Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-3gf4-rwmr-gpjh

больше 3 лет назад

Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 6.1 and 7.x before 7.0+Patch 1 allows remote attackers to execute arbitrary code via an invalid request.

EPSS: Средний
github логотип

GHSA-3gf3-x9x8-839v

почти 2 года назад

An issue in MiniZinc before 2.8.0 allows a NULL pointer dereference via ti_expr in a crafted .mzn file. NOTE: this is disputed because there is no common libminizinc use case in which an unattended process is supposed to run forever to process a series of atttacker-controlled .mzn files.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3gf3-wxcr-v28j

больше 3 лет назад

A remote code execution vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36715268.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3gf3-q286-fvmm

9 месяцев назад

Input provided in a field containing "activationMessage" in Konsola Proget is not sanitized correctly, allowing a high-privileged user to perform a Stored Cross-Site Scripting attack. This issue has been fixed in 2.17.5 version of Konsola Proget (server part of the MDM suite).

EPSS: Низкий
github логотип

GHSA-3gf2-723m-w3fv

почти 4 года назад

In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3gf2-6hpq-8qpf

больше 3 лет назад

Multiple SQL injection vulnerabilities in login.php in Pre Projects Pre Real Estate Listings allow remote attackers to execute arbitrary SQL commands via (1) the us parameter (aka the Username field) or (2) the ps parameter (aka the Password field).

EPSS: Низкий
github логотип

GHSA-3gf2-35gj-m8v9

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in Clubpage allow remote attackers to inject arbitrary web script or HTML via the (1) news_archive, (2) language, and (3) intranetLogin parameters in (a) index.php; the (4) sites_id parameter in (b) sites.php; and the (5) news_id parameter in (c) news_more.php.

EPSS: Низкий
github логотип

GHSA-3gcx-wjr4-jv32

больше 2 лет назад

A time-of-check to time-of-use issue exists in io_uring subsystem's IORING_OP_CLOSE operation in the Linux kernel's versions 5.6 - 5.11 (inclusive), which allows a local user to elevate their privileges to root. Introduced in b5dba59e0cf7e2cc4d3b3b1ac5fe81ddf21959eb, patched in 9eac1904d3364254d622bf2c771c4f85cd435fc2, backported to stable in 788d0824269bef539fe31a785b1517882eafed93.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3gcx-p34g-c7x5

почти 3 года назад

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3gcx-c67c-32vj

больше 3 лет назад

GitLab CE/EE, versions 8.8 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an authorization vulnerability that allows access to the web-UI as a user using a Personal Access Token of any scope.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3gcx-7vw9-42m9

больше 3 лет назад

A vulnerability in Suprema Bio Star 2 v2.8.16 allows attackers to escalate privileges to System Administrator via a crafted PUT request to the update profile page.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3gcx-69hx-4g6m

почти 4 года назад

Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to execute arbitrary code by appending an SVG comment DOM node to another type of document, which triggers memory corruption.

EPSS: Средний
github логотип

GHSA-3gcw-wvq5-m2pm

больше 2 лет назад

Vulnerability in Cloud Foundry Notifications, Cloud Foundry SMB-volume release, Cloud FOundry cf-nfs-volume release.This issue affects Notifications: All versions prior to 63; SMB-volume release: All versions prior to 3.1.19; cf-nfs-volume release: 5.0.X versions prior to 5.0.27, 7.1.X versions prior to 7.1.19.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3gcw-46mx-pvmh

почти 4 года назад

Unknown vulnerability in Lasso Professional Server8.0.4 and 8.0.5 allows attackers to bypass authentication, related to [Auth] tags.

EPSS: Низкий
github логотип

GHSA-3gcv-q5vm-qrxr

больше 3 лет назад

A null pointer dereference flaw was found in the way samba checked database outputs from the LDB database layer. An authenticated attacker could use this flaw to crash a samba server in an Active Directory Domain Controller configuration. Samba versions before 4.7.9 and 4.8.4 are vulnerable.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3gcv-ff7j-4x62

5 месяцев назад

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.5.3145 build 20250526 and later QuTS hero h5.2.5.3138 build 20250519 and later

EPSS: Низкий
github логотип

GHSA-3gcv-cwcr-w49h

больше 3 лет назад

An elevation of privilege vulnerability exists in OpenSSH for Windows when it does not properly restrict access to configuration settings, aka 'OpenSSH for Windows Elevation of Privilege Vulnerability'.

EPSS: Средний
github логотип

GHSA-3gcv-3vj4-42c9

больше 3 лет назад

Heap-based buffer overflow in the TIFF image converter in the graphics filters in Microsoft Office XP SP3, Office Converter Pack, and Works 9 allows remote attackers to execute arbitrary code via a crafted TIFF image in an Office document, aka "TIFF Image Converter Heap Overflow Vulnerability."

EPSS: Средний
github логотип

GHSA-3gcr-cppr-2cjh

около 1 года назад

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `S1Setup Request` packet missing an expected `Supported TAs` field.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3gcq-r7g8-xfvf

больше 3 лет назад

The W3 Total Cache plugin before 0.9.4.1 for WordPress does not properly handle empty nonces, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and hijack the authentication of administrators for requests that change the mobile site redirect URI via the mobile_groups[*][redirect] parameter and an empty _wpnonce parameter in the w3tc_mobile page to wp-admin/admin.php.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3gf4-rwmr-gpjh

Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 6.1 and 7.x before 7.0+Patch 1 allows remote attackers to execute arbitrary code via an invalid request.

49%
Средний
больше 3 лет назад
github логотип
GHSA-3gf3-x9x8-839v

An issue in MiniZinc before 2.8.0 allows a NULL pointer dereference via ti_expr in a crafted .mzn file. NOTE: this is disputed because there is no common libminizinc use case in which an unattended process is supposed to run forever to process a series of atttacker-controlled .mzn files.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-3gf3-wxcr-v28j

A remote code execution vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36715268.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3gf3-q286-fvmm

Input provided in a field containing "activationMessage" in Konsola Proget is not sanitized correctly, allowing a high-privileged user to perform a Stored Cross-Site Scripting attack. This issue has been fixed in 2.17.5 version of Konsola Proget (server part of the MDM suite).

0%
Низкий
9 месяцев назад
github логотип
GHSA-3gf2-723m-w3fv

In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-3gf2-6hpq-8qpf

Multiple SQL injection vulnerabilities in login.php in Pre Projects Pre Real Estate Listings allow remote attackers to execute arbitrary SQL commands via (1) the us parameter (aka the Username field) or (2) the ps parameter (aka the Password field).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3gf2-35gj-m8v9

Multiple cross-site scripting (XSS) vulnerabilities in Clubpage allow remote attackers to inject arbitrary web script or HTML via the (1) news_archive, (2) language, and (3) intranetLogin parameters in (a) index.php; the (4) sites_id parameter in (b) sites.php; and the (5) news_id parameter in (c) news_more.php.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3gcx-wjr4-jv32

A time-of-check to time-of-use issue exists in io_uring subsystem's IORING_OP_CLOSE operation in the Linux kernel's versions 5.6 - 5.11 (inclusive), which allows a local user to elevate their privileges to root. Introduced in b5dba59e0cf7e2cc4d3b3b1ac5fe81ddf21959eb, patched in 9eac1904d3364254d622bf2c771c4f85cd435fc2, backported to stable in 788d0824269bef539fe31a785b1517882eafed93.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3gcx-p34g-c7x5

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

CVSS3: 6.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-3gcx-c67c-32vj

GitLab CE/EE, versions 8.8 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an authorization vulnerability that allows access to the web-UI as a user using a Personal Access Token of any scope.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3gcx-7vw9-42m9

A vulnerability in Suprema Bio Star 2 v2.8.16 allows attackers to escalate privileges to System Administrator via a crafted PUT request to the update profile page.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3gcx-69hx-4g6m

Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to execute arbitrary code by appending an SVG comment DOM node to another type of document, which triggers memory corruption.

42%
Средний
почти 4 года назад
github логотип
GHSA-3gcw-wvq5-m2pm

Vulnerability in Cloud Foundry Notifications, Cloud Foundry SMB-volume release, Cloud FOundry cf-nfs-volume release.This issue affects Notifications: All versions prior to 63; SMB-volume release: All versions prior to 3.1.19; cf-nfs-volume release: 5.0.X versions prior to 5.0.27, 7.1.X versions prior to 7.1.19.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3gcw-46mx-pvmh

Unknown vulnerability in Lasso Professional Server8.0.4 and 8.0.5 allows attackers to bypass authentication, related to [Auth] tags.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3gcv-q5vm-qrxr

A null pointer dereference flaw was found in the way samba checked database outputs from the LDB database layer. An authenticated attacker could use this flaw to crash a samba server in an Active Directory Domain Controller configuration. Samba versions before 4.7.9 and 4.8.4 are vulnerable.

CVSS3: 6.5
4%
Низкий
больше 3 лет назад
github логотип
GHSA-3gcv-ff7j-4x62

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.5.3145 build 20250526 and later QuTS hero h5.2.5.3138 build 20250519 and later

0%
Низкий
5 месяцев назад
github логотип
GHSA-3gcv-cwcr-w49h

An elevation of privilege vulnerability exists in OpenSSH for Windows when it does not properly restrict access to configuration settings, aka 'OpenSSH for Windows Elevation of Privilege Vulnerability'.

14%
Средний
больше 3 лет назад
github логотип
GHSA-3gcv-3vj4-42c9

Heap-based buffer overflow in the TIFF image converter in the graphics filters in Microsoft Office XP SP3, Office Converter Pack, and Works 9 allows remote attackers to execute arbitrary code via a crafted TIFF image in an Office document, aka "TIFF Image Converter Heap Overflow Vulnerability."

58%
Средний
больше 3 лет назад
github логотип
GHSA-3gcr-cppr-2cjh

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `S1Setup Request` packet missing an expected `Supported TAs` field.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-3gcq-r7g8-xfvf

The W3 Total Cache plugin before 0.9.4.1 for WordPress does not properly handle empty nonces, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and hijack the authentication of administrators for requests that change the mobile site redirect URI via the mobile_groups[*][redirect] parameter and an empty _wpnonce parameter in the w3tc_mobile page to wp-admin/admin.php.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу