Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-33fw-34vg-hgjh

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: CDC-NCM: avoid overflow in sanity checking A broken device may give an extreme offset like 0xFFF0 and a reasonable length for a fragment. In the sanity check as formulated now, this will create an integer overflow, defeating the sanity check. Both offset and offset + len need to be checked in such a manner that no overflow can occur. And those quantities should be unsigned.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-33fr-rpxm-q4fp

около 2 лет назад

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gopi Ramasamy Email download link.This issue affects Email download link: from n/a through 3.7.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-33fr-2jgq-xxjj

больше 3 лет назад

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-47123. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the xHCI component. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of the hypervisor. Was ZDI-CAN-10031.

EPSS: Низкий
github логотип

GHSA-33fq-qm4m-cjw3

больше 3 лет назад

baserCMS Access Control Bypass

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-33fq-cj88-4v27

больше 2 лет назад

An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes, e.g., one with only an unknown transit attribute.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-33fp-rvp9-r3r8

больше 2 лет назад

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Joel James Disqus Conditional Load plugin <= 11.0.6 versions.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-33fp-fhhx-5667

больше 3 лет назад

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, a buffer overwrite may occur in ProcSetReqInternal() due to missing length check.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-33fm-9xj7-6vfq

больше 3 лет назад

SQL injection vulnerability in the Time Spent module 6.x and 7.x for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-33fj-x2h7-rxj3

почти 4 года назад

Unknown vulnerability in the TCP/IP stack for Sun Solaris 8 and 9 allows local users to cause a denial of service (system panic) via unknown vectors.

EPSS: Низкий
github логотип

GHSA-33fh-jhp9-q8w6

больше 2 лет назад

Fuge CMS v1.0 contains an Open Redirect vulnerability in member/RegisterAct.java.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-33fh-cmjr-7j9h

почти 4 года назад

Untrusted search path vulnerability in Gauche before 0.8.6-r1 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build directory, which is part of the RUNPATH.

EPSS: Низкий
github логотип

GHSA-33fh-7hc9-vgc4

больше 2 лет назад

Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 20.005.30334 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-33fh-7gm7-q4rf

больше 3 лет назад

In SAP HANA Extended Application Services, 1.0, some general server statistics and status information could be retrieved by unauthorized users.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-33fh-4pvq-9x35

11 месяцев назад

A flaw was found in the 389-ds-base LDAP Server. This issue occurs when issuing a Modify DN LDAP operation through the ldap protocol, when the function return value is not tested and a NULL pointer is dereferenced. If a privileged user performs a ldap MODDN operation after a failed operation, it could lead to a Denial of Service (DoS) or system crash.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-33fg-vcj3-g326

около 2 лет назад

Transient DOS in Multi-Mode Call Processor due to UE failure because of heap leakage.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-33fg-v3g6-559q

больше 3 лет назад

Due to insufficient input validation, SAP Business Objects - version 420, allows an authenticated attacker to submit a malicious request through an allowed operation. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-33fg-f8wx-chw2

около 1 года назад

Some Huawei home routers have a connection hijacking vulnerability. Successful exploitation of this vulnerability may cause DoS or information leakage.(Vulnerability ID:HWPSIRT-2023-76605) This vulnerability has been assigned a (CVE)ID:CVE-2023-7266

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-33fg-76g4-jv5r

11 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shinetheme Traveler.This issue affects Traveler: from n/a through 3.1.8.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-33fg-65f8-58pv

больше 3 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 5.6.49 and prior, 5.7.31 and prior and 8.0.21 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-33ff-v6qp-8qqf

больше 2 лет назад

A vulnerability was found in rkhunter Rootkit Hunter 1.4.4/1.4.6. It has been classified as problematic. Affected is an unknown function of the file /var/log/rkhunter.log. The manipulation leads to sensitive information in log files. An attack has to be approached locally. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-237516.

CVSS3: 2.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-33fw-34vg-hgjh

In the Linux kernel, the following vulnerability has been resolved: CDC-NCM: avoid overflow in sanity checking A broken device may give an extreme offset like 0xFFF0 and a reasonable length for a fragment. In the sanity check as formulated now, this will create an integer overflow, defeating the sanity check. Both offset and offset + len need to be checked in such a manner that no overflow can occur. And those quantities should be unsigned.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-33fr-rpxm-q4fp

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gopi Ramasamy Email download link.This issue affects Email download link: from n/a through 3.7.

CVSS3: 5.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-33fr-2jgq-xxjj

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-47123. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the xHCI component. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of the hypervisor. Was ZDI-CAN-10031.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-33fq-qm4m-cjw3

baserCMS Access Control Bypass

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-33fq-cj88-4v27

An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes, e.g., one with only an unknown transit attribute.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-33fp-rvp9-r3r8

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Joel James Disqus Conditional Load plugin <= 11.0.6 versions.

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-33fp-fhhx-5667

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, a buffer overwrite may occur in ProcSetReqInternal() due to missing length check.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-33fm-9xj7-6vfq

SQL injection vulnerability in the Time Spent module 6.x and 7.x for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-33fj-x2h7-rxj3

Unknown vulnerability in the TCP/IP stack for Sun Solaris 8 and 9 allows local users to cause a denial of service (system panic) via unknown vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-33fh-jhp9-q8w6

Fuge CMS v1.0 contains an Open Redirect vulnerability in member/RegisterAct.java.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-33fh-cmjr-7j9h

Untrusted search path vulnerability in Gauche before 0.8.6-r1 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build directory, which is part of the RUNPATH.

0%
Низкий
почти 4 года назад
github логотип
GHSA-33fh-7hc9-vgc4

Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 20.005.30334 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-33fh-7gm7-q4rf

In SAP HANA Extended Application Services, 1.0, some general server statistics and status information could be retrieved by unauthorized users.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-33fh-4pvq-9x35

A flaw was found in the 389-ds-base LDAP Server. This issue occurs when issuing a Modify DN LDAP operation through the ldap protocol, when the function return value is not tested and a NULL pointer is dereferenced. If a privileged user performs a ldap MODDN operation after a failed operation, it could lead to a Denial of Service (DoS) or system crash.

CVSS3: 4.9
1%
Низкий
11 месяцев назад
github логотип
GHSA-33fg-vcj3-g326

Transient DOS in Multi-Mode Call Processor due to UE failure because of heap leakage.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-33fg-v3g6-559q

Due to insufficient input validation, SAP Business Objects - version 420, allows an authenticated attacker to submit a malicious request through an allowed operation. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-33fg-f8wx-chw2

Some Huawei home routers have a connection hijacking vulnerability. Successful exploitation of this vulnerability may cause DoS or information leakage.(Vulnerability ID:HWPSIRT-2023-76605) This vulnerability has been assigned a (CVE)ID:CVE-2023-7266

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-33fg-76g4-jv5r

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shinetheme Traveler.This issue affects Traveler: from n/a through 3.1.8.

CVSS3: 9.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-33fg-65f8-58pv

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 5.6.49 and prior, 5.7.31 and prior and 8.0.21 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-33ff-v6qp-8qqf

A vulnerability was found in rkhunter Rootkit Hunter 1.4.4/1.4.6. It has been classified as problematic. Affected is an unknown function of the file /var/log/rkhunter.log. The manipulation leads to sensitive information in log files. An attack has to be approached locally. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-237516.

CVSS3: 2.5
больше 2 лет назад

Уязвимостей на страницу