Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-3cv6-g432-57c7

больше 3 лет назад

IBM Security Guardium 10.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 124684.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3cv6-6qgh-wmgm

больше 3 лет назад

Multiple buffer overflows in fs/nfsd/nfs4xdr.c in the XDR implementation in the NFS server in the Linux kernel before 2.6.34-rc6 allow remote attackers to cause a denial of service (panic) or possibly execute arbitrary code via a crafted NFSv4 compound WRITE request, related to the read_buf and nfsd4_decode_compound functions.

EPSS: Низкий
github логотип

GHSA-3cv5-xp7r-mhvx

больше 3 лет назад

Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect confidentiality, related to Apache HTTP Server.

EPSS: Низкий
github логотип

GHSA-3cv5-x72m-qrqh

почти 4 года назад

chroot in Digital Ultrix 4.1 and 4.0 is insecurely installed, which allows local users to gain privileges.

EPSS: Низкий
github логотип

GHSA-3cv5-x4w9-vjq6

больше 3 лет назад

Cacti before 0.8.7f, as used in Red Hat High Performance Computing (HPC) Solution and other products, allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in (1) the FQDN field of a Device or (2) the Vertical Label field of a Graph Template.

EPSS: Низкий
github логотип

GHSA-3cv5-r4jh-v4pj

5 месяцев назад

In pfSense CE /usr/local/www/snort/snort_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related characters/strings before being used to check if a file exists. While the contents of the file cannot be read, the server reveals whether a file exists, which allows an attacker to enumerate files on the target. The attacker must be authenticated with at least "WebCfg - Services: Snort package" permissions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3cv5-m2hv-52mv

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the web framework in Cisco Prime Security Manager (aka PRSM) 9.2.1-2 and earlier allow remote attackers to inject arbitrary web script or HTML via a (1) Access Policies or (2) Device Summary Dashboard parameter, aka Bug ID CSCuq80661.

EPSS: Низкий
github логотип

GHSA-3cv5-693m-8vg4

больше 3 лет назад

Cisco IOS XR 5.1.1.K9SEC allows remote authenticated users to cause a denial of service (vty error, and SSH and TELNET outage) via a crafted disconnect action within an SSH session, aka Bug ID CSCul63127.

EPSS: Низкий
github логотип

GHSA-3cv4-xxv7-934q

больше 4 лет назад

Improper Verification of Cryptographic Signature in Apache Pulsar in TensorFlow

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-3cv4-wq55-4fr6

больше 3 лет назад

The Polo Video Gallery – Best wordpress video gallery plugin WordPress plugin through 1.2 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcode

EPSS: Низкий
github логотип

GHSA-3cv3-p9mg-jf6g

больше 3 лет назад

IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to obtain sensitive information via a crafted request, which reveals the full path in an error message.

EPSS: Низкий
github логотип

GHSA-3cv2-9pff-v434

11 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ntm custom-field-list-widget allows PHP Local File Inclusion. This issue affects custom-field-list-widget: from n/a through 1.5.1.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3crx-72mc-vg28

около 1 года назад

In Modem, there is a possible out of bonds write due to a mission bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00957388; Issue ID: MSV-1872.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3crw-xq5c-jr37

почти 4 года назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.37 and prior and 8.0.28 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-3crw-hq66-3456

около 2 лет назад

SQL injection vulnerability in Webkul Bundle Product 6.0.1 allows a remote attacker to execute arbitrary code via the id_product parameters in the UpdateProductQuantity function.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3crw-gpxv-2mm6

больше 3 лет назад

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.5 and iPadOS 14.5. A local user may be able to read kernel memory.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3crv-xrq6-c4hq

больше 3 лет назад

** DISPUTED ** Multiple integer overflows in the lzo1x_decompress_safe function in lib/lzo/lzo1x_decompress_safe.c in the LZO decompressor in the Linux kernel before 3.15.2 allow context-dependent attackers to cause a denial of service (memory corruption) via a crafted Literal Run. NOTE: the author of the LZO algorithms says "the Linux kernel is *not* affected; media hype."

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3crv-g23g-rwc9

больше 3 лет назад

Directory traversal vulnerability in substitute.bcl in the WebView CimWeb subsystem in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process Systems with CIMPLICITY, allows remote attackers to read arbitrary files via a crafted packet.

EPSS: Средний
github логотип

GHSA-3crr-vpcf-qqqv

больше 3 лет назад

In Joomla! before 3.8.2, a logic bug in com_fields exposed read-only information about a site's custom fields to unauthorized users.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3crr-m7mr-q7pc

почти 4 года назад

Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request, possibly triggering a buffer overflow.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3cv6-g432-57c7

IBM Security Guardium 10.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 124684.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3cv6-6qgh-wmgm

Multiple buffer overflows in fs/nfsd/nfs4xdr.c in the XDR implementation in the NFS server in the Linux kernel before 2.6.34-rc6 allow remote attackers to cause a denial of service (panic) or possibly execute arbitrary code via a crafted NFSv4 compound WRITE request, related to the read_buf and nfsd4_decode_compound functions.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-3cv5-xp7r-mhvx

Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect confidentiality, related to Apache HTTP Server.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3cv5-x72m-qrqh

chroot in Digital Ultrix 4.1 and 4.0 is insecurely installed, which allows local users to gain privileges.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3cv5-x4w9-vjq6

Cacti before 0.8.7f, as used in Red Hat High Performance Computing (HPC) Solution and other products, allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in (1) the FQDN field of a Device or (2) the Vertical Label field of a Graph Template.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-3cv5-r4jh-v4pj

In pfSense CE /usr/local/www/snort/snort_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related characters/strings before being used to check if a file exists. While the contents of the file cannot be read, the server reveals whether a file exists, which allows an attacker to enumerate files on the target. The attacker must be authenticated with at least "WebCfg - Services: Snort package" permissions.

CVSS3: 4.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-3cv5-m2hv-52mv

Multiple cross-site scripting (XSS) vulnerabilities in the web framework in Cisco Prime Security Manager (aka PRSM) 9.2.1-2 and earlier allow remote attackers to inject arbitrary web script or HTML via a (1) Access Policies or (2) Device Summary Dashboard parameter, aka Bug ID CSCuq80661.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3cv5-693m-8vg4

Cisco IOS XR 5.1.1.K9SEC allows remote authenticated users to cause a denial of service (vty error, and SSH and TELNET outage) via a crafted disconnect action within an SSH session, aka Bug ID CSCul63127.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3cv4-xxv7-934q

Improper Verification of Cryptographic Signature in Apache Pulsar in TensorFlow

CVSS3: 9.8
19%
Средний
больше 4 лет назад
github логотип
GHSA-3cv4-wq55-4fr6

The Polo Video Gallery – Best wordpress video gallery plugin WordPress plugin through 1.2 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcode

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3cv3-p9mg-jf6g

IBM InfoSphere Master Data Management Collaborative Edition 9.1, 10.1, 11.0, 11.3, and 11.4 before FP03 allows remote authenticated users to obtain sensitive information via a crafted request, which reveals the full path in an error message.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3cv2-9pff-v434

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ntm custom-field-list-widget allows PHP Local File Inclusion. This issue affects custom-field-list-widget: from n/a through 1.5.1.

CVSS3: 8.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-3crx-72mc-vg28

In Modem, there is a possible out of bonds write due to a mission bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00957388; Issue ID: MSV-1872.

CVSS3: 6.7
0%
Низкий
около 1 года назад
github логотип
GHSA-3crw-xq5c-jr37

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.37 and prior and 8.0.28 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-3crw-hq66-3456

SQL injection vulnerability in Webkul Bundle Product 6.0.1 allows a remote attacker to execute arbitrary code via the id_product parameters in the UpdateProductQuantity function.

CVSS3: 9.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-3crw-gpxv-2mm6

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.5 and iPadOS 14.5. A local user may be able to read kernel memory.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3crv-xrq6-c4hq

** DISPUTED ** Multiple integer overflows in the lzo1x_decompress_safe function in lib/lzo/lzo1x_decompress_safe.c in the LZO decompressor in the Linux kernel before 3.15.2 allow context-dependent attackers to cause a denial of service (memory corruption) via a crafted Literal Run. NOTE: the author of the LZO algorithms says "the Linux kernel is *not* affected; media hype."

CVSS3: 7.3
9%
Низкий
больше 3 лет назад
github логотип
GHSA-3crv-g23g-rwc9

Directory traversal vulnerability in substitute.bcl in the WebView CimWeb subsystem in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process Systems with CIMPLICITY, allows remote attackers to read arbitrary files via a crafted packet.

13%
Средний
больше 3 лет назад
github логотип
GHSA-3crr-vpcf-qqqv

In Joomla! before 3.8.2, a logic bug in com_fields exposed read-only information about a site's custom fields to unauthorized users.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3crr-m7mr-q7pc

Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request, possibly triggering a buffer overflow.

3%
Низкий
почти 4 года назад

Уязвимостей на страницу