Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3f39-v4r2-mjqq

больше 3 лет назад

Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicket and "custom lifecycle transition" permission, which allows remote authenticated users with the ModifyTicket permission to delete tickets via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3f39-gxh3-r25v

больше 3 лет назад

The Security component in IBM DB2 UDB 9.5 before FP6a logs AUDIT events by using a USERID and an AUTHID value corresponding to the instance owner, instead of a USERID and an AUTHID value corresponding to the logged-in user account, which makes it easier for remote authenticated users to execute Audit administration commands without discovery.

EPSS: Низкий
github логотип

GHSA-3f38-wq7x-5cp3

8 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme Nitan allows PHP Local File Inclusion. This issue affects Nitan: from n/a through 2.9.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3f38-96qm-r3fw

около 2 лет назад

esptool allows attackers to view sensitive information via weak cryptographic algorithm

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3f37-xrxw-857g

больше 3 лет назад

Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly allocate memory, which allows remote attackers to cause a denial of service via a crafted (1) web site or (2) file, aka "Adobe Font Driver Denial of Service Vulnerability."

EPSS: Средний
github логотип

GHSA-3f37-fppf-rcr7

почти 4 года назад

SQL injection vulnerability in functions.php in Teca Diary PE 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) yy, (2) mm, and (3) dd parameters.

EPSS: Низкий
github логотип

GHSA-3f36-xgxj-8g4q

больше 3 лет назад

(1) AlbumTab.py, (2) ArtistTab.py, (3) LinksTab.py, and (4) LyricsTab.py in the Context module in GNOME Rhythmbox 0.13.3 and earlier allows local users to execute arbitrary code via a symlink attack on a temporary HTML template file in the /tmp/context directory.

EPSS: Низкий
github логотип

GHSA-3f36-x6r9-r53h

2 месяца назад

In the Linux kernel, the following vulnerability has been resolved: sched_ext: Fix scx_enable() crash on helper kthread creation failure A crash was observed when the sched_ext selftests runner was terminated with Ctrl+\ while test 15 was running: NIP [c00000000028fa58] scx_enable.constprop.0+0x358/0x12b0 LR [c00000000028fa2c] scx_enable.constprop.0+0x32c/0x12b0 Call Trace: scx_enable.constprop.0+0x32c/0x12b0 (unreliable) bpf_struct_ops_link_create+0x18c/0x22c __sys_bpf+0x23f8/0x3044 sys_bpf+0x2c/0x6c system_call_exception+0x124/0x320 system_call_vectored_common+0x15c/0x2ec kthread_run_worker() returns an ERR_PTR() on failure rather than NULL, but the current code in scx_alloc_and_add_sched() only checks for a NULL helper. Incase of failure on SIGQUIT, the error is not handled in scx_alloc_and_add_sched() and scx_enable() ends up dereferencing an error pointer. Error handling is fixed in scx_alloc_and_add_sched() to propagate PTR_ERR() into ret, so that scx_enable() jumps to th...

EPSS: Низкий
github логотип

GHSA-3f36-r4c3-hh86

около 3 лет назад

The search term could have been specified externally to trigger SQL injection. This vulnerability affects Firefox for iOS < 101.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3f35-5jmv-gjvp

около 2 лет назад

Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Bookings.This issue affects WooCommerce Bookings: from n/a through 1.15.78.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3f33-r945-2gv6

больше 3 лет назад

The nlm_swap_auxiliary_headers_in function in bfd/nlmcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap read via a crafted nlm file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3f33-424w-8gqc

2 месяца назад

EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access. Successful exploitation of this vulnerability could alter control flow in unexpected ways, potentially allowing arbitrary command execution and impacting Confidentiality, Integrity, and Availability.

EPSS: Низкий
github логотип

GHSA-3f32-jc9w-78m7

больше 1 года назад

The goTenna Pro series use AES CTR mode for short, encrypted messages without any additional integrity checking mechanisms. This leaves messages malleable to any attacker that can access the message.

EPSS: Низкий
github логотип

GHSA-3f32-592h-7fx5

почти 4 года назад

A CWE-862: Missing Authorization vulnerability exists that could cause information exposure when an attacker sends a specific message. Affected Product: Interactive Graphical SCADA System Data Server (V15.0.0.22020 and prior)

EPSS: Низкий
github логотип

GHSA-3f2v-mfqw-2824

19 дней назад

Multiple reflected cross-site scripting (xss) vulnerabilities exist in the config.php functionality of MedDream PACS Premium 7.3.6.870. Specially crafted malicious URLs can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger these vulnerabilities.This vulnerability affects the status parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3f2v-9x94-8rwj

больше 3 лет назад

A vulnerability, which was classified as problematic, was found in Axiomatic Bento4. Affected is an unknown function of the component mp4decrypt. The manipulation leads to memory leak. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-212682 is the identifier assigned to this vulnerability.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3f2r-h473-hqjx

больше 3 лет назад

MKCMS V6.2 has SQL injection via /ucenter/reg.php name parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3f2r-5fxf-85xw

больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability on HP ProCurve 1700-8 (aka J9079A) switches with software before VA.02.09 and 1700-24 (aka J9080A) switches with software before VB.02.09 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

EPSS: Низкий
github логотип

GHSA-3f2r-2r5j-wqrm

почти 4 года назад

Buffer overflow in CWMail.exe in NetWin before 2.8a allows remote authenticated users to execute arbitrary code via a long item parameter.

EPSS: Низкий
github логотип

GHSA-3f2q-h2mg-2c86

больше 3 лет назад

In Poppler 0.54.0, a memory leak vulnerability was found in the function Object::initArray in Object.cc, which allows attackers to cause a denial of service via a crafted file.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3f39-v4r2-mjqq

Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicket and "custom lifecycle transition" permission, which allows remote authenticated users with the ModifyTicket permission to delete tickets via unspecified vectors.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3f39-gxh3-r25v

The Security component in IBM DB2 UDB 9.5 before FP6a logs AUDIT events by using a USERID and an AUTHID value corresponding to the instance owner, instead of a USERID and an AUTHID value corresponding to the logged-in user account, which makes it easier for remote authenticated users to execute Audit administration commands without discovery.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3f38-wq7x-5cp3

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme Nitan allows PHP Local File Inclusion. This issue affects Nitan: from n/a through 2.9.

CVSS3: 8.1
0%
Низкий
8 месяцев назад
github логотип
GHSA-3f38-96qm-r3fw

esptool allows attackers to view sensitive information via weak cryptographic algorithm

CVSS3: 7.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-3f37-xrxw-857g

Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly allocate memory, which allows remote attackers to cause a denial of service via a crafted (1) web site or (2) file, aka "Adobe Font Driver Denial of Service Vulnerability."

15%
Средний
больше 3 лет назад
github логотип
GHSA-3f37-fppf-rcr7

SQL injection vulnerability in functions.php in Teca Diary PE 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) yy, (2) mm, and (3) dd parameters.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3f36-xgxj-8g4q

(1) AlbumTab.py, (2) ArtistTab.py, (3) LinksTab.py, and (4) LyricsTab.py in the Context module in GNOME Rhythmbox 0.13.3 and earlier allows local users to execute arbitrary code via a symlink attack on a temporary HTML template file in the /tmp/context directory.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3f36-x6r9-r53h

In the Linux kernel, the following vulnerability has been resolved: sched_ext: Fix scx_enable() crash on helper kthread creation failure A crash was observed when the sched_ext selftests runner was terminated with Ctrl+\ while test 15 was running: NIP [c00000000028fa58] scx_enable.constprop.0+0x358/0x12b0 LR [c00000000028fa2c] scx_enable.constprop.0+0x32c/0x12b0 Call Trace: scx_enable.constprop.0+0x32c/0x12b0 (unreliable) bpf_struct_ops_link_create+0x18c/0x22c __sys_bpf+0x23f8/0x3044 sys_bpf+0x2c/0x6c system_call_exception+0x124/0x320 system_call_vectored_common+0x15c/0x2ec kthread_run_worker() returns an ERR_PTR() on failure rather than NULL, but the current code in scx_alloc_and_add_sched() only checks for a NULL helper. Incase of failure on SIGQUIT, the error is not handled in scx_alloc_and_add_sched() and scx_enable() ends up dereferencing an error pointer. Error handling is fixed in scx_alloc_and_add_sched() to propagate PTR_ERR() into ret, so that scx_enable() jumps to th...

0%
Низкий
2 месяца назад
github логотип
GHSA-3f36-r4c3-hh86

The search term could have been specified externally to trigger SQL injection. This vulnerability affects Firefox for iOS < 101.

CVSS3: 9.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-3f35-5jmv-gjvp

Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Bookings.This issue affects WooCommerce Bookings: from n/a through 1.15.78.

CVSS3: 5.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-3f33-r945-2gv6

The nlm_swap_auxiliary_headers_in function in bfd/nlmcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap read via a crafted nlm file.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3f33-424w-8gqc

EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access. Successful exploitation of this vulnerability could alter control flow in unexpected ways, potentially allowing arbitrary command execution and impacting Confidentiality, Integrity, and Availability.

0%
Низкий
2 месяца назад
github логотип
GHSA-3f32-jc9w-78m7

The goTenna Pro series use AES CTR mode for short, encrypted messages without any additional integrity checking mechanisms. This leaves messages malleable to any attacker that can access the message.

0%
Низкий
больше 1 года назад
github логотип
GHSA-3f32-592h-7fx5

A CWE-862: Missing Authorization vulnerability exists that could cause information exposure when an attacker sends a specific message. Affected Product: Interactive Graphical SCADA System Data Server (V15.0.0.22020 and prior)

0%
Низкий
почти 4 года назад
github логотип
GHSA-3f2v-mfqw-2824

Multiple reflected cross-site scripting (xss) vulnerabilities exist in the config.php functionality of MedDream PACS Premium 7.3.6.870. Specially crafted malicious URLs can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger these vulnerabilities.This vulnerability affects the status parameter.

CVSS3: 6.1
0%
Низкий
19 дней назад
github логотип
GHSA-3f2v-9x94-8rwj

A vulnerability, which was classified as problematic, was found in Axiomatic Bento4. Affected is an unknown function of the component mp4decrypt. The manipulation leads to memory leak. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-212682 is the identifier assigned to this vulnerability.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3f2r-h473-hqjx

MKCMS V6.2 has SQL injection via /ucenter/reg.php name parameter.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3f2r-5fxf-85xw

Cross-site request forgery (CSRF) vulnerability on HP ProCurve 1700-8 (aka J9079A) switches with software before VA.02.09 and 1700-24 (aka J9080A) switches with software before VB.02.09 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3f2r-2r5j-wqrm

Buffer overflow in CWMail.exe in NetWin before 2.8a allows remote authenticated users to execute arbitrary code via a long item parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3f2q-h2mg-2c86

In Poppler 0.54.0, a memory leak vulnerability was found in the function Object::initArray in Object.cc, which allows attackers to cause a denial of service via a crafted file.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу