Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 212

Количество 314 212

github логотип

GHSA-33jw-84xq-w6fj

почти 3 года назад

A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiAuthenticator 6.4.x and before allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests to the login form.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-33jw-2jpq-625x

больше 1 года назад

Loftware Spectrum before 4.6 HF14 allows authenticated XXE attacks.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-33jv-w23j-x28v

почти 4 года назад

SQL injection vulnerability in member.asp in qjForum allows remote attackers to execute arbitrary SQL commands via the uName parameter.

EPSS: Низкий
github логотип

GHSA-33jv-mx9r-jr3q

больше 3 лет назад

Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-2160, CVE-2010-2166, CVE-2010-2171, CVE-2010-2175, CVE-2010-2176, CVE-2010-2177, CVE-2010-2178, CVE-2010-2180, CVE-2010-2182, CVE-2010-2184, CVE-2010-2187, and CVE-2010-2188.

EPSS: Низкий
github логотип

GHSA-33jv-5wxr-v6v3

почти 3 года назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EMF files. Crafted data in an EMF file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17634.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-33jv-3p35-h2qx

почти 4 года назад

Vulnerabilities in the KDE kvt terminal program allow local users to gain root privileges.

EPSS: Низкий
github логотип

GHSA-33jr-73hp-7wxc

больше 3 лет назад

Any URLs with download_attachment.php under templates or home folders can allow arbitrary files downloaded without login in BroadLearning eClass before version ip.2.5.10.2.1.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-33jr-59q9-j8vq

почти 4 года назад

Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service (100% CPU consumption) via large HTML form fields such as text inputs in a table cell.

EPSS: Низкий
github логотип

GHSA-33jq-r57w-5666

около 2 месяцев назад

UliCMS 2023.1 contains a privilege escalation vulnerability that allows unauthenticated attackers to create administrative accounts through the UserController endpoint. Attackers can send a crafted POST request to /dist/admin/index.php with specific parameters to generate a new admin user with full system access.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-33jq-g649-fc48

больше 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Andy Moyle Church Admin allows Reflected XSS.This issue affects Church Admin: from n/a before 5.0.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-33jp-9c34-9c92

больше 3 лет назад

An issue was discovered in CSS-TRICKS Chat2 through 2015-05-05. The userid parameter in jumpin.php has a SQL injection vulnerability.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-33jm-jx25-33gx

почти 2 года назад

Memory corruption when the bandpass filter order received from AHAL is not within the expected range.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-33jj-rpwm-v75g

почти 4 года назад

An SQL Injection vulnerability exists in oasys oa_system as of 9/7/2021 in resources/mappers/notice-mapper.xml.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-33jj-pgpw-2mqq

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: PCI: mt7621: Add sentinel to quirks table Current driver is missing a sentinel in the struct soc_device_attribute array, which causes an oops when assessed by the soc_device_match(mt7621_pcie_quirks_match) call. This was only exposed once the CONFIG_SOC_MT7621 mt7621 soc_dev_attr was fixed to register the SOC as a device, in: commit 7c18b64bba3b ("mips: ralink: mt7621: do not use kzalloc too early") Fix it by adding the required sentinel.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-33jj-92px-m4g7

больше 3 лет назад

Craft CMS Cross-site Scripting Vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-33jh-9x8q-p7j7

больше 3 лет назад

The Control and Provisioning functionality in Cisco Mobility Services Engine (MSE) 10.0(0.1) allows remote authenticated users to obtain sensitive information by reading log files, aka Bug ID CSCut36851.

EPSS: Низкий
github логотип

GHSA-33jh-2f37-89xc

около 2 месяцев назад

A vulnerability was detected in campcodes Online Student Enrollment System 1.0. This affects an unknown function of the file /admin/index.php?page=user-profile. Performing manipulation of the argument userphoto results in unrestricted upload. The attack can be initiated remotely. The exploit is now public and may be used.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-33jf-8996-c3p5

больше 3 лет назад

An exploitable integer-overflow vulnerability exists within Iceni Argus. When it attempts to convert a malformed PDF to XML, it will attempt to convert each character from a font into a polygon and then attempt to rasterize these shapes. As the application attempts to iterate through the rows and initializing the polygon shape in the buffer, it will write outside of the bounds of said buffer. This can lead to code execution under the context of the account running it.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-33jf-4rqx-933q

почти 4 года назад

OpenSSH before 5.1 sets the SO_REUSEADDR socket option when the X11UseLocalhost configuration setting is disabled, which allows local users on some platforms to hijack the X11 forwarding port via a bind to a single IP address, as demonstrated on the HP-UX platform.

EPSS: Низкий
github логотип

GHSA-33j9-x55f-349p

почти 3 года назад

Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious user with high Privileges may potentially exploit this vulnerability to perform arbitrary code execution or cause denial of service.

CVSS3: 6.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-33jw-84xq-w6fj

A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiAuthenticator 6.4.x and before allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests to the login form.

CVSS3: 5.3
7%
Низкий
почти 3 года назад
github логотип
GHSA-33jw-2jpq-625x

Loftware Spectrum before 4.6 HF14 allows authenticated XXE attacks.

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-33jv-w23j-x28v

SQL injection vulnerability in member.asp in qjForum allows remote attackers to execute arbitrary SQL commands via the uName parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-33jv-mx9r-jr3q

Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-2160, CVE-2010-2166, CVE-2010-2171, CVE-2010-2175, CVE-2010-2176, CVE-2010-2177, CVE-2010-2178, CVE-2010-2180, CVE-2010-2182, CVE-2010-2184, CVE-2010-2187, and CVE-2010-2188.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-33jv-5wxr-v6v3

This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EMF files. Crafted data in an EMF file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17634.

CVSS3: 7.8
3%
Низкий
почти 3 года назад
github логотип
GHSA-33jv-3p35-h2qx

Vulnerabilities in the KDE kvt terminal program allow local users to gain root privileges.

0%
Низкий
почти 4 года назад
github логотип
GHSA-33jr-73hp-7wxc

Any URLs with download_attachment.php under templates or home folders can allow arbitrary files downloaded without login in BroadLearning eClass before version ip.2.5.10.2.1.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-33jr-59q9-j8vq

Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service (100% CPU consumption) via large HTML form fields such as text inputs in a table cell.

9%
Низкий
почти 4 года назад
github логотип
GHSA-33jq-r57w-5666

UliCMS 2023.1 contains a privilege escalation vulnerability that allows unauthenticated attackers to create administrative accounts through the UserController endpoint. Attackers can send a crafted POST request to /dist/admin/index.php with specific parameters to generate a new admin user with full system access.

CVSS3: 9.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-33jq-g649-fc48

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Andy Moyle Church Admin allows Reflected XSS.This issue affects Church Admin: from n/a before 5.0.0.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-33jp-9c34-9c92

An issue was discovered in CSS-TRICKS Chat2 through 2015-05-05. The userid parameter in jumpin.php has a SQL injection vulnerability.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-33jm-jx25-33gx

Memory corruption when the bandpass filter order received from AHAL is not within the expected range.

CVSS3: 6.7
0%
Низкий
почти 2 года назад
github логотип
GHSA-33jj-rpwm-v75g

An SQL Injection vulnerability exists in oasys oa_system as of 9/7/2021 in resources/mappers/notice-mapper.xml.

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-33jj-pgpw-2mqq

In the Linux kernel, the following vulnerability has been resolved: PCI: mt7621: Add sentinel to quirks table Current driver is missing a sentinel in the struct soc_device_attribute array, which causes an oops when assessed by the soc_device_match(mt7621_pcie_quirks_match) call. This was only exposed once the CONFIG_SOC_MT7621 mt7621 soc_dev_attr was fixed to register the SOC as a device, in: commit 7c18b64bba3b ("mips: ralink: mt7621: do not use kzalloc too early") Fix it by adding the required sentinel.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-33jj-92px-m4g7

Craft CMS Cross-site Scripting Vulnerability

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-33jh-9x8q-p7j7

The Control and Provisioning functionality in Cisco Mobility Services Engine (MSE) 10.0(0.1) allows remote authenticated users to obtain sensitive information by reading log files, aka Bug ID CSCut36851.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-33jh-2f37-89xc

A vulnerability was detected in campcodes Online Student Enrollment System 1.0. This affects an unknown function of the file /admin/index.php?page=user-profile. Performing manipulation of the argument userphoto results in unrestricted upload. The attack can be initiated remotely. The exploit is now public and may be used.

CVSS3: 4.7
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-33jf-8996-c3p5

An exploitable integer-overflow vulnerability exists within Iceni Argus. When it attempts to convert a malformed PDF to XML, it will attempt to convert each character from a font into a polygon and then attempt to rasterize these shapes. As the application attempts to iterate through the rows and initializing the polygon shape in the buffer, it will write outside of the bounds of said buffer. This can lead to code execution under the context of the account running it.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-33jf-4rqx-933q

OpenSSH before 5.1 sets the SO_REUSEADDR socket option when the X11UseLocalhost configuration setting is disabled, which allows local users on some platforms to hijack the X11 forwarding port via a bind to a single IP address, as demonstrated on the HP-UX platform.

0%
Низкий
почти 4 года назад
github логотип
GHSA-33j9-x55f-349p

Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious user with high Privileges may potentially exploit this vulnerability to perform arbitrary code execution or cause denial of service.

CVSS3: 6.7
0%
Низкий
почти 3 года назад

Уязвимостей на страницу