Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3f43-59gc-w39r

почти 3 года назад

In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628588; Issue ID: ALPS07628588.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3f42-7384-7vpr

около 2 лет назад

Zoho ManageEngine ADAudit Plus through 7250 allows SQL Injection in the aggregate report feature.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3f3x-x2x3-wvhg

около 4 лет назад

Guest can force Linux netback driver to hog large amounts of kernel memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Incoming data packets for a guest in the Linux kernel's netback driver are buffered until the guest is ready to process them. There are some measures taken for avoiding to pile up too much data, but those can be bypassed by the guest: There is a timeout how long the client side of an interface can stop consuming new packets before it is assumed to have stalled, but this timeout is rather long (60 seconds by default). Using a UDP connection on a fast interface can easily accumulate gigabytes of data in that time. (CVE-2021-28715) The timeout could even never trigger if the guest manages to have only one free slot in its RX queue ring page and the next package would require more than one free slot, which may be the case when using GSO, XDP, or software hashing. (CVE-2021-28714)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3f3x-rr4h-mf7f

почти 4 года назад

** DISPUTED ** Microsoft Internet Explorer 7.0 Beta allows remote attackers to cause a denial of service (application crash) via a web page with multiple empty APPLET start tags. NOTE: a third party has disputed this issue, stating that the crash does not occur with Microsoft Internet Explorer 7.0 Beta3.

EPSS: Средний
github логотип

GHSA-3f3x-7h29-jgrg

12 месяцев назад

A SQL Injection vulnerability was found in /admin/edit-propertytype.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the editid GET request parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3f3w-qrjm-6m77

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: mm: cachestat: fix two shmem bugs When cachestat on shmem races with swapping and invalidation, there are two possible bugs: 1) A swapin error can have resulted in a poisoned swap entry in the shmem inode's xarray. Calling get_shadow_from_swap_cache() on it will result in an out-of-bounds access to swapper_spaces[]. Validate the entry with non_swap_entry() before going further. 2) When we find a valid swap entry in the shmem's inode, the shadow entry in the swapcache might not exist yet: swap IO is still in progress and we're before __remove_mapping; swapin, invalidation, or swapoff have removed the shadow from swapcache after we saw the shmem swap entry. This will send a NULL to workingset_test_recent(). The latter purely operates on pointer bits, so it won't crash - node 0, memcg ID 0, eviction timestamp 0, etc. are all valid inputs - but it's a bogus test. In theory that cou...

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3f3w-h3vg-6wx9

больше 3 лет назад

An out-of-bounds heap read vulnerability was found in the jpc_pi_nextpcrl() function of jasper before 2.0.6 when processing crafted input.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3f3w-gmqf-4hj3

больше 3 лет назад

Apache Linkis subject to Remote Code Execution via deserialization

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3f3w-cq8p-qm4f

больше 3 лет назад

Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters). The supported version that is affected is 8.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology. Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS score depend on the software that uses the Outside In Technology code. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology code, but if data is not received over a network t...

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3f3w-7mj3-hjf9

больше 2 лет назад

Use after free in UI in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3f3w-4rvj-j62g

больше 2 лет назад

Memory Corruption due to improper validation of array index in Linux while updating adn record.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3f3v-mh9q-2pxq

больше 3 лет назад

libxml2 in Apple iOS before 9.3, OS X before 10.11.4, and watchOS before 2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XML document.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-3f3v-j4pm-7283

около 4 лет назад

An out-of-bounds read vulnerability exists when reading a TIF file using Open Design Alliance Drawings SDK before 2022.12. The specific issue exists after loading TIF files. An unchecked input data from a crafted TIF file leads to an out-of-bounds read. An attacker can leverage this vulnerability to execute code in the context of the current process.

EPSS: Низкий
github логотип

GHSA-3f3v-9mp5-jfjc

почти 3 года назад

A stored Cross-site Scripting (XSS) vulnerability in BlogEngine.NET 3.3.8.0, allows injection of arbitrary JavaScript in the security context of a blog visitor through an upload of a specially crafted file.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3f3v-72qh-67q2

больше 3 лет назад

An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in memory, aka 'Windows State Repository Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1124, CVE-2020-1131, CVE-2020-1144, CVE-2020-1184, CVE-2020-1185, CVE-2020-1186, CVE-2020-1187, CVE-2020-1188, CVE-2020-1189, CVE-2020-1190, CVE-2020-1191.

EPSS: Низкий
github логотип

GHSA-3f3r-g48r-83hh

больше 3 лет назад

A flaw was found in Red Hat 3scale’s API docs URL, where it is accessible without credentials. This flaw allows an attacker to view sensitive information or modify service APIs. Versions before 3scale-2.10.0-ER1 are affected.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3f3r-7r2j-v7vc

3 месяца назад

A flaw has been found in SourceCodester Best House Rental Management System 1.0. Affected by this issue is the function save_tenant of the file /admin_class.php. Executing manipulation of the argument firstname can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used. Other parameters might be affected as well.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-3f3q-q5cj-phc5

5 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix race with concurrent opens in rename(2) Besides sending the rename request to the server, the rename process also involves closing any deferred close, waiting for outstanding I/O to complete as well as marking all existing open handles as deleted to prevent them from deferring closes, which increases the race window for potential concurrent opens on the target file. Fix this by unhashing the dentry in advance to prevent any concurrent opens on the target.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-3f3q-cv7c-w6c7

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: mm/damon/dbgfs: protect targets destructions with kdamond_lock DAMON debugfs interface iterates current monitoring targets in 'dbgfs_target_ids_read()' while holding the corresponding 'kdamond_lock'. However, it also destructs the monitoring targets in 'dbgfs_before_terminate()' without holding the lock. This can result in a use_after_free bug. This commit avoids the race by protecting the destruction with the corresponding 'kdamond_lock'.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-3f3p-qhfv-7p8h

больше 3 лет назад

Jenkins openid Plugin missing permission check

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3f43-59gc-w39r

In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628588; Issue ID: ALPS07628588.

CVSS3: 6.7
0%
Низкий
почти 3 года назад
github логотип
GHSA-3f42-7384-7vpr

Zoho ManageEngine ADAudit Plus through 7250 allows SQL Injection in the aggregate report feature.

CVSS3: 9.8
9%
Низкий
около 2 лет назад
github логотип
GHSA-3f3x-x2x3-wvhg

Guest can force Linux netback driver to hog large amounts of kernel memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Incoming data packets for a guest in the Linux kernel's netback driver are buffered until the guest is ready to process them. There are some measures taken for avoiding to pile up too much data, but those can be bypassed by the guest: There is a timeout how long the client side of an interface can stop consuming new packets before it is assumed to have stalled, but this timeout is rather long (60 seconds by default). Using a UDP connection on a fast interface can easily accumulate gigabytes of data in that time. (CVE-2021-28715) The timeout could even never trigger if the guest manages to have only one free slot in its RX queue ring page and the next package would require more than one free slot, which may be the case when using GSO, XDP, or software hashing. (CVE-2021-28714)

CVSS3: 6.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-3f3x-rr4h-mf7f

** DISPUTED ** Microsoft Internet Explorer 7.0 Beta allows remote attackers to cause a denial of service (application crash) via a web page with multiple empty APPLET start tags. NOTE: a third party has disputed this issue, stating that the crash does not occur with Microsoft Internet Explorer 7.0 Beta3.

21%
Средний
почти 4 года назад
github логотип
GHSA-3f3x-7h29-jgrg

A SQL Injection vulnerability was found in /admin/edit-propertytype.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the editid GET request parameter.

CVSS3: 9.8
1%
Низкий
12 месяцев назад
github логотип
GHSA-3f3w-qrjm-6m77

In the Linux kernel, the following vulnerability has been resolved: mm: cachestat: fix two shmem bugs When cachestat on shmem races with swapping and invalidation, there are two possible bugs: 1) A swapin error can have resulted in a poisoned swap entry in the shmem inode's xarray. Calling get_shadow_from_swap_cache() on it will result in an out-of-bounds access to swapper_spaces[]. Validate the entry with non_swap_entry() before going further. 2) When we find a valid swap entry in the shmem's inode, the shadow entry in the swapcache might not exist yet: swap IO is still in progress and we're before __remove_mapping; swapin, invalidation, or swapoff have removed the shadow from swapcache after we saw the shmem swap entry. This will send a NULL to workingset_test_recent(). The latter purely operates on pointer bits, so it won't crash - node 0, memcg ID 0, eviction timestamp 0, etc. are all valid inputs - but it's a bogus test. In theory that cou...

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-3f3w-h3vg-6wx9

An out-of-bounds heap read vulnerability was found in the jpc_pi_nextpcrl() function of jasper before 2.0.6 when processing crafted input.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3f3w-gmqf-4hj3

Apache Linkis subject to Remote Code Execution via deserialization

CVSS3: 8.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3f3w-cq8p-qm4f

Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters). The supported version that is affected is 8.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology. Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS score depend on the software that uses the Outside In Technology code. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology code, but if data is not received over a network t...

CVSS3: 7.1
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3f3w-7mj3-hjf9

Use after free in UI in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3f3w-4rvj-j62g

Memory Corruption due to improper validation of array index in Linux while updating adn record.

CVSS3: 6.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3f3v-mh9q-2pxq

libxml2 in Apple iOS before 9.3, OS X before 10.11.4, and watchOS before 2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XML document.

CVSS3: 9.8
14%
Средний
больше 3 лет назад
github логотип
GHSA-3f3v-j4pm-7283

An out-of-bounds read vulnerability exists when reading a TIF file using Open Design Alliance Drawings SDK before 2022.12. The specific issue exists after loading TIF files. An unchecked input data from a crafted TIF file leads to an out-of-bounds read. An attacker can leverage this vulnerability to execute code in the context of the current process.

0%
Низкий
около 4 лет назад
github логотип
GHSA-3f3v-9mp5-jfjc

A stored Cross-site Scripting (XSS) vulnerability in BlogEngine.NET 3.3.8.0, allows injection of arbitrary JavaScript in the security context of a blog visitor through an upload of a specially crafted file.

CVSS3: 5.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-3f3v-72qh-67q2

An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in memory, aka 'Windows State Repository Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1124, CVE-2020-1131, CVE-2020-1144, CVE-2020-1184, CVE-2020-1185, CVE-2020-1186, CVE-2020-1187, CVE-2020-1188, CVE-2020-1189, CVE-2020-1190, CVE-2020-1191.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3f3r-g48r-83hh

A flaw was found in Red Hat 3scale’s API docs URL, where it is accessible without credentials. This flaw allows an attacker to view sensitive information or modify service APIs. Versions before 3scale-2.10.0-ER1 are affected.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3f3r-7r2j-v7vc

A flaw has been found in SourceCodester Best House Rental Management System 1.0. Affected by this issue is the function save_tenant of the file /admin_class.php. Executing manipulation of the argument firstname can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used. Other parameters might be affected as well.

CVSS3: 4.7
0%
Низкий
3 месяца назад
github логотип
GHSA-3f3q-q5cj-phc5

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix race with concurrent opens in rename(2) Besides sending the rename request to the server, the rename process also involves closing any deferred close, waiting for outstanding I/O to complete as well as marking all existing open handles as deleted to prevent them from deferring closes, which increases the race window for potential concurrent opens on the target file. Fix this by unhashing the dentry in advance to prevent any concurrent opens on the target.

CVSS3: 4.7
0%
Низкий
5 месяцев назад
github логотип
GHSA-3f3q-cv7c-w6c7

In the Linux kernel, the following vulnerability has been resolved: mm/damon/dbgfs: protect targets destructions with kdamond_lock DAMON debugfs interface iterates current monitoring targets in 'dbgfs_target_ids_read()' while holding the corresponding 'kdamond_lock'. However, it also destructs the monitoring targets in 'dbgfs_before_terminate()' without holding the lock. This can result in a use_after_free bug. This commit avoids the race by protecting the destruction with the corresponding 'kdamond_lock'.

CVSS3: 7
0%
Низкий
почти 2 года назад
github логотип
GHSA-3f3p-qhfv-7p8h

Jenkins openid Plugin missing permission check

CVSS3: 6.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу