Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 300 915

Количество 300 915

github логотип

GHSA-25wx-2r9g-p2hv

больше 3 лет назад

In the Android kernel in i2c driver there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-25ww-mhx2-69ff

5 месяцев назад

An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to 0, 1 or 2 in /administer/selectionnode/framesSelectionNetworks.asp.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-25wv-pf2x-9jpv

больше 3 лет назад

Buffer overflow in Composer in Netscape 4.77 allows local users to overwrite process memory and execute arbitrary code via a font tag with a long face attribute.

EPSS: Низкий
github логотип

GHSA-25wr-cfxr-69vm

больше 3 лет назад

Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field names and custom SLA names via an Information Disclosure vulnerability in the /secure/QueryComponent!Default.jspa endpoint. The affected versions are before version 8.5.8, and from version 8.6.0 before 8.11.1.

CVSS3: 5.3
EPSS: Критический
github логотип

GHSA-25wr-8m9x-v3pr

больше 3 лет назад

The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3376, CVE-2016-7185, and CVE-2016-7211.

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-25wq-m5r4-rrm3

6 месяцев назад

Deserialization of Untrusted Data vulnerability in themeton Dash allows Object Injection. This issue affects Dash: from n/a through 1.3.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-25wm-p4q5-cvgw

больше 3 лет назад

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-25wj-x94f-xxw3

больше 3 лет назад

The JPEGLSCodec::DecodeExtent function in MediaStorageAndFileFormat/gdcmJPEGLSCodec.cxx in Grassroots DICOM (aka GDCM) before 2.6.2 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (application crash) via an embedded JPEG-LS image with dimensions larger than the selected region in a (1) two-dimensional or (2) three-dimensional DICOM image file, which triggers an out-of-bounds read.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-25wj-phmw-qw67

больше 3 лет назад

Vulnerability in the Oracle Application Express component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Application Express accessible data as well as unauthorized read access to a subset of Oracle Application Express accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).

EPSS: Низкий
github логотип

GHSA-25wj-f645-7mjg

больше 3 лет назад

X-Micro WLAN 11b Broadband Router 1.2.2, 1.2.2.3, 1.2.2.4, and 1.6.0.0 has a hardcoded "super" username and password, which could allow remote attackers to gain access.

EPSS: Низкий
github логотип

GHSA-25wj-5m66-r5mg

больше 3 лет назад

SAP Internet Transaction Server (ITS) 6200.X.X has Reflected Cross Site Scripting (XSS) via certain wgate URIs. NOTE: the vendor has reportedly indicated that there will not be any further releases of this product.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-25wh-8v9q-4p3q

больше 3 лет назад

Remote attackers can cause a system crash through ipintr() in ipq in OpenBSD.

EPSS: Низкий
github логотип

GHSA-25wg-q69h-xh22

больше 3 лет назад

The Photos in Wifi application 1.0.1 for iOS has directory traversal via the ext parameter to assets-library://asset/asset.php.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-25wg-pp2p-rfw9

больше 3 лет назад

A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1167.

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-25wf-7x6c-wmpf

18 дней назад

Moodle does not properly enforce MFA

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-25wc-vm27-vmmq

больше 3 лет назад

A vulnerability has been identified in TeleControl Server Basic < V3.1. An authenticated attacker with a low-privileged account to the TeleControl Server Basic's port 8000/tcp could escalate his privileges and perform administrative operations.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-25w9-wqfq-gwqx

11 месяцев назад

SiYuan has an arbitrary file read and path traversal via /api/export/exportResources

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-25w9-qw26-8c4r

больше 3 лет назад

Stack-based buffer overflow in the image tooltip implementation in Trillian before 3.1.12.0 allows remote attackers to execute arbitrary code via a long image filename, related to "AIM IMG Tag Parsing."

EPSS: Средний
github логотип

GHSA-25w9-jxhc-6r43

около 1 года назад

The Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters submitted during form entries like 'after_html' in versions before 2.05.03 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-25w9-jc8c-rx9w

почти 3 года назад

Use After Free vulnerability in Linux Kernel allows Privilege Escalation. An improper Update of Reference Count in io_uring leads to Use-After-Free and Local Privilege Escalation. When io_msg_ring was invoked with a fixed file, it called io_fput_file() which improperly decreased its reference count (leading to Use-After-Free and Local Privilege Escalation). Fixed files are permanently registered to the ring, and should not be put separately. We recommend upgrading past commit https://github.com/torvalds/linux/commit/fc7222c3a9f56271fba02aabbfbae999042f1679 https://github.com/torvalds/linux/commit/fc7222c3a9f56271fba02aabbfbae999042f1679

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-25wx-2r9g-p2hv

In the Android kernel in i2c driver there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 6.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-25ww-mhx2-69ff

An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to 0, 1 or 2 in /administer/selectionnode/framesSelectionNetworks.asp.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-25wv-pf2x-9jpv

Buffer overflow in Composer in Netscape 4.77 allows local users to overwrite process memory and execute arbitrary code via a font tag with a long face attribute.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-25wr-cfxr-69vm

Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field names and custom SLA names via an Information Disclosure vulnerability in the /secure/QueryComponent!Default.jspa endpoint. The affected versions are before version 8.5.8, and from version 8.6.0 before 8.11.1.

CVSS3: 5.3
93%
Критический
больше 3 лет назад
github логотип
GHSA-25wr-8m9x-v3pr

The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3376, CVE-2016-7185, and CVE-2016-7211.

CVSS3: 7.8
10%
Средний
больше 3 лет назад
github логотип
GHSA-25wq-m5r4-rrm3

Deserialization of Untrusted Data vulnerability in themeton Dash allows Object Injection. This issue affects Dash: from n/a through 1.3.

CVSS3: 9.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-25wm-p4q5-cvgw

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-25wj-x94f-xxw3

The JPEGLSCodec::DecodeExtent function in MediaStorageAndFileFormat/gdcmJPEGLSCodec.cxx in Grassroots DICOM (aka GDCM) before 2.6.2 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (application crash) via an embedded JPEG-LS image with dimensions larger than the selected region in a (1) two-dimensional or (2) three-dimensional DICOM image file, which triggers an out-of-bounds read.

CVSS3: 8.2
2%
Низкий
больше 3 лет назад
github логотип
GHSA-25wj-phmw-qw67

Vulnerability in the Oracle Application Express component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Application Express accessible data as well as unauthorized read access to a subset of Oracle Application Express accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-25wj-f645-7mjg

X-Micro WLAN 11b Broadband Router 1.2.2, 1.2.2.3, 1.2.2.4, and 1.6.0.0 has a hardcoded "super" username and password, which could allow remote attackers to gain access.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-25wj-5m66-r5mg

SAP Internet Transaction Server (ITS) 6200.X.X has Reflected Cross Site Scripting (XSS) via certain wgate URIs. NOTE: the vendor has reportedly indicated that there will not be any further releases of this product.

CVSS3: 6.1
3%
Низкий
больше 3 лет назад
github логотип
GHSA-25wh-8v9q-4p3q

Remote attackers can cause a system crash through ipintr() in ipq in OpenBSD.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-25wg-q69h-xh22

The Photos in Wifi application 1.0.1 for iOS has directory traversal via the ext parameter to assets-library://asset/asset.php.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-25wg-pp2p-rfw9

A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1167.

CVSS3: 7.8
13%
Средний
больше 3 лет назад
github логотип
GHSA-25wf-7x6c-wmpf

Moodle does not properly enforce MFA

CVSS3: 5.3
0%
Низкий
18 дней назад
github логотип
GHSA-25wc-vm27-vmmq

A vulnerability has been identified in TeleControl Server Basic < V3.1. An authenticated attacker with a low-privileged account to the TeleControl Server Basic's port 8000/tcp could escalate his privileges and perform administrative operations.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-25w9-wqfq-gwqx

SiYuan has an arbitrary file read and path traversal via /api/export/exportResources

CVSS3: 7.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-25w9-qw26-8c4r

Stack-based buffer overflow in the image tooltip implementation in Trillian before 3.1.12.0 allows remote attackers to execute arbitrary code via a long image filename, related to "AIM IMG Tag Parsing."

27%
Средний
больше 3 лет назад
github логотип
GHSA-25w9-jxhc-6r43

The Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters submitted during form entries like 'after_html' in versions before 2.05.03 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS3: 8.3
0%
Низкий
около 1 года назад
github логотип
GHSA-25w9-jc8c-rx9w

Use After Free vulnerability in Linux Kernel allows Privilege Escalation. An improper Update of Reference Count in io_uring leads to Use-After-Free and Local Privilege Escalation. When io_msg_ring was invoked with a fixed file, it called io_fput_file() which improperly decreased its reference count (leading to Use-After-Free and Local Privilege Escalation). Fixed files are permanently registered to the ring, and should not be put separately. We recommend upgrading past commit https://github.com/torvalds/linux/commit/fc7222c3a9f56271fba02aabbfbae999042f1679 https://github.com/torvalds/linux/commit/fc7222c3a9f56271fba02aabbfbae999042f1679

CVSS3: 7.8
0%
Низкий
почти 3 года назад

Уязвимостей на страницу