Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 375

Количество 314 375

github логотип

GHSA-3jhq-49ph-54f5

около 4 лет назад

In OnMetadataChangedListener of AdvancedBluetoothDetailsHeaderController.java, there is a possible leak of Bluetooth MAC addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-181588752

EPSS: Низкий
github логотип

GHSA-3jhp-7x6r-7792

больше 3 лет назад

Stack-based buffer overflow in the (1) put_dir function in mongoose.c in Mongoose 3.0, (2) put_dir function in yasslEWS.c in yaSSL Embedded Web Server (yasslEWS) 0.2, and (3) _shttpd_put_dir function in io_dir.c in Simple HTTPD (shttpd) 1.42 allows remote attackers to execute arbitrary code via an HTTP PUT request, as exploited in the wild in 2011.

EPSS: Средний
github логотип

GHSA-3jhm-f5jx-jwjj

больше 3 лет назад

A vulnerability in the API subsystem of Cisco Meetings App could allow an unauthenticated, remote attacker to retain and reuse the Traversal Using Relay NAT (TURN) server credentials that are configured in an affected system. The vulnerability is due to insufficient protection mechanisms for the TURN server credentials. An attacker could exploit this vulnerability by intercepting the legitimate traffic that is generated by an affected system. An exploit could allow the attacker to obtain the TURN server credentials, which the attacker could use to place audio/video calls and forward packets through the configured TURN server. The attacker would not be able to take control of the TURN server unless the same credentials were used in multiple systems.

EPSS: Низкий
github логотип

GHSA-3jhm-87m6-x959

больше 3 лет назад

Path traversal mitigation bypass in OctoRPKI

EPSS: Низкий
github логотип

GHSA-3jhj-3m5p-2g94

4 месяца назад

Server-Side Request Forgery (SSRF) vulnerability in captcha.eu Captcha.eu captcha-eu allows Server Side Request Forgery.This issue affects Captcha.eu: from n/a through <= 1.0.61.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3jhj-2cfq-97q3

больше 3 лет назад

Unspecified vulnerability in IBM Rational Requirements Composer before 4.0.4 makes it easier for local users to gain privileges via unknown vectors.

EPSS: Низкий
github логотип

GHSA-3jhh-jx96-63p5

больше 2 лет назад

UPSMON PRO’s has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to bypass authentication and access arbitrary system files.

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-3jhh-8pq8-rfch

больше 3 лет назад

The Easy Contact Form Pro WordPress plugin before 1.1.1.9 did not properly sanitise the text fields (such as Email Subject, Email Recipient, etc) when creating or editing a form, leading to an authenticated (author+) stored cross-site scripting issue. This could allow medium privilege accounts (such as author and editor) to perform XSS attacks against high privilege ones like administrator.

EPSS: Низкий
github логотип

GHSA-3jhh-8hqg-j8q7

почти 4 года назад

Unspecified vulnerability in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Office document that contains a malformed object, related to a "memory handling error," aka "Microsoft Office Execution Jump Vulnerability."

EPSS: Средний
github логотип

GHSA-3jhg-jx8m-q62v

больше 2 лет назад

Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-3jhg-69mr-g25w

почти 3 года назад

The Simple Giveaways WordPress plugin before 2.45.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3jhg-2x63-53q4

больше 3 лет назад

IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 157012.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3jhf-p284-qg8m

больше 3 лет назад

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0968, CVE-2019-0977, CVE-2019-1009, CVE-2019-1010, CVE-2019-1011, CVE-2019-1012, CVE-2019-1013, CVE-2019-1015, CVE-2019-1046, CVE-2019-1047, CVE-2019-1048, CVE-2019-1049, CVE-2019-1050.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3jhf-jgrg-mcw3

3 месяца назад

An issue was discovered in the GPU driver in Samsung Mobile Processor Exynos 1480, 2400, 1580, 2500. There is a use-after-free in the Xclipse GPU Driver.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3jhf-hf27-8fww

7 месяцев назад

The Ajax Load More plugin before 2.8.1.2 does not have authorisation in some of its AJAX actions, allowing any authenticated users, such as subscriber, to upload and delete arbitrary files.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-3jhf-gxhr-q4cx

6 месяцев назад

MaterialX Null Pointer Dereference in getShaderNodes due to Unchecked nodeGraph->getOutput return

EPSS: Низкий
github логотип

GHSA-3jhf-59jq-5cpv

почти 4 года назад

Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1 allows user-assisted remote attackers to force a client to download arbitrary files via the MIME-Type URL flag (-->) for the FLAC image file in a crafted .FLAC file.

EPSS: Низкий
github логотип

GHSA-3jhc-wjqf-5f2c

больше 3 лет назад

Virtualenv Allows Symlink Attack on /tmp/

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-3jhc-7hph-69cq

больше 2 лет назад

RPA Technology Mobile Mouse 3.6.0.4 is vulnerable to Remote Code Execution (RCE).

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-3jhc-73h5-x7fx

больше 3 лет назад

Deserialization of Untrusted Data vulnerability in ICONICS GENESIS64 versions 10.97.1 and prior and Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior allows a remote unauthenticated attacker to execute an arbitrary malicious code by sending specially crafted packets to the GENESIS64 server.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3jhq-49ph-54f5

In OnMetadataChangedListener of AdvancedBluetoothDetailsHeaderController.java, there is a possible leak of Bluetooth MAC addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-181588752

0%
Низкий
около 4 лет назад
github логотип
GHSA-3jhp-7x6r-7792

Stack-based buffer overflow in the (1) put_dir function in mongoose.c in Mongoose 3.0, (2) put_dir function in yasslEWS.c in yaSSL Embedded Web Server (yasslEWS) 0.2, and (3) _shttpd_put_dir function in io_dir.c in Simple HTTPD (shttpd) 1.42 allows remote attackers to execute arbitrary code via an HTTP PUT request, as exploited in the wild in 2011.

54%
Средний
больше 3 лет назад
github логотип
GHSA-3jhm-f5jx-jwjj

A vulnerability in the API subsystem of Cisco Meetings App could allow an unauthenticated, remote attacker to retain and reuse the Traversal Using Relay NAT (TURN) server credentials that are configured in an affected system. The vulnerability is due to insufficient protection mechanisms for the TURN server credentials. An attacker could exploit this vulnerability by intercepting the legitimate traffic that is generated by an affected system. An exploit could allow the attacker to obtain the TURN server credentials, which the attacker could use to place audio/video calls and forward packets through the configured TURN server. The attacker would not be able to take control of the TURN server unless the same credentials were used in multiple systems.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jhm-87m6-x959

Path traversal mitigation bypass in OctoRPKI

больше 3 лет назад
github логотип
GHSA-3jhj-3m5p-2g94

Server-Side Request Forgery (SSRF) vulnerability in captcha.eu Captcha.eu captcha-eu allows Server Side Request Forgery.This issue affects Captcha.eu: from n/a through <= 1.0.61.

CVSS3: 5.3
0%
Низкий
4 месяца назад
github логотип
GHSA-3jhj-2cfq-97q3

Unspecified vulnerability in IBM Rational Requirements Composer before 4.0.4 makes it easier for local users to gain privileges via unknown vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jhh-jx96-63p5

UPSMON PRO’s has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to bypass authentication and access arbitrary system files.

CVSS3: 6.5
48%
Средний
больше 2 лет назад
github логотип
GHSA-3jhh-8pq8-rfch

The Easy Contact Form Pro WordPress plugin before 1.1.1.9 did not properly sanitise the text fields (such as Email Subject, Email Recipient, etc) when creating or editing a form, leading to an authenticated (author+) stored cross-site scripting issue. This could allow medium privilege accounts (such as author and editor) to perform XSS attacks against high privilege ones like administrator.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jhh-8hqg-j8q7

Unspecified vulnerability in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Office document that contains a malformed object, related to a "memory handling error," aka "Microsoft Office Execution Jump Vulnerability."

56%
Средний
почти 4 года назад
github логотип
GHSA-3jhg-jx8m-q62v

Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

CVSS3: 3.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3jhg-69mr-g25w

The Simple Giveaways WordPress plugin before 2.45.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 4.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-3jhg-2x63-53q4

IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 157012.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jhf-p284-qg8m

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0968, CVE-2019-0977, CVE-2019-1009, CVE-2019-1010, CVE-2019-1011, CVE-2019-1012, CVE-2019-1013, CVE-2019-1015, CVE-2019-1046, CVE-2019-1047, CVE-2019-1048, CVE-2019-1049, CVE-2019-1050.

CVSS3: 6.5
8%
Низкий
больше 3 лет назад
github логотип
GHSA-3jhf-jgrg-mcw3

An issue was discovered in the GPU driver in Samsung Mobile Processor Exynos 1480, 2400, 1580, 2500. There is a use-after-free in the Xclipse GPU Driver.

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-3jhf-hf27-8fww

The Ajax Load More plugin before 2.8.1.2 does not have authorisation in some of its AJAX actions, allowing any authenticated users, such as subscriber, to upload and delete arbitrary files.

CVSS3: 8.8
50%
Средний
7 месяцев назад
github логотип
GHSA-3jhf-gxhr-q4cx

MaterialX Null Pointer Dereference in getShaderNodes due to Unchecked nodeGraph->getOutput return

0%
Низкий
6 месяцев назад
github логотип
GHSA-3jhf-59jq-5cpv

Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1 allows user-assisted remote attackers to force a client to download arbitrary files via the MIME-Type URL flag (-->) for the FLAC image file in a crafted .FLAC file.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3jhc-wjqf-5f2c

Virtualenv Allows Symlink Attack on /tmp/

CVSS3: 6.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jhc-7hph-69cq

RPA Technology Mobile Mouse 3.6.0.4 is vulnerable to Remote Code Execution (RCE).

CVSS3: 9.8
61%
Средний
больше 2 лет назад
github логотип
GHSA-3jhc-73h5-x7fx

Deserialization of Untrusted Data vulnerability in ICONICS GENESIS64 versions 10.97.1 and prior and Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior allows a remote unauthenticated attacker to execute an arbitrary malicious code by sending specially crafted packets to the GENESIS64 server.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад

Уязвимостей на страницу