Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-3f66-9wgv-7rw2

около 3 лет назад

An OS command injection vulnerability allows admins to execute code via SSL VPN configuration uploads in Sophos Firewall older than version 19.5 GA.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3f65-pmph-3762

больше 3 лет назад

An issue was discovered in JerryScript 1.0. There is a heap-based buffer over-read in the lit_read_code_unit_from_hex function via a RegExp("[\\u0") payload, related to re_parse_char_class in parser/regexp/re-parser.c.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3f65-m234-9mxr

больше 1 года назад

github.com/huandu/facebook may expose access_token in error message.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-3f65-5prq-693p

больше 3 лет назад

The "encrypt wallet" feature in wxBitcoin and bitcoind 0.4.x before 0.4.1, and 0.5.0rc, does not properly interact with the deletion functionality of BSDDB, which allows context-dependent attackers to obtain unencrypted private keys from Bitcoin wallet files by bypassing the BSDDB interface and reading entries that are marked for deletion.

EPSS: Низкий
github логотип

GHSA-3f64-v74g-7p75

около 1 года назад

A vulnerability was found in PHPGurukul Maid Hiring Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/search-booking-request.php. The manipulation of the argument searchdata leads to cross site scripting. The attack may be launched remotely.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-3f63-w59m-x8ff

больше 2 лет назад

cashIT! - serving solutions. Devices from "PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH" to 03.A06rks 2023.02.37 are affected by an unauthenticated remote code execution vulnerability. This vulnerability can be triggered by an HTTP endpoint exposed to the network.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3f63-vqp6-r5p2

больше 3 лет назад

The Ignite Realtime Smack XMPP API, as used in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0, allows remote configured XMPP servers to execute arbitrary Java code via serialized data in an XMPP message.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3f63-hfp8-52jq

около 2 лет назад

Arbitrary Code Execution in Pillow

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3f63-37gm-w4qp

больше 3 лет назад

The World of Tanks Assistant (aka ru.worldoftanks.mobile) application 1.7.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-3f62-5j9w-457w

больше 3 лет назад

A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.3. An application may be able to read restricted memory.

EPSS: Низкий
github логотип

GHSA-3f62-5j79-h47w

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Anshul Labs Mobile Address Bar Changer plugin <= 3.0 versions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3f5w-q39v-gmmh

почти 4 года назад

The JavaScript engine in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) js_LeaveSharpObject, (2) ParseXMLSource, and (3) a certain assertion in jsinterp.c; and other vectors.

EPSS: Средний
github логотип

GHSA-3f5w-779w-6xpc

почти 4 года назад

support/dispatch.cgi in SiteScape Forum allows remote attackers to execute arbitrary TCL code via code separator characters in the query string.

EPSS: Средний
github логотип

GHSA-3f5w-744p-v66w

4 месяца назад

Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL. The relationship between parameter and assigned identifier is 'l, demo, demo2, TNTLOGIN, UO and SuppConn' parameters in '/clt/LOGINFRM_MOL.ASP'.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3f5v-f3mc-6rj8

4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: drivers/perf: hisi: Don't migrate perf to the CPU going to teardown The driver needs to migrate the perf context if the current using CPU going to teardown. By the time calling the cpuhp::teardown() callback the cpu_online_mask() hasn't updated yet and still includes the CPU going to teardown. In current driver's implementation we may migrate the context to the teardown CPU and leads to the below calltrace: ... [ 368.104662][ T932] task:cpuhp/0 state:D stack: 0 pid: 15 ppid: 2 flags:0x00000008 [ 368.113699][ T932] Call trace: [ 368.116834][ T932] __switch_to+0x7c/0xbc [ 368.120924][ T932] __schedule+0x338/0x6f0 [ 368.125098][ T932] schedule+0x50/0xe0 [ 368.128926][ T932] schedule_preempt_disabled+0x18/0x24 [ 368.134229][ T932] __mutex_lock.constprop.0+0x1d4/0x5dc [ 368.139617][ T932] __mutex_lock_slowpath+0x1c/0x30 [ 368.144573][ T932] mutex_lock+0x50/0x60 [ 368.148579][...

EPSS: Низкий
github логотип

GHSA-3f5v-6r4g-mx23

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Remove direct link to net_device Do not manage a per device direct link to net_device. Rely on associated ib_devices net_device management, not doubling the effort locally. A badly managed local link to net_device was causing a 'KASAN: slab-use-after-free' exception during siw_query_port() call.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3f5r-xjp9-9xrp

больше 3 лет назад

A CWE-248 Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause a denial of Service when sending invalid debug parameters to the controller over Modbus.

EPSS: Низкий
github логотип

GHSA-3f5r-wqg2-6x74

больше 3 лет назад

An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. The vulnerability is caused by the computation that writes data past the end of the intended buffer; the computation is part of the JavaScript API related to color conversion. An attacker can potentially leverage the vulnerability to corrupt sensitive data or execute arbitrary code.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3f5r-vp32-5ghx

больше 2 лет назад

Auth. (subscriber+) Stored Cross-Site Scripting') vulnerability in Plainware Locatoraid Store Locator plugin <= 3.9.18 versions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3f5r-8cpv-jgc3

больше 3 лет назад

Johnson & Johnson Animas OneTouch Ping devices allow remote attackers to bypass authentication via replay attacks.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3f66-9wgv-7rw2

An OS command injection vulnerability allows admins to execute code via SSL VPN configuration uploads in Sophos Firewall older than version 19.5 GA.

CVSS3: 7.2
0%
Низкий
около 3 лет назад
github логотип
GHSA-3f65-pmph-3762

An issue was discovered in JerryScript 1.0. There is a heap-based buffer over-read in the lit_read_code_unit_from_hex function via a RegExp("[\\u0") payload, related to re_parse_char_class in parser/regexp/re-parser.c.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3f65-m234-9mxr

github.com/huandu/facebook may expose access_token in error message.

CVSS3: 3.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-3f65-5prq-693p

The "encrypt wallet" feature in wxBitcoin and bitcoind 0.4.x before 0.4.1, and 0.5.0rc, does not properly interact with the deletion functionality of BSDDB, which allows context-dependent attackers to obtain unencrypted private keys from Bitcoin wallet files by bypassing the BSDDB interface and reading entries that are marked for deletion.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3f64-v74g-7p75

A vulnerability was found in PHPGurukul Maid Hiring Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/search-booking-request.php. The manipulation of the argument searchdata leads to cross site scripting. The attack may be launched remotely.

CVSS3: 2.4
0%
Низкий
около 1 года назад
github логотип
GHSA-3f63-w59m-x8ff

cashIT! - serving solutions. Devices from "PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH" to 03.A06rks 2023.02.37 are affected by an unauthenticated remote code execution vulnerability. This vulnerability can be triggered by an HTTP endpoint exposed to the network.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3f63-vqp6-r5p2

The Ignite Realtime Smack XMPP API, as used in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0, allows remote configured XMPP servers to execute arbitrary Java code via serialized data in an XMPP message.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3f63-hfp8-52jq

Arbitrary Code Execution in Pillow

CVSS3: 8.1
1%
Низкий
около 2 лет назад
github логотип
GHSA-3f63-37gm-w4qp

The World of Tanks Assistant (aka ru.worldoftanks.mobile) application 1.7.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3f62-5j9w-457w

A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.3. An application may be able to read restricted memory.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3f62-5j79-h47w

Cross-Site Request Forgery (CSRF) vulnerability in Anshul Labs Mobile Address Bar Changer plugin <= 3.0 versions.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3f5w-q39v-gmmh

The JavaScript engine in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) js_LeaveSharpObject, (2) ParseXMLSource, and (3) a certain assertion in jsinterp.c; and other vectors.

10%
Средний
почти 4 года назад
github логотип
GHSA-3f5w-779w-6xpc

support/dispatch.cgi in SiteScape Forum allows remote attackers to execute arbitrary TCL code via code separator characters in the query string.

13%
Средний
почти 4 года назад
github логотип
GHSA-3f5w-744p-v66w

Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL. The relationship between parameter and assigned identifier is 'l, demo, demo2, TNTLOGIN, UO and SuppConn' parameters in '/clt/LOGINFRM_MOL.ASP'.

CVSS3: 6.1
0%
Низкий
4 месяца назад
github логотип
GHSA-3f5v-f3mc-6rj8

In the Linux kernel, the following vulnerability has been resolved: drivers/perf: hisi: Don't migrate perf to the CPU going to teardown The driver needs to migrate the perf context if the current using CPU going to teardown. By the time calling the cpuhp::teardown() callback the cpu_online_mask() hasn't updated yet and still includes the CPU going to teardown. In current driver's implementation we may migrate the context to the teardown CPU and leads to the below calltrace: ... [ 368.104662][ T932] task:cpuhp/0 state:D stack: 0 pid: 15 ppid: 2 flags:0x00000008 [ 368.113699][ T932] Call trace: [ 368.116834][ T932] __switch_to+0x7c/0xbc [ 368.120924][ T932] __schedule+0x338/0x6f0 [ 368.125098][ T932] schedule+0x50/0xe0 [ 368.128926][ T932] schedule_preempt_disabled+0x18/0x24 [ 368.134229][ T932] __mutex_lock.constprop.0+0x1d4/0x5dc [ 368.139617][ T932] __mutex_lock_slowpath+0x1c/0x30 [ 368.144573][ T932] mutex_lock+0x50/0x60 [ 368.148579][...

0%
Низкий
4 месяца назад
github логотип
GHSA-3f5v-6r4g-mx23

In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Remove direct link to net_device Do not manage a per device direct link to net_device. Rely on associated ib_devices net_device management, not doubling the effort locally. A badly managed local link to net_device was causing a 'KASAN: slab-use-after-free' exception during siw_query_port() call.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-3f5r-xjp9-9xrp

A CWE-248 Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause a denial of Service when sending invalid debug parameters to the controller over Modbus.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-3f5r-wqg2-6x74

An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. The vulnerability is caused by the computation that writes data past the end of the intended buffer; the computation is part of the JavaScript API related to color conversion. An attacker can potentially leverage the vulnerability to corrupt sensitive data or execute arbitrary code.

CVSS3: 8.8
4%
Низкий
больше 3 лет назад
github логотип
GHSA-3f5r-vp32-5ghx

Auth. (subscriber+) Stored Cross-Site Scripting') vulnerability in Plainware Locatoraid Store Locator plugin <= 3.9.18 versions.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3f5r-8cpv-jgc3

Johnson & Johnson Animas OneTouch Ping devices allow remote attackers to bypass authentication via replay attacks.

CVSS3: 9.8
3%
Низкий
больше 3 лет назад

Уязвимостей на страницу