Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-38h7-w62h-qf32

9 месяцев назад

Wavlink WL-WN530H4 20220801 was found to contain a command injection vulnerability in the ping_test function of the adm.cgi via the pingIp parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-38h7-7925-fvwv

больше 1 года назад

Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR") for Intel VT-d or Unity Mapping ranges for AMD-Vi. These are typically used for platform tasks such as legacy USB emulation. Since the precise purpose of these regions is unknown, once a device associated with such a region is active, the mappings of these regions need to remain continuouly accessible by the device. In the logic establishing these mappings, error handling was flawed, resulting in such mappings to potentially remain in place when they should have been removed again. Respective guests would then gain access to memory regions which they aren't supposed to have access to.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-38h6-xf6r-fw6f

почти 4 года назад

MediaWiki before 1.5.4 uses a hard-coded "internal placeholder string", which allows remote attackers to bypass protection against cross-site scripting (XSS) attacks and execute Javascript using inline style attributes, which are processed by Internet Explorer.

EPSS: Низкий
github логотип

GHSA-38h6-wxxg-2c7g

больше 3 лет назад

WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.

EPSS: Низкий
github логотип

GHSA-38h6-vxp4-qxvm

больше 3 лет назад

Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation. This affects net.ParseIP and net.ParseCIDR.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-38h6-gmr2-j4wx

почти 3 года назад

Silverstripe Form Capture vulnerable to stored cross-site-scripting

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-38h5-q5q6-wmqj

больше 3 лет назад

Cloudera Hue 4.6.0 allows XSS via the type parameter.

EPSS: Низкий
github логотип

GHSA-38h5-7v7x-v6pw

9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix invalid data access in ath12k_dp_rx_h_undecap_nwifi In certain cases, hardware might provide packets with a length greater than the maximum native Wi-Fi header length. This can lead to accessing and modifying fields in the header within the ath12k_dp_rx_h_undecap_nwifi function for DP_RX_DECAP_TYPE_NATIVE_WIFI decap type and potentially resulting in invalid data access and memory corruption. Add a sanity check before processing the SKB to prevent invalid data access in the undecap native Wi-Fi function for the DP_RX_DECAP_TYPE_NATIVE_WIFI decap type. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.3.1-00173-QCAHKSWPL_SILICONZ-1

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-38h4-p674-c649

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in LeadSquared, Inc LeadSquared Suite plugin <= 0.7.4 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-38h4-hmr8-8c7q

около 1 года назад

Memory corruption when IOCTL call is invoked from user-space to read board data.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-38h4-fx85-qcx7

12 месяцев назад

Exiv2 allows Use After Free

EPSS: Низкий
github логотип

GHSA-38h4-92v3-hhh5

больше 3 лет назад

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability This CVE ID is unique from CVE-2020-17005, CVE-2020-17006, CVE-2020-17018.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-38h4-4x7h-qprw

больше 3 лет назад

Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to prevent certain UI elements from being displayed by non-visible pages, which allowed a remote attacker to show certain UI elements on a page they don't control via a crafted HTML page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-38h4-3233-xrh9

больше 3 лет назад

Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier allows remote authenticated users to affect availability via vectors related to DML.

EPSS: Низкий
github логотип

GHSA-38h3-wj4x-mm5c

почти 4 года назад

unix_random.c in lshd for lsh 2.0.1 leaks file descriptors related to the randomness generator, which allows local users to cause a denial of service by truncating the seed file, which prevents the server from starting, or obtain sensitive seed information that could be used to crack keys.

EPSS: Низкий
github логотип

GHSA-38h3-jcwf-hx88

почти 3 года назад

External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in YugaByte, Inc. Yugabyte DB on Windows, Linux, MacOS, iOS (DevopsBase.Java:execCommand, TableManager.Java:runCommand modules) allows API Manipulation, Privilege Abuse. This vulnerability is associated with program files backup.Py. This issue affects Yugabyte DB: Lesser then 2.2.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-38gx-pgpj-9cw5

почти 4 года назад

Luocms v2.0 is affected by an incorrect access control vulnerability. Through /admin/templates/template_manage.php, an attacker can write an arbitrary shell file.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-38gw-wmv7-g95w

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the duwasai flashy theme 1.3 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-38gw-6g45-69p7

больше 3 лет назад

GTK+ 3.10.9 and earlier, as used in cinnamon-screensaver, gnome-screensaver, and other applications, allows physically proximate attackers to bypass the lock screen by pressing the menu button.

EPSS: Низкий
github логотип

GHSA-38gv-g72v-rp63

больше 3 лет назад

SELinux policycoreutils allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-38h7-w62h-qf32

Wavlink WL-WN530H4 20220801 was found to contain a command injection vulnerability in the ping_test function of the adm.cgi via the pingIp parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

CVSS3: 9.8
2%
Низкий
9 месяцев назад
github логотип
GHSA-38h7-7925-fvwv

Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR") for Intel VT-d or Unity Mapping ranges for AMD-Vi. These are typically used for platform tasks such as legacy USB emulation. Since the precise purpose of these regions is unknown, once a device associated with such a region is active, the mappings of these regions need to remain continuouly accessible by the device. In the logic establishing these mappings, error handling was flawed, resulting in such mappings to potentially remain in place when they should have been removed again. Respective guests would then gain access to memory regions which they aren't supposed to have access to.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-38h6-xf6r-fw6f

MediaWiki before 1.5.4 uses a hard-coded "internal placeholder string", which allows remote attackers to bypass protection against cross-site scripting (XSS) attacks and execute Javascript using inline style attributes, which are processed by Internet Explorer.

1%
Низкий
почти 4 года назад
github логотип
GHSA-38h6-wxxg-2c7g

WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-38h6-vxp4-qxvm

Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation. This affects net.ParseIP and net.ParseCIDR.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-38h6-gmr2-j4wx

Silverstripe Form Capture vulnerable to stored cross-site-scripting

CVSS3: 6.1
1%
Низкий
почти 3 года назад
github логотип
GHSA-38h5-q5q6-wmqj

Cloudera Hue 4.6.0 allows XSS via the type parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-38h5-7v7x-v6pw

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix invalid data access in ath12k_dp_rx_h_undecap_nwifi In certain cases, hardware might provide packets with a length greater than the maximum native Wi-Fi header length. This can lead to accessing and modifying fields in the header within the ath12k_dp_rx_h_undecap_nwifi function for DP_RX_DECAP_TYPE_NATIVE_WIFI decap type and potentially resulting in invalid data access and memory corruption. Add a sanity check before processing the SKB to prevent invalid data access in the undecap native Wi-Fi function for the DP_RX_DECAP_TYPE_NATIVE_WIFI decap type. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.3.1-00173-QCAHKSWPL_SILICONZ-1

CVSS3: 7.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-38h4-p674-c649

Cross-Site Request Forgery (CSRF) vulnerability in LeadSquared, Inc LeadSquared Suite plugin <= 0.7.4 versions.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-38h4-hmr8-8c7q

Memory corruption when IOCTL call is invoked from user-space to read board data.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-38h4-fx85-qcx7

Exiv2 allows Use After Free

1%
Низкий
12 месяцев назад
github логотип
GHSA-38h4-92v3-hhh5

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability This CVE ID is unique from CVE-2020-17005, CVE-2020-17006, CVE-2020-17018.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-38h4-4x7h-qprw

Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to prevent certain UI elements from being displayed by non-visible pages, which allowed a remote attacker to show certain UI elements on a page they don't control via a crafted HTML page.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-38h4-3233-xrh9

Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier allows remote authenticated users to affect availability via vectors related to DML.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-38h3-wj4x-mm5c

unix_random.c in lshd for lsh 2.0.1 leaks file descriptors related to the randomness generator, which allows local users to cause a denial of service by truncating the seed file, which prevents the server from starting, or obtain sensitive seed information that could be used to crack keys.

0%
Низкий
почти 4 года назад
github логотип
GHSA-38h3-jcwf-hx88

External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in YugaByte, Inc. Yugabyte DB on Windows, Linux, MacOS, iOS (DevopsBase.Java:execCommand, TableManager.Java:runCommand modules) allows API Manipulation, Privilege Abuse. This vulnerability is associated with program files backup.Py. This issue affects Yugabyte DB: Lesser then 2.2.

CVSS3: 9.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-38gx-pgpj-9cw5

Luocms v2.0 is affected by an incorrect access control vulnerability. Through /admin/templates/template_manage.php, an attacker can write an arbitrary shell file.

CVSS3: 9.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-38gw-wmv7-g95w

Cross-site scripting (XSS) vulnerability in the duwasai flashy theme 1.3 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-38gw-6g45-69p7

GTK+ 3.10.9 and earlier, as used in cinnamon-screensaver, gnome-screensaver, and other applications, allows physically proximate attackers to bypass the lock screen by pressing the menu button.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-38gv-g72v-rp63

SELinux policycoreutils allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу