Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-398m-f4ch-cf26

больше 3 лет назад

Cryptocat before 2.0.22 has Nickname User Impersonation

EPSS: Низкий
github логотип

GHSA-398m-55cm-6j6x

около 2 лет назад

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-398j-x47f-2q99

больше 3 лет назад

When sharing geolocation during an active WebRTC share, Firefox could have reset the webRTC sharing state in the user interface, leading to loss of control over the currently granted permission. This vulnerability affects Firefox < 85.

EPSS: Низкий
github логотип

GHSA-398j-w8vh-r865

больше 3 лет назад

The Tomcat package on Red Hat Enterprise Linux (RHEL) 5 through 7, JBoss Web Server 3.0, and JBoss EWS 2 uses weak permissions for (1) /etc/sysconfig/tomcat and (2) /etc/tomcat/tomcat.conf, which allows local users to gain privileges by leveraging membership in the tomcat group.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-398j-r5c5-vrph

больше 3 лет назад

In Cloud Foundry router routing-release all versions prior to v0.163.0 and cf-release all versions prior to v274, in some applications, it is possible to append a combination of characters to the URL that will allow for an open redirect. An attacker could exploit this as a phishing attack to gain access to user credentials or other sensitive data. NOTE: 274 resolves the vulnerability but has a serious bug that is fixed in 275.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-398j-f7m7-795j

больше 3 лет назад

PHPMailer vulnerable to email header injection

EPSS: Низкий
github логотип

GHSA-398j-37xh-xw92

почти 4 года назад

SQL injection vulnerability in messages.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the msg_view parameter, a different vulnerability than CVE-2005-3157 and CVE-2005-3158.

EPSS: Низкий
github логотип

GHSA-398g-xgm8-h7c4

почти 4 года назад

Kaspersky Anti-Virus (KAV) and Internet Security 7.0 build 125 do not properly validate certain parameters to System Service Descriptor Table (SSDT) and Shadow SSDT function handlers, which allows local users to cause a denial of service (crash) via the (1) NtUserSendInput, (2) LoadLibraryA, (3) NtOpenProcess, (4) NtOpenThread, (5) NtTerminateProcess, (6) NtUserFindWindowEx, and (7) NtUserBuildHwndList kernel SSDT hooks in kylif.sys; the (8) NtDuplicateObject (DuplicateHandle) kernel SSDT hook; and possibly other kernel SSDT hooks. NOTE: the NtCreateSection vector is covered by CVE-2007-5043.1. NOTE: the vendor disputes that the DuplicateHandle vector is a vulnerability in their code, stating that "it is not an error in our code, but an obscure method for manipulating standard Windows routines to circumvent our self-defense mechanisms."

EPSS: Низкий
github логотип

GHSA-398g-pgqg-vjj2

больше 3 лет назад

A local attacker may be able to elevate their privileges. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. A memory corruption issue was addressed with improved validation.

EPSS: Низкий
github логотип

GHSA-398f-726v-q88v

около 2 лет назад

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4. An app may be able to read sensitive location information.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-398f-443h-w6mr

почти 4 года назад

Cryptocat before 2.0.22: cryptocat.js handlePresence() has cross site scripting

EPSS: Низкий
github логотип

GHSA-398c-f7w9-crc8

около 1 года назад

A flaw was found in FFmpeg's TTY Demuxer. This vulnerability allows possible data exfiltration via improper parsing of non-TTY-compliant input files in HLS playlists.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-398c-7m57-4f84

больше 3 лет назад

Multiple integer overflows in drivers/crypto/msm/qcedev.c in the Qualcomm cryptographic engine driver in Android before 2016-10-05 on Nexus 5X, Nexus 6, Nexus 6P, and Android One devices allow attackers to gain privileges via a crafted application, aka Android internal bug 29999665 and Qualcomm internal bug CR 1046507.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3989-vpff-cvxj

больше 1 года назад

Missing Authorization vulnerability in actpro Extra Product Options for WooCommerce.This issue affects Extra Product Options for WooCommerce: from n/a through 3.0.6.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3989-crp4-69hw

больше 1 года назад

A vulnerability has been found in code-projects Blood Bank Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /file/updateprofile.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3989-4c6x-725f

почти 3 года назад

XWiki Platform vulnerable to privilege escalation from view right on XWiki.AttachmentSelector

CVSS3: 9.9
EPSS: Средний
github логотип

GHSA-3988-q8q7-p787

10 месяцев назад

ash_authentication has email link auto-click account confirmation vulnerability

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3988-jj2m-p6m7

3 месяца назад

A vulnerability has been identified in Altair Grid Engine (All versions < V2026.0.0). Affected products do not properly validate environment variables when loading shared libraries, allowing path hijacking through malicious library substitution. This could allow a local attacker to execute arbitrary code with superuser privileges by manipulating the environment variable and placing a malicious library in the controlled path.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3988-h75v-hwf6

почти 4 года назад

Arbitrary shell execution

EPSS: Низкий
github логотип

GHSA-3988-7v79-mrm7

больше 3 лет назад

HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (document management page) to obtain database schema and data.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-398m-f4ch-cf26

Cryptocat before 2.0.22 has Nickname User Impersonation

0%
Низкий
больше 3 лет назад
github логотип
GHSA-398m-55cm-6j6x

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

CVSS3: 7.6
0%
Низкий
около 2 лет назад
github логотип
GHSA-398j-x47f-2q99

When sharing geolocation during an active WebRTC share, Firefox could have reset the webRTC sharing state in the user interface, leading to loss of control over the currently granted permission. This vulnerability affects Firefox < 85.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-398j-w8vh-r865

The Tomcat package on Red Hat Enterprise Linux (RHEL) 5 through 7, JBoss Web Server 3.0, and JBoss EWS 2 uses weak permissions for (1) /etc/sysconfig/tomcat and (2) /etc/tomcat/tomcat.conf, which allows local users to gain privileges by leveraging membership in the tomcat group.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-398j-r5c5-vrph

In Cloud Foundry router routing-release all versions prior to v0.163.0 and cf-release all versions prior to v274, in some applications, it is possible to append a combination of characters to the URL that will allow for an open redirect. An attacker could exploit this as a phishing attack to gain access to user credentials or other sensitive data. NOTE: 274 resolves the vulnerability but has a serious bug that is fixed in 275.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-398j-f7m7-795j

PHPMailer vulnerable to email header injection

0%
Низкий
больше 3 лет назад
github логотип
GHSA-398j-37xh-xw92

SQL injection vulnerability in messages.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the msg_view parameter, a different vulnerability than CVE-2005-3157 and CVE-2005-3158.

1%
Низкий
почти 4 года назад
github логотип
GHSA-398g-xgm8-h7c4

Kaspersky Anti-Virus (KAV) and Internet Security 7.0 build 125 do not properly validate certain parameters to System Service Descriptor Table (SSDT) and Shadow SSDT function handlers, which allows local users to cause a denial of service (crash) via the (1) NtUserSendInput, (2) LoadLibraryA, (3) NtOpenProcess, (4) NtOpenThread, (5) NtTerminateProcess, (6) NtUserFindWindowEx, and (7) NtUserBuildHwndList kernel SSDT hooks in kylif.sys; the (8) NtDuplicateObject (DuplicateHandle) kernel SSDT hook; and possibly other kernel SSDT hooks. NOTE: the NtCreateSection vector is covered by CVE-2007-5043.1. NOTE: the vendor disputes that the DuplicateHandle vector is a vulnerability in their code, stating that "it is not an error in our code, but an obscure method for manipulating standard Windows routines to circumvent our self-defense mechanisms."

0%
Низкий
почти 4 года назад
github логотип
GHSA-398g-pgqg-vjj2

A local attacker may be able to elevate their privileges. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. A memory corruption issue was addressed with improved validation.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-398f-726v-q88v

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4. An app may be able to read sensitive location information.

CVSS3: 3.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-398f-443h-w6mr

Cryptocat before 2.0.22: cryptocat.js handlePresence() has cross site scripting

0%
Низкий
почти 4 года назад
github логотип
GHSA-398c-f7w9-crc8

A flaw was found in FFmpeg's TTY Demuxer. This vulnerability allows possible data exfiltration via improper parsing of non-TTY-compliant input files in HLS playlists.

CVSS3: 5.3
0%
Низкий
около 1 года назад
github логотип
GHSA-398c-7m57-4f84

Multiple integer overflows in drivers/crypto/msm/qcedev.c in the Qualcomm cryptographic engine driver in Android before 2016-10-05 on Nexus 5X, Nexus 6, Nexus 6P, and Android One devices allow attackers to gain privileges via a crafted application, aka Android internal bug 29999665 and Qualcomm internal bug CR 1046507.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3989-vpff-cvxj

Missing Authorization vulnerability in actpro Extra Product Options for WooCommerce.This issue affects Extra Product Options for WooCommerce: from n/a through 3.0.6.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-3989-crp4-69hw

A vulnerability has been found in code-projects Blood Bank Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /file/updateprofile.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-3989-4c6x-725f

XWiki Platform vulnerable to privilege escalation from view right on XWiki.AttachmentSelector

CVSS3: 9.9
18%
Средний
почти 3 года назад
github логотип
GHSA-3988-q8q7-p787

ash_authentication has email link auto-click account confirmation vulnerability

CVSS3: 5.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-3988-jj2m-p6m7

A vulnerability has been identified in Altair Grid Engine (All versions < V2026.0.0). Affected products do not properly validate environment variables when loading shared libraries, allowing path hijacking through malicious library substitution. This could allow a local attacker to execute arbitrary code with superuser privileges by manipulating the environment variable and placing a malicious library in the controlled path.

CVSS3: 7.8
0%
Низкий
3 месяца назад
github логотип
GHSA-3988-h75v-hwf6

Arbitrary shell execution

почти 4 года назад
github логотип
GHSA-3988-7v79-mrm7

HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (document management page) to obtain database schema and data.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу