Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 301 330

Количество 301 330

github логотип

GHSA-2784-p9wg-c9fp

больше 3 лет назад

An Improper Access Control: CWE-284 vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 which could cause impact to confidentiality, integrity, and availability when a remote attacker crafts a malicious request to the encoder webUI.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-2784-7v92-p2wc

больше 3 лет назад

An issue was discovered on Samsung mobile devices with P(9.0) software. Attackers can use Smartwatch to view Secure Folder notification content. The Samsung ID is SVE-2019-13899 (April 2019).

EPSS: Низкий
github логотип

GHSA-2784-39w4-9568

больше 3 лет назад

sapi/fpm/fpm/fpm_log.c in PHP before 5.5.31, 5.6.x before 5.6.17, and 7.x before 7.0.2 misinterprets the semantics of the snprintf return value, which allows attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read and buffer overflow) via a long string, as demonstrated by a long URI in a configuration with custom REQUEST_URI logging.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-2783-h34h-q54q

больше 3 лет назад

It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to CVE-2018-1058, in order to execute arbitrary SQL command in the context of the user used for replication.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2783-26j3-5ghf

больше 3 лет назад

SQL Injection exists in the OS Property Real Estate 3.12.7 component for Joomla! via the cooling_system1, heating_system1, or laundry parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2782-hv4h-h26m

больше 3 лет назад

Parsing documents as HTML in Downloads in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to cause Chrome to execute scripts via a local non-HTML page.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-277x-wqvr-c5w3

больше 3 лет назад

PHP remote file inclusion vulnerability in include/user.php in the NoBoard BETA module for MKPortal allows remote attackers to execute arbitrary PHP code via a URL in the MK_PATH parameter.

EPSS: Средний
github логотип

GHSA-277x-g4g7-hg6j

около 2 лет назад

ASUS RT-AC86U unused Traffic Analyzer legacy Statistic function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-277x-frmf-w2gm

5 месяцев назад

The WP Lightbox 2 WordPress plugin before 3.0.6.8 does not correctly sanitize the value of the title attribute of links before using them, which may allow malicious users to conduct XSS attacks.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-277w-qpxr-2549

больше 3 лет назад

MediaElement Vulnerable to Reflected XSS

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-277v-gwfr-hmpj

около 6 лет назад

Missing Authentication for Critical Function in LibreNMS

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-277q-9jj6-mg2v

больше 3 лет назад

Cisco Adaptive Security Appliances (ASA) devices with firmware 8.x through 8.4(1) do not properly manage SSH sessions, which allows remote authenticated users to cause a denial of service (device crash) by establishing multiple sessions, aka Bug ID CSCtc59462.

EPSS: Низкий
github логотип

GHSA-277p-xwpp-3jf7

около 5 лет назад

Malicious Package in rrgod

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-277p-ffm3-r4h5

больше 3 лет назад

** DISPUTED ** CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated administrators to execute arbitrary PHP code via the code parameter to admin/editusertag.php, related to the CreateTagFunction and CallUserTag functions. NOTE: the vendor reportedly has stated this is "a feature, not a bug."

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-277j-xqqh-j9j2

больше 3 лет назад

Unspecified cross-site scripting (XSS) vulnerability in Horde before 2.2.9 allows remote attackers to inject arbitrary web script or HTML via "not properly escaped error messages".

EPSS: Низкий
github логотип

GHSA-277j-v92f-57q6

больше 3 лет назад

Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Microsoft Office Excel DbOrParamQry Record Parsing Vulnerability."

EPSS: Средний
github логотип

GHSA-277j-v78r-mm9w

больше 3 лет назад

Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper functions, which could allow unprivileged users, and possibly remote attackers, to run stored procedures with administrator privileges via (1) xp_execresultset, (2) xp_printstatements, or (3) xp_displayparamstmt.

EPSS: Средний
github логотип

GHSA-277j-7gg4-fp2x

почти 3 года назад

A Missing Release of Memory after Effective Lifetime vulnerability in the Juniper Networks Junos OS on MX Series platforms with MPC10/MPC11 line cards, allows an unauthenticated adjacent attacker to cause a Denial of Service (DoS). Devices are only vulnerable when the Suspicious Control Flow Detection (scfd) feature is enabled. Upon enabling this specific feature, an attacker sending specific traffic is causing memory to be allocated dynamically and it is not freed. Memory is not freed even after deactivating this feature. Sustained processing of such traffic will eventually lead to an out of memory condition that prevents all services from continuing to function, and requires a manual restart to recover. The FPC memory usage can be monitored using the CLI command "show chassis fpc". On running the above command, the memory of AftDdosScfdFlow can be observed to detect the memory leak. This issue affects Juniper Networks Junos OS on MX Series: All versions prior to 20.2R3-S5; 20.3 ve...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-277h-px4m-62q8

около 1 года назад

@saltcorn/server arbitrary file zip read and download when downloading auto backups

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-277h-m4vc-5wqc

больше 3 лет назад

Buffer overflow in Microsoft Windows Media Player 6.4 allows remote attackers to execute arbitrary code via a malformed Advanced Streaming Format (ASF) file.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2784-p9wg-c9fp

An Improper Access Control: CWE-284 vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 which could cause impact to confidentiality, integrity, and availability when a remote attacker crafts a malicious request to the encoder webUI.

CVSS3: 9.8
67%
Средний
больше 3 лет назад
github логотип
GHSA-2784-7v92-p2wc

An issue was discovered on Samsung mobile devices with P(9.0) software. Attackers can use Smartwatch to view Secure Folder notification content. The Samsung ID is SVE-2019-13899 (April 2019).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2784-39w4-9568

sapi/fpm/fpm/fpm_log.c in PHP before 5.5.31, 5.6.x before 5.6.17, and 7.x before 7.0.2 misinterprets the semantics of the snprintf return value, which allows attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read and buffer overflow) via a long string, as demonstrated by a long URI in a configuration with custom REQUEST_URI logging.

CVSS3: 9.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2783-h34h-q54q

It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to CVE-2018-1058, in order to execute arbitrary SQL command in the context of the user used for replication.

CVSS3: 7.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2783-26j3-5ghf

SQL Injection exists in the OS Property Real Estate 3.12.7 component for Joomla! via the cooling_system1, heating_system1, or laundry parameter.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2782-hv4h-h26m

Parsing documents as HTML in Downloads in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to cause Chrome to execute scripts via a local non-HTML page.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-277x-wqvr-c5w3

PHP remote file inclusion vulnerability in include/user.php in the NoBoard BETA module for MKPortal allows remote attackers to execute arbitrary PHP code via a URL in the MK_PATH parameter.

21%
Средний
больше 3 лет назад
github логотип
GHSA-277x-g4g7-hg6j

ASUS RT-AC86U unused Traffic Analyzer legacy Statistic function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services.

CVSS3: 8.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-277x-frmf-w2gm

The WP Lightbox 2 WordPress plugin before 3.0.6.8 does not correctly sanitize the value of the title attribute of links before using them, which may allow malicious users to conduct XSS attacks.

CVSS3: 6.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-277w-qpxr-2549

MediaElement Vulnerable to Reflected XSS

CVSS3: 6.1
4%
Низкий
больше 3 лет назад
github логотип
GHSA-277v-gwfr-hmpj

Missing Authentication for Critical Function in LibreNMS

CVSS3: 9.1
0%
Низкий
около 6 лет назад
github логотип
GHSA-277q-9jj6-mg2v

Cisco Adaptive Security Appliances (ASA) devices with firmware 8.x through 8.4(1) do not properly manage SSH sessions, which allows remote authenticated users to cause a denial of service (device crash) by establishing multiple sessions, aka Bug ID CSCtc59462.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-277p-xwpp-3jf7

Malicious Package in rrgod

CVSS3: 9.8
около 5 лет назад
github логотип
GHSA-277p-ffm3-r4h5

** DISPUTED ** CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated administrators to execute arbitrary PHP code via the code parameter to admin/editusertag.php, related to the CreateTagFunction and CallUserTag functions. NOTE: the vendor reportedly has stated this is "a feature, not a bug."

CVSS3: 7.2
4%
Низкий
больше 3 лет назад
github логотип
GHSA-277j-xqqh-j9j2

Unspecified cross-site scripting (XSS) vulnerability in Horde before 2.2.9 allows remote attackers to inject arbitrary web script or HTML via "not properly escaped error messages".

1%
Низкий
больше 3 лет назад
github логотип
GHSA-277j-v92f-57q6

Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Microsoft Office Excel DbOrParamQry Record Parsing Vulnerability."

57%
Средний
больше 3 лет назад
github логотип
GHSA-277j-v78r-mm9w

Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper functions, which could allow unprivileged users, and possibly remote attackers, to run stored procedures with administrator privileges via (1) xp_execresultset, (2) xp_printstatements, or (3) xp_displayparamstmt.

54%
Средний
больше 3 лет назад
github логотип
GHSA-277j-7gg4-fp2x

A Missing Release of Memory after Effective Lifetime vulnerability in the Juniper Networks Junos OS on MX Series platforms with MPC10/MPC11 line cards, allows an unauthenticated adjacent attacker to cause a Denial of Service (DoS). Devices are only vulnerable when the Suspicious Control Flow Detection (scfd) feature is enabled. Upon enabling this specific feature, an attacker sending specific traffic is causing memory to be allocated dynamically and it is not freed. Memory is not freed even after deactivating this feature. Sustained processing of such traffic will eventually lead to an out of memory condition that prevents all services from continuing to function, and requires a manual restart to recover. The FPC memory usage can be monitored using the CLI command "show chassis fpc". On running the above command, the memory of AftDdosScfdFlow can be observed to detect the memory leak. This issue affects Juniper Networks Junos OS on MX Series: All versions prior to 20.2R3-S5; 20.3 ve...

CVSS3: 7.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-277h-px4m-62q8

@saltcorn/server arbitrary file zip read and download when downloading auto backups

CVSS3: 4.4
около 1 года назад
github логотип
GHSA-277h-m4vc-5wqc

Buffer overflow in Microsoft Windows Media Player 6.4 allows remote attackers to execute arbitrary code via a malformed Advanced Streaming Format (ASF) file.

17%
Средний
больше 3 лет назад

Уязвимостей на страницу