Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-3c2p-r64j-24rr

больше 3 лет назад

A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3c2m-gxqv-2jrx

больше 3 лет назад

A malicious application may be able to execute arbitrary code with kernel privileges. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. An out-of-bounds write issue was addressed with improved bounds checking.

EPSS: Низкий
github логотип

GHSA-3c2m-8jfj-576j

больше 3 лет назад

MediaWiki 1.27.x before 1.27.1 might allow remote attackers to bypass intended session access restrictions by leveraging a call to the UserGetRights function after Session::getAllowedUserRights.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3c2m-37hh-w3j8

почти 4 года назад

Multiple integer overflows in vclmi.dll in the visual class library module in IBM Lotus Symphony before 3.0.1 might allow remote attackers to execute arbitrary code via an embedded (1) JPEG or (2) PNG image object in a Symphony document that triggers a heap-based buffer overflow, as demonstrated by a .doc file.

EPSS: Средний
github логотип

GHSA-3c2j-x8m7-hrhp

больше 3 лет назад

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0060.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3c2j-rv98-w4xf

10 месяцев назад

Improper access control of endpoint in HCL Leap allows certain admin users to import applications from the server's filesystem.

CVSS3: 4.1
EPSS: Низкий
github логотип

GHSA-3c2j-r5f4-2fcc

больше 2 лет назад

Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.3, 12.4, 14.0-14.3 and 14.5-14.7. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle FLEXCUBE Universal Banking accessible data as well as unauthorized update, insert or delete access to some of Oracle FLEXCUBE Universal Banking accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle FLEXCUBE Universal Banking. CVSS 3.1 Base Score 5.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:L).

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3c2j-gj86-4xvq

8 месяцев назад

A vulnerability was found in Tenda AC15 15.03.05.19_multi. It has been classified as critical. This affects the function formSetSafeWanWebMan of the file /goform/SetRemoteWebCfg of the component HTTP POST Request Handler. The manipulation of the argument remoteIp leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3c2h-wqwf-4hjq

8 месяцев назад

Missing Authorization vulnerability in iCount iCount Payment Gateway allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects iCount Payment Gateway: from n/a through 2.0.6.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3c2h-px55-3fmw

почти 2 года назад

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /3g/index.php.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3c2h-g633-rm9x

больше 3 лет назад

In the Android kernel in F2FS touch driver there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-3c2h-8xmc-2258

3 месяца назад

Legacy Vivotek Device firmware uses default credetials for the root and user login accounts.

EPSS: Низкий
github логотип

GHSA-3c2h-289j-mhp4

2 месяца назад

Improper input sanitization in the file archives upload functionality of Eaton Galileo software allows traversing paths which could lead into an attacker with local access to execute unauthorized code or commands. This security issue has been fixed in the latest version of Galileo which is available on the Eaton download center.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3c2g-fm84-g225

больше 3 лет назад

The Portlet Bridge for JavaServer Faces in Red Hat JBoss Portal 6.2.0, when used in portlets with the default resource serving for GenericPortlet, does not properly restrict access to restricted resources, which allows remote attackers to obtain sensitive information via a URL with a modified resource ID.

EPSS: Низкий
github логотип

GHSA-3c2g-cf55-wr6p

больше 3 лет назад

Performance Co-Pilot (PCP) before 3.6.5 exports some of the /proc file system, which allows attackers to obtain sensitive information such as proc/pid/maps and command line arguments.

EPSS: Низкий
github логотип

GHSA-3c2g-95gg-q68p

больше 3 лет назад

In NETGEAR Nighthawk X10-R900 prior to 1.0.4.26, an attacker may execute arbitrary system commands as root by sending a specially-crafted MAC address to the "NETGEAR Genie" SOAP endpoint at AdvancedQoS:GetCurrentBandwidthByMAC. Although this requires QoS being enabled, advanced QoS being enabled, and a valid authentication JWT, additional vulnerabilities (CVE-2019-12510) allow an attacker to interact with the entire SOAP API without authentication. Additionally, DNS rebinding techniques may be used to exploit this vulnerability remotely. Exploiting this vulnerability is somewhat involved. The following limitations apply to the payload and must be overcome for successful exploitation: - No more than 17 characters may be used. - At least one colon must be included to prevent mangling. - A single-quote and meta-character must be used to break out of the existing command. - Parent command remnants after the injection point must be dealt with. - The payload must be in all-caps....

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3c2f-8cpm-89m3

больше 3 лет назад

An improper check for unusual or exceptional conditions in Juniper Networks Junos OS and Junos OS Evolved Routing Protocol Daemon (RPD) service allows an attacker to send a valid BGP FlowSpec message thereby causing an unexpected change in the route advertisements within the BGP FlowSpec domain leading to disruptions in network traffic causing a Denial of Service (DoS) condition. Continued receipt of these update messages will cause a sustained Denial of Service condition. This issue affects Juniper Networks: Junos OS: All versions prior to 17.3R3-S10 with the exceptions of 15.1X49-D240 on SRX Series and 15.1R7-S8 on EX Series; 17.3 versions prior to 17.3R3-S10; 17.4 versions prior to 17.4R2-S12, 17.4R3-S4; 18.1 versions prior to 18.1R3-S12; 18.2 versions prior to 18.2R2-S8, 18.2R3-S6; 18.3 versions prior to 18.3R3-S4; 18.4 versions prior to 18.4R1-S8, 18.4R2-S6, 18.4R3-S6; 19.1 versions prior to 19.1R1-S6, 19.1R2-S2, 19.1R3-S3; 19.2 versions prior to 19.2R3-S1; 19.3 versions prior ...

EPSS: Низкий
github логотип

GHSA-3c2c-v8x8-23vv

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in IBM Power Hardware Management Console (HMC) 7R7.1.0, 7R7.2.0, 7R7.3.0 through 7R7.3.5, 7R7.7.0 through SP3, and 7R7.8.0 before SP1 allows remote attackers to inject arbitrary web script or HTML via the user name on the logon screen. IBM X-Force ID: 91163.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3c2c-h86v-vq82

больше 3 лет назад

ImageMagick 7.0.8-4 has a memory leak in DecodeImage in coders/pcd.c.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3c29-qfhr-mp78

больше 3 лет назад

An issue was discovered in Xen 4.9 through 4.14.x. On Arm, a guest is allowed to control whether memory accesses are bypassing the cache. This means that Xen needs to ensure that all writes (such as the ones during scrubbing) have reached the memory before handing over the page to a guest. Unfortunately, the operation to clean the cache is happening before checking if the page was scrubbed. Therefore there is no guarantee when all the writes will reach the memory.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3c2p-r64j-24rr

A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS 5, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c2m-gxqv-2jrx

A malicious application may be able to execute arbitrary code with kernel privileges. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. An out-of-bounds write issue was addressed with improved bounds checking.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c2m-8jfj-576j

MediaWiki 1.27.x before 1.27.1 might allow remote attackers to bypass intended session access restrictions by leveraging a call to the UserGetRights function after Session::getAllowedUserRights.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c2m-37hh-w3j8

Multiple integer overflows in vclmi.dll in the visual class library module in IBM Lotus Symphony before 3.0.1 might allow remote attackers to execute arbitrary code via an embedded (1) JPEG or (2) PNG image object in a Symphony document that triggers a heap-based buffer overflow, as demonstrated by a .doc file.

11%
Средний
почти 4 года назад
github логотип
GHSA-3c2j-x8m7-hrhp

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0060.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c2j-rv98-w4xf

Improper access control of endpoint in HCL Leap allows certain admin users to import applications from the server's filesystem.

CVSS3: 4.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-3c2j-r5f4-2fcc

Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.3, 12.4, 14.0-14.3 and 14.5-14.7. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle FLEXCUBE Universal Banking accessible data as well as unauthorized update, insert or delete access to some of Oracle FLEXCUBE Universal Banking accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle FLEXCUBE Universal Banking. CVSS 3.1 Base Score 5.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:L).

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3c2j-gj86-4xvq

A vulnerability was found in Tenda AC15 15.03.05.19_multi. It has been classified as critical. This affects the function formSetSafeWanWebMan of the file /goform/SetRemoteWebCfg of the component HTTP POST Request Handler. The manipulation of the argument remoteIp leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-3c2h-wqwf-4hjq

Missing Authorization vulnerability in iCount iCount Payment Gateway allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects iCount Payment Gateway: from n/a through 2.0.6.

CVSS3: 5.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-3c2h-px55-3fmw

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /3g/index.php.

CVSS3: 8.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-3c2h-g633-rm9x

In the Android kernel in F2FS touch driver there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 4.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c2h-8xmc-2258

Legacy Vivotek Device firmware uses default credetials for the root and user login accounts.

0%
Низкий
3 месяца назад
github логотип
GHSA-3c2h-289j-mhp4

Improper input sanitization in the file archives upload functionality of Eaton Galileo software allows traversing paths which could lead into an attacker with local access to execute unauthorized code or commands. This security issue has been fixed in the latest version of Galileo which is available on the Eaton download center.

CVSS3: 7.3
0%
Низкий
2 месяца назад
github логотип
GHSA-3c2g-fm84-g225

The Portlet Bridge for JavaServer Faces in Red Hat JBoss Portal 6.2.0, when used in portlets with the default resource serving for GenericPortlet, does not properly restrict access to restricted resources, which allows remote attackers to obtain sensitive information via a URL with a modified resource ID.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c2g-cf55-wr6p

Performance Co-Pilot (PCP) before 3.6.5 exports some of the /proc file system, which allows attackers to obtain sensitive information such as proc/pid/maps and command line arguments.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3c2g-95gg-q68p

In NETGEAR Nighthawk X10-R900 prior to 1.0.4.26, an attacker may execute arbitrary system commands as root by sending a specially-crafted MAC address to the "NETGEAR Genie" SOAP endpoint at AdvancedQoS:GetCurrentBandwidthByMAC. Although this requires QoS being enabled, advanced QoS being enabled, and a valid authentication JWT, additional vulnerabilities (CVE-2019-12510) allow an attacker to interact with the entire SOAP API without authentication. Additionally, DNS rebinding techniques may be used to exploit this vulnerability remotely. Exploiting this vulnerability is somewhat involved. The following limitations apply to the payload and must be overcome for successful exploitation: - No more than 17 characters may be used. - At least one colon must be included to prevent mangling. - A single-quote and meta-character must be used to break out of the existing command. - Parent command remnants after the injection point must be dealt with. - The payload must be in all-caps....

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c2f-8cpm-89m3

An improper check for unusual or exceptional conditions in Juniper Networks Junos OS and Junos OS Evolved Routing Protocol Daemon (RPD) service allows an attacker to send a valid BGP FlowSpec message thereby causing an unexpected change in the route advertisements within the BGP FlowSpec domain leading to disruptions in network traffic causing a Denial of Service (DoS) condition. Continued receipt of these update messages will cause a sustained Denial of Service condition. This issue affects Juniper Networks: Junos OS: All versions prior to 17.3R3-S10 with the exceptions of 15.1X49-D240 on SRX Series and 15.1R7-S8 on EX Series; 17.3 versions prior to 17.3R3-S10; 17.4 versions prior to 17.4R2-S12, 17.4R3-S4; 18.1 versions prior to 18.1R3-S12; 18.2 versions prior to 18.2R2-S8, 18.2R3-S6; 18.3 versions prior to 18.3R3-S4; 18.4 versions prior to 18.4R1-S8, 18.4R2-S6, 18.4R3-S6; 19.1 versions prior to 19.1R1-S6, 19.1R2-S2, 19.1R3-S3; 19.2 versions prior to 19.2R3-S1; 19.3 versions prior ...

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c2c-v8x8-23vv

Cross-site scripting (XSS) vulnerability in IBM Power Hardware Management Console (HMC) 7R7.1.0, 7R7.2.0, 7R7.3.0 through 7R7.3.5, 7R7.7.0 through SP3, and 7R7.8.0 before SP1 allows remote attackers to inject arbitrary web script or HTML via the user name on the logon screen. IBM X-Force ID: 91163.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c2c-h86v-vq82

ImageMagick 7.0.8-4 has a memory leak in DecodeImage in coders/pcd.c.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c29-qfhr-mp78

An issue was discovered in Xen 4.9 through 4.14.x. On Arm, a guest is allowed to control whether memory accesses are bypassing the cache. This means that Xen needs to ensure that all writes (such as the ones during scrubbing) have reached the memory before handing over the page to a guest. Unfortunately, the operation to clean the cache is happening before checking if the page was scrubbed. Therefore there is no guarantee when all the writes will reach the memory.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу