Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 375

Количество 314 375

github логотип

GHSA-3h53-6977-c549

больше 3 лет назад

Microsoft graphics in Windows 7 SP1 and Windows Server 2008 SP2 and R2 SP1 allows an attacker to potentially read data that was not intended to be disclosed due to the way that the Microsoft Windows Embedded OpenType (EOT) font engine parses specially crafted embedded fonts, aka "Windows EOT Font Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-11832.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3h52-vv68-p6m9

больше 2 лет назад

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Joost de Valk Enhanced WP Contact Form plugin <= 2.2.3 versions.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3h52-fhpg-8fqw

больше 3 лет назад

An issue was discovered in libgpac.a in GPAC before 0.8.0, as demonstrated by MP4Box. It contains an invalid pointer dereference in gf_list_count in utils/list.c that can cause a denial of service via a crafted MP4 file.

EPSS: Низкий
github логотип

GHSA-3h52-269p-cp9r

8 месяцев назад

Information exposure in Next.js dev server due to lack of origin verification

EPSS: Низкий
github логотип

GHSA-3h4x-jrvr-p38w

больше 3 лет назад

An error in the URL handler Bosch IP cameras may lead to a reflected cross site scripting (XSS) in the web-based interface. An attacker with knowledge of the camera address can send a crafted link to a user, which will execute javascript code in the context of the user.

EPSS: Низкий
github логотип

GHSA-3h4v-p542-7xmc

9 месяцев назад

IXON VPN Client before 1.4.4 on Windows allows Local Privilege Escalation to SYSTEM because there is code execution from a configuration file that can be controlled by a low-privileged user. There is a race condition in which a temporary configuration file, in a world-writable directory, can be overwritten.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3h4v-m4g6-c2v8

больше 3 лет назад

Heap buffer overflow in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific input into DevTools.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3h4v-5rmg-5m36

6 месяцев назад

A vulnerability, which was classified as problematic, was found in Open5GS up to 2.7.5. Affected is the function gmm_state_de_registered/gmm_state_exception of the file src/amf/gmm-sm.c of the component AMF. The manipulation leads to denial of service. It is possible to launch the attack remotely. Upgrading to version 2.7.6 is able to address this issue. The name of the patch is 1f30edac27f69f61cff50162e980fe58fdeb30ca. It is recommended to upgrade the affected component.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3h4r-x85w-hcrm

почти 4 года назад

A Process Control vulnerability in ProductAgentUI.exe as used in Bitdefender Antivirus Plus allows an attacker to tamper with product settings via a specially crafted DLL file. This issue affects: Bitdefender Antivirus Plus versions prior to 24.0.26.136. Bitdefender Internet Security versions prior to 24.0.26.136. Bitdefender Total Security versions prior to 24.0.26.136.

EPSS: Низкий
github логотип

GHSA-3h4r-pjv6-cph9

больше 6 лет назад

RubyGems Escape sequence injection vulnerability in api response handling

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3h4r-h95r-47jc

больше 3 лет назад

Integer signedness error in the virtio_net_load function in hw/net/virtio-net.c in QEMU 1.x before 1.7.2 allows remote attackers to execute arbitrary code via a crafted savevm image, which triggers a buffer overflow.

EPSS: Низкий
github логотип

GHSA-3h4r-2q6q-wfr8

больше 1 года назад

VMware Cloud Director Availability contains an HTML injection vulnerability. A malicious actor with network access to VMware Cloud Director Availability can craft malicious HTML tags to execute within replication tasks.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-3h4q-7386-ff6m

больше 3 лет назад

IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 176475.

EPSS: Низкий
github логотип

GHSA-3h4p-v99m-68x5

почти 4 года назад

SQL injection vulnerability in the Diocese of Portsmouth Database (pd_diocesedatabase) extension before 0.7.13 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3h4p-g442-4q4v

около 1 года назад

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3h4m-m55v-gx4m

больше 2 лет назад

Apache Airflow Improper Input Validation vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3h4j-qhvh-q69x

больше 3 лет назад

OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag deletion function.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3h4h-w66g-8c4g

почти 4 года назад

Outlook in Microsoft Office for Mac 2008 before 12.3.6 and Office for Mac 2011 before 14.3.2 allows remote attackers to trigger access to a remote URL and consequently confirm the rendering of an HTML e-mail message by including unspecified HTML5 elements and leveraging the installation of a WebKit browser on the victim's machine, aka "Unintended Content Loading Vulnerability."

EPSS: Средний
github логотип

GHSA-3h4h-g6p9-v72m

11 месяцев назад

The API used to interact with documents in the application contains two endpoints with a flaw that allows an authenticated attacker to write a file with controlled contents to an arbitrary location on the underlying file system. This can be used to facilitate RCE. An account with ‘read’ and ‘write’ privileges on at least one existing document in the application is required to exploit the vulnerability. Exploitation of this vulnerability would allow an attacker to run commands of their choosing on the underlying operating system of the web server running LogicalDOC.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3h4g-vcc2-xxf3

9 месяцев назад

A vulnerability in the Cloud Connect component of Cisco Unified Contact Center Enterprise (CCE) could allow an unauthenticated, remote attacker to read and modify data on an affected device. This vulnerability is due to a lack of proper authentication controls. An attacker could exploit this vulnerability by sending crafted TCP data to a specific port on an affected device. A successful exploit could allow the attacker to read or modify data on the affected device.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3h53-6977-c549

Microsoft graphics in Windows 7 SP1 and Windows Server 2008 SP2 and R2 SP1 allows an attacker to potentially read data that was not intended to be disclosed due to the way that the Microsoft Windows Embedded OpenType (EOT) font engine parses specially crafted embedded fonts, aka "Windows EOT Font Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-11832.

CVSS3: 5.5
3%
Низкий
больше 3 лет назад
github логотип
GHSA-3h52-vv68-p6m9

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Joost de Valk Enhanced WP Contact Form plugin <= 2.2.3 versions.

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3h52-fhpg-8fqw

An issue was discovered in libgpac.a in GPAC before 0.8.0, as demonstrated by MP4Box. It contains an invalid pointer dereference in gf_list_count in utils/list.c that can cause a denial of service via a crafted MP4 file.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h52-269p-cp9r

Information exposure in Next.js dev server due to lack of origin verification

0%
Низкий
8 месяцев назад
github логотип
GHSA-3h4x-jrvr-p38w

An error in the URL handler Bosch IP cameras may lead to a reflected cross site scripting (XSS) in the web-based interface. An attacker with knowledge of the camera address can send a crafted link to a user, which will execute javascript code in the context of the user.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h4v-p542-7xmc

IXON VPN Client before 1.4.4 on Windows allows Local Privilege Escalation to SYSTEM because there is code execution from a configuration file that can be controlled by a low-privileged user. There is a race condition in which a temporary configuration file, in a world-writable directory, can be overwritten.

CVSS3: 8.1
0%
Низкий
9 месяцев назад
github логотип
GHSA-3h4v-m4g6-c2v8

Heap buffer overflow in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific input into DevTools.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3h4v-5rmg-5m36

A vulnerability, which was classified as problematic, was found in Open5GS up to 2.7.5. Affected is the function gmm_state_de_registered/gmm_state_exception of the file src/amf/gmm-sm.c of the component AMF. The manipulation leads to denial of service. It is possible to launch the attack remotely. Upgrading to version 2.7.6 is able to address this issue. The name of the patch is 1f30edac27f69f61cff50162e980fe58fdeb30ca. It is recommended to upgrade the affected component.

CVSS3: 5.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-3h4r-x85w-hcrm

A Process Control vulnerability in ProductAgentUI.exe as used in Bitdefender Antivirus Plus allows an attacker to tamper with product settings via a specially crafted DLL file. This issue affects: Bitdefender Antivirus Plus versions prior to 24.0.26.136. Bitdefender Internet Security versions prior to 24.0.26.136. Bitdefender Total Security versions prior to 24.0.26.136.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3h4r-pjv6-cph9

RubyGems Escape sequence injection vulnerability in api response handling

CVSS3: 7.5
0%
Низкий
больше 6 лет назад
github логотип
GHSA-3h4r-h95r-47jc

Integer signedness error in the virtio_net_load function in hw/net/virtio-net.c in QEMU 1.x before 1.7.2 allows remote attackers to execute arbitrary code via a crafted savevm image, which triggers a buffer overflow.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-3h4r-2q6q-wfr8

VMware Cloud Director Availability contains an HTML injection vulnerability. A malicious actor with network access to VMware Cloud Director Availability can craft malicious HTML tags to execute within replication tasks.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-3h4q-7386-ff6m

IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 176475.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h4p-v99m-68x5

SQL injection vulnerability in the Diocese of Portsmouth Database (pd_diocesedatabase) extension before 0.7.13 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3h4p-g442-4q4v

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS3: 4.8
0%
Низкий
около 1 года назад
github логотип
GHSA-3h4m-m55v-gx4m

Apache Airflow Improper Input Validation vulnerability

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3h4j-qhvh-q69x

OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the tag_id variable in the Tag deletion function.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h4h-w66g-8c4g

Outlook in Microsoft Office for Mac 2008 before 12.3.6 and Office for Mac 2011 before 14.3.2 allows remote attackers to trigger access to a remote URL and consequently confirm the rendering of an HTML e-mail message by including unspecified HTML5 elements and leveraging the installation of a WebKit browser on the victim's machine, aka "Unintended Content Loading Vulnerability."

29%
Средний
почти 4 года назад
github логотип
GHSA-3h4h-g6p9-v72m

The API used to interact with documents in the application contains two endpoints with a flaw that allows an authenticated attacker to write a file with controlled contents to an arbitrary location on the underlying file system. This can be used to facilitate RCE. An account with ‘read’ and ‘write’ privileges on at least one existing document in the application is required to exploit the vulnerability. Exploitation of this vulnerability would allow an attacker to run commands of their choosing on the underlying operating system of the web server running LogicalDOC.

CVSS3: 8.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-3h4g-vcc2-xxf3

A vulnerability in the Cloud Connect component of Cisco Unified Contact Center Enterprise (CCE) could allow an unauthenticated, remote attacker to read and modify data on an affected device. This vulnerability is due to a lack of proper authentication controls. An attacker could exploit this vulnerability by sending crafted TCP data to a specific port on an affected device. A successful exploit could allow the attacker to read or modify data on the affected device.

CVSS3: 6.5
0%
Низкий
9 месяцев назад

Уязвимостей на страницу