Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3j5m-7mq9-mfj7

больше 3 лет назад

The Authorize.Net module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

EPSS: Низкий
github логотип

GHSA-3j5m-4qj3-wjqr

около 1 года назад

In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-3j5j-x7ph-c2r8

почти 4 года назад

Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.12 and SeaMonkey before 1.1.8 might allow remote attackers to execute arbitrary code via a crafted external-body MIME type in an e-mail message, related to an incorrect memory allocation during message preview.

EPSS: Средний
github логотип

GHSA-3j5h-p2g7-9wc9

около 2 лет назад

An XSS vulnerability stored in Repox has been identified, which allows a local attacker to store a specially crafted JavaScript payload on the server, due to the lack of proper sanitisation of field elements, allowing the attacker to trigger the malicious payload when the application loads.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3j5h-f552-7rhh

2 месяца назад

An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Apache HTTP Server: from 2.4.30 before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3j5g-pgw8-92vr

около 3 лет назад

Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3j5c-vvwf-m29h

больше 3 лет назад

ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

EPSS: Средний
github логотип

GHSA-3j5c-gqf5-5qv4

больше 2 лет назад

There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Make an Offer Widget v1.0.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3j59-wr8c-7648

около 3 лет назад

A vulnerability classified as critical was found in purpleparrots 491-Project. This vulnerability affects unknown code of the file update.php of the component Highscore Handler. The manipulation leads to sql injection. The name of the patch is a812a5e4cf72f2a635a716086fe1ee2b8fa0b1ab. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217648.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3j58-p785-f27x

около 4 лет назад

Cross-site Scripting in microweber

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3j58-p4j5-9hc3

больше 3 лет назад

An information disclosure vulnerability in Bluetooth could allow a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as Moderate due to details specific to the vulnerability. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34946955.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3j57-8hvg-f4cv

около 1 года назад

In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-3j56-rc6g-pp7q

больше 1 года назад

Heap-based buffer overflow vulnerability in Assimp versions prior to 5.4.3 allows a local attacker to execute arbitrary code by importing a specially crafted file into the product.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-3j56-76c6-9xf6

почти 3 года назад

Information disclosure in modem due to buffer over-read while processing response from DNS server

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3j55-q2r8-vc2j

почти 4 года назад

csLiveSupport.cgi in CGIScript.net csLiveSupport allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function.

EPSS: Низкий
github логотип

GHSA-3j55-px9j-gc5p

почти 2 года назад

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/catalog_edit.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3j55-7hc5-m8vh

больше 2 лет назад

An issue in ZIONCOM (Hong Kong) Technology Limited A7000R v.4.1cu.4154 allows an attacker to execute arbitrary code via the cig-bin/cstecgi.cgi to the settings/setPasswordCfg function.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3j54-wjw6-wg58

почти 2 года назад

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/templets_one_edit.php

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3j54-rx6j-frg9

почти 4 года назад

Multiple SQL injection vulnerabilities in RI Blog 1.1 allow remote attackers to execute arbitrary SQL command via the (1) username or (2) password fields.

EPSS: Низкий
github логотип

GHSA-3j54-g484-c9vm

больше 3 лет назад

The gst_date_time_new_from_iso8601_string function in gst/gstdatetime.c in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a malformed datetime string.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3j5m-7mq9-mfj7

The Authorize.Net module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3j5m-4qj3-wjqr

In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 8.4
0%
Низкий
около 1 года назад
github логотип
GHSA-3j5j-x7ph-c2r8

Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.12 and SeaMonkey before 1.1.8 might allow remote attackers to execute arbitrary code via a crafted external-body MIME type in an e-mail message, related to an incorrect memory allocation during message preview.

31%
Средний
почти 4 года назад
github логотип
GHSA-3j5h-p2g7-9wc9

An XSS vulnerability stored in Repox has been identified, which allows a local attacker to store a specially crafted JavaScript payload on the server, due to the lack of proper sanitisation of field elements, allowing the attacker to trigger the malicious payload when the application loads.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-3j5h-f552-7rhh

An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Apache HTTP Server: from 2.4.30 before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 7.5
0%
Низкий
2 месяца назад
github логотип
GHSA-3j5g-pgw8-92vr

Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-3j5c-vvwf-m29h

ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

46%
Средний
больше 3 лет назад
github логотип
GHSA-3j5c-gqf5-5qv4

There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Make an Offer Widget v1.0.

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3j59-wr8c-7648

A vulnerability classified as critical was found in purpleparrots 491-Project. This vulnerability affects unknown code of the file update.php of the component Highscore Handler. The manipulation leads to sql injection. The name of the patch is a812a5e4cf72f2a635a716086fe1ee2b8fa0b1ab. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217648.

CVSS3: 9.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-3j58-p785-f27x

Cross-site Scripting in microweber

CVSS3: 5.4
7%
Низкий
около 4 лет назад
github логотип
GHSA-3j58-p4j5-9hc3

An information disclosure vulnerability in Bluetooth could allow a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as Moderate due to details specific to the vulnerability. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34946955.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3j57-8hvg-f4cv

In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox

CVSS3: 8
0%
Низкий
около 1 года назад
github логотип
GHSA-3j56-rc6g-pp7q

Heap-based buffer overflow vulnerability in Assimp versions prior to 5.4.3 allows a local attacker to execute arbitrary code by importing a specially crafted file into the product.

CVSS3: 8.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-3j56-76c6-9xf6

Information disclosure in modem due to buffer over-read while processing response from DNS server

CVSS3: 7.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-3j55-q2r8-vc2j

csLiveSupport.cgi in CGIScript.net csLiveSupport allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3j55-px9j-gc5p

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/catalog_edit.php.

CVSS3: 6.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-3j55-7hc5-m8vh

An issue in ZIONCOM (Hong Kong) Technology Limited A7000R v.4.1cu.4154 allows an attacker to execute arbitrary code via the cig-bin/cstecgi.cgi to the settings/setPasswordCfg function.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3j54-wjw6-wg58

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/templets_one_edit.php

CVSS3: 6.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-3j54-rx6j-frg9

Multiple SQL injection vulnerabilities in RI Blog 1.1 allow remote attackers to execute arbitrary SQL command via the (1) username or (2) password fields.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3j54-g484-c9vm

The gst_date_time_new_from_iso8601_string function in gst/gstdatetime.c in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a malformed datetime string.

CVSS3: 7.5
3%
Низкий
больше 3 лет назад

Уязвимостей на страницу