Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-33pg-v77m-8hhv

почти 4 года назад

Check Point Zone Labs ZoneAlarm Internet Security Suite 6.5.722.000, 6.1.737.000, and possibly other versions do not properly validate RegSaveKey, RegRestoreKey, and RegDeleteKey function calls, which allows local users to cause a denial of service (system crash) via a certain combination of these function calls with an HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VETFDDNT\Enum argument.

EPSS: Низкий
github логотип

GHSA-33pg-m6jh-5237

почти 3 года назад

Docker Swarm encrypted overlay network traffic may be unencrypted

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-33pg-fqx9-9w66

почти 2 года назад

A vulnerability, which was classified as critical, was found in lakernote EasyAdmin up to 20240315. Affected is the function thumbnail of the file src/main/java/com/laker/admin/module/sys/controller/IndexController.java. The manipulation of the argument url leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The patch is identified as 23165d8cb569048c531150f194fea39f8800b8d5. It is recommended to apply a patch to fix this issue. VDB-257718 is the identifier assigned to this vulnerability.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-33pc-wm38-7ffg

почти 4 года назад

HyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the length of a value that is saved in a session file, which allows remote attackers to execute arbitrary code via a malicious HyperTerminal session file (.ht), web site, or Telnet URL contained in an e-mail message, triggering a buffer overflow.

EPSS: Средний
github логотип

GHSA-33pc-q72m-p74w

больше 2 лет назад

NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3.0-DEV.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-33pc-42rm-x55v

3 месяца назад

A reflected cross-site scripting (XSS) vulnerability in the /overview/network/ endpoint of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the charge parameter.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-33p9-qh39-m99v

2 месяца назад

Multiple SQL Injections in Frappe CRM Dashboard Controller due to unsafe concatenation of user-controlled parameters into dynamic SQL statements. This issue affects Frappe CRM: 1.53.1.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-33p9-j27p-6f2h

около 1 года назад

In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was identified. Reported by Karol Więsek.

EPSS: Низкий
github логотип

GHSA-33p9-3qx3-xpc6

больше 3 лет назад

Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable use after free vulnerability in the XFA parsing engine when handling certain types of internal instructions. Successful exploitation could lead to arbitrary code execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-33p9-3p43-82vq

8 месяцев назад

Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-33p8-v8q2-mx53

около 2 лет назад

An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This vulnerability is similar to, but not identical to, CVE-2023-47197.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-33p7-vhh2-qpvp

почти 4 года назад

Buffer overflow in ncurses 5.0, and the ncurses4 compatibility package as used in Red Hat Linux, allows local users to gain privileges, related to "routines for moving the physical cursor and scrolling."

EPSS: Низкий
github логотип

GHSA-33p7-qrxw-8cm4

больше 3 лет назад

Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-0606, CVE-2013-0612, CVE-2013-0615, CVE-2013-0617, and CVE-2013-0621.

EPSS: Средний
github логотип

GHSA-33p7-cjfg-8vc5

больше 3 лет назад

A buffer overflow in Redis 3.2.x prior to 3.2.4 causes arbitrary code execution when a crafted command is sent. An out of bounds write vulnerability exists in the handling of the client-output-buffer-limit option during the CONFIG SET command for the Redis data structure store. A crafted CONFIG SET command can lead to an out of bounds write potentially resulting in code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-33p7-c5wh-6q6g

больше 3 лет назад

Trend Micro Antivirus for Mac 2020 (Consumer) contains a race condition vulnerability in the Web Threat Protection Blocklist component, that if exploited, could allow an attacker to case a kernel panic or crash. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability.

EPSS: Низкий
github логотип

GHSA-33p6-fx42-7rf5

почти 4 года назад

Harbor is vulnerable to a limited Server-Side Request Forgery (SSRF) (CVE-2020-13788)

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-33p5-m25c-cp6w

почти 3 года назад

A privilege escalation vulnerability exists in Node.js <19.6.1, <18.14.1, <16.19.1 and <14.21.3 that made it possible to bypass the experimental Permissions (https://nodejs.org/api/permissions.html) feature in Node.js and access non authorized modules by using process.mainModule.require(). This only affects users who had enabled the experimental permissions option with --experimental-policy.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-33p5-6c3v-v29v

больше 3 лет назад

Special crafted InPage document leads to arbitrary code execution in InPage reader.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-33p4-8hxp-x9pp

10 месяцев назад

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Nikita Advanced WordPress Backgrounds allows Code Injection. This issue affects Advanced WordPress Backgrounds: from n/a through 1.12.4.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-33p4-7h6v-86r2

почти 4 года назад

Integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBitmap function in SplashBitmap.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.10.6, as used in GPdf and kdegraphics KPDF, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-33pg-v77m-8hhv

Check Point Zone Labs ZoneAlarm Internet Security Suite 6.5.722.000, 6.1.737.000, and possibly other versions do not properly validate RegSaveKey, RegRestoreKey, and RegDeleteKey function calls, which allows local users to cause a denial of service (system crash) via a certain combination of these function calls with an HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VETFDDNT\Enum argument.

0%
Низкий
почти 4 года назад
github логотип
GHSA-33pg-m6jh-5237

Docker Swarm encrypted overlay network traffic may be unencrypted

CVSS3: 6.8
3%
Низкий
почти 3 года назад
github логотип
GHSA-33pg-fqx9-9w66

A vulnerability, which was classified as critical, was found in lakernote EasyAdmin up to 20240315. Affected is the function thumbnail of the file src/main/java/com/laker/admin/module/sys/controller/IndexController.java. The manipulation of the argument url leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The patch is identified as 23165d8cb569048c531150f194fea39f8800b8d5. It is recommended to apply a patch to fix this issue. VDB-257718 is the identifier assigned to this vulnerability.

CVSS3: 6.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-33pc-wm38-7ffg

HyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the length of a value that is saved in a session file, which allows remote attackers to execute arbitrary code via a malicious HyperTerminal session file (.ht), web site, or Telnet URL contained in an e-mail message, triggering a buffer overflow.

27%
Средний
почти 4 года назад
github логотип
GHSA-33pc-q72m-p74w

NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3.0-DEV.

CVSS3: 4.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-33pc-42rm-x55v

A reflected cross-site scripting (XSS) vulnerability in the /overview/network/ endpoint of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the charge parameter.

CVSS3: 5.4
0%
Низкий
3 месяца назад
github логотип
GHSA-33p9-qh39-m99v

Multiple SQL Injections in Frappe CRM Dashboard Controller due to unsafe concatenation of user-controlled parameters into dynamic SQL statements. This issue affects Frappe CRM: 1.53.1.

CVSS3: 8.8
0%
Низкий
2 месяца назад
github логотип
GHSA-33p9-j27p-6f2h

In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was identified. Reported by Karol Więsek.

1%
Низкий
около 1 года назад
github логотип
GHSA-33p9-3qx3-xpc6

Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable use after free vulnerability in the XFA parsing engine when handling certain types of internal instructions. Successful exploitation could lead to arbitrary code execution.

CVSS3: 8.8
5%
Низкий
больше 3 лет назад
github логотип
GHSA-33p9-3p43-82vq

Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

CVSS3: 7.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-33p8-v8q2-mx53

An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This vulnerability is similar to, but not identical to, CVE-2023-47197.

CVSS3: 7.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-33p7-vhh2-qpvp

Buffer overflow in ncurses 5.0, and the ncurses4 compatibility package as used in Red Hat Linux, allows local users to gain privileges, related to "routines for moving the physical cursor and scrolling."

0%
Низкий
почти 4 года назад
github логотип
GHSA-33p7-qrxw-8cm4

Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-0606, CVE-2013-0612, CVE-2013-0615, CVE-2013-0617, and CVE-2013-0621.

23%
Средний
больше 3 лет назад
github логотип
GHSA-33p7-cjfg-8vc5

A buffer overflow in Redis 3.2.x prior to 3.2.4 causes arbitrary code execution when a crafted command is sent. An out of bounds write vulnerability exists in the handling of the client-output-buffer-limit option during the CONFIG SET command for the Redis data structure store. A crafted CONFIG SET command can lead to an out of bounds write potentially resulting in code execution.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-33p7-c5wh-6q6g

Trend Micro Antivirus for Mac 2020 (Consumer) contains a race condition vulnerability in the Web Threat Protection Blocklist component, that if exploited, could allow an attacker to case a kernel panic or crash. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-33p6-fx42-7rf5

Harbor is vulnerable to a limited Server-Side Request Forgery (SSRF) (CVE-2020-13788)

CVSS3: 4.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-33p5-m25c-cp6w

A privilege escalation vulnerability exists in Node.js <19.6.1, <18.14.1, <16.19.1 and <14.21.3 that made it possible to bypass the experimental Permissions (https://nodejs.org/api/permissions.html) feature in Node.js and access non authorized modules by using process.mainModule.require(). This only affects users who had enabled the experimental permissions option with --experimental-policy.

CVSS3: 7.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-33p5-6c3v-v29v

Special crafted InPage document leads to arbitrary code execution in InPage reader.

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-33p4-8hxp-x9pp

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Nikita Advanced WordPress Backgrounds allows Code Injection. This issue affects Advanced WordPress Backgrounds: from n/a through 1.12.4.

CVSS3: 5.4
10 месяцев назад
github логотип
GHSA-33p4-7h6v-86r2

Integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBitmap function in SplashBitmap.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.10.6, as used in GPdf and kdegraphics KPDF, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.

22%
Средний
почти 4 года назад

Уязвимостей на страницу