Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 289 543

Количество 289 543

github логотип

GHSA-22jv-gjfc-xrr5

больше 3 лет назад

The Hipchat for Mac desktop client is vulnerable to client-side remote code execution via video call link parsing. Hipchat for Mac desktop clients at or above version 4.0 and before version 4.30 are affected by this vulnerability.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-22jv-7gj6-846j

больше 2 лет назад

An issue was discovered in drivers/mtd/ubi/cdev.c in the Linux kernel 6.2. There is a divide-by-zero error in do_div(sz,mtd->erasesize), used indirectly by ctrl_cdev_ioctl, when mtd->erasesize is 0.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-22jv-4f49-gfvh

около 1 месяца назад

A vulnerability classified as critical has been found in code-projects Online Appointment Booking System 1.0. This affects an unknown part of the file /ulocateus.php. The manipulation of the argument doctorname leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-22jv-36fh-m28x

около 1 года назад

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application does not properly implement brute force protection against user credentials in its Client Communication component. This could allow an attacker to learn user credentials that are vulnerable to brute force attacks.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-22jr-vc7j-g762

больше 5 лет назад

Potential buffer overflow in psd-tools

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-22jq-crhx-w9j5

больше 3 лет назад

The COPPA error page in the Accounts setup dialog in Mozilla Firefox OS before 2.2 embeds content from an external web server URL into the System process, which allows man-in-the-middle attackers to bypass intended access restrictions by spoofing that server.

EPSS: Низкий
github логотип

GHSA-22jq-62mj-8hw3

больше 3 лет назад

Directory traversal vulnerability in download.php in Sisfo Kampus 0.8 allows remote attackers to list arbitrary directories via an absolute pathname in the dir parameter.

EPSS: Низкий
github логотип

GHSA-22jq-22rq-52q5

больше 3 лет назад

Multiple unspecified vulnerabilities in the (1) Mobile IP NAT Traversal feature and (2) Mobile IPv6 subsystem in Cisco IOS 12.3 through 12.4 allow remote attackers to cause a denial of service (input queue wedge and interface outage) via MIPv6 packets, aka Bug ID CSCsm97220.

EPSS: Низкий
github логотип

GHSA-22jp-m5f3-q68p

около 3 лет назад

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier version, 2017.011.30138 and earlier version, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-22jm-p2vv-j2hc

больше 3 лет назад

Plone XSS

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-22jm-gmg3-6r8v

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in board.php in mowdBB RC-6 allows remote attackers to inject arbitrary web script or HTML via the forum_name[] parameter.

EPSS: Низкий
github логотип

GHSA-22jm-4hxw-35jf

около 3 лет назад

OpenStack Nova can leak consoleauth token into log files

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-22jj-744v-92v5

больше 3 лет назад

livehelperchat is vulnerable to Generation of Error Message Containing Sensitive Information

EPSS: Низкий
github логотип

GHSA-22jh-hqf7-v4mw

около 3 лет назад

Windows Network Address Translation (NAT) Denial of Service Vulnerability.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-22jh-6gx8-f944

около 3 лет назад

Elastic APM agent for Python client CGI proxy redirection flaw

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-22jh-5463-4m46

около 3 лет назад

Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/blog/blogpublish.php.

EPSS: Низкий
github логотип

GHSA-22jg-rc3r-96wc

больше 3 лет назад

Real Media RealServer (rmserver) 6.0.3.353 stores a password in plaintext in the world-readable rmserver.cfg file, which allows local users to gain privileges.

EPSS: Низкий
github логотип

GHSA-22jf-gccc-jpfh

около 3 лет назад

VCFTools vcfools prior to version 0.1.15 is affected by: Heap Use-After-Free. The impact is: Denial of Service or possibly unspecified impact (eg. code execution or information disclosure). The component is: The header::add_FILTER_descriptor method in header.cpp. The attack vector is: The victim must open a specially crafted VCF file.

EPSS: Низкий
github логотип

GHSA-22jf-974v-hf7j

около 3 лет назад

A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited..

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-22jc-frmh-h993

4 месяца назад

TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

CVSS3: 6.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-22jv-gjfc-xrr5

The Hipchat for Mac desktop client is vulnerable to client-side remote code execution via video call link parsing. Hipchat for Mac desktop clients at or above version 4.0 and before version 4.30 are affected by this vulnerability.

CVSS3: 9.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-22jv-7gj6-846j

An issue was discovered in drivers/mtd/ubi/cdev.c in the Linux kernel 6.2. There is a divide-by-zero error in do_div(sz,mtd->erasesize), used indirectly by ctrl_cdev_ioctl, when mtd->erasesize is 0.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-22jv-4f49-gfvh

A vulnerability classified as critical has been found in code-projects Online Appointment Booking System 1.0. This affects an unknown part of the file /ulocateus.php. The manipulation of the argument doctorname leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-22jv-36fh-m28x

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application does not properly implement brute force protection against user credentials in its Client Communication component. This could allow an attacker to learn user credentials that are vulnerable to brute force attacks.

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-22jr-vc7j-g762

Potential buffer overflow in psd-tools

CVSS3: 9.8
0%
Низкий
больше 5 лет назад
github логотип
GHSA-22jq-crhx-w9j5

The COPPA error page in the Accounts setup dialog in Mozilla Firefox OS before 2.2 embeds content from an external web server URL into the System process, which allows man-in-the-middle attackers to bypass intended access restrictions by spoofing that server.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-22jq-62mj-8hw3

Directory traversal vulnerability in download.php in Sisfo Kampus 0.8 allows remote attackers to list arbitrary directories via an absolute pathname in the dir parameter.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-22jq-22rq-52q5

Multiple unspecified vulnerabilities in the (1) Mobile IP NAT Traversal feature and (2) Mobile IPv6 subsystem in Cisco IOS 12.3 through 12.4 allow remote attackers to cause a denial of service (input queue wedge and interface outage) via MIPv6 packets, aka Bug ID CSCsm97220.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-22jp-m5f3-q68p

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier version, 2017.011.30138 and earlier version, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVSS3: 6.5
7%
Низкий
около 3 лет назад
github логотип
CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-22jm-gmg3-6r8v

Cross-site scripting (XSS) vulnerability in board.php in mowdBB RC-6 allows remote attackers to inject arbitrary web script or HTML via the forum_name[] parameter.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-22jm-4hxw-35jf

OpenStack Nova can leak consoleauth token into log files

CVSS3: 3.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-22jj-744v-92v5

livehelperchat is vulnerable to Generation of Error Message Containing Sensitive Information

0%
Низкий
больше 3 лет назад
github логотип
GHSA-22jh-hqf7-v4mw

Windows Network Address Translation (NAT) Denial of Service Vulnerability.

CVSS3: 7.5
18%
Средний
около 3 лет назад
github логотип
GHSA-22jh-6gx8-f944

Elastic APM agent for Python client CGI proxy redirection flaw

CVSS3: 7.2
0%
Низкий
около 3 лет назад
github логотип
GHSA-22jh-5463-4m46

Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/blog/blogpublish.php.

0%
Низкий
около 3 лет назад
github логотип
GHSA-22jg-rc3r-96wc

Real Media RealServer (rmserver) 6.0.3.353 stores a password in plaintext in the world-readable rmserver.cfg file, which allows local users to gain privileges.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-22jf-gccc-jpfh

VCFTools vcfools prior to version 0.1.15 is affected by: Heap Use-After-Free. The impact is: Denial of Service or possibly unspecified impact (eg. code execution or information disclosure). The component is: The header::add_FILTER_descriptor method in header.cpp. The attack vector is: The victim must open a specially crafted VCF file.

около 3 лет назад
github логотип
GHSA-22jf-974v-hf7j

A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited..

CVSS3: 7
6%
Низкий
около 3 лет назад
github логотип
GHSA-22jc-frmh-h993

TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

CVSS3: 6.5
16%
Средний
4 месяца назад

Уязвимостей на страницу