Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 324 758

Количество 324 758

github логотип

GHSA-xr82-vj36-ch3w

почти 4 года назад

A problem was found in Centreon Web through 19.04.3. An authenticated command injection is present in the page include/configuration/configObject/traps-mibs/formMibs.php. This page is called from the Centreon administration interface. This is the mibs management feature that contains a file filing form. At the time of submission of a file, the mnftr parameter is sent to the page and is not filtered properly. This allows one to inject Linux commands directly.

EPSS: Низкий
github логотип

GHSA-xr82-v4c6-wp6r

почти 4 года назад

The kvm_set_msr_common function in arch/x86/kvm/x86.c in the Linux kernel through 3.8.4 does not ensure a required time_page alignment during an MSR_KVM_SYSTEM_TIME operation, which allows guest OS users to cause a denial of service (buffer overflow and host OS memory corruption) or possibly have unspecified other impact via a crafted application.

EPSS: Низкий
github логотип

GHSA-xr82-rp9q-jgqf

почти 4 года назад

Microsoft Office 2007 SP3, Office 2010 SP2, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-xr82-97gj-f3qm

почти 4 года назад

** DISPUTED ** An issue was discovered on Canon LBP6650, LBP3370, LBP3460, and LBP7750C devices. It is possible to bypass the Administrator Mode authentication for /tlogin.cgi via vectors involving frame.cgi?page=DevStatus. NOTE: the vendor reportedly responded that this issue occurs when a customer keeps the default settings without using the countermeasures and best practices shown in the documentation.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xr82-8hm6-h468

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: btrfs: don't abort filesystem when attempting to snapshot deleted subvolume If the source file descriptor to the snapshot ioctl refers to a deleted subvolume, we get the following abort: BTRFS: Transaction aborted (error -2) WARNING: CPU: 0 PID: 833 at fs/btrfs/transaction.c:1875 create_pending_snapshot+0x1040/0x1190 [btrfs] Modules linked in: pata_acpi btrfs ata_piix libata scsi_mod virtio_net blake2b_generic xor net_failover virtio_rng failover scsi_common rng_core raid6_pq libcrc32c CPU: 0 PID: 833 Comm: t_snapshot_dele Not tainted 6.7.0-rc6 #2 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-1.fc39 04/01/2014 RIP: 0010:create_pending_snapshot+0x1040/0x1190 [btrfs] RSP: 0018:ffffa09c01337af8 EFLAGS: 00010282 RAX: 0000000000000000 RBX: ffff9982053e7c78 RCX: 0000000000000027 RDX: ffff99827dc20848 RSI: 0000000000000001 RDI: ffff99827dc20840 RBP: ffffa09c01337c00 R08: 00000000...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xr7x-hc9m-fv57

почти 4 года назад

An issue was discovered in Artifex Ghostscript before 9.26. LockSafetyParams is not checked correctly if another device is used.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xr7x-cpgh-xg5x

12 дней назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eyecix Addon Jobsearch Chat addon-jobsearch-chat allows SQL Injection.This issue affects Addon Jobsearch Chat: from n/a through <= 3.0.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-xr7x-cgg3-q7vw

6 месяцев назад

In gnss driver, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09920036; Issue ID: MSV-3798.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xr7x-6c7p-2fw4

почти 2 года назад

Missing Authorization vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.16.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xr7w-c4xp-gqc3

больше 2 лет назад

A memory leakage vulnerability was reported in the NvmramSmm SMM driver that may allow a local attacker with elevated privileges to write to NVRAM variables.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-xr7w-9r28-r57c

почти 4 года назад

Multiple eval injection vulnerabilities in MyBB 1.2.10 and earlier allow remote attackers to execute arbitrary code via the sortby parameter to (1) forumdisplay.php or (2) a results action in search.php.

EPSS: Средний
github логотип

GHSA-xr7v-qwrm-67xg

почти 4 года назад

In Azure Data Expert Ultimate 2.2.16, the SMTP verification function suffers from a buffer overflow vulnerability, leading to remote code execution. The attack vector is a crafted SMTP daemon that sends a long 220 (aka "Service ready") string.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xr7v-j379-34v9

2 месяца назад

NocoDB has Blind SSRF via Unvalidated HEAD Request in uploadViaURL Functionality

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-xr7v-hj32-mr4r

10 дней назад

Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xr7v-c623-gxm3

почти 4 года назад

Veeam ONE Reporter 9.5.0.3201 allows XSS via the Add/Edit Widget with a crafted Caption field to setDashboardWidget in CommonDataHandlerReadOnly.ashx.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xr7v-8xc4-62vc

почти 4 года назад

ZoneMinder before 1.36.13 allows remote code execution via an invalid language.

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-xr7r-f8xq-vfvv

около 2 лет назад

runc vulnerable to container breakout through process.cwd trickery and leaked fds

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-xr7r-88qv-q7hm

больше 4 лет назад

Out of bounds write in serde_cbor

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xr7r-38qp-crjh

почти 4 года назад

** DISPUTED ** Evolution CMS 2.0.x allows XSS via a description and new category location in a template. NOTE: the vendor states that the behavior is consistent with the "access policy in the administration panel."

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xr7r-23jq-mmmx

больше 4 лет назад

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at ‘sn_filter’ parameter to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xr82-vj36-ch3w

A problem was found in Centreon Web through 19.04.3. An authenticated command injection is present in the page include/configuration/configObject/traps-mibs/formMibs.php. This page is called from the Centreon administration interface. This is the mibs management feature that contains a file filing form. At the time of submission of a file, the mnftr parameter is sent to the page and is not filtered properly. This allows one to inject Linux commands directly.

9%
Низкий
почти 4 года назад
github логотип
GHSA-xr82-v4c6-wp6r

The kvm_set_msr_common function in arch/x86/kvm/x86.c in the Linux kernel through 3.8.4 does not ensure a required time_page alignment during an MSR_KVM_SYSTEM_TIME operation, which allows guest OS users to cause a denial of service (buffer overflow and host OS memory corruption) or possibly have unspecified other impact via a crafted application.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xr82-rp9q-jgqf

Microsoft Office 2007 SP3, Office 2010 SP2, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."

CVSS3: 7.8
36%
Средний
почти 4 года назад
github логотип
GHSA-xr82-97gj-f3qm

** DISPUTED ** An issue was discovered on Canon LBP6650, LBP3370, LBP3460, and LBP7750C devices. It is possible to bypass the Administrator Mode authentication for /tlogin.cgi via vectors involving frame.cgi?page=DevStatus. NOTE: the vendor reportedly responded that this issue occurs when a customer keeps the default settings without using the countermeasures and best practices shown in the documentation.

CVSS3: 9.8
3%
Низкий
почти 4 года назад
github логотип
GHSA-xr82-8hm6-h468

In the Linux kernel, the following vulnerability has been resolved: btrfs: don't abort filesystem when attempting to snapshot deleted subvolume If the source file descriptor to the snapshot ioctl refers to a deleted subvolume, we get the following abort: BTRFS: Transaction aborted (error -2) WARNING: CPU: 0 PID: 833 at fs/btrfs/transaction.c:1875 create_pending_snapshot+0x1040/0x1190 [btrfs] Modules linked in: pata_acpi btrfs ata_piix libata scsi_mod virtio_net blake2b_generic xor net_failover virtio_rng failover scsi_common rng_core raid6_pq libcrc32c CPU: 0 PID: 833 Comm: t_snapshot_dele Not tainted 6.7.0-rc6 #2 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-1.fc39 04/01/2014 RIP: 0010:create_pending_snapshot+0x1040/0x1190 [btrfs] RSP: 0018:ffffa09c01337af8 EFLAGS: 00010282 RAX: 0000000000000000 RBX: ffff9982053e7c78 RCX: 0000000000000027 RDX: ffff99827dc20848 RSI: 0000000000000001 RDI: ffff99827dc20840 RBP: ffffa09c01337c00 R08: 00000000...

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-xr7x-hc9m-fv57

An issue was discovered in Artifex Ghostscript before 9.26. LockSafetyParams is not checked correctly if another device is used.

CVSS3: 9.8
10%
Средний
почти 4 года назад
github логотип
GHSA-xr7x-cpgh-xg5x

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eyecix Addon Jobsearch Chat addon-jobsearch-chat allows SQL Injection.This issue affects Addon Jobsearch Chat: from n/a through <= 3.0.

CVSS3: 9.3
0%
Низкий
12 дней назад
github логотип
GHSA-xr7x-cgg3-q7vw

In gnss driver, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09920036; Issue ID: MSV-3798.

CVSS3: 5.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-xr7x-6c7p-2fw4

Missing Authorization vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.16.

CVSS3: 5.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-xr7w-c4xp-gqc3

A memory leakage vulnerability was reported in the NvmramSmm SMM driver that may allow a local attacker with elevated privileges to write to NVRAM variables.

CVSS3: 6.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xr7w-9r28-r57c

Multiple eval injection vulnerabilities in MyBB 1.2.10 and earlier allow remote attackers to execute arbitrary code via the sortby parameter to (1) forumdisplay.php or (2) a results action in search.php.

63%
Средний
почти 4 года назад
github логотип
GHSA-xr7v-qwrm-67xg

In Azure Data Expert Ultimate 2.2.16, the SMTP verification function suffers from a buffer overflow vulnerability, leading to remote code execution. The attack vector is a crafted SMTP daemon that sends a long 220 (aka "Service ready") string.

CVSS3: 9.8
22%
Средний
почти 4 года назад
github логотип
GHSA-xr7v-j379-34v9

NocoDB has Blind SSRF via Unvalidated HEAD Request in uploadViaURL Functionality

CVSS3: 4.9
0%
Низкий
2 месяца назад
github логотип
GHSA-xr7v-hj32-mr4r

Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.

CVSS3: 7.5
0%
Низкий
10 дней назад
github логотип
GHSA-xr7v-c623-gxm3

Veeam ONE Reporter 9.5.0.3201 allows XSS via the Add/Edit Widget with a crafted Caption field to setDashboardWidget in CommonDataHandlerReadOnly.ashx.

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-xr7v-8xc4-62vc

ZoneMinder before 1.36.13 allows remote code execution via an invalid language.

CVSS3: 9.8
77%
Высокий
почти 4 года назад
github логотип
GHSA-xr7r-f8xq-vfvv

runc vulnerable to container breakout through process.cwd trickery and leaked fds

CVSS3: 8.6
7%
Низкий
около 2 лет назад
github логотип
GHSA-xr7r-88qv-q7hm

Out of bounds write in serde_cbor

CVSS3: 7.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xr7r-38qp-crjh

** DISPUTED ** Evolution CMS 2.0.x allows XSS via a description and new category location in a template. NOTE: the vendor states that the behavior is consistent with the "access policy in the administration panel."

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-xr7r-23jq-mmmx

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at ‘sn_filter’ parameter to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу