Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 375

Количество 314 375

github логотип

GHSA-3hfj-qcvj-4hx8

12 месяцев назад

Leantime has Missing Authorization Check for Host Parameter

EPSS: Низкий
github логотип

GHSA-3hfj-pw8w-wj22

больше 3 лет назад

Open Solution Quick.Cart 5.0 allows remote attackers to obtain sensitive information via (1) a long string or (2) invalid characters in a cookie, which reveals the installation path in an error message.

EPSS: Низкий
github логотип

GHSA-3hfj-mrxp-x3v9

3 месяца назад

A NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the load() function of bin_dyldcache.c. Processing a crafted file can cause a segmentation fault and crash the program.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3hfj-59gc-vp5m

больше 3 лет назад

WebKit, as used in Apple iOS before 9.2.1, Safari before 9.0.3, and tvOS before 9.1.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1727.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3hfh-w64f-p273

больше 3 лет назад

Data race in extensions guest view in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3hfh-c9pr-r52q

больше 1 года назад

A vulnerability has been reported to affect Network & Virtual Switch. If exploited, the vulnerability could allow local authenticated administrators to gain access to and execute certain functions via unspecified vectors. We have already fixed the vulnerability in the following versions: QTS 5.1.8.2823 build 20240712 and later QuTS hero h5.1.8.2823 build 20240712 and later

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-3hff-6c4j-j2w5

больше 3 лет назад

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object in an Office document, as exploited in the wild with a "Sandworm" attack in June through October 2014, aka "Windows OLE Remote Code Execution Vulnerability."

CVSS3: 7.8
EPSS: Критический
github логотип

GHSA-3hfc-7w8c-chcm

больше 1 года назад

A vulnerability, which was classified as problematic, has been found in ClassCMS 4.8. Affected by this issue is some unknown functionality of the file /index.php/admin of the component Article Handler. The manipulation of the argument Title leads to basic cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-3hf9-x4q8-q4gg

больше 3 лет назад

Tenda AC21 V16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, function: formSetQosBand.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3hf8-r22c-289m

больше 3 лет назад

SmartRG SR506n 2.5.15 and SR510n 2.6.13 routers are vulnerable to Remote Code Execution (RCE) via the ping host feature.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-3hf8-m65w-793g

больше 3 лет назад

Adobe Flash Player versions 24.0.0.221 and earlier have an exploitable use after free vulnerability related to an interaction between the privacy user interface and the ActionScript 2 Camera object. Successful exploitation could lead to arbitrary code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3hf8-f5cj-vcfr

больше 3 лет назад

An issue was discovered on Humax Digital HG100R 2.0.6 devices. There is XSS on the 404 page.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3hf8-77g6-rmgm

больше 3 лет назад

Remote Development Extension for Visual Studio Code Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-3hf8-259h-577p

11 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: video: fbdev: cirrusfb: check pixclock to avoid divide by zero Do a sanity check on pixclock value to avoid divide by zero. If the pixclock value is zero, the cirrusfb driver will round up pixclock to get the derived frequency as close to maxclock as possible. Syzkaller reported a divide error in cirrusfb_check_pixclock. divide error: 0000 [#1] SMP KASAN PTI CPU: 0 PID: 14938 Comm: cirrusfb_test Not tainted 5.15.0-rc6 #1 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.11.0-2 RIP: 0010:cirrusfb_check_var+0x6f1/0x1260 Call Trace: fb_set_var+0x398/0xf90 do_fb_ioctl+0x4b8/0x6f0 fb_ioctl+0xeb/0x130 __x64_sys_ioctl+0x19d/0x220 do_syscall_64+0x3a/0x80 entry_SYSCALL_64_after_hwframe+0x44/0xae

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3hf7-wgc9-hq3w

больше 3 лет назад

The CairoTextureClientD3D9::BorrowDrawTarget function in the Direct3D 9 implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 reads data from uninitialized memory locations, which has unspecified impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-3hf7-p43g-vpv6

больше 3 лет назад

In s/qmail through 4.0.07, an active MitM can inject arbitrary plaintext commands into a STARTTLS encrypted session between an SMTP client and s/qmail. This allows e-mail messages and user credentials to be sent to the MitM attacker.

EPSS: Низкий
github логотип

GHSA-3hf6-v3rj-8h44

почти 4 года назад

The upload function in PHProjekt 2.0 through 3.1 does not properly verify certain variables related to uploaded data, which allows remote attackers to cause PHProjekt to process arbitrary files.

EPSS: Низкий
github логотип

GHSA-3hf6-f8ch-5869

около 2 лет назад

Cross-site Scripting in JFinalcms

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3hf6-9xf2-jh59

почти 4 года назад

Stack-based buffer overflow in the bsd_queue() function for lpq on Solaris 2.6 and 7 allows local users to gain root privilege.

EPSS: Низкий
github логотип

GHSA-3hf5-wj4j-gfv8

почти 4 года назад

Integer overflow in Apple Quicktime before 7.2 on Mac OS X 10.3.9 and 10.4.9 allows user-assisted remote attackers to execute arbitrary code via crafted (1) title and (2) author fields in an SMIL file, related to improper calculations for memory allocation.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3hfj-qcvj-4hx8

Leantime has Missing Authorization Check for Host Parameter

12 месяцев назад
github логотип
GHSA-3hfj-pw8w-wj22

Open Solution Quick.Cart 5.0 allows remote attackers to obtain sensitive information via (1) a long string or (2) invalid characters in a cookie, which reveals the installation path in an error message.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3hfj-mrxp-x3v9

A NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the load() function of bin_dyldcache.c. Processing a crafted file can cause a segmentation fault and crash the program.

CVSS3: 5.3
0%
Низкий
3 месяца назад
github логотип
GHSA-3hfj-59gc-vp5m

WebKit, as used in Apple iOS before 9.2.1, Safari before 9.0.3, and tvOS before 9.1.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1727.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3hfh-w64f-p273

Data race in extensions guest view in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 7.5
7%
Низкий
больше 3 лет назад
github логотип
GHSA-3hfh-c9pr-r52q

A vulnerability has been reported to affect Network & Virtual Switch. If exploited, the vulnerability could allow local authenticated administrators to gain access to and execute certain functions via unspecified vectors. We have already fixed the vulnerability in the following versions: QTS 5.1.8.2823 build 20240712 and later QuTS hero h5.1.8.2823 build 20240712 and later

CVSS3: 4.2
0%
Низкий
больше 1 года назад
github логотип
GHSA-3hff-6c4j-j2w5

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object in an Office document, as exploited in the wild with a "Sandworm" attack in June through October 2014, aka "Windows OLE Remote Code Execution Vulnerability."

CVSS3: 7.8
92%
Критический
больше 3 лет назад
github логотип
GHSA-3hfc-7w8c-chcm

A vulnerability, which was classified as problematic, has been found in ClassCMS 4.8. Affected by this issue is some unknown functionality of the file /index.php/admin of the component Article Handler. The manipulation of the argument Title leads to basic cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 2.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-3hf9-x4q8-q4gg

Tenda AC21 V16.03.08.15 is vulnerable to Buffer Overflow via /bin/httpd, function: formSetQosBand.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3hf8-r22c-289m

SmartRG SR506n 2.5.15 and SR510n 2.6.13 routers are vulnerable to Remote Code Execution (RCE) via the ping host feature.

CVSS3: 9.8
30%
Средний
больше 3 лет назад
github логотип
GHSA-3hf8-m65w-793g

Adobe Flash Player versions 24.0.0.221 and earlier have an exploitable use after free vulnerability related to an interaction between the privacy user interface and the ActionScript 2 Camera object. Successful exploitation could lead to arbitrary code execution.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3hf8-f5cj-vcfr

An issue was discovered on Humax Digital HG100R 2.0.6 devices. There is XSS on the 404 page.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3hf8-77g6-rmgm

Remote Development Extension for Visual Studio Code Remote Code Execution Vulnerability

CVSS3: 7.8
14%
Средний
больше 3 лет назад
github логотип
GHSA-3hf8-259h-577p

In the Linux kernel, the following vulnerability has been resolved: video: fbdev: cirrusfb: check pixclock to avoid divide by zero Do a sanity check on pixclock value to avoid divide by zero. If the pixclock value is zero, the cirrusfb driver will round up pixclock to get the derived frequency as close to maxclock as possible. Syzkaller reported a divide error in cirrusfb_check_pixclock. divide error: 0000 [#1] SMP KASAN PTI CPU: 0 PID: 14938 Comm: cirrusfb_test Not tainted 5.15.0-rc6 #1 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.11.0-2 RIP: 0010:cirrusfb_check_var+0x6f1/0x1260 Call Trace: fb_set_var+0x398/0xf90 do_fb_ioctl+0x4b8/0x6f0 fb_ioctl+0xeb/0x130 __x64_sys_ioctl+0x19d/0x220 do_syscall_64+0x3a/0x80 entry_SYSCALL_64_after_hwframe+0x44/0xae

CVSS3: 5.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-3hf7-wgc9-hq3w

The CairoTextureClientD3D9::BorrowDrawTarget function in the Direct3D 9 implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 reads data from uninitialized memory locations, which has unspecified impact and attack vectors.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3hf7-p43g-vpv6

In s/qmail through 4.0.07, an active MitM can inject arbitrary plaintext commands into a STARTTLS encrypted session between an SMTP client and s/qmail. This allows e-mail messages and user credentials to be sent to the MitM attacker.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3hf6-v3rj-8h44

The upload function in PHProjekt 2.0 through 3.1 does not properly verify certain variables related to uploaded data, which allows remote attackers to cause PHProjekt to process arbitrary files.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3hf6-f8ch-5869

Cross-site Scripting in JFinalcms

CVSS3: 5.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-3hf6-9xf2-jh59

Stack-based buffer overflow in the bsd_queue() function for lpq on Solaris 2.6 and 7 allows local users to gain root privilege.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3hf5-wj4j-gfv8

Integer overflow in Apple Quicktime before 7.2 on Mac OS X 10.3.9 and 10.4.9 allows user-assisted remote attackers to execute arbitrary code via crafted (1) title and (2) author fields in an SMIL file, related to improper calculations for memory allocation.

42%
Средний
почти 4 года назад

Уязвимостей на страницу