Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 212

Количество 314 212

github логотип

GHSA-3cr5-frrf-7285

больше 3 лет назад

, aka 'Kerberos Security Feature Bypass Vulnerability'.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3cr5-fc93-2g6v

больше 3 лет назад

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the calculateNow method. By performing actions in JavaScript, an attacker can trigger a type confusion condition. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-6007.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3cr5-2446-8pg3

около 2 лет назад

PaddlePaddle command injection in convert_shape_compare

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-3cr4-xm57-685p

почти 4 года назад

A user interface issue was addressed. This issue is fixed in watchOS 8.5, Safari 15.4. Visiting a malicious website may lead to address bar spoofing.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3cr4-wh42-gq3c

больше 2 лет назад

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x expose dashboard prompts to users who are not part of the authorization list. 

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3cr4-c5wq-3ccv

больше 3 лет назад

By design, BIND is intended to limit the number of TCP clients that can be connected at any given time. The number of allowed connections is a tunable parameter which, if unset, defaults to a conservative value for most servers. Unfortunately, the code which was intended to limit the number of simultaneous connections contained an error which could be exploited to grow the number of simultaneous connections beyond this limit. Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.6, 9.12.0 -> 9.12.4, 9.14.0. BIND 9 Supported Preview Edition versions 9.9.3-S1 -> 9.11.5-S3, and 9.11.5-S5. Versions 9.13.0 -> 9.13.7 of the 9.13 development branch are also affected. Versions prior to BIND 9.9.0 have not been evaluated for vulnerability to CVE-2018-5743.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3cr3-v8qm-wfcv

больше 1 года назад

Wavelog 1.8.5 allows Activated_gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3cr3-h6hf-h5mg

больше 3 лет назад

Windows WLAN AutoConfig Service Security Feature Bypass Vulnerability

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-3cr3-865x-m256

почти 4 года назад

Gallery.pm in Apache::Gallery (aka A::G) uses predictable temporary filenames when running Inline::C, which allows local users to execute arbitrary code by creating and modifying the files before Apache::Gallery does.

EPSS: Низкий
github логотип

GHSA-3cqw-w427-m45x

больше 2 лет назад

Use after free vulnerability exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3cqw-vxh9-h7x2

больше 3 лет назад

A potential security vulnerability has been identified in the software solution HP Access Control versions prior to 16.7. This vulnerability could potentially grant elevation of privilege.

EPSS: Низкий
github логотип

GHSA-3cqw-pxgr-jhrm

почти 4 года назад

TYPO3 Backend Command Injection via Shell Metacharacters in Uploaded File Name

EPSS: Низкий
github логотип

GHSA-3cqw-cf93-mf47

около 3 лет назад

An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. There is Blind Stored XSS via a URL to the Upload Image feature.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3cqw-4qwf-ghv9

почти 4 года назад

The Microsoft Java implementation, as used in Internet Explorer, provides a public load0() method for the CabCracker class (com.ms.vm.loader.CabCracker), which allows remote attackers to bypass the security checks that are performed by the load() method.

EPSS: Низкий
github логотип

GHSA-3cqv-h6hf-3729

10 месяцев назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-3cqr-ghj9-p46w

4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: cpufreq: davinci: Fix clk use after free The remove function first frees the clks and only then calls cpufreq_unregister_driver(). If one of the cpufreq callbacks is called just before cpufreq_unregister_driver() is run, the freed clks might be used.

EPSS: Низкий
github логотип

GHSA-3cqr-58rm-57f8

почти 4 года назад

Arbitrary Code Execution in Handlebars

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3cqq-q6w5-34hf

больше 3 лет назад

Adobe Flash Player before 18.0.0.252 and 19.x before 19.0.0.207 on Windows and OS X and before 11.2.202.535 on Linux, Adobe AIR before 19.0.0.213, Adobe AIR SDK before 19.0.0.213, and Adobe AIR SDK & Compiler before 19.0.0.213 improperly implement the Flash broker API, which has unspecified impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-3cqq-q3c4-9jg6

почти 4 года назад

The NFS server in Sun Solaris 10, and OpenSolaris before snv_111, does not properly implement the AUTH_NONE (aka sec=none) security mode in combination with other security modes, which allows remote attackers to bypass intended access restrictions and read or modify files, as demonstrated by a combination of the AUTH_NONE and AUTH_SYS security modes.

EPSS: Низкий
github логотип

GHSA-3cqq-f797-pvc4

около 2 лет назад

Cross Site Scripting (XSS) vulnerability in AVA teaching video application service platform version 3.1, allows remote attackers to execute arbitrary code via a crafted script to ajax.aspx.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3cr5-frrf-7285

, aka 'Kerberos Security Feature Bypass Vulnerability'.

CVSS3: 6.5
9%
Низкий
больше 3 лет назад
github логотип
GHSA-3cr5-fc93-2g6v

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the calculateNow method. By performing actions in JavaScript, an attacker can trigger a type confusion condition. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-6007.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3cr5-2446-8pg3

PaddlePaddle command injection in convert_shape_compare

CVSS3: 9.6
0%
Низкий
около 2 лет назад
github логотип
GHSA-3cr4-xm57-685p

A user interface issue was addressed. This issue is fixed in watchOS 8.5, Safari 15.4. Visiting a malicious website may lead to address bar spoofing.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-3cr4-wh42-gq3c

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x expose dashboard prompts to users who are not part of the authorization list. 

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3cr4-c5wq-3ccv

By design, BIND is intended to limit the number of TCP clients that can be connected at any given time. The number of allowed connections is a tunable parameter which, if unset, defaults to a conservative value for most servers. Unfortunately, the code which was intended to limit the number of simultaneous connections contained an error which could be exploited to grow the number of simultaneous connections beyond this limit. Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.6, 9.12.0 -> 9.12.4, 9.14.0. BIND 9 Supported Preview Edition versions 9.9.3-S1 -> 9.11.5-S3, and 9.11.5-S5. Versions 9.13.0 -> 9.13.7 of the 9.13 development branch are also affected. Versions prior to BIND 9.9.0 have not been evaluated for vulnerability to CVE-2018-5743.

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3cr3-v8qm-wfcv

Wavelog 1.8.5 allows Activated_gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.

CVSS3: 9.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3cr3-h6hf-h5mg

Windows WLAN AutoConfig Service Security Feature Bypass Vulnerability

CVSS3: 4.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3cr3-865x-m256

Gallery.pm in Apache::Gallery (aka A::G) uses predictable temporary filenames when running Inline::C, which allows local users to execute arbitrary code by creating and modifying the files before Apache::Gallery does.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3cqw-w427-m45x

Use after free vulnerability exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3cqw-vxh9-h7x2

A potential security vulnerability has been identified in the software solution HP Access Control versions prior to 16.7. This vulnerability could potentially grant elevation of privilege.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3cqw-pxgr-jhrm

TYPO3 Backend Command Injection via Shell Metacharacters in Uploaded File Name

1%
Низкий
почти 4 года назад
github логотип
GHSA-3cqw-cf93-mf47

An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. There is Blind Stored XSS via a URL to the Upload Image feature.

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-3cqw-4qwf-ghv9

The Microsoft Java implementation, as used in Internet Explorer, provides a public load0() method for the CabCracker class (com.ms.vm.loader.CabCracker), which allows remote attackers to bypass the security checks that are performed by the load() method.

3%
Низкий
почти 4 года назад
github логотип
GHSA-3cqv-h6hf-3729

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
0%
Низкий
10 месяцев назад
github логотип
GHSA-3cqr-ghj9-p46w

In the Linux kernel, the following vulnerability has been resolved: cpufreq: davinci: Fix clk use after free The remove function first frees the clks and only then calls cpufreq_unregister_driver(). If one of the cpufreq callbacks is called just before cpufreq_unregister_driver() is run, the freed clks might be used.

0%
Низкий
4 месяца назад
github логотип
GHSA-3cqr-58rm-57f8

Arbitrary Code Execution in Handlebars

CVSS3: 8.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-3cqq-q6w5-34hf

Adobe Flash Player before 18.0.0.252 and 19.x before 19.0.0.207 on Windows and OS X and before 11.2.202.535 on Linux, Adobe AIR before 19.0.0.213, Adobe AIR SDK before 19.0.0.213, and Adobe AIR SDK & Compiler before 19.0.0.213 improperly implement the Flash broker API, which has unspecified impact and attack vectors.

6%
Низкий
больше 3 лет назад
github логотип
GHSA-3cqq-q3c4-9jg6

The NFS server in Sun Solaris 10, and OpenSolaris before snv_111, does not properly implement the AUTH_NONE (aka sec=none) security mode in combination with other security modes, which allows remote attackers to bypass intended access restrictions and read or modify files, as demonstrated by a combination of the AUTH_NONE and AUTH_SYS security modes.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3cqq-f797-pvc4

Cross Site Scripting (XSS) vulnerability in AVA teaching video application service platform version 3.1, allows remote attackers to execute arbitrary code via a crafted script to ajax.aspx.

CVSS3: 6.1
0%
Низкий
около 2 лет назад

Уязвимостей на страницу