Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 311 677

Количество 311 677

github логотип

GHSA-2wrq-r74m-9pj3

больше 3 лет назад

A vulnerability has been identified in Solid Edge (All Versions < SE2022MP9). The affected application contains an out of bounds write past the fixed-length heap-based buffer while parsing specially crafted DWG files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-17627)

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2wrq-fr55-6869

около 2 лет назад

In display, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08059081; Issue ID: ALPS08059081.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2wrq-8v99-jmf7

больше 3 лет назад

Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4080, CVE-2014-4089, and CVE-2014-4091.

EPSS: Средний
github логотип

GHSA-2wrq-53r8-rc4c

почти 4 года назад

The _udp_lib_get_port function in net/ipv4/udp.c in Linux kernel 2.6.21 and earlier does not prevent a bind to a port with a local address when there is already a bind to that port with a wildcard local address, which might allow local users to intercept local traffic for daemons or other applications.

EPSS: Низкий
github логотип

GHSA-2wrp-6fg6-hmc5

почти 2 года назад

Spring Framework URL Parsing with Host Validation

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2wrj-mx36-vgp8

2 месяца назад

The atec Duplicate Page & Post plugin for WordPress is vulnerable to unauthorized post duplication due to missing authorization validation on the duplicate_post() function in all versions up to, and including, 1.2.20. This makes it possible for authenticated attackers, with Contributor-level access and above, to duplicate arbitrary posts, including private and password-protected posts, leading to data exposure.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2wrh-j8p9-w4c5

почти 3 года назад

llvm-project commit a0138390 was discovered to contain an assertion failure at !replacements.count(op) && "operation was already replaced.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2wrh-hm5q-2h33

больше 2 лет назад

A Cross-Site Request Forgery (CSRF) in Guanzhou Tozed Kangwei Intelligent Technology ZLTS10G software version S10G_3.11.6 allows attackers to takeover user accounts via sending a crafted POST request to /goform/goform_set_cmd_process.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2wrh-h883-mcp8

почти 4 года назад

The asynchronous I/O facility in 4.4 BSD kernel does not check user credentials when setting the recipient of I/O notification, which allows local users to cause a denial of service by using certain ioctl and fcntl calls to cause the signal to be sent to an arbitrary process ID.

EPSS: Низкий
github логотип

GHSA-2wrh-6pvc-2jm9

больше 2 лет назад

Improper rendering of text nodes in golang.org/x/net/html

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2wrh-3gmh-mgcw

почти 2 года назад

IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to weaker than expected security. IBM X-Force ID: 236452.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2wrg-v6wv-9q7f

больше 1 года назад

A vulnerability has been found in SourceCodester Event Registration System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/login.php. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-265198 is the identifier assigned to this vulnerability.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2wrg-jmgf-rcgj

почти 3 года назад

Adobe Dimension version 3.4.8 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2wrg-7gpc-j9h6

около 1 года назад

IBM Security ReaQta 3.12 returns sensitive information in an HTTP response that could be used in further attacks against the system.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2wrf-hf7j-cx32

больше 3 лет назад

An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player before 3.0.9 allows remote attackers to cause a denial of service (memory corruption) via a crafted image file. NOTE: this may be related to the SDL_Image product.

EPSS: Низкий
github логотип

GHSA-2wrf-6w3p-8x3p

почти 2 года назад

Sante DICOM Viewer Pro DCM File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante DICOM Viewer Pro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DCM images. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15629.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2wrc-xqr6-94x6

почти 4 года назад

Integer overflow in RealArcade 1.2.0.994 and earlier allows remote attackers to execute arbitrary code via an RGS file with an invalid size string for the GUID and game name, which leads to a buffer overflow.

EPSS: Низкий
github логотип

GHSA-2wrc-cg26-jf7m

больше 3 лет назад

** UNSUPPORTED WHEN ASSIGNED ** In OSS-RC systems of the release 18B and older during data migration procedures certain files containing usernames and passwords are left in the system undeleted but in folders accessible by top privileged accounts only. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. Ericsson Network Manager is a new generation OSS system which OSS-RC customers shall upgrade to.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-2wrc-8rc6-mc72

больше 3 лет назад

Huawei FusionAccess with software V100R005C10,V100R005C20 could allow attackers to craft and send a malformed HDP protocol packet to cause the virtual cloud desktop to be displaying an error and not usable.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2wrc-685p-7pgf

больше 3 лет назад

The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.

CVSS3: 3.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2wrq-r74m-9pj3

A vulnerability has been identified in Solid Edge (All Versions < SE2022MP9). The affected application contains an out of bounds write past the fixed-length heap-based buffer while parsing specially crafted DWG files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-17627)

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2wrq-fr55-6869

In display, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08059081; Issue ID: ALPS08059081.

CVSS3: 6.7
0%
Низкий
около 2 лет назад
github логотип
GHSA-2wrq-8v99-jmf7

Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4080, CVE-2014-4089, and CVE-2014-4091.

16%
Средний
больше 3 лет назад
github логотип
GHSA-2wrq-53r8-rc4c

The _udp_lib_get_port function in net/ipv4/udp.c in Linux kernel 2.6.21 and earlier does not prevent a bind to a port with a local address when there is already a bind to that port with a wildcard local address, which might allow local users to intercept local traffic for daemons or other applications.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2wrp-6fg6-hmc5

Spring Framework URL Parsing with Host Validation

CVSS3: 8.1
10%
Низкий
почти 2 года назад
github логотип
GHSA-2wrj-mx36-vgp8

The atec Duplicate Page & Post plugin for WordPress is vulnerable to unauthorized post duplication due to missing authorization validation on the duplicate_post() function in all versions up to, and including, 1.2.20. This makes it possible for authenticated attackers, with Contributor-level access and above, to duplicate arbitrary posts, including private and password-protected posts, leading to data exposure.

CVSS3: 5.3
0%
Низкий
2 месяца назад
github логотип
GHSA-2wrh-j8p9-w4c5

llvm-project commit a0138390 was discovered to contain an assertion failure at !replacements.count(op) && "operation was already replaced.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-2wrh-hm5q-2h33

A Cross-Site Request Forgery (CSRF) in Guanzhou Tozed Kangwei Intelligent Technology ZLTS10G software version S10G_3.11.6 allows attackers to takeover user accounts via sending a crafted POST request to /goform/goform_set_cmd_process.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2wrh-h883-mcp8

The asynchronous I/O facility in 4.4 BSD kernel does not check user credentials when setting the recipient of I/O notification, which allows local users to cause a denial of service by using certain ioctl and fcntl calls to cause the signal to be sent to an arbitrary process ID.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2wrh-6pvc-2jm9

Improper rendering of text nodes in golang.org/x/net/html

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2wrh-3gmh-mgcw

IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to weaker than expected security. IBM X-Force ID: 236452.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-2wrg-v6wv-9q7f

A vulnerability has been found in SourceCodester Event Registration System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/login.php. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-265198 is the identifier assigned to this vulnerability.

CVSS3: 7.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2wrg-jmgf-rcgj

Adobe Dimension version 3.4.8 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-2wrg-7gpc-j9h6

IBM Security ReaQta 3.12 returns sensitive information in an HTTP response that could be used in further attacks against the system.

CVSS3: 5.3
0%
Низкий
около 1 года назад
github логотип
GHSA-2wrf-hf7j-cx32

An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player before 3.0.9 allows remote attackers to cause a denial of service (memory corruption) via a crafted image file. NOTE: this may be related to the SDL_Image product.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2wrf-6w3p-8x3p

Sante DICOM Viewer Pro DCM File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante DICOM Viewer Pro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DCM images. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15629.

CVSS3: 7.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-2wrc-xqr6-94x6

Integer overflow in RealArcade 1.2.0.994 and earlier allows remote attackers to execute arbitrary code via an RGS file with an invalid size string for the GUID and game name, which leads to a buffer overflow.

3%
Низкий
почти 4 года назад
github логотип
GHSA-2wrc-cg26-jf7m

** UNSUPPORTED WHEN ASSIGNED ** In OSS-RC systems of the release 18B and older during data migration procedures certain files containing usernames and passwords are left in the system undeleted but in folders accessible by top privileged accounts only. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. Ericsson Network Manager is a new generation OSS system which OSS-RC customers shall upgrade to.

CVSS3: 4.9
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2wrc-8rc6-mc72

Huawei FusionAccess with software V100R005C10,V100R005C20 could allow attackers to craft and send a malformed HDP protocol packet to cause the virtual cloud desktop to be displaying an error and not usable.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2wrc-685p-7pgf

The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.

CVSS3: 3.4
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу