Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-3795-q2gj-wwmj

около 2 месяцев назад

Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker to execute malicious scripts in the context of the victim's browser. Exploitation of this issue requires user interaction, such as visiting a crafted URL or interacting with a manipulated web page.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3795-4m6r-47rj

больше 3 лет назад

Format string vulnerability in the client in Tftpd32 before 4.50 allows remote servers to cause a denial of service (crash) or possibly execute arbitrary code via format string specifiers in the Remote File field.

EPSS: Низкий
github логотип

GHSA-3794-vfg4-p57g

почти 4 года назад

A remote vulnerability was discovered in Aruba Instant On 1930 Switch Series version(s): Firmware below v1.0.7.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3794-gcgw-37cm

больше 1 года назад

Windows Themes Denial of Service Vulnerability

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3794-c67g-vh97

больше 3 лет назад

In postInstantAppNotif of InstantAppNotifier.java, there is a possible permission bypass due to a PendingIntent error. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-8.0 Android-8.1 Android-9Android ID: A-154719656

EPSS: Низкий
github логотип

GHSA-3793-h2x2-5gc7

больше 3 лет назад

IBM Emptoris Supplier Lifecycle Management 10.1.0.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120658.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3793-4q29-j9vm

12 месяцев назад

Improper input validation for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable denial of service via local access.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-3792-ff84-674w

больше 3 лет назад

Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-3792-937m-5pm4

около 2 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: crypto: zstd - fix double-free in per-CPU stream cleanup The crypto/zstd module has a double-free bug that occurs when multiple tfms are allocated and freed. The issue happens because zstd_streams (per-CPU contexts) are freed in zstd_exit() during every tfm destruction, rather than being managed at the module level. When multiple tfms exist, each tfm exit attempts to free the same shared per-CPU streams, resulting in a double-free. This leads to a stack trace similar to: BUG: Bad page state in process kworker/u16:1 pfn:106fd93 page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x106fd93 flags: 0x17ffffc0000000(node=0|zone=2|lastcpupid=0x1fffff) page_type: 0xffffffff() raw: 0017ffffc0000000 dead000000000100 dead000000000122 0000000000000000 raw: 0000000000000000 0000000000000000 00000000ffffffff 0000000000000000 page dumped because: nonzero entire_mapcount Modules linked in: ......

EPSS: Низкий
github логотип

GHSA-378x-6p4f-8jgm

6 месяцев назад

SKOPS Card.get_model happily allows arbitrary code execution

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-378w-m5r6-wj6p

11 месяцев назад

The Inline Image Upload for BBPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the file uploading functionality in all versions up to, and including, 1.1.19. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. This may be exploitable by unauthenticated attackers when the "Allow guest users without accounts to create topics and replies" setting is enabled.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-378w-3fqw-3555

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in GET requests in FreshRSS 1.11.1 allow remote attackers to inject arbitrary web script or HTML via the (1) c parameter or (2) a parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-378v-gpcp-jf6v

почти 4 года назад

OpenShift cartridge allows remote URL retrieval

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-378v-8vg7-wxcv

почти 4 года назад

Microsoft Internet Explorer 5.01, 6, and 7 uses certain COM objects from (1) Msb1fren.dll, (2) Htmlmm.ocx, and (3) Blnmgrps.dll as ActiveX controls, which allows remote attackers to execute arbitrary code via unspecified vectors, a different issue than CVE-2006-4697.

EPSS: Средний
github логотип

GHSA-378r-2hmj-3r7x

10 месяцев назад

The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to modify protected parts of the file system.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-378q-m7x3-6f3j

больше 3 лет назад

Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

EPSS: Низкий
github логотип

GHSA-378q-gq6q-wjhh

больше 3 лет назад

timg v1.4.4 was discovered to contain a memory leak via the function timg::QueryBackgroundColor() at /timg/src/term-query.cc.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-378p-j64m-xgm4

больше 3 лет назад

Use-after-free in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-378p-hrq3-x4p3

больше 4 лет назад

Cross-site scripting in Shopizer

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-378p-935f-rmpw

больше 3 лет назад

Stack-based buffer overflow in the (1) sid_parse and (2) dom_sid_parse functions in Samba before 3.5.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted Windows Security ID (SID) on a file share.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3795-q2gj-wwmj

Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker to execute malicious scripts in the context of the victim's browser. Exploitation of this issue requires user interaction, such as visiting a crafted URL or interacting with a manipulated web page.

CVSS3: 5.4
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3795-4m6r-47rj

Format string vulnerability in the client in Tftpd32 before 4.50 allows remote servers to cause a denial of service (crash) or possibly execute arbitrary code via format string specifiers in the Remote File field.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3794-vfg4-p57g

A remote vulnerability was discovered in Aruba Instant On 1930 Switch Series version(s): Firmware below v1.0.7.0.

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-3794-gcgw-37cm

Windows Themes Denial of Service Vulnerability

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3794-c67g-vh97

In postInstantAppNotif of InstantAppNotifier.java, there is a possible permission bypass due to a PendingIntent error. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-8.0 Android-8.1 Android-9Android ID: A-154719656

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3793-h2x2-5gc7

IBM Emptoris Supplier Lifecycle Management 10.1.0.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120658.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3793-4q29-j9vm

Improper input validation for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated user to potentially enable denial of service via local access.

CVSS3: 5
0%
Низкий
12 месяцев назад
github логотип
GHSA-3792-ff84-674w

Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.

CVSS3: 9.8
93%
Критический
больше 3 лет назад
github логотип
GHSA-3792-937m-5pm4

In the Linux kernel, the following vulnerability has been resolved: crypto: zstd - fix double-free in per-CPU stream cleanup The crypto/zstd module has a double-free bug that occurs when multiple tfms are allocated and freed. The issue happens because zstd_streams (per-CPU contexts) are freed in zstd_exit() during every tfm destruction, rather than being managed at the module level. When multiple tfms exist, each tfm exit attempts to free the same shared per-CPU streams, resulting in a double-free. This leads to a stack trace similar to: BUG: Bad page state in process kworker/u16:1 pfn:106fd93 page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x106fd93 flags: 0x17ffffc0000000(node=0|zone=2|lastcpupid=0x1fffff) page_type: 0xffffffff() raw: 0017ffffc0000000 dead000000000100 dead000000000122 0000000000000000 raw: 0000000000000000 0000000000000000 00000000ffffffff 0000000000000000 page dumped because: nonzero entire_mapcount Modules linked in: ......

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-378x-6p4f-8jgm

SKOPS Card.get_model happily allows arbitrary code execution

CVSS3: 8.4
0%
Низкий
6 месяцев назад
github логотип
GHSA-378w-m5r6-wj6p

The Inline Image Upload for BBPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the file uploading functionality in all versions up to, and including, 1.1.19. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. This may be exploitable by unauthenticated attackers when the "Allow guest users without accounts to create topics and replies" setting is enabled.

CVSS3: 8.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-378w-3fqw-3555

Multiple cross-site scripting (XSS) vulnerabilities in GET requests in FreshRSS 1.11.1 allow remote attackers to inject arbitrary web script or HTML via the (1) c parameter or (2) a parameter.

CVSS3: 6.1
6%
Низкий
больше 3 лет назад
github логотип
GHSA-378v-gpcp-jf6v

OpenShift cartridge allows remote URL retrieval

CVSS3: 8.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-378v-8vg7-wxcv

Microsoft Internet Explorer 5.01, 6, and 7 uses certain COM objects from (1) Msb1fren.dll, (2) Htmlmm.ocx, and (3) Blnmgrps.dll as ActiveX controls, which allows remote attackers to execute arbitrary code via unspecified vectors, a different issue than CVE-2006-4697.

62%
Средний
почти 4 года назад
github логотип
GHSA-378r-2hmj-3r7x

The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to modify protected parts of the file system.

CVSS3: 5
0%
Низкий
10 месяцев назад
github логотип
GHSA-378q-m7x3-6f3j

Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-378q-gq6q-wjhh

timg v1.4.4 was discovered to contain a memory leak via the function timg::QueryBackgroundColor() at /timg/src/term-query.cc.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-378p-j64m-xgm4

Use-after-free in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

CVSS3: 6.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-378p-hrq3-x4p3

Cross-site scripting in Shopizer

CVSS3: 4.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-378p-935f-rmpw

Stack-based buffer overflow in the (1) sid_parse and (2) dom_sid_parse functions in Samba before 3.5.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted Windows Security ID (SID) on a file share.

17%
Средний
больше 3 лет назад

Уязвимостей на страницу