Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 375

Количество 314 375

github логотип

GHSA-3jrv-3c97-g969

больше 3 лет назад

Certain MMU virtualization operations in Xen 4.2.x through 4.4.x, when using shadow pagetables, are not preemptible, which allows local HVM guest to cause a denial of service (vcpu consumption) by invoking these operations, which process every page assigned to a guest, a different vulnerability than CVE-2014-5146.

EPSS: Низкий
github логотип

GHSA-3jrr-p7ff-prq5

больше 3 лет назад

Vulnerability in the PeopleSoft Enterprise FSCM component of Oracle PeopleSoft Products (subcomponent: Staffing Front Office). The supported version that is affected is 9.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FSCM. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise FSCM accessible data. CVSS 3.0 Base Score 2.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-3jrr-28fg-vcxg

больше 3 лет назад

In several functions of mali_gralloc_reference.cpp, there is a possible arbitrary code execution due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-212804042References: N/A

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3jrq-x5vv-pvcw

около 4 лет назад

Windows 10 Update Assistant Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-43211.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-3jrq-q9gq-vqpx

больше 3 лет назад

IBM Security SiteProtector System 3.0 before 3.0.0.7, 3.1 before 3.1.0.4, and 3.1.1 before 3.1.1.2 allows local users to obtain sensitive information by reading cached data.

EPSS: Низкий
github логотип

GHSA-3jrq-ghjr-jwf2

больше 1 года назад

Buffer Overflow vulnerability in btstack mesh commit before v.864e2f2b6b7878c8fab3cf5ee84ae566e3380c58 allows a remote attacker to execute arbitrary code via the pb_adv_handle_tranaction_cont function in the src/mesh/pb_adv.c component

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3jrq-922c-9wmf

больше 3 лет назад

The user-account creation feature in Chef Manage 2.1.0 through 2.4.4 allows remote attackers to execute arbitrary code. This is fixed in 2.4.5.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3jrq-728f-h4m6

больше 2 лет назад

Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3jrq-4wj8-868w

почти 4 года назад

Roaming Security Rights Management Services Remote Code Execution Vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3jrp-hwqh-j247

больше 3 лет назад

Aruba Networks ClearPass Policy Manager 6.1.x, 6.2.x before 6.2.5.61640 and 6.3.x before 6.3.0.61712, when configured to use tunneled and non-tunneled EAP methods in a single policy construct, allows remote authenticated users to gain privileges by advertising independent inner and outer identities within a tunneled EAP method.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3jrp-g9m7-98h4

больше 3 лет назад

Use-after-free vulnerability in the nsEditor::FindNextLeafNode function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3jrj-x6cj-97cp

больше 3 лет назад

Moodle contains CSRF vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3jrj-hcqp-mf49

почти 4 года назад

An issue was discovered in xiaohuanxiong CMS 5.0.17. There is a CSRF vulnerability that can that can add the administrator account.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3jrj-65jh-gx24

больше 3 лет назад

An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "IOAcceleratorFamily" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3jrh-75p8-c472

больше 3 лет назад

Adobe Illustrator versions 24.1.2 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution .

EPSS: Низкий
github логотип

GHSA-3jrg-h4x2-422g

больше 3 лет назад

Open Redirect in Z-BlogPHP v1.5.2 and earlier allows remote attackers to obtain sensitive information via the "redirect" parameter in the component "zb_system/cmd.php."

EPSS: Низкий
github логотип

GHSA-3jrg-97f3-rqh9

9 месяцев назад

TYPO3 Unverified Password Change for Backend Users

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-3jrg-7968-639r

больше 1 года назад

A stack-based buffer overflow vulnerability exists in the boa getInfo functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can send a series of HTTP requests to trigger this vulnerability.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3jrf-74h9-v6jf

около 1 месяца назад

A weakness has been identified in youlaitech youlai-mall 1.0.0/2.0.0. This impacts the function getMemberByMobile of the file mall-ums/ums-boot/src/main/java/com/youlai/mall/ums/controller/app/MemberController.java. This manipulation causes improper access controls. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3jrc-j5p2-v7xj

11 месяцев назад

IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.22, 7.2 through 7.2.3.15, and 7.3 through 7.3.2.10 / IBM DevOps Deploy 8.0 through 8.0.1.5 and 8.1 through 8.1.0.1 could allow unauthorized access to other services or potential exposure of sensitive data due to missing authentication in its Agent Relay service.

CVSS3: 6.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3jrv-3c97-g969

Certain MMU virtualization operations in Xen 4.2.x through 4.4.x, when using shadow pagetables, are not preemptible, which allows local HVM guest to cause a denial of service (vcpu consumption) by invoking these operations, which process every page assigned to a guest, a different vulnerability than CVE-2014-5146.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jrr-p7ff-prq5

Vulnerability in the PeopleSoft Enterprise FSCM component of Oracle PeopleSoft Products (subcomponent: Staffing Front Office). The supported version that is affected is 9.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FSCM. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise FSCM accessible data. CVSS 3.0 Base Score 2.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).

CVSS3: 2.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jrr-28fg-vcxg

In several functions of mali_gralloc_reference.cpp, there is a possible arbitrary code execution due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-212804042References: N/A

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jrq-x5vv-pvcw

Windows 10 Update Assistant Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-43211.

CVSS3: 5
1%
Низкий
около 4 лет назад
github логотип
GHSA-3jrq-q9gq-vqpx

IBM Security SiteProtector System 3.0 before 3.0.0.7, 3.1 before 3.1.0.4, and 3.1.1 before 3.1.1.2 allows local users to obtain sensitive information by reading cached data.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jrq-ghjr-jwf2

Buffer Overflow vulnerability in btstack mesh commit before v.864e2f2b6b7878c8fab3cf5ee84ae566e3380c58 allows a remote attacker to execute arbitrary code via the pb_adv_handle_tranaction_cont function in the src/mesh/pb_adv.c component

CVSS3: 9.8
2%
Низкий
больше 1 года назад
github логотип
GHSA-3jrq-922c-9wmf

The user-account creation feature in Chef Manage 2.1.0 through 2.4.4 allows remote attackers to execute arbitrary code. This is fixed in 2.4.5.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3jrq-728f-h4m6

Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3jrq-4wj8-868w

Roaming Security Rights Management Services Remote Code Execution Vulnerability.

CVSS3: 7.8
9%
Низкий
почти 4 года назад
github логотип
GHSA-3jrp-hwqh-j247

Aruba Networks ClearPass Policy Manager 6.1.x, 6.2.x before 6.2.5.61640 and 6.3.x before 6.3.0.61712, when configured to use tunneled and non-tunneled EAP methods in a single policy construct, allows remote authenticated users to gain privileges by advertising independent inner and outer identities within a tunneled EAP method.

CVSS3: 7.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jrp-g9m7-98h4

Use-after-free vulnerability in the nsEditor::FindNextLeafNode function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-3jrj-x6cj-97cp

Moodle contains CSRF vulnerability

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jrj-hcqp-mf49

An issue was discovered in xiaohuanxiong CMS 5.0.17. There is a CSRF vulnerability that can that can add the administrator account.

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-3jrj-65jh-gx24

An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "IOAcceleratorFamily" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jrh-75p8-c472

Adobe Illustrator versions 24.1.2 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution .

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3jrg-h4x2-422g

Open Redirect in Z-BlogPHP v1.5.2 and earlier allows remote attackers to obtain sensitive information via the "redirect" parameter in the component "zb_system/cmd.php."

7%
Низкий
больше 3 лет назад
github логотип
GHSA-3jrg-97f3-rqh9

TYPO3 Unverified Password Change for Backend Users

CVSS3: 3.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-3jrg-7968-639r

A stack-based buffer overflow vulnerability exists in the boa getInfo functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can send a series of HTTP requests to trigger this vulnerability.

CVSS3: 7.2
7%
Низкий
больше 1 года назад
github логотип
GHSA-3jrf-74h9-v6jf

A weakness has been identified in youlaitech youlai-mall 1.0.0/2.0.0. This impacts the function getMemberByMobile of the file mall-ums/ums-boot/src/main/java/com/youlai/mall/ums/controller/app/MemberController.java. This manipulation causes improper access controls. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3jrc-j5p2-v7xj

IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.22, 7.2 through 7.2.3.15, and 7.3 through 7.3.2.10 / IBM DevOps Deploy 8.0 through 8.0.1.5 and 8.1 through 8.1.0.1 could allow unauthorized access to other services or potential exposure of sensitive data due to missing authentication in its Agent Relay service.

CVSS3: 6.3
0%
Низкий
11 месяцев назад

Уязвимостей на страницу