Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 691

Количество 314 691

github логотип

GHSA-3c3p-xh4f-pfh7

5 месяцев назад

json-schema-editor-visual vulnerable to prototype pollution

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3c3m-qp4j-mgv8

больше 3 лет назад

An issue was discovered in sela through 20200412. A NULL pointer dereference exists in the function lpc::SampleGenerator::process() located in sample_generator.cpp. It allows an attacker to cause Denial of Service.

EPSS: Низкий
github логотип

GHSA-3c3m-ffrh-rq6p

больше 3 лет назад

An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php searchColumn parameter.

EPSS: Критический
github логотип

GHSA-3c3h-v674-rhqr

больше 3 лет назад

md4c 0.2.6 has a NULL pointer dereference in the function md_process_line in md4c.c, related to ctx->current_block.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3c3g-q64x-8mfv

больше 1 года назад

The Google CSE WordPress plugin through 1.0.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3c3f-mfjj-vmx7

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in mail compose in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7.8.2-rev31, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev28 allows remote attackers to inject arbitrary web script or HTML via the data-target attribute in an HTML page with data-toggle gadgets.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3c3f-93qj-h99f

почти 4 года назад

Cross-site scripting (XSS) vulnerability in clanek.php in OwnRS Beta 3 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

EPSS: Низкий
github логотип

GHSA-3c3f-2h7p-qwc8

больше 3 лет назад

When a user opens manipulated Scalable Vector Graphics (.SVG) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to the user until restart of the application.

EPSS: Низкий
github логотип

GHSA-3c3c-wv2g-35jm

почти 4 года назад

Million Dollar Text Links 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the userid cookie to 1.

EPSS: Низкий
github логотип

GHSA-3c3c-2xp4-j4qp

больше 3 лет назад

The wp-slimstat plugin before 4.8.1 for WordPress has XSS.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3c39-x2h8-rmf7

больше 3 лет назад

Absolute path traversal vulnerability in the extract_jar function in jartool.c in FastJar 0.98 allows remote attackers to create or overwrite arbitrary files via a full pathname for a file within a .jar archive, a related issue to CVE-2010-0831. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-3619.

EPSS: Низкий
github логотип

GHSA-3c39-w687-672w

почти 2 года назад

Azure SDK Spoofing Vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3c38-6263-x4qc

почти 4 года назад

Format string vulnerability in the log function in Net::Server 0.87 and earlier, as used in Postfix Greylisting Policy Server (Postgrey) 1.18 and earlier, and possibly other products, allows remote attackers to cause a denial of service (crash) via format string specifiers that are not properly handled before being sent to syslog, as demonstrated using sender addresses to Postgrey.

EPSS: Низкий
github логотип

GHSA-3c38-2mw5-c664

больше 3 лет назад

In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_win7_x64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c402004.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3c38-2c7r-g6j4

около 4 лет назад

The Smart Floating / Sticky Buttons WordPress plugin before 2.5.5 does not sanitise and escape some parameter before outputting them in attributes and page, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

EPSS: Низкий
github логотип

GHSA-3c37-qxqv-r99x

больше 3 лет назад

A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0662.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-3c37-jjmv-92cc

почти 4 года назад

Unknown vulnerability in Squiggle for Batik before 1.5.1 allows attackers to bypass certain access controls via certain features of the Rhino scripting engine due to a "script security issue."

EPSS: Низкий
github логотип

GHSA-3c37-5qc5-cf3q

почти 4 года назад

Human Interface Toolbox (HIToolBox) for Apple Mac 0S X 10.3.6 allows local users to exit applications via the force-quit key combination, even when the system is running in kiosk mode.

EPSS: Низкий
github логотип

GHSA-3c36-xcfh-9hv4

почти 2 года назад

Trimble SketchUp Viewer SKP File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SKP files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-20789.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3c35-prjf-p48q

21 день назад

dr_flac, an audio decoder within the dr_libs toolset, contains an integer overflow vulnerability flaw due to trusting the totalPCMFrameCount field from FLAC metadata before calculating buffer size, allowing an attacker with a specially crafted file to perform DoS against programs using the tool.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3c3p-xh4f-pfh7

json-schema-editor-visual vulnerable to prototype pollution

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-3c3m-qp4j-mgv8

An issue was discovered in sela through 20200412. A NULL pointer dereference exists in the function lpc::SampleGenerator::process() located in sample_generator.cpp. It allows an attacker to cause Denial of Service.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c3m-ffrh-rq6p

An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php searchColumn parameter.

94%
Критический
больше 3 лет назад
github логотип
GHSA-3c3h-v674-rhqr

md4c 0.2.6 has a NULL pointer dereference in the function md_process_line in md4c.c, related to ctx->current_block.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c3g-q64x-8mfv

The Google CSE WordPress plugin through 1.0.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 4.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3c3f-mfjj-vmx7

Cross-site scripting (XSS) vulnerability in mail compose in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7.8.2-rev31, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev28 allows remote attackers to inject arbitrary web script or HTML via the data-target attribute in an HTML page with data-toggle gadgets.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c3f-93qj-h99f

Cross-site scripting (XSS) vulnerability in clanek.php in OwnRS Beta 3 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

3%
Низкий
почти 4 года назад
github логотип
GHSA-3c3f-2h7p-qwc8

When a user opens manipulated Scalable Vector Graphics (.SVG) format files received from untrusted sources in SAP 3D Visual Enterprise Viewer version 9, the application crashes and becomes temporarily unavailable to the user until restart of the application.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c3c-wv2g-35jm

Million Dollar Text Links 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the userid cookie to 1.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3c3c-2xp4-j4qp

The wp-slimstat plugin before 4.8.1 for WordPress has XSS.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c39-x2h8-rmf7

Absolute path traversal vulnerability in the extract_jar function in jartool.c in FastJar 0.98 allows remote attackers to create or overwrite arbitrary files via a full pathname for a file within a .jar archive, a related issue to CVE-2010-0831. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-3619.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3c39-w687-672w

Azure SDK Spoofing Vulnerability

CVSS3: 7.5
7%
Низкий
почти 2 года назад
github логотип
GHSA-3c38-6263-x4qc

Format string vulnerability in the log function in Net::Server 0.87 and earlier, as used in Postfix Greylisting Policy Server (Postgrey) 1.18 and earlier, and possibly other products, allows remote attackers to cause a denial of service (crash) via format string specifiers that are not properly handled before being sent to syslog, as demonstrated using sender addresses to Postgrey.

6%
Низкий
почти 4 года назад
github логотип
GHSA-3c38-2mw5-c664

In Advanced SystemCare Ultimate 11.0.1.58, the driver file (Monitor_win7_x64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c402004.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3c38-2c7r-g6j4

The Smart Floating / Sticky Buttons WordPress plugin before 2.5.5 does not sanitise and escape some parameter before outputting them in attributes and page, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

0%
Низкий
около 4 лет назад
github логотип
GHSA-3c37-qxqv-r99x

A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0662.

CVSS3: 8.8
36%
Средний
больше 3 лет назад
github логотип
GHSA-3c37-jjmv-92cc

Unknown vulnerability in Squiggle for Batik before 1.5.1 allows attackers to bypass certain access controls via certain features of the Rhino scripting engine due to a "script security issue."

0%
Низкий
почти 4 года назад
github логотип
GHSA-3c37-5qc5-cf3q

Human Interface Toolbox (HIToolBox) for Apple Mac 0S X 10.3.6 allows local users to exit applications via the force-quit key combination, even when the system is running in kiosk mode.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3c36-xcfh-9hv4

Trimble SketchUp Viewer SKP File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SKP files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-20789.

CVSS3: 7.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-3c35-prjf-p48q

dr_flac, an audio decoder within the dr_libs toolset, contains an integer overflow vulnerability flaw due to trusting the totalPCMFrameCount field from FLAC metadata before calculating buffer size, allowing an attacker with a specially crafted file to perform DoS against programs using the tool.

CVSS3: 5.5
0%
Низкий
21 день назад

Уязвимостей на страницу