Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 315 672

Количество 315 672

github логотип

GHSA-3852-76gc-8vp3

больше 3 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

EPSS: Низкий
github логотип

GHSA-384x-vf8j-86f2

больше 3 лет назад

VMware NSX Edge 6.1 before 6.1.7 and 6.2 before 6.2.3 and vCNS Edge 5.5 before 5.5.4.3, when the SSL-VPN feature is configured, allow remote attackers to obtain sensitive information via unspecified vectors.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-384x-r4rg-wj95

больше 3 лет назад

Memory corruption in WLAN due to buffer copy without checking size of input while parsing keys in Snapdragon Connectivity, Snapdragon Mobile

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-384x-gr5v-qvwq

почти 3 года назад

A vulnerability, which was classified as critical, has been found in SourceCodester Lost and Found Information System 1.0. Affected by this issue is some unknown functionality of the file admin/?page=items/view_item of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-228980.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-384w-wffr-x63q

почти 2 года назад

Pterodactyl panel's admin area vulnerable to Cross-site Scripting

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-384w-5v3f-q499

около 5 лет назад

Base class whitelist configuration ignored in OAuthenticator

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-384v-9gx5-rmx4

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: sh: push-switch: Reorder cleanup operations to avoid use-after-free bug The original code puts flush_work() before timer_shutdown_sync() in switch_drv_remove(). Although we use flush_work() to stop the worker, it could be rescheduled in switch_timer(). As a result, a use-after-free bug can occur. The details are shown below: (cpu 0) | (cpu 1) switch_drv_remove() | flush_work() | ... | switch_timer // timer | schedule_work(&psw->work) timer_shutdown_sync() | ... | switch_work_handler // worker kfree(psw) // free | | psw->state = 0 // use This patch puts timer_shutdown_sync() before flush_work() to mitigate the bugs. As a result, the worker and timer will be stopped safely before the deallocate opera...

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-384v-5m98-7qm4

почти 4 года назад

Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, uses hard coded credentials. Access to the device's default telnet port (23) can be obtained through using one of a few default credentials shared among all devices.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-384q-wx27-r5cm

около 1 года назад

Out-of-bounds write in handling the block size for smp4vtd in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggering this vulnerability.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-384q-pv6w-p8vv

почти 4 года назад

Directory traversal vulnerability in scp for OpenSSH before 3.4p1 allows remote malicious servers to overwrite arbitrary files. NOTE: this may be a rediscovery of CVE-2000-0992.

EPSS: Низкий
github логотип

GHSA-384q-gq9c-w4g3

больше 3 лет назад

Insecure Direct Object References (IDOR) vulnerability in Spiffy Plugins Spiffy Calendar <= 4.9.0 at WordPress allows an attacker to edit or delete events.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-384q-chjj-5g2w

почти 3 года назад

Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the company parameter in the user profile update function.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-384q-8qmm-f548

больше 2 лет назад

Broadcom RAID Controller web interface is vulnerable due to usage of Libcurl with LSA has known vulnerabilities

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-384p-867v-fjvf

больше 3 лет назад

An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This issue is due to untrusted pointer dereference in the JavaScript API engine. In this scenario, the JavaScript input is crafted in way that the computation results with pointer to memory locations that do not belong to the relevant process address space. The dereferencing operation is a read operation, and an attack can result with sensitive data exposure.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-384m-rpvv-4rw6

почти 2 года назад

Denial of service condition in M-Files Server in versions before 24.2 (excluding 23.2 SR7 and 23.8 SR5) allows anonymous user to cause denial of service against other anonymous users.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-384m-hrm4-hx7q

почти 4 года назад

In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible stack corruption due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-69478941.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-384j-hgrr-qp35

больше 3 лет назад

An issue was discovered in LINBIT csync2 through 2.0. csync_daemon_session in daemon.c neglects to force a failure of a hello command when the configuration requires use of SSL.

EPSS: Низкий
github логотип

GHSA-384j-85hc-jfq2

больше 3 лет назад

An Open Redirect vulnerability in EpiServer Find before 13.2.7 allows an attacker to redirect users to untrusted websites via the _t_redirect parameter in a crafted URL, such as a /find_v2/_click URL.

EPSS: Средний
github логотип

GHSA-384j-3c7v-xh2f

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in dotProject before 2.1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) callback parameter in a color_selector action, (2) field parameter in a date_format action, or (3) company_name parameter in an addedit action to index.php. NOTE: the date parameter vector is already covered by CVE-2008-3886.

EPSS: Низкий
github логотип

GHSA-384h-9fwc-m44m

24 дня назад

Deserialization of Untrusted Data vulnerability in ThemeREX Sound | Musical Instruments Online Store musicplace allows Object Injection.This issue affects Sound | Musical Instruments Online Store: from n/a through <= 1.6.9.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3852-76gc-8vp3

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-384x-vf8j-86f2

VMware NSX Edge 6.1 before 6.1.7 and 6.2 before 6.2.3 and vCNS Edge 5.5 before 5.5.4.3, when the SSL-VPN feature is configured, allow remote attackers to obtain sensitive information via unspecified vectors.

CVSS3: 5.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-384x-r4rg-wj95

Memory corruption in WLAN due to buffer copy without checking size of input while parsing keys in Snapdragon Connectivity, Snapdragon Mobile

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-384x-gr5v-qvwq

A vulnerability, which was classified as critical, has been found in SourceCodester Lost and Found Information System 1.0. Affected by this issue is some unknown functionality of the file admin/?page=items/view_item of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-228980.

CVSS3: 6.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-384w-wffr-x63q

Pterodactyl panel's admin area vulnerable to Cross-site Scripting

CVSS3: 6.1
1%
Низкий
почти 2 года назад
github логотип
GHSA-384w-5v3f-q499

Base class whitelist configuration ignored in OAuthenticator

CVSS3: 6.3
0%
Низкий
около 5 лет назад
github логотип
GHSA-384v-9gx5-rmx4

In the Linux kernel, the following vulnerability has been resolved: sh: push-switch: Reorder cleanup operations to avoid use-after-free bug The original code puts flush_work() before timer_shutdown_sync() in switch_drv_remove(). Although we use flush_work() to stop the worker, it could be rescheduled in switch_timer(). As a result, a use-after-free bug can occur. The details are shown below: (cpu 0) | (cpu 1) switch_drv_remove() | flush_work() | ... | switch_timer // timer | schedule_work(&psw->work) timer_shutdown_sync() | ... | switch_work_handler // worker kfree(psw) // free | | psw->state = 0 // use This patch puts timer_shutdown_sync() before flush_work() to mitigate the bugs. As a result, the worker and timer will be stopped safely before the deallocate opera...

CVSS3: 8.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-384v-5m98-7qm4

Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, uses hard coded credentials. Access to the device's default telnet port (23) can be obtained through using one of a few default credentials shared among all devices.

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-384q-wx27-r5cm

Out-of-bounds write in handling the block size for smp4vtd in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggering this vulnerability.

CVSS3: 7
0%
Низкий
около 1 года назад
github логотип
GHSA-384q-pv6w-p8vv

Directory traversal vulnerability in scp for OpenSSH before 3.4p1 allows remote malicious servers to overwrite arbitrary files. NOTE: this may be a rediscovery of CVE-2000-0992.

0%
Низкий
почти 4 года назад
github логотип
GHSA-384q-gq9c-w4g3

Insecure Direct Object References (IDOR) vulnerability in Spiffy Plugins Spiffy Calendar <= 4.9.0 at WordPress allows an attacker to edit or delete events.

CVSS3: 5.4
2%
Низкий
больше 3 лет назад
github логотип
GHSA-384q-chjj-5g2w

Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the company parameter in the user profile update function.

CVSS3: 8.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-384q-8qmm-f548

Broadcom RAID Controller web interface is vulnerable due to usage of Libcurl with LSA has known vulnerabilities

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-384p-867v-fjvf

An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This issue is due to untrusted pointer dereference in the JavaScript API engine. In this scenario, the JavaScript input is crafted in way that the computation results with pointer to memory locations that do not belong to the relevant process address space. The dereferencing operation is a read operation, and an attack can result with sensitive data exposure.

CVSS3: 8.8
9%
Низкий
больше 3 лет назад
github логотип
GHSA-384m-rpvv-4rw6

Denial of service condition in M-Files Server in versions before 24.2 (excluding 23.2 SR7 and 23.8 SR5) allows anonymous user to cause denial of service against other anonymous users.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-384m-hrm4-hx7q

In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible stack corruption due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-69478941.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-384j-hgrr-qp35

An issue was discovered in LINBIT csync2 through 2.0. csync_daemon_session in daemon.c neglects to force a failure of a hello command when the configuration requires use of SSL.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-384j-85hc-jfq2

An Open Redirect vulnerability in EpiServer Find before 13.2.7 allows an attacker to redirect users to untrusted websites via the _t_redirect parameter in a crafted URL, such as a /find_v2/_click URL.

65%
Средний
больше 3 лет назад
github логотип
GHSA-384j-3c7v-xh2f

Multiple cross-site scripting (XSS) vulnerabilities in dotProject before 2.1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) callback parameter in a color_selector action, (2) field parameter in a date_format action, or (3) company_name parameter in an addedit action to index.php. NOTE: the date parameter vector is already covered by CVE-2008-3886.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-384h-9fwc-m44m

Deserialization of Untrusted Data vulnerability in ThemeREX Sound | Musical Instruments Online Store musicplace allows Object Injection.This issue affects Sound | Musical Instruments Online Store: from n/a through <= 1.6.9.

CVSS3: 9.8
0%
Низкий
24 дня назад

Уязвимостей на страницу