Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-352x-3qr9-4hfp

больше 3 лет назад

In all Qualcomm products with Android releases from CAF using the Linux kernel, when an access point sends a challenge text greater than 128 bytes, the host driver is unable to validate this potentially leading to authentication failure.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-352v-hhmh-2w8h

больше 2 лет назад

Jenkins Code Dx Plugin displays API keys in plain text

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-352r-wjp6-2638

почти 4 года назад

Unspecified vulnerability in Microsoft Internet Explorer 7 on Windows XP SP2, Windows Server 2003 SP1 or SP2, or Windows Vista allows remote attackers to execute arbitrary code via crafted HTML objects, which results in memory corruption, aka the first of two "HTML Objects Memory Corruption Vulnerabilities" and a different issue than CVE-2007-0947.

EPSS: Средний
github логотип

GHSA-352r-pm46-cmhx

больше 3 лет назад

An issue was discovered in LibSass through 3.5.4. A NULL pointer dereference was found in the function Sass::Functions::selector_append which could be leveraged by an attacker to cause a denial of service (application crash) or possibly have unspecified other impact.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-352r-9xwj-2fm8

больше 3 лет назад

Use-after-free vulnerability in Google Chrome before 28.0.1500.71 allows remote servers to execute arbitrary code via crafted response traffic after a URL request.

EPSS: Низкий
github логотип

GHSA-352q-p9ch-9v33

почти 4 года назад

Windows DNS Server Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-24536, CVE-2022-26811, CVE-2022-26812, CVE-2022-26813, CVE-2022-26814, CVE-2022-26815, CVE-2022-26817, CVE-2022-26819, CVE-2022-26820, CVE-2022-26821, CVE-2022-26822, CVE-2022-26823, CVE-2022-26824, CVE-2022-26825, CVE-2022-26826, CVE-2022-26829.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-352q-cw7r-wrj8

почти 4 года назад

** DISPUTED ** ecjia-daojia 1.38.1-20210202629 is vulnerable to information leakage via content/apps/installer/classes/Helper.php. When the web program is installed, a new environment file is created, and the database information is recorded, including the database record password. NOTE: the vendor disputes this because the environment file is in the data directory, which is not intended for access by website visitors (only the statics directory can be accessed by website visitors).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-352p-rhvq-7g78

больше 4 лет назад

Null pointer deference in av-data

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-352p-7m4h-f756

почти 4 года назад

Directory traversal vulnerability in myhtml.php in Mobilelib GOLD 3.0, when magic_quotes_gpc is enabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the GLOBALS[page] parameter.

EPSS: Низкий
github логотип

GHSA-352p-6fhx-xmph

больше 3 лет назад

tPanel 2009 allows SQL injection for Authentication Bypass via 'or 1=1 or ''=' to login.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-352m-3444-89q4

больше 3 лет назад

A Denial of Service (DOS) issue was discovered in ControlByWeb X-320M-I Web-Enabled Instrumentation-Grade Data Acquisition module 1.05 with firmware revision v1.05. An authenticated user can configure invalid network settings, stopping TCP based communications to the device. A physical factory reset is required to restore the device to an operational state.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-352j-rqv2-cp9f

больше 3 лет назад

phpLDAPadmin 1.2.2 allows LDAP injection via a crafted server_id parameter in a cmd.php?cmd=login_form request, or a crafted username and password in the login panel.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-352j-376q-2pmc

9 месяцев назад

This High severity PrivEsc (Privilege Escalation) vulnerability was introduced in versions: 9.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Core Data Center and Server 5.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Service Management Data Center and Server This PrivEsc (Privilege Escalation) vulnerability, with a CVSS Score of 7.2, allows an attacker to perform actions as a higher-privileged user. Atlassian recommends that Jira Core Data Center and Server and Jira Service Management Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Jira Core Data Center and Server 9.12: Upgrade to a release greater than or equal to 9.12.20 Jira Service Management Data Center and Server 5.12: Upgrade to a release greater than or equal to 5.12.20 Jira Core Data Center 10.3: Upgrade to a release greater than or equal to 10.3.5 Jira Service Management Data Center 10.3: Upgrade to a release great...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-352j-2x5m-wf94

больше 3 лет назад

HOME SPOT CUBE2 V102 contains an OS command injection vulnerability due to improper processing of data received from DHCP server. An adjacent attacker may execute an arbitrary OS command on the product if a malicious DHCP server is placed on the WAN side of the product.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-352h-846h-f54v

больше 1 года назад

The Team+ from TEAMPLUS TECHNOLOGY does not properly validate specific page parameter, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify and delete database contents.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-352f-rwjm-p38m

больше 1 года назад

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Reports for iOS 11.0.0.7 could allow a local attacker to obtain sensitive information in the form of an API key. An attacker could use this information to launch further attacks against affected applications.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-352f-q892-q47q

больше 3 лет назад

A stored Reflected Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.0 up to 14.3.1 allowed an attacker to execute arbitrary javascript code.

EPSS: Низкий
github логотип

GHSA-352f-p7c4-xq3r

больше 3 лет назад

ownCloud Server before 6.0.1 does not properly check permissions, which allows remote authenticated users to access arbitrary preview pictures via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-352f-c86f-rrhx

12 месяцев назад

Microsoft PC Manager Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-352f-66f5-76w2

больше 3 лет назад

OpenJPEG before 2.3.1 has a heap buffer overflow in color_apply_icc_profile in bin/common/color.c.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-352x-3qr9-4hfp

In all Qualcomm products with Android releases from CAF using the Linux kernel, when an access point sends a challenge text greater than 128 bytes, the host driver is unable to validate this potentially leading to authentication failure.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-352v-hhmh-2w8h

Jenkins Code Dx Plugin displays API keys in plain text

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-352r-wjp6-2638

Unspecified vulnerability in Microsoft Internet Explorer 7 on Windows XP SP2, Windows Server 2003 SP1 or SP2, or Windows Vista allows remote attackers to execute arbitrary code via crafted HTML objects, which results in memory corruption, aka the first of two "HTML Objects Memory Corruption Vulnerabilities" and a different issue than CVE-2007-0947.

59%
Средний
почти 4 года назад
github логотип
GHSA-352r-pm46-cmhx

An issue was discovered in LibSass through 3.5.4. A NULL pointer dereference was found in the function Sass::Functions::selector_append which could be leveraged by an attacker to cause a denial of service (application crash) or possibly have unspecified other impact.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-352r-9xwj-2fm8

Use-after-free vulnerability in Google Chrome before 28.0.1500.71 allows remote servers to execute arbitrary code via crafted response traffic after a URL request.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-352q-p9ch-9v33

Windows DNS Server Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-24536, CVE-2022-26811, CVE-2022-26812, CVE-2022-26813, CVE-2022-26814, CVE-2022-26815, CVE-2022-26817, CVE-2022-26819, CVE-2022-26820, CVE-2022-26821, CVE-2022-26822, CVE-2022-26823, CVE-2022-26824, CVE-2022-26825, CVE-2022-26826, CVE-2022-26829.

CVSS3: 6.6
3%
Низкий
почти 4 года назад
github логотип
GHSA-352q-cw7r-wrj8

** DISPUTED ** ecjia-daojia 1.38.1-20210202629 is vulnerable to information leakage via content/apps/installer/classes/Helper.php. When the web program is installed, a new environment file is created, and the database information is recorded, including the database record password. NOTE: the vendor disputes this because the environment file is in the data directory, which is not intended for access by website visitors (only the statics directory can be accessed by website visitors).

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-352p-rhvq-7g78

Null pointer deference in av-data

CVSS3: 7.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-352p-7m4h-f756

Directory traversal vulnerability in myhtml.php in Mobilelib GOLD 3.0, when magic_quotes_gpc is enabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the GLOBALS[page] parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-352p-6fhx-xmph

tPanel 2009 allows SQL injection for Authentication Bypass via 'or 1=1 or ''=' to login.php.

CVSS3: 9.8
4%
Низкий
больше 3 лет назад
github логотип
GHSA-352m-3444-89q4

A Denial of Service (DOS) issue was discovered in ControlByWeb X-320M-I Web-Enabled Instrumentation-Grade Data Acquisition module 1.05 with firmware revision v1.05. An authenticated user can configure invalid network settings, stopping TCP based communications to the device. A physical factory reset is required to restore the device to an operational state.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-352j-rqv2-cp9f

phpLDAPadmin 1.2.2 allows LDAP injection via a crafted server_id parameter in a cmd.php?cmd=login_form request, or a crafted username and password in the login panel.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-352j-376q-2pmc

This High severity PrivEsc (Privilege Escalation) vulnerability was introduced in versions: 9.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Core Data Center and Server 5.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Service Management Data Center and Server This PrivEsc (Privilege Escalation) vulnerability, with a CVSS Score of 7.2, allows an attacker to perform actions as a higher-privileged user. Atlassian recommends that Jira Core Data Center and Server and Jira Service Management Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Jira Core Data Center and Server 9.12: Upgrade to a release greater than or equal to 9.12.20 Jira Service Management Data Center and Server 5.12: Upgrade to a release greater than or equal to 5.12.20 Jira Core Data Center 10.3: Upgrade to a release greater than or equal to 10.3.5 Jira Service Management Data Center 10.3: Upgrade to a release great...

CVSS3: 8.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-352j-2x5m-wf94

HOME SPOT CUBE2 V102 contains an OS command injection vulnerability due to improper processing of data received from DHCP server. An adjacent attacker may execute an arbitrary OS command on the product if a malicious DHCP server is placed on the WAN side of the product.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-352h-846h-f54v

The Team+ from TEAMPLUS TECHNOLOGY does not properly validate specific page parameter, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify and delete database contents.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-352f-rwjm-p38m

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Reports for iOS 11.0.0.7 could allow a local attacker to obtain sensitive information in the form of an API key. An attacker could use this information to launch further attacks against affected applications.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-352f-q892-q47q

A stored Reflected Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.0 up to 14.3.1 allowed an attacker to execute arbitrary javascript code.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-352f-p7c4-xq3r

ownCloud Server before 6.0.1 does not properly check permissions, which allows remote authenticated users to access arbitrary preview pictures via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-352f-c86f-rrhx

Microsoft PC Manager Elevation of Privilege Vulnerability

CVSS3: 7.8
0%
Низкий
12 месяцев назад
github логотип
GHSA-352f-66f5-76w2

OpenJPEG before 2.3.1 has a heap buffer overflow in color_apply_icc_profile in bin/common/color.c.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу