Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3hfw-x7gx-437c

около 4 лет назад

Path traversal in Matrix Synapse

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3hfw-hf6c-x95h

почти 4 года назад

Stack-based buffer overflow in the NetBackup bpcd daemon (bpcd.exe) in Symantec Veritas NetBackup 5.0 before 5.0_MP7, 5.1 before 5.1_MP6, and 6.0 before 6.0_MP4 allows remote attackers to execute arbitrary code via a long request with a malformed length prefix.

EPSS: Средний
github логотип

GHSA-3hfw-66ww-x4hj

почти 4 года назад

Buffer overflow in SIPfoundry sipXtapi released before 20060324 allows remote attackers to execute arbitrary code via a long CSeq field value in an INVITE message.

EPSS: Высокий
github логотип

GHSA-3hfv-3383-4hvp

больше 3 лет назад

A use-after-free in the mac80211 stack when parsing a multi-BSSID element in the Linux kernel 5.2 through 5.19.14 could be used by attackers (able to inject WLAN frames) to crash the kernel and potentially execute code.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3hfr-246f-6fxv

почти 2 года назад

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to leak memory from the vmx process.  

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3hfq-cx9j-923w

около 2 лет назад

Attacker can cause Kyverno user to unintentionally consume insecure image

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3hfp-wjpj-68wv

больше 3 лет назад

IBM DB2 9.7, 10.1, 10.5, and 11.1 libdb2e.so.1 is vulnerable to a stack based buffer overflow, caused by improper bounds checking which could allow an attacker to execute arbitrary code. IBM X-Force ID: 153316.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3hfm-rp5v-6w54

больше 3 лет назад

SQL Injection vulnerability in product_admin.php in atoms183 CMS 1.0, allows attackers to execute arbitrary commands via the Name, Fname, and ID parameters to search.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3hfm-p6g2-9fv7

больше 3 лет назад

A Incorrect Permission Assignment for Critical Resource vulnerability in skuba of SUSE CaaS Platform 4.5 allows local attackers to gain access to the kublet key. This issue affects: SUSE CaaS Platform 4.5 skuba versions prior to https://github.com/SUSE/skuba/pull/1416.

EPSS: Низкий
github логотип

GHSA-3hfm-c4w3-rfw4

2 месяца назад

A vulnerability was detected in itsourcecode Student Management System 1.0. This impacts an unknown function of the file /newcurriculm.php. Performing manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3hfj-wm5c-qv7r

больше 3 лет назад

A vulnerability has been identified in Spectrum Power™ 5 (All versions < v5.50 HF02). The web server could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into accessing a malicious link. User interaction is required for a successful exploitation. If deployed according to recommended system configuration, Siemens consideres the environmental vector as CR:L/IR:M/AR:H/MAV:A (4.1).

EPSS: Низкий
github логотип

GHSA-3hfj-vjmw-rjj4

почти 4 года назад

CRLF injection vulnerability in Serendipity before 0.7rc1 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the url parameter in (1) index.php and (2) exit.php, or (3) the HTTP Referer field in comment.php.

EPSS: Низкий
github логотип

GHSA-3hfj-qcvj-4hx8

12 месяцев назад

Leantime has Missing Authorization Check for Host Parameter

EPSS: Низкий
github логотип

GHSA-3hfj-pw8w-wj22

больше 3 лет назад

Open Solution Quick.Cart 5.0 allows remote attackers to obtain sensitive information via (1) a long string or (2) invalid characters in a cookie, which reveals the installation path in an error message.

EPSS: Низкий
github логотип

GHSA-3hfj-mrxp-x3v9

3 месяца назад

A NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the load() function of bin_dyldcache.c. Processing a crafted file can cause a segmentation fault and crash the program.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3hfj-59gc-vp5m

больше 3 лет назад

WebKit, as used in Apple iOS before 9.2.1, Safari before 9.0.3, and tvOS before 9.1.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1727.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3hfh-w64f-p273

больше 3 лет назад

Data race in extensions guest view in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3hfh-c9pr-r52q

больше 1 года назад

A vulnerability has been reported to affect Network & Virtual Switch. If exploited, the vulnerability could allow local authenticated administrators to gain access to and execute certain functions via unspecified vectors. We have already fixed the vulnerability in the following versions: QTS 5.1.8.2823 build 20240712 and later QuTS hero h5.1.8.2823 build 20240712 and later

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-3hff-6c4j-j2w5

больше 3 лет назад

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object in an Office document, as exploited in the wild with a "Sandworm" attack in June through October 2014, aka "Windows OLE Remote Code Execution Vulnerability."

CVSS3: 7.8
EPSS: Критический
github логотип

GHSA-3hfc-7w8c-chcm

больше 1 года назад

A vulnerability, which was classified as problematic, has been found in ClassCMS 4.8. Affected by this issue is some unknown functionality of the file /index.php/admin of the component Article Handler. The manipulation of the argument Title leads to basic cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 2.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3hfw-x7gx-437c

Path traversal in Matrix Synapse

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-3hfw-hf6c-x95h

Stack-based buffer overflow in the NetBackup bpcd daemon (bpcd.exe) in Symantec Veritas NetBackup 5.0 before 5.0_MP7, 5.1 before 5.1_MP6, and 6.0 before 6.0_MP4 allows remote attackers to execute arbitrary code via a long request with a malformed length prefix.

39%
Средний
почти 4 года назад
github логотип
GHSA-3hfw-66ww-x4hj

Buffer overflow in SIPfoundry sipXtapi released before 20060324 allows remote attackers to execute arbitrary code via a long CSeq field value in an INVITE message.

84%
Высокий
почти 4 года назад
github логотип
GHSA-3hfv-3383-4hvp

A use-after-free in the mac80211 stack when parsing a multi-BSSID element in the Linux kernel 5.2 through 5.19.14 could be used by attackers (able to inject WLAN frames) to crash the kernel and potentially execute code.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3hfr-246f-6fxv

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to leak memory from the vmx process.  

CVSS3: 7.1
4%
Низкий
почти 2 года назад
github логотип
GHSA-3hfq-cx9j-923w

Attacker can cause Kyverno user to unintentionally consume insecure image

CVSS3: 7.1
1%
Низкий
около 2 лет назад
github логотип
GHSA-3hfp-wjpj-68wv

IBM DB2 9.7, 10.1, 10.5, and 11.1 libdb2e.so.1 is vulnerable to a stack based buffer overflow, caused by improper bounds checking which could allow an attacker to execute arbitrary code. IBM X-Force ID: 153316.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3hfm-rp5v-6w54

SQL Injection vulnerability in product_admin.php in atoms183 CMS 1.0, allows attackers to execute arbitrary commands via the Name, Fname, and ID parameters to search.php.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3hfm-p6g2-9fv7

A Incorrect Permission Assignment for Critical Resource vulnerability in skuba of SUSE CaaS Platform 4.5 allows local attackers to gain access to the kublet key. This issue affects: SUSE CaaS Platform 4.5 skuba versions prior to https://github.com/SUSE/skuba/pull/1416.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3hfm-c4w3-rfw4

A vulnerability was detected in itsourcecode Student Management System 1.0. This impacts an unknown function of the file /newcurriculm.php. Performing manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used.

CVSS3: 7.3
0%
Низкий
2 месяца назад
github логотип
GHSA-3hfj-wm5c-qv7r

A vulnerability has been identified in Spectrum Power™ 5 (All versions < v5.50 HF02). The web server could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into accessing a malicious link. User interaction is required for a successful exploitation. If deployed according to recommended system configuration, Siemens consideres the environmental vector as CR:L/IR:M/AR:H/MAV:A (4.1).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3hfj-vjmw-rjj4

CRLF injection vulnerability in Serendipity before 0.7rc1 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the url parameter in (1) index.php and (2) exit.php, or (3) the HTTP Referer field in comment.php.

8%
Низкий
почти 4 года назад
github логотип
GHSA-3hfj-qcvj-4hx8

Leantime has Missing Authorization Check for Host Parameter

12 месяцев назад
github логотип
GHSA-3hfj-pw8w-wj22

Open Solution Quick.Cart 5.0 allows remote attackers to obtain sensitive information via (1) a long string or (2) invalid characters in a cookie, which reveals the installation path in an error message.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3hfj-mrxp-x3v9

A NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the load() function of bin_dyldcache.c. Processing a crafted file can cause a segmentation fault and crash the program.

CVSS3: 5.3
0%
Низкий
3 месяца назад
github логотип
GHSA-3hfj-59gc-vp5m

WebKit, as used in Apple iOS before 9.2.1, Safari before 9.0.3, and tvOS before 9.1.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1727.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3hfh-w64f-p273

Data race in extensions guest view in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 7.5
7%
Низкий
больше 3 лет назад
github логотип
GHSA-3hfh-c9pr-r52q

A vulnerability has been reported to affect Network & Virtual Switch. If exploited, the vulnerability could allow local authenticated administrators to gain access to and execute certain functions via unspecified vectors. We have already fixed the vulnerability in the following versions: QTS 5.1.8.2823 build 20240712 and later QuTS hero h5.1.8.2823 build 20240712 and later

CVSS3: 4.2
0%
Низкий
больше 1 года назад
github логотип
GHSA-3hff-6c4j-j2w5

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object in an Office document, as exploited in the wild with a "Sandworm" attack in June through October 2014, aka "Windows OLE Remote Code Execution Vulnerability."

CVSS3: 7.8
92%
Критический
больше 3 лет назад
github логотип
GHSA-3hfc-7w8c-chcm

A vulnerability, which was classified as problematic, has been found in ClassCMS 4.8. Affected by this issue is some unknown functionality of the file /index.php/admin of the component Article Handler. The manipulation of the argument Title leads to basic cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 2.4
0%
Низкий
больше 1 года назад

Уязвимостей на страницу