Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 691

Количество 314 691

github логотип

GHSA-3c6c-vv76-h53v

почти 4 года назад

SimpNews 2.41.03 allows remote attackers to obtain sensitive information via (1) an invalid lang parameter to admin/index.php; or a direct request to (2) admin/dbg_infos.php, (3) admin/heading.php, or (4) evsearch.php; which reveals the path in various error messages.

EPSS: Низкий
github логотип

GHSA-3c6c-gjpg-qq92

почти 4 года назад

xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3c6c-24gr-prmj

почти 4 года назад

uploadimg.php in the Expose RC35 and earlier (com_expose) component for Joomla! sends an error message but does not exit when it detects an attempt to upload a non-JPEG file, which allows remote attackers to upload and execute arbitrary PHP code in the img/ folder.

EPSS: Низкий
github логотип

GHSA-3c69-vjm9-xgc7

больше 3 лет назад

Integer overflow in the GatewayService component in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to execute arbitrary code via a large size value in the packet header, which triggers a heap-based buffer overflow.

EPSS: Низкий
github логотип

GHSA-3c69-m56m-795w

больше 3 лет назад

In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the SoulSeek dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-slsk.c by making loop bounds more explicit.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3c69-j5vj-xf6p

почти 4 года назад

Multiple SQL injection vulnerabilities in the Kose_Yazilari module for PHP-Nuke allow remote attackers to execute arbitrary SQL commands via the artid parameter in a (1) viewarticle or (2) printpage action to modules.php.

EPSS: Низкий
github логотип

GHSA-3c69-6w5j-4xrh

больше 3 лет назад

An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-16913.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3c68-7mfh-fv9v

около 4 лет назад

In Open5GS 2.4.0, a crafted packet from UE can crash SGW-U/UPF.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3c68-5wgm-9f52

больше 3 лет назад

Insufficient validation of untrusted input in navigation in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

EPSS: Низкий
github логотип

GHSA-3c67-gc48-983w

почти 5 лет назад

Path Traversal in Ansible

CVSS3: 5.2
EPSS: Низкий
github логотип

GHSA-3c67-g3rm-28pr

почти 4 года назад

oftpd 0.3.7 allows remote attackers to cause a denial of service via a USER command with a large number of null (\0) characters.

EPSS: Низкий
github логотип

GHSA-3c67-5hwx-f6wx

больше 1 года назад

Gradios's CORS origin validation is not performed when the request has a cookie

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3c67-5778-ch7c

почти 4 года назад

Unspecified vulnerability in the Drush Debian Packaging module for Drupal allows local users to obtain database credentials via unknown vectors.

EPSS: Низкий
github логотип

GHSA-3c65-jw75-c45f

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Alt-N MDaemon Free 12.5.4 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with (1) the Cascading Style Sheets (CSS) expression property in conjunction with a CSS comment within the STYLE attribute of an IMG element, (2) the CSS expression property in conjunction with multiple CSS comments within the STYLE attribute of an arbitrary element, or (3) an innerHTML attribute within an XML document.

EPSS: Низкий
github логотип

GHSA-3c64-vv99-p2qr

2 месяца назад

In the Linux kernel, the following vulnerability has been resolved: NFSD: Define actions for the new time_deleg FATTR4 attributes NFSv4 clients won't send legitimate GETATTR requests for these new attributes because they are intended to be used only with CB_GETATTR and SETATTR. But NFSD has to do something besides crashing if it ever sees a GETATTR request that queries these attributes. RFC 8881 Section 18.7.3 states: > The server MUST return a value for each attribute that the client > requests if the attribute is supported by the server for the > target file system. If the server does not support a particular > attribute on the target file system, then it MUST NOT return the > attribute value and MUST NOT set the attribute bit in the result > bitmap. The server MUST return an error if it supports an > attribute on the target but cannot obtain its value. In that case, > no attribute values will be returned. Further, RFC 9754 Section 5 states: > These new attributes are invali...

EPSS: Низкий
github логотип

GHSA-3c64-pg4p-f5fw

почти 4 года назад

wu-ftpd 2.4 FTP server does not properly drop privileges when an ABOR (abort file transfer) command is executed during a file transfer, which causes a signal to be handled incorrectly and allows local and possibly remote attackers to read arbitrary files.

EPSS: Низкий
github логотип

GHSA-3c63-mvjc-rj3q

около 3 лет назад

A vulnerability was found in mrobit robitailletheknot. It has been classified as problematic. This affects an unknown part of the file app/filters.php of the component CSRF Token Handler. The manipulation of the argument _token leads to incorrect comparison. It is possible to initiate the attack remotely. The name of the patch is 6b2813696ccb88d0576dfb305122ee880eb36197. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217599.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3c62-hfcf-656j

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Classic Meeting Server in IBM Sametime 8.x through 8.5.2.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

EPSS: Низкий
github логотип

GHSA-3c62-92g5-fp7f

больше 3 лет назад

Buffer overflow in the shader compiler in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted GLSL shader.

EPSS: Низкий
github логотип

GHSA-3c62-83fv-2r38

около 3 лет назад

In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3c6c-vv76-h53v

SimpNews 2.41.03 allows remote attackers to obtain sensitive information via (1) an invalid lang parameter to admin/index.php; or a direct request to (2) admin/dbg_infos.php, (3) admin/heading.php, or (4) evsearch.php; which reveals the path in various error messages.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3c6c-gjpg-qq92

xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.

CVSS3: 9.8
9%
Низкий
почти 4 года назад
github логотип
GHSA-3c6c-24gr-prmj

uploadimg.php in the Expose RC35 and earlier (com_expose) component for Joomla! sends an error message but does not exit when it detects an attempt to upload a non-JPEG file, which allows remote attackers to upload and execute arbitrary PHP code in the img/ folder.

4%
Низкий
почти 4 года назад
github логотип
GHSA-3c69-vjm9-xgc7

Integer overflow in the GatewayService component in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to execute arbitrary code via a large size value in the packet header, which triggers a heap-based buffer overflow.

9%
Низкий
больше 3 лет назад
github логотип
GHSA-3c69-m56m-795w

In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the SoulSeek dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-slsk.c by making loop bounds more explicit.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3c69-j5vj-xf6p

Multiple SQL injection vulnerabilities in the Kose_Yazilari module for PHP-Nuke allow remote attackers to execute arbitrary SQL commands via the artid parameter in a (1) viewarticle or (2) printpage action to modules.php.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3c69-6w5j-4xrh

An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-16913.

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3c68-7mfh-fv9v

In Open5GS 2.4.0, a crafted packet from UE can crash SGW-U/UPF.

CVSS3: 7.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-3c68-5wgm-9f52

Insufficient validation of untrusted input in navigation in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c67-gc48-983w

Path Traversal in Ansible

CVSS3: 5.2
0%
Низкий
почти 5 лет назад
github логотип
GHSA-3c67-g3rm-28pr

oftpd 0.3.7 allows remote attackers to cause a denial of service via a USER command with a large number of null (\0) characters.

6%
Низкий
почти 4 года назад
github логотип
GHSA-3c67-5hwx-f6wx

Gradios's CORS origin validation is not performed when the request has a cookie

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3c67-5778-ch7c

Unspecified vulnerability in the Drush Debian Packaging module for Drupal allows local users to obtain database credentials via unknown vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3c65-jw75-c45f

Multiple cross-site scripting (XSS) vulnerabilities in Alt-N MDaemon Free 12.5.4 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with (1) the Cascading Style Sheets (CSS) expression property in conjunction with a CSS comment within the STYLE attribute of an IMG element, (2) the CSS expression property in conjunction with multiple CSS comments within the STYLE attribute of an arbitrary element, or (3) an innerHTML attribute within an XML document.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c64-vv99-p2qr

In the Linux kernel, the following vulnerability has been resolved: NFSD: Define actions for the new time_deleg FATTR4 attributes NFSv4 clients won't send legitimate GETATTR requests for these new attributes because they are intended to be used only with CB_GETATTR and SETATTR. But NFSD has to do something besides crashing if it ever sees a GETATTR request that queries these attributes. RFC 8881 Section 18.7.3 states: > The server MUST return a value for each attribute that the client > requests if the attribute is supported by the server for the > target file system. If the server does not support a particular > attribute on the target file system, then it MUST NOT return the > attribute value and MUST NOT set the attribute bit in the result > bitmap. The server MUST return an error if it supports an > attribute on the target but cannot obtain its value. In that case, > no attribute values will be returned. Further, RFC 9754 Section 5 states: > These new attributes are invali...

0%
Низкий
2 месяца назад
github логотип
GHSA-3c64-pg4p-f5fw

wu-ftpd 2.4 FTP server does not properly drop privileges when an ABOR (abort file transfer) command is executed during a file transfer, which causes a signal to be handled incorrectly and allows local and possibly remote attackers to read arbitrary files.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3c63-mvjc-rj3q

A vulnerability was found in mrobit robitailletheknot. It has been classified as problematic. This affects an unknown part of the file app/filters.php of the component CSRF Token Handler. The manipulation of the argument _token leads to incorrect comparison. It is possible to initiate the attack remotely. The name of the patch is 6b2813696ccb88d0576dfb305122ee880eb36197. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217599.

CVSS3: 9.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-3c62-hfcf-656j

Cross-site scripting (XSS) vulnerability in the Classic Meeting Server in IBM Sametime 8.x through 8.5.2.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c62-92g5-fp7f

Buffer overflow in the shader compiler in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted GLSL shader.

6%
Низкий
больше 3 лет назад
github логотип
GHSA-3c62-83fv-2r38

In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.

CVSS3: 5.5
0%
Низкий
около 3 лет назад

Уязвимостей на страницу