Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-399p-vq28-5hg8

около 3 лет назад

keynote Cross-site Scripting vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-399p-gmjm-mpxv

больше 3 лет назад

Tor Browser through 8.5.3 has an information exposure vulnerability. It allows remote attackers to detect the browser's language via vectors involving an IFRAME element, because text in that language is included in the title attribute of a LINK element for a non-HTML page. This is related to a behavior of Firefox before 68.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-399m-rf4f-w5x4

7 месяцев назад

hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue to CVE-2024-26327.

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-399m-q8wq-qf54

больше 3 лет назад

A vulnerability in the Cisco Data Center Analytics Framework application could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to improper CSRF protection by the affected application. An attacker could exploit this vulnerability by persuading a user of the affected application to click a malicious link. A successful exploit could allow the attacker to submit arbitrary requests and take unauthorized actions on behalf of the user. Cisco Bug IDs: CSCvg45114.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-399m-8cpm-hqf8

больше 3 лет назад

Vulnerability in the Oracle Email Center product of Oracle E-Business Suite (component: Customer Search). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Email Center. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Email Center, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Email Center accessible data as well as unauthorized update, insert or delete access to some of Oracle Email Center accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).

EPSS: Низкий
github логотип

GHSA-399m-4fj8-h7wr

почти 3 года назад

Adobe Dimension versions 3.4.7 (and earlier) is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-399j-vxmf-hjvr

3 месяца назад

@react-native-community/cli has arbitrary OS command injection

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-399j-46mc-wxhx

почти 4 года назад

Teredo clients, when source routing is enabled, recognize a Routing header in an encapsulated IPv6 packet and send the packet to the next hop, which might allow remote attackers to bypass policies of certain Internet gateways that drop all source-routed packets.

EPSS: Средний
github логотип

GHSA-399h-rrqc-rpgv

2 месяца назад

When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malicious server to cause the client to read large amounts of data into memory, potentially causing OOM or other DoS.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-399h-m926-3rpw

7 месяцев назад

YONO SBI: Banking & Lifestyle v1.23.36 was discovered to use unencrypted communicatons, possibly allowing attackers to execute a man-in-the-middle attack.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-399h-cmvp-qgx5

больше 4 лет назад

Incorrect Default Permissions in Binance tss-lib

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-399h-c495-rg37

больше 3 лет назад

An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: N/A. Android ID: A-31471220. References: QC-CR#979426.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-399f-x62x-r9gr

больше 3 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2433.

EPSS: Низкий
github логотип

GHSA-399f-937r-fwr9

больше 2 лет назад

Adobe Media Encoder versions 22.0, 15.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious 3GP ?file

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-399c-wvqc-phrq

больше 3 лет назад

The BlackBerry Universal Device Service in BlackBerry Enterprise Service (BES) 10.0 through 10.1.2 does not properly restrict access to the JBoss Remote Method Invocation (RMI) interface, which allows remote attackers to upload and execute arbitrary packages via a request to port 1098.

EPSS: Низкий
github логотип

GHSA-399c-6449-xhh6

больше 2 лет назад

Bluetooth® Low Energy Pairing in Bluetooth Core Specification v4.0 through v5.3 may permit an unauthenticated MITM to acquire credentials with two pairing devices via adjacent access when the MITM negotiates Legacy Passkey Pairing with the pairing Initiator and Secure Connections Passkey Pairing with the pairing Responder and brute forces the Passkey entered by the user into the Initiator. The MITM attacker can use the identified Passkey value to complete authentication with the Responder via Bluetooth pairing method confusion.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-399c-25pm-72mj

больше 3 лет назад

A file write vulnerability exists in the httpd upload.cgi functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can upload a malicious file to trigger this vulnerability.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3999-5ffv-wp2r

почти 2 года назад

Yamux Memory Exhaustion Vulnerability via Active::pending_frames property

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3997-cwm3-9wpp

больше 3 лет назад

Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow remote attackers to execute arbitrary code via a font.

EPSS: Низкий
github логотип

GHSA-3997-6wvq-mg36

больше 3 лет назад

Improper Access Control vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local users to access files which the user otherwise would not have access to via manipulating symbolic links to redirect McAfee file operations to an unintended file.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-399p-vq28-5hg8

keynote Cross-site Scripting vulnerability

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-399p-gmjm-mpxv

Tor Browser through 8.5.3 has an information exposure vulnerability. It allows remote attackers to detect the browser's language via vectors involving an IFRAME element, because text in that language is included in the title attribute of a LINK element for a non-HTML page. This is related to a behavior of Firefox before 68.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-399m-rf4f-w5x4

hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue to CVE-2024-26327.

CVSS3: 4.2
0%
Низкий
7 месяцев назад
github логотип
GHSA-399m-q8wq-qf54

A vulnerability in the Cisco Data Center Analytics Framework application could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to improper CSRF protection by the affected application. An attacker could exploit this vulnerability by persuading a user of the affected application to click a malicious link. A successful exploit could allow the attacker to submit arbitrary requests and take unauthorized actions on behalf of the user. Cisco Bug IDs: CSCvg45114.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-399m-8cpm-hqf8

Vulnerability in the Oracle Email Center product of Oracle E-Business Suite (component: Customer Search). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Email Center. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Email Center, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Email Center accessible data as well as unauthorized update, insert or delete access to some of Oracle Email Center accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).

1%
Низкий
больше 3 лет назад
github логотип
GHSA-399m-4fj8-h7wr

Adobe Dimension versions 3.4.7 (and earlier) is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-399j-vxmf-hjvr

@react-native-community/cli has arbitrary OS command injection

CVSS3: 9.8
7%
Низкий
3 месяца назад
github логотип
GHSA-399j-46mc-wxhx

Teredo clients, when source routing is enabled, recognize a Routing header in an encapsulated IPv6 packet and send the packet to the next hop, which might allow remote attackers to bypass policies of certain Internet gateways that drop all source-routed packets.

10%
Средний
почти 4 года назад
github логотип
GHSA-399h-rrqc-rpgv

When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malicious server to cause the client to read large amounts of data into memory, potentially causing OOM or other DoS.

CVSS3: 9.1
0%
Низкий
2 месяца назад
github логотип
GHSA-399h-m926-3rpw

YONO SBI: Banking & Lifestyle v1.23.36 was discovered to use unencrypted communicatons, possibly allowing attackers to execute a man-in-the-middle attack.

CVSS3: 8.8
7 месяцев назад
github логотип
GHSA-399h-cmvp-qgx5

Incorrect Default Permissions in Binance tss-lib

CVSS3: 8.6
0%
Низкий
больше 4 лет назад
github логотип
GHSA-399h-c495-rg37

An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: N/A. Android ID: A-31471220. References: QC-CR#979426.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-399f-x62x-r9gr

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2433.

6%
Низкий
больше 3 лет назад
github логотип
GHSA-399f-937r-fwr9

Adobe Media Encoder versions 22.0, 15.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious 3GP ?file

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-399c-wvqc-phrq

The BlackBerry Universal Device Service in BlackBerry Enterprise Service (BES) 10.0 through 10.1.2 does not properly restrict access to the JBoss Remote Method Invocation (RMI) interface, which allows remote attackers to upload and execute arbitrary packages via a request to port 1098.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-399c-6449-xhh6

Bluetooth® Low Energy Pairing in Bluetooth Core Specification v4.0 through v5.3 may permit an unauthenticated MITM to acquire credentials with two pairing devices via adjacent access when the MITM negotiates Legacy Passkey Pairing with the pairing Initiator and Secure Connections Passkey Pairing with the pairing Responder and brute forces the Passkey entered by the user into the Initiator. The MITM attacker can use the identified Passkey value to complete authentication with the Responder via Bluetooth pairing method confusion.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-399c-25pm-72mj

A file write vulnerability exists in the httpd upload.cgi functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can upload a malicious file to trigger this vulnerability.

CVSS3: 8.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3999-5ffv-wp2r

Yamux Memory Exhaustion Vulnerability via Active::pending_frames property

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-3997-cwm3-9wpp

Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow remote attackers to execute arbitrary code via a font.

10%
Низкий
больше 3 лет назад
github логотип
GHSA-3997-6wvq-mg36

Improper Access Control vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local users to access files which the user otherwise would not have access to via manipulating symbolic links to redirect McAfee file operations to an unintended file.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу