Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3g9w-ghrc-hc72

больше 3 лет назад

In ARM mbed TLS before 2.7.0, there is a bounds-check bypass through an integer overflow in PSK identity parsing in the ssl_parse_client_psk_identity() function in library/ssl_srv.c.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3g9v-mx9v-wmwv

7 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: ice: fix eswitch code memory leak in reset scenario Add simple eswitch mode checker in attaching VF procedure and allocate required port representor memory structures only in switchdev mode. The reset flows triggers VF (if present) detach/attach procedure. It might involve VF port representor(s) re-creation if the device is configured is switchdev mode (not legacy one). The memory was blindly allocated in current implementation, regardless of the mode and not freed if in legacy mode. Kmemeleak trace: unreferenced object (percpu) 0x7e3bce5b888458 (size 40): comm "bash", pid 1784, jiffies 4295743894 hex dump (first 32 bytes on cpu 45): 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace (crc 0): pcpu_alloc_noprof+0x4c4/0x7c0 ice_repr_create+0x66/0x130 [ice] ice_repr_create_vf+0x22/0x70 [ice] ice_e...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3g9v-j5q9-fhvc

почти 4 года назад

Cross-site scripting (XSS) vulnerability in forms/smpwservices.fcc in CA (formerly Computer Associates) eTrust SiteMinder Agent allows remote attackers to inject arbitrary web script or HTML via the SMAUTHREASON parameter, a different vector than CVE-2005-2204.

EPSS: Низкий
github логотип

GHSA-3g9v-h3h6-7qf4

больше 2 лет назад

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3g9v-g85v-2jg3

больше 3 лет назад

Dell EMC VxRail versions 4.7.410 and 4.7.411 contain an improper authentication vulnerability. A remote unauthenticated attacker may exploit this vulnerability to obtain sensitive information in an encrypted form.

EPSS: Низкий
github логотип

GHSA-3g9v-2x9v-4j4g

больше 3 лет назад

In Wireshark through 2.0.13 and 2.2.x through 2.2.7, the openSAFETY dissector could crash or exhaust system memory. This was addressed in epan/dissectors/packet-opensafety.c by adding length validation. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-9350.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3g9r-wrp4-36rm

больше 3 лет назад

The NTP Server configuration function of the IP camera device is not verified with special parameters. Remote attackers can perform a command Injection attack and execute arbitrary commands after logging in with the privileged permission.

EPSS: Низкий
github логотип

GHSA-3g9r-qc5h-97f4

больше 3 лет назад

An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1250.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3g9r-f97h-h43m

больше 1 года назад

Administrative Management System from Wellchoose has an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject and execute arbitrary OS commands.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3g9q-pxcf-xr75

10 месяцев назад

A vulnerability was found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this issue is some unknown functionality of the component MODE Command Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3g9q-cmgv-g4p6

около 3 лет назад

Arbitrary file read vulnerability in Jenkins Pipeline Utility Steps Plugin

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3g9q-9jqp-362q

больше 3 лет назад

wp-admin/includes/class-wp-posts-list-table.php in WordPress before 3.3.3 does not properly restrict excerpt-view access, which allows remote authenticated users to obtain sensitive information by visiting a draft.

EPSS: Низкий
github логотип

GHSA-3g9m-qpqh-r4r2

11 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in PasqualePuzio Login Alert allows Stored XSS. This issue affects Login Alert: from n/a through 0.2.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3g9m-2rxr-22r8

больше 3 лет назад

On BIG-IP DNS and GTM version 13.1.x before 13.1.0.4, and all versions of 12.1.x and 11.6.x, big3d does not securely handle and parse certain payloads resulting in a buffer overflow. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

EPSS: Низкий
github логотип

GHSA-3g9j-v8wq-8c77

больше 3 лет назад

The Jetpack Scan team identified a Reflected Cross-Site Scripting in the Login Form of the Patreon WordPress plugin before 1.7.2. The WordPress login form (wp-login.php) is hooked by the plugin and offers to allow users to authenticate on the site using their Patreon account. Unfortunately, some of the error logging logic behind the scene allowed user-controlled input to be reflected on the login page, unsanitized.

EPSS: Низкий
github логотип

GHSA-3g9j-4fcm-pr52

больше 3 лет назад

Windows Kernel Information Disclosure Vulnerability.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-3g9j-3prp-r5vg

почти 4 года назад

BilboBlog 0.2.1 allows remote attackers to obtain sensitive information via (1) an enable_cache=false query string to footer.php or (2) a direct request to pagination.php, which reveals the installation path in an error message.

EPSS: Низкий
github логотип

GHSA-3g9h-ghw9-m9mm

больше 3 лет назад

WebKit, as used in Apple iOS before 8 and Apple TV before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-09-17-1 and APPLE-SA-2014-09-17-2.

EPSS: Низкий
github логотип

GHSA-3g9h-f994-3h4c

больше 2 лет назад

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formDosCfg.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3g9f-gfm4-qv9g

почти 2 года назад

An issue was discovered in the default configurations of ROS2 Humble Hawksbill in ROS2 Humble Hawksbill in ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows unauthenticated attackers to gain access using default credentials.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3g9w-ghrc-hc72

In ARM mbed TLS before 2.7.0, there is a bounds-check bypass through an integer overflow in PSK identity parsing in the ssl_parse_client_psk_identity() function in library/ssl_srv.c.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3g9v-mx9v-wmwv

In the Linux kernel, the following vulnerability has been resolved: ice: fix eswitch code memory leak in reset scenario Add simple eswitch mode checker in attaching VF procedure and allocate required port representor memory structures only in switchdev mode. The reset flows triggers VF (if present) detach/attach procedure. It might involve VF port representor(s) re-creation if the device is configured is switchdev mode (not legacy one). The memory was blindly allocated in current implementation, regardless of the mode and not freed if in legacy mode. Kmemeleak trace: unreferenced object (percpu) 0x7e3bce5b888458 (size 40): comm "bash", pid 1784, jiffies 4295743894 hex dump (first 32 bytes on cpu 45): 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace (crc 0): pcpu_alloc_noprof+0x4c4/0x7c0 ice_repr_create+0x66/0x130 [ice] ice_repr_create_vf+0x22/0x70 [ice] ice_e...

CVSS3: 5.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-3g9v-j5q9-fhvc

Cross-site scripting (XSS) vulnerability in forms/smpwservices.fcc in CA (formerly Computer Associates) eTrust SiteMinder Agent allows remote attackers to inject arbitrary web script or HTML via the SMAUTHREASON parameter, a different vector than CVE-2005-2204.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3g9v-h3h6-7qf4

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

CVSS3: 8.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3g9v-g85v-2jg3

Dell EMC VxRail versions 4.7.410 and 4.7.411 contain an improper authentication vulnerability. A remote unauthenticated attacker may exploit this vulnerability to obtain sensitive information in an encrypted form.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3g9v-2x9v-4j4g

In Wireshark through 2.0.13 and 2.2.x through 2.2.7, the openSAFETY dissector could crash or exhaust system memory. This was addressed in epan/dissectors/packet-opensafety.c by adding length validation. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-9350.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3g9r-wrp4-36rm

The NTP Server configuration function of the IP camera device is not verified with special parameters. Remote attackers can perform a command Injection attack and execute arbitrary commands after logging in with the privileged permission.

8%
Низкий
больше 3 лет назад
github логотип
GHSA-3g9r-qc5h-97f4

An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1250.

CVSS3: 5.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3g9r-f97h-h43m

Administrative Management System from Wellchoose has an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject and execute arbitrary OS commands.

CVSS3: 8.8
3%
Низкий
больше 1 года назад
github логотип
GHSA-3g9q-pxcf-xr75

A vulnerability was found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this issue is some unknown functionality of the component MODE Command Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-3g9q-cmgv-g4p6

Arbitrary file read vulnerability in Jenkins Pipeline Utility Steps Plugin

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-3g9q-9jqp-362q

wp-admin/includes/class-wp-posts-list-table.php in WordPress before 3.3.3 does not properly restrict excerpt-view access, which allows remote authenticated users to obtain sensitive information by visiting a draft.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3g9m-qpqh-r4r2

Cross-Site Request Forgery (CSRF) vulnerability in PasqualePuzio Login Alert allows Stored XSS. This issue affects Login Alert: from n/a through 0.2.1.

CVSS3: 7.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-3g9m-2rxr-22r8

On BIG-IP DNS and GTM version 13.1.x before 13.1.0.4, and all versions of 12.1.x and 11.6.x, big3d does not securely handle and parse certain payloads resulting in a buffer overflow. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3g9j-v8wq-8c77

The Jetpack Scan team identified a Reflected Cross-Site Scripting in the Login Form of the Patreon WordPress plugin before 1.7.2. The WordPress login form (wp-login.php) is hooked by the plugin and offers to allow users to authenticate on the site using their Patreon account. Unfortunately, some of the error logging logic behind the scene allowed user-controlled input to be reflected on the login page, unsanitized.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3g9j-4fcm-pr52

Windows Kernel Information Disclosure Vulnerability.

CVSS3: 4.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3g9j-3prp-r5vg

BilboBlog 0.2.1 allows remote attackers to obtain sensitive information via (1) an enable_cache=false query string to footer.php or (2) a direct request to pagination.php, which reveals the installation path in an error message.

5%
Низкий
почти 4 года назад
github логотип
GHSA-3g9h-ghw9-m9mm

WebKit, as used in Apple iOS before 8 and Apple TV before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-09-17-1 and APPLE-SA-2014-09-17-2.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3g9h-f994-3h4c

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formDosCfg.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3g9f-gfm4-qv9g

An issue was discovered in the default configurations of ROS2 Humble Hawksbill in ROS2 Humble Hawksbill in ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows unauthenticated attackers to gain access using default credentials.

почти 2 года назад

Уязвимостей на страницу