Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 292 001

Количество 292 001

github логотип

GHSA-23cw-p4x6-mcqc

больше 3 лет назад

A buffer overflow vulnerability in cif_print_page() in devices/gdevcif.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-23cv-w96c-877f

6 месяцев назад

The Go1 also known as "The World's First Intelligence Bionic Quadruped Robot Companion of Consumer Level," contains an undocumented backdoor that can enable the manufacturer, and anyone in possession of the correct API key, complete remote control over the affected robotic device using the CloudSail remote access service.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-23cv-jh4v-vffm

больше 3 лет назад

Denial of service in ASP.NET Core

EPSS: Низкий
github логотип

GHSA-23cv-hj48-7c4g

больше 3 лет назад

The Keybase app 2.13.2 for iOS provides potentially insufficient notice that it is employing a user's private key to sign a certain cryptocurrency attestation (that an address at keybase.io can be used for Stellar payments to the user), which might be incompatible with a user's personal position on the semantics of an attestation.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-23cv-7mvx-jcq6

11 месяцев назад

Authentication Bypass Using an Alternate Path or Channel vulnerability in Realty Workstation allows Authentication Bypass.This issue affects Realty Workstation: from n/a through 1.0.45.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-23cv-53vv-c2x5

больше 3 лет назад

Cross Site Scripting (XSS) vulnerability in Booking Core - Ultimate Booking System Booking Core 1.7.0 via the (1) "About Yourself” section under the “My Profile” page, " (2) “Hotel Policy” field under the “Hotel Details” page, (3) “Pricing code” and “name” fields under the “Manage Tour” page, and (4) all the labels under the “Menu” section.

EPSS: Низкий
github логотип

GHSA-23cr-wmpf-6wp5

больше 3 лет назад

Use-after-free vulnerability in Google Chrome before 14.0.835.163 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the focus controller.

EPSS: Низкий
github логотип

GHSA-23cr-5p5j-334x

больше 3 лет назад

IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 through 6.0.6) is vulnerable to HTTP header injection, caused by improper validation of input. By persuading a victim to visit a specially-crafted Web page, a remote attacker could exploit this vulnerability to inject arbitrary HTTP headers, which will allow the attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 144884.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-23cr-5hr4-rgwv

больше 3 лет назад

Improper Input Validation in Apache ActiveMQ

EPSS: Низкий
github логотип

GHSA-23cq-q28j-944h

больше 3 лет назад

Untrusted search path vulnerability in SnowFox Total Video Converter 2.5.1 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .avi file. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-23cq-gcvc-5552

8 месяцев назад

Improper handling of alternate encoding occurs when Elastic Defend on Windows systems attempts to scan a file or process encoded as a multibyte character. This leads to an uncaught exception causing Elastic Defend to crash which in turn will prevent it from quarantining the file and/or killing the process.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-23cq-6739-c6x5

больше 3 лет назад

A heap-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests to the LogReport API controller.

EPSS: Низкий
github логотип

GHSA-23cp-hr68-96ff

больше 3 лет назад

A cross site scripting issue has been found in custompage.cgi in Pulse Secure Pulse Connect Secure (PCS) before 8.0R17.0, 8.1.x before 8.1R13, 8.2.x before 8.2R9, and 8.3.x before 8.3R3 and Pulse Policy Secure (PPS) before 5.2R10, 5.3.x before 5.3R9, and 5.4.x before 5.4R3 due to one of the URL parameters not being sanitized. Exploitation does require the user to be logged in as administrator; the issue is not applicable to the end user portal.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-23cm-x6j7-6hq3

почти 4 года назад

matrix-js-sdk can be tricked into disclosing E2EE room keys to a participating homeserver

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-23cm-frh8-jp6q

больше 3 лет назад

The graphite2::GlyphCache::Loader::Loader function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-23cj-9wgg-g8w7

больше 3 лет назад

Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in KOffice 2.3.3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ODF style in an ODF document. NOTE: this is the same vulnerability as CVE-2012-3456, but it was SPLIT by the CNA even though Calligra and KOffice share the same codebase.

EPSS: Низкий
github логотип

GHSA-23cj-6mpm-r98j

8 месяцев назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-23ch-w9vh-2wxw

больше 3 лет назад

Mail in Apple iPhone 1.1.1 allows remote user-assisted attackers to force the iPhone user to make calls to arbitrary telephone numbers via a "tel:" link, which does not prompt the user before dialing the number.

EPSS: Низкий
github логотип

GHSA-23cg-4fwx-fhrv

больше 3 лет назад

Arbitrary file deletion vulnerability was discovered in wuzhicms v 4.0.1 via coreframe\app\attachment\admin\index.php, which allows attackers to access sensitive information.

EPSS: Низкий
github логотип

GHSA-23cg-3343-mmvh

больше 3 лет назад

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile MDM9625, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 810, SD 820, and SD 820A, untrusted pointer dereference in QSEE Syscall without proper validation can lead to access of blacklisted memory.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-23cw-p4x6-mcqc

A buffer overflow vulnerability in cif_print_page() in devices/gdevcif.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

CVSS3: 5.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-23cv-w96c-877f

The Go1 also known as "The World's First Intelligence Bionic Quadruped Robot Companion of Consumer Level," contains an undocumented backdoor that can enable the manufacturer, and anyone in possession of the correct API key, complete remote control over the affected robotic device using the CloudSail remote access service.

CVSS3: 6.6
0%
Низкий
6 месяцев назад
github логотип
GHSA-23cv-jh4v-vffm

Denial of service in ASP.NET Core

4%
Низкий
больше 3 лет назад
github логотип
GHSA-23cv-hj48-7c4g

The Keybase app 2.13.2 for iOS provides potentially insufficient notice that it is employing a user's private key to sign a certain cryptocurrency attestation (that an address at keybase.io can be used for Stellar payments to the user), which might be incompatible with a user's personal position on the semantics of an attestation.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-23cv-7mvx-jcq6

Authentication Bypass Using an Alternate Path or Channel vulnerability in Realty Workstation allows Authentication Bypass.This issue affects Realty Workstation: from n/a through 1.0.45.

CVSS3: 9.8
1%
Низкий
11 месяцев назад
github логотип
GHSA-23cv-53vv-c2x5

Cross Site Scripting (XSS) vulnerability in Booking Core - Ultimate Booking System Booking Core 1.7.0 via the (1) "About Yourself” section under the “My Profile” page, " (2) “Hotel Policy” field under the “Hotel Details” page, (3) “Pricing code” and “name” fields under the “Manage Tour” page, and (4) all the labels under the “Menu” section.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23cr-wmpf-6wp5

Use-after-free vulnerability in Google Chrome before 14.0.835.163 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the focus controller.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-23cr-5p5j-334x

IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 through 6.0.6) is vulnerable to HTTP header injection, caused by improper validation of input. By persuading a victim to visit a specially-crafted Web page, a remote attacker could exploit this vulnerability to inject arbitrary HTTP headers, which will allow the attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 144884.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-23cr-5hr4-rgwv

Improper Input Validation in Apache ActiveMQ

1%
Низкий
больше 3 лет назад
github логотип
GHSA-23cq-q28j-944h

Untrusted search path vulnerability in SnowFox Total Video Converter 2.5.1 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .avi file. NOTE: some of these details are obtained from third party information.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23cq-gcvc-5552

Improper handling of alternate encoding occurs when Elastic Defend on Windows systems attempts to scan a file or process encoded as a multibyte character. This leads to an uncaught exception causing Elastic Defend to crash which in turn will prevent it from quarantining the file and/or killing the process.

CVSS3: 5.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-23cq-6739-c6x5

A heap-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests to the LogReport API controller.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-23cp-hr68-96ff

A cross site scripting issue has been found in custompage.cgi in Pulse Secure Pulse Connect Secure (PCS) before 8.0R17.0, 8.1.x before 8.1R13, 8.2.x before 8.2R9, and 8.3.x before 8.3R3 and Pulse Policy Secure (PPS) before 5.2R10, 5.3.x before 5.3R9, and 5.4.x before 5.4R3 due to one of the URL parameters not being sanitized. Exploitation does require the user to be logged in as administrator; the issue is not applicable to the end user portal.

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-23cm-x6j7-6hq3

matrix-js-sdk can be tricked into disclosing E2EE room keys to a participating homeserver

CVSS3: 5.9
0%
Низкий
почти 4 года назад
github логотип
GHSA-23cm-frh8-jp6q

The graphite2::GlyphCache::Loader::Loader function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-23cj-9wgg-g8w7

Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in KOffice 2.3.3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ODF style in an ODF document. NOTE: this is the same vulnerability as CVE-2012-3456, but it was SPLIT by the CNA even though Calligra and KOffice share the same codebase.

7%
Низкий
больше 3 лет назад
github логотип
GHSA-23cj-6mpm-r98j

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 6.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-23ch-w9vh-2wxw

Mail in Apple iPhone 1.1.1 allows remote user-assisted attackers to force the iPhone user to make calls to arbitrary telephone numbers via a "tel:" link, which does not prompt the user before dialing the number.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-23cg-4fwx-fhrv

Arbitrary file deletion vulnerability was discovered in wuzhicms v 4.0.1 via coreframe\app\attachment\admin\index.php, which allows attackers to access sensitive information.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23cg-3343-mmvh

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile MDM9625, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 810, SD 820, and SD 820A, untrusted pointer dereference in QSEE Syscall without proper validation can lead to access of blacklisted memory.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу