Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3hjj-hrqp-h46r

больше 3 лет назад

Certain NETGEAR devices are affected by CSRF. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JR6150 before 1.0.1.24, R6020 before 1.0.0.42, R6050 before 1.0.1.24, R6080 before 1.0.0.42, R6120 before 1.0.0.66, R6220 before 1.1.0.100, R6260 before 1.1.0.64, R6700v2 before 1.2.0.62, R6800 before 1.2.0.62, R6900v2 before 1.2.0.62, R7450 before 1.2.0.62, and WNR2020 before 1.1.0.62.

EPSS: Низкий
github логотип

GHSA-3hjj-hrcp-g8r3

больше 3 лет назад

Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that the scripting engine handles objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8649, CVE-2017-8649, CVE-2017-8660, CVE-2017-8729, CVE-2017-8738, CVE-2017-8740, CVE-2017-8741, CVE-2017-8748, CVE-2017-8752, CVE-2017-8753, CVE-2017-8756, and CVE-2017-11764.

CVSS3: 7.5
EPSS: Высокий
github логотип

GHSA-3hjj-h6rj-vfvf

больше 3 лет назад

The Discussions sub module in the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal allows remote authenticated users with "access content" permissions to modify arbitrary nodes by leveraging improper access checks on unspecified ajax callbacks.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3hjh-r8jh-f6p4

почти 4 года назад

Directory traversal vulnerability in the VJDEO (com_vjdeo) component 1.0 and 1.0.1 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-3hjh-p587-3c92

больше 2 лет назад

A vulnerability classified as problematic has been found in Bug Finder MineStack 1.0. This affects an unknown part of the file /user/ticket/create of the component Ticket Handler. The manipulation of the argument message leads to cross site scripting. It is possible to initiate the attack remotely. The identifier VDB-235161 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-3hjh-jh2h-vrg6

больше 1 года назад

Denial of service in langchain-community

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-3hjh-cjx8-8c83

6 месяцев назад

A flaw was found in the Linux kernel's ksmbd component. A memory leak can occur if a client sends a session setup request with an unknown NTLMSSP message type, potentially leading to resource exhaustion.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3hjh-9vcg-w788

больше 3 лет назад

libautotrace.a in AutoTrace 0.31.1 has a "cannot be represented in type int" issue in input-bmp.c:309:7.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3hjh-72vp-2mx6

больше 3 лет назад

The web interface in BitTorrent allows remote attackers to execute arbitrary commands by leveraging knowledge of the pairing values and a crafted request to port 10000.

EPSS: Низкий
github логотип

GHSA-3hjh-5hgx-f5wh

почти 3 года назад

Path traversal vulnerability in glance

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3hjh-36cf-mgj5

6 месяцев назад

Improper array index verification vulnerability in the audio codec module. Impact: Successful exploitation of this vulnerability may affect the audio decoding function.

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-3hjg-vc7r-rcrw

почти 4 года назад

Denial of Service vulnerability in @podium/layout and @podium/proxy

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3hjg-cghv-22ww

почти 3 года назад

org.xwiki.platform:xwiki-platform-attachment-ui vulnerable to Code Injection

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-3hjg-c8jc-c68f

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Invision Power Board 2.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via an IFRAME tag in the signature.

EPSS: Низкий
github логотип

GHSA-3hjf-m6vc-vh7h

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: btrfs: don't BUG_ON on ENOMEM from btrfs_lookup_extent_info() in walk_down_proc() We handle errors here properly, ENOMEM isn't fatal, return the error.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3hjf-h43w-9frf

почти 2 года назад

PDF-XChange Editor Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-20891.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-3hjc-gv2m-96gh

больше 2 лет назад

Windows SMB Witness Service Security Feature Bypass Vulnerability

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3hj9-v3ch-6rc4

больше 3 лет назад

In __wlan_hdd_cfg80211_vendor_scan(), a buffer overwrite can potentially occur in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3hj8-7626-3gc8

больше 3 лет назад

Buffer overflow vulnerability in Core FTP Server v1.2 Build 583, via a crafted username.

EPSS: Низкий
github логотип

GHSA-3hj7-rw79-jh5m

3 месяца назад

Improper locking vulnerability in Softing Industrial Automation GmbH gateways allows infected memory and/or resource leak exposure.This issue affects smartLink HW-PN: from 1.02 through 1.03 smartLink HW-DP: 1.31

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3hjj-hrqp-h46r

Certain NETGEAR devices are affected by CSRF. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JR6150 before 1.0.1.24, R6020 before 1.0.0.42, R6050 before 1.0.1.24, R6080 before 1.0.0.42, R6120 before 1.0.0.66, R6220 before 1.1.0.100, R6260 before 1.1.0.64, R6700v2 before 1.2.0.62, R6800 before 1.2.0.62, R6900v2 before 1.2.0.62, R7450 before 1.2.0.62, and WNR2020 before 1.1.0.62.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3hjj-hrcp-g8r3

Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that the scripting engine handles objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8649, CVE-2017-8649, CVE-2017-8660, CVE-2017-8729, CVE-2017-8738, CVE-2017-8740, CVE-2017-8741, CVE-2017-8748, CVE-2017-8752, CVE-2017-8753, CVE-2017-8756, and CVE-2017-11764.

CVSS3: 7.5
77%
Высокий
больше 3 лет назад
github логотип
GHSA-3hjj-h6rj-vfvf

The Discussions sub module in the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal allows remote authenticated users with "access content" permissions to modify arbitrary nodes by leveraging improper access checks on unspecified ajax callbacks.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3hjh-r8jh-f6p4

Directory traversal vulnerability in the VJDEO (com_vjdeo) component 1.0 and 1.0.1 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.

7%
Низкий
почти 4 года назад
github логотип
GHSA-3hjh-p587-3c92

A vulnerability classified as problematic has been found in Bug Finder MineStack 1.0. This affects an unknown part of the file /user/ticket/create of the component Ticket Handler. The manipulation of the argument message leads to cross site scripting. It is possible to initiate the attack remotely. The identifier VDB-235161 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3hjh-jh2h-vrg6

Denial of service in langchain-community

CVSS3: 4.2
0%
Низкий
больше 1 года назад
github логотип
GHSA-3hjh-cjx8-8c83

A flaw was found in the Linux kernel's ksmbd component. A memory leak can occur if a client sends a session setup request with an unknown NTLMSSP message type, potentially leading to resource exhaustion.

CVSS3: 5.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-3hjh-9vcg-w788

libautotrace.a in AutoTrace 0.31.1 has a "cannot be represented in type int" issue in input-bmp.c:309:7.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3hjh-72vp-2mx6

The web interface in BitTorrent allows remote attackers to execute arbitrary commands by leveraging knowledge of the pairing values and a crafted request to port 10000.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3hjh-5hgx-f5wh

Path traversal vulnerability in glance

CVSS3: 6.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-3hjh-36cf-mgj5

Improper array index verification vulnerability in the audio codec module. Impact: Successful exploitation of this vulnerability may affect the audio decoding function.

CVSS3: 4.2
0%
Низкий
6 месяцев назад
github логотип
GHSA-3hjg-vc7r-rcrw

Denial of Service vulnerability in @podium/layout and @podium/proxy

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-3hjg-cghv-22ww

org.xwiki.platform:xwiki-platform-attachment-ui vulnerable to Code Injection

CVSS3: 8.8
16%
Средний
почти 3 года назад
github логотип
GHSA-3hjg-c8jc-c68f

Cross-site scripting (XSS) vulnerability in Invision Power Board 2.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via an IFRAME tag in the signature.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3hjf-m6vc-vh7h

In the Linux kernel, the following vulnerability has been resolved: btrfs: don't BUG_ON on ENOMEM from btrfs_lookup_extent_info() in walk_down_proc() We handle errors here properly, ENOMEM isn't fatal, return the error.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3hjf-h43w-9frf

PDF-XChange Editor Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-20891.

CVSS3: 3.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-3hjc-gv2m-96gh

Windows SMB Witness Service Security Feature Bypass Vulnerability

CVSS3: 7.1
2%
Низкий
больше 2 лет назад
github логотип
GHSA-3hj9-v3ch-6rc4

In __wlan_hdd_cfg80211_vendor_scan(), a buffer overwrite can potentially occur in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3hj8-7626-3gc8

Buffer overflow vulnerability in Core FTP Server v1.2 Build 583, via a crafted username.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3hj7-rw79-jh5m

Improper locking vulnerability in Softing Industrial Automation GmbH gateways allows infected memory and/or resource leak exposure.This issue affects smartLink HW-PN: from 1.02 through 1.03 smartLink HW-DP: 1.31

0%
Низкий
3 месяца назад

Уязвимостей на страницу