Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3jv4-c99q-p2j6

больше 3 лет назад

The login resource of CrowdId in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3jv4-4ccq-7qx5

почти 4 года назад

AXIS IP Utility prior to 4.17.0 allows for remote code execution and local privilege escalation by the means of DLL hijacking. IPUtility.exe would attempt to load DLLs from its current working directory which could allow for remote code execution if a compromised DLL would be placed in the same folder.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3jrx-xgc5-h2f9

больше 3 лет назад

gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1, has a heap-based buffer overflow. This can be exploited by an attacker who is able to trigger imagecolormatch calls with crafted image data.

CVSS3: 8.8
EPSS: Высокий
github логотип

GHSA-3jrx-h7mq-gphv

26 дней назад

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3jrx-9rpx-73p9

почти 4 года назад

ICQLite 2003a creates the ICQ Lite directory with an ACE for "Full Control" privileges for Interactive Users, which allows local users to gain privileges as other users by replacing the executables with malicious programs.

EPSS: Низкий
github логотип

GHSA-3jrw-q59w-mpr2

8 месяцев назад

An issue was discovered in Unicom Focal Point 7.6.1. The database is encrypted with a hardcoded key, making it easier to recover the cleartext data.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-3jrw-g6mq-cx56

7 месяцев назад

A missing critical step in authentication vulnerability [CWE-304] in Fortinet FortiOS version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.10, and before 7.0.16 & FortiProxy version 7.6.0 through 7.6.1, 7.4.0 through 7.4.8, 7.2.0 through 7.2.13 and before 7.0.20 allows an API-user using api-key + PKI user certificate authentication to login even if the certificate is invalid.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3jrw-43cp-6whq

больше 3 лет назад

A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to run arbitrary commands as the Linux tomcat user on an affected system. More Information: CSCvc76620. Known Affected Releases: 2.2(9.76).

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3jrv-jgp8-45v3

около 1 года назад

Undertow incorrectly parses cookies

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-3jrv-ghj9-h744

около 2 лет назад

The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via the get_content function. This is due to the plugin making use of the call_user_func function with user input. This makes it possible for unauthenticated attackers to execute any public function with one parameter, which could result in remote code execution.

CVSS3: 8.1
EPSS: Критический
github логотип

GHSA-3jrv-f6qj-v68p

больше 3 лет назад

A buffer overflow vulnerability in GetNumWrongData() in contrib/lips4/gdevlips.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3jrv-4wcq-q836

больше 2 лет назад

Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3jrv-3c97-g969

больше 3 лет назад

Certain MMU virtualization operations in Xen 4.2.x through 4.4.x, when using shadow pagetables, are not preemptible, which allows local HVM guest to cause a denial of service (vcpu consumption) by invoking these operations, which process every page assigned to a guest, a different vulnerability than CVE-2014-5146.

EPSS: Низкий
github логотип

GHSA-3jrr-p7ff-prq5

больше 3 лет назад

Vulnerability in the PeopleSoft Enterprise FSCM component of Oracle PeopleSoft Products (subcomponent: Staffing Front Office). The supported version that is affected is 9.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FSCM. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise FSCM accessible data. CVSS 3.0 Base Score 2.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-3jrr-28fg-vcxg

больше 3 лет назад

In several functions of mali_gralloc_reference.cpp, there is a possible arbitrary code execution due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-212804042References: N/A

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3jrq-x5vv-pvcw

около 4 лет назад

Windows 10 Update Assistant Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-43211.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-3jrq-q9gq-vqpx

больше 3 лет назад

IBM Security SiteProtector System 3.0 before 3.0.0.7, 3.1 before 3.1.0.4, and 3.1.1 before 3.1.1.2 allows local users to obtain sensitive information by reading cached data.

EPSS: Низкий
github логотип

GHSA-3jrq-ghjr-jwf2

больше 1 года назад

Buffer Overflow vulnerability in btstack mesh commit before v.864e2f2b6b7878c8fab3cf5ee84ae566e3380c58 allows a remote attacker to execute arbitrary code via the pb_adv_handle_tranaction_cont function in the src/mesh/pb_adv.c component

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3jrq-922c-9wmf

больше 3 лет назад

The user-account creation feature in Chef Manage 2.1.0 through 2.4.4 allows remote attackers to execute arbitrary code. This is fixed in 2.4.5.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3jrq-728f-h4m6

больше 2 лет назад

Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3jv4-c99q-p2j6

The login resource of CrowdId in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jv4-4ccq-7qx5

AXIS IP Utility prior to 4.17.0 allows for remote code execution and local privilege escalation by the means of DLL hijacking. IPUtility.exe would attempt to load DLLs from its current working directory which could allow for remote code execution if a compromised DLL would be placed in the same folder.

CVSS3: 7.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-3jrx-xgc5-h2f9

gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1, has a heap-based buffer overflow. This can be exploited by an attacker who is able to trigger imagecolormatch calls with crafted image data.

CVSS3: 8.8
88%
Высокий
больше 3 лет назад
github логотип
GHSA-3jrx-h7mq-gphv

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
26 дней назад
github логотип
GHSA-3jrx-9rpx-73p9

ICQLite 2003a creates the ICQ Lite directory with an ACE for "Full Control" privileges for Interactive Users, which allows local users to gain privileges as other users by replacing the executables with malicious programs.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3jrw-q59w-mpr2

An issue was discovered in Unicom Focal Point 7.6.1. The database is encrypted with a hardcoded key, making it easier to recover the cleartext data.

CVSS3: 4.6
0%
Низкий
8 месяцев назад
github логотип
GHSA-3jrw-g6mq-cx56

A missing critical step in authentication vulnerability [CWE-304] in Fortinet FortiOS version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.10, and before 7.0.16 & FortiProxy version 7.6.0 through 7.6.1, 7.4.0 through 7.4.8, 7.2.0 through 7.2.13 and before 7.0.20 allows an API-user using api-key + PKI user certificate authentication to login even if the certificate is invalid.

CVSS3: 7.2
0%
Низкий
7 месяцев назад
github логотип
GHSA-3jrw-43cp-6whq

A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to run arbitrary commands as the Linux tomcat user on an affected system. More Information: CSCvc76620. Known Affected Releases: 2.2(9.76).

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3jrv-jgp8-45v3

Undertow incorrectly parses cookies

CVSS3: 7.4
5%
Низкий
около 1 года назад
github логотип
GHSA-3jrv-ghj9-h744

The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via the get_content function. This is due to the plugin making use of the call_user_func function with user input. This makes it possible for unauthenticated attackers to execute any public function with one parameter, which could result in remote code execution.

CVSS3: 8.1
92%
Критический
около 2 лет назад
github логотип
GHSA-3jrv-f6qj-v68p

A buffer overflow vulnerability in GetNumWrongData() in contrib/lips4/gdevlips.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jrv-4wcq-q836

Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.

CVSS3: 8.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3jrv-3c97-g969

Certain MMU virtualization operations in Xen 4.2.x through 4.4.x, when using shadow pagetables, are not preemptible, which allows local HVM guest to cause a denial of service (vcpu consumption) by invoking these operations, which process every page assigned to a guest, a different vulnerability than CVE-2014-5146.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jrr-p7ff-prq5

Vulnerability in the PeopleSoft Enterprise FSCM component of Oracle PeopleSoft Products (subcomponent: Staffing Front Office). The supported version that is affected is 9.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FSCM. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise FSCM accessible data. CVSS 3.0 Base Score 2.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).

CVSS3: 2.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jrr-28fg-vcxg

In several functions of mali_gralloc_reference.cpp, there is a possible arbitrary code execution due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-212804042References: N/A

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jrq-x5vv-pvcw

Windows 10 Update Assistant Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-43211.

CVSS3: 5
1%
Низкий
около 4 лет назад
github логотип
GHSA-3jrq-q9gq-vqpx

IBM Security SiteProtector System 3.0 before 3.0.0.7, 3.1 before 3.1.0.4, and 3.1.1 before 3.1.1.2 allows local users to obtain sensitive information by reading cached data.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jrq-ghjr-jwf2

Buffer Overflow vulnerability in btstack mesh commit before v.864e2f2b6b7878c8fab3cf5ee84ae566e3380c58 allows a remote attacker to execute arbitrary code via the pb_adv_handle_tranaction_cont function in the src/mesh/pb_adv.c component

CVSS3: 9.8
2%
Низкий
больше 1 года назад
github логотип
GHSA-3jrq-922c-9wmf

The user-account creation feature in Chef Manage 2.1.0 through 2.4.4 allows remote attackers to execute arbitrary code. This is fixed in 2.4.5.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3jrq-728f-h4m6

Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу