Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 301 840

Количество 301 840

github логотип

GHSA-296j-r9gr-7w2c

около 1 года назад

Dell Dock Firmware and Dell Client Platform contain an Improper Link Resolution vulnerability during installation resulting in arbitrary folder deletion, which could lead to Privilege Escalation or Denial of Service.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-296j-2h87-8rxh

больше 3 лет назад

Visual Studio Code ESLint Extension Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-296j-266h-6jc4

больше 3 лет назад

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-296h-f7c6-qrvp

больше 3 лет назад

Stack-based buffer overflow in Jasc Paint Shop Pro 8.10 (aka Corel Paint Shop Pro) allows user-assisted remote attackers to execute arbitrary code via a crafted PNG file. NOTE: this might be the same issue as CVE-2007-2366.

EPSS: Низкий
github логотип

GHSA-296g-m5cw-f8p9

больше 3 лет назад

A vulnerability in Cisco AMP for Endpoints Linux Connector Software and Cisco AMP for Endpoints Mac Connector Software could allow an authenticated, local attacker to cause a buffer overflow on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted packet to an affected device. A successful exploit could allow the attacker to cause the Cisco AMP for Endpoints service to crash and restart.

EPSS: Низкий
github логотип

GHSA-296f-j97f-9r25

больше 3 лет назад

IOHIDFamily in Apple OS X before 10.10 allows attackers to cause denial of service (out-of-bounds read operation) via a crafted application.

EPSS: Низкий
github логотип

GHSA-296f-cx2x-g274

9 месяцев назад

SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the userService API model.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-296f-9hr7-4mwq

12 месяцев назад

Stored Cross-Site Scripting in the Access Request History in Omada Identity before version 15 update 1 allows an authenticated attacker to execute arbitrary code in the browser of a victim via a specially crafted link or by viewing a manipulated Access Request History

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-296f-4hq2-5r99

больше 3 лет назад

Web authoring command in Microsoft Content Management Server (MCMS) 2001 allows attackers to authenticate and upload executable content, by modifying the upload location, aka "Program Execution via MCMS Authoring Function."

EPSS: Низкий
github логотип

GHSA-296c-8m99-q77p

больше 1 года назад

Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-2969-8hh9-57jc

почти 4 года назад

Allocation of Resources Without Limits or Throttling in ckb

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2969-2qqp-g57c

больше 3 лет назад

cPanel before 67.9999.103 allows code execution in the context of the mailman account because of incorrect environment-variable filtering (SEC-302).

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2968-xc5j-q436

больше 3 лет назад

The OC_Util::getUrlContent function in ownCloud Server before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 allows remote attackers to read arbitrary files via a file:// protocol.

EPSS: Низкий
github логотип

GHSA-2968-wv79-2wqf

около 1 месяца назад

HCL BigFix Mobile 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset of endpoint actions, potentially allowing access to select internal functions.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2968-fmvc-r6gw

больше 2 лет назад

Signal Handler Race Condition vulnerability in Mitsubishi Electric India GC-ENET-COM whose first 2 digits of 11-digit serial number of unit are "16" allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition in Ethernet communication by sending a large number of specially crafted packets to any UDP port when GC-ENET-COM is configured as a Modbus TCP Server. The communication resumes only when the power of the main unit is turned off and on or when the GC-ENET-COM is hot-swapped from the main unit.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2968-6vjj-whq8

почти 3 года назад

Phicomm K2G v22.6.3.20 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade function.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2967-w8m2-xw7h

больше 3 лет назад

PHP remote file inclusion vulnerability in class.cs_phpmailer.php in CS-Cart 1.3.3 allows remote attackers to execute arbitrary PHP code via a URL in the classes_dir parameter.

EPSS: Низкий
github логотип

GHSA-2966-gh5h-j633

больше 3 лет назад

The session extension in PHP 4 before 4.4.5, and PHP 5 before 5.2.1, calculates the reference count for the session variables without considering the internal pointer from the session globals, which allows context-dependent attackers to execute arbitrary code via a crafted string in the session_register after unsetting HTTP_SESSION_VARS and _SESSION, which destroys the session data Hashtable.

EPSS: Низкий
github логотип

GHSA-2965-8m5f-3hph

больше 2 лет назад

Insufficient policy enforcement in Extensions API in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious extension to bypass an enterprise policy via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2963-qpfw-w3r2

больше 1 года назад

InDesign Desktop versions ID18.5.2, ID19.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to an application denial-of-service (DoS). An attacker could exploit this vulnerability to crash the application, resulting in a denial of service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-296j-r9gr-7w2c

Dell Dock Firmware and Dell Client Platform contain an Improper Link Resolution vulnerability during installation resulting in arbitrary folder deletion, which could lead to Privilege Escalation or Denial of Service.

CVSS3: 6.7
0%
Низкий
около 1 года назад
github логотип
GHSA-296j-2h87-8rxh

Visual Studio Code ESLint Extension Remote Code Execution Vulnerability

CVSS3: 7.8
6%
Низкий
больше 3 лет назад
github логотип
GHSA-296j-266h-6jc4

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-296h-f7c6-qrvp

Stack-based buffer overflow in Jasc Paint Shop Pro 8.10 (aka Corel Paint Shop Pro) allows user-assisted remote attackers to execute arbitrary code via a crafted PNG file. NOTE: this might be the same issue as CVE-2007-2366.

8%
Низкий
больше 3 лет назад
github логотип
GHSA-296g-m5cw-f8p9

A vulnerability in Cisco AMP for Endpoints Linux Connector Software and Cisco AMP for Endpoints Mac Connector Software could allow an authenticated, local attacker to cause a buffer overflow on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted packet to an affected device. A successful exploit could allow the attacker to cause the Cisco AMP for Endpoints service to crash and restart.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-296f-j97f-9r25

IOHIDFamily in Apple OS X before 10.10 allows attackers to cause denial of service (out-of-bounds read operation) via a crafted application.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-296f-cx2x-g274

SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the userService API model.

CVSS3: 9.1
0%
Низкий
9 месяцев назад
github логотип
GHSA-296f-9hr7-4mwq

Stored Cross-Site Scripting in the Access Request History in Omada Identity before version 15 update 1 allows an authenticated attacker to execute arbitrary code in the browser of a victim via a specially crafted link or by viewing a manipulated Access Request History

CVSS3: 8
0%
Низкий
12 месяцев назад
github логотип
GHSA-296f-4hq2-5r99

Web authoring command in Microsoft Content Management Server (MCMS) 2001 allows attackers to authenticate and upload executable content, by modifying the upload location, aka "Program Execution via MCMS Authoring Function."

9%
Низкий
больше 3 лет назад
github логотип
GHSA-296c-8m99-q77p

Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager.

CVSS3: 8.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-2969-8hh9-57jc

Allocation of Resources Without Limits or Throttling in ckb

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-2969-2qqp-g57c

cPanel before 67.9999.103 allows code execution in the context of the mailman account because of incorrect environment-variable filtering (SEC-302).

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2968-xc5j-q436

The OC_Util::getUrlContent function in ownCloud Server before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 allows remote attackers to read arbitrary files via a file:// protocol.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2968-wv79-2wqf

HCL BigFix Mobile 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset of endpoint actions, potentially allowing access to select internal functions.

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-2968-fmvc-r6gw

Signal Handler Race Condition vulnerability in Mitsubishi Electric India GC-ENET-COM whose first 2 digits of 11-digit serial number of unit are "16" allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition in Ethernet communication by sending a large number of specially crafted packets to any UDP port when GC-ENET-COM is configured as a Modbus TCP Server. The communication resumes only when the power of the main unit is turned off and on or when the GC-ENET-COM is hot-swapped from the main unit.

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2968-6vjj-whq8

Phicomm K2G v22.6.3.20 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade function.

CVSS3: 7.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-2967-w8m2-xw7h

PHP remote file inclusion vulnerability in class.cs_phpmailer.php in CS-Cart 1.3.3 allows remote attackers to execute arbitrary PHP code via a URL in the classes_dir parameter.

9%
Низкий
больше 3 лет назад
github логотип
GHSA-2966-gh5h-j633

The session extension in PHP 4 before 4.4.5, and PHP 5 before 5.2.1, calculates the reference count for the session variables without considering the internal pointer from the session globals, which allows context-dependent attackers to execute arbitrary code via a crafted string in the session_register after unsetting HTTP_SESSION_VARS and _SESSION, which destroys the session data Hashtable.

5%
Низкий
больше 3 лет назад
github логотип
GHSA-2965-8m5f-3hph

Insufficient policy enforcement in Extensions API in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious extension to bypass an enterprise policy via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2963-qpfw-w3r2

InDesign Desktop versions ID18.5.2, ID19.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to an application denial-of-service (DoS). An attacker could exploit this vulnerability to crash the application, resulting in a denial of service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
0%
Низкий
больше 1 года назад

Уязвимостей на страницу