Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 301 840

Количество 301 840

github логотип

GHSA-294h-g237-97pw

больше 3 лет назад

Integer overflow in the (a) OLE2 and (b) CHM parsers for ESET NOD32 Antivirus before 1.1743 allows remote attackers to execute arbitrary code via a crafted (1) .DOC or (2) .CAB file that triggers a heap-based buffer overflow.

EPSS: Низкий
github логотип

GHSA-294h-9fqc-xfq7

больше 3 лет назад

Improper access control in the runner jobs API in GitLab CE/EE affecting all versions prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows a previous maintainer of a project with a specific runner to access job and project meta data under certain conditions

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-294f-mx29-rgp2

больше 3 лет назад

An issue was discovered in RICOH Streamline NX Client Tool and RICOH Streamline NX PC Client that allows attackers to escalate local privileges.

EPSS: Низкий
github логотип

GHSA-294f-6x8f-w547

больше 3 лет назад

Cross-site request forgery in OpenOversight 0.6.4 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.

EPSS: Низкий
github логотип

GHSA-294c-hx25-mgvq

11 месяцев назад

Dell RecoverPoint for Virtual Machines 6.0.x contains use of hard-coded credentials vulnerability. A Remote unauthenticated attacker could potentially exploit this vulnerability by gaining access to the source code, easily retrieving these secrets and reusing them to access the system leading to gaining access to unauthorized data.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-294c-hpxh-5qrx

около 2 лет назад

A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode) if the pointer is warped from within a window on one screen to the root window of the other screen and if the original window is destroyed followed by another window being destroyed.

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-294c-c6r2-489h

больше 3 лет назад

IBM Lotus Notes Traveler before 8.5.1.3, when a multidomain environment is used, does not properly apply policy documents to mobile users from a different Domino domain than the Traveler server, which allows remote authenticated users to bypass intended access restrictions by using credentials from a different domain.

EPSS: Низкий
github логотип

GHSA-2948-xh52-592r

больше 3 лет назад

The SOAP Admin API component of TIBCO Software Inc.'s TIBCO Silver Fabric contains a vulnerability that may allow reflected cross-site scripting (XSS) attacks. Affected releases are TIBCO Software Inc.'s TIBCO Silver Fabric: versions up to and including 5.8.1.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2948-wgj8-jg4r

больше 3 лет назад

In an audio driver in all Qualcomm products with Android releases from CAF using the Linux kernel, when a sanity check encounters a length value not in the correct range, an error message is printed, but code execution continues in the same way as for a correct length value.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-2948-rrxj-6qwq

больше 3 лет назад

Cisco Content Security Management Appliance (SMA) 7.8.0-000 does not properly validate credentials, which allows remote attackers to cause a denial of service (rapid log-file rollover and application fault) via crafted HTTP requests, aka Bug ID CSCuw09620.

EPSS: Низкий
github логотип

GHSA-2948-3mj2-4gw2

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Use online_vcpus, not created_vcpus, to iterate over vCPUs Use the kvm_for_each_vcpu() helper to iterate over vCPUs when encrypting VMSAs for SEV, which effectively switches to use online_vcpus instead of created_vcpus. This fixes a possible null-pointer dereference as created_vcpus does not guarantee a vCPU exists, since it is updated at the very beginning of KVM_CREATE_VCPU. created_vcpus exists to allow the bulk of vCPU creation to run in parallel, while still correctly restricting the max number of max vCPUs.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2947-h8cf-6m6g

почти 2 года назад

An issue discovered in D-Link dir815 v.1.01SSb08.bin allows a remote attacker to execute arbitrary code via a crafted POST request to the service parameter in the soapcgi_main function of the cgibin binary component.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-2946-xv2c-75wg

больше 3 лет назад

The UpdateDataSize function in ebmlmaster.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (assert fault) via a crafted mkv file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2945-84q7-684p

10 месяцев назад

Tenda ac9 v1.0 firmware v15.03.05.19 contains a stack overflow vulnerability in /goform/SetOnlineDevName, which may lead to remote arbitrary code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2945-6wgc-c9rc

больше 3 лет назад

XML external entity vulnerability in the Extended Computer Aided Test Tool (eCATT) in SAP NetWeaver AS ABAP 7.31 and earlier allows remote attackers to access arbitrary files via a crafted XML request, related to ECATT_DISPLAY_XMLSTRING_REMOTE, aka SAP Note 2016638.

EPSS: Низкий
github логотип

GHSA-2943-53pm-phm4

больше 3 лет назад

Victor CMS through 2019-02-28 allows XSS via the register.php user_firstname or user_lastname field.

EPSS: Низкий
github логотип

GHSA-2943-4gp2-qhj2

больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in HP Operations Orchestration Central 10.x before 10.22.001 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

EPSS: Низкий
github логотип

GHSA-2942-p8v5-q78c

почти 4 года назад

Windows Kerberos Elevation of Privilege Vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2942-jp7w-55rc

больше 1 года назад

An issue in GLPI v.10.0.12 and before allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the title field.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-293x-x4gc-p56j

больше 3 лет назад

Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to a file read operation over RPC.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-294h-g237-97pw

Integer overflow in the (a) OLE2 and (b) CHM parsers for ESET NOD32 Antivirus before 1.1743 allows remote attackers to execute arbitrary code via a crafted (1) .DOC or (2) .CAB file that triggers a heap-based buffer overflow.

8%
Низкий
больше 3 лет назад
github логотип
GHSA-294h-9fqc-xfq7

Improper access control in the runner jobs API in GitLab CE/EE affecting all versions prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows a previous maintainer of a project with a specific runner to access job and project meta data under certain conditions

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-294f-mx29-rgp2

An issue was discovered in RICOH Streamline NX Client Tool and RICOH Streamline NX PC Client that allows attackers to escalate local privileges.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-294f-6x8f-w547

Cross-site request forgery in OpenOversight 0.6.4 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-294c-hx25-mgvq

Dell RecoverPoint for Virtual Machines 6.0.x contains use of hard-coded credentials vulnerability. A Remote unauthenticated attacker could potentially exploit this vulnerability by gaining access to the source code, easily retrieving these secrets and reusing them to access the system leading to gaining access to unauthorized data.

CVSS3: 5.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-294c-hpxh-5qrx

A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode) if the pointer is warped from within a window on one screen to the root window of the other screen and if the original window is destroyed followed by another window being destroyed.

CVSS3: 5.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-294c-c6r2-489h

IBM Lotus Notes Traveler before 8.5.1.3, when a multidomain environment is used, does not properly apply policy documents to mobile users from a different Domino domain than the Traveler server, which allows remote authenticated users to bypass intended access restrictions by using credentials from a different domain.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2948-xh52-592r

The SOAP Admin API component of TIBCO Software Inc.'s TIBCO Silver Fabric contains a vulnerability that may allow reflected cross-site scripting (XSS) attacks. Affected releases are TIBCO Software Inc.'s TIBCO Silver Fabric: versions up to and including 5.8.1.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2948-wgj8-jg4r

In an audio driver in all Qualcomm products with Android releases from CAF using the Linux kernel, when a sanity check encounters a length value not in the correct range, an error message is printed, but code execution continues in the same way as for a correct length value.

CVSS3: 7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2948-rrxj-6qwq

Cisco Content Security Management Appliance (SMA) 7.8.0-000 does not properly validate credentials, which allows remote attackers to cause a denial of service (rapid log-file rollover and application fault) via crafted HTTP requests, aka Bug ID CSCuw09620.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2948-3mj2-4gw2

In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Use online_vcpus, not created_vcpus, to iterate over vCPUs Use the kvm_for_each_vcpu() helper to iterate over vCPUs when encrypting VMSAs for SEV, which effectively switches to use online_vcpus instead of created_vcpus. This fixes a possible null-pointer dereference as created_vcpus does not guarantee a vCPU exists, since it is updated at the very beginning of KVM_CREATE_VCPU. created_vcpus exists to allow the bulk of vCPU creation to run in parallel, while still correctly restricting the max number of max vCPUs.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2947-h8cf-6m6g

An issue discovered in D-Link dir815 v.1.01SSb08.bin allows a remote attacker to execute arbitrary code via a crafted POST request to the service parameter in the soapcgi_main function of the cgibin binary component.

CVSS3: 9.8
48%
Средний
почти 2 года назад
github логотип
GHSA-2946-xv2c-75wg

The UpdateDataSize function in ebmlmaster.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (assert fault) via a crafted mkv file.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2945-84q7-684p

Tenda ac9 v1.0 firmware v15.03.05.19 contains a stack overflow vulnerability in /goform/SetOnlineDevName, which may lead to remote arbitrary code execution.

CVSS3: 9.8
1%
Низкий
10 месяцев назад
github логотип
GHSA-2945-6wgc-c9rc

XML external entity vulnerability in the Extended Computer Aided Test Tool (eCATT) in SAP NetWeaver AS ABAP 7.31 and earlier allows remote attackers to access arbitrary files via a crafted XML request, related to ECATT_DISPLAY_XMLSTRING_REMOTE, aka SAP Note 2016638.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2943-53pm-phm4

Victor CMS through 2019-02-28 allows XSS via the register.php user_firstname or user_lastname field.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2943-4gp2-qhj2

Cross-site request forgery (CSRF) vulnerability in HP Operations Orchestration Central 10.x before 10.22.001 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2942-p8v5-q78c

Windows Kerberos Elevation of Privilege Vulnerability.

CVSS3: 8.8
8%
Низкий
почти 4 года назад
github логотип
GHSA-2942-jp7w-55rc

An issue in GLPI v.10.0.12 and before allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the title field.

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-293x-x4gc-p56j

Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to a file read operation over RPC.

29%
Средний
больше 3 лет назад

Уязвимостей на страницу