Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-38mm-6p5m-rh38

больше 1 года назад

A file dialog shown while in full-screen mode could have resulted in the window remaining disabled. This vulnerability affects Firefox < 126.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-38mm-4j73-pxpp

больше 3 лет назад

SWFTools 2013-04-09-1007 on Windows has a "Data from Faulting Address controls Branch Selection starting at image00000000_00400000+0x0000000000003e71" issue. This issue can be triggered by a malformed TTF file that is mishandled by font2swf. Attackers could exploit this issue for DoS (Access Violation).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-38mm-37q5-m94p

около 2 месяцев назад

Missing Authorization vulnerability in netopsae Accessibility by AudioEye accessibility-by-audioeye allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accessibility by AudioEye: from n/a through <= 1.0.49.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-38mm-2gr2-2gvf

больше 3 лет назад

Heap-based buffer overflow in SAP Network Interface Router (SAProuter) 7.30 allows remote attackers to cause a denial of service and execute arbitrary code via crafted NI Route messages.

EPSS: Низкий
github логотип

GHSA-38mj-2rw7-pf37

больше 3 лет назад

The mintToken function of a smart contract implementation for ECToints (ECT) (Contract Name: ECPoints), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-38mh-mg22-vw9h

больше 3 лет назад

Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more than 256 attached devices, allows local users to gain privileges via a small transfer buffer in a REPORT LUNS command.

EPSS: Низкий
github логотип

GHSA-38mh-jrc4-gqqf

больше 2 лет назад

An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to gain access to already freed memory. This affects Midgard r29p0 through r32p0, Bifrost r17p0 through r42p0 before r43p0, Valhall r19p0 through r42p0 before r43p0, and Arm's GPU Architecture Gen5 r41p0 through r42p0 before r43p0.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-38mh-jhrf-5454

больше 3 лет назад

SANtricity OS Controller Software versions 11.50.1 and higher are susceptible to a vulnerability which could allow an attacker to discover sensitive information by intercepting its transmission within an https session.

EPSS: Низкий
github логотип

GHSA-38mg-wm59-g64x

11 месяцев назад

composio allows Server-Side Request Forgery (SSRF) in BROWSERTOOL

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-38mg-mw32-j4p4

2 месяца назад

A vulnerability has been identified in Gridscale X Prepay (All versions < V4.2.1). The affected application is vulnerable to user enumeration due to distinguishable responses. This could allow an unauthenticated remote attacker to determine if a user is valid or not, enabling a brute force attack with valid users.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-38mc-wg4f-vp95

больше 3 лет назад

There exists a heap-based buffer overflow in vc1_decode_i_block_adv in vc1_block.c in Libav 12.3, which allows attackers to cause a denial-of-service via a crafted aac file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-38mc-jpfh-xh7r

почти 4 года назад

The cpoint.sys driver in Panda Internet Security 2008 and Antivirus+ Firewall 2008 allows local users to cause a denial of service (system crash or kernel panic), overwrite memory, or execute arbitrary code via a crafted IOCTL request that triggers an out-of-bounds write of kernel memory.

EPSS: Низкий
github логотип

GHSA-38m9-3vg4-rwvp

почти 4 года назад

Cross-site Scripting in microweber

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-38m8-5gfc-663g

почти 2 года назад

Enhavo Cross-site Scripting vulnerability

EPSS: Низкий
github логотип

GHSA-38m8-39f8-gq75

19 дней назад

A memory leak in Node.js’s OpenSSL integration occurs when converting `X.509` certificate fields to UTF-8 without freeing the allocated buffer. When applications call `socket.getPeerCertificate(true)`, each certificate field leaks memory, allowing remote clients to trigger steady memory growth through repeated TLS connections. Over time this can lead to resource exhaustion and denial of service.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-38m7-p7j8-c694

больше 3 лет назад

ModSecurity before 2.6.6, when used with PHP, does not properly handle single quotes not at the beginning of a request parameter value in the Content-Disposition field of a request with a multipart/form-data Content-Type header, which allows remote attackers to bypass filtering rules and perform other attacks such as cross-site scripting (XSS) attacks. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-5031.

EPSS: Низкий
github логотип

GHSA-38m7-p48j-3jpx

почти 4 года назад

Unspecified vulnerability in Cisco IOS 12.2XNA, 12.2XNB, 12.2XNC, 12.2XND, 12.4MD, 12.4T, 12.4XZ, and 12.4YA allows remote attackers to cause a denial of service (device reload) via a crafted NTPv4 packet, aka Bug IDs CSCsu24505 and CSCsv75948.

EPSS: Низкий
github логотип

GHSA-38m7-jq7p-vr4x

больше 3 лет назад

Possible buffer over read due to improper validation of frame length while processing AEAD decryption during ASSOC response in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music

EPSS: Низкий
github логотип

GHSA-38m7-9jcp-3w2c

больше 3 лет назад

On versions 15.0.0-15.0.1, 14.0.0-14.1.2.2, and 13.1.0-13.1.3.1, TMM may restart on BIG-IP Virtual Edition (VE) when using virtio direct descriptors and packets 2 KB or larger.

EPSS: Низкий
github логотип

GHSA-38m7-95rg-7m84

больше 1 года назад

Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass in limited scenarios.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.0.2.

CVSS3: 7.4
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-38mm-6p5m-rh38

A file dialog shown while in full-screen mode could have resulted in the window remaining disabled. This vulnerability affects Firefox < 126.

CVSS3: 8.2
1%
Низкий
больше 1 года назад
github логотип
GHSA-38mm-4j73-pxpp

SWFTools 2013-04-09-1007 on Windows has a "Data from Faulting Address controls Branch Selection starting at image00000000_00400000+0x0000000000003e71" issue. This issue can be triggered by a malformed TTF file that is mishandled by font2swf. Attackers could exploit this issue for DoS (Access Violation).

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-38mm-37q5-m94p

Missing Authorization vulnerability in netopsae Accessibility by AudioEye accessibility-by-audioeye allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accessibility by AudioEye: from n/a through <= 1.0.49.

CVSS3: 4.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-38mm-2gr2-2gvf

Heap-based buffer overflow in SAP Network Interface Router (SAProuter) 7.30 allows remote attackers to cause a denial of service and execute arbitrary code via crafted NI Route messages.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-38mj-2rw7-pf37

The mintToken function of a smart contract implementation for ECToints (ECT) (Contract Name: ECPoints), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-38mh-mg22-vw9h

Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more than 256 attached devices, allows local users to gain privileges via a small transfer buffer in a REPORT LUNS command.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-38mh-jrc4-gqqf

An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to gain access to already freed memory. This affects Midgard r29p0 through r32p0, Bifrost r17p0 through r42p0 before r43p0, Valhall r19p0 through r42p0 before r43p0, and Arm's GPU Architecture Gen5 r41p0 through r42p0 before r43p0.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-38mh-jhrf-5454

SANtricity OS Controller Software versions 11.50.1 and higher are susceptible to a vulnerability which could allow an attacker to discover sensitive information by intercepting its transmission within an https session.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-38mg-wm59-g64x

composio allows Server-Side Request Forgery (SSRF) in BROWSERTOOL

CVSS3: 6.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-38mg-mw32-j4p4

A vulnerability has been identified in Gridscale X Prepay (All versions < V4.2.1). The affected application is vulnerable to user enumeration due to distinguishable responses. This could allow an unauthenticated remote attacker to determine if a user is valid or not, enabling a brute force attack with valid users.

CVSS3: 5.3
0%
Низкий
2 месяца назад
github логотип
GHSA-38mc-wg4f-vp95

There exists a heap-based buffer overflow in vc1_decode_i_block_adv in vc1_block.c in Libav 12.3, which allows attackers to cause a denial-of-service via a crafted aac file.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-38mc-jpfh-xh7r

The cpoint.sys driver in Panda Internet Security 2008 and Antivirus+ Firewall 2008 allows local users to cause a denial of service (system crash or kernel panic), overwrite memory, or execute arbitrary code via a crafted IOCTL request that triggers an out-of-bounds write of kernel memory.

0%
Низкий
почти 4 года назад
github логотип
GHSA-38m9-3vg4-rwvp

Cross-site Scripting in microweber

CVSS3: 6.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-38m8-5gfc-663g

Enhavo Cross-site Scripting vulnerability

0%
Низкий
почти 2 года назад
github логотип
GHSA-38m8-39f8-gq75

A memory leak in Node.js’s OpenSSL integration occurs when converting `X.509` certificate fields to UTF-8 without freeing the allocated buffer. When applications call `socket.getPeerCertificate(true)`, each certificate field leaks memory, allowing remote clients to trigger steady memory growth through repeated TLS connections. Over time this can lead to resource exhaustion and denial of service.

CVSS3: 6.5
0%
Низкий
19 дней назад
github логотип
GHSA-38m7-p7j8-c694

ModSecurity before 2.6.6, when used with PHP, does not properly handle single quotes not at the beginning of a request parameter value in the Content-Disposition field of a request with a multipart/form-data Content-Type header, which allows remote attackers to bypass filtering rules and perform other attacks such as cross-site scripting (XSS) attacks. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-5031.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-38m7-p48j-3jpx

Unspecified vulnerability in Cisco IOS 12.2XNA, 12.2XNB, 12.2XNC, 12.2XND, 12.4MD, 12.4T, 12.4XZ, and 12.4YA allows remote attackers to cause a denial of service (device reload) via a crafted NTPv4 packet, aka Bug IDs CSCsu24505 and CSCsv75948.

2%
Низкий
почти 4 года назад
github логотип
GHSA-38m7-jq7p-vr4x

Possible buffer over read due to improper validation of frame length while processing AEAD decryption during ASSOC response in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music

0%
Низкий
больше 3 лет назад
github логотип
GHSA-38m7-9jcp-3w2c

On versions 15.0.0-15.0.1, 14.0.0-14.1.2.2, and 13.1.0-13.1.3.1, TMM may restart on BIG-IP Virtual Edition (VE) when using virtio direct descriptors and packets 2 KB or larger.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-38m7-95rg-7m84

Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass in limited scenarios.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.0.2.

CVSS3: 7.4
90%
Высокий
больше 1 года назад

Уязвимостей на страницу