Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 375

Количество 314 375

github логотип

GHSA-3j5r-rx9m-43h3

около 4 лет назад

A double-free vulnerability exists in fig2dev through 3.28a is affected by: via the free_stream function in readpics.c, which could cause a denial of service (context-dependent).

EPSS: Низкий
github логотип

GHSA-3j5r-mfj4-r8qm

больше 3 лет назад

TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function NTPSyncWithHost of the file system.so which can control hostTime to attack.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3j5r-3852-j63v

11 месяцев назад

A missing check_access() function in the lollms_binding_infos module of the parisneo/lollms repository, version V14, allows attackers to add, modify, and remove bindings arbitrarily. This vulnerability affects the /install_binding and /reinstall_binding endpoints, among others, enabling unauthorized access and manipulation of binding settings without requiring the client_id value.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-3j5q-94qj-cf33

7 месяцев назад

A vulnerability, which was classified as critical, has been found in code-projects Simple Forum 1.0. This issue affects some unknown processing of the file /forum1.php. The manipulation of the argument File leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3j5p-vc95-vxgc

больше 3 лет назад

An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the third-party "file" product. Versions before 5.30 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3j5p-hx9x-75vj

больше 3 лет назад

Microsoft SharePoint Foundation 2010, Microsoft SharePoint Server 2013 and Microsoft SharePoint Server 2016 allow an elevation of privilege vulnerability due to the way web requests are handled, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0790.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-3j5p-c9jq-rrfh

почти 4 года назад

The Pascal run-time library (PAS$RTL.EXE) before 20070418 on OpenVMS for Integrity Servers 8.3, and PAS$RTL.EXE before 20070419 on OpenVMS Alpha 8.3, does not properly restore PC and PSL values, which allows local users to cause a denial of service (system crash) via certain Pascal code.

EPSS: Низкий
github логотип

GHSA-3j5m-w89j-c2hm

больше 3 лет назад

Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0 allows remote attackers to cause a denial of service (device crash) by pinging a virtual interface, aka Bug ID CSCte55370.

EPSS: Низкий
github логотип

GHSA-3j5m-7mq9-mfj7

больше 3 лет назад

The Authorize.Net module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

EPSS: Низкий
github логотип

GHSA-3j5m-4qj3-wjqr

около 1 года назад

In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-3j5j-x7ph-c2r8

почти 4 года назад

Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.12 and SeaMonkey before 1.1.8 might allow remote attackers to execute arbitrary code via a crafted external-body MIME type in an e-mail message, related to an incorrect memory allocation during message preview.

EPSS: Средний
github логотип

GHSA-3j5h-p2g7-9wc9

около 2 лет назад

An XSS vulnerability stored in Repox has been identified, which allows a local attacker to store a specially crafted JavaScript payload on the server, due to the lack of proper sanitisation of field elements, allowing the attacker to trigger the malicious payload when the application loads.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3j5h-f552-7rhh

2 месяца назад

An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Apache HTTP Server: from 2.4.30 before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3j5g-pgw8-92vr

около 3 лет назад

Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3j5c-vvwf-m29h

больше 3 лет назад

ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

EPSS: Средний
github логотип

GHSA-3j5c-gqf5-5qv4

больше 2 лет назад

There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Make an Offer Widget v1.0.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3j59-wr8c-7648

около 3 лет назад

A vulnerability classified as critical was found in purpleparrots 491-Project. This vulnerability affects unknown code of the file update.php of the component Highscore Handler. The manipulation leads to sql injection. The name of the patch is a812a5e4cf72f2a635a716086fe1ee2b8fa0b1ab. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217648.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3j58-p785-f27x

около 4 лет назад

Cross-site Scripting in microweber

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3j58-p4j5-9hc3

больше 3 лет назад

An information disclosure vulnerability in Bluetooth could allow a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as Moderate due to details specific to the vulnerability. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34946955.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3j57-8hvg-f4cv

около 1 года назад

In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox

CVSS3: 8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3j5r-rx9m-43h3

A double-free vulnerability exists in fig2dev through 3.28a is affected by: via the free_stream function in readpics.c, which could cause a denial of service (context-dependent).

0%
Низкий
около 4 лет назад
github логотип
GHSA-3j5r-mfj4-r8qm

TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function NTPSyncWithHost of the file system.so which can control hostTime to attack.

CVSS3: 9.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-3j5r-3852-j63v

A missing check_access() function in the lollms_binding_infos module of the parisneo/lollms repository, version V14, allows attackers to add, modify, and remove bindings arbitrarily. This vulnerability affects the /install_binding and /reinstall_binding endpoints, among others, enabling unauthorized access and manipulation of binding settings without requiring the client_id value.

CVSS3: 8
0%
Низкий
11 месяцев назад
github логотип
GHSA-3j5q-94qj-cf33

A vulnerability, which was classified as critical, has been found in code-projects Simple Forum 1.0. This issue affects some unknown processing of the file /forum1.php. The manipulation of the argument File leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-3j5p-vc95-vxgc

An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the third-party "file" product. Versions before 5.30 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3j5p-hx9x-75vj

Microsoft SharePoint Foundation 2010, Microsoft SharePoint Server 2013 and Microsoft SharePoint Server 2016 allow an elevation of privilege vulnerability due to the way web requests are handled, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0790.

CVSS3: 8.8
22%
Средний
больше 3 лет назад
github логотип
GHSA-3j5p-c9jq-rrfh

The Pascal run-time library (PAS$RTL.EXE) before 20070418 on OpenVMS for Integrity Servers 8.3, and PAS$RTL.EXE before 20070419 on OpenVMS Alpha 8.3, does not properly restore PC and PSL values, which allows local users to cause a denial of service (system crash) via certain Pascal code.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3j5m-w89j-c2hm

Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0 allows remote attackers to cause a denial of service (device crash) by pinging a virtual interface, aka Bug ID CSCte55370.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3j5m-7mq9-mfj7

The Authorize.Net module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3j5m-4qj3-wjqr

In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 8.4
0%
Низкий
около 1 года назад
github логотип
GHSA-3j5j-x7ph-c2r8

Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.12 and SeaMonkey before 1.1.8 might allow remote attackers to execute arbitrary code via a crafted external-body MIME type in an e-mail message, related to an incorrect memory allocation during message preview.

31%
Средний
почти 4 года назад
github логотип
GHSA-3j5h-p2g7-9wc9

An XSS vulnerability stored in Repox has been identified, which allows a local attacker to store a specially crafted JavaScript payload on the server, due to the lack of proper sanitisation of field elements, allowing the attacker to trigger the malicious payload when the application loads.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-3j5h-f552-7rhh

An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Apache HTTP Server: from 2.4.30 before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 7.5
0%
Низкий
2 месяца назад
github логотип
GHSA-3j5g-pgw8-92vr

Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-3j5c-vvwf-m29h

ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

46%
Средний
больше 3 лет назад
github логотип
GHSA-3j5c-gqf5-5qv4

There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Make an Offer Widget v1.0.

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3j59-wr8c-7648

A vulnerability classified as critical was found in purpleparrots 491-Project. This vulnerability affects unknown code of the file update.php of the component Highscore Handler. The manipulation leads to sql injection. The name of the patch is a812a5e4cf72f2a635a716086fe1ee2b8fa0b1ab. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217648.

CVSS3: 9.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-3j58-p785-f27x

Cross-site Scripting in microweber

CVSS3: 5.4
7%
Низкий
около 4 лет назад
github логотип
GHSA-3j58-p4j5-9hc3

An information disclosure vulnerability in Bluetooth could allow a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as Moderate due to details specific to the vulnerability. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34946955.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3j57-8hvg-f4cv

In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox

CVSS3: 8
0%
Низкий
около 1 года назад

Уязвимостей на страницу