Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-36xm-4j44-qpm8

больше 3 лет назад

On Insteon Hub 2245-222 devices with firmware version 1012, specially crafted replies received from the PubNub service can cause buffer overflows on a global section overwriting arbitrary data. An attacker should impersonate PubNub and answer an HTTPS GET request to trigger this vulnerability. A strcpy overflows the buffer insteon_pubnub.channel_ak, which has a size of 16 bytes. An attacker can send an arbitrarily long "ak" parameter in order to exploit this vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-36xm-35qq-795w

больше 2 лет назад

Inventory exposes reference to non-Sync data to an arbitrary thread

EPSS: Низкий
github логотип

GHSA-36xj-qg9x-f33m

больше 3 лет назад

The IPv6 routing header parser in tcpdump before 4.9.2 has a buffer over-read in print-rt6.c:rt6_print().

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-36xj-gx8g-m5fr

больше 1 года назад

The goTenna Pro series allows unauthenticated attackers to remotely update the local public keys used for P2P and Group messages.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-36xj-gcr2-cgrf

около 2 лет назад

Buffer Overflow vulnerability in the nomath() function in Mathtex v.1.05 and before allows a remote attacker to cause a denial of service via a crafted string in the application URL.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-36xh-w73j-574g

больше 3 лет назад

A flaw was found in samba. Spaces used in a string around a domain name (DN), while supposed to be ignored, can cause invalid DN strings with spaces to instead write a zero-byte into out-of-bounds memory, resulting in a crash. The highest threat from this vulnerability is to system availability.

EPSS: Средний
github логотип

GHSA-36xh-8g5r-c7cj

почти 4 года назад

The recursor in PowerDNS before 3.0.1 allows remote attackers to cause a denial of service (application crash) via malformed EDNS0 packets.

EPSS: Низкий
github логотип

GHSA-36xh-276f-w5j9

больше 1 года назад

The Accordion Image Menu WordPress plugin through 3.1.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-36xg-989x-49mx

почти 4 года назад

Unquoted Windows search path vulnerability in iTunesHelper.exe in iTunes 4.7.1.30 and iTunes 5 for Windows might allow local users to gain privileges via a malicious C:\program.exe file.

EPSS: Низкий
github логотип

GHSA-36xg-7wfq-m2jj

8 месяцев назад

A vulnerability classified as problematic has been found in enilu web-flash 1.0. This affects the function fileService.upload of the file src/main/java/cn/enilu/flash/api/controller/FileController/upload of the component File Upload. The manipulation of the argument File leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-36xf-6g36-vrxc

почти 4 года назад

Cross-site scripting (XSS) vulnerability in mod.php in the datenbank module for phpBB allows remote attackers to inject arbitrary web script or HTML via the id parameter.

EPSS: Низкий
github логотип

GHSA-36xf-5ww9-9jq3

больше 3 лет назад

An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 10 Servers, Windows 10. This CVE ID is unique from CVE-2018-8207.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-36xf-46cq-66rf

почти 4 года назад

Forms generated by JQueryForm.com before 2022-02-05 allows a remote authenticated attacker to access the cleartext credentials of all other form users. admin.php contains a hidden base64-encoded string with these credentials.

EPSS: Низкий
github логотип

GHSA-36xf-458c-932h

около 1 года назад

Missing Authorization vulnerability in Lucian Apostol Auto Affiliate Links allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Auto Affiliate Links: from n/a through 6.2.1.5.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-36xc-3g6q-fjj6

11 месяцев назад

Server-Side Request Forgery (SSRF) vulnerability in SuitePlugins Video & Photo Gallery for Ultimate Member allows Server Side Request Forgery.This issue affects Video & Photo Gallery for Ultimate Member: from n/a through 1.1.2.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-36x9-qhr2-jphh

больше 1 года назад

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters in all versions up to, and including, 7.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-36x9-82rm-pg8f

почти 4 года назад

man-db 2.3.12 and 2.3.18 to 2.4.1 uses certain user-controlled DEFINE directives from the ~/.manpath file, even when running setuid, which could allow local users to gain privileges.

EPSS: Низкий
github логотип

GHSA-36x9-553r-v339

6 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: nfsd: avoid ref leak in nfsd_open_local_fh() If two calls to nfsd_open_local_fh() race and both successfully call nfsd_file_acquire_local(), they will both get an extra reference to the net to accompany the file reference stored in *pnf. One of them will fail to store (using xchg()) the file reference in *pnf and will drop that reference but WON'T drop the accompanying reference to the net. This leak means that when the nfs server is shut down it will hang in nfsd_shutdown_net() waiting for &nn->nfsd_net_free_done. This patch adds the missing nfsd_net_put().

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-36x9-48hm-r28q

больше 3 лет назад

A cross-site scripting vulnerability was discovered in the Comments parameter in Textpattern CMS 4.8.4 which allows remote attackers to execute arbitrary code via a crafted payload entered into the URL field. The vulnerability is triggered by users visiting https://site.com/articles/welcome-to-your-site#comments-head.

EPSS: Низкий
github логотип

GHSA-36x9-388f-m9wr

больше 3 лет назад

Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-36xm-4j44-qpm8

On Insteon Hub 2245-222 devices with firmware version 1012, specially crafted replies received from the PubNub service can cause buffer overflows on a global section overwriting arbitrary data. An attacker should impersonate PubNub and answer an HTTPS GET request to trigger this vulnerability. A strcpy overflows the buffer insteon_pubnub.channel_ak, which has a size of 16 bytes. An attacker can send an arbitrarily long "ak" parameter in order to exploit this vulnerability.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-36xm-35qq-795w

Inventory exposes reference to non-Sync data to an arbitrary thread

больше 2 лет назад
github логотип
GHSA-36xj-qg9x-f33m

The IPv6 routing header parser in tcpdump before 4.9.2 has a buffer over-read in print-rt6.c:rt6_print().

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-36xj-gx8g-m5fr

The goTenna Pro series allows unauthenticated attackers to remotely update the local public keys used for P2P and Group messages.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-36xj-gcr2-cgrf

Buffer Overflow vulnerability in the nomath() function in Mathtex v.1.05 and before allows a remote attacker to cause a denial of service via a crafted string in the application URL.

CVSS3: 7.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-36xh-w73j-574g

A flaw was found in samba. Spaces used in a string around a domain name (DN), while supposed to be ignored, can cause invalid DN strings with spaces to instead write a zero-byte into out-of-bounds memory, resulting in a crash. The highest threat from this vulnerability is to system availability.

18%
Средний
больше 3 лет назад
github логотип
GHSA-36xh-8g5r-c7cj

The recursor in PowerDNS before 3.0.1 allows remote attackers to cause a denial of service (application crash) via malformed EDNS0 packets.

0%
Низкий
почти 4 года назад
github логотип
GHSA-36xh-276f-w5j9

The Accordion Image Menu WordPress plugin through 3.1.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-36xg-989x-49mx

Unquoted Windows search path vulnerability in iTunesHelper.exe in iTunes 4.7.1.30 and iTunes 5 for Windows might allow local users to gain privileges via a malicious C:\program.exe file.

0%
Низкий
почти 4 года назад
github логотип
GHSA-36xg-7wfq-m2jj

A vulnerability classified as problematic has been found in enilu web-flash 1.0. This affects the function fileService.upload of the file src/main/java/cn/enilu/flash/api/controller/FileController/upload of the component File Upload. The manipulation of the argument File leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 3.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-36xf-6g36-vrxc

Cross-site scripting (XSS) vulnerability in mod.php in the datenbank module for phpBB allows remote attackers to inject arbitrary web script or HTML via the id parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-36xf-5ww9-9jq3

An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 10 Servers, Windows 10. This CVE ID is unique from CVE-2018-8207.

CVSS3: 4.7
1%
Низкий
больше 3 лет назад
github логотип
GHSA-36xf-46cq-66rf

Forms generated by JQueryForm.com before 2022-02-05 allows a remote authenticated attacker to access the cleartext credentials of all other form users. admin.php contains a hidden base64-encoded string with these credentials.

0%
Низкий
почти 4 года назад
github логотип
GHSA-36xf-458c-932h

Missing Authorization vulnerability in Lucian Apostol Auto Affiliate Links allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Auto Affiliate Links: from n/a through 6.2.1.5.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-36xc-3g6q-fjj6

Server-Side Request Forgery (SSRF) vulnerability in SuitePlugins Video & Photo Gallery for Ultimate Member allows Server Side Request Forgery.This issue affects Video & Photo Gallery for Ultimate Member: from n/a through 1.1.2.

CVSS3: 4.9
0%
Низкий
11 месяцев назад
github логотип
GHSA-36x9-qhr2-jphh

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters in all versions up to, and including, 7.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-36x9-82rm-pg8f

man-db 2.3.12 and 2.3.18 to 2.4.1 uses certain user-controlled DEFINE directives from the ~/.manpath file, even when running setuid, which could allow local users to gain privileges.

0%
Низкий
почти 4 года назад
github логотип
GHSA-36x9-553r-v339

In the Linux kernel, the following vulnerability has been resolved: nfsd: avoid ref leak in nfsd_open_local_fh() If two calls to nfsd_open_local_fh() race and both successfully call nfsd_file_acquire_local(), they will both get an extra reference to the net to accompany the file reference stored in *pnf. One of them will fail to store (using xchg()) the file reference in *pnf and will drop that reference but WON'T drop the accompanying reference to the net. This leak means that when the nfs server is shut down it will hang in nfsd_shutdown_net() waiting for &nn->nfsd_net_free_done. This patch adds the missing nfsd_net_put().

CVSS3: 4.7
0%
Низкий
6 месяцев назад
github логотип
GHSA-36x9-48hm-r28q

A cross-site scripting vulnerability was discovered in the Comments parameter in Textpattern CMS 4.8.4 which allows remote attackers to execute arbitrary code via a crafted payload entered into the URL field. The vulnerability is triggered by users visiting https://site.com/articles/welcome-to-your-site#comments-head.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-36x9-388f-m9wr

Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 5.5
2%
Низкий
больше 3 лет назад

Уязвимостей на страницу