Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3fpm-hgm9-6v2c

больше 3 лет назад

The Management Web Interface in Palo Alto Networks PAN-OS before 7.1.9 allows remote authenticated users to gain privileges via unspecified request parameters.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3fpm-h3c3-72hq

6 месяцев назад

poco v1.14.1-release was discovered to contain weak encryption.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-3fpm-8w39-5p69

больше 3 лет назад

The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return a trust-scoped token when one is received, which allows remote trust users to gain privileges by generating EC2 credentials from a trust-scoped token and using them in an ec2tokens API request.

EPSS: Низкий
github логотип

GHSA-3fpj-j9c6-v8cp

больше 3 лет назад

DNRD (aka Domain Name Relay Daemon) 2.20.3 forwards and caches DNS queries with the CD (aka checking disabled) bit set to 1. This leads to disabling of DNSSEC protection provided by upstream resolvers.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3fpg-j8cw-vcjq

почти 2 года назад

A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIPassiveGrabDevice() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness. This vulnerability could be exploited by an attacker to cause the X server to read heap memory values and then transmit them back to the client until encountering an unmapped page, resulting in a crash. Despite the attacker's inability to control the specific memory copied into the replies, the small length values typically stored in a 32-bit integer can result in significant attempted out-of-bounds reads.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3fpg-9p39-ghm8

больше 3 лет назад

The SkBitmap::ReadRawPixels function in core/SkBitmap.cpp in the filters implementation in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an out-of-bounds write operation.

EPSS: Низкий
github логотип

GHSA-3fpg-5xv7-pq63

почти 2 года назад

A problem has been identified in the CloudStack additional VM configuration (extraconfig) feature which can be misused by anyone who has privilege to deploy a VM instance or configure settings of an already deployed VM instance, to configure additional VM configuration even when the feature is not explicitly enabled by the administrator. In a KVM based CloudStack environment, an attacker can exploit this issue to attach host devices such as storage disks, and PCI and USB devices such as network adapters and GPUs, in a regular VM instance that can be further exploited to gain access to the underlying network and storage infrastructure resources, and access any VM instance disks on the local storage. Users are advised to upgrade to version 4.18.1.1 or 4.19.0.1, which fixes this issue.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-3fpf-rc46-9vm6

больше 1 года назад

Missing Authorization vulnerability in WPChill Strong Testimonials allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Strong Testimonials: from n/a through 3.1.16.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3fpf-fcfr-3q46

больше 3 лет назад

IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 before 8.0.0.1 CF14, and 8.5.0 through 8.5.0.0 CF02 allows remote authenticated users to discover credentials by reading HTML source code.

EPSS: Низкий
github логотип

GHSA-3fp9-g95c-hppc

почти 4 года назад

In updateState of UsbDeviceManager.java, there is a possible unauthorized access of files due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-207057578

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3fp9-8qw5-j35g

больше 3 лет назад

PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has HTML injection via the First Name field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3fp9-5j6q-rjrv

больше 3 лет назад

TestLink v1.9.20 was discovered to contain a Cross-Site Request Forgery (CSRF) via /lib/plan/planView.php.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3fp8-pw38-wfpg

больше 3 лет назад

Huawei PCManager with the versions before 9.0.1.66 (Oversea) and versions before 9.0.1.70 (China) have an information leak vulnerability. Successful exploitation may cause the attacker to read information.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3fp8-5gxg-cm93

около 1 месяца назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-3fp6-x3rc-h83r

почти 4 года назад

Directory traversal vulnerability in (1) Openfile.aspx and (2) Html.aspx in HTTP Commander 4.0 allows remote attackers to view arbitrary files via a .. (dot dot) in the file parameter.

EPSS: Низкий
github логотип

GHSA-3fp6-mxrp-2j4g

больше 3 лет назад

Untrusted search path vulnerability in TeamViewer 5.0.8703 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a .tvs or .tvc file.

EPSS: Низкий
github логотип

GHSA-3fp6-h65v-mprr

почти 2 года назад

IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite for Software 1.10.12.0 through 1.10.19.0 does not set the SameSite attribute for sensitive cookies which could allow an attacker to obtain sensitive information using man-in-the-middle techniques. IBM X-Force ID: 233778.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3fp5-98pf-7937

больше 3 лет назад

The Uniwill SparkIO.sys driver 1.0 is vulnerable to a stack-based buffer overflow via IOCTL 0x40002008.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3fp5-72pm-rf42

больше 3 лет назад

wp-admin/press-this.php in WordPress before 3.0.6 does not enforce the publish_posts capability requirement, which allows remote authenticated users to perform publish actions by leveraging the Contributor role.

EPSS: Низкий
github логотип

GHSA-3fp5-374q-v5p2

почти 4 года назад

Unspecified vulnerability in OC4J for Oracle Application Server 9.0.4.2 and 10.1.2.0.0 has unknown impact and attack vectors, aka Oracle Vuln# AS07.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3fpm-hgm9-6v2c

The Management Web Interface in Palo Alto Networks PAN-OS before 7.1.9 allows remote authenticated users to gain privileges via unspecified request parameters.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3fpm-h3c3-72hq

poco v1.14.1-release was discovered to contain weak encryption.

CVSS3: 7
0%
Низкий
6 месяцев назад
github логотип
GHSA-3fpm-8w39-5p69

The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return a trust-scoped token when one is received, which allows remote trust users to gain privileges by generating EC2 credentials from a trust-scoped token and using them in an ec2tokens API request.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3fpj-j9c6-v8cp

DNRD (aka Domain Name Relay Daemon) 2.20.3 forwards and caches DNS queries with the CD (aka checking disabled) bit set to 1. This leads to disabling of DNSSEC protection provided by upstream resolvers.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3fpg-j8cw-vcjq

A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIPassiveGrabDevice() function. This issue occurs when byte-swapped length values are used in replies, potentially leading to memory leakage and segmentation faults, particularly when triggered by a client with a different endianness. This vulnerability could be exploited by an attacker to cause the X server to read heap memory values and then transmit them back to the client until encountering an unmapped page, resulting in a crash. Despite the attacker's inability to control the specific memory copied into the replies, the small length values typically stored in a 32-bit integer can result in significant attempted out-of-bounds reads.

CVSS3: 7.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-3fpg-9p39-ghm8

The SkBitmap::ReadRawPixels function in core/SkBitmap.cpp in the filters implementation in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an out-of-bounds write operation.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3fpg-5xv7-pq63

A problem has been identified in the CloudStack additional VM configuration (extraconfig) feature which can be misused by anyone who has privilege to deploy a VM instance or configure settings of an already deployed VM instance, to configure additional VM configuration even when the feature is not explicitly enabled by the administrator. In a KVM based CloudStack environment, an attacker can exploit this issue to attach host devices such as storage disks, and PCI and USB devices such as network adapters and GPUs, in a regular VM instance that can be further exploited to gain access to the underlying network and storage infrastructure resources, and access any VM instance disks on the local storage. Users are advised to upgrade to version 4.18.1.1 or 4.19.0.1, which fixes this issue.

CVSS3: 6.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-3fpf-rc46-9vm6

Missing Authorization vulnerability in WPChill Strong Testimonials allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Strong Testimonials: from n/a through 3.1.16.

CVSS3: 4.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-3fpf-fcfr-3q46

IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 before 8.0.0.1 CF14, and 8.5.0 through 8.5.0.0 CF02 allows remote authenticated users to discover credentials by reading HTML source code.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3fp9-g95c-hppc

In updateState of UsbDeviceManager.java, there is a possible unauthorized access of files due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-207057578

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-3fp9-8qw5-j35g

PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has HTML injection via the First Name field.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3fp9-5j6q-rjrv

TestLink v1.9.20 was discovered to contain a Cross-Site Request Forgery (CSRF) via /lib/plan/planView.php.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3fp8-pw38-wfpg

Huawei PCManager with the versions before 9.0.1.66 (Oversea) and versions before 9.0.1.70 (China) have an information leak vulnerability. Successful exploitation may cause the attacker to read information.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3fp8-5gxg-cm93

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

около 1 месяца назад
github логотип
GHSA-3fp6-x3rc-h83r

Directory traversal vulnerability in (1) Openfile.aspx and (2) Html.aspx in HTTP Commander 4.0 allows remote attackers to view arbitrary files via a .. (dot dot) in the file parameter.

5%
Низкий
почти 4 года назад
github логотип
GHSA-3fp6-mxrp-2j4g

Untrusted search path vulnerability in TeamViewer 5.0.8703 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a .tvs or .tvc file.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-3fp6-h65v-mprr

IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite for Software 1.10.12.0 through 1.10.19.0 does not set the SameSite attribute for sensitive cookies which could allow an attacker to obtain sensitive information using man-in-the-middle techniques. IBM X-Force ID: 233778.

CVSS3: 5.9
0%
Низкий
почти 2 года назад
github логотип
GHSA-3fp5-98pf-7937

The Uniwill SparkIO.sys driver 1.0 is vulnerable to a stack-based buffer overflow via IOCTL 0x40002008.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3fp5-72pm-rf42

wp-admin/press-this.php in WordPress before 3.0.6 does not enforce the publish_posts capability requirement, which allows remote authenticated users to perform publish actions by leveraging the Contributor role.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3fp5-374q-v5p2

Unspecified vulnerability in OC4J for Oracle Application Server 9.0.4.2 and 10.1.2.0.0 has unknown impact and attack vectors, aka Oracle Vuln# AS07.

3%
Низкий
почти 4 года назад

Уязвимостей на страницу