Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 529

Количество 314 529

github логотип

GHSA-38h9-g2p9-689w

около 1 года назад

A vulnerability classified as critical has been found in JFinalCMS 1.0. This affects the function findPage of the file src\main\java\com\cms\entity\ContentModel.java of the component File Content Handler. The manipulation of the argument name leads to sql injection. It is possible to initiate the attack remotely.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-38h9-5963-2wq2

больше 3 лет назад

An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GPMF_Next, related to certain checks for GPMF_KEY_END and nest_level (conditional on a buffer_size_longs check).

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-38h8-x697-gh8q

около 7 лет назад

Tmp files readable by other users in sync-exec

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-38h8-4x5x-cvpr

почти 4 года назад

SQL injection vulnerability in module/down.inc.php in jportal 2.3.1 allows remote attackers to execute arbitrary SQL commands via the search field to download.php.

EPSS: Низкий
github логотип

GHSA-38h7-w62h-qf32

9 месяцев назад

Wavlink WL-WN530H4 20220801 was found to contain a command injection vulnerability in the ping_test function of the adm.cgi via the pingIp parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-38h7-7925-fvwv

больше 1 года назад

Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR") for Intel VT-d or Unity Mapping ranges for AMD-Vi. These are typically used for platform tasks such as legacy USB emulation. Since the precise purpose of these regions is unknown, once a device associated with such a region is active, the mappings of these regions need to remain continuouly accessible by the device. In the logic establishing these mappings, error handling was flawed, resulting in such mappings to potentially remain in place when they should have been removed again. Respective guests would then gain access to memory regions which they aren't supposed to have access to.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-38h6-xf6r-fw6f

почти 4 года назад

MediaWiki before 1.5.4 uses a hard-coded "internal placeholder string", which allows remote attackers to bypass protection against cross-site scripting (XSS) attacks and execute Javascript using inline style attributes, which are processed by Internet Explorer.

EPSS: Низкий
github логотип

GHSA-38h6-wxxg-2c7g

больше 3 лет назад

WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.

EPSS: Низкий
github логотип

GHSA-38h6-vxp4-qxvm

больше 3 лет назад

Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation. This affects net.ParseIP and net.ParseCIDR.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-38h6-gmr2-j4wx

почти 3 года назад

Silverstripe Form Capture vulnerable to stored cross-site-scripting

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-38h5-q5q6-wmqj

больше 3 лет назад

Cloudera Hue 4.6.0 allows XSS via the type parameter.

EPSS: Низкий
github логотип

GHSA-38h5-7v7x-v6pw

9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix invalid data access in ath12k_dp_rx_h_undecap_nwifi In certain cases, hardware might provide packets with a length greater than the maximum native Wi-Fi header length. This can lead to accessing and modifying fields in the header within the ath12k_dp_rx_h_undecap_nwifi function for DP_RX_DECAP_TYPE_NATIVE_WIFI decap type and potentially resulting in invalid data access and memory corruption. Add a sanity check before processing the SKB to prevent invalid data access in the undecap native Wi-Fi function for the DP_RX_DECAP_TYPE_NATIVE_WIFI decap type. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.3.1-00173-QCAHKSWPL_SILICONZ-1

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-38h4-p674-c649

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in LeadSquared, Inc LeadSquared Suite plugin <= 0.7.4 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-38h4-hmr8-8c7q

около 1 года назад

Memory corruption when IOCTL call is invoked from user-space to read board data.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-38h4-fx85-qcx7

12 месяцев назад

Exiv2 allows Use After Free

EPSS: Низкий
github логотип

GHSA-38h4-92v3-hhh5

больше 3 лет назад

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability This CVE ID is unique from CVE-2020-17005, CVE-2020-17006, CVE-2020-17018.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-38h4-4x7h-qprw

больше 3 лет назад

Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to prevent certain UI elements from being displayed by non-visible pages, which allowed a remote attacker to show certain UI elements on a page they don't control via a crafted HTML page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-38h4-3233-xrh9

больше 3 лет назад

Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier allows remote authenticated users to affect availability via vectors related to DML.

EPSS: Низкий
github логотип

GHSA-38h3-wj4x-mm5c

почти 4 года назад

unix_random.c in lshd for lsh 2.0.1 leaks file descriptors related to the randomness generator, which allows local users to cause a denial of service by truncating the seed file, which prevents the server from starting, or obtain sensitive seed information that could be used to crack keys.

EPSS: Низкий
github логотип

GHSA-38h3-jcwf-hx88

почти 3 года назад

External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in YugaByte, Inc. Yugabyte DB on Windows, Linux, MacOS, iOS (DevopsBase.Java:execCommand, TableManager.Java:runCommand modules) allows API Manipulation, Privilege Abuse. This vulnerability is associated with program files backup.Py. This issue affects Yugabyte DB: Lesser then 2.2.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-38h9-g2p9-689w

A vulnerability classified as critical has been found in JFinalCMS 1.0. This affects the function findPage of the file src\main\java\com\cms\entity\ContentModel.java of the component File Content Handler. The manipulation of the argument name leads to sql injection. It is possible to initiate the attack remotely.

CVSS3: 6.3
0%
Низкий
около 1 года назад
github логотип
GHSA-38h9-5963-2wq2

An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GPMF_Next, related to certain checks for GPMF_KEY_END and nest_level (conditional on a buffer_size_longs check).

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-38h8-x697-gh8q

Tmp files readable by other users in sync-exec

CVSS3: 6.5
0%
Низкий
около 7 лет назад
github логотип
GHSA-38h8-4x5x-cvpr

SQL injection vulnerability in module/down.inc.php in jportal 2.3.1 allows remote attackers to execute arbitrary SQL commands via the search field to download.php.

0%
Низкий
почти 4 года назад
github логотип
GHSA-38h7-w62h-qf32

Wavlink WL-WN530H4 20220801 was found to contain a command injection vulnerability in the ping_test function of the adm.cgi via the pingIp parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

CVSS3: 9.8
2%
Низкий
9 месяцев назад
github логотип
GHSA-38h7-7925-fvwv

Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR") for Intel VT-d or Unity Mapping ranges for AMD-Vi. These are typically used for platform tasks such as legacy USB emulation. Since the precise purpose of these regions is unknown, once a device associated with such a region is active, the mappings of these regions need to remain continuouly accessible by the device. In the logic establishing these mappings, error handling was flawed, resulting in such mappings to potentially remain in place when they should have been removed again. Respective guests would then gain access to memory regions which they aren't supposed to have access to.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-38h6-xf6r-fw6f

MediaWiki before 1.5.4 uses a hard-coded "internal placeholder string", which allows remote attackers to bypass protection against cross-site scripting (XSS) attacks and execute Javascript using inline style attributes, which are processed by Internet Explorer.

1%
Низкий
почти 4 года назад
github логотип
GHSA-38h6-wxxg-2c7g

WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-38h6-vxp4-qxvm

Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation. This affects net.ParseIP and net.ParseCIDR.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-38h6-gmr2-j4wx

Silverstripe Form Capture vulnerable to stored cross-site-scripting

CVSS3: 6.1
1%
Низкий
почти 3 года назад
github логотип
GHSA-38h5-q5q6-wmqj

Cloudera Hue 4.6.0 allows XSS via the type parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-38h5-7v7x-v6pw

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix invalid data access in ath12k_dp_rx_h_undecap_nwifi In certain cases, hardware might provide packets with a length greater than the maximum native Wi-Fi header length. This can lead to accessing and modifying fields in the header within the ath12k_dp_rx_h_undecap_nwifi function for DP_RX_DECAP_TYPE_NATIVE_WIFI decap type and potentially resulting in invalid data access and memory corruption. Add a sanity check before processing the SKB to prevent invalid data access in the undecap native Wi-Fi function for the DP_RX_DECAP_TYPE_NATIVE_WIFI decap type. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.3.1-00173-QCAHKSWPL_SILICONZ-1

CVSS3: 7.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-38h4-p674-c649

Cross-Site Request Forgery (CSRF) vulnerability in LeadSquared, Inc LeadSquared Suite plugin <= 0.7.4 versions.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-38h4-hmr8-8c7q

Memory corruption when IOCTL call is invoked from user-space to read board data.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-38h4-fx85-qcx7

Exiv2 allows Use After Free

1%
Низкий
12 месяцев назад
github логотип
GHSA-38h4-92v3-hhh5

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability This CVE ID is unique from CVE-2020-17005, CVE-2020-17006, CVE-2020-17018.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-38h4-4x7h-qprw

Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to prevent certain UI elements from being displayed by non-visible pages, which allowed a remote attacker to show certain UI elements on a page they don't control via a crafted HTML page.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-38h4-3233-xrh9

Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier allows remote authenticated users to affect availability via vectors related to DML.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-38h3-wj4x-mm5c

unix_random.c in lshd for lsh 2.0.1 leaks file descriptors related to the randomness generator, which allows local users to cause a denial of service by truncating the seed file, which prevents the server from starting, or obtain sensitive seed information that could be used to crack keys.

0%
Низкий
почти 4 года назад
github логотип
GHSA-38h3-jcwf-hx88

External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in YugaByte, Inc. Yugabyte DB on Windows, Linux, MacOS, iOS (DevopsBase.Java:execCommand, TableManager.Java:runCommand modules) allows API Manipulation, Privilege Abuse. This vulnerability is associated with program files backup.Py. This issue affects Yugabyte DB: Lesser then 2.2.

CVSS3: 9.8
0%
Низкий
почти 3 года назад

Уязвимостей на страницу