Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3fqg-54mc-wmg3

около 1 года назад

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3fqc-v7hh-4m8x

16 дней назад

In the Linux kernel, the following vulnerability has been resolved: libceph: return the handler error from mon_handle_auth_done() Currently any error from ceph_auth_handle_reply_done() is propagated via finish_auth() but isn't returned from mon_handle_auth_done(). This results in higher layers learning that (despite the monitor considering us to be successfully authenticated) something went wrong in the authentication phase and reacting accordingly, but msgr2 still trying to proceed with establishing the session in the background. In the case of secure mode this can trigger a WARN in setup_crypto() and later lead to a NULL pointer dereference inside of prepare_auth_signature().

EPSS: Низкий
github логотип

GHSA-3fqc-qp8w-rr4h

почти 4 года назад

A vulnerability in Zoom On-Premise Meeting Connector Controller version 4.8.102.20220310 and On-Premise Meeting Connector MMR version 4.8.102.20220310 exposes process memory fragments to connected clients, which could be observed by a passive attacker.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3fqc-qhh2-fxhg

больше 3 лет назад

In GPAC MP4Box 1.1.0, there is a Null pointer reference in the function gf_filter_pid_get_packet function in src/filter_core/filter_pid.c:5394, as demonstrated by GPAC. This can cause a denial of service (DOS).

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3fq9-qj86-7ww9

почти 4 года назад

Product: AndroidVersions: Android kernelAndroid ID: A-209014813References: N/A

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3fq9-h6m7-6g68

10 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RedefiningTheWeb PDF Generator Addon for Elementor Page Builder allows Stored XSS. This issue affects PDF Generator Addon for Elementor Page Builder: from n/a through 1.7.5.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3fq9-fm98-2gqp

больше 3 лет назад

NVIDIA Tegra kernel driver contains a vulnerability in NVMAP where an attacker has the ability to write an arbitrary value to an arbitrary location which may lead to an escalation of privileges. This issue is rated as high.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3fq7-xp3x-g73j

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in wp-plugins-net/index.php in the WP Plugin Manager (wppm) plugin 1.6.4.b and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the filter parameter.

EPSS: Низкий
github логотип

GHSA-3fq7-x42r-jhxq

больше 2 лет назад

A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14. An app may be able to access Notes attachments.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-3fq7-vqr9-hr59

больше 3 лет назад

A stack-based buffer overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Researchers have identified multiple vulnerabilities where there is a lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer, which could allow an attacker to execute arbitrary code under the context of the process.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3fq7-mmjq-fv4x

больше 3 лет назад

CandidATS version 3.0.0 allows an external attacker to elevate privileges in the application. This is possible because the application suffers from CSRF. This allows to persuade an administrator to create a new account with administrative permissions.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3fq7-hx4j-7hh8

больше 3 лет назад

Vulnerability in the BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise BI Publisher. While the vulnerability is in BI Publisher, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all BI Publisher accessible data as well as unauthorized update, insert or delete access to some of BI Publisher accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).

EPSS: Низкий
github логотип

GHSA-3fq7-c5m8-g86x

2 месяца назад

Mautic user without privileged access to the Marketplace can install and uninstall composer packages

EPSS: Низкий
github логотип

GHSA-3fq7-8gqg-m2m9

больше 3 лет назад

An exploitable denial-of-service vulnerability exists in the session handling functionality of the NETGEAR N300 (WNR2000v5 with Firmware Version V1.0.0.70) HTTP server. An HTTP request with an empty User-Agent string sent to a page requiring authentication can cause a null pointer dereference, resulting in the HTTP service crashing. An unauthenticated attacker can send a specially crafted HTTP request to trigger this vulnerability.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-3fq7-5q53-mpg7

больше 3 лет назад

Use-after-free vulnerability in arch/x86/kvm/x86.c in the Linux kernel through 3.8.4 allows guest OS users to cause a denial of service (host OS memory corruption) or possibly have unspecified other impact via a crafted application that triggers use of a guest physical address (GPA) in (1) movable or (2) removable memory during an MSR_KVM_SYSTEM_TIME kvm_set_msr_common operation.

EPSS: Низкий
github логотип

GHSA-3fq7-38hc-94p4

почти 4 года назад

Efkan Forum 1.0 and earlier store sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for forum.mdb. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-3fq6-wpf5-96cx

почти 4 года назад

index.php in ezDatabase 2.1.2 and earlier allows remote attackers to obtain sensitive information via an invalid cat_id parameter, which leaks the full pathname in an error message. NOTE: these details are uncertain because the original report has terminology problems and lack of relevant details. The description is based partially on feedback comments.

EPSS: Низкий
github логотип

GHSA-3fq6-pwph-4674

больше 3 лет назад

The Webhooks component of Atlassian Jira before version 7.6.7 and from version 7.7.0 before version 7.11.0 allows remote attackers who are able to observe or otherwise intercept webhook events to learn information about changes in issues that should not be sent because they are not contained within the results of a specified JQL query.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3fq6-pp6m-49g9

больше 3 лет назад

A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0949, CVE-2019-0950.

EPSS: Низкий
github логотип

GHSA-3fq5-p5h6-7xvf

почти 4 года назад

Auto-update feature of Macromedia Shockwave 7 transmits a user's password and hard disk information back to Macromedia.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3fqg-54mc-wmg3

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-3fqc-v7hh-4m8x

In the Linux kernel, the following vulnerability has been resolved: libceph: return the handler error from mon_handle_auth_done() Currently any error from ceph_auth_handle_reply_done() is propagated via finish_auth() but isn't returned from mon_handle_auth_done(). This results in higher layers learning that (despite the monitor considering us to be successfully authenticated) something went wrong in the authentication phase and reacting accordingly, but msgr2 still trying to proceed with establishing the session in the background. In the case of secure mode this can trigger a WARN in setup_crypto() and later lead to a NULL pointer dereference inside of prepare_auth_signature().

0%
Низкий
16 дней назад
github логотип
GHSA-3fqc-qp8w-rr4h

A vulnerability in Zoom On-Premise Meeting Connector Controller version 4.8.102.20220310 and On-Premise Meeting Connector MMR version 4.8.102.20220310 exposes process memory fragments to connected clients, which could be observed by a passive attacker.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-3fqc-qhh2-fxhg

In GPAC MP4Box 1.1.0, there is a Null pointer reference in the function gf_filter_pid_get_packet function in src/filter_core/filter_pid.c:5394, as demonstrated by GPAC. This can cause a denial of service (DOS).

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3fq9-qj86-7ww9

Product: AndroidVersions: Android kernelAndroid ID: A-209014813References: N/A

CVSS3: 9.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-3fq9-h6m7-6g68

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RedefiningTheWeb PDF Generator Addon for Elementor Page Builder allows Stored XSS. This issue affects PDF Generator Addon for Elementor Page Builder: from n/a through 1.7.5.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-3fq9-fm98-2gqp

NVIDIA Tegra kernel driver contains a vulnerability in NVMAP where an attacker has the ability to write an arbitrary value to an arbitrary location which may lead to an escalation of privileges. This issue is rated as high.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3fq7-xp3x-g73j

Cross-site scripting (XSS) vulnerability in wp-plugins-net/index.php in the WP Plugin Manager (wppm) plugin 1.6.4.b and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the filter parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3fq7-x42r-jhxq

A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14. An app may be able to access Notes attachments.

CVSS3: 3.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3fq7-vqr9-hr59

A stack-based buffer overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Researchers have identified multiple vulnerabilities where there is a lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer, which could allow an attacker to execute arbitrary code under the context of the process.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3fq7-mmjq-fv4x

CandidATS version 3.0.0 allows an external attacker to elevate privileges in the application. This is possible because the application suffers from CSRF. This allows to persuade an administrator to create a new account with administrative permissions.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3fq7-hx4j-7hh8

Vulnerability in the BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise BI Publisher. While the vulnerability is in BI Publisher, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all BI Publisher accessible data as well as unauthorized update, insert or delete access to some of BI Publisher accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3fq7-c5m8-g86x

Mautic user without privileged access to the Marketplace can install and uninstall composer packages

0%
Низкий
2 месяца назад
github логотип
GHSA-3fq7-8gqg-m2m9

An exploitable denial-of-service vulnerability exists in the session handling functionality of the NETGEAR N300 (WNR2000v5 with Firmware Version V1.0.0.70) HTTP server. An HTTP request with an empty User-Agent string sent to a page requiring authentication can cause a null pointer dereference, resulting in the HTTP service crashing. An unauthenticated attacker can send a specially crafted HTTP request to trigger this vulnerability.

CVSS3: 7.5
11%
Средний
больше 3 лет назад
github логотип
GHSA-3fq7-5q53-mpg7

Use-after-free vulnerability in arch/x86/kvm/x86.c in the Linux kernel through 3.8.4 allows guest OS users to cause a denial of service (host OS memory corruption) or possibly have unspecified other impact via a crafted application that triggers use of a guest physical address (GPA) in (1) movable or (2) removable memory during an MSR_KVM_SYSTEM_TIME kvm_set_msr_common operation.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3fq7-38hc-94p4

Efkan Forum 1.0 and earlier store sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for forum.mdb. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3fq6-wpf5-96cx

index.php in ezDatabase 2.1.2 and earlier allows remote attackers to obtain sensitive information via an invalid cat_id parameter, which leaks the full pathname in an error message. NOTE: these details are uncertain because the original report has terminology problems and lack of relevant details. The description is based partially on feedback comments.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3fq6-pwph-4674

The Webhooks component of Atlassian Jira before version 7.6.7 and from version 7.7.0 before version 7.11.0 allows remote attackers who are able to observe or otherwise intercept webhook events to learn information about changes in issues that should not be sent because they are not contained within the results of a specified JQL query.

CVSS3: 5.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3fq6-pp6m-49g9

A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0949, CVE-2019-0950.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3fq5-p5h6-7xvf

Auto-update feature of Macromedia Shockwave 7 transmits a user's password and hard disk information back to Macromedia.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу