Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3jf3-rqfc-mfmr

больше 3 лет назад

Unspecified vulnerability in the kernel in Microsoft Windows 7 allows local users to gain privileges via unknown vectors, as demonstrated by Nils and Jon of MWR Labs during a Pwn2Own competition at CanSecWest 2013, a different vulnerability than CVE-2013-0912.

EPSS: Низкий
github логотип

GHSA-3jf3-8c3v-79gx

почти 2 года назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-33891. Reason: This candidate is a reservation duplicate of CVE-2024-33891. Notes: All CVE users should reference CVE-2024-33891 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

EPSS: Низкий
github логотип

GHSA-3jf2-c8c6-ph58

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in CRU Ditto Forensic FieldStation with firmware 2013Oct15a and earlier allow (1) remote attackers to inject arbitrary web script or HTML via the username parameter in a login or (2) remote authenticated users to inject arbitrary web script or HTML via unspecified form fields.

EPSS: Низкий
github логотип

GHSA-3jf2-2rp2-p843

почти 4 года назад

IBM WebSphere Application Server (WAS) 6.0 before 20050201, when serving pages in an Application WAR or an Extended Document Root, allows remote attackers to obtain the JSP source code and other sensitive information via "a specific JSP URL," related to lack of normalization of the URL format.

EPSS: Низкий
github логотип

GHSA-3jcx-v57w-c6rq

около 4 лет назад

Vulnerability in dirhistory plugin Description: the widgets that go back and forward in the directory history, triggered by pressing Alt-Left and Alt-Right, use functions that unsafely execute eval on directory names. If you cd into a directory with a carefully-crafted name, then press Alt-Left, the system is subject to command injection. Impacted areas: - Functions pop_past and pop_future in dirhistory plugin.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3jcw-ph85-3mv4

больше 3 лет назад

OX App Suite through 7.10.3 allows SSRF because GET requests are sent to arbitrary domain names with an initial autoconfig. substring.

EPSS: Низкий
github логотип

GHSA-3jcv-phqx-p74w

11 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in andrew_fisher WOO Codice Fiscale allows Reflected XSS. This issue affects WOO Codice Fiscale: from n/a through 1.6.3.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3jcv-mqf8-ww8q

почти 4 года назад

The Cisco Web Management interface in routers running CBOS 2.4.1 and earlier does not log invalid logins, which allows remote attackers to guess passwords without detection.

EPSS: Низкий
github логотип

GHSA-3jcv-5f9p-2f2p

почти 2 года назад

Cross-site Scripting in electron-pdf

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3jcr-m733-wp5w

около 1 года назад

After Effects versions 24.6.2, 25.0.1 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3jcq-cwr7-6332

больше 3 лет назад

jplayer Cross Site Scripting vulnerability

EPSS: Низкий
github логотип

GHSA-3jcq-7m4x-57r2

почти 4 года назад

BEA WebLogic Server and WebLogic Express version 8.1 up to SP2, 7.0 up to SP4, and 6.1 up to SP6 may store the database username and password for an untargeted JDBC connection pool in plaintext in config.xml, which allows local users to gain privileges.

EPSS: Низкий
github логотип

GHSA-3jcp-j236-2qqc

больше 3 лет назад

User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. When interacting in a normal matter with the Sametime chat application, users hold a cookie containing their session ID (SID). This value is also used when sending chat messages, receiving notifications and/or transferring files.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-3jcp-hmmf-vcvp

больше 3 лет назад

An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3jcm-w957-2h9v

больше 3 лет назад

An issue was discovered on Samsung mobile devices with Q(10.0) (Exynos980 9630 and Exynos990 9830 chipsets) software. The Bootloader has a heap-based buffer overflow because of the mishandling of specific commands. The Samsung IDs are SVE-2020-16981, SVE-2020-16991 (May 2020).

EPSS: Низкий
github логотип

GHSA-3jcm-pqj4-w2mw

почти 4 года назад

Unspecified vulnerability in the Logical Standby component in Oracle Database allows remote authenticated users to affect integrity via unknown vectors.

EPSS: Низкий
github логотип

GHSA-3jcj-m65j-r72c

почти 4 года назад

Format string vulnerability in vmrun in VMware VIX API 1.6.x, VMware Workstation 6.5.x before 6.5.4 build 246459, VMware Player 2.5.x before 2.5.4 build 246459, and VMware Server 2.x on Linux, and VMware Fusion 2.x before 2.0.7 build 246742, allows local users to gain privileges via format string specifiers in process metadata.

EPSS: Низкий
github логотип

GHSA-3jcj-hgr2-f986

больше 3 лет назад

An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Office, Microsoft Excel.

CVSS3: 5.5
EPSS: Средний
github логотип

GHSA-3jch-9qgp-4844

больше 3 лет назад

Generated code can read and write out of bounds in safe code

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3jcg-vx7f-j6qf

больше 1 года назад

The fuels-ts typescript SDK has no awareness of to-be-spent transactions

CVSS3: 3.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3jf3-rqfc-mfmr

Unspecified vulnerability in the kernel in Microsoft Windows 7 allows local users to gain privileges via unknown vectors, as demonstrated by Nils and Jon of MWR Labs during a Pwn2Own competition at CanSecWest 2013, a different vulnerability than CVE-2013-0912.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3jf3-8c3v-79gx

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-33891. Reason: This candidate is a reservation duplicate of CVE-2024-33891. Notes: All CVE users should reference CVE-2024-33891 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

почти 2 года назад
github логотип
GHSA-3jf2-c8c6-ph58

Multiple cross-site scripting (XSS) vulnerabilities in CRU Ditto Forensic FieldStation with firmware 2013Oct15a and earlier allow (1) remote attackers to inject arbitrary web script or HTML via the username parameter in a login or (2) remote authenticated users to inject arbitrary web script or HTML via unspecified form fields.

8%
Низкий
больше 3 лет назад
github логотип
GHSA-3jf2-2rp2-p843

IBM WebSphere Application Server (WAS) 6.0 before 20050201, when serving pages in an Application WAR or an Extended Document Root, allows remote attackers to obtain the JSP source code and other sensitive information via "a specific JSP URL," related to lack of normalization of the URL format.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3jcx-v57w-c6rq

Vulnerability in dirhistory plugin Description: the widgets that go back and forward in the directory history, triggered by pressing Alt-Left and Alt-Right, use functions that unsafely execute eval on directory names. If you cd into a directory with a carefully-crafted name, then press Alt-Left, the system is subject to command injection. Impacted areas: - Functions pop_past and pop_future in dirhistory plugin.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-3jcw-ph85-3mv4

OX App Suite through 7.10.3 allows SSRF because GET requests are sent to arbitrary domain names with an initial autoconfig. substring.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jcv-phqx-p74w

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in andrew_fisher WOO Codice Fiscale allows Reflected XSS. This issue affects WOO Codice Fiscale: from n/a through 1.6.3.

CVSS3: 7.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-3jcv-mqf8-ww8q

The Cisco Web Management interface in routers running CBOS 2.4.1 and earlier does not log invalid logins, which allows remote attackers to guess passwords without detection.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3jcv-5f9p-2f2p

Cross-site Scripting in electron-pdf

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-3jcr-m733-wp5w

After Effects versions 24.6.2, 25.0.1 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-3jcq-cwr7-6332

jplayer Cross Site Scripting vulnerability

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3jcq-7m4x-57r2

BEA WebLogic Server and WebLogic Express version 8.1 up to SP2, 7.0 up to SP4, and 6.1 up to SP6 may store the database username and password for an untargeted JDBC connection pool in plaintext in config.xml, which allows local users to gain privileges.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3jcp-j236-2qqc

User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. When interacting in a normal matter with the Sametime chat application, users hold a cookie containing their session ID (SID). This value is also used when sending chat messages, receiving notifications and/or transferring files.

CVSS3: 7.6
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jcp-hmmf-vcvp

An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVSS3: 8.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3jcm-w957-2h9v

An issue was discovered on Samsung mobile devices with Q(10.0) (Exynos980 9630 and Exynos990 9830 chipsets) software. The Bootloader has a heap-based buffer overflow because of the mishandling of specific commands. The Samsung IDs are SVE-2020-16981, SVE-2020-16991 (May 2020).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jcm-pqj4-w2mw

Unspecified vulnerability in the Logical Standby component in Oracle Database allows remote authenticated users to affect integrity via unknown vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3jcj-m65j-r72c

Format string vulnerability in vmrun in VMware VIX API 1.6.x, VMware Workstation 6.5.x before 6.5.4 build 246459, VMware Player 2.5.x before 2.5.4 build 246459, and VMware Server 2.x on Linux, and VMware Fusion 2.x before 2.0.7 build 246742, allows local users to gain privileges via format string specifiers in process metadata.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3jcj-hgr2-f986

An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Office, Microsoft Excel.

CVSS3: 5.5
29%
Средний
больше 3 лет назад
github логотип
GHSA-3jch-9qgp-4844

Generated code can read and write out of bounds in safe code

CVSS3: 9.8
больше 3 лет назад
github логотип
GHSA-3jcg-vx7f-j6qf

The fuels-ts typescript SDK has no awareness of to-be-spent transactions

CVSS3: 3.1
0%
Низкий
больше 1 года назад

Уязвимостей на страницу