Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 529

Количество 314 529

github логотип

GHSA-393v-j9q3-p63r

10 месяцев назад

An Improper Check for Unusual or Exceptional Conditions vulnerability in the pfe (packet forwarding engine) of Juniper Networks Junos OS on MX Series causes a port within a pool to be blocked leading to Denial of Service (DoS). In a DS-Lite (Dual-Stack Lite) and NAT (Network Address Translation) scenario, when crafted IPv6 traffic is received and prefix-length is set to 56, the ports assigned to the user will not be freed.  Eventually, users cannot establish new connections. Affected FPC/PIC need to be manually restarted to recover. Following is the command to identify the issue:      user@host> show services nat source port-block      Host_IP                     External_IP                   Port_Block      Ports_Used/       Block_State/                                                               Range           Ports_Total       Left_Time(s)     2001::                    �...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-393v-ghcr-3x2m

больше 3 лет назад

Microsoft Bluetooth Driver in Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703 allows a spoofing vulnerability due to Microsoft's implementation of the Bluetooth stack, aka "Microsoft Bluetooth Driver Spoofing Vulnerability".

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-393r-r9mq-g9jv

больше 3 лет назад

Jenkins Configuration as Code Plugin vulnerable to Exposure of Sensitive Information

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-393r-2hjv-4h5f

больше 2 лет назад

SpotCam Co., Ltd. SpotCam FHD 2’s hidden Telnet function has a vulnerability of using hard-coded Telnet credentials. An remote unauthenticated attacker can exploit this vulnerability to access the system to perform arbitrary system operations or disrupt service.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-393q-7g3p-mp9v

больше 3 лет назад

signond before 8.57+15.04.20141127.1-0ubuntu1, as used in Ubuntu Touch, did not properly restrict applications from querying oath tokens due to incorrect checks and the missing installation of the signon-apparmor-extension. An attacker could use this create a malicious click app that collects oauth tokens for other applications, exposing sensitive information.

EPSS: Низкий
github логотип

GHSA-393q-6xw4-wfg2

почти 3 года назад

Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: OBVAM Trn Journal Domain). Supported versions that are affected are 14.5, 14.6 and 14.7. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Banking Virtual Account Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Banking Virtual Account Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Banking Virtual Account Management. CVSS 3.1 Base Score 5.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/...

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-393q-2jgx-p9ph

больше 3 лет назад

OrbiTeam BSCW before 5.0.8 allows remote attackers to obtain sensitive metadata via the inf operations (op=inf) to an object in pub/bscw.cgi/.

EPSS: Низкий
github логотип

GHSA-393p-mc4h-j8g2

больше 3 лет назад

The Beaver Builder – WordPress Page Builder for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Caption - On Hover' value associated with images in versions up to, and including, 2.5.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with access to the Beaver Builder editor to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-393m-vg99-2x36

больше 3 лет назад

IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows physically proximate attackers to obtain sensitive information by reading cached data on a client device.

CVSS3: 2.1
EPSS: Низкий
github логотип

GHSA-393j-fpg3-h6c9

больше 2 лет назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Page Visit Counter Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress allows SQL Injection.This issue affects Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress: from n/a through 7.1.1.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-393j-8xcq-h729

больше 3 лет назад

Version 1.0.0 of the Instana Dynamic APM Docker image contains a blank password for the root user. Systems deployed using affected versions of the Instana Dynamic APM container may allow a remote attacker to achieve root access with a blank password.

EPSS: Низкий
github логотип

GHSA-393h-j526-4h79

больше 3 лет назад

In NETGEAR Nighthawk X10-R900 prior to 1.0.4.26, an attacker may bypass all authentication checks on the device's "NETGEAR Genie" SOAP API ("/soap/server_sa") by supplying a malicious X-Forwarded-For header of the device's LAN IP address (192.168.1.1) in every request. As a result, an attacker may modify almost all of the device's settings and view various configuration settings.

EPSS: Низкий
github логотип

GHSA-393g-7274-4jmv

больше 3 лет назад

Canon Oce Print Exec Workgroup 1.3.2 allows Host header injection.

EPSS: Низкий
github логотип

GHSA-393f-4662-497f

больше 3 лет назад

An issue was discovered in the Linux kernel before 5.2.6. There is a use-after-free caused by a malicious USB device in the drivers/media/v4l2-core/v4l2-dev.c driver because drivers/media/radio/radio-raremono.c does not properly allocate memory.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-393f-2jr3-cp69

больше 4 лет назад

CHECK-fail in DrawBoundingBoxes

CVSS3: 2.5
EPSS: Низкий
github логотип

GHSA-393c-qgvj-3xph

18 дней назад

Gitea does not properly validate repository ownership when deleting Git LFS locks

EPSS: Низкий
github логотип

GHSA-393c-hwwh-9gm2

больше 3 лет назад

A use-after-free vulnerability can occur when an IndexedDB index is deleted while still in use by JavaScript code that is providing payload values to be stored. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-393c-4g2g-74rm

больше 2 лет назад

An issue was discovered in Webmin 2.021. A Cross-site Scripting (XSS) Bypass vulnerability was discovered in the file upload functionality. Normally, the application restricts the upload of certain file types such as .svg, .php, etc., and displays an error message if a prohibited file type is detected. However, by following certain steps, an attacker can bypass these restrictions and inject malicious code.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3939-pwx4-f89g

больше 3 лет назад

Unspecified vulnerability in HP Operations Agent 7.36 and 8.6 on Windows allows remote attackers to execute arbitrary code via unknown vectors.

EPSS: Низкий
github логотип

GHSA-3938-vx68-327v

больше 3 лет назад

Improper Input Validation, Cross-site Scripting (XSS) vulnerability in Web GUI of Secomea GateManager allows an attacker to execute arbitrary javascript code. This issue affects: Secomea GateManager all versions prior to 9.4.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-393v-j9q3-p63r

An Improper Check for Unusual or Exceptional Conditions vulnerability in the pfe (packet forwarding engine) of Juniper Networks Junos OS on MX Series causes a port within a pool to be blocked leading to Denial of Service (DoS). In a DS-Lite (Dual-Stack Lite) and NAT (Network Address Translation) scenario, when crafted IPv6 traffic is received and prefix-length is set to 56, the ports assigned to the user will not be freed.  Eventually, users cannot establish new connections. Affected FPC/PIC need to be manually restarted to recover. Following is the command to identify the issue:      user@host> show services nat source port-block      Host_IP                     External_IP                   Port_Block      Ports_Used/       Block_State/                                                               Range           Ports_Total       Left_Time(s)     2001::                    �...

CVSS3: 7.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-393v-ghcr-3x2m

Microsoft Bluetooth Driver in Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703 allows a spoofing vulnerability due to Microsoft's implementation of the Bluetooth stack, aka "Microsoft Bluetooth Driver Spoofing Vulnerability".

CVSS3: 6.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-393r-r9mq-g9jv

Jenkins Configuration as Code Plugin vulnerable to Exposure of Sensitive Information

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-393r-2hjv-4h5f

SpotCam Co., Ltd. SpotCam FHD 2’s hidden Telnet function has a vulnerability of using hard-coded Telnet credentials. An remote unauthenticated attacker can exploit this vulnerability to access the system to perform arbitrary system operations or disrupt service.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-393q-7g3p-mp9v

signond before 8.57+15.04.20141127.1-0ubuntu1, as used in Ubuntu Touch, did not properly restrict applications from querying oath tokens due to incorrect checks and the missing installation of the signon-apparmor-extension. An attacker could use this create a malicious click app that collects oauth tokens for other applications, exposing sensitive information.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-393q-6xw4-wfg2

Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: OBVAM Trn Journal Domain). Supported versions that are affected are 14.5, 14.6 and 14.7. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Banking Virtual Account Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Banking Virtual Account Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Banking Virtual Account Management. CVSS 3.1 Base Score 5.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/...

CVSS3: 5.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-393q-2jgx-p9ph

OrbiTeam BSCW before 5.0.8 allows remote attackers to obtain sensitive metadata via the inf operations (op=inf) to an object in pub/bscw.cgi/.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-393p-mc4h-j8g2

The Beaver Builder – WordPress Page Builder for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Caption - On Hover' value associated with images in versions up to, and including, 2.5.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with access to the Beaver Builder editor to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-393m-vg99-2x36

IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows physically proximate attackers to obtain sensitive information by reading cached data on a client device.

CVSS3: 2.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-393j-fpg3-h6c9

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Page Visit Counter Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress allows SQL Injection.This issue affects Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress: from n/a through 7.1.1.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-393j-8xcq-h729

Version 1.0.0 of the Instana Dynamic APM Docker image contains a blank password for the root user. Systems deployed using affected versions of the Instana Dynamic APM container may allow a remote attacker to achieve root access with a blank password.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-393h-j526-4h79

In NETGEAR Nighthawk X10-R900 prior to 1.0.4.26, an attacker may bypass all authentication checks on the device's "NETGEAR Genie" SOAP API ("/soap/server_sa") by supplying a malicious X-Forwarded-For header of the device's LAN IP address (192.168.1.1) in every request. As a result, an attacker may modify almost all of the device's settings and view various configuration settings.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-393g-7274-4jmv

Canon Oce Print Exec Workgroup 1.3.2 allows Host header injection.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-393f-4662-497f

An issue was discovered in the Linux kernel before 5.2.6. There is a use-after-free caused by a malicious USB device in the drivers/media/v4l2-core/v4l2-dev.c driver because drivers/media/radio/radio-raremono.c does not properly allocate memory.

CVSS3: 4.6
0%
Низкий
больше 3 лет назад
github логотип
GHSA-393f-2jr3-cp69

CHECK-fail in DrawBoundingBoxes

CVSS3: 2.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-393c-qgvj-3xph

Gitea does not properly validate repository ownership when deleting Git LFS locks

0%
Низкий
18 дней назад
github логотип
GHSA-393c-hwwh-9gm2

A use-after-free vulnerability can occur when an IndexedDB index is deleted while still in use by JavaScript code that is providing payload values to be stored. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.

CVSS3: 9.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-393c-4g2g-74rm

An issue was discovered in Webmin 2.021. A Cross-site Scripting (XSS) Bypass vulnerability was discovered in the file upload functionality. Normally, the application restricts the upload of certain file types such as .svg, .php, etc., and displays an error message if a prohibited file type is detected. However, by following certain steps, an attacker can bypass these restrictions and inject malicious code.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3939-pwx4-f89g

Unspecified vulnerability in HP Operations Agent 7.36 and 8.6 on Windows allows remote attackers to execute arbitrary code via unknown vectors.

5%
Низкий
больше 3 лет назад
github логотип
GHSA-3938-vx68-327v

Improper Input Validation, Cross-site Scripting (XSS) vulnerability in Web GUI of Secomea GateManager allows an attacker to execute arbitrary javascript code. This issue affects: Secomea GateManager all versions prior to 9.4.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу