Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-32jq-w4j4-wjvc

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: ceph: give up on paths longer than PATH_MAX If the full path to be built by ceph_mdsc_build_path() happens to be longer than PATH_MAX, then this function will enter an endless (retry) loop, effectively blocking the whole task. Most of the machine becomes unusable, making this a very simple and effective DoS vulnerability. I cannot imagine why this retry was ever implemented, but it seems rather useless and harmful to me. Let's remove it and fail with ENAMETOOLONG instead.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-32jq-mv89-5rx7

почти 2 года назад

CoreWCF NetFraming based services can leave connections open when they should be closed

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-32jp-v3x3-64xq

почти 4 года назад

The web administration interface (mainApp) to Cisco IDS before 4.1(5c), and IPS 5.0 before 5.0(6p1) and 5.1 before 5.1(2) allows remote attackers to cause a denial of service (unresponsive device) via a crafted SSLv2 Client Hello packet.

EPSS: Низкий
github логотип

GHSA-32jp-7xc2-p7fc

больше 3 лет назад

Various resources in Atlassian Confluence Server before version 6.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the issuesURL parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-32jm-56p4-qjh3

больше 3 лет назад

IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 119732.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-32jj-wp9g-2g8g

около 3 лет назад

Buffer Overflow vulnerability in pdfimages in xpdf 4.03 allows attackers to crash the application via crafted command.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-32jj-82v4-hh23

больше 3 лет назад

Improper authentication for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

EPSS: Низкий
github логотип

GHSA-32jg-xqp8-jrc4

около 2 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Farm Agrico farmagrico allows PHP Local File Inclusion.This issue affects Farm Agrico: from n/a through <= 1.3.11.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-32jg-gjgm-gc7x

больше 3 лет назад

An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0848.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-32jg-6c46-hc8j

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: kdb: Fix buffer overflow during tab-complete Currently, when the user attempts symbol completion with the Tab key, kdb will use strncpy() to insert the completed symbol into the command buffer. Unfortunately it passes the size of the source buffer rather than the destination to strncpy() with predictably horrible results. Most obviously if the command buffer is already full but cp, the cursor position, is in the middle of the buffer, then we will write past the end of the supplied buffer. Fix this by replacing the dubious strncpy() calls with memmove()/memcpy() calls plus explicit boundary checks to make sure we have enough space before we start moving characters around.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-32jf-h775-g29h

больше 1 года назад

MongoDB Rust driver may issue unintended commands

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-32jf-8hmq-3gv8

больше 3 лет назад

app/views_mod/user/user.py in LibrIT PaSSHport through 2.5 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided search filter because user input gets no sanitization.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-32jf-3cpj-cxx9

больше 3 лет назад

Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-32jc-f729-2rgf

больше 3 лет назад

Frog CMS 0.9.5 has XSS in the admin/?/page/edit/1 body field.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-32jc-9p58-p82x

почти 3 года назад

Moodle Improper Access Control vulnerability

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-32jc-5c8m-p2c9

почти 4 года назад

The ARI Fancy Lightbox WordPress plugin before 1.3.9 does not sanitise and escape the msg parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-32jc-368c-fvg6

больше 2 лет назад

The ActivityPub WordPress plugin before 1.0.0 does not sanitize and escape some data from post content, which could allow contributor and above role to perform Stored Cross-Site Scripting attacks

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-32j9-px4f-v6vv

почти 4 года назад

Format string vulnerability in cfd daemon in GNU CFEngine before 1.6.0a11 allows attackers to execute arbitrary commands via format characters in the CAUTH command.

EPSS: Низкий
github логотип

GHSA-32j9-8mq4-72ff

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: netfs: Delete subtree of 'fs/netfs' when netfs module exits In netfs_init() or fscache_proc_init(), we create dentry under 'fs/netfs', but in netfs_exit(), we only delete the proc entry of 'fs/netfs' without deleting its subtree. This triggers the following WARNING: ================================================================== remove_proc_entry: removing non-empty directory 'fs/netfs', leaking at least 'requests' WARNING: CPU: 4 PID: 566 at fs/proc/generic.c:717 remove_proc_entry+0x160/0x1c0 Modules linked in: netfs(-) CPU: 4 UID: 0 PID: 566 Comm: rmmod Not tainted 6.11.0-rc3 #860 RIP: 0010:remove_proc_entry+0x160/0x1c0 Call Trace: <TASK> netfs_exit+0x12/0x620 [netfs] __do_sys_delete_module.isra.0+0x14c/0x2e0 do_syscall_64+0x4b/0x110 entry_SYSCALL_64_after_hwframe+0x76/0x7e ================================================================== Therefore use remove_proc_subtree() instead of remove_proc_entr...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-32j9-6qqm-mq9g

почти 4 года назад

Unhandled case in node-lmdb

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-32jq-w4j4-wjvc

In the Linux kernel, the following vulnerability has been resolved: ceph: give up on paths longer than PATH_MAX If the full path to be built by ceph_mdsc_build_path() happens to be longer than PATH_MAX, then this function will enter an endless (retry) loop, effectively blocking the whole task. Most of the machine becomes unusable, making this a very simple and effective DoS vulnerability. I cannot imagine why this retry was ever implemented, but it seems rather useless and harmful to me. Let's remove it and fail with ENAMETOOLONG instead.

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-32jq-mv89-5rx7

CoreWCF NetFraming based services can leave connections open when they should be closed

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-32jp-v3x3-64xq

The web administration interface (mainApp) to Cisco IDS before 4.1(5c), and IPS 5.0 before 5.0(6p1) and 5.1 before 5.1(2) allows remote attackers to cause a denial of service (unresponsive device) via a crafted SSLv2 Client Hello packet.

2%
Низкий
почти 4 года назад
github логотип
GHSA-32jp-7xc2-p7fc

Various resources in Atlassian Confluence Server before version 6.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the issuesURL parameter.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-32jm-56p4-qjh3

IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 119732.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-32jj-wp9g-2g8g

Buffer Overflow vulnerability in pdfimages in xpdf 4.03 allows attackers to crash the application via crafted command.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-32jj-82v4-hh23

Improper authentication for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-32jg-xqp8-jrc4

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Farm Agrico farmagrico allows PHP Local File Inclusion.This issue affects Farm Agrico: from n/a through <= 1.3.11.

CVSS3: 8.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-32jg-gjgm-gc7x

An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0848.

CVSS3: 5.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-32jg-6c46-hc8j

In the Linux kernel, the following vulnerability has been resolved: kdb: Fix buffer overflow during tab-complete Currently, when the user attempts symbol completion with the Tab key, kdb will use strncpy() to insert the completed symbol into the command buffer. Unfortunately it passes the size of the source buffer rather than the destination to strncpy() with predictably horrible results. Most obviously if the command buffer is already full but cp, the cursor position, is in the middle of the buffer, then we will write past the end of the supplied buffer. Fix this by replacing the dubious strncpy() calls with memmove()/memcpy() calls plus explicit boundary checks to make sure we have enough space before we start moving characters around.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-32jf-h775-g29h

MongoDB Rust driver may issue unintended commands

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-32jf-8hmq-3gv8

app/views_mod/user/user.py in LibrIT PaSSHport through 2.5 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided search filter because user input gets no sanitization.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-32jf-3cpj-cxx9

Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

CVSS3: 9.8
4%
Низкий
больше 3 лет назад
github логотип
GHSA-32jc-f729-2rgf

Frog CMS 0.9.5 has XSS in the admin/?/page/edit/1 body field.

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-32jc-9p58-p82x

Moodle Improper Access Control vulnerability

CVSS3: 8.2
1%
Низкий
почти 3 года назад
github логотип
GHSA-32jc-5c8m-p2c9

The ARI Fancy Lightbox WordPress plugin before 1.3.9 does not sanitise and escape the msg parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-32jc-368c-fvg6

The ActivityPub WordPress plugin before 1.0.0 does not sanitize and escape some data from post content, which could allow contributor and above role to perform Stored Cross-Site Scripting attacks

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-32j9-px4f-v6vv

Format string vulnerability in cfd daemon in GNU CFEngine before 1.6.0a11 allows attackers to execute arbitrary commands via format characters in the CAUTH command.

1%
Низкий
почти 4 года назад
github логотип
GHSA-32j9-8mq4-72ff

In the Linux kernel, the following vulnerability has been resolved: netfs: Delete subtree of 'fs/netfs' when netfs module exits In netfs_init() or fscache_proc_init(), we create dentry under 'fs/netfs', but in netfs_exit(), we only delete the proc entry of 'fs/netfs' without deleting its subtree. This triggers the following WARNING: ================================================================== remove_proc_entry: removing non-empty directory 'fs/netfs', leaking at least 'requests' WARNING: CPU: 4 PID: 566 at fs/proc/generic.c:717 remove_proc_entry+0x160/0x1c0 Modules linked in: netfs(-) CPU: 4 UID: 0 PID: 566 Comm: rmmod Not tainted 6.11.0-rc3 #860 RIP: 0010:remove_proc_entry+0x160/0x1c0 Call Trace: <TASK> netfs_exit+0x12/0x620 [netfs] __do_sys_delete_module.isra.0+0x14c/0x2e0 do_syscall_64+0x4b/0x110 entry_SYSCALL_64_after_hwframe+0x76/0x7e ================================================================== Therefore use remove_proc_subtree() instead of remove_proc_entr...

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-32j9-6qqm-mq9g

Unhandled case in node-lmdb

CVSS3: 7.5
0%
Низкий
почти 4 года назад

Уязвимостей на страницу