Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-33mm-7q99-mpgc

больше 3 лет назад

An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service agents could allow a local attacker to escalate privileges on affected installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

EPSS: Низкий
github логотип

GHSA-33mj-c75m-m568

больше 3 лет назад

In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.adminlog.php.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-33mh-qwc8-jxxx

больше 2 лет назад

A heap-based buffer overflow vulnerability exists in the vpnserver WpcParsePacket() functionality of SoftEther VPN 4.41-9782-beta, 5.01.9674 and 5.02. A specially crafted network packet can lead to arbitrary code execution. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-33mh-74gh-7rp5

почти 4 года назад

Improper validation of maximum size of data write to EFS file can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

EPSS: Низкий
github логотип

GHSA-33mh-4657-92h5

около 3 лет назад

Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.2.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-33mg-w6qx-r88m

больше 3 лет назад

Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 have a out-of-bounds read vulnerability. Due to insufficient input validation, an authenticated, remote attacker could send malformed SOAP packets to the target device. Successful exploit could make the device access invalid memory and might reset a process.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-33mg-r278-fh2j

больше 3 лет назад

Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to execute arbitrary OS commands by navigating to the Diagnostics Ping page and entering shell metacharacters in the Target IP address field. (In some cases, authentication can be achieved with the comtech password for the comtech account.)

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-33mf-x5r5-qqmj

больше 3 лет назад

TPview.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, which allows guest OS users to cause a host OS denial of service via unspecified vectors, a different vulnerability than CVE-2015-2339.

EPSS: Низкий
github логотип

GHSA-33mf-v24m-432m

больше 3 лет назад

In Dell EMC Isilon OneFS, the compadmin is able to run tcpdump binary with root privileges. In versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, the tcpdump binary, being run with sudo, may potentially be used by compadmin to execute arbitrary code with root privileges.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-33mf-fw4p-7m8h

больше 3 лет назад

The frame scheduling module has a Use After Free (UAF) vulnerability.Successful exploitation of this vulnerability will affect data integrity, availability, and confidentiality.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-33mf-f48h-g743

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in Yblog allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in (a) funk.php, or the (2) action parameter in (b) tem.php and (c) uss.php.

EPSS: Низкий
github логотип

GHSA-33m9-pm4r-23hx

больше 3 лет назад

Race condition in Apple iOS 4.0 through 4.1 for iPhone 3G and later allows physically proximate attackers to bypass the passcode lock by making a call from the Emergency Call screen, then quickly pressing the Sleep/Wake button.

EPSS: Низкий
github логотип

GHSA-33m9-pfw5-gmf2

больше 3 лет назад

In Xiaomi router R3600, ROM version<1.0.20, the connection service can be injected through the web interface, resulting in stack overflow or remote code execution.

EPSS: Низкий
github логотип

GHSA-33m8-f4hw-wm3q

около 3 лет назад

usememos/memos Denial of Service vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-33m7-qmp2-vj6x

больше 3 лет назад

ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/ URI.

EPSS: Низкий
github логотип

GHSA-33m7-2r3h-jgfx

11 месяцев назад

Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-33m6-wpwp-3cw5

почти 4 года назад

Multiple unspecified vulnerabilities in the Vsftpd Webmin module before 1.3b for the Vsftpd server have unknown impact and attack vectors related to "Some security issues."

EPSS: Низкий
github логотип

GHSA-33m6-q9v5-62r7

около 3 лет назад

go.uuid has Predictable UUID Identifiers

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-33m5-rgm6-r8x3

около 3 лет назад

Microsoft Business Central Information Disclosure Vulnerability.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-33m4-frvp-3wr7

больше 3 лет назад

An information disclosure vulnerability in Web Vulnerability Scan profile of Fortinet's FortiWeb version 6.2.x below 6.2.4 and version 6.3.x below 6.3.5 may allow a remote authenticated attacker to read the password used by the FortiWeb scanner to access the device defined in the scan profile.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-33mm-7q99-mpgc

An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service agents could allow a local attacker to escalate privileges on affected installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-33mj-c75m-m568

In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.adminlog.php.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-33mh-qwc8-jxxx

A heap-based buffer overflow vulnerability exists in the vpnserver WpcParsePacket() functionality of SoftEther VPN 4.41-9782-beta, 5.01.9674 and 5.02. A specially crafted network packet can lead to arbitrary code execution. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.

CVSS3: 9
1%
Низкий
больше 2 лет назад
github логотип
GHSA-33mh-74gh-7rp5

Improper validation of maximum size of data write to EFS file can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

0%
Низкий
почти 4 года назад
github логотип
GHSA-33mh-4657-92h5

Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.2.

CVSS3: 6.1
4%
Низкий
около 3 лет назад
github логотип
GHSA-33mg-w6qx-r88m

Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 have a out-of-bounds read vulnerability. Due to insufficient input validation, an authenticated, remote attacker could send malformed SOAP packets to the target device. Successful exploit could make the device access invalid memory and might reset a process.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-33mg-r278-fh2j

Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to execute arbitrary OS commands by navigating to the Diagnostics Ping page and entering shell metacharacters in the Target IP address field. (In some cases, authentication can be achieved with the comtech password for the comtech account.)

CVSS3: 7.2
2%
Низкий
больше 3 лет назад
github логотип
GHSA-33mf-x5r5-qqmj

TPview.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, which allows guest OS users to cause a host OS denial of service via unspecified vectors, a different vulnerability than CVE-2015-2339.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-33mf-v24m-432m

In Dell EMC Isilon OneFS, the compadmin is able to run tcpdump binary with root privileges. In versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, the tcpdump binary, being run with sudo, may potentially be used by compadmin to execute arbitrary code with root privileges.

CVSS3: 6.7
1%
Низкий
больше 3 лет назад
github логотип
GHSA-33mf-fw4p-7m8h

The frame scheduling module has a Use After Free (UAF) vulnerability.Successful exploitation of this vulnerability will affect data integrity, availability, and confidentiality.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-33mf-f48h-g743

Multiple cross-site scripting (XSS) vulnerabilities in Yblog allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in (a) funk.php, or the (2) action parameter in (b) tem.php and (c) uss.php.

1%
Низкий
почти 4 года назад
github логотип
GHSA-33m9-pm4r-23hx

Race condition in Apple iOS 4.0 through 4.1 for iPhone 3G and later allows physically proximate attackers to bypass the passcode lock by making a call from the Emergency Call screen, then quickly pressing the Sleep/Wake button.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-33m9-pfw5-gmf2

In Xiaomi router R3600, ROM version<1.0.20, the connection service can be injected through the web interface, resulting in stack overflow or remote code execution.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-33m8-f4hw-wm3q

usememos/memos Denial of Service vulnerability

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-33m7-qmp2-vj6x

ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/ URI.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-33m7-2r3h-jgfx

Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.

CVSS3: 5.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-33m6-wpwp-3cw5

Multiple unspecified vulnerabilities in the Vsftpd Webmin module before 1.3b for the Vsftpd server have unknown impact and attack vectors related to "Some security issues."

0%
Низкий
почти 4 года назад
github логотип
GHSA-33m6-q9v5-62r7

go.uuid has Predictable UUID Identifiers

CVSS3: 9.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-33m5-rgm6-r8x3

Microsoft Business Central Information Disclosure Vulnerability.

CVSS3: 4.4
2%
Низкий
около 3 лет назад
github логотип
GHSA-33m4-frvp-3wr7

An information disclosure vulnerability in Web Vulnerability Scan profile of Fortinet's FortiWeb version 6.2.x below 6.2.4 and version 6.3.x below 6.3.5 may allow a remote authenticated attacker to read the password used by the FortiWeb scanner to access the device defined in the scan profile.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу