Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3j54-7r73-qgxr

больше 3 лет назад

Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0952 and CVE-2016-0953.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-3j54-7gqc-xjwp

почти 3 года назад

The myMail app through 14.30 for iOS sends cleartext credentials in a situation where STARTTLS is expected by a server.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3j53-j44c-wp43

11 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: kernel/irq/irqdomain.c: fix memory leak with using debugfs_lookup() When calling debugfs_lookup() the result must have dput() called on it, otherwise the memory will leak over time. To make things simpler, just call debugfs_lookup_and_remove() instead which handles all of the logic at once.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3j52-m85f-mg6g

почти 4 года назад

HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in department.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3j52-86hv-pq9m

почти 4 года назад

WebKit in Apple Safari before 4.0 does not properly initialize memory for Attr DOM objects, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document.

EPSS: Низкий
github логотип

GHSA-3j4x-wh8q-39g3

около 3 лет назад

A vulnerability was found in soerennb eXtplorer up to 2.1.12 and classified as critical. Affected by this issue is some unknown functionality of the component Directory Content Handler. The manipulation leads to path traversal. Upgrading to version 2.1.13 is able to address this issue. The name of the patch is b8fcb888f4ff5e171c16797a4b075c6c6f50bf46. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-217436.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3j4x-9q9q-3277

около 2 лет назад

Cross-site Scripting in JFinal

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3j4w-jcv6-fv59

12 дней назад

ForensiT AppX Management Service 2.2.0.4 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSystem account permissions during service startup.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3j4w-c76p-2jvh

больше 3 лет назад

Integer overflow in Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to cause a denial of service (daemon crash) via a crafted packet with a certain opcode that triggers an incorrect memory allocation and a buffer overflow.

EPSS: Низкий
github логотип

GHSA-3j4v-h6mr-q2j9

больше 3 лет назад

The WavFileBase class in WavFile.cpp in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (heap corruption from size inconsistency) or possibly have unspecified other impact, as demonstrated by SoundStretch.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3j4r-w3gq-96pw

больше 3 лет назад

An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0699.

EPSS: Низкий
github логотип

GHSA-3j4r-qx26-f2pp

больше 3 лет назад

SQL injection vulnerability in DBD::PgPP 0.05 and earlier

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3j4r-55jx-gvmw

почти 4 года назад

CC Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry.

EPSS: Низкий
github логотип

GHSA-3j4r-3gwf-p2pm

больше 3 лет назад

The About option on the Help menu in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Management Database (CCMDB) 6.2, 7.1, and 7.2 shows the username, which might allow remote authenticated users to have an unspecified impact via a targeted attack against the corresponding user account.

EPSS: Низкий
github логотип

GHSA-3j4q-w64j-h3mx

около 3 лет назад

This CVE is not valid.

EPSS: Низкий
github логотип

GHSA-3j4q-r565-vcj9

4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: block: fix rq-qos breakage from skipping rq_qos_done_bio() a647a524a467 ("block: don't call rq_qos_ops->done_bio if the bio isn't tracked") made bio_endio() skip rq_qos_done_bio() if BIO_TRACKED is not set. While this fixed a potential oops, it also broke blk-iocost by skipping the done_bio callback for merged bios. Before, whether a bio goes through rq_qos_throttle() or rq_qos_merge(), rq_qos_done_bio() would be called on the bio on completion with BIO_TRACKED distinguishing the former from the latter. rq_qos_done_bio() is not called for bios which wenth through rq_qos_merge(). This royally confuses blk-iocost as the merged bios never finish and are considered perpetually in-flight. One reliably reproducible failure mode is an intermediate cgroup geting stuck active preventing its children from being activated due to the leaf-only rule, leading to loss of control. The following is from resctl-bench protection s...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3j4q-cm56-9492

больше 1 года назад

Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the delno parameter in the fromPptpUserSetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3j4p-qc5m-wqgh

около 2 лет назад

An issue was discovered in SchedMD Slurm 22.05.x and 23.02.x. There is Incorrect Access Control: an attacker can modified their extended group list that is used with the sbcast subsystem, and open files with an unauthorized set of extended groups. The fixed versions are 22.05.11 and 23.02.7.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-3j4p-7g9x-w28j

больше 3 лет назад

A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be downloadable when appending /download to the URL.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3j4m-97f8-qmph

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the table feature in PmWiki 2.2.15 allows remote authenticated users to inject arbitrary web script or HTML via the width attribute.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3j54-7r73-qgxr

Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0952 and CVE-2016-0953.

CVSS3: 9.8
18%
Средний
больше 3 лет назад
github логотип
GHSA-3j54-7gqc-xjwp

The myMail app through 14.30 for iOS sends cleartext credentials in a situation where STARTTLS is expected by a server.

CVSS3: 7.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-3j53-j44c-wp43

In the Linux kernel, the following vulnerability has been resolved: kernel/irq/irqdomain.c: fix memory leak with using debugfs_lookup() When calling debugfs_lookup() the result must have dput() called on it, otherwise the memory will leak over time. To make things simpler, just call debugfs_lookup_and_remove() instead which handles all of the logic at once.

CVSS3: 5.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-3j52-m85f-mg6g

HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in department.php.

CVSS3: 9.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-3j52-86hv-pq9m

WebKit in Apple Safari before 4.0 does not properly initialize memory for Attr DOM objects, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document.

6%
Низкий
почти 4 года назад
github логотип
GHSA-3j4x-wh8q-39g3

A vulnerability was found in soerennb eXtplorer up to 2.1.12 and classified as critical. Affected by this issue is some unknown functionality of the component Directory Content Handler. The manipulation leads to path traversal. Upgrading to version 2.1.13 is able to address this issue. The name of the patch is b8fcb888f4ff5e171c16797a4b075c6c6f50bf46. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-217436.

CVSS3: 9.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-3j4x-9q9q-3277

Cross-site Scripting in JFinal

CVSS3: 5.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-3j4w-jcv6-fv59

ForensiT AppX Management Service 2.2.0.4 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSystem account permissions during service startup.

CVSS3: 7.8
0%
Низкий
12 дней назад
github логотип
GHSA-3j4w-c76p-2jvh

Integer overflow in Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to cause a denial of service (daemon crash) via a crafted packet with a certain opcode that triggers an incorrect memory allocation and a buffer overflow.

8%
Низкий
больше 3 лет назад
github логотип
GHSA-3j4v-h6mr-q2j9

The WavFileBase class in WavFile.cpp in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (heap corruption from size inconsistency) or possibly have unspecified other impact, as demonstrated by SoundStretch.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3j4r-w3gq-96pw

An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0699.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3j4r-qx26-f2pp

SQL injection vulnerability in DBD::PgPP 0.05 and earlier

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3j4r-55jx-gvmw

CC Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry.

4%
Низкий
почти 4 года назад
github логотип
GHSA-3j4r-3gwf-p2pm

The About option on the Help menu in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Management Database (CCMDB) 6.2, 7.1, and 7.2 shows the username, which might allow remote authenticated users to have an unspecified impact via a targeted attack against the corresponding user account.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3j4q-w64j-h3mx

This CVE is not valid.

около 3 лет назад
github логотип
GHSA-3j4q-r565-vcj9

In the Linux kernel, the following vulnerability has been resolved: block: fix rq-qos breakage from skipping rq_qos_done_bio() a647a524a467 ("block: don't call rq_qos_ops->done_bio if the bio isn't tracked") made bio_endio() skip rq_qos_done_bio() if BIO_TRACKED is not set. While this fixed a potential oops, it also broke blk-iocost by skipping the done_bio callback for merged bios. Before, whether a bio goes through rq_qos_throttle() or rq_qos_merge(), rq_qos_done_bio() would be called on the bio on completion with BIO_TRACKED distinguishing the former from the latter. rq_qos_done_bio() is not called for bios which wenth through rq_qos_merge(). This royally confuses blk-iocost as the merged bios never finish and are considered perpetually in-flight. One reliably reproducible failure mode is an intermediate cgroup geting stuck active preventing its children from being activated due to the leaf-only rule, leading to loss of control. The following is from resctl-bench protection s...

CVSS3: 5.5
0%
Низкий
4 месяца назад
github логотип
GHSA-3j4q-cm56-9492

Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the delno parameter in the fromPptpUserSetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVSS3: 7.5
4%
Низкий
больше 1 года назад
github логотип
GHSA-3j4p-qc5m-wqgh

An issue was discovered in SchedMD Slurm 22.05.x and 23.02.x. There is Incorrect Access Control: an attacker can modified their extended group list that is used with the sbcast subsystem, and open files with an unauthorized set of extended groups. The fixed versions are 22.05.11 and 23.02.7.

CVSS3: 8.2
0%
Низкий
около 2 лет назад
github логотип
GHSA-3j4p-7g9x-w28j

A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be downloadable when appending /download to the URL.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3j4m-97f8-qmph

Cross-site scripting (XSS) vulnerability in the table feature in PmWiki 2.2.15 allows remote authenticated users to inject arbitrary web script or HTML via the width attribute.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу