Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 212

Количество 314 212

github логотип

GHSA-3fp5-72pm-rf42

больше 3 лет назад

wp-admin/press-this.php in WordPress before 3.0.6 does not enforce the publish_posts capability requirement, which allows remote authenticated users to perform publish actions by leveraging the Contributor role.

EPSS: Низкий
github логотип

GHSA-3fp5-374q-v5p2

почти 4 года назад

Unspecified vulnerability in OC4J for Oracle Application Server 9.0.4.2 and 10.1.2.0.0 has unknown impact and attack vectors, aka Oracle Vuln# AS07.

EPSS: Низкий
github логотип

GHSA-3fp5-2xwh-fxm6

почти 2 года назад

Evmos transaction execution not accounting for all state transition after interaction with precompiles

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-3fp4-v27w-gh48

больше 3 лет назад

In ged, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07202966; Issue ID: ALPS07202966.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3fp4-rv66-mvj2

больше 3 лет назад

A security feature bypass vulnerability exists in Microsoft Word software when it fails to properly handle .LNK files, aka 'Microsoft Word Security Feature Bypass Vulnerability'.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3fp3-6m8h-4x7c

больше 3 лет назад

pmm-server in Percona Monitoring and Management (PMM) 2.2.x before 2.2.1 allows unauthenticated denial of service.

EPSS: Низкий
github логотип

GHSA-3fp3-2jwc-wxvv

больше 3 лет назад

This vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion Platform 2020.2. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SaveUserSetting endpoint. The issue results from improper restriction of this endpoint to unprivileged users. An attacker can leverage this vulnerability to escalate privileges their privileges from Guest to Administrator. Was ZDI-CAN-11903.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-3fp2-p2cp-pcrx

больше 3 лет назад

A buffer overflow vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent by the server could potentially result in an out-of-bounds write of one byte. A malicious server can send a negative content-length in response to a HTTP request triggering the vulnerability.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3fp2-6mwq-4q3j

6 месяцев назад

Liferay Portal Vulnerable to Cross-Site Scripting through URLs

EPSS: Низкий
github логотип

GHSA-3fmx-gx73-5jg7

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: PCI: Avoid potential out-of-bounds read in pci_dev_for_each_resource() Coverity complains that pointer in the pci_dev_for_each_resource() may be wrong, i.e., might be used for the out-of-bounds read. There is no actual issue right now because we have another check afterwards and the out-of-bounds read is not being performed. In any case it's better code with this fixed, hence the proposed change. As Jonas pointed out "It probably makes the code slightly less performant as res will now be checked for being not NULL (which will always be true), but I doubt it will be significant (or in any hot paths)."

EPSS: Низкий
github логотип

GHSA-3fmx-7555-v8rg

почти 4 года назад

rpc.statd allows remote attackers to forward RPC calls to the local operating system via the SM_MON and SM_NOTIFY commands, which in turn could be used to remotely exploit other bugs such as in automountd.

EPSS: Низкий
github логотип

GHSA-3fmw-2235-q93p

больше 3 лет назад

A Denial of Service vulnerability related to message decoding in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attacker to send a combination of messages to lmgrd or the vendor daemon, causing the heartbeat between lmgrd and the vendor daemon to stop, and the vendor daemon to shut down.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3fmr-rjpp-p943

почти 4 года назад

Transparent Network Substrate (TNS) Listener in Oracle 9i 9.0.1.1 allows remote attackers to cause a denial of service (CPU consumption) via a single malformed TCP packet to port 1521.

EPSS: Низкий
github логотип

GHSA-3fmr-qqcp-fr3c

почти 4 года назад

Avirt Mail 4.0 and 4.2 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long "RCPT TO" or "MAIL FROM" command.

EPSS: Низкий
github логотип

GHSA-3fmr-m4vg-vfvw

больше 3 лет назад

Buffer overflow in WG-C10 v3.0.79 and earlier allows an attacker to execute arbitrary commands via unspecified vectors.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3fmq-xqpg-7wmg

почти 2 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Solwin Infotech User Activity Log.This issue affects User Activity Log: from n/a through 1.8.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-3fmq-x9q6-wm39

больше 1 года назад

random_compat Uses insecure CSPRNG

EPSS: Низкий
github логотип

GHSA-3fmq-prxr-gqfw

больше 3 лет назад

An issue was discovered in Nokia NetAct 18A. A malicious user can change a filename of an uploaded file to include JavaScript code, which is then stored and executed by a victim's web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or e-mailed directly to victims. Here, the /netact/sct filename parameter is used.

EPSS: Низкий
github логотип

GHSA-3fmq-g9m7-v3qg

больше 3 лет назад

An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3fmm-r3g2-5cc2

почти 4 года назад

Buffer overflow in index.cgi administration interface for Boozt! Standard 0.9.8 allows local users to execute arbitrary code via a long name field when creating a new banner.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3fp5-72pm-rf42

wp-admin/press-this.php in WordPress before 3.0.6 does not enforce the publish_posts capability requirement, which allows remote authenticated users to perform publish actions by leveraging the Contributor role.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3fp5-374q-v5p2

Unspecified vulnerability in OC4J for Oracle Application Server 9.0.4.2 and 10.1.2.0.0 has unknown impact and attack vectors, aka Oracle Vuln# AS07.

3%
Низкий
почти 4 года назад
github логотип
GHSA-3fp5-2xwh-fxm6

Evmos transaction execution not accounting for all state transition after interaction with precompiles

CVSS3: 9.1
1%
Низкий
почти 2 года назад
github логотип
GHSA-3fp4-v27w-gh48

In ged, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07202966; Issue ID: ALPS07202966.

CVSS3: 6.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3fp4-rv66-mvj2

A security feature bypass vulnerability exists in Microsoft Word software when it fails to properly handle .LNK files, aka 'Microsoft Word Security Feature Bypass Vulnerability'.

CVSS3: 8.8
4%
Низкий
больше 3 лет назад
github логотип
GHSA-3fp3-6m8h-4x7c

pmm-server in Percona Monitoring and Management (PMM) 2.2.x before 2.2.1 allows unauthenticated denial of service.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3fp3-2jwc-wxvv

This vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion Platform 2020.2. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SaveUserSetting endpoint. The issue results from improper restriction of this endpoint to unprivileged users. An attacker can leverage this vulnerability to escalate privileges their privileges from Guest to Administrator. Was ZDI-CAN-11903.

CVSS3: 9.8
11%
Средний
больше 3 лет назад
github логотип
GHSA-3fp2-p2cp-pcrx

A buffer overflow vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent by the server could potentially result in an out-of-bounds write of one byte. A malicious server can send a negative content-length in response to a HTTP request triggering the vulnerability.

CVSS3: 8.1
3%
Низкий
больше 3 лет назад
github логотип
GHSA-3fp2-6mwq-4q3j

Liferay Portal Vulnerable to Cross-Site Scripting through URLs

0%
Низкий
6 месяцев назад
github логотип
GHSA-3fmx-gx73-5jg7

In the Linux kernel, the following vulnerability has been resolved: PCI: Avoid potential out-of-bounds read in pci_dev_for_each_resource() Coverity complains that pointer in the pci_dev_for_each_resource() may be wrong, i.e., might be used for the out-of-bounds read. There is no actual issue right now because we have another check afterwards and the out-of-bounds read is not being performed. In any case it's better code with this fixed, hence the proposed change. As Jonas pointed out "It probably makes the code slightly less performant as res will now be checked for being not NULL (which will always be true), but I doubt it will be significant (or in any hot paths)."

почти 2 года назад
github логотип
GHSA-3fmx-7555-v8rg

rpc.statd allows remote attackers to forward RPC calls to the local operating system via the SM_MON and SM_NOTIFY commands, which in turn could be used to remotely exploit other bugs such as in automountd.

7%
Низкий
почти 4 года назад
github логотип
GHSA-3fmw-2235-q93p

A Denial of Service vulnerability related to message decoding in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attacker to send a combination of messages to lmgrd or the vendor daemon, causing the heartbeat between lmgrd and the vendor daemon to stop, and the vendor daemon to shut down.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3fmr-rjpp-p943

Transparent Network Substrate (TNS) Listener in Oracle 9i 9.0.1.1 allows remote attackers to cause a denial of service (CPU consumption) via a single malformed TCP packet to port 1521.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3fmr-qqcp-fr3c

Avirt Mail 4.0 and 4.2 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long "RCPT TO" or "MAIL FROM" command.

8%
Низкий
почти 4 года назад
github логотип
GHSA-3fmr-m4vg-vfvw

Buffer overflow in WG-C10 v3.0.79 and earlier allows an attacker to execute arbitrary commands via unspecified vectors.

CVSS3: 7.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3fmq-xqpg-7wmg

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Solwin Infotech User Activity Log.This issue affects User Activity Log: from n/a through 1.8.

CVSS3: 7.6
0%
Низкий
почти 2 года назад
github логотип
GHSA-3fmq-x9q6-wm39

random_compat Uses insecure CSPRNG

больше 1 года назад
github логотип
GHSA-3fmq-prxr-gqfw

An issue was discovered in Nokia NetAct 18A. A malicious user can change a filename of an uploaded file to include JavaScript code, which is then stored and executed by a victim's web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or e-mailed directly to victims. Here, the /netact/sct filename parameter is used.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3fmq-g9m7-v3qg

An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3fmm-r3g2-5cc2

Buffer overflow in index.cgi administration interface for Boozt! Standard 0.9.8 allows local users to execute arbitrary code via a long name field when creating a new banner.

2%
Низкий
почти 4 года назад

Уязвимостей на страницу