Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3hwv-fr9j-3wjq

больше 1 года назад

VLC media player 3.0.20 and earlier is vulnerable to denial of service through an integer overflow which could be triggered with a maliciously crafted mms stream (heap based overflow). If successful, a malicious third party could trigger either a crash of VLC or an arbitrary code execution with the target user's privileges.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-3hwv-cmwg-vxxj

больше 2 лет назад

When a secure cookie existed in the Firefox cookie jar an insecure cookie for the same domain could have been created, when it should have silently failed. This could have led to a desynchronization in expected results when reading from the secure cookie. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3hwv-6ww9-fwqx

больше 3 лет назад

PHP remote file inclusion vulnerability in url.php in FreshScripts Fresh Email Script 1.0 through 1.11 allows remote attackers to execute arbitrary PHP code via a URL in the tmp_sid parameter.

EPSS: Низкий
github логотип

GHSA-3hwq-9jq5-p7f9

больше 3 лет назад

uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows remote attackers to obtain sensitive information by calling the decodeURI function and leveraging "type confusion."

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3hwp-p2jw-j4xh

почти 2 года назад

Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3hwp-mf4v-qcwm

почти 4 года назад

Integer overflow in the LoadImage API of the USER32 Lib for Microsoft Windows allows remote attackers to execute arbitrary code via a .bmp, .cur, .ico or .ani file with a large image size field, which leads to a buffer overflow, aka the "Cursor and Icon Format Handling Vulnerability."

EPSS: Средний
github логотип

GHSA-3hwp-78x6-2274

больше 3 лет назад

There is a denial of service vulnerability in some versions of ManageOne. There is a logic error in the implementation of a function of a module. When the service pressure is heavy, there is a low probability that an exception may occur. Successful exploit may cause some services abnormal.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3hwm-xx77-96rq

больше 1 года назад

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 3.23.5 via the get_image_alt function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract either excerpt data or titles of private or password-protected posts.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3hwm-p7rr-jj9v

около 1 года назад

Rejected reason: Further investigation determines issue is not within scope of this CNA

EPSS: Низкий
github логотип

GHSA-3hwm-922r-47hw

почти 3 года назад

Stud42 vulnerable to denial of service

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3hwm-8mqp-2386

почти 3 года назад

In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3hwm-6pxc-3vcf

больше 3 лет назад

xhyve commit dfbe09b was discovered to contain a NULL pointer dereference via the component vi_pci_write(). This vulnerability allows attackers to cause a Denial of Service via unspecified vectors.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3hwm-4538-x9g2

10 месяцев назад

The Upsell Funnel Builder for WooCommerce plugin for WordPress is vulnerable to order manipulation in all versions up to, and including, 3.0.0. This is due to the plugin allowing the additional product ID and discount field to be manipulated prior to processing via the 'add_offer_in_cart' function. This makes it possible for unauthenticated attackers to arbitrarily update the product associated with any order bump, and arbitrarily update the discount applied to any order bump item, when adding it to the cart.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3hwj-p677-6rgg

больше 3 лет назад

Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Studio). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Data Integrator. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Data Integrator accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3hwj-48pj-369j

больше 3 лет назад

The Management Web Interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, and 7.1.x before 7.1.9 allows remote authenticated users to obtain sensitive information by leveraging incorrect permission validation, aka PAN-SA-2017-0013 and PAN-70541.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3hwj-3gj3-6grw

больше 3 лет назад

The lockout-recovery feature in the Security Configurator component in ICONICS GENESIS32 9.22 and earlier and BizViz 9.22 and earlier uses an improper encryption algorithm for generation of an authentication code, which allows local users to bypass intended access restrictions and obtain administrative access by predicting a challenge response.

EPSS: Низкий
github логотип

GHSA-3hwj-36x6-3356

больше 3 лет назад

The polkit_backend_action_pool_init function in polkitbackend/polkitbackendactionpool.c in PolicyKit (aka polkit) before 0.113 might allow local users to gain privileges via duplicate action IDs in action descriptions.

EPSS: Низкий
github логотип

GHSA-3hwg-mg48-rrmm

больше 3 лет назад

SQL injection vulnerability in the WP e-Commerce plugin before 3.8.7.6 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3hwf-33q9-r3w3

около 3 лет назад

tdpServer of TP-Link RE300 V1 improperly processes its input, which may allow an attacker to cause a denial-of-service (DoS) condition of the product's OneMesh function.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3hwc-rqwp-v36q

почти 2 года назад

Apache Solr can leak certain passwords due to System Property redaction logic inconsistencies

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3hwv-fr9j-3wjq

VLC media player 3.0.20 and earlier is vulnerable to denial of service through an integer overflow which could be triggered with a maliciously crafted mms stream (heap based overflow). If successful, a malicious third party could trigger either a crash of VLC or an arbitrary code execution with the target user's privileges.

CVSS3: 8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3hwv-cmwg-vxxj

When a secure cookie existed in the Firefox cookie jar an insecure cookie for the same domain could have been created, when it should have silently failed. This could have led to a desynchronization in expected results when reading from the secure cookie. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3hwv-6ww9-fwqx

PHP remote file inclusion vulnerability in url.php in FreshScripts Fresh Email Script 1.0 through 1.11 allows remote attackers to execute arbitrary PHP code via a URL in the tmp_sid parameter.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-3hwq-9jq5-p7f9

uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows remote attackers to obtain sensitive information by calling the decodeURI function and leveraging "type confusion."

CVSS3: 6.5
10%
Низкий
больше 3 лет назад
github логотип
GHSA-3hwp-p2jw-j4xh

Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-3hwp-mf4v-qcwm

Integer overflow in the LoadImage API of the USER32 Lib for Microsoft Windows allows remote attackers to execute arbitrary code via a .bmp, .cur, .ico or .ani file with a large image size field, which leads to a buffer overflow, aka the "Cursor and Icon Format Handling Vulnerability."

63%
Средний
почти 4 года назад
github логотип
GHSA-3hwp-78x6-2274

There is a denial of service vulnerability in some versions of ManageOne. There is a logic error in the implementation of a function of a module. When the service pressure is heavy, there is a low probability that an exception may occur. Successful exploit may cause some services abnormal.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3hwm-xx77-96rq

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 3.23.5 via the get_image_alt function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract either excerpt data or titles of private or password-protected posts.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-3hwm-p7rr-jj9v

Rejected reason: Further investigation determines issue is not within scope of this CNA

около 1 года назад
github логотип
GHSA-3hwm-922r-47hw

Stud42 vulnerable to denial of service

CVSS3: 7.5
почти 3 года назад
github логотип
GHSA-3hwm-8mqp-2386

In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-3hwm-6pxc-3vcf

xhyve commit dfbe09b was discovered to contain a NULL pointer dereference via the component vi_pci_write(). This vulnerability allows attackers to cause a Denial of Service via unspecified vectors.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3hwm-4538-x9g2

The Upsell Funnel Builder for WooCommerce plugin for WordPress is vulnerable to order manipulation in all versions up to, and including, 3.0.0. This is due to the plugin allowing the additional product ID and discount field to be manipulated prior to processing via the 'add_offer_in_cart' function. This makes it possible for unauthenticated attackers to arbitrarily update the product associated with any order bump, and arbitrarily update the discount applied to any order bump item, when adding it to the cart.

CVSS3: 5.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-3hwj-p677-6rgg

Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Studio). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Data Integrator. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Data Integrator accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3hwj-48pj-369j

The Management Web Interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, and 7.1.x before 7.1.9 allows remote authenticated users to obtain sensitive information by leveraging incorrect permission validation, aka PAN-SA-2017-0013 and PAN-70541.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3hwj-3gj3-6grw

The lockout-recovery feature in the Security Configurator component in ICONICS GENESIS32 9.22 and earlier and BizViz 9.22 and earlier uses an improper encryption algorithm for generation of an authentication code, which allows local users to bypass intended access restrictions and obtain administrative access by predicting a challenge response.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3hwj-36x6-3356

The polkit_backend_action_pool_init function in polkitbackend/polkitbackendactionpool.c in PolicyKit (aka polkit) before 0.113 might allow local users to gain privileges via duplicate action IDs in action descriptions.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3hwg-mg48-rrmm

SQL injection vulnerability in the WP e-Commerce plugin before 3.8.7.6 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3hwf-33q9-r3w3

tdpServer of TP-Link RE300 V1 improperly processes its input, which may allow an attacker to cause a denial-of-service (DoS) condition of the product's OneMesh function.

CVSS3: 5.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-3hwc-rqwp-v36q

Apache Solr can leak certain passwords due to System Property redaction logic inconsistencies

CVSS3: 7.5
3%
Низкий
почти 2 года назад

Уязвимостей на страницу