Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 301 538

Количество 301 538

github логотип

GHSA-27pw-7wxg-pvx9

почти 2 года назад

Improper access control vulnerability in Quick Share prior to 13.5.52.0 allows local attacker to access local files.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-27pw-27h4-97mx

больше 3 лет назад

net/ceph/auth_x.c in Ceph, as used in the Linux kernel before 3.16.3, does not properly validate auth replies, which allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via crafted data from the IP address of a Ceph Monitor.

EPSS: Низкий
github логотип

GHSA-27pv-q55r-222g

больше 4 лет назад

Path traversal in github.com/ipfs/go-ipfs

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-27pv-p83w-4xp4

больше 3 лет назад

Stack consumption vulnerability in the dissect_ber_unknown function in epan/dissectors/packet-ber.c in the BER dissector in Wireshark 1.4.x before 1.4.1 and 1.2.x before 1.2.12 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a long string in an unknown ASN.1/BER encoded packet, as demonstrated using SNMP.

EPSS: Низкий
github логотип

GHSA-27pv-9qxj-gfj6

больше 3 лет назад

In RTTTL_Event of eas_rtttl.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-123700383

EPSS: Низкий
github логотип

GHSA-27pv-53mj-ff4j

больше 3 лет назад

PHP remote file inclusion vulnerability in modules/rtmessageadd.php in LAN Management System (LMS) 1.5.3, and possibly 1.5.4, allows remote attackers to execute arbitrary PHP code via a URL in the _LIB_DIR parameter, a different vector than CVE-2007-1643.

EPSS: Низкий
github логотип

GHSA-27pr-r7hm-c2rc

больше 2 лет назад

Missing permission check in Jenkins Dimensions Plugin allows enumerating credentials IDs

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-27pr-43qm-8hmf

больше 3 лет назад

The LoadText method in the spreadsheet component in Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to read arbitrary files through Internet Explorer via a URL that redirects to the target file.

EPSS: Средний
github логотип

GHSA-27pq-p52w-4h65

около 3 лет назад

Genesys PureConnect Interaction Web Tools Chat Service (up to at least 26- September- 2019) allows XSS within the Printable Chat History via the participant -> name JSON POST parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-27pq-ccjc-wxmc

больше 2 лет назад

Sngrep v1.6.0 was discovered to contain a stack buffer overflow via the function packet_set_payload at /src/packet.c.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-27pp-94gr-r5v9

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in vbshout.php in DragonByte Technologies vBShout module for vBulletin allows remote attackers to inject arbitrary web script or HTML via the shout parameter in a shout action.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-27pm-56m3-q426

почти 2 года назад

TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘hour’ parameter of the setRebootScheCfg interface of the cstecgi .cgi.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-27ph-x57w-v4gm

больше 3 лет назад

Stack-based buffer overflow in the ast_uri_encode function in main/utils.c in Asterisk Open Source before 1.4.38.1, 1.4.39.1, 1.6.1.21, 1.6.2.15.1, 1.6.2.16.1, 1.8.1.2, 1.8.2.; and Business Edition before C.3.6.2; when running in pedantic mode allows remote authenticated users to execute arbitrary code via crafted caller ID data in vectors involving the (1) SIP channel driver, (2) URIENCODE dialplan function, or (3) AGI dialplan function.

EPSS: Низкий
github логотип

GHSA-27pg-jvfh-7c97

почти 4 года назад

Improper access control while doing XPU re-configuration dynamically can lead to unauthorized access to a secure resource in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wired Infrastructure and Networking

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-27pg-f79j-mx3w

около 2 лет назад

Memory corruption in WLAN HAL while passing command parameters through WMI interfaces.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-27pg-cfc8-4p42

больше 3 лет назад

Unspecified vulnerability in the Windows Media Player ActiveX control in Windows Media Player (WMP) 9 on Microsoft Windows 2000 SP4 and XP SP2 and SP3 allows remote attackers to execute arbitrary code via crafted media content, aka "Media Player Remote Code Execution Vulnerability."

EPSS: Средний
github логотип

GHSA-27pg-4cj6-8994

больше 2 лет назад

yuan1994 tpAdmin Unrestricted Upload of File with Dangerous Type vulnerability

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-27p9-j7h2-2wgf

больше 3 лет назад

Directory traversal vulnerability in HolaCMS 1.4.9-1 allows remote attackers to overwrite arbitrary files via a "holaDB/votes" followed by a .. (dot dot) in the vote_filename parameter, which bypasses the check by HolaCMS to ensure that the file is in the holaDB/votes directory.

EPSS: Низкий
github логотип

GHSA-27p9-9jjq-pmww

больше 1 года назад

The WPZOOM Social Feed Widget & Block plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpzoom_instagram_clear_data() function in all versions up to, and including, 2.1.13. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete all Instagram images installed on the site.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-27p8-m7h9-xchc

около 2 месяцев назад

Multiple robotic products by Unitree sharing a common firmware, including the Go2, G1, H1, and B2 devices, contain a command injection vulnerability. By setting a malicious string when configuring the on-board WiFi via a BLE module of an affected robot, then triggering a restart of the WiFi service, an attacker can ultimately trigger commands to be run as root via the wpa_supplicant_restart.sh shell script.

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-27pw-7wxg-pvx9

Improper access control vulnerability in Quick Share prior to 13.5.52.0 allows local attacker to access local files.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-27pw-27h4-97mx

net/ceph/auth_x.c in Ceph, as used in the Linux kernel before 3.16.3, does not properly validate auth replies, which allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via crafted data from the IP address of a Ceph Monitor.

4%
Низкий
больше 3 лет назад
github логотип
GHSA-27pv-q55r-222g

Path traversal in github.com/ipfs/go-ipfs

CVSS3: 7.7
2%
Низкий
больше 4 лет назад
github логотип
GHSA-27pv-p83w-4xp4

Stack consumption vulnerability in the dissect_ber_unknown function in epan/dissectors/packet-ber.c in the BER dissector in Wireshark 1.4.x before 1.4.1 and 1.2.x before 1.2.12 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a long string in an unknown ASN.1/BER encoded packet, as demonstrated using SNMP.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-27pv-9qxj-gfj6

In RTTTL_Event of eas_rtttl.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-123700383

0%
Низкий
больше 3 лет назад
github логотип
GHSA-27pv-53mj-ff4j

PHP remote file inclusion vulnerability in modules/rtmessageadd.php in LAN Management System (LMS) 1.5.3, and possibly 1.5.4, allows remote attackers to execute arbitrary PHP code via a URL in the _LIB_DIR parameter, a different vector than CVE-2007-1643.

5%
Низкий
больше 3 лет назад
github логотип
GHSA-27pr-r7hm-c2rc

Missing permission check in Jenkins Dimensions Plugin allows enumerating credentials IDs

CVSS3: 4.2
0%
Низкий
больше 2 лет назад
github логотип
GHSA-27pr-43qm-8hmf

The LoadText method in the spreadsheet component in Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to read arbitrary files through Internet Explorer via a URL that redirects to the target file.

25%
Средний
больше 3 лет назад
github логотип
GHSA-27pq-p52w-4h65

Genesys PureConnect Interaction Web Tools Chat Service (up to at least 26- September- 2019) allows XSS within the Printable Chat History via the participant -> name JSON POST parameter.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-27pq-ccjc-wxmc

Sngrep v1.6.0 was discovered to contain a stack buffer overflow via the function packet_set_payload at /src/packet.c.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-27pp-94gr-r5v9

Cross-site scripting (XSS) vulnerability in vbshout.php in DragonByte Technologies vBShout module for vBulletin allows remote attackers to inject arbitrary web script or HTML via the shout parameter in a shout action.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-27pm-56m3-q426

TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘hour’ parameter of the setRebootScheCfg interface of the cstecgi .cgi.

CVSS3: 9.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-27ph-x57w-v4gm

Stack-based buffer overflow in the ast_uri_encode function in main/utils.c in Asterisk Open Source before 1.4.38.1, 1.4.39.1, 1.6.1.21, 1.6.2.15.1, 1.6.2.16.1, 1.8.1.2, 1.8.2.; and Business Edition before C.3.6.2; when running in pedantic mode allows remote authenticated users to execute arbitrary code via crafted caller ID data in vectors involving the (1) SIP channel driver, (2) URIENCODE dialplan function, or (3) AGI dialplan function.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-27pg-jvfh-7c97

Improper access control while doing XPU re-configuration dynamically can lead to unauthorized access to a secure resource in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wired Infrastructure and Networking

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-27pg-f79j-mx3w

Memory corruption in WLAN HAL while passing command parameters through WMI interfaces.

CVSS3: 7.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-27pg-cfc8-4p42

Unspecified vulnerability in the Windows Media Player ActiveX control in Windows Media Player (WMP) 9 on Microsoft Windows 2000 SP4 and XP SP2 and SP3 allows remote attackers to execute arbitrary code via crafted media content, aka "Media Player Remote Code Execution Vulnerability."

64%
Средний
больше 3 лет назад
github логотип
GHSA-27pg-4cj6-8994

yuan1994 tpAdmin Unrestricted Upload of File with Dangerous Type vulnerability

CVSS3: 7.2
0%
Низкий
больше 2 лет назад
github логотип
GHSA-27p9-j7h2-2wgf

Directory traversal vulnerability in HolaCMS 1.4.9-1 allows remote attackers to overwrite arbitrary files via a "holaDB/votes" followed by a .. (dot dot) in the vote_filename parameter, which bypasses the check by HolaCMS to ensure that the file is in the holaDB/votes directory.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-27p9-9jjq-pmww

The WPZOOM Social Feed Widget & Block plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpzoom_instagram_clear_data() function in all versions up to, and including, 2.1.13. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete all Instagram images installed on the site.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-27p8-m7h9-xchc

Multiple robotic products by Unitree sharing a common firmware, including the Go2, G1, H1, and B2 devices, contain a command injection vulnerability. By setting a malicious string when configuring the on-board WiFi via a BLE module of an affected robot, then triggering a restart of the WiFi service, an attacker can ultimately trigger commands to be run as root via the wpa_supplicant_restart.sh shell script.

CVSS3: 7.3
2%
Низкий
около 2 месяцев назад

Уязвимостей на страницу