Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-38pp-mf7x-c483

больше 1 года назад

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 HF1). Affected applications are vulnerable to command injection due to missing server side input sanitation when loading SNMP configurations. This could allow an attacker with the right to modify the SNMP configuration to execute arbitrary code with root privileges.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-38pp-gx3m-25h5

больше 3 лет назад

Stack-based buffer overflow in Microsoft Excel 2007 SP2 and SP3 and 2010 SP1; Office 2011 for Mac; Excel Viewer; and Office Compatibility Pack SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Stack Overflow Vulnerability."

EPSS: Средний
github логотип

GHSA-38pp-6gcp-rqvm

2 месяца назад

Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-38pp-34cq-8xpr

больше 3 лет назад

A race condition was addressed with improved state handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. An application may be able to gain elevated privileges.

CVSS3: 7
EPSS: Средний
github логотип

GHSA-38pm-jvpp-x7rv

больше 3 лет назад

Fretwell-Downing Informatics (FDI) OLIB7 WebView 2.5.1.1 allows remote authenticated users to obtain sensitive information from files via the infile parameter to the default URI under cgi/, as demonstrated by the (1) get_settings.ini, (2) setup.ini, and (3) text.ini files.

EPSS: Низкий
github логотип

GHSA-38pm-jr4r-8rj7

больше 3 лет назад

** DISPUTED ** TinyXML2 6.2.0 has a heap-based buffer over-read in the XMLDocument::Parse function in libtinyxml2.so. NOTE: The tinyxml2 developers have determined that the reported overflow is due to improper use of the library and not a vulnerability in tinyxml2.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-38pm-74xc-phcw

больше 3 лет назад

CSRF vulnerability in Jenkins XebiaLabs XL Deploy Plugin allows capturing credentials

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-38pj-x3w4-hmj5

4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: clk: tegra20: Fix refcount leak in tegra20_clock_init of_find_matching_node() returns a node pointer with refcount incremented, we should use of_node_put() on it when not need anymore. Add missing of_node_put() to avoid refcount leak.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-38pj-fcjm-8hcj

около 2 лет назад

An authenticated Denial-of-Service (DoS) vulnerability exists in the CLI service. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected access point.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-38pg-fhjw-6gv5

почти 4 года назад

With administrator or admin privileges the application can be tricked into overwriting files in app_data/Config folder, e.g. the systemsettings.xml file. THis is possible in SmarterTrack v100.0.8019.14010

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-38pf-r5mj-cxpx

почти 4 года назад

TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the httpRemotePort parameter.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-38pf-hw2h-2w5q

почти 4 года назад

The printf wrappers in libsafe 2.0-11 and earlier do not properly handle argument indexing specifiers, which could allow attackers to exploit certain function calls through arguments that are not verified by libsafe.

EPSS: Низкий
github логотип

GHSA-38pc-hchj-j5w7

больше 3 лет назад

Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."

EPSS: Низкий
github логотип

GHSA-38p9-xg79-q3f9

больше 3 лет назад

mq_parse_http in mongoose.c in Mongoose 6.15 has a heap-based buffer over-read.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-38p9-j94m-w67p

больше 3 лет назад

Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2023, CVE-2012-2024, CVE-2012-2025, and CVE-2012-2026.

EPSS: Средний
github логотип

GHSA-38p9-hv7m-9vv5

почти 4 года назад

** DISPUTED ** NOTE: this issue has been disputed by the upstream vendor. nasl/nasl_crypto2.c in the Nessus Attack Scripting Language library (aka libnasl) 2.2.11 does not properly check the return value from the OpenSSL DSA_do_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077. NOTE: the upstream vendor has disputed this issue, stating "while we do misuse this function (this is a bug), it has absolutely no security ramification."

EPSS: Низкий
github логотип

GHSA-38p9-56pv-pmwc

больше 3 лет назад

An elevation of privilege vulnerability exists when the Windows Delivery Optimization service improperly handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0934, CVE-2020-1009, CVE-2020-1011, CVE-2020-1015.

EPSS: Низкий
github логотип

GHSA-38p8-mxmp-83gm

около 2 месяцев назад

A vulnerability was identified in DedeCMS up to 5.7.118. This impacts an unknown function of the file /freelist_main.php. The manipulation of the argument orderby leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-38p7-f895-f9ch

больше 3 лет назад

Unrestricted file upload vulnerability in PHPStore Complete Classifieds allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a logo, then accessing it via a direct request to the file in classifieds1/yellow_images/.

EPSS: Низкий
github логотип

GHSA-38p7-5mvh-wf3m

около 1 года назад

The Guten Free Options WordPress plugin through 0.9.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-38pp-mf7x-c483

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 HF1). Affected applications are vulnerable to command injection due to missing server side input sanitation when loading SNMP configurations. This could allow an attacker with the right to modify the SNMP configuration to execute arbitrary code with root privileges.

CVSS3: 8.8
2%
Низкий
больше 1 года назад
github логотип
GHSA-38pp-gx3m-25h5

Stack-based buffer overflow in Microsoft Excel 2007 SP2 and SP3 and 2010 SP1; Office 2011 for Mac; Excel Viewer; and Office Compatibility Pack SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Stack Overflow Vulnerability."

66%
Средний
больше 3 лет назад
github логотип
GHSA-38pp-6gcp-rqvm

Cilium with misconfigured toGroups in policies can lead to unrestricted egress traffic

CVSS3: 4
0%
Низкий
2 месяца назад
github логотип
GHSA-38pp-34cq-8xpr

A race condition was addressed with improved state handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. An application may be able to gain elevated privileges.

CVSS3: 7
36%
Средний
больше 3 лет назад
github логотип
GHSA-38pm-jvpp-x7rv

Fretwell-Downing Informatics (FDI) OLIB7 WebView 2.5.1.1 allows remote authenticated users to obtain sensitive information from files via the infile parameter to the default URI under cgi/, as demonstrated by the (1) get_settings.ini, (2) setup.ini, and (3) text.ini files.

5%
Низкий
больше 3 лет назад
github логотип
GHSA-38pm-jr4r-8rj7

** DISPUTED ** TinyXML2 6.2.0 has a heap-based buffer over-read in the XMLDocument::Parse function in libtinyxml2.so. NOTE: The tinyxml2 developers have determined that the reported overflow is due to improper use of the library and not a vulnerability in tinyxml2.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-38pm-74xc-phcw

CSRF vulnerability in Jenkins XebiaLabs XL Deploy Plugin allows capturing credentials

CVSS3: 8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-38pj-x3w4-hmj5

In the Linux kernel, the following vulnerability has been resolved: clk: tegra20: Fix refcount leak in tegra20_clock_init of_find_matching_node() returns a node pointer with refcount incremented, we should use of_node_put() on it when not need anymore. Add missing of_node_put() to avoid refcount leak.

CVSS3: 5.5
0%
Низкий
4 месяца назад
github логотип
GHSA-38pj-fcjm-8hcj

An authenticated Denial-of-Service (DoS) vulnerability exists in the CLI service. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected access point.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-38pg-fhjw-6gv5

With administrator or admin privileges the application can be tricked into overwriting files in app_data/Config folder, e.g. the systemsettings.xml file. THis is possible in SmarterTrack v100.0.8019.14010

CVSS3: 7.2
1%
Низкий
почти 4 года назад
github логотип
GHSA-38pf-r5mj-cxpx

TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the httpRemotePort parameter.

CVSS3: 7.2
0%
Низкий
почти 4 года назад
github логотип
GHSA-38pf-hw2h-2w5q

The printf wrappers in libsafe 2.0-11 and earlier do not properly handle argument indexing specifiers, which could allow attackers to exploit certain function calls through arguments that are not verified by libsafe.

0%
Низкий
почти 4 года назад
github логотип
GHSA-38pc-hchj-j5w7

Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."

8%
Низкий
больше 3 лет назад
github логотип
GHSA-38p9-xg79-q3f9

mq_parse_http in mongoose.c in Mongoose 6.15 has a heap-based buffer over-read.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-38p9-j94m-w67p

Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2023, CVE-2012-2024, CVE-2012-2025, and CVE-2012-2026.

40%
Средний
больше 3 лет назад
github логотип
GHSA-38p9-hv7m-9vv5

** DISPUTED ** NOTE: this issue has been disputed by the upstream vendor. nasl/nasl_crypto2.c in the Nessus Attack Scripting Language library (aka libnasl) 2.2.11 does not properly check the return value from the OpenSSL DSA_do_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077. NOTE: the upstream vendor has disputed this issue, stating "while we do misuse this function (this is a bug), it has absolutely no security ramification."

0%
Низкий
почти 4 года назад
github логотип
GHSA-38p9-56pv-pmwc

An elevation of privilege vulnerability exists when the Windows Delivery Optimization service improperly handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0934, CVE-2020-1009, CVE-2020-1011, CVE-2020-1015.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-38p8-mxmp-83gm

A vulnerability was identified in DedeCMS up to 5.7.118. This impacts an unknown function of the file /freelist_main.php. The manipulation of the argument orderby leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

CVSS3: 6.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-38p7-f895-f9ch

Unrestricted file upload vulnerability in PHPStore Complete Classifieds allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a logo, then accessing it via a direct request to the file in classifieds1/yellow_images/.

4%
Низкий
больше 3 лет назад
github логотип
GHSA-38p7-5mvh-wf3m

The Guten Free Options WordPress plugin through 0.9.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVSS3: 6.1
0%
Низкий
около 1 года назад

Уязвимостей на страницу