Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-32x8-xhwp-vhg9

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: u_serial: Fix the issue that gs_start_io crashed due to accessing null pointer Considering that in some extreme cases, when u_serial driver is accessed by multiple threads, Thread A is executing the open operation and calling the gs_open, Thread B is executing the disconnect operation and calling the gserial_disconnect function,The port->port_usb pointer will be set to NULL. E.g. Thread A Thread B gs_open() gadget_unbind_driver() gs_start_io() composite_disconnect() gs_start_rx() gserial_disconnect() ... ... spin_unlock(&port->port_lock) status = usb_ep_queue() spin_lock(&port->port_lock) spin_lock(&port->port_lock) port->port_usb = NULL gs_free_requests(port->port_usb->in) spin_u...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-32x8-p2xx-7jp5

больше 3 лет назад

Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-32x8-mv4r-c7xp

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Simple Plugins Target Notifications allows Reflected XSS.This issue affects Target Notifications: from n/a through 1.1.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-32x7-fpgq-gpw8

больше 3 лет назад

rdesktop versions up to and including v1.8.3 contain several Out-Of- Bounds Reads in the file secure.c that result in a Denial of Service (segfault).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-32x7-c7f5-m8mm

больше 3 лет назад

Google Chrome before 8.0.552.215 does not properly restrict privileged extensions, which allows remote attackers to cause a denial of service (memory corruption) via a crafted extension.

EPSS: Низкий
github логотип

GHSA-32x6-v639-gvj8

больше 3 лет назад

An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. The issue involves the "Kernel" component. It allows local users to bypass intended memory-read restrictions or cause a denial of service (system crash).

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-32x6-qvw6-mxj4

почти 4 года назад

Forwarding of confidentials headers to third parties in fluture-node

CVSS3: 2.6
EPSS: Низкий
github логотип

GHSA-32x6-6wch-qrgg

больше 3 лет назад

The imdb-widget plugin before 1.0.9 for WordPress has Local File Inclusion.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-32x6-3vx9-jwfc

больше 2 лет назад

A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the availability of the web page.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-32x5-wqvr-v5j9

больше 3 лет назад

CSRF in admin/ajax-hub.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to post a comment on any article via a crafted request.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-32x5-p6vh-hgrq

больше 3 лет назад

Cross Site Scripting (XSS) vulnerability in HuCart 5.7.4 via nickname in index.php.

EPSS: Низкий
github логотип

GHSA-32x5-jw55-c96h

больше 2 лет назад

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Pensopay WooCommerce PensoPay plugin <= 6.3.1 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-32x5-6p4q-q8jh

больше 3 лет назад

Magento Information Disclosure via File upload functionality

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-32x5-673x-7q8q

больше 3 лет назад

"HCL Marketing Platform is vulnerable to cross-site scripting during addition of new users and also while searching for users in Dashboard, potentially giving an attacker ability to inject malicious code into the system. "

EPSS: Низкий
github логотип

GHSA-32x4-wf82-frg6

больше 3 лет назад

The CIP dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (memory consumption) via a malformed packet.

EPSS: Низкий
github логотип

GHSA-32x4-2mw2-5hjv

больше 3 лет назад

A vulnerability in SonicOS where the HTTP server response leaks partial memory by sending a crafted HTTP request, this can potentially lead to an internal sensitive data disclosure vulnerability.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-32x3-7jmh-qgfj

больше 3 лет назад

plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to execute arbitrary PHP code via PHP sequences in the sort parameter, which is processed by create_function.

EPSS: Низкий
github логотип

GHSA-32x3-2qh2-v3w9

больше 3 лет назад

A vulnerability in the configuration archive functionality of Cisco DNA Center could allow any privilege-level authenticated, remote attacker to obtain the full unmasked running configuration of managed devices. The vulnerability is due to the configuration archives files being stored in clear text, which can be retrieved by various API calls. An attacker could exploit this vulnerability by authenticating to the device and executing a series of API calls. A successful exploit could allow the attacker to retrieve the full unmasked running configurations of managed devices.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-32x2-f5q9-2h3f

больше 3 лет назад

In MPLS environments, receipt of a specific SNMP packet may cause the routing protocol daemon (RPD) process to crash and restart. By continuously sending a specially crafted SNMP packet, an attacker can repetitively crash the RPD process causing prolonged denial of service. No other Juniper Networks products or platforms are affected by this issue. Affected releases are Juniper Networks Junos OS : 12.1X46 versions prior to 12.1X46-D77 on SRX Series; 12.3 versions prior to 12.3R12-S10; 12.3X48 versions prior to 12.3X48-D75 on SRX Series; 14.1X53 versions prior to 14.1X53-D48 on EX/QFX series; 15.1 versions prior to 15.1R4-S9, 15.1R7-S2; 15.1F6 versions prior to 15.1F6-S11; 15.1X49 versions prior to 15.1X49-D141, 15.1X49-D144, 15.1X49-D150 on SRX Series; 15.1X53 versions prior to 15.1X53-D234 on QFX5200/QFX5110 Series; 15.1X53 versions prior to 15.1X53-D68 on QFX10K Series; 15.1X53 versions prior to 15.1X53-D471, 15.1X53-D490 on NFX Series; 15.1X53 versions prior to 15.1X53-D590 on EX...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-32wx-p4x4-cg2v

больше 3 лет назад

Buffer overflow occurs when emulated RPMB is used due to sector size assumptions in the TA rollback protection logic. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in MDM9206, MDM9607, MDM9650, MDM9655, MSM8996AU, QCS404, QCS605, Qualcomm 215, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 8CX, SDA660, SDM439, SDM630, SDM660, Snapdragon_High_Med_2016, SXR1130

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-32x8-xhwp-vhg9

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: u_serial: Fix the issue that gs_start_io crashed due to accessing null pointer Considering that in some extreme cases, when u_serial driver is accessed by multiple threads, Thread A is executing the open operation and calling the gs_open, Thread B is executing the disconnect operation and calling the gserial_disconnect function,The port->port_usb pointer will be set to NULL. E.g. Thread A Thread B gs_open() gadget_unbind_driver() gs_start_io() composite_disconnect() gs_start_rx() gserial_disconnect() ... ... spin_unlock(&port->port_lock) status = usb_ep_queue() spin_lock(&port->port_lock) spin_lock(&port->port_lock) port->port_usb = NULL gs_free_requests(port->port_usb->in) spin_u...

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-32x8-p2xx-7jp5

Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12, tvOS 12, watchOS 5, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-32x8-mv4r-c7xp

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Simple Plugins Target Notifications allows Reflected XSS.This issue affects Target Notifications: from n/a through 1.1.1.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-32x7-fpgq-gpw8

rdesktop versions up to and including v1.8.3 contain several Out-Of- Bounds Reads in the file secure.c that result in a Denial of Service (segfault).

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-32x7-c7f5-m8mm

Google Chrome before 8.0.552.215 does not properly restrict privileged extensions, which allows remote attackers to cause a denial of service (memory corruption) via a crafted extension.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-32x6-v639-gvj8

An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. The issue involves the "Kernel" component. It allows local users to bypass intended memory-read restrictions or cause a denial of service (system crash).

CVSS3: 6.6
0%
Низкий
больше 3 лет назад
github логотип
GHSA-32x6-qvw6-mxj4

Forwarding of confidentials headers to third parties in fluture-node

CVSS3: 2.6
0%
Низкий
почти 4 года назад
github логотип
GHSA-32x6-6wch-qrgg

The imdb-widget plugin before 1.0.9 for WordPress has Local File Inclusion.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-32x6-3vx9-jwfc

A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the availability of the web page.

CVSS3: 4.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-32x5-wqvr-v5j9

CSRF in admin/ajax-hub.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to post a comment on any article via a crafted request.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-32x5-p6vh-hgrq

Cross Site Scripting (XSS) vulnerability in HuCart 5.7.4 via nickname in index.php.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-32x5-jw55-c96h

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Pensopay WooCommerce PensoPay plugin <= 6.3.1 versions.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-32x5-6p4q-q8jh

Magento Information Disclosure via File upload functionality

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-32x5-673x-7q8q

"HCL Marketing Platform is vulnerable to cross-site scripting during addition of new users and also while searching for users in Dashboard, potentially giving an attacker ability to inject malicious code into the system. "

0%
Низкий
больше 3 лет назад
github логотип
GHSA-32x4-wf82-frg6

The CIP dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (memory consumption) via a malformed packet.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-32x4-2mw2-5hjv

A vulnerability in SonicOS where the HTTP server response leaks partial memory by sending a crafted HTTP request, this can potentially lead to an internal sensitive data disclosure vulnerability.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-32x3-7jmh-qgfj

plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to execute arbitrary PHP code via PHP sequences in the sort parameter, which is processed by create_function.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-32x3-2qh2-v3w9

A vulnerability in the configuration archive functionality of Cisco DNA Center could allow any privilege-level authenticated, remote attacker to obtain the full unmasked running configuration of managed devices. The vulnerability is due to the configuration archives files being stored in clear text, which can be retrieved by various API calls. An attacker could exploit this vulnerability by authenticating to the device and executing a series of API calls. A successful exploit could allow the attacker to retrieve the full unmasked running configurations of managed devices.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-32x2-f5q9-2h3f

In MPLS environments, receipt of a specific SNMP packet may cause the routing protocol daemon (RPD) process to crash and restart. By continuously sending a specially crafted SNMP packet, an attacker can repetitively crash the RPD process causing prolonged denial of service. No other Juniper Networks products or platforms are affected by this issue. Affected releases are Juniper Networks Junos OS : 12.1X46 versions prior to 12.1X46-D77 on SRX Series; 12.3 versions prior to 12.3R12-S10; 12.3X48 versions prior to 12.3X48-D75 on SRX Series; 14.1X53 versions prior to 14.1X53-D48 on EX/QFX series; 15.1 versions prior to 15.1R4-S9, 15.1R7-S2; 15.1F6 versions prior to 15.1F6-S11; 15.1X49 versions prior to 15.1X49-D141, 15.1X49-D144, 15.1X49-D150 on SRX Series; 15.1X53 versions prior to 15.1X53-D234 on QFX5200/QFX5110 Series; 15.1X53 versions prior to 15.1X53-D68 on QFX10K Series; 15.1X53 versions prior to 15.1X53-D471, 15.1X53-D490 on NFX Series; 15.1X53 versions prior to 15.1X53-D590 on EX...

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-32wx-p4x4-cg2v

Buffer overflow occurs when emulated RPMB is used due to sector size assumptions in the TA rollback protection logic. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in MDM9206, MDM9607, MDM9650, MDM9655, MSM8996AU, QCS404, QCS605, Qualcomm 215, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 8CX, SDA660, SDM439, SDM630, SDM660, Snapdragon_High_Med_2016, SXR1130

CVSS3: 7.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу