Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 301 024

Количество 301 024

github логотип

GHSA-2676-4vwj-wgm4

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Magento E-Commerce Platform 1.9.0.1.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2675-7qgw-hjvx

больше 3 лет назад

AVC_DuplicateConfig() at isomedia/avc_ext.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file. There is "cfg_new->AVCLevelIndication = cfg->AVCLevelIndication;" but cfg could be NULL.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2675-54p5-24ww

почти 3 года назад

A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.2, macOS Big Sur 11.7.2, macOS Ventura 13. An app may bypass Gatekeeper checks.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2673-vwc6-q3m5

больше 3 лет назад

The Missing Device feature in Lookout allows physically proximate attackers to provide arbitrary location data via a "commonly available simple GPS location spoofer."

EPSS: Низкий
github логотип

GHSA-2673-hcr2-rj4v

больше 2 лет назад

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.3, watchOS 9.4, tvOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, iOS 16.4 and iPadOS 16.4. An app may be able to execute arbitrary code with kernel privileges

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2672-vg22-4pj7

почти 4 года назад

Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious MXF file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

EPSS: Низкий
github логотип

GHSA-266x-3x8x-xj7x

больше 3 лет назад

An improper authorization vulnerability in Palo Alto Networks Cortex XSOAR enables a remote unauthenticated attacker with network access to the Cortex XSOAR server to perform unauthorized actions through the REST API. This issue impacts: Cortex XSOAR 6.1.0 builds later than 1016923 and earlier than 1271064; Cortex XSOAR 6.2.0 builds earlier than 1271065. This issue does not impact Cortex XSOAR 5.5.0, Cortex XSOAR 6.0.0, Cortex XSOAR 6.0.1, or Cortex XSOAR 6.0.2 versions. All Cortex XSOAR instances hosted by Palo Alto Networks are upgraded to resolve this vulnerability. No additional action is required for these instances.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-266w-j5c5-474h

больше 3 лет назад

PageLayer before 1.3.5 allows reflected XSS via the font-size parameter.

EPSS: Низкий
github логотип

GHSA-266v-q3gx-4vx4

около 1 года назад

Authentication Bypass Using an Alternate Path or Channel vulnerability in MaanTheme MaanStore API allows Authentication Bypass.This issue affects MaanStore API: from n/a through 1.0.1.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-266r-h4p4-f6fp

12 месяцев назад

Integer overflow for some Intel(R) VPL software before version 24.1.4 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-266r-7mhh-hw6w

около 2 лет назад

A vulnerability, which was classified as critical, was found in Tongda OA 2017 up to 11.10. Affected is an unknown function of the file /manage/delete_query.php of the component General News. The manipulation of the argument NEWS_ID leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-243588. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-266p-jjrg-gmfx

больше 3 лет назад

** DISPUTED ** The GNU Multiple Precision Arithmetic Library (GMP) interfaces for PHP through 7.1.4 allow attackers to cause a denial of service (memory consumption and application crash) via operations on long strings. NOTE: the vendor disputes this, stating "There is no security issue here, because GMP safely aborts in case of an OOM condition. The only attack vector here is denial of service. However, if you allow attacker-controlled, unbounded allocations you have a DoS vector regardless of GMP's OOM behavior."

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-266p-f47g-vvp3

больше 3 лет назад

SQL injection vulnerability in Integry Systems LiveCart 1.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to the /category URI.

EPSS: Низкий
github логотип

GHSA-266p-f3wq-cj93

больше 3 лет назад

Linux kernel before after 2.6.12 and before 2.6.13.1 might allow attackers to cause a denial of service (Oops) via certain IPSec packets that cause alignment problems in standard multi-block cipher processors. NOTE: it is not clear whether this issue can be triggered by an attacker.

EPSS: Низкий
github логотип

GHSA-266m-wp2v-x7mq

5 месяцев назад

Microsoft Security Advisory CVE-2025-30399 | .NET Remote Code Vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-266j-p4xx-fvxr

больше 3 лет назад

dwarf.c in GNU Binutils 2.28 is vulnerable to an invalid read of size 1 during dumping of debug information from a corrupt binary. This vulnerability causes programs that conduct an analysis of binary programs, such as objdump and readelf, to crash.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-266j-gpf6-27hm

больше 3 лет назад

A CSRF vulnerability was detected in one of the admin endpoints of JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49852.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-266j-ggfg-wh9m

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the topic administration page in the RTFM extension 2.0.4 through 2.4.3 for Best Practical Solutions RT allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-266h-r2q6-xh4w

больше 3 лет назад

Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-266h-7g3r-4j2m

больше 3 лет назад

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the delay property of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-7157.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2676-4vwj-wgm4

Cross-site scripting (XSS) vulnerability in Magento E-Commerce Platform 1.9.0.1.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2675-7qgw-hjvx

AVC_DuplicateConfig() at isomedia/avc_ext.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file. There is "cfg_new->AVCLevelIndication = cfg->AVCLevelIndication;" but cfg could be NULL.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2675-54p5-24ww

A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.2, macOS Big Sur 11.7.2, macOS Ventura 13. An app may bypass Gatekeeper checks.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-2673-vwc6-q3m5

The Missing Device feature in Lookout allows physically proximate attackers to provide arbitrary location data via a "commonly available simple GPS location spoofer."

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2673-hcr2-rj4v

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.3, watchOS 9.4, tvOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, iOS 16.4 and iPadOS 16.4. An app may be able to execute arbitrary code with kernel privileges

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2672-vg22-4pj7

Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious MXF file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

2%
Низкий
почти 4 года назад
github логотип
GHSA-266x-3x8x-xj7x

An improper authorization vulnerability in Palo Alto Networks Cortex XSOAR enables a remote unauthenticated attacker with network access to the Cortex XSOAR server to perform unauthorized actions through the REST API. This issue impacts: Cortex XSOAR 6.1.0 builds later than 1016923 and earlier than 1271064; Cortex XSOAR 6.2.0 builds earlier than 1271065. This issue does not impact Cortex XSOAR 5.5.0, Cortex XSOAR 6.0.0, Cortex XSOAR 6.0.1, or Cortex XSOAR 6.0.2 versions. All Cortex XSOAR instances hosted by Palo Alto Networks are upgraded to resolve this vulnerability. No additional action is required for these instances.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-266w-j5c5-474h

PageLayer before 1.3.5 allows reflected XSS via the font-size parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-266v-q3gx-4vx4

Authentication Bypass Using an Alternate Path or Channel vulnerability in MaanTheme MaanStore API allows Authentication Bypass.This issue affects MaanStore API: from n/a through 1.0.1.

CVSS3: 9.8
0%
Низкий
около 1 года назад
github логотип
GHSA-266r-h4p4-f6fp

Integer overflow for some Intel(R) VPL software before version 24.1.4 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 4.8
0%
Низкий
12 месяцев назад
github логотип
GHSA-266r-7mhh-hw6w

A vulnerability, which was classified as critical, was found in Tongda OA 2017 up to 11.10. Affected is an unknown function of the file /manage/delete_query.php of the component General News. The manipulation of the argument NEWS_ID leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-243588. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-266p-jjrg-gmfx

** DISPUTED ** The GNU Multiple Precision Arithmetic Library (GMP) interfaces for PHP through 7.1.4 allow attackers to cause a denial of service (memory consumption and application crash) via operations on long strings. NOTE: the vendor disputes this, stating "There is no security issue here, because GMP safely aborts in case of an OOM condition. The only attack vector here is denial of service. However, if you allow attacker-controlled, unbounded allocations you have a DoS vector regardless of GMP's OOM behavior."

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-266p-f47g-vvp3

SQL injection vulnerability in Integry Systems LiveCart 1.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to the /category URI.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-266p-f3wq-cj93

Linux kernel before after 2.6.12 and before 2.6.13.1 might allow attackers to cause a denial of service (Oops) via certain IPSec packets that cause alignment problems in standard multi-block cipher processors. NOTE: it is not clear whether this issue can be triggered by an attacker.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-266m-wp2v-x7mq

Microsoft Security Advisory CVE-2025-30399 | .NET Remote Code Vulnerability

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-266j-p4xx-fvxr

dwarf.c in GNU Binutils 2.28 is vulnerable to an invalid read of size 1 during dumping of debug information from a corrupt binary. This vulnerability causes programs that conduct an analysis of binary programs, such as objdump and readelf, to crash.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-266j-gpf6-27hm

A CSRF vulnerability was detected in one of the admin endpoints of JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49852.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-266j-ggfg-wh9m

Multiple cross-site scripting (XSS) vulnerabilities in the topic administration page in the RTFM extension 2.0.4 through 2.4.3 for Best Practical Solutions RT allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-266h-r2q6-xh4w

Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 5.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-266h-7g3r-4j2m

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.2.0.9297. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the delay property of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-7157.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу