Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 928

Количество 314 928

github логотип

GHSA-365p-96qv-xr7g

больше 7 лет назад

ASP.NET Core allow an elevation of privilege

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-365m-rf96-qxh8

почти 4 года назад

Directory traversal vulnerability in Adobe Flash Media Server (FMS) before 3.5.3 allows attackers to load arbitrary DLL files via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-365m-qv8p-499g

почти 4 года назад

Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 9.0.4.3 and 10.1.2.3 allows remote attackers to affect integrity via unknown vectors, a different vulnerability than CVE-2008-3975.

EPSS: Низкий
github логотип

GHSA-365m-6cxm-68v4

около 1 года назад

lunasvg v3.0.1 was discovered to contain a segmentation violation via the component gray_find_cell

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-365m-3gwm-q93h

около 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Aleksandar Urošević My YouTube Channel plugin <= 3.23.3 versions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-365h-hvh8-45g8

больше 3 лет назад

A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Routing Protocol Daemon (rpd) of Juniper Networks Junos OS, Junos OS Evolved allows a network-based unauthenticated attacker to cause a Denial of Service (DoS). When a BGP flow route with redirect IP extended community is received, and the reachability to the next-hop of the corresponding redirect IP is flapping, the rpd process might crash. Whether the crash occurs depends on the timing of the internally processing of these two events and is outside the attackers control. Please note that this issue also affects Route-Reflectors unless 'routing-options flow firewall-install-disable' is configured. This issue affects: Juniper Networks Junos OS: 18.4 versions prior to 18.4R2-S10, 18.4R3-S10; 19.1 versions prior to 19.1R3-S7; 19.2 versions prior to 19.2R1-S8, 19.2R3-S4; 19.4 versions prior to 19.4R3-S8; 20.2 versions prior to 20.2R3-S3; 20.3 versions prior to 20.3R3-S2; 20.4 versions prior to 20.4R3; 21.1 versions pr...

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-365g-vjw2-grx8

4 месяца назад

n8n: Execute Command Node Allows Authenticated Users to Run Arbitrary Commands on Host

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-365f-6rq6-q4j4

почти 4 года назад

Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1286, CVE-2010-1287, CVE-2010-1289, CVE-2010-1290, and CVE-2010-1291.

EPSS: Низкий
github логотип

GHSA-3659-qppf-7pgh

больше 3 лет назад

The kernel in Apple iOS before 9.1 allows attackers to cause a denial of service via a crafted app.

EPSS: Низкий
github логотип

GHSA-3659-jjmv-v338

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: drm/bridge: sii902x: Fix probing race issue A null pointer dereference crash has been observed rarely on TI platforms using sii9022 bridge: [ 53.271356] sii902x_get_edid+0x34/0x70 [sii902x] [ 53.276066] sii902x_bridge_get_edid+0x14/0x20 [sii902x] [ 53.281381] drm_bridge_get_edid+0x20/0x34 [drm] [ 53.286305] drm_bridge_connector_get_modes+0x8c/0xcc [drm_kms_helper] [ 53.292955] drm_helper_probe_single_connector_modes+0x190/0x538 [drm_kms_helper] [ 53.300510] drm_client_modeset_probe+0x1f0/0xbd4 [drm] [ 53.305958] __drm_fb_helper_initial_config_and_unlock+0x50/0x510 [drm_kms_helper] [ 53.313611] drm_fb_helper_initial_config+0x48/0x58 [drm_kms_helper] [ 53.320039] drm_fbdev_dma_client_hotplug+0x84/0xd4 [drm_dma_helper] [ 53.326401] drm_client_register+0x5c/0xa0 [drm] [ 53.331216] drm_fbdev_dma_setup+0xc8/0x13c [drm_dma_helper] [ 53.336881] tidss_probe+0x128/0x264 [tidss] [ 53.34...

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-3659-9xv5-5669

около 1 года назад

The Import Eventbrite Events plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.7.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3657-w454-hxhx

почти 4 года назад

Cross-site scripting (XSS) vulnerability in esp/editUser.esp in the Palo Alto Networks firewall 3.0.x before 3.0.9 and 3.1.x before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the role parameter.

EPSS: Низкий
github логотип

GHSA-3657-q433-mmpx

больше 3 лет назад

Canvs Canvas Cross-site Scripting (XSS) via title and content fields

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3657-fjf8-53fm

больше 3 лет назад

Heap buffer overflow in History in Google Chrome prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

EPSS: Низкий
github логотип

GHSA-3656-jvhv-q239

больше 3 лет назад

SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_BlitCopy in video/SDL_blit_copy.c via a crafted .BMP file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3656-hc57-pfv2

почти 2 года назад

Windows DNS Server Remote Code Execution Vulnerability

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3655-xq3q-xq2p

почти 4 года назад

Format string vulnerability in Apple iPhoto 6.0.5 (316), and other versions before 6.0.6, allows remote user-assisted attackers to execute arbitrary code via a crafted photocast with format string specifiers in the title of an RSS iPhoto feed.

EPSS: Средний
github логотип

GHSA-3654-wj8m-9hfq

около 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in OceanWP Ocean Extra.This issue affects Ocean Extra: from n/a through 2.2.2.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3654-94f7-vj6m

больше 3 лет назад

Improper access control in Intel(R) Graphics Drivers before version 26.20.100.6912 may allow an authenticated user to potentially enable escalation of privilege via local access.

EPSS: Низкий
github логотип

GHSA-3654-92rm-xcmh

больше 3 лет назад

In RegisterNotificationResponse::GetEvent of register_notification_packet.cc, there is a possible abort due to improper input validation. This could lead to remote denial of service of the Bluetooth service, over Bluetooth, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-144066833

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-365p-96qv-xr7g

ASP.NET Core allow an elevation of privilege

CVSS3: 8.8
17%
Средний
больше 7 лет назад
github логотип
GHSA-365m-rf96-qxh8

Directory traversal vulnerability in Adobe Flash Media Server (FMS) before 3.5.3 allows attackers to load arbitrary DLL files via unspecified vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-365m-qv8p-499g

Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 9.0.4.3 and 10.1.2.3 allows remote attackers to affect integrity via unknown vectors, a different vulnerability than CVE-2008-3975.

0%
Низкий
почти 4 года назад
github логотип
GHSA-365m-6cxm-68v4

lunasvg v3.0.1 was discovered to contain a segmentation violation via the component gray_find_cell

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-365m-3gwm-q93h

Cross-Site Request Forgery (CSRF) vulnerability in Aleksandar Urošević My YouTube Channel plugin <= 3.23.3 versions.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-365h-hvh8-45g8

A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Routing Protocol Daemon (rpd) of Juniper Networks Junos OS, Junos OS Evolved allows a network-based unauthenticated attacker to cause a Denial of Service (DoS). When a BGP flow route with redirect IP extended community is received, and the reachability to the next-hop of the corresponding redirect IP is flapping, the rpd process might crash. Whether the crash occurs depends on the timing of the internally processing of these two events and is outside the attackers control. Please note that this issue also affects Route-Reflectors unless 'routing-options flow firewall-install-disable' is configured. This issue affects: Juniper Networks Junos OS: 18.4 versions prior to 18.4R2-S10, 18.4R3-S10; 19.1 versions prior to 19.1R3-S7; 19.2 versions prior to 19.2R1-S8, 19.2R3-S4; 19.4 versions prior to 19.4R3-S8; 20.2 versions prior to 20.2R3-S3; 20.3 versions prior to 20.3R3-S2; 20.4 versions prior to 20.4R3; 21.1 versions pr...

CVSS3: 5.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-365g-vjw2-grx8

n8n: Execute Command Node Allows Authenticated Users to Run Arbitrary Commands on Host

CVSS3: 8.8
4 месяца назад
github логотип
GHSA-365f-6rq6-q4j4

Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1286, CVE-2010-1287, CVE-2010-1289, CVE-2010-1290, and CVE-2010-1291.

3%
Низкий
почти 4 года назад
github логотип
GHSA-3659-qppf-7pgh

The kernel in Apple iOS before 9.1 allows attackers to cause a denial of service via a crafted app.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3659-jjmv-v338

In the Linux kernel, the following vulnerability has been resolved: drm/bridge: sii902x: Fix probing race issue A null pointer dereference crash has been observed rarely on TI platforms using sii9022 bridge: [ 53.271356] sii902x_get_edid+0x34/0x70 [sii902x] [ 53.276066] sii902x_bridge_get_edid+0x14/0x20 [sii902x] [ 53.281381] drm_bridge_get_edid+0x20/0x34 [drm] [ 53.286305] drm_bridge_connector_get_modes+0x8c/0xcc [drm_kms_helper] [ 53.292955] drm_helper_probe_single_connector_modes+0x190/0x538 [drm_kms_helper] [ 53.300510] drm_client_modeset_probe+0x1f0/0xbd4 [drm] [ 53.305958] __drm_fb_helper_initial_config_and_unlock+0x50/0x510 [drm_kms_helper] [ 53.313611] drm_fb_helper_initial_config+0x48/0x58 [drm_kms_helper] [ 53.320039] drm_fbdev_dma_client_hotplug+0x84/0xd4 [drm_dma_helper] [ 53.326401] drm_client_register+0x5c/0xa0 [drm] [ 53.331216] drm_fbdev_dma_setup+0xc8/0x13c [drm_dma_helper] [ 53.336881] tidss_probe+0x128/0x264 [tidss] [ 53.34...

CVSS3: 4.7
0%
Низкий
почти 2 года назад
github логотип
GHSA-3659-9xv5-5669

The Import Eventbrite Events plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.7.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
1%
Низкий
около 1 года назад
github логотип
GHSA-3657-w454-hxhx

Cross-site scripting (XSS) vulnerability in esp/editUser.esp in the Palo Alto Networks firewall 3.0.x before 3.0.9 and 3.1.x before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the role parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-3657-q433-mmpx

Canvs Canvas Cross-site Scripting (XSS) via title and content fields

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3657-fjf8-53fm

Heap buffer overflow in History in Google Chrome prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3656-jvhv-q239

SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_BlitCopy in video/SDL_blit_copy.c via a crafted .BMP file.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3656-hc57-pfv2

Windows DNS Server Remote Code Execution Vulnerability

CVSS3: 7.2
4%
Низкий
почти 2 года назад
github логотип
GHSA-3655-xq3q-xq2p

Format string vulnerability in Apple iPhoto 6.0.5 (316), and other versions before 6.0.6, allows remote user-assisted attackers to execute arbitrary code via a crafted photocast with format string specifiers in the title of an RSS iPhoto feed.

35%
Средний
почти 4 года назад
github логотип
GHSA-3654-wj8m-9hfq

Cross-Site Request Forgery (CSRF) vulnerability in OceanWP Ocean Extra.This issue affects Ocean Extra: from n/a through 2.2.2.

CVSS3: 5.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-3654-94f7-vj6m

Improper access control in Intel(R) Graphics Drivers before version 26.20.100.6912 may allow an authenticated user to potentially enable escalation of privilege via local access.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3654-92rm-xcmh

In RegisterNotificationResponse::GetEvent of register_notification_packet.cc, there is a possible abort due to improper input validation. This could lead to remote denial of service of the Bluetooth service, over Bluetooth, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-144066833

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу