Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 301 538

Количество 301 538

github логотип

GHSA-27qw-pwxv-qq8r

около 3 лет назад

Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function formSetVirtualSer.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-27qw-fff9-qjq8

4 месяца назад

Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-27qw-cxvq-fp97

больше 3 лет назад

HPE IPFilter A.11.31.18.21 on HP-UX, when a certain keep-state configuration is enabled, allows remote attackers to cause a denial of service via unspecified UDP packets.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-27qv-mw67-9whg

больше 3 лет назад

An issue was discovered in ezXML 0.8.2 through 0.8.6. The function ezxml_str2utf8, while parsing a crafted XML file, performs zero-length reallocation in ezxml.c, leading to returning a NULL pointer (in some compilers). After this, the function ezxml_parse_str does not check whether the s variable is not NULL in ezxml.c, leading to a NULL pointer dereference and crash (segmentation fault).

EPSS: Низкий
github логотип

GHSA-27qr-6rgm-2f59

3 месяца назад

An authentication bypass vulnerability in Arcserve Unified Data Protection (UDP) allows unauthenticated attackers to gain unauthorized access to protected functionality or user accounts. By manipulating specific request parameters or exploiting a logic flaw, an attacker can bypass login mechanisms without valid credentials and access administrator-level features. This vulnerability affects all UDP versions prior to 10.2. UDP 10.2 includes the necessary patches and requires no action. Versions 8.0 through 10.1 are supported and require either patch application or upgrade to 10.2. Versions 7.x and earlier are unsupported or out of maintenance and must be upgraded to 10.2 to remediate the issue.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-27qr-636m-wxg2

больше 1 года назад

codeigniter/framework SQL injection in ODBC database driver

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-27qm-xvmj-53q7

больше 3 лет назад

Multiple directory traversal vulnerabilities in cpCommerce 1.1.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the language parameter in a language action to the default URI, which is not properly handled in actions/language.act.php, or (2) the action parameter to category.php.

EPSS: Низкий
github логотип

GHSA-27qm-rh9r-32fx

около 2 лет назад

Cross-site scripting vulnerability in HOTELDRUID 3.0.5 and earlier allows a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-27qm-jwxp-8whw

почти 3 года назад

The WP-Polls WordPress plugin before 2.76.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations to vote in certain situations.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-27qh-h38r-jf2v

около 2 лет назад

Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the login.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-27qh-4m42-f89x

больше 3 лет назад

Unknown vulnerability in the eflags checking in the 32-bit ptrace emulation for the Linux kernel on AMD64 systems allows local users to gain privileges.

EPSS: Низкий
github логотип

GHSA-27qg-h9vp-x2xp

почти 2 года назад

HCL DRYiCE MyXalytics product is impacted by unauthenticated file upload vulnerability. The web application permits the upload of a certain file without requiring user authentication.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-27qg-f2r7-8953

почти 4 года назад

Improper input validation for some Intel(R) PROSet/Wireless WiFi in multiple operating systems and Killer(TM) WiFi in Windows 10 and 11 may allow an authenticated user to potentially enable denial of service via adjacent access.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-27qf-jwm8-g7f3

около 4 лет назад

FPE in LSH in TFLite

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-27qc-c946-g657

больше 3 лет назад

CUPS on Mandriva Linux 2008.0, 2008.1, 2009.0, Corporate Server (CS) 3.0 and 4.0, and Multi Network Firewall (MNF) 2.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pdf.log temporary file.

EPSS: Низкий
github логотип

GHSA-27qc-3h99-8rcj

больше 3 лет назад

Parallels H-Sphere 3.6.2 allows XSS via the index_en.php from parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-27qc-3c4c-hwfw

больше 3 лет назад

Mate 9 with software MHA-AL00AC00B125 has a denial of service (DoS) vulnerability. An attacker tricks a user into installing a malicious application. Since the system does not verify the broadcasting message from the application, it could be exploited to cause some functions of system unavailable.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-27q9-h529-q4g3

почти 2 года назад

OpenSSH through 9.6, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of authenticated in mm_answer_authpassword does not resist flips of a single bit. NOTE: this is applicable to a certain threat model of attacker-victim co-location in which the attacker has user privileges.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-27q9-g54w-g6cm

больше 3 лет назад

msxlsview.sh in xlsview for catdoc 0.91 and earlier allows local users to overwrite arbitrary files via a symlink attack on predictable temporary file names ("word$$.html").

EPSS: Низкий
github логотип

GHSA-27q8-8p72-c44c

больше 3 лет назад

Trend Micro Security (Consumer) 2020 (v16.x) is affected by a vulnerability in where null pointer dereference errors result in the crash of application, which could potentially lead to possible unsigned code execution under certain circumstances.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-27qw-pwxv-qq8r

Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function formSetVirtualSer.

CVSS3: 9.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-27qw-fff9-qjq8

Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-27qw-cxvq-fp97

HPE IPFilter A.11.31.18.21 on HP-UX, when a certain keep-state configuration is enabled, allows remote attackers to cause a denial of service via unspecified UDP packets.

CVSS3: 5.9
2%
Низкий
больше 3 лет назад
github логотип
GHSA-27qv-mw67-9whg

An issue was discovered in ezXML 0.8.2 through 0.8.6. The function ezxml_str2utf8, while parsing a crafted XML file, performs zero-length reallocation in ezxml.c, leading to returning a NULL pointer (in some compilers). After this, the function ezxml_parse_str does not check whether the s variable is not NULL in ezxml.c, leading to a NULL pointer dereference and crash (segmentation fault).

1%
Низкий
больше 3 лет назад
github логотип
GHSA-27qr-6rgm-2f59

An authentication bypass vulnerability in Arcserve Unified Data Protection (UDP) allows unauthenticated attackers to gain unauthorized access to protected functionality or user accounts. By manipulating specific request parameters or exploiting a logic flaw, an attacker can bypass login mechanisms without valid credentials and access administrator-level features. This vulnerability affects all UDP versions prior to 10.2. UDP 10.2 includes the necessary patches and requires no action. Versions 8.0 through 10.1 are supported and require either patch application or upgrade to 10.2. Versions 7.x and earlier are unsupported or out of maintenance and must be upgraded to 10.2 to remediate the issue.

CVSS3: 9.8
0%
Низкий
3 месяца назад
github логотип
GHSA-27qr-636m-wxg2

codeigniter/framework SQL injection in ODBC database driver

CVSS3: 10
больше 1 года назад
github логотип
GHSA-27qm-xvmj-53q7

Multiple directory traversal vulnerabilities in cpCommerce 1.1.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the language parameter in a language action to the default URI, which is not properly handled in actions/language.act.php, or (2) the action parameter to category.php.

6%
Низкий
больше 3 лет назад
github логотип
GHSA-27qm-rh9r-32fx

Cross-site scripting vulnerability in HOTELDRUID 3.0.5 and earlier allows a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product.

CVSS3: 6.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-27qm-jwxp-8whw

The WP-Polls WordPress plugin before 2.76.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations to vote in certain situations.

CVSS3: 5.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-27qh-h38r-jf2v

Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the login.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.

CVSS3: 6.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-27qh-4m42-f89x

Unknown vulnerability in the eflags checking in the 32-bit ptrace emulation for the Linux kernel on AMD64 systems allows local users to gain privileges.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-27qg-h9vp-x2xp

HCL DRYiCE MyXalytics product is impacted by unauthenticated file upload vulnerability. The web application permits the upload of a certain file without requiring user authentication.

CVSS3: 8.2
0%
Низкий
почти 2 года назад
github логотип
GHSA-27qg-f2r7-8953

Improper input validation for some Intel(R) PROSet/Wireless WiFi in multiple operating systems and Killer(TM) WiFi in Windows 10 and 11 may allow an authenticated user to potentially enable denial of service via adjacent access.

CVSS3: 5.7
0%
Низкий
почти 4 года назад
github логотип
GHSA-27qf-jwm8-g7f3

FPE in LSH in TFLite

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-27qc-c946-g657

CUPS on Mandriva Linux 2008.0, 2008.1, 2009.0, Corporate Server (CS) 3.0 and 4.0, and Multi Network Firewall (MNF) 2.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pdf.log temporary file.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-27qc-3h99-8rcj

Parallels H-Sphere 3.6.2 allows XSS via the index_en.php from parameter.

CVSS3: 6.1
6%
Низкий
больше 3 лет назад
github логотип
GHSA-27qc-3c4c-hwfw

Mate 9 with software MHA-AL00AC00B125 has a denial of service (DoS) vulnerability. An attacker tricks a user into installing a malicious application. Since the system does not verify the broadcasting message from the application, it could be exploited to cause some functions of system unavailable.

CVSS3: 3.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-27q9-h529-q4g3

OpenSSH through 9.6, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of authenticated in mm_answer_authpassword does not resist flips of a single bit. NOTE: this is applicable to a certain threat model of attacker-victim co-location in which the attacker has user privileges.

CVSS3: 7
0%
Низкий
почти 2 года назад
github логотип
GHSA-27q9-g54w-g6cm

msxlsview.sh in xlsview for catdoc 0.91 and earlier allows local users to overwrite arbitrary files via a symlink attack on predictable temporary file names ("word$$.html").

0%
Низкий
больше 3 лет назад
github логотип
GHSA-27q8-8p72-c44c

Trend Micro Security (Consumer) 2020 (v16.x) is affected by a vulnerability in where null pointer dereference errors result in the crash of application, which could potentially lead to possible unsigned code execution under certain circumstances.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу