Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 529

Количество 314 529

github логотип

GHSA-356v-396g-55j7

больше 3 лет назад

The web console in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, and Thunderbird ESR 10.x before 10.0.7 allows user-assisted remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site that injects this code and triggers an eval operation.

EPSS: Низкий
github логотип

GHSA-356v-2cpg-fj3v

больше 3 лет назад

An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.18. Android ID: A-33899363. References: N-CVE-2017-0333.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-356r-x8g9-vh8c

больше 2 лет назад

The use of `module.constructor.createRequire()` can bypass the policy mechanism and require modules outside of the policy.json definition for a given module. This vulnerability affects all users using the experimental policy mechanism in all active release lines: 16.x, 18.x, and, 20.x. Please note that at the time this CVE was issued, the policy is an experimental feature of Node.js.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-356r-hh49-wcj9

больше 3 лет назад

In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-143604331

EPSS: Низкий
github логотип

GHSA-356r-77q8-f64f

больше 4 лет назад

Cross-Site Request Forgery in firefly-iii

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-356q-8vgj-62xf

больше 1 года назад

A vulnerability has been identified in Simcenter Nastran 2306 (All versions), Simcenter Nastran 2312 (All versions), Simcenter Nastran 2406 (All versions < V2406.5000). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted BDF files. This could allow an attacker to execute code in the context of the current process.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-356q-44f6-58cf

около 3 лет назад

In thermal_cooling_device_stats_update of thermal_sysfs.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-229258234References: N/A

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-356p-vp2q-7rg4

больше 3 лет назад

An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An attacker can get access to historical data from AprolSqlServer by bypassing authentication, a different vulnerability than CVE-2019-16358.

EPSS: Низкий
github логотип

GHSA-356p-pg27-x2cf

больше 3 лет назад

GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-356m-64j5-84f5

больше 3 лет назад

The Giveaway WordPress plugin through 1.2.2 is vulnerable to an SQL Injection issue which allows an administrative user to execute arbitrary SQL commands via the $post_id on the options.php page.

EPSS: Низкий
github логотип

GHSA-356j-hg45-x525

около 2 лет назад

Potential CSV export data leak

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-356h-vwf2-6hvf

почти 4 года назад

Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Security.

EPSS: Низкий
github логотип

GHSA-356h-vw92-46hh

больше 3 лет назад

The web interface on SerVision HVG Video Gateway devices with firmware before 2.2.26a100 has a hardcoded administrative password, which makes it easier for remote attackers to obtain access via an HTTP session.

EPSS: Низкий
github логотип

GHSA-356h-gg7j-mwv3

больше 3 лет назад

An issue was discovered in amqp_handle_input in amqp_connection.c in rabbitmq-c 0.9.0. There is an integer overflow that leads to heap memory corruption in the handling of CONNECTION_STATE_HEADER. A rogue server could return a malicious frame header that leads to a smaller target_size value than needed. This condition is then carried on to a memcpy function that copies too much data into a heap buffer.

EPSS: Низкий
github логотип

GHSA-356h-6p87-pgw2

больше 1 года назад

Windows Network Virtualization Remote Code Execution Vulnerability

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-356h-69fm-h3qg

почти 4 года назад

SQL injection vulnerability in index.php in Arctic Issue Tracker 2.1.1 allows remote attackers to execute arbitrary SQL commands via the (1) matchings[id] or (2) matchings[title] parameters in a Login action to an unspecified program, or (3) the matchings[id] parameter in a search action to index.php, a different vector than CVE-2008-3250. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-356g-gwg5-3vmc

около 3 лет назад

A buffer overflow vulnerability in the library of the web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an unauthenticated attacker to execute some OS commands or to cause denial-of-service (DoS) conditions on a vulnerable device.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-356g-gr7f-c28h

больше 2 лет назад

Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-356g-c3c7-vfjp

больше 3 лет назад

The Wedding Photo Frames-Love Pics (aka com.WeddingPhotoFramesLovePics) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-356g-7x36-7m34

больше 1 года назад

Moodle CSRF risks due to misuse of confirm_sesskey

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-356v-396g-55j7

The web console in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, and Thunderbird ESR 10.x before 10.0.7 allows user-assisted remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site that injects this code and triggers an eval operation.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-356v-2cpg-fj3v

An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.18. Android ID: A-33899363. References: N-CVE-2017-0333.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-356r-x8g9-vh8c

The use of `module.constructor.createRequire()` can bypass the policy mechanism and require modules outside of the policy.json definition for a given module. This vulnerability affects all users using the experimental policy mechanism in all active release lines: 16.x, 18.x, and, 20.x. Please note that at the time this CVE was issued, the policy is an experimental feature of Node.js.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-356r-hh49-wcj9

In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-143604331

1%
Низкий
больше 3 лет назад
github логотип
GHSA-356r-77q8-f64f

Cross-Site Request Forgery in firefly-iii

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
github логотип
GHSA-356q-8vgj-62xf

A vulnerability has been identified in Simcenter Nastran 2306 (All versions), Simcenter Nastran 2312 (All versions), Simcenter Nastran 2406 (All versions < V2406.5000). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted BDF files. This could allow an attacker to execute code in the context of the current process.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-356q-44f6-58cf

In thermal_cooling_device_stats_update of thermal_sysfs.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-229258234References: N/A

CVSS3: 6.7
0%
Низкий
около 3 лет назад
github логотип
GHSA-356p-vp2q-7rg4

An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An attacker can get access to historical data from AprolSqlServer by bypassing authentication, a different vulnerability than CVE-2019-16358.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-356p-pg27-x2cf

GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.

CVSS3: 6.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-356m-64j5-84f5

The Giveaway WordPress plugin through 1.2.2 is vulnerable to an SQL Injection issue which allows an administrative user to execute arbitrary SQL commands via the $post_id on the options.php page.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-356j-hg45-x525

Potential CSV export data leak

CVSS3: 8.4
1%
Низкий
около 2 лет назад
github логотип
GHSA-356h-vwf2-6hvf

Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Security.

2%
Низкий
почти 4 года назад
github логотип
GHSA-356h-vw92-46hh

The web interface on SerVision HVG Video Gateway devices with firmware before 2.2.26a100 has a hardcoded administrative password, which makes it easier for remote attackers to obtain access via an HTTP session.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-356h-gg7j-mwv3

An issue was discovered in amqp_handle_input in amqp_connection.c in rabbitmq-c 0.9.0. There is an integer overflow that leads to heap memory corruption in the handling of CONNECTION_STATE_HEADER. A rogue server could return a malicious frame header that leads to a smaller target_size value than needed. This condition is then carried on to a memcpy function that copies too much data into a heap buffer.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-356h-6p87-pgw2

Windows Network Virtualization Remote Code Execution Vulnerability

CVSS3: 9.1
3%
Низкий
больше 1 года назад
github логотип
GHSA-356h-69fm-h3qg

SQL injection vulnerability in index.php in Arctic Issue Tracker 2.1.1 allows remote attackers to execute arbitrary SQL commands via the (1) matchings[id] or (2) matchings[title] parameters in a Login action to an unspecified program, or (3) the matchings[id] parameter in a search action to index.php, a different vector than CVE-2008-3250. NOTE: some of these details are obtained from third party information.

0%
Низкий
почти 4 года назад
github логотип
GHSA-356g-gwg5-3vmc

A buffer overflow vulnerability in the library of the web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an unauthenticated attacker to execute some OS commands or to cause denial-of-service (DoS) conditions on a vulnerable device.

CVSS3: 9.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-356g-gr7f-c28h

Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS3: 8.2
0%
Низкий
больше 2 лет назад
github логотип
GHSA-356g-c3c7-vfjp

The Wedding Photo Frames-Love Pics (aka com.WeddingPhotoFramesLovePics) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-356g-7x36-7m34

Moodle CSRF risks due to misuse of confirm_sesskey

CVSS3: 5.4
0%
Низкий
больше 1 года назад

Уязвимостей на страницу