Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-3c39-w687-672w

почти 2 года назад

Azure SDK Spoofing Vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3c38-6263-x4qc

почти 4 года назад

Format string vulnerability in the log function in Net::Server 0.87 and earlier, as used in Postfix Greylisting Policy Server (Postgrey) 1.18 and earlier, and possibly other products, allows remote attackers to cause a denial of service (crash) via format string specifiers that are not properly handled before being sent to syslog, as demonstrated using sender addresses to Postgrey.

EPSS: Низкий
github логотип

GHSA-3c38-2mw5-c664

больше 3 лет назад

In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_win7_x64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c402004.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3c38-2c7r-g6j4

около 4 лет назад

The Smart Floating / Sticky Buttons WordPress plugin before 2.5.5 does not sanitise and escape some parameter before outputting them in attributes and page, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

EPSS: Низкий
github логотип

GHSA-3c37-qxqv-r99x

больше 3 лет назад

A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0662.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-3c37-jjmv-92cc

почти 4 года назад

Unknown vulnerability in Squiggle for Batik before 1.5.1 allows attackers to bypass certain access controls via certain features of the Rhino scripting engine due to a "script security issue."

EPSS: Низкий
github логотип

GHSA-3c37-5qc5-cf3q

почти 4 года назад

Human Interface Toolbox (HIToolBox) for Apple Mac 0S X 10.3.6 allows local users to exit applications via the force-quit key combination, even when the system is running in kiosk mode.

EPSS: Низкий
github логотип

GHSA-3c36-xcfh-9hv4

почти 2 года назад

Trimble SketchUp Viewer SKP File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SKP files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-20789.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3c35-prjf-p48q

18 дней назад

dr_flac, an audio decoder within the dr_libs toolset, contains an integer overflow vulnerability flaw due to trusting the totalPCMFrameCount field from FLAC metadata before calculating buffer size, allowing an attacker with a specially crafted file to perform DoS against programs using the tool.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3c34-8r75-5w8x

больше 3 лет назад

All versions of the NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler for DxgDdiEscape where due to improper locking on certain conditions may lead to a denial of service

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3c33-3465-fhx2

больше 4 лет назад

Exposure of Resource to Wrong Sphere in LibreNMS

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3c33-2j43-9jqp

почти 3 года назад

An Improper Handling of Exceptional Conditions vulnerability in obs-service-go_modules of openSUSE Factory allows attackers that can influence the call to the service to delete files and directories on the system of the victim. This issue affects: SUSE openSUSE Factory obs-service-go_modules versions prior to 0.6.1.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3c32-4hq9-6wgj

больше 1 года назад

SpiceDB calls to LookupResources using LookupResources2 with caveats may return context is missing when it is not

CVSS3: 2
EPSS: Низкий
github логотип

GHSA-3c2x-g6mp-5gcv

11 месяцев назад

Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the formWifiWpsOOB function.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3c2v-mhqp-67jx

больше 3 лет назад

SQL injection vulnerability in functions/prepend_adm.php in Nagios Core Config Manager in Nagios XI before 2012R2.4 allows remote attackers to execute arbitrary SQL commands via the tfPassword parameter to nagiosql/index.php.

EPSS: Средний
github логотип

GHSA-3c2r-w857-w87r

около 4 лет назад

In vow driver, there is a possible memory corruption due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05862986; Issue ID: ALPS05862986.

EPSS: Низкий
github логотип

GHSA-3c2r-qjq2-2r45

почти 4 года назад

Bugzilla 2.16.x before 2.16.3, 2.17.x before 2.17.4, and earlier versions allows local users to overwrite arbitrary files via a symlink attack on temporary files that are created in directories with group-writable or world-writable permissions.

EPSS: Низкий
github логотип

GHSA-3c2r-pvhv-53p8

больше 3 лет назад

OpenVPN before version 2.5.3 on Windows allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main OpenVPN process (openvpn.exe).

EPSS: Низкий
github логотип

GHSA-3c2r-59vj-vq75

больше 3 лет назад

An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34197514. References: B-RB#112600.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-3c2r-3m9c-jjqx

больше 3 лет назад

In FreeBSD 12.0-STABLE before r350637, 12.0-RELEASE before 12.0-RELEASE-p9, 11.3-STABLE before r350638, 11.3-RELEASE before 11.3-RELEASE-p2, and 11.2-RELEASE before 11.2-RELEASE-p13, the bsnmp library is not properly validating the submitted length from a type-length-value encoding. A remote user could cause an out-of-bounds read or trigger a crash of the software such as bsnmpd resulting in a denial of service.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3c39-w687-672w

Azure SDK Spoofing Vulnerability

CVSS3: 7.5
7%
Низкий
почти 2 года назад
github логотип
GHSA-3c38-6263-x4qc

Format string vulnerability in the log function in Net::Server 0.87 and earlier, as used in Postfix Greylisting Policy Server (Postgrey) 1.18 and earlier, and possibly other products, allows remote attackers to cause a denial of service (crash) via format string specifiers that are not properly handled before being sent to syslog, as demonstrated using sender addresses to Postgrey.

6%
Низкий
почти 4 года назад
github логотип
GHSA-3c38-2mw5-c664

In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_win7_x64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c402004.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c38-2c7r-g6j4

The Smart Floating / Sticky Buttons WordPress plugin before 2.5.5 does not sanitise and escape some parameter before outputting them in attributes and page, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

0%
Низкий
около 4 лет назад
github логотип
GHSA-3c37-qxqv-r99x

A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0662.

CVSS3: 8.8
36%
Средний
больше 3 лет назад
github логотип
GHSA-3c37-jjmv-92cc

Unknown vulnerability in Squiggle for Batik before 1.5.1 allows attackers to bypass certain access controls via certain features of the Rhino scripting engine due to a "script security issue."

0%
Низкий
почти 4 года назад
github логотип
GHSA-3c37-5qc5-cf3q

Human Interface Toolbox (HIToolBox) for Apple Mac 0S X 10.3.6 allows local users to exit applications via the force-quit key combination, even when the system is running in kiosk mode.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3c36-xcfh-9hv4

Trimble SketchUp Viewer SKP File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SKP files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-20789.

CVSS3: 7.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-3c35-prjf-p48q

dr_flac, an audio decoder within the dr_libs toolset, contains an integer overflow vulnerability flaw due to trusting the totalPCMFrameCount field from FLAC metadata before calculating buffer size, allowing an attacker with a specially crafted file to perform DoS against programs using the tool.

CVSS3: 5.5
0%
Низкий
18 дней назад
github логотип
GHSA-3c34-8r75-5w8x

All versions of the NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler for DxgDdiEscape where due to improper locking on certain conditions may lead to a denial of service

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c33-3465-fhx2

Exposure of Resource to Wrong Sphere in LibreNMS

CVSS3: 8.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3c33-2j43-9jqp

An Improper Handling of Exceptional Conditions vulnerability in obs-service-go_modules of openSUSE Factory allows attackers that can influence the call to the service to delete files and directories on the system of the victim. This issue affects: SUSE openSUSE Factory obs-service-go_modules versions prior to 0.6.1.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-3c32-4hq9-6wgj

SpiceDB calls to LookupResources using LookupResources2 with caveats may return context is missing when it is not

CVSS3: 2
0%
Низкий
больше 1 года назад
github логотип
GHSA-3c2x-g6mp-5gcv

Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the formWifiWpsOOB function.

CVSS3: 9.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-3c2v-mhqp-67jx

SQL injection vulnerability in functions/prepend_adm.php in Nagios Core Config Manager in Nagios XI before 2012R2.4 allows remote attackers to execute arbitrary SQL commands via the tfPassword parameter to nagiosql/index.php.

20%
Средний
больше 3 лет назад
github логотип
GHSA-3c2r-w857-w87r

In vow driver, there is a possible memory corruption due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05862986; Issue ID: ALPS05862986.

0%
Низкий
около 4 лет назад
github логотип
GHSA-3c2r-qjq2-2r45

Bugzilla 2.16.x before 2.16.3, 2.17.x before 2.17.4, and earlier versions allows local users to overwrite arbitrary files via a symlink attack on temporary files that are created in directories with group-writable or world-writable permissions.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3c2r-pvhv-53p8

OpenVPN before version 2.5.3 on Windows allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main OpenVPN process (openvpn.exe).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c2r-59vj-vq75

An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34197514. References: B-RB#112600.

CVSS3: 7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c2r-3m9c-jjqx

In FreeBSD 12.0-STABLE before r350637, 12.0-RELEASE before 12.0-RELEASE-p9, 11.3-STABLE before r350638, 11.3-RELEASE before 11.3-RELEASE-p2, and 11.2-RELEASE before 11.2-RELEASE-p13, the bsnmp library is not properly validating the submitted length from a type-length-value encoding. A remote user could cause an out-of-bounds read or trigger a crash of the software such as bsnmpd resulting in a denial of service.

CVSS3: 7.5
4%
Низкий
больше 3 лет назад

Уязвимостей на страницу