Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-333x-jcc3-m545

почти 4 года назад

Remote Desktop Commander Suite Agent before v4.8 contains an unquoted service path which allows attackers to escalate privileges to the system level.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-333x-9vgq-v2j4

больше 8 лет назад

Directory Traversal in geddy

EPSS: Средний
github логотип

GHSA-333w-rxj3-f55r

больше 7 лет назад

Regular Expression Denial Of Service in uri-js

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-333w-grm8-fgcg

больше 3 лет назад

The vulnerability allows a successful attacker to bypass the integrity check of FW uploaded to the free@home System Access Point.

EPSS: Низкий
github логотип

GHSA-333v-68xh-8mmq

23 дня назад

RustFS's RPC signature verification logs shared secret

EPSS: Низкий
github логотип

GHSA-333r-822h-h7j4

около 1 месяца назад

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Noor Alam Easy Media Download easy-media-download allows Reflection Injection.This issue affects Easy Media Download: from n/a through <= 1.1.11.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-333p-49h6-q8x3

11 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in oooorgle Quotes llama allows DOM-Based XSS. This issue affects Quotes llama: from n/a through 3.1.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-333m-q4jm-qjq4

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: x86/sgx: Fix deadlock in SGX NUMA node search When the current node doesn't have an EPC section configured by firmware and all other EPC sections are used up, CPU can get stuck inside the while loop that looks for an available EPC page from remote nodes indefinitely, leading to a soft lockup. Note how nid_of_current will never be equal to nid in that while loop because nid_of_current is not set in sgx_numa_mask. Also worth mentioning is that it's perfectly fine for the firmware not to setup an EPC section on a node. While setting up an EPC section on each node can enhance performance, it is not a requirement for functionality. Rework the loop to start and end on *a* node that has SGX memory. This avoids the deadlock looking for the current SGX-lacking node to show up in the loop when it never will.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-333m-gvxr-m7wp

больше 3 лет назад

The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webgeneratesslcfg function.

EPSS: Низкий
github логотип

GHSA-333m-9882-vwgr

больше 3 лет назад

A reachable Object::dictLookup assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to the lack of a check for the dict data type, as demonstrated by use of the FileSpec class (in FileSpec.cc) in pdfdetach.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-333m-4m49-38wm

почти 3 года назад

An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to the Configuration Dashboard page. Input validation and a proper XML parser configuration are missing. For an external attacker, it is very difficult to exploit this, because a few dynamically created parameters such as Jsession-id, a CSRF token, and an Nxsrf token would be needed. The attack can realistically only be performed by an internal user.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-333j-26m2-5w78

больше 3 лет назад

Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7.3, 11.2.0.1, and 11.2.0.2 allows remote authenticated users to affect integrity, related to SYSDBA.

EPSS: Низкий
github логотип

GHSA-333h-qmh2-4xw6

больше 3 лет назад

The Asus ZenFone 4 Selfie Android device with a build fingerprint of asus/WW_Z01M/ASUS_Z01M_1:7.1.1/NMF26F/WW_71.50.395.57_20180913:user/release-keys contains a pre-installed app with a package name of com.asus.loguploaderproxy app (versionCode=1570000020, versionName=7.0.0.4_170901) that allows other pre-installed apps to perform command execution via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.

EPSS: Низкий
github логотип

GHSA-333h-f5pr-9xg9

больше 3 лет назад

Due to insecure session management, SAP Enable Now allows an unauthenticated attacker to gain access to user's account. On successful exploitation, an attacker can view or modify user data causing limited impact on confidentiality and integrity of the application.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-333g-rpr4-7hxq

больше 6 лет назад

rest-client Gem Contains Malicious Code

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-333g-r8qf-r22c

почти 3 года назад

SQL injection vulnerability found in PrestaShop bdroppy v.2.2.12 and before allowing a remote attacker to gain privileges via the BdroppyCronModuleFrontController::importProducts component.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-333g-8frm-xc2h

больше 2 лет назад

SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the friendmonths parameter within the /QueryView.php.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-333g-4p9h-pgjv

больше 2 лет назад

A vulnerability in a specific Cisco ISE CLI command could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, an attacker must have valid Read-only-level privileges or higher on the affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted CLI command. A successful exploit could allow the attacker to elevate privileges to root.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-333f-2r4g-87jc

больше 3 лет назад

Stack-based buffer overflow in the VImpX.VImpAX ActiveX control (VImpX.ocx) 4.8.8.0 in DB Software Laboratory VImp X, possibly 4.7.7, allows remote attackers to execute arbitrary code via a long LogFile property.

EPSS: Средний
github логотип

GHSA-3339-3jp2-pq45

больше 2 лет назад

An authenticated, remote attacker may use a out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into memory which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-333x-jcc3-m545

Remote Desktop Commander Suite Agent before v4.8 contains an unquoted service path which allows attackers to escalate privileges to the system level.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-333x-9vgq-v2j4

Directory Traversal in geddy

69%
Средний
больше 8 лет назад
github логотип
GHSA-333w-rxj3-f55r

Regular Expression Denial Of Service in uri-js

CVSS3: 6.5
0%
Низкий
больше 7 лет назад
github логотип
GHSA-333w-grm8-fgcg

The vulnerability allows a successful attacker to bypass the integrity check of FW uploaded to the free@home System Access Point.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-333v-68xh-8mmq

RustFS's RPC signature verification logs shared secret

0%
Низкий
23 дня назад
github логотип
GHSA-333r-822h-h7j4

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Noor Alam Easy Media Download easy-media-download allows Reflection Injection.This issue affects Easy Media Download: from n/a through <= 1.1.11.

CVSS3: 5.4
0%
Низкий
около 1 месяца назад
github логотип
GHSA-333p-49h6-q8x3

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in oooorgle Quotes llama allows DOM-Based XSS. This issue affects Quotes llama: from n/a through 3.1.0.

CVSS3: 6.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-333m-q4jm-qjq4

In the Linux kernel, the following vulnerability has been resolved: x86/sgx: Fix deadlock in SGX NUMA node search When the current node doesn't have an EPC section configured by firmware and all other EPC sections are used up, CPU can get stuck inside the while loop that looks for an available EPC page from remote nodes indefinitely, leading to a soft lockup. Note how nid_of_current will never be equal to nid in that while loop because nid_of_current is not set in sgx_numa_mask. Also worth mentioning is that it's perfectly fine for the firmware not to setup an EPC section on a node. While setting up an EPC section on each node can enhance performance, it is not a requirement for functionality. Rework the loop to start and end on *a* node that has SGX memory. This avoids the deadlock looking for the current SGX-lacking node to show up in the loop when it never will.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-333m-gvxr-m7wp

The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webgeneratesslcfg function.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-333m-9882-vwgr

A reachable Object::dictLookup assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to the lack of a check for the dict data type, as demonstrated by use of the FileSpec class (in FileSpec.cc) in pdfdetach.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-333m-4m49-38wm

An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to the Configuration Dashboard page. Input validation and a proper XML parser configuration are missing. For an external attacker, it is very difficult to exploit this, because a few dynamically created parameters such as Jsession-id, a CSRF token, and an Nxsrf token would be needed. The attack can realistically only be performed by an internal user.

CVSS3: 6.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-333j-26m2-5w78

Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7.3, 11.2.0.1, and 11.2.0.2 allows remote authenticated users to affect integrity, related to SYSDBA.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-333h-qmh2-4xw6

The Asus ZenFone 4 Selfie Android device with a build fingerprint of asus/WW_Z01M/ASUS_Z01M_1:7.1.1/NMF26F/WW_71.50.395.57_20180913:user/release-keys contains a pre-installed app with a package name of com.asus.loguploaderproxy app (versionCode=1570000020, versionName=7.0.0.4_170901) that allows other pre-installed apps to perform command execution via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that exported their capabilities to other pre-installed app.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-333h-f5pr-9xg9

Due to insecure session management, SAP Enable Now allows an unauthenticated attacker to gain access to user's account. On successful exploitation, an attacker can view or modify user data causing limited impact on confidentiality and integrity of the application.

CVSS3: 9.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-333g-rpr4-7hxq

rest-client Gem Contains Malicious Code

CVSS3: 9.8
2%
Низкий
больше 6 лет назад
github логотип
GHSA-333g-r8qf-r22c

SQL injection vulnerability found in PrestaShop bdroppy v.2.2.12 and before allowing a remote attacker to gain privileges via the BdroppyCronModuleFrontController::importProducts component.

CVSS3: 9.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-333g-8frm-xc2h

SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the friendmonths parameter within the /QueryView.php.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-333g-4p9h-pgjv

A vulnerability in a specific Cisco ISE CLI command could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, an attacker must have valid Read-only-level privileges or higher on the affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted CLI command. A successful exploit could allow the attacker to elevate privileges to root.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-333f-2r4g-87jc

Stack-based buffer overflow in the VImpX.VImpAX ActiveX control (VImpX.ocx) 4.8.8.0 in DB Software Laboratory VImp X, possibly 4.7.7, allows remote attackers to execute arbitrary code via a long LogFile property.

20%
Средний
больше 3 лет назад
github логотип
GHSA-3339-3jp2-pq45

An authenticated, remote attacker may use a out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into memory which can lead to a denial-of-service condition, memory overwriting, or remote code execution.

CVSS3: 8.8
5%
Низкий
больше 2 лет назад

Уязвимостей на страницу