Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 375

Количество 314 375

github логотип

GHSA-3h2q-4qw3-2f5h

больше 3 лет назад

IBM Content Navigator 2.0 and 3.0 is vulnerable to Comma Separated Value (CSV) Injection. An attacker could exploit this vulnerability to exploit other vulnerabilities in spreadsheet software. IBM X-Force ID: 137452.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3h2m-jjrw-87hw

больше 3 лет назад

The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 does not perform token comparison in constant time before determining if a debugging message should be logged, which allows remote attackers to guess the edit token and bypass CSRF protection via a timing attack, a different vulnerability than CVE-2015-8623.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3h2j-h4g8-5pmr

почти 4 года назад

An issue was discovered in mruby 1.4.1. There is a NULL pointer dereference in mrb_class_real because "class BasicObject" is not properly supported in class.c.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3h2j-95j8-599v

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Apache Solr Autocomplete module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving autocomplete results.

EPSS: Низкий
github логотип

GHSA-3h2h-xqr2-2jp7

почти 4 года назад

Cross-site Scripting (XSS) in Apache ActiveMQ Artemis

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3h2h-j4vg-8xm8

около 2 лет назад

An issue in Notion for macOS version 3.1.0 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments components.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3h2h-fwxh-x5w9

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Outlook Web Access in Microsoft Exchange Server 2010 SP2 and SP3 and 2013 Cumulative Update 2 and 3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "OWA XSS Vulnerability."

EPSS: Низкий
github логотип

GHSA-3h2g-8x7p-qmjq

почти 4 года назад

crontab by Paul Vixie uses predictable file names for a temporary file and does not properly ensure that the file is owned by the user executing the crontab -e command, which allows local users with write access to the crontab spool directory to execute arbitrary commands by creating world-writeable temporary files and modifying them while the victim is editing the file.

EPSS: Низкий
github логотип

GHSA-3h2g-4ppf-wwf9

больше 3 лет назад

chm2pdf 0.9 uses temporary files in directories with fixed names, which allows local users to cause a denial of service (chm2pdf failure) of other users by creating those directories ahead of time.

EPSS: Низкий
github логотип

GHSA-3h2f-w6h5-7wr8

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the nav_path function in lib/viewvc.py in ViewVC before 1.0.14 and 1.1.x before 1.1.26 allows remote attackers to inject arbitrary web script or HTML via the nav_data name.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3h2f-562g-hqwc

больше 2 лет назад

SonicOS post-authentication Stack-Based Buffer Overflow Vulnerability in the SSL VPN plainprefs.exp URL endpoint leads to a firewall crash.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3h2c-3fmg-pxf2

больше 3 лет назад

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to a targeted device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on an affected device.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3h29-6jm6-hw9v

больше 3 лет назад

In the permission declaration for com.google.android.providers.gsf.permission.WRITE_GSERVICES in AndroidManifest.xml, there is a possible permissions bypass. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-147247775

EPSS: Низкий
github логотип

GHSA-3h29-52vh-pqgr

больше 4 лет назад

Uncontrolled Resource Consumption in Apache Tika

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3h28-8mxg-rxfp

больше 3 лет назад

libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer overflow in the ReadImage function in input-bmp.c:353:25.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3h28-8c8j-44v8

6 месяцев назад

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted USD file may disclose memory contents.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3h28-663g-h6cx

11 месяцев назад

A vulnerability classified as critical was found in code-projects Blood Bank Management System 1.0. This vulnerability affects unknown code of the file /admin/admin_login.php of the component Admin Login Page. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3h28-545j-c6pv

почти 4 года назад

SQL injection vulnerability in listpics.asp in ASP ListPics 5.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.

EPSS: Низкий
github логотип

GHSA-3h27-2wg2-w59m

больше 3 лет назад

An issue has been found in PowerDNS Recursor versions 4.1.x before 4.1.9 where records in the answer section of responses received from authoritative servers with the AA flag not set were not properly validated, allowing an attacker to bypass DNSSEC validation.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3h26-w882-gmrp

больше 3 лет назад

Unspecified vulnerability in the FTP Server in Oracle Solaris 8, 9, 10, and 11 Express allows remote attackers to affect availability. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from a reliable researcher that this is an issue in the glob implementation in libc that allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3h2q-4qw3-2f5h

IBM Content Navigator 2.0 and 3.0 is vulnerable to Comma Separated Value (CSV) Injection. An attacker could exploit this vulnerability to exploit other vulnerabilities in spreadsheet software. IBM X-Force ID: 137452.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h2m-jjrw-87hw

The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 does not perform token comparison in constant time before determining if a debugging message should be logged, which allows remote attackers to guess the edit token and bypass CSRF protection via a timing attack, a different vulnerability than CVE-2015-8623.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h2j-h4g8-5pmr

An issue was discovered in mruby 1.4.1. There is a NULL pointer dereference in mrb_class_real because "class BasicObject" is not properly supported in class.c.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-3h2j-95j8-599v

Cross-site scripting (XSS) vulnerability in the Apache Solr Autocomplete module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving autocomplete results.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3h2h-xqr2-2jp7

Cross-site Scripting (XSS) in Apache ActiveMQ Artemis

CVSS3: 6.1
3%
Низкий
почти 4 года назад
github логотип
GHSA-3h2h-j4vg-8xm8

An issue in Notion for macOS version 3.1.0 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments components.

CVSS3: 9.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-3h2h-fwxh-x5w9

Cross-site scripting (XSS) vulnerability in Outlook Web Access in Microsoft Exchange Server 2010 SP2 and SP3 and 2013 Cumulative Update 2 and 3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "OWA XSS Vulnerability."

7%
Низкий
больше 3 лет назад
github логотип
GHSA-3h2g-8x7p-qmjq

crontab by Paul Vixie uses predictable file names for a temporary file and does not properly ensure that the file is owned by the user executing the crontab -e command, which allows local users with write access to the crontab spool directory to execute arbitrary commands by creating world-writeable temporary files and modifying them while the victim is editing the file.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3h2g-4ppf-wwf9

chm2pdf 0.9 uses temporary files in directories with fixed names, which allows local users to cause a denial of service (chm2pdf failure) of other users by creating those directories ahead of time.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h2f-w6h5-7wr8

Cross-site scripting (XSS) vulnerability in the nav_path function in lib/viewvc.py in ViewVC before 1.0.14 and 1.1.x before 1.1.26 allows remote attackers to inject arbitrary web script or HTML via the nav_data name.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3h2f-562g-hqwc

SonicOS post-authentication Stack-Based Buffer Overflow Vulnerability in the SSL VPN plainprefs.exp URL endpoint leads to a firewall crash.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3h2c-3fmg-pxf2

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to a targeted device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on an affected device.

CVSS3: 7.2
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3h29-6jm6-hw9v

In the permission declaration for com.google.android.providers.gsf.permission.WRITE_GSERVICES in AndroidManifest.xml, there is a possible permissions bypass. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-147247775

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h29-52vh-pqgr

Uncontrolled Resource Consumption in Apache Tika

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3h28-8mxg-rxfp

libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer overflow in the ReadImage function in input-bmp.c:353:25.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3h28-8c8j-44v8

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted USD file may disclose memory contents.

CVSS3: 5.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-3h28-663g-h6cx

A vulnerability classified as critical was found in code-projects Blood Bank Management System 1.0. This vulnerability affects unknown code of the file /admin/admin_login.php of the component Admin Login Page. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-3h28-545j-c6pv

SQL injection vulnerability in listpics.asp in ASP ListPics 5.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3h27-2wg2-w59m

An issue has been found in PowerDNS Recursor versions 4.1.x before 4.1.9 where records in the answer section of responses received from authoritative servers with the AA flag not set were not properly validated, allowing an attacker to bypass DNSSEC validation.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3h26-w882-gmrp

Unspecified vulnerability in the FTP Server in Oracle Solaris 8, 9, 10, and 11 Express allows remote attackers to affect availability. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from a reliable researcher that this is an issue in the glob implementation in libc that allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames.

6%
Низкий
больше 3 лет назад

Уязвимостей на страницу