Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3g85-527x-3jv5

больше 3 лет назад

The Chainfire SuperSU package before 1.69 for Android allows attackers to gain privileges via the (1) backtick or (2) $() type of shell metacharacters in the -c option to /system/xbin/su.

EPSS: Низкий
github логотип

GHSA-3g85-44xp-3vmj

больше 3 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: GIS). Supported versions that are affected are 8.0.26 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

EPSS: Низкий
github логотип

GHSA-3g84-qj7h-884w

больше 3 лет назад

Use-after-free vulnerability in the Samsung Exynos fimg2d driver for Android with Exynos 5433, 54xx, or 7420 chipsets allows attackers to obtain sensitive information via unspecified vectors. The Samsung ID is SVE-2016-6853.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3g83-whg6-2g8h

почти 4 года назад

file.cgi in Secure Computing SecurityReporter (aka Network Security Analyzer) 4.6.3 allows remote attackers to bypass authentication via a name parameter that specifies the eventcache directory and a non-GIF file, which causes the $dontvalidate variable to be set to true. NOTE: a separate traversal vulnerability could be leveraged to download arbitrary files.

EPSS: Низкий
github логотип

GHSA-3g82-r8f2-r5vq

больше 3 лет назад

Dave Gamble cJSON version 1.7.2 and earlier contains a CWE-415: Double Free vulnerability in cJSON library that can result in Possible crash or RCE. This attack appear to be exploitable via Attacker must be able to force victim to print JSON data, depending on how cJSON library is used this could be either local or over a network. This vulnerability appears to have been fixed in 1.7.3.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3g7x-qmj2-jxwp

почти 4 года назад

Buffer overflow in Winamp 2.81 allows remote attackers to execute arbitrary code via a long Artist ID3v2 tag in an MP3 file.

EPSS: Низкий
github логотип

GHSA-3g7x-q6q4-3cqc

больше 3 лет назад

Unspecified vulnerability in Vignette Content Management 7.3.0.5, 7.3.1, 7.3.1.1, 7.4, and 7.5 allows "low privileged" users to gain administrator privileges via unknown attack vectors.

EPSS: Низкий
github логотип

GHSA-3g7w-h796-wcg5

9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: cxl/pmem: Fix cxl_pmem_region and cxl_memdev leak When a cxl_nvdimm object goes through a ->remove() event (device physically removed, nvdimm-bridge disabled, or nvdimm device disabled), then any associated regions must also be disabled. As highlighted by the cxl-create-region.sh test [1], a single device may host multiple regions, but the driver was only tracking one region at a time. This leads to a situation where only the last enabled region per nvdimm device is cleaned up properly. Other regions are leaked, and this also causes cxl_memdev reference leaks. Fix the tracking by allowing cxl_nvdimm objects to track multiple region associations.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3g7w-2hm5-mfrj

больше 3 лет назад

Windows WalletService Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-1686, CVE-2021-1687, CVE-2021-1690.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3g7r-r3cr-q6f8

больше 1 года назад

Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 was discovered to store credentials in plaintext.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3g7r-m224-xg6p

10 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matat Technologies Deliver via Shipos for WooCommerce allows Reflected XSS. This issue affects Deliver via Shipos for WooCommerce: from n/a through 2.1.7.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3g7r-cgj9-56wc

почти 4 года назад

Directory traversal vulnerability in upload capability of WWW File Share Pro 2.42 and earlier allows remote attackers to overwrite arbitrary files via .. (dot dot) sequences in the filename parameter of a Content-Disposition: header.

EPSS: Низкий
github логотип

GHSA-3g7p-8qhx-mc8r

больше 2 лет назад

Shescape potential environment variable exposure on Windows with CMD

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-3g7p-5j4x-78cm

почти 4 года назад

Cross-site scripting (XSS) vulnerability in index.php in CMS Made Simple 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the cntnt01searchinput parameter in a Search action.

EPSS: Низкий
github логотип

GHSA-3g7m-jx8x-3j3x

больше 3 лет назад

Unify OpenStage/OpenScape Desk Phone IP SIP before V3 R3.11.0 has an authentication bypass in the default mode of the Workpoint Interface

EPSS: Низкий
github логотип

GHSA-3g7m-g8qm-x6j5

больше 3 лет назад

Magento discloses sensitive information

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3g7m-8wg3-6ggh

почти 2 года назад

An issue was discovered in ROS2 Humble Hawksbill in ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows attackers to obtain sensitive information via man-in-the-middle attacks due to cleartext transmission of data across the ROS2 nodes' communication channels.

EPSS: Низкий
github логотип

GHSA-3g7j-53r5-ww2g

больше 3 лет назад

In all Android releases from CAF using the Linux kernel, a race condition exists in a video driver potentially leading to buffer overflow or write to arbitrary pointer location.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-3g7h-wv72-q2hf

7 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: dm: limit swapping tables for devices with zone write plugs dm_revalidate_zones() only allowed new or previously unzoned devices to call blk_revalidate_disk_zones(). If the device was already zoned, disk->nr_zones would always equal md->nr_zones, so dm_revalidate_zones() returned without doing any work. This would make the zoned settings for the device not match the new table. If the device had zone write plug resources, it could run into errors like bdev_zone_is_seq() reading invalid memory because disk->conv_zones_bitmap was the wrong size. If the device doesn't have any zone write plug resources, calling blk_revalidate_disk_zones() will always correctly update device. If blk_revalidate_disk_zones() fails, it can still overwrite or clear the current disk->nr_zones value. In this case, DM must restore the previous value of disk->nr_zones, so that the zoned settings will continue to match the previous value that...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3g7h-qr24-8xr5

около 1 месяца назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3g85-527x-3jv5

The Chainfire SuperSU package before 1.69 for Android allows attackers to gain privileges via the (1) backtick or (2) $() type of shell metacharacters in the -c option to /system/xbin/su.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3g85-44xp-3vmj

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: GIS). Supported versions that are affected are 8.0.26 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3g84-qj7h-884w

Use-after-free vulnerability in the Samsung Exynos fimg2d driver for Android with Exynos 5433, 54xx, or 7420 chipsets allows attackers to obtain sensitive information via unspecified vectors. The Samsung ID is SVE-2016-6853.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3g83-whg6-2g8h

file.cgi in Secure Computing SecurityReporter (aka Network Security Analyzer) 4.6.3 allows remote attackers to bypass authentication via a name parameter that specifies the eventcache directory and a non-GIF file, which causes the $dontvalidate variable to be set to true. NOTE: a separate traversal vulnerability could be leveraged to download arbitrary files.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3g82-r8f2-r5vq

Dave Gamble cJSON version 1.7.2 and earlier contains a CWE-415: Double Free vulnerability in cJSON library that can result in Possible crash or RCE. This attack appear to be exploitable via Attacker must be able to force victim to print JSON data, depending on how cJSON library is used this could be either local or over a network. This vulnerability appears to have been fixed in 1.7.3.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3g7x-qmj2-jxwp

Buffer overflow in Winamp 2.81 allows remote attackers to execute arbitrary code via a long Artist ID3v2 tag in an MP3 file.

2%
Низкий
почти 4 года назад
github логотип
GHSA-3g7x-q6q4-3cqc

Unspecified vulnerability in Vignette Content Management 7.3.0.5, 7.3.1, 7.3.1.1, 7.4, and 7.5 allows "low privileged" users to gain administrator privileges via unknown attack vectors.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3g7w-h796-wcg5

In the Linux kernel, the following vulnerability has been resolved: cxl/pmem: Fix cxl_pmem_region and cxl_memdev leak When a cxl_nvdimm object goes through a ->remove() event (device physically removed, nvdimm-bridge disabled, or nvdimm device disabled), then any associated regions must also be disabled. As highlighted by the cxl-create-region.sh test [1], a single device may host multiple regions, but the driver was only tracking one region at a time. This leads to a situation where only the last enabled region per nvdimm device is cleaned up properly. Other regions are leaked, and this also causes cxl_memdev reference leaks. Fix the tracking by allowing cxl_nvdimm objects to track multiple region associations.

CVSS3: 5.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-3g7w-2hm5-mfrj

Windows WalletService Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-1686, CVE-2021-1687, CVE-2021-1690.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3g7r-r3cr-q6f8

Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 was discovered to store credentials in plaintext.

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3g7r-m224-xg6p

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matat Technologies Deliver via Shipos for WooCommerce allows Reflected XSS. This issue affects Deliver via Shipos for WooCommerce: from n/a through 2.1.7.

CVSS3: 7.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-3g7r-cgj9-56wc

Directory traversal vulnerability in upload capability of WWW File Share Pro 2.42 and earlier allows remote attackers to overwrite arbitrary files via .. (dot dot) sequences in the filename parameter of a Content-Disposition: header.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3g7p-8qhx-mc8r

Shescape potential environment variable exposure on Windows with CMD

CVSS3: 3.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3g7p-5j4x-78cm

Cross-site scripting (XSS) vulnerability in index.php in CMS Made Simple 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the cntnt01searchinput parameter in a Search action.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3g7m-jx8x-3j3x

Unify OpenStage/OpenScape Desk Phone IP SIP before V3 R3.11.0 has an authentication bypass in the default mode of the Workpoint Interface

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3g7m-g8qm-x6j5

Magento discloses sensitive information

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3g7m-8wg3-6ggh

An issue was discovered in ROS2 Humble Hawksbill in ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows attackers to obtain sensitive information via man-in-the-middle attacks due to cleartext transmission of data across the ROS2 nodes' communication channels.

почти 2 года назад
github логотип
GHSA-3g7j-53r5-ww2g

In all Android releases from CAF using the Linux kernel, a race condition exists in a video driver potentially leading to buffer overflow or write to arbitrary pointer location.

CVSS3: 7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3g7h-wv72-q2hf

In the Linux kernel, the following vulnerability has been resolved: dm: limit swapping tables for devices with zone write plugs dm_revalidate_zones() only allowed new or previously unzoned devices to call blk_revalidate_disk_zones(). If the device was already zoned, disk->nr_zones would always equal md->nr_zones, so dm_revalidate_zones() returned without doing any work. This would make the zoned settings for the device not match the new table. If the device had zone write plug resources, it could run into errors like bdev_zone_is_seq() reading invalid memory because disk->conv_zones_bitmap was the wrong size. If the device doesn't have any zone write plug resources, calling blk_revalidate_disk_zones() will always correctly update device. If blk_revalidate_disk_zones() fails, it can still overwrite or clear the current disk->nr_zones value. In this case, DM must restore the previous value of disk->nr_zones, so that the zoned settings will continue to match the previous value that...

CVSS3: 5.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-3g7h-qr24-8xr5

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

около 1 месяца назад

Уязвимостей на страницу