Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 375

Количество 314 375

github логотип

GHSA-3g25-46v4-h26c

больше 3 лет назад

** DISPUTED ** Technicolor TG588V V2 devices allow remote attackers to cause a denial of service (networking outage) via a flood of random MAC addresses, as demonstrated by macof. NOTE: this might overlap CVE-2018-15852 and CVE-2018-15907. NOTE: Technicolor denies that the described behavior is a vulnerability and states that Wi-Fi traffic is slowed or stopped only while the devices are exposed to a MAC flooding attack. This has been confirmed through testing against official up-to-date versions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3g24-rv7h-5xh5

больше 3 лет назад

An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject arbitrary HTML via a crafted email with HTML content in the Subject field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3g24-mff9-8mv9

около 2 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: libceph: replace BUG_ON with bounds check for map->max_osd OSD indexes come from untrusted network packets. Boundary checks are added to validate these against map->max_osd. [ idryomov: drop BUG_ON in ceph_get_primary_affinity(), minor cosmetic edits ]

EPSS: Низкий
github логотип

GHSA-3g24-jm9m-c47r

больше 3 лет назад

Mozilla Firefox before 20.0 and SeaMonkey before 2.17 do not prevent origin spoofing of tab-modal dialogs, which allows remote attackers to conduct phishing attacks via a crafted web site.

EPSS: Низкий
github логотип

GHSA-3g24-4p5j-c5q8

больше 3 лет назад

An improper neutralization of input during web page generation in FortiAuthenticator WEB UI 6.0.0 may allow an unauthenticated user to perform a cross-site scripting attack (XSS) via a parameter of the logon page.

EPSS: Низкий
github логотип

GHSA-3g23-95wx-3cc6

около 3 лет назад

Rukovoditel v3.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the component /rukovoditel/index.php?module=dashboard/ajax_request.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-3g23-7g3r-898j

9 месяцев назад

Mojolicious versions from 0.999922 through 9.39 for Perl uses a hard coded string, or the application's class name, as a HMAC session secret by default. These predictable default secrets can be exploited to forge session cookies. An attacker who knows or guesses the secret could compute valid HMAC signatures for the session cookie, allowing them to tamper with or hijack another user’s session.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3g23-34hp-r6rx

больше 3 лет назад

Improper Neutralization of HTTP requests in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attacker to execute commands on the server remotely via carefully constructed HTTP requests.

EPSS: Низкий
github логотип

GHSA-3g22-92jx-c9hc

3 месяца назад

The Ninja Countdown | Fastest Countdown Builder plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'ninja_countdown_admin_ajax' AJAX endpoint in all versions up to, and including, 1.5.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary countdowns.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3g22-4xc6-m8w3

больше 3 лет назад

IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.3 allows remote authenticated users to bypass intended access restrictions via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3g22-36vj-437q

больше 3 лет назад

A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to find the password hash when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M221 controller and broke the encryption keys.

EPSS: Низкий
github логотип

GHSA-3fxw-xghg-85m2

почти 4 года назад

An issue was discovered in SdHostDriver in Insyde InsydeH2O with kernel 5.1 before 05.16.25, 5.2 before 05.26.25, 5.3 before 05.35.25, 5.4 before 05.43.25, and 5.5 before 05.51.25. A vulnerability exists in the SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated buffer pointer (CommBufferData).

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-3fxr-g4w3-xwx9

больше 3 лет назад

checkpath in OpenRC before 0.44.7 uses the direct output of strlen() to allocate strings, which does not account for the '\0' byte at the end of the string. This results in memory corruption. CVE-2021-42341 was introduced in git commit 63db2d99e730547339d1bdd28e8437999c380cae, which was introduced as part of OpenRC 0.44.0 development.

EPSS: Низкий
github логотип

GHSA-3fxq-vfm3-v9wf

3 месяца назад

In Modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01672598; Issue ID: MSV-4622.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3fxq-g92j-92g5

7 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: regulator: gpio: Fix the out-of-bounds access to drvdata::gpiods drvdata::gpiods is supposed to hold an array of 'gpio_desc' pointers. But the memory is allocated for only one pointer. This will lead to out-of-bounds access later in the code if 'config::ngpios' is > 1. So fix the code to allocate enough memory to hold 'config::ngpios' of GPIO descriptors. While at it, also move the check for memory allocation failure to be below the allocation to make it more readable.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3fxq-f952-g28c

почти 4 года назад

Unspecified vulnerability in the NFS server in Sun Solaris 10 before 20070613 allows remote attackers to cause a denial of service (system crash) via certain XDR data in NFS requests, probably related to processing of data by the xdr_bool and xdrmblk_getint32 functions.

EPSS: Низкий
github логотип

GHSA-3fxq-98r3-r3g2

больше 3 лет назад

A DNS rebinding vulnerability in Freebox HD before 1.5.29.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-3fxq-93m7-p4qm

больше 3 лет назад

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, tvOS 14.0, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, watchOS 7.0, iOS 14.0 and iPadOS 14.0. An application may be able to execute arbitrary code with kernel privileges.

EPSS: Низкий
github логотип

GHSA-3fxp-vwxm-2r5p

больше 4 лет назад

Command injection in gitlogplus

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3fxp-m3gr-pfvm

больше 3 лет назад

A NULL pointer dereference flaw was found in the way openjpeg 2.1.2 decoded certain input images. Due to a logic error in the code responsible for decoding the input image, an application using openjpeg to process image data could crash when processing a crafted image.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3g25-46v4-h26c

** DISPUTED ** Technicolor TG588V V2 devices allow remote attackers to cause a denial of service (networking outage) via a flood of random MAC addresses, as demonstrated by macof. NOTE: this might overlap CVE-2018-15852 and CVE-2018-15907. NOTE: Technicolor denies that the described behavior is a vulnerability and states that Wi-Fi traffic is slowed or stopped only while the devices are exposed to a MAC flooding attack. This has been confirmed through testing against official up-to-date versions.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3g24-rv7h-5xh5

An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject arbitrary HTML via a crafted email with HTML content in the Subject field.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3g24-mff9-8mv9

In the Linux kernel, the following vulnerability has been resolved: libceph: replace BUG_ON with bounds check for map->max_osd OSD indexes come from untrusted network packets. Boundary checks are added to validate these against map->max_osd. [ idryomov: drop BUG_ON in ceph_get_primary_affinity(), minor cosmetic edits ]

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3g24-jm9m-c47r

Mozilla Firefox before 20.0 and SeaMonkey before 2.17 do not prevent origin spoofing of tab-modal dialogs, which allows remote attackers to conduct phishing attacks via a crafted web site.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3g24-4p5j-c5q8

An improper neutralization of input during web page generation in FortiAuthenticator WEB UI 6.0.0 may allow an unauthenticated user to perform a cross-site scripting attack (XSS) via a parameter of the logon page.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3g23-95wx-3cc6

Rukovoditel v3.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the component /rukovoditel/index.php?module=dashboard/ajax_request.

CVSS3: 9.8
10%
Средний
около 3 лет назад
github логотип
GHSA-3g23-7g3r-898j

Mojolicious versions from 0.999922 through 9.39 for Perl uses a hard coded string, or the application's class name, as a HMAC session secret by default. These predictable default secrets can be exploited to forge session cookies. An attacker who knows or guesses the secret could compute valid HMAC signatures for the session cookie, allowing them to tamper with or hijack another user’s session.

CVSS3: 8.1
0%
Низкий
9 месяцев назад
github логотип
GHSA-3g23-34hp-r6rx

Improper Neutralization of HTTP requests in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attacker to execute commands on the server remotely via carefully constructed HTTP requests.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3g22-92jx-c9hc

The Ninja Countdown | Fastest Countdown Builder plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'ninja_countdown_admin_ajax' AJAX endpoint in all versions up to, and including, 1.5.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary countdowns.

CVSS3: 4.3
0%
Низкий
3 месяца назад
github логотип
GHSA-3g22-4xc6-m8w3

IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.3 allows remote authenticated users to bypass intended access restrictions via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3g22-36vj-437q

A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to find the password hash when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M221 controller and broke the encryption keys.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3fxw-xghg-85m2

An issue was discovered in SdHostDriver in Insyde InsydeH2O with kernel 5.1 before 05.16.25, 5.2 before 05.26.25, 5.3 before 05.35.25, 5.4 before 05.43.25, and 5.5 before 05.51.25. A vulnerability exists in the SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated buffer pointer (CommBufferData).

CVSS3: 8.2
0%
Низкий
почти 4 года назад
github логотип
GHSA-3fxr-g4w3-xwx9

checkpath in OpenRC before 0.44.7 uses the direct output of strlen() to allocate strings, which does not account for the '\0' byte at the end of the string. This results in memory corruption. CVE-2021-42341 was introduced in git commit 63db2d99e730547339d1bdd28e8437999c380cae, which was introduced as part of OpenRC 0.44.0 development.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-3fxq-vfm3-v9wf

In Modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01672598; Issue ID: MSV-4622.

CVSS3: 7.5
0%
Низкий
3 месяца назад
github логотип
GHSA-3fxq-g92j-92g5

In the Linux kernel, the following vulnerability has been resolved: regulator: gpio: Fix the out-of-bounds access to drvdata::gpiods drvdata::gpiods is supposed to hold an array of 'gpio_desc' pointers. But the memory is allocated for only one pointer. This will lead to out-of-bounds access later in the code if 'config::ngpios' is > 1. So fix the code to allocate enough memory to hold 'config::ngpios' of GPIO descriptors. While at it, also move the check for memory allocation failure to be below the allocation to make it more readable.

CVSS3: 7.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-3fxq-f952-g28c

Unspecified vulnerability in the NFS server in Sun Solaris 10 before 20070613 allows remote attackers to cause a denial of service (system crash) via certain XDR data in NFS requests, probably related to processing of data by the xdr_bool and xdrmblk_getint32 functions.

2%
Низкий
почти 4 года назад
github логотип
GHSA-3fxq-98r3-r3g2

A DNS rebinding vulnerability in Freebox HD before 1.5.29.

CVSS3: 9.6
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3fxq-93m7-p4qm

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, tvOS 14.0, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, watchOS 7.0, iOS 14.0 and iPadOS 14.0. An application may be able to execute arbitrary code with kernel privileges.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3fxp-vwxm-2r5p

Command injection in gitlogplus

CVSS3: 9.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-3fxp-m3gr-pfvm

A NULL pointer dereference flaw was found in the way openjpeg 2.1.2 decoded certain input images. Due to a logic error in the code responsible for decoding the input image, an application using openjpeg to process image data could crash when processing a crafted image.

CVSS3: 6.5
2%
Низкий
больше 3 лет назад

Уязвимостей на страницу