Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 301 694

Количество 301 694

github логотип

GHSA-288h-f6gm-4vf9

больше 3 лет назад

PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string.

EPSS: Средний
github логотип

GHSA-288h-4m8f-x8cf

больше 3 лет назад

Pragyan CMS v3.0 is vulnerable to a Boolean-based SQL injection in cms/admin.lib.php via $_GET['forwhat'], resulting in Information Disclosure.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-288f-gh2h-9j8q

больше 3 лет назад

Mumble: murmur-server has DoS due to malformed client query

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-288c-fr85-5qmw

больше 3 лет назад

The VIP.com application for IOS and Android allows remote attackers to obtain sensitive information and hijack the authentication of users via a rogue access point and a man-in-the-middle attack.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-288c-cq4h-88gq

больше 4 лет назад

XML External Entity (XXE) Injection in Jackson Databind

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-288c-8vm9-x4gr

больше 3 лет назад

Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5902, CVE-2014-0410, CVE-2014-0415, CVE-2014-0418, and CVE-2014-0424.

EPSS: Низкий
github логотип

GHSA-2889-4jg5-2f75

около 1 месяца назад

If a user tries to login but the provided credentials are incorrect a log is created. The data for this POST requests is not validated and it’s possible to send giant payloads which are then logged.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2889-44x2-9xg5

больше 3 лет назад

, aka 'Windows Overlay Filter Security Feature Bypass Vulnerability'.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2888-q29x-2g3p

больше 2 лет назад

A man in the middle can redirect traffic to a malicious server in a compromised configuration.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2888-p547-jrjr

5 месяцев назад

Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC450M_AE4 v4.0.0 and BL-X26_DA3 v1.2.7 were discovered to contain multiple command injection vulnerabilities via the dns1 and dns2 parameters in the bs_SetDNSInfo function.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2888-gm7h-x2rw

около 1 года назад

A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0016), Tecnomatix Plant Simulation V2404 (All versions < V2404.0005). The affected application is vulnerable to memory corruption while parsing specially crafted WRL files. An attacker could leverage this in conjunction with other vulnerabilities to execute code in the context of the current process.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2887-wp98-w322

больше 3 лет назад

Puppet Enterprise before 3.2.0 does not properly restrict access to node endpoints in the console, which allows remote attackers to obtain sensitive information via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2887-hwqc-wcg8

больше 3 лет назад

Algorithmic complexity vulnerability in Moodle 1.9.x before 1.9.19, 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote authenticated users to cause a denial of service (CPU consumption) by using the advanced-search feature on a database activity that has many records.

EPSS: Низкий
github логотип

GHSA-2886-x646-53fj

больше 3 лет назад

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1, Safari 15.3 (v. 16612.4.9.1.8 and 15612.4.9.1.8). Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2886-fxgx-g9vm

больше 3 лет назад

An issue was discovered in Noise-Java through 2020-08-27. AESGCMFallbackCipherState.encryptWithAd() allows out-of-bounds access.

EPSS: Низкий
github логотип

GHSA-2886-9536-rhhj

около 17 часов назад

Certain HP LaserJet Pro printers may be vulnerable to information disclosure leading to credential exposure by altering the scan/send destination address and/or modifying the LDAP Server.

EPSS: Низкий
github логотип

GHSA-2885-vc9p-8279

11 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in Event Espresso Event Espresso 4 Decaf allows Cross Site Request Forgery.This issue affects Event Espresso 4 Decaf: from n/a through 5.0.28.decaf.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2885-hmxc-wwgx

больше 3 лет назад

Unspecified vulnerability in SAP Crystal Reports Server 2008 on Windows XP allows attackers to cause a denial of service (infinite loop) via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.3 through 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

EPSS: Низкий
github логотип

GHSA-2885-grqh-2673

10 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_set_pipapo: fix initial map fill The initial buffer has to be inited to all-ones, but it must restrict it to the size of the first field, not the total field size. After each round in the map search step, the result and the fill map are swapped, so if we have a set where f->bsize of the first element is smaller than m->bsize_max, those one-bits are leaked into future rounds result map. This makes pipapo find an incorrect matching results for sets where first field size is not the largest. Followup patch adds a test case to nft_concat_range.sh selftest script. Thanks to Stefano Brivio for pointing out that we need to zero out the remainder explicitly, only correcting memset() argument isn't enough.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2884-h97f-466v

почти 2 года назад

SysAid before 23.2.15 allows Indirect Object Reference (IDOR) attacks to read ticket data via a modified sid parameter to EmailHtmlSourceIframe.jsp or a modified srID parameter to ShowMessage.jsp.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-288h-f6gm-4vf9

PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string.

61%
Средний
больше 3 лет назад
github логотип
GHSA-288h-4m8f-x8cf

Pragyan CMS v3.0 is vulnerable to a Boolean-based SQL injection in cms/admin.lib.php via $_GET['forwhat'], resulting in Information Disclosure.

CVSS3: 4.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-288f-gh2h-9j8q

Mumble: murmur-server has DoS due to malformed client query

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-288c-fr85-5qmw

The VIP.com application for IOS and Android allows remote attackers to obtain sensitive information and hijack the authentication of users via a rogue access point and a man-in-the-middle attack.

CVSS3: 8.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-288c-cq4h-88gq

XML External Entity (XXE) Injection in Jackson Databind

CVSS3: 7.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-288c-8vm9-x4gr

Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5902, CVE-2014-0410, CVE-2014-0415, CVE-2014-0418, and CVE-2014-0424.

6%
Низкий
больше 3 лет назад
github логотип
GHSA-2889-4jg5-2f75

If a user tries to login but the provided credentials are incorrect a log is created. The data for this POST requests is not validated and it’s possible to send giant payloads which are then logged.

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-2889-44x2-9xg5

, aka 'Windows Overlay Filter Security Feature Bypass Vulnerability'.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2888-q29x-2g3p

A man in the middle can redirect traffic to a malicious server in a compromised configuration.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2888-p547-jrjr

Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC450M_AE4 v4.0.0 and BL-X26_DA3 v1.2.7 were discovered to contain multiple command injection vulnerabilities via the dns1 and dns2 parameters in the bs_SetDNSInfo function.

CVSS3: 9.8
1%
Низкий
5 месяцев назад
github логотип
GHSA-2888-gm7h-x2rw

A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0016), Tecnomatix Plant Simulation V2404 (All versions < V2404.0005). The affected application is vulnerable to memory corruption while parsing specially crafted WRL files. An attacker could leverage this in conjunction with other vulnerabilities to execute code in the context of the current process.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-2887-wp98-w322

Puppet Enterprise before 3.2.0 does not properly restrict access to node endpoints in the console, which allows remote attackers to obtain sensitive information via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2887-hwqc-wcg8

Algorithmic complexity vulnerability in Moodle 1.9.x before 1.9.19, 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote authenticated users to cause a denial of service (CPU consumption) by using the advanced-search feature on a database activity that has many records.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2886-x646-53fj

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1, Safari 15.3 (v. 16612.4.9.1.8 and 15612.4.9.1.8). Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

CVSS3: 8.8
5%
Низкий
больше 3 лет назад
github логотип
GHSA-2886-fxgx-g9vm

An issue was discovered in Noise-Java through 2020-08-27. AESGCMFallbackCipherState.encryptWithAd() allows out-of-bounds access.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2886-9536-rhhj

Certain HP LaserJet Pro printers may be vulnerable to information disclosure leading to credential exposure by altering the scan/send destination address and/or modifying the LDAP Server.

около 17 часов назад
github логотип
GHSA-2885-vc9p-8279

Cross-Site Request Forgery (CSRF) vulnerability in Event Espresso Event Espresso 4 Decaf allows Cross Site Request Forgery.This issue affects Event Espresso 4 Decaf: from n/a through 5.0.28.decaf.

CVSS3: 4.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-2885-hmxc-wwgx

Unspecified vulnerability in SAP Crystal Reports Server 2008 on Windows XP allows attackers to cause a denial of service (infinite loop) via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.3 through 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2885-grqh-2673

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_set_pipapo: fix initial map fill The initial buffer has to be inited to all-ones, but it must restrict it to the size of the first field, not the total field size. After each round in the map search step, the result and the fill map are swapped, so if we have a set where f->bsize of the first element is smaller than m->bsize_max, those one-bits are leaked into future rounds result map. This makes pipapo find an incorrect matching results for sets where first field size is not the largest. Followup patch adds a test case to nft_concat_range.sh selftest script. Thanks to Stefano Brivio for pointing out that we need to zero out the remainder explicitly, only correcting memset() argument isn't enough.

CVSS3: 5.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-2884-h97f-466v

SysAid before 23.2.15 allows Indirect Object Reference (IDOR) attacks to read ticket data via a modified sid parameter to EmailHtmlSourceIframe.jsp or a modified srID parameter to ShowMessage.jsp.

CVSS3: 6.5
0%
Низкий
почти 2 года назад

Уязвимостей на страницу