Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-38fh-5rpq-pxq2

больше 3 лет назад

Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

EPSS: Низкий
github логотип

GHSA-38fg-rh2c-fh5c

больше 3 лет назад

Unspecified vulnerability in libpng before 1.6.20, as used in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01, allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 23265085.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-38fc-wpqx-33j7

больше 4 лет назад

Uncontrolled Resource Consumption in trim-off-newlines

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-38fc-w9g8-x254

больше 3 лет назад

An issue was discovered in GPAC version 0.8.0. There is a NULL pointer dereference in the function gf_isom_get_media_data_size() in isomedia/isom_read.c.

EPSS: Низкий
github логотип

GHSA-38fc-cmwf-cfvc

почти 4 года назад

Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability.

EPSS: Средний
github логотип

GHSA-38fc-9xqv-7f7q

почти 7 лет назад

SQLAlchemy is vulnerable to SQL Injection via group_by parameter

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-38f9-m297-6q9g

больше 5 лет назад

DoS via malicious record IDs in WatermelonDB

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-38f9-jc9v-rgw6

почти 2 года назад

An RBAC authorization risk in Carina v0.13.0 and earlier allows local attackers to execute arbitrary code through designed commands to obtain the secrets of the entire cluster and further take over the cluster.

CVSS3: 6.9
EPSS: Низкий
github логотип

GHSA-38f9-86mj-c2gg

больше 3 лет назад

An issue was discovered in Open Design Alliance Drawings SDK before 2021.11. A NULL pointer dereference exists when rendering malformed .DXF and .DWG files. This can allow attackers to cause a crash, potentially enabling a denial of service attack (Crash, Exit, or Restart). This is issue 1 of 3.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-38f9-4vhq-9cr8

больше 3 лет назад

Zen Cart vulnerable to authenticated remote code execution

CVSS3: 7.2
EPSS: Средний
github логотип

GHSA-38f8-fpgx-rq7p

3 месяца назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Dør dor allows PHP Local File Inclusion.This issue affects Dør: from n/a through <= 2.4.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-38f8-6mx5-p5qh

больше 3 лет назад

Use after free in Sharing in Google Chrome prior to 101.0.4951.64 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-38f7-vv5r-859m

больше 2 лет назад

On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlayfs.* xattrs", an unprivileged user may set privileged extended attributes on the mounted files, leading them to be set on the upper files without the appropriate security checks.

CVSS3: 7.8
EPSS: Критический
github логотип

GHSA-38f7-2qg7-wj3f

почти 4 года назад

Multiple SQL injection vulnerabilities in AbleSpace 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to events_view.php and the (2) id parameter to events_clndr_view.php.

EPSS: Низкий
github логотип

GHSA-38f6-jcm3-35jc

больше 3 лет назад

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.75, D6000 before 1.0.0.75, D6100 before 1.0.0.63, D7800 before 1.0.1.44, R7500v2 before 1.0.3.38, R7800 before 1.0.2.52, R8900 before 1.0.4.2, R9000 before 1.0.4.2, RBK20 before 2.3.0.28, RBR20 before 2.3.0.28, RBS20 before 2.3.0.28, RBK50 before 2.3.0.32, RBR50 before 2.3.0.32, RBS50 before 2.3.0.32, RBS40 before 2.3.0.28, WNDR3700v4 before 1.0.2.102, WNDR4300v1 before 1.0.2.104, WNDR4300v2 before 1.0.0.58, WNDR4500v3 before 1.0.0.58, WNR2000v5 before 1.0.0.68, and XR500 before 2.3.2.32.

EPSS: Низкий
github логотип

GHSA-38f6-89gx-6f42

почти 3 года назад

Zoho ManageEngine Applications Manager through 16390 allows DOM XSS.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-38f5-rx4x-f6j9

почти 2 года назад

A Use After Free vulnerability in command processing of Juniper Networks Junos OS on MX Series allows a local, authenticated attacker to cause the broadband edge service manager daemon (bbe-smgd) to crash upon execution of specific CLI commands, creating a Denial of Service (DoS) condition.  The process crashes and restarts automatically. When specific CLI commands are executed, the bbe-smgd daemon attempts to write into an area of memory (mgd socket) that was already closed, causing the process to crash.  This process manages and controls the configuration of broadband subscriber sessions and services.  While the process is unavailable, additional subscribers will not be able to connect to the device, causing a temporary Denial of Service condition. This issue only occurs if Graceful Routing Engine Switchover (GRES) and Subscriber Management are enabled. This issue affects Junos OS: * All versions before 20.4R3-S5, * from 21.1 before 21.1R3-S4, * from 21.2 before...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-38f5-ghc2-fcmv

больше 7 лет назад

Code Injection in cryo

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-38f5-5m8x-c6h5

больше 3 лет назад

Server-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and earlier unsupported versions relies on Java SAX Parser to implement its XML-RPC interface and by default that parser supports external entities in XML DOCTYPE, which opens Roller up to SSRF / File Enumeration vulnerability. Note that this vulnerability exists even if Roller XML-RPC interface is disable via the Roller web admin UI. Mitigation: There are a couple of ways you can fix this vulnerability: 1) Upgrade to the latest version of Roller, which is now 5.2.2 2) Or, edit the Roller web.xml file and comment out the XML-RPC Servlet mapping as shown below: <!-- <servlet-mapping> <servlet-name>XmlRpcServlet</servlet-name> <url-pattern>/roller-services/xmlrpc</url-pattern> </servlet-mapping> -->

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-38f4-wx3j-w2g9

почти 2 года назад

Missing Authorization vulnerability in Rometheme RomethemeKit For Elementor.This issue affects RomethemeKit For Elementor: from n/a through 1.4.1.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-38fh-5rpq-pxq2

Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

0%
Низкий
больше 3 лет назад
github логотип
GHSA-38fg-rh2c-fh5c

Unspecified vulnerability in libpng before 1.6.20, as used in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01, allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 23265085.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-38fc-wpqx-33j7

Uncontrolled Resource Consumption in trim-off-newlines

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
github логотип
GHSA-38fc-w9g8-x254

An issue was discovered in GPAC version 0.8.0. There is a NULL pointer dereference in the function gf_isom_get_media_data_size() in isomedia/isom_read.c.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-38fc-cmwf-cfvc

Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability.

31%
Средний
почти 4 года назад
github логотип
GHSA-38fc-9xqv-7f7q

SQLAlchemy is vulnerable to SQL Injection via group_by parameter

CVSS3: 7.8
1%
Низкий
почти 7 лет назад
github логотип
GHSA-38f9-m297-6q9g

DoS via malicious record IDs in WatermelonDB

CVSS3: 5.9
0%
Низкий
больше 5 лет назад
github логотип
GHSA-38f9-jc9v-rgw6

An RBAC authorization risk in Carina v0.13.0 and earlier allows local attackers to execute arbitrary code through designed commands to obtain the secrets of the entire cluster and further take over the cluster.

CVSS3: 6.9
0%
Низкий
почти 2 года назад
github логотип
GHSA-38f9-86mj-c2gg

An issue was discovered in Open Design Alliance Drawings SDK before 2021.11. A NULL pointer dereference exists when rendering malformed .DXF and .DWG files. This can allow attackers to cause a crash, potentially enabling a denial of service attack (Crash, Exit, or Restart). This is issue 1 of 3.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-38f9-4vhq-9cr8

Zen Cart vulnerable to authenticated remote code execution

CVSS3: 7.2
38%
Средний
больше 3 лет назад
github логотип
GHSA-38f8-fpgx-rq7p

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Dør dor allows PHP Local File Inclusion.This issue affects Dør: from n/a through <= 2.4.

CVSS3: 9.8
0%
Низкий
3 месяца назад
github логотип
GHSA-38f8-6mx5-p5qh

Use after free in Sharing in Google Chrome prior to 101.0.4951.64 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-38f7-vv5r-859m

On Ubuntu kernels carrying both c914c0e27eb0 and "UBUNTU: SAUCE: overlayfs: Skip permission checking for trusted.overlayfs.* xattrs", an unprivileged user may set privileged extended attributes on the mounted files, leading them to be set on the upper files without the appropriate security checks.

CVSS3: 7.8
92%
Критический
больше 2 лет назад
github логотип
GHSA-38f7-2qg7-wj3f

Multiple SQL injection vulnerabilities in AbleSpace 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to events_view.php and the (2) id parameter to events_clndr_view.php.

0%
Низкий
почти 4 года назад
github логотип
GHSA-38f6-jcm3-35jc

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.75, D6000 before 1.0.0.75, D6100 before 1.0.0.63, D7800 before 1.0.1.44, R7500v2 before 1.0.3.38, R7800 before 1.0.2.52, R8900 before 1.0.4.2, R9000 before 1.0.4.2, RBK20 before 2.3.0.28, RBR20 before 2.3.0.28, RBS20 before 2.3.0.28, RBK50 before 2.3.0.32, RBR50 before 2.3.0.32, RBS50 before 2.3.0.32, RBS40 before 2.3.0.28, WNDR3700v4 before 1.0.2.102, WNDR4300v1 before 1.0.2.104, WNDR4300v2 before 1.0.0.58, WNDR4500v3 before 1.0.0.58, WNR2000v5 before 1.0.0.68, and XR500 before 2.3.2.32.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-38f6-89gx-6f42

Zoho ManageEngine Applications Manager through 16390 allows DOM XSS.

CVSS3: 6.1
4%
Низкий
почти 3 года назад
github логотип
GHSA-38f5-rx4x-f6j9

A Use After Free vulnerability in command processing of Juniper Networks Junos OS on MX Series allows a local, authenticated attacker to cause the broadband edge service manager daemon (bbe-smgd) to crash upon execution of specific CLI commands, creating a Denial of Service (DoS) condition.  The process crashes and restarts automatically. When specific CLI commands are executed, the bbe-smgd daemon attempts to write into an area of memory (mgd socket) that was already closed, causing the process to crash.  This process manages and controls the configuration of broadband subscriber sessions and services.  While the process is unavailable, additional subscribers will not be able to connect to the device, causing a temporary Denial of Service condition. This issue only occurs if Graceful Routing Engine Switchover (GRES) and Subscriber Management are enabled. This issue affects Junos OS: * All versions before 20.4R3-S5, * from 21.1 before 21.1R3-S4, * from 21.2 before...

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-38f5-ghc2-fcmv

Code Injection in cryo

CVSS3: 9.8
1%
Низкий
больше 7 лет назад
github логотип
GHSA-38f5-5m8x-c6h5

Server-side Request Forgery (SSRF) and File Enumeration vulnerability in Apache Roller 5.2.1, 5.2.0 and earlier unsupported versions relies on Java SAX Parser to implement its XML-RPC interface and by default that parser supports external entities in XML DOCTYPE, which opens Roller up to SSRF / File Enumeration vulnerability. Note that this vulnerability exists even if Roller XML-RPC interface is disable via the Roller web admin UI. Mitigation: There are a couple of ways you can fix this vulnerability: 1) Upgrade to the latest version of Roller, which is now 5.2.2 2) Or, edit the Roller web.xml file and comment out the XML-RPC Servlet mapping as shown below: <!-- <servlet-mapping> <servlet-name>XmlRpcServlet</servlet-name> <url-pattern>/roller-services/xmlrpc</url-pattern> </servlet-mapping> -->

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-38f4-wx3j-w2g9

Missing Authorization vulnerability in Rometheme RomethemeKit For Elementor.This issue affects RomethemeKit For Elementor: from n/a through 1.4.1.

CVSS3: 6.5
0%
Низкий
почти 2 года назад

Уязвимостей на страницу