Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 301 330

Количество 301 330

github логотип

GHSA-2795-wfr2-m5v3

около 1 месяца назад

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Avoid fcport pointer dereference Klocwork reported warning of NULL pointer may be dereferenced. The routine exits when sa_ctl is NULL and fcport is allocated after the exit call thus causing NULL fcport pointer to dereference at the time of exit. To avoid fcport pointer dereference, exit the routine when sa_ctl is NULL.

EPSS: Низкий
github логотип

GHSA-2795-pjw4-5495

10 месяцев назад

A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0) allows the OpenSSL configuration file to load from a non-existent directory. An unauthorized, locally authenticated user with low privileges can potentially create the directory and load a specially crafted openssl.conf file leading to the execution of a malicious DLL (Dynamic-Link Library) with elevated privileges.

EPSS: Низкий
github логотип

GHSA-2795-hprj-q9m8

больше 3 лет назад

Multiple vulnerabilities in the web UI of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against users on an affected system. The vulnerabilities are due to insufficient validation of user-supplied input that is processed by the web UI. An attacker could exploit these vulnerabilities by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information on an affected system.

EPSS: Низкий
github логотип

GHSA-2795-85x7-cp8v

больше 3 лет назад

QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the server via command injection in the servicestart parameter.

EPSS: Средний
github логотип

GHSA-2794-c693-53gf

11 месяцев назад

A vulnerability classified as problematic has been found in FabulaTech USB over Network 6.0.6.1. Affected is the function 0x22040C in the library ftusbbus2.sys of the component IOCT Handler. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2794-6m94-77f7

около 1 года назад

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-2793-r34m-9rvh

больше 3 лет назад

libxml2 in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2016-4614, CVE-2016-4616, and CVE-2016-4619.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2793-qrcg-qwq3

около 2 лет назад

Windows Error Reporting Service Elevation of Privilege Vulnerability

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-2793-7v75-7pw5

больше 3 лет назад

A remote sql injection authentication bypass in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-2793-3243-f8xx

около 3 лет назад

Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain a cross-site scripting (XSS) vulnerability.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2792-x8v5-77wp

около 2 лет назад

Integer overflow vulnerability in tool_operate.c in curl 7.65.2 via crafted value as the retry delay.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-278x-ph66-x5gw

почти 3 года назад

Memory corruption due to access of uninitialized pointer in Bluetooth HOST while processing the AVRCP packet.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-278x-ggmc-78v9

больше 3 лет назад

IBM QRadar Network Security 5.4.0 and 5.5.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 174340.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-278x-6vg6-6g42

больше 3 лет назад

src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3.34 versions, does not validate string length fields in SDP packets, which allows remote SDP servers to cause a denial of service or possibly have unspecified other impact via a crafted length field that triggers excessive memory allocation or a buffer over-read.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-278v-j3cr-jv2x

больше 3 лет назад

Jenkins Kanboard Plugin vulnerable to Server-side request forgery (SSRF)

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-278v-98mp-vjv7

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Domino Blogsphere 3.01 Beta 7 allows remote attackers to inject arbitrary web script or HTML via the name field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-278v-8427-jw24

почти 4 года назад

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. GetMask param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-278v-44j3-pqxv

больше 3 лет назад

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 13.3, watchOS 6.1.1, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. Processing maliciously crafted web content may lead to arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-278r-xxvf-49rm

почти 2 года назад

An issue was discovered in Zammad before 6.2.0. Due to lack of rate limiting in the "email address verification" feature, an attacker could send many requests for a known address to cause Denial Of Service (generation of many emails, which would also spam the victim).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-278r-549p-g687

почти 3 года назад

An Out-of-bounds read vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This is similar to, but not the same as CVE-2022-44648.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2795-wfr2-m5v3

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Avoid fcport pointer dereference Klocwork reported warning of NULL pointer may be dereferenced. The routine exits when sa_ctl is NULL and fcport is allocated after the exit call thus causing NULL fcport pointer to dereference at the time of exit. To avoid fcport pointer dereference, exit the routine when sa_ctl is NULL.

0%
Низкий
около 1 месяца назад
github логотип
GHSA-2795-pjw4-5495

A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0) allows the OpenSSL configuration file to load from a non-existent directory. An unauthorized, locally authenticated user with low privileges can potentially create the directory and load a specially crafted openssl.conf file leading to the execution of a malicious DLL (Dynamic-Link Library) with elevated privileges.

0%
Низкий
10 месяцев назад
github логотип
GHSA-2795-hprj-q9m8

Multiple vulnerabilities in the web UI of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against users on an affected system. The vulnerabilities are due to insufficient validation of user-supplied input that is processed by the web UI. An attacker could exploit these vulnerabilities by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information on an affected system.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2795-85x7-cp8v

QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the server via command injection in the servicestart parameter.

40%
Средний
больше 3 лет назад
github логотип
GHSA-2794-c693-53gf

A vulnerability classified as problematic has been found in FabulaTech USB over Network 6.0.6.1. Affected is the function 0x22040C in the library ftusbbus2.sys of the component IOCT Handler. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-2794-6m94-77f7

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service.

CVSS3: 4.9
1%
Низкий
около 1 года назад
github логотип
GHSA-2793-r34m-9rvh

libxml2 in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2016-4614, CVE-2016-4616, and CVE-2016-4619.

CVSS3: 9.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-2793-qrcg-qwq3

Windows Error Reporting Service Elevation of Privilege Vulnerability

CVSS3: 7
0%
Низкий
около 2 лет назад
github логотип
GHSA-2793-7v75-7pw5

A remote sql injection authentication bypass in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found.

CVSS3: 9.8
35%
Средний
больше 3 лет назад
github логотип
GHSA-2793-3243-f8xx

Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain a cross-site scripting (XSS) vulnerability.

CVSS3: 5.4
2%
Низкий
около 3 лет назад
github логотип
GHSA-2792-x8v5-77wp

Integer overflow vulnerability in tool_operate.c in curl 7.65.2 via crafted value as the retry delay.

CVSS3: 9.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-278x-ph66-x5gw

Memory corruption due to access of uninitialized pointer in Bluetooth HOST while processing the AVRCP packet.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-278x-ggmc-78v9

IBM QRadar Network Security 5.4.0 and 5.5.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 174340.

CVSS3: 5.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-278x-6vg6-6g42

src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3.34 versions, does not validate string length fields in SDP packets, which allows remote SDP servers to cause a denial of service or possibly have unspecified other impact via a crafted length field that triggers excessive memory allocation or a buffer over-read.

CVSS3: 9.8
6%
Низкий
больше 3 лет назад
github логотип
GHSA-278v-j3cr-jv2x

Jenkins Kanboard Plugin vulnerable to Server-side request forgery (SSRF)

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-278v-98mp-vjv7

Cross-site scripting (XSS) vulnerability in Domino Blogsphere 3.01 Beta 7 allows remote attackers to inject arbitrary web script or HTML via the name field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-278v-8427-jw24

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. GetMask param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-278v-44j3-pqxv

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 13.3, watchOS 6.1.1, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. Processing maliciously crafted web content may lead to arbitrary code execution.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-278r-xxvf-49rm

An issue was discovered in Zammad before 6.2.0. Due to lack of rate limiting in the "email address verification" feature, an attacker could send many requests for a known address to cause Denial Of Service (generation of many emails, which would also spam the victim).

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-278r-549p-g687

An Out-of-bounds read vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This is similar to, but not the same as CVE-2022-44648.

CVSS3: 5.5
0%
Низкий
почти 3 года назад

Уязвимостей на страницу