Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 212

Количество 314 212

github логотип

GHSA-3ccx-q8q7-xf6x

почти 4 года назад

A wrong type is used for a return value from strlen in WebKit in Google Chrome before Blink M12 on 64-bit platforms.

EPSS: Низкий
github логотип

GHSA-3ccx-f6pf-p86m

больше 3 лет назад

Unspecified vulnerability in the Oracle Communications EAGLE Application Processor component in Oracle Communications Applications 16.0 allows remote authenticated users to affect confidentiality and integrity via vectors related to APPL.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-3ccx-8rq3-28hx

около 4 лет назад

Cross-site Scripting vulnerability in Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior and ICONICS MobileHMI versions 10.96.2 and prior allows a remote unauthenticated attacker to gain authentication information of an MC Works64 or MobileHMI and perform any operation using the acquired authentication information, by injecting a malicious script in the URL of a monitoring screen delivered from the MC Works64 server or MobileHMI server to an application for mobile devices and leading a legitimate user to access this URL.

EPSS: Низкий
github логотип

GHSA-3ccx-8m26-xh3c

больше 3 лет назад

Stack-based buffer overflow in Activision Infinity Ward Call of Duty Modern Warfare 2 before 2018-04-26 allows remote attackers to execute arbitrary code via crafted packets.

CVSS3: 10
EPSS: Средний
github логотип

GHSA-3ccx-7588-r6c6

больше 3 лет назад

Magento 2 Community Edition XSS Vulnerability

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3ccx-358p-c5mm

больше 3 лет назад

A vulnerability was found in ImageMagick-7.0.11-5, where executing a crafted file with the convert command, ASAN detects memory leaks.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-3ccx-2hm9-3h7m

8 месяцев назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

EPSS: Низкий
github логотип

GHSA-3ccw-p5pw-r7xc

больше 3 лет назад

Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/classes/Master.php?f=delete_inquiry.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3ccw-85j3-j56p

около 2 месяцев назад

Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information over a network.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3ccw-6p8h-92ch

почти 2 года назад

JFrog Artifactory later than version 7.17.4 but prior to version 7.77.0 is vulnerable to an issue whereby a sequence of improperly handled exceptions in repository configuration initialization steps may lead to exposure of sensitive data.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-3ccv-5g25-fx4v

больше 2 лет назад

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Sudipto Pratap Mahato Simple Light Weight Social Share plugin <= 2.0 versions.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3ccv-3j4f-926q

больше 3 лет назад

The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information by leveraging timing differences when accessing a pre-computed table during modular exponentiation, related to a "Last-Level Cache Side-Channel Attack."

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3ccv-38v3-xjvw

почти 4 года назад

libsafe 2.0-11 and earlier allows attackers to bypass protection against format string vulnerabilities via format strings that use the "'" and "I" characters, which are implemented in libc but not libsafe.

EPSS: Низкий
github логотип

GHSA-3ccq-phh7-c9v8

почти 4 года назад

Unspecified vulnerability in phpMyFAQ 1.6.9 and earlier, when register_globals is enabled, allows remote attackers to "gain the privilege for uploading files on the server."

EPSS: Низкий
github логотип

GHSA-3ccq-gccx-pm7j

больше 3 лет назад

Jenkins SonarQube Scanner Plugin stored server authentication token in plain text

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3ccq-6jj2-4rxc

больше 3 лет назад

Tenable.sc and Tenable.sc Core versions 5.13.0 through 5.17.0 were found to contain a vulnerability that could allow an authenticated, unprivileged user to perform Remote Code Execution (RCE) on the Tenable.sc server via Hypertext Preprocessor unserialization.

EPSS: Низкий
github логотип

GHSA-3ccq-5vw3-2p6x

больше 4 лет назад

XStream is vulnerable to an Arbitrary Code Execution attack

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-3ccp-5v4p-6xpq

около 2 месяцев назад

A vulnerability has been identified in Simcenter Femap (All versions < V2512). The affected applications contains an uninitialized memory vulnerability while parsing specially crafted SLDPRT files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-27146)

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3ccm-2cr5-453p

6 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix wrong next length validation of ea buffer in smb2_set_ea() There are multiple smb2_ea_info buffers in FILE_FULL_EA_INFORMATION request from client. ksmbd find next smb2_ea_info using ->NextEntryOffset of current smb2_ea_info. ksmbd need to validate buffer length Before accessing the next ea. ksmbd should check buffer length using buf_len, not next variable. next is the start offset of current ea that got from previous ea.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3ccj-h5mc-8965

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in OpenMRS 2.1 Standalone Edition allow remote attackers to inject arbitrary web script or HTML via the (1) givenName, (2) familyName, (3) address1, or (4) address2 parameter to registrationapp/registerPatient.page; the (5) comment parameter to allergyui/allergy.page; the (6) w10 parameter to htmlformentryui/htmlform/enterHtmlForm/submit.action; the (7) HTTP Referer Header to login.htm; the (8) returnUrl parameter to htmlformentryui/htmlform/enterHtmlFormWithStandardUi.page or (9) coreapps/mergeVisits.page; or the (10) visitId parameter to htmlformentryui/htmlform/enterHtmlFormWithSimpleUi.page.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3ccx-q8q7-xf6x

A wrong type is used for a return value from strlen in WebKit in Google Chrome before Blink M12 on 64-bit platforms.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3ccx-f6pf-p86m

Unspecified vulnerability in the Oracle Communications EAGLE Application Processor component in Oracle Communications Applications 16.0 allows remote authenticated users to affect confidentiality and integrity via vectors related to APPL.

CVSS3: 6.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3ccx-8rq3-28hx

Cross-site Scripting vulnerability in Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior and ICONICS MobileHMI versions 10.96.2 and prior allows a remote unauthenticated attacker to gain authentication information of an MC Works64 or MobileHMI and perform any operation using the acquired authentication information, by injecting a malicious script in the URL of a monitoring screen delivered from the MC Works64 server or MobileHMI server to an application for mobile devices and leading a legitimate user to access this URL.

0%
Низкий
около 4 лет назад
github логотип
GHSA-3ccx-8m26-xh3c

Stack-based buffer overflow in Activision Infinity Ward Call of Duty Modern Warfare 2 before 2018-04-26 allows remote attackers to execute arbitrary code via crafted packets.

CVSS3: 10
63%
Средний
больше 3 лет назад
github логотип
GHSA-3ccx-7588-r6c6

Magento 2 Community Edition XSS Vulnerability

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3ccx-358p-c5mm

A vulnerability was found in ImageMagick-7.0.11-5, where executing a crafted file with the convert command, ASAN detects memory leaks.

CVSS3: 3.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3ccx-2hm9-3h7m

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

8 месяцев назад
github логотип
GHSA-3ccw-p5pw-r7xc

Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/classes/Master.php?f=delete_inquiry.

CVSS3: 7.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3ccw-85j3-j56p

Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information over a network.

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3ccw-6p8h-92ch

JFrog Artifactory later than version 7.17.4 but prior to version 7.77.0 is vulnerable to an issue whereby a sequence of improperly handled exceptions in repository configuration initialization steps may lead to exposure of sensitive data.

CVSS3: 6.6
0%
Низкий
почти 2 года назад
github логотип
GHSA-3ccv-5g25-fx4v

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Sudipto Pratap Mahato Simple Light Weight Social Share plugin <= 2.0 versions.

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3ccv-3j4f-926q

The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information by leveraging timing differences when accessing a pre-computed table during modular exponentiation, related to a "Last-Level Cache Side-Channel Attack."

CVSS3: 5.9
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3ccv-38v3-xjvw

libsafe 2.0-11 and earlier allows attackers to bypass protection against format string vulnerabilities via format strings that use the "'" and "I" characters, which are implemented in libc but not libsafe.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3ccq-phh7-c9v8

Unspecified vulnerability in phpMyFAQ 1.6.9 and earlier, when register_globals is enabled, allows remote attackers to "gain the privilege for uploading files on the server."

1%
Низкий
почти 4 года назад
github логотип
GHSA-3ccq-gccx-pm7j

Jenkins SonarQube Scanner Plugin stored server authentication token in plain text

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3ccq-6jj2-4rxc

Tenable.sc and Tenable.sc Core versions 5.13.0 through 5.17.0 were found to contain a vulnerability that could allow an authenticated, unprivileged user to perform Remote Code Execution (RCE) on the Tenable.sc server via Hypertext Preprocessor unserialization.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-3ccq-5vw3-2p6x

XStream is vulnerable to an Arbitrary Code Execution attack

CVSS3: 8.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3ccp-5v4p-6xpq

A vulnerability has been identified in Simcenter Femap (All versions < V2512). The affected applications contains an uninitialized memory vulnerability while parsing specially crafted SLDPRT files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-27146)

CVSS3: 7.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3ccm-2cr5-453p

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix wrong next length validation of ea buffer in smb2_set_ea() There are multiple smb2_ea_info buffers in FILE_FULL_EA_INFORMATION request from client. ksmbd find next smb2_ea_info using ->NextEntryOffset of current smb2_ea_info. ksmbd need to validate buffer length Before accessing the next ea. ksmbd should check buffer length using buf_len, not next variable. next is the start offset of current ea that got from previous ea.

CVSS3: 5.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-3ccj-h5mc-8965

Multiple cross-site scripting (XSS) vulnerabilities in OpenMRS 2.1 Standalone Edition allow remote attackers to inject arbitrary web script or HTML via the (1) givenName, (2) familyName, (3) address1, or (4) address2 parameter to registrationapp/registerPatient.page; the (5) comment parameter to allergyui/allergy.page; the (6) w10 parameter to htmlformentryui/htmlform/enterHtmlForm/submit.action; the (7) HTTP Referer Header to login.htm; the (8) returnUrl parameter to htmlformentryui/htmlform/enterHtmlFormWithStandardUi.page or (9) coreapps/mergeVisits.page; or the (10) visitId parameter to htmlformentryui/htmlform/enterHtmlFormWithSimpleUi.page.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу