Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3cfr-mv5q-x2vc

больше 3 лет назад

The process_add_entry function in archive_read_support_format_mtree.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mtree file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3cfq-pxwf-wqwq

больше 3 лет назад

Microsoft Internet Explorer 11 on Windows 10, 1511, and 1606 and Windows Server 2016 does not enforce cross-domain policies, allowing attackers to access information from one domain and inject it into another via a crafted application, aka, "Internet Explorer Elevation of Privilege Vulnerability."

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-3cfq-9ww9-q4xm

больше 3 лет назад

Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-3cfp-9cr8-v26m

около 3 лет назад

NOSH 4a5cfdb allows stored XSS via the create user page. For example, a first name (of a physician, assistant, or billing user) can have a JavaScript payload that is executed upon visiting the /users/2/1 page. This may allow attackers to steal Protected Health Information because the product is for health charting.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3cfp-926c-3w2x

12 месяцев назад

Dell Client Platform BIOS contains a Weak Authentication vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-3cfm-vj7w-48fq

больше 2 лет назад

Vulnerability in Easy Address Book Web Server 1.6 version, affecting the parameters (firstname, homephone, lastname, middlename, workaddress, workcity, workcountry, workphone, workstate and workzip) of the /addrbook.ghp file, allowing an attacker to inject a JavaScript payload specially designed to run when the application is loaded

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3cfm-q6rm-f5w2

почти 4 года назад

Multiple SQL injection vulnerabilities in PHD Help Desk before 1.31 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3cfm-94xc-h7hp

больше 3 лет назад

A flaw was found in libtpms in versions before 0.8.2. The commonly used integration of libtpms with OpenSSL contained a vulnerability related to the returned IV (initialization vector) when certain symmetric ciphers were used. Instead of returning the last IV it returned the initial IV to the caller, thus weakening the subsequent encryption and decryption steps. The highest threat from this vulnerability is to data confidentiality.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3cfm-49vw-5qrv

около 2 лет назад

A Null pointer dereference problem was found in ida_free in lib/idr.c in the Linux Kernel. This issue may allow an attacker using this library to cause a denial of service problem due to a missing check at a function return.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3cfj-vhx9-vcmp

больше 2 лет назад

Landscape allowed URLs which caused open redirection.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3cfj-r393-3gq3

почти 4 года назад

apt 0.7.20 does not check when the date command returns an "invalid date" error, which can prevent apt from loading security updates in time zones for which DST occurs at midnight.

EPSS: Низкий
github логотип

GHSA-3cfj-8mxg-4897

больше 3 лет назад

Improper initialization in some Intel(R) Thunderbolt(TM) DCH drivers for Windows* before version 72 may allow an authenticated user to potentially enable information disclosure via local access.

EPSS: Низкий
github логотип

GHSA-3cfh-wr8w-8mhf

9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: backlight: led_bl: Hold led_access lock when calling led_sysfs_disable() Lockdep detects the following issue on led-backlight removal: [ 142.315935] ------------[ cut here ]------------ [ 142.315954] WARNING: CPU: 2 PID: 292 at drivers/leds/led-core.c:455 led_sysfs_enable+0x54/0x80 ... [ 142.500725] Call trace: [ 142.503176] led_sysfs_enable+0x54/0x80 (P) [ 142.507370] led_bl_remove+0x80/0xa8 [led_bl] [ 142.511742] platform_remove+0x30/0x58 [ 142.515501] device_remove+0x54/0x90 ... Indeed, led_sysfs_enable() has to be called with the led_access lock held. Hold the lock when calling led_sysfs_disable().

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3cfh-hf3f-2p3x

9 месяцев назад

A junction point vulnerability within AMD uProf can allow a local low-privileged attacker to create junction points, potentially resulting in arbitrary file deletion or disclosure.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-3cfg-w257-cgf8

12 месяцев назад

Magento Information Exposure vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3cfg-rxh6-h2rh

больше 3 лет назад

LavaLite Stored Cross-site Scripting vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3cfg-p79p-hp56

около 1 года назад

A SQL injection vulnerability was found in phpgurukul Online Nurse Hiring System v1.0 in /admin/password-recovery.php via the mobileno parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3cfg-877r-978v

почти 4 года назад

Multiple SQL injection vulnerabilities in Simple PHP Forum before 0.4 allow remote attackers to execute arbitrary SQL commands via the username parameter to (1) logon_user.php and (2) update_profile.php.

EPSS: Низкий
github логотип

GHSA-3cff-w6rq-c82x

больше 3 лет назад

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.2.20. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-3cff-rx64-jq4x

больше 3 лет назад

Marvell SSD Controller (88SS1074, 88SS1079, 88SS1080, 88SS1093, 88SS1092, 88SS1095, 88SS9174, 88SS9175, 88SS9187, 88SS9188, 88SS9189, 88SS9190, 88SS1085, 88SS1087, 88SS1090, 88SS1100, 88SS1084, 88SS1088, & 88SS1098) devices allow reprogramming flash memory to bypass the secure boot protection mechanism.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3cfr-mv5q-x2vc

The process_add_entry function in archive_read_support_format_mtree.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mtree file.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3cfq-pxwf-wqwq

Microsoft Internet Explorer 11 on Windows 10, 1511, and 1606 and Windows Server 2016 does not enforce cross-domain policies, allowing attackers to access information from one domain and inject it into another via a crafted application, aka, "Internet Explorer Elevation of Privilege Vulnerability."

CVSS3: 4.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3cfq-9ww9-q4xm

Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

8%
Низкий
больше 3 лет назад
github логотип
GHSA-3cfp-9cr8-v26m

NOSH 4a5cfdb allows stored XSS via the create user page. For example, a first name (of a physician, assistant, or billing user) can have a JavaScript payload that is executed upon visiting the /users/2/1 page. This may allow attackers to steal Protected Health Information because the product is for health charting.

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-3cfp-926c-3w2x

Dell Client Platform BIOS contains a Weak Authentication vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

CVSS3: 8.2
0%
Низкий
12 месяцев назад
github логотип
GHSA-3cfm-vj7w-48fq

Vulnerability in Easy Address Book Web Server 1.6 version, affecting the parameters (firstname, homephone, lastname, middlename, workaddress, workcity, workcountry, workphone, workstate and workzip) of the /addrbook.ghp file, allowing an attacker to inject a JavaScript payload specially designed to run when the application is loaded

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3cfm-q6rm-f5w2

Multiple SQL injection vulnerabilities in PHD Help Desk before 1.31 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3cfm-94xc-h7hp

A flaw was found in libtpms in versions before 0.8.2. The commonly used integration of libtpms with OpenSSL contained a vulnerability related to the returned IV (initialization vector) when certain symmetric ciphers were used. Instead of returning the last IV it returned the initial IV to the caller, thus weakening the subsequent encryption and decryption steps. The highest threat from this vulnerability is to data confidentiality.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3cfm-49vw-5qrv

A Null pointer dereference problem was found in ida_free in lib/idr.c in the Linux Kernel. This issue may allow an attacker using this library to cause a denial of service problem due to a missing check at a function return.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-3cfj-vhx9-vcmp

Landscape allowed URLs which caused open redirection.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3cfj-r393-3gq3

apt 0.7.20 does not check when the date command returns an "invalid date" error, which can prevent apt from loading security updates in time zones for which DST occurs at midnight.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3cfj-8mxg-4897

Improper initialization in some Intel(R) Thunderbolt(TM) DCH drivers for Windows* before version 72 may allow an authenticated user to potentially enable information disclosure via local access.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3cfh-wr8w-8mhf

In the Linux kernel, the following vulnerability has been resolved: backlight: led_bl: Hold led_access lock when calling led_sysfs_disable() Lockdep detects the following issue on led-backlight removal: [ 142.315935] ------------[ cut here ]------------ [ 142.315954] WARNING: CPU: 2 PID: 292 at drivers/leds/led-core.c:455 led_sysfs_enable+0x54/0x80 ... [ 142.500725] Call trace: [ 142.503176] led_sysfs_enable+0x54/0x80 (P) [ 142.507370] led_bl_remove+0x80/0xa8 [led_bl] [ 142.511742] platform_remove+0x30/0x58 [ 142.515501] device_remove+0x54/0x90 ... Indeed, led_sysfs_enable() has to be called with the led_access lock held. Hold the lock when calling led_sysfs_disable().

CVSS3: 5.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-3cfh-hf3f-2p3x

A junction point vulnerability within AMD uProf can allow a local low-privileged attacker to create junction points, potentially resulting in arbitrary file deletion or disclosure.

CVSS3: 6.6
0%
Низкий
9 месяцев назад
github логотип
GHSA-3cfg-w257-cgf8

Magento Information Exposure vulnerability

CVSS3: 6.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-3cfg-rxh6-h2rh

LavaLite Stored Cross-site Scripting vulnerability

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3cfg-p79p-hp56

A SQL injection vulnerability was found in phpgurukul Online Nurse Hiring System v1.0 in /admin/password-recovery.php via the mobileno parameter.

CVSS3: 9.8
0%
Низкий
около 1 года назад
github логотип
GHSA-3cfg-877r-978v

Multiple SQL injection vulnerabilities in Simple PHP Forum before 0.4 allow remote attackers to execute arbitrary SQL commands via the username parameter to (1) logon_user.php and (2) update_profile.php.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3cff-w6rq-c82x

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.2.20. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).

CVSS3: 8.6
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3cff-rx64-jq4x

Marvell SSD Controller (88SS1074, 88SS1079, 88SS1080, 88SS1093, 88SS1092, 88SS1095, 88SS9174, 88SS9175, 88SS9187, 88SS9188, 88SS9189, 88SS9190, 88SS1085, 88SS1087, 88SS1090, 88SS1100, 88SS1084, 88SS1088, & 88SS1098) devices allow reprogramming flash memory to bypass the secure boot protection mechanism.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу