Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 300 899

Количество 300 899

github логотип

GHSA-25gv-fvh4-vpcx

больше 3 лет назад

Privilege escalation in 'upload.php' in FrogCMS SentCMS v0.9.5 allows attacker to execute arbitrary code via crafted php file.

EPSS: Низкий
github логотип

GHSA-25gv-85m9-qg67

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF).This issue affects WordPress Meta Data and Taxonomies Filter (MDTF): from n/a through 1.3.3.1.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-25gv-4h88-97v2

10 месяцев назад

A path handling issue was addressed with improved validation. This issue is fixed in macOS Sonoma 14.7.2, macOS Sequoia 15.2, macOS Ventura 13.7.2. An app may be able to overwrite arbitrary files.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-25gr-ph8w-33hc

больше 3 лет назад

Use-after-free vulnerability in the nsRefreshDriver::Tick function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by leveraging improper interaction between timeline destruction and the Web Animations model implementation.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-25gr-fx9v-whc8

больше 3 лет назад

In SWFTools 2013-04-09-1007 on Windows, png2swf allows remote attackers to execute arbitrary code or cause a denial of service via a crafted file, related to a "User Mode Write AV near NULL starting at wow64!Wow64NotifyDebugger+0x000000000000001d."

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-25gq-jvx2-vg9x

больше 1 года назад

Silverstripe X-Forwarded-Host request hostname injection

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-25gq-3qmx-682c

больше 3 лет назад

libheif 1.4.0 has a use-after-free in heif::HeifContext::Image::set_alpha_channel in heif_context.h because heif_context.cc mishandles references to non-existing alpha images.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-25gp-h9jh-j64g

больше 3 лет назад

Directory traversal vulnerability in Free Download Manager (FDM) before 3.0.852 allows remote attackers to create arbitrary files via directory traversal sequences in the name attribute of a file element in a metalink file.

EPSS: Низкий
github логотип

GHSA-25gm-jxwr-cv79

около 1 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stark Digital WP Testimonial Widget.This issue affects WP Testimonial Widget: from n/a through 3.1.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-25gm-f4jj-c4jm

больше 3 лет назад

Mitigates an XSS issue in NetIQ Access Manager versions prior to 4.4 SP3.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-25gm-5rg6-r2ph

больше 3 лет назад

pdftops.pl before 1.20 in alternate pdftops filter allows local users to overwrite arbitrary files via a symlink attack on the pdfin.[PID].tmp temporary file, which is created when pdftops reads a PDF file from stdin, such as when pdftops is invoked by CUPS.

EPSS: Низкий
github логотип

GHSA-25gj-gvw5-5xcq

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in swamp/action/LoginActions (aka the login box) in the Novell OpenSUSE SWAMP Workflow Administration and Management Platform 1.x allows remote attackers to inject arbitrary web script or HTML via the username parameter. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-25gj-gfhx-xwgh

около 2 лет назад

A vulnerability has been identified in PT-G503 Series versions prior to v5.2, where the session cookies attribute is not set properly in the affected application. The vulnerability may lead to security risks, potentially exposing user session data to unauthorized access and manipulation.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-25gj-576f-pwm3

больше 3 лет назад

Cisco Clean Access (CCA) 3.5.x through 3.5.9 and 3.6.x through 3.6.1.1 on the Clean Access Manager (CAM) allows remote attackers to bypass authentication and download arbitrary manual database backups by guessing the snapshot filename using brute force, then making a direct request for the file.

EPSS: Низкий
github логотип

GHSA-25gj-4578-83qm

больше 3 лет назад

Untrusted search path vulnerability in Xtreme RAT 3.5 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as the current working directory. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-25gj-3mw9-4cjw

больше 1 года назад

Insecure key exchange between Delinea PAM Secret Server 11.4 and the Distributed Engine 8.4.3 allows a PAM administrator to obtain the Symmetric Key (used to encrypt RabbitMQ messages) via crafted payloads to the /pre-authenticate, /authenticate, and /execute-and-respond REST API endpoints. This makes it possible for a PAM administrator to impersonate the Engine and exfiltrate sensitive information from the messages published in the RabbitMQ exchanges, without being audited in the application.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-25gg-qp55-68p3

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Prevent potential buffer overflow in map_hw_resources Adds a check in the map_hw_resources function to prevent a potential buffer overflow. The function was accessing arrays using an index that could potentially be greater than the size of the arrays, leading to a buffer overflow. Adds a check to ensure that the index is within the bounds of the arrays. If the index is out of bounds, an error message is printed and break it will continue execution with just ignoring extra data early to prevent the buffer overflow. Reported by smatch: drivers/gpu/drm/amd/amdgpu/../display/dc/dml2/dml2_wrapper.c:79 map_hw_resources() error: buffer overflow 'dml2->v20.scratch.dml_to_dc_pipe_mapping.disp_cfg_to_stream_id' 6 <= 7 drivers/gpu/drm/amd/amdgpu/../display/dc/dml2/dml2_wrapper.c:81 map_hw_resources() error: buffer overflow 'dml2->v20.scratch.dml_to_dc_pipe_mapping.disp_cfg_to_plane_id' 6 <= 7

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-25gf-mm96-28wq

больше 1 года назад

Missing Authorization vulnerability in AF themes WP Post Author.This issue affects WP Post Author: from n/a through 3.6.4.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-25gf-8qrr-g78r

больше 4 лет назад

Hashicorp Consul Missing SSL Certificate Validation

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-25gf-7mcm-h7vj

больше 3 лет назад

The uas driver in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device, related to drivers/usb/storage/uas-detect.h and drivers/usb/storage/uas.c.

CVSS3: 6.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-25gv-fvh4-vpcx

Privilege escalation in 'upload.php' in FrogCMS SentCMS v0.9.5 allows attacker to execute arbitrary code via crafted php file.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-25gv-85m9-qg67

Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF).This issue affects WordPress Meta Data and Taxonomies Filter (MDTF): from n/a through 1.3.3.1.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-25gv-4h88-97v2

A path handling issue was addressed with improved validation. This issue is fixed in macOS Sonoma 14.7.2, macOS Sequoia 15.2, macOS Ventura 13.7.2. An app may be able to overwrite arbitrary files.

CVSS3: 5.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-25gr-ph8w-33hc

Use-after-free vulnerability in the nsRefreshDriver::Tick function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by leveraging improper interaction between timeline destruction and the Web Animations model implementation.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-25gr-fx9v-whc8

In SWFTools 2013-04-09-1007 on Windows, png2swf allows remote attackers to execute arbitrary code or cause a denial of service via a crafted file, related to a "User Mode Write AV near NULL starting at wow64!Wow64NotifyDebugger+0x000000000000001d."

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-25gq-jvx2-vg9x

Silverstripe X-Forwarded-Host request hostname injection

CVSS3: 7.2
больше 1 года назад
github логотип
GHSA-25gq-3qmx-682c

libheif 1.4.0 has a use-after-free in heif::HeifContext::Image::set_alpha_channel in heif_context.h because heif_context.cc mishandles references to non-existing alpha images.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-25gp-h9jh-j64g

Directory traversal vulnerability in Free Download Manager (FDM) before 3.0.852 allows remote attackers to create arbitrary files via directory traversal sequences in the name attribute of a file element in a metalink file.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-25gm-jxwr-cv79

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stark Digital WP Testimonial Widget.This issue affects WP Testimonial Widget: from n/a through 3.1.

CVSS3: 7.6
0%
Низкий
около 1 года назад
github логотип
GHSA-25gm-f4jj-c4jm

Mitigates an XSS issue in NetIQ Access Manager versions prior to 4.4 SP3.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-25gm-5rg6-r2ph

pdftops.pl before 1.20 in alternate pdftops filter allows local users to overwrite arbitrary files via a symlink attack on the pdfin.[PID].tmp temporary file, which is created when pdftops reads a PDF file from stdin, such as when pdftops is invoked by CUPS.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-25gj-gvw5-5xcq

Cross-site scripting (XSS) vulnerability in swamp/action/LoginActions (aka the login box) in the Novell OpenSUSE SWAMP Workflow Administration and Management Platform 1.x allows remote attackers to inject arbitrary web script or HTML via the username parameter. NOTE: some of these details are obtained from third party information.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-25gj-gfhx-xwgh

A vulnerability has been identified in PT-G503 Series versions prior to v5.2, where the session cookies attribute is not set properly in the affected application. The vulnerability may lead to security risks, potentially exposing user session data to unauthorized access and manipulation.

CVSS3: 3.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-25gj-576f-pwm3

Cisco Clean Access (CCA) 3.5.x through 3.5.9 and 3.6.x through 3.6.1.1 on the Clean Access Manager (CAM) allows remote attackers to bypass authentication and download arbitrary manual database backups by guessing the snapshot filename using brute force, then making a direct request for the file.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-25gj-4578-83qm

Untrusted search path vulnerability in Xtreme RAT 3.5 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as the current working directory. NOTE: some of these details are obtained from third party information.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-25gj-3mw9-4cjw

Insecure key exchange between Delinea PAM Secret Server 11.4 and the Distributed Engine 8.4.3 allows a PAM administrator to obtain the Symmetric Key (used to encrypt RabbitMQ messages) via crafted payloads to the /pre-authenticate, /authenticate, and /execute-and-respond REST API endpoints. This makes it possible for a PAM administrator to impersonate the Engine and exfiltrate sensitive information from the messages published in the RabbitMQ exchanges, without being audited in the application.

CVSS3: 5.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-25gg-qp55-68p3

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Prevent potential buffer overflow in map_hw_resources Adds a check in the map_hw_resources function to prevent a potential buffer overflow. The function was accessing arrays using an index that could potentially be greater than the size of the arrays, leading to a buffer overflow. Adds a check to ensure that the index is within the bounds of the arrays. If the index is out of bounds, an error message is printed and break it will continue execution with just ignoring extra data early to prevent the buffer overflow. Reported by smatch: drivers/gpu/drm/amd/amdgpu/../display/dc/dml2/dml2_wrapper.c:79 map_hw_resources() error: buffer overflow 'dml2->v20.scratch.dml_to_dc_pipe_mapping.disp_cfg_to_stream_id' 6 <= 7 drivers/gpu/drm/amd/amdgpu/../display/dc/dml2/dml2_wrapper.c:81 map_hw_resources() error: buffer overflow 'dml2->v20.scratch.dml_to_dc_pipe_mapping.disp_cfg_to_plane_id' 6 <= 7

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-25gf-mm96-28wq

Missing Authorization vulnerability in AF themes WP Post Author.This issue affects WP Post Author: from n/a through 3.6.4.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-25gf-8qrr-g78r

Hashicorp Consul Missing SSL Certificate Validation

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-25gf-7mcm-h7vj

The uas driver in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device, related to drivers/usb/storage/uas-detect.h and drivers/usb/storage/uas.c.

CVSS3: 6.6
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу