XSS. This issue affects Event Tickets: from n/a through 5.20.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3jwg-r279-2xj2

больше 3 лет назад

A use-after-free vulnerability in xps_finish_image_path() in devices/vector/gdevxps.c of Artifex Software GhostScript v9.50 allows a remote attacker to escalate privileges via a crafted PDF file. This is fixed in v9.51.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3jwg-934c-hf4r

почти 4 года назад

MySQL before 5.1.18 allows remote authenticated users without SELECT privileges to obtain sensitive information from partitioned tables via an ALTER TABLE statement.

EPSS: Низкий
github логотип

GHSA-3jwg-839p-m5gf

больше 3 лет назад

The OAuth status rest resource in Atlassian Application Links before version 5.2.7, from 5.3.0 before 5.3.4 and from 5.4.0 before 5.4.3 allows remote attackers with administrative rights to access the content of internal network resources via a Server Side Request Forgery (SSRF) by creating an OAuth application link to a location they control and then redirecting access from the linked location's OAuth status rest resource to an internal location. When running in an environment like Amazon EC2, this flaw maybe used to access to a metadata resource that provides access credentials and other potentially confidential information.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3jwf-xf4c-pfp3

больше 2 лет назад

Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 allows unauthenticated remote code execution via an XML document.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3jx3-rj5x-wr5c

NetApp SnapCenter Server 1.0 and 1.0P1 allows remote attackers to partially bypass authentication and then list and delete backups via unspecified vectors.

CVSS3: 7.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jx3-8c88-w838

InDesign Desktop versions ID19.4, ID18.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3jx2-x7xj-8x2c

A denial of service vulnerability was reported in Check Point Endpoint Security Client for Windows before E82.10, that could allow service log file to be written to non-standard locations.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jwx-6387-468v

dpic 2021.01.01 has a Heap-based Buffer Overflow in thestorestring function in dpic.y.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3jwx-4xp9-65px

glib-networking's OpenSSL backend fails to properly check the return value of a call to BIO_write(), resulting in an out of bounds read.

CVSS3: 4.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-3jww-f8pj-hj29

Illustrator versions 29.2.1, 28.7.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-3jwv-cj2j-h5c7

In OPTEE, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08522504; Issue ID: ALPS08522504.

CVSS3: 4.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-3jwq-498g-6473

A vulnerability in the Image Signature Verification feature used in an NX-OS CLI command in Cisco Nexus 3000 Series and 9000 Series Switches could allow an authenticated, local attacker with administrator-level credentials to install a malicious software image on an affected device. The vulnerability exists because software digital signatures are not properly verified during CLI command execution. An attacker could exploit this vulnerability to install an unsigned software image on an affected device. Note: If the device has not been patched for the vulnerability previously disclosed in the Cisco Security Advisory cisco-sa-20190306-nxos-sig-verif, a successful exploit could allow the attacker to boot a malicious software image.

CVSS3: 6.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jwp-gjhp-77f3

The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application, aka "Windows GDI Elevation of Privilege Vulnerability." This vulnerability is different from those described in CVE-2017-0005, CVE-2017-0025, and CVE-2017-0047.

CVSS3: 7.8
25%
Средний
больше 3 лет назад
github логотип
GHSA-3jwm-v8r9-h7fv

IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileges to obtain root access. IBM X-Force ID: 128058.

CVSS3: 6.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jwm-23jh-8fh8

Mozilla Firefox 3.6.x, 3.5.x, 3.0.19, and earlier, and SeaMonkey, executes a mail application in situations where an IFRAME element has a mailto: URL in its SRC attribute, which allows remote attackers to cause a denial of service (excessive application launches) via an HTML document with many IFRAME elements.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3jwj-m34m-4x34

Multiple SQL injection vulnerabilities in index.php in HB-NS 1.1.6 allow remote attackers to execute arbitrary SQL commands via the (1) topic or (2) id parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3jwh-q6hx-pvmh

Directory traversal vulnerability in the ZipArchive::extractTo function in PHP 5.2.6 and earlier allows context-dependent attackers to write arbitrary files via a ZIP file with a file whose name contains .. (dot dot) sequences.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-3jwh-g84j-75mq

In all Qualcomm products with Android releases from CAF using the Linux kernel, playReady DRM failed to check a length potentially leading to unauthorized access to secure memory.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jwh-g5rj-5hgj

Sonatype Nexus Repository Manager 2.x before 2.14.13 allows XSS.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jwh-25gj-xrgf

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The Events Calendar Event Tickets allows Reflected XSS. This issue affects Event Tickets: from n/a through 5.20.0.

CVSS3: 7.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-3jwg-r279-2xj2

A use-after-free vulnerability in xps_finish_image_path() in devices/vector/gdevxps.c of Artifex Software GhostScript v9.50 allows a remote attacker to escalate privileges via a crafted PDF file. This is fixed in v9.51.

CVSS3: 7.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-3jwg-934c-hf4r

MySQL before 5.1.18 allows remote authenticated users without SELECT privileges to obtain sensitive information from partitioned tables via an ALTER TABLE statement.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3jwg-839p-m5gf

The OAuth status rest resource in Atlassian Application Links before version 5.2.7, from 5.3.0 before 5.3.4 and from 5.4.0 before 5.4.3 allows remote attackers with administrative rights to access the content of internal network resources via a Server Side Request Forgery (SSRF) by creating an OAuth application link to a location they control and then redirecting access from the linked location's OAuth status rest resource to an internal location. When running in an environment like Amazon EC2, this flaw maybe used to access to a metadata resource that provides access credentials and other potentially confidential information.

CVSS3: 7.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jwf-xf4c-pfp3

Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 allows unauthenticated remote code execution via an XML document.

CVSS3: 9.8
2%
Низкий
больше 2 лет назад

Уязвимостей на страницу