Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 292 067

Количество 292 067

github логотип

GHSA-22mq-rgq4-vw87

больше 3 лет назад

Unspecified vulnerability in the XDB - XML Database component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect availability via unknown vectors.

EPSS: Низкий
github логотип

GHSA-22mq-h6q3-chp7

больше 3 лет назад

Revive Adserver before 3.2.3 suffers from session fixation, by allowing arbitrary session identifiers to be forced and, at the same time, by not invalidating the existing session upon a successful authentication. Under some circumstances, that could have been an opportunity for an attacker to steal an authenticated session.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-22mm-995r-mr33

около 3 лет назад

IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-22mm-7p56-9x76

больше 3 лет назад

The GIGA HOBBY (aka com.innopage.store.gigahobby) application 1.0.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-22mm-7j6p-x82x

почти 2 года назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). The supported version that is affected is 8.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-22mj-xmh9-hw2p

больше 3 лет назад

A memory leak in the nfp_flower_spawn_vnic_reprs() function in drivers/net/ethernet/netronome/nfp/flower/main.c in the Linux kernel before 5.3.4 allows attackers to cause a denial of service (memory consumption), aka CID-8ce39eb5a67a.

EPSS: Низкий
github логотип

GHSA-22mj-r7hq-f9h2

4 месяца назад

Improper Verification of Cryptographic Signature vulnerability in LibreOffice allows PDF Signature Spoofing by Improper Validation. In the affected versions of LibreOffice a flaw in the verification code for adbe.pkcs7.sha1 signatures could cause invalid signatures to be accepted as valid This issue affects LibreOffice: from 24.8 before < 24.8.6, from 25.2 before < 25.2.2.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-22mj-9hjg-cp82

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: tap: add missing verification for short frame The cited commit missed to check against the validity of the frame length in the tap_get_user_xdp() path, which could cause a corrupted skb to be sent downstack. Even before the skb is transmitted, the tap_get_user_xdp()-->skb_set_network_header() may assume the size is more than ETH_HLEN. Once transmitted, this could either cause out-of-bound access beyond the actual length, or confuse the underlayer with incorrect or inconsistent header length in the skb metadata. In the alternative path, tap_get_user() already prohibits short frame which has the length less than Ethernet header size from being transmitted. This is to drop any frame shorter than the Ethernet header size just like how tap_get_user() does. CVE: CVE-2024-41090

EPSS: Низкий
github логотип

GHSA-22mj-96mj-m59p

больше 3 лет назад

Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows attackers to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2012-0756.

EPSS: Низкий
github логотип

GHSA-22mh-fcv5-gcmq

больше 2 лет назад

An HPE OneView appliance dump may expose proxy credential settings

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-22mh-26gq-mrqg

больше 3 лет назад

Simple WAIS (SWAIS) 1.11 allows remote attackers to execute arbitrary commands via the shell metacharacters in the search field, as demonstrated using the "|" (pipe) character.

EPSS: Низкий
github логотип

GHSA-22mg-v565-j444

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.13, when MakeClicky is configured, allows remote attackers to inject arbitrary web script or HTML via a URL in a ticket. NOTE: this issue has been SPLIT from CVE-2013-3371 due to different affected versions.

EPSS: Низкий
github логотип

GHSA-22mg-qg4r-wh4q

больше 3 лет назад

In GitLab before 13.0.12, 13.1.6 and 13.2.3, access grants were not revoked when a user revoked access to an application.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-22mg-hprw-43g2

около 2 лет назад

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Robert Heller WebLibrarian plugin <= 3.5.8.1 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-22mf-wg7m-839j

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the web based operator client in LiveZilla before 5.1.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) name of an uploaded file or (2) customer name in a resource created from an uploaded file, a different vulnerability than CVE-2013-7003.

EPSS: Низкий
github логотип

GHSA-22mf-f3cc-mh6f

больше 1 года назад

A vulnerability was found in Karjasoft Sami HTTP Server 2.0. It has been classified as problematic. Affected is an unknown function of the component HTTP HEAD Rrequest Handler. The manipulation leads to denial of service. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250836.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-22mf-97vh-x8rw

около 6 лет назад

Deserialization vulnerability exists in parso

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-22mc-c7v8-g2wp

почти 2 года назад

In the Unbreakable Enterprise Kernel (UEK), the RDS module in UEK has two setsockopt(2) options, RDS_CONN_RESET and RDS6_CONN_RESET, that are not re-entrant. A malicious local user with CAP_NET_ADMIN can use this to crash the kernel. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-22mc-4x52-cw6q

больше 3 лет назад

Windows Digital TV Tuner device registration application Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-22m9-m3ww-53h3

больше 2 лет назад

Flarum post mentions can be used to read any post on the forum without access control

CVSS3: 7.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-22mq-rgq4-vw87

Unspecified vulnerability in the XDB - XML Database component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect availability via unknown vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-22mq-h6q3-chp7

Revive Adserver before 3.2.3 suffers from session fixation, by allowing arbitrary session identifiers to be forced and, at the same time, by not invalidating the existing session upon a successful authentication. Under some circumstances, that could have been an opportunity for an attacker to steal an authenticated session.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-22mm-995r-mr33

IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-22mm-7p56-9x76

The GIGA HOBBY (aka com.innopage.store.gigahobby) application 1.0.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-22mm-7j6p-x82x

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). The supported version that is affected is 8.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-22mj-xmh9-hw2p

A memory leak in the nfp_flower_spawn_vnic_reprs() function in drivers/net/ethernet/netronome/nfp/flower/main.c in the Linux kernel before 5.3.4 allows attackers to cause a denial of service (memory consumption), aka CID-8ce39eb5a67a.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-22mj-r7hq-f9h2

Improper Verification of Cryptographic Signature vulnerability in LibreOffice allows PDF Signature Spoofing by Improper Validation. In the affected versions of LibreOffice a flaw in the verification code for adbe.pkcs7.sha1 signatures could cause invalid signatures to be accepted as valid This issue affects LibreOffice: from 24.8 before < 24.8.6, from 25.2 before < 25.2.2.

CVSS3: 9.8
0%
Низкий
4 месяца назад
github логотип
GHSA-22mj-9hjg-cp82

In the Linux kernel, the following vulnerability has been resolved: tap: add missing verification for short frame The cited commit missed to check against the validity of the frame length in the tap_get_user_xdp() path, which could cause a corrupted skb to be sent downstack. Even before the skb is transmitted, the tap_get_user_xdp()-->skb_set_network_header() may assume the size is more than ETH_HLEN. Once transmitted, this could either cause out-of-bound access beyond the actual length, or confuse the underlayer with incorrect or inconsistent header length in the skb metadata. In the alternative path, tap_get_user() already prohibits short frame which has the length less than Ethernet header size from being transmitted. This is to drop any frame shorter than the Ethernet header size just like how tap_get_user() does. CVE: CVE-2024-41090

0%
Низкий
около 1 года назад
github логотип
GHSA-22mj-96mj-m59p

Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows attackers to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2012-0756.

5%
Низкий
больше 3 лет назад
github логотип
GHSA-22mh-fcv5-gcmq

An HPE OneView appliance dump may expose proxy credential settings

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-22mh-26gq-mrqg

Simple WAIS (SWAIS) 1.11 allows remote attackers to execute arbitrary commands via the shell metacharacters in the search field, as demonstrated using the "|" (pipe) character.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-22mg-v565-j444

Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.13, when MakeClicky is configured, allows remote attackers to inject arbitrary web script or HTML via a URL in a ticket. NOTE: this issue has been SPLIT from CVE-2013-3371 due to different affected versions.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-22mg-qg4r-wh4q

In GitLab before 13.0.12, 13.1.6 and 13.2.3, access grants were not revoked when a user revoked access to an application.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-22mg-hprw-43g2

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Robert Heller WebLibrarian plugin <= 3.5.8.1 versions.

CVSS3: 7.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-22mf-wg7m-839j

Multiple cross-site scripting (XSS) vulnerabilities in the web based operator client in LiveZilla before 5.1.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) name of an uploaded file or (2) customer name in a resource created from an uploaded file, a different vulnerability than CVE-2013-7003.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-22mf-f3cc-mh6f

A vulnerability was found in Karjasoft Sami HTTP Server 2.0. It has been classified as problematic. Affected is an unknown function of the component HTTP HEAD Rrequest Handler. The manipulation leads to denial of service. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250836.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-22mf-97vh-x8rw

Deserialization vulnerability exists in parso

CVSS3: 7.5
1%
Низкий
около 6 лет назад
github логотип
GHSA-22mc-c7v8-g2wp

In the Unbreakable Enterprise Kernel (UEK), the RDS module in UEK has two setsockopt(2) options, RDS_CONN_RESET and RDS6_CONN_RESET, that are not re-entrant. A malicious local user with CAP_NET_ADMIN can use this to crash the kernel. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-22mc-4x52-cw6q

Windows Digital TV Tuner device registration application Elevation of Privilege Vulnerability

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-22m9-m3ww-53h3

Flarum post mentions can be used to read any post on the forum without access control

CVSS3: 7.7
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу