Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-32cr-574m-fmxq

больше 3 лет назад

Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via the Session Initiation Protocol.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-32cq-h35v-hv9g

почти 4 года назад

httpdx 1.4.4 and earlier allows remote attackers to obtain the source code for a web page by appending a . (dot) character to the URI.

EPSS: Низкий
github логотип

GHSA-32cp-f6vp-4m5h

больше 3 лет назад

The Stickman Ski Racer (aka com.djinnworks.StickmanSkiRacer.free) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-32cp-9h8g-xvhr

11 месяцев назад

A vulnerability was found in Mage AI 0.9.75. It has been classified as problematic. This affects an unknown part. The manipulation leads to insecure default initialization of resource. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. After 7 months of repeated follow-ups by the researcher, Mage AI has decided to not accept this issue as a valid security vulnerability and has confirmed that they will not be addressing it.

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-32cm-387p-hxf5

почти 3 года назад

An issue in the CSV Import function of ChurchCRM v4.5.3 and below allows attackers to execute arbitrary code via importing a crafted CSV file.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-32cj-5wx4-gq8p

больше 1 года назад

HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims

CVSS3: 2.6
EPSS: Низкий
github логотип

GHSA-32ch-w695-p5qw

больше 3 лет назад

Unrestricted upload of file with dangerous type in WallacePOS 1.4.3 allows a remote, authenticated attacker to execute arbitrary code by uploading a malicious PHP file.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-32ch-hx5j-xxhq

почти 4 года назад

in.lpd in the print service in Sun Solaris 8 and 9 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors that trigger a "fork()/exec() bomb."

EPSS: Низкий
github логотип

GHSA-32ch-6x54-q4h9

почти 2 года назад

When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as "Authorization" or "Cookie". For example, a redirect from foo.com to www.foo.com will forward the Authorization header, but a redirect to bar.com will not. A maliciously crafted HTTP redirect could cause sensitive headers to be unexpectedly forwarded.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-32cf-974m-jh3r

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in cifs_stats_proc_show() Skip sessions that are being teared down (status == SES_EXITING) to avoid UAF.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-32cf-6454-vhqx

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: media: [next] staging: media: atomisp: fix memory leak of object flash In the case where the call to lm3554_platform_data_func returns an error there is a memory leak on the error return path of object flash. Fix this by adding an error return path that will free flash and rename labels fail2 to fail3 and fail1 to fail2.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-32cc-x95p-fxcg

4 дня назад

FUXA Unauthenticated Remote Code Execution via Hardcoded JWT Secret in Default Configuration

EPSS: Низкий
github логотип

GHSA-32cc-f5gm-cv4r

10 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Daisycon Daisycon prijsvergelijkers allows SQL Injection. This issue affects Daisycon prijsvergelijkers: from n/a through 4.8.4.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-32c9-pf87-q237

больше 3 лет назад

Microsoft Asha OS on the Microsoft Mobile Nokia Asha 501 phone 14.0.4 allows physically proximate attackers to bypass the lock-screen protection mechanism, and read or modify contact information or dial arbitrary telephone numbers, by tapping the SOS Option and then tapping the Green Call Option.

EPSS: Низкий
github логотип

GHSA-32c9-9352-jvgc

около 2 месяцев назад

A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious code into shipping options configuration. This could lead to potential theft of sensitive data by executing malicious scripts in users' browsers.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-32c9-8jgc-9c8c

почти 4 года назад

heartbeat.c in heartbeat before 2.0.6 sets insecure permissions in a shmget call for shared memory, which allows local users to cause an unspecified denial of service via unknown vectors, possibly during a short time window on startup.

EPSS: Низкий
github логотип

GHSA-32c8-f69v-cf4f

около 3 лет назад

Use after free in Extensions in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install an extension to potentially exploit heap corruption via a crafted Chrome Extension and UI interaction. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-32c8-2q94-9pqj

больше 3 лет назад

includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress allows unauthenticated options changes.

EPSS: Низкий
github логотип

GHSA-32c7-mv5c-m5rr

около 4 лет назад

Improper access control allows any project member to retrieve the service desk email address in GitLab CE/EE versions starting 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-32c7-72q6-p3cg

больше 3 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Supported versions that are affected are 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-32cr-574m-fmxq

Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via the Session Initiation Protocol.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-32cq-h35v-hv9g

httpdx 1.4.4 and earlier allows remote attackers to obtain the source code for a web page by appending a . (dot) character to the URI.

7%
Низкий
почти 4 года назад
github логотип
GHSA-32cp-f6vp-4m5h

The Stickman Ski Racer (aka com.djinnworks.StickmanSkiRacer.free) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-32cp-9h8g-xvhr

A vulnerability was found in Mage AI 0.9.75. It has been classified as problematic. This affects an unknown part. The manipulation leads to insecure default initialization of resource. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. After 7 months of repeated follow-ups by the researcher, Mage AI has decided to not accept this issue as a valid security vulnerability and has confirmed that they will not be addressing it.

CVSS3: 5.6
5%
Низкий
11 месяцев назад
github логотип
GHSA-32cm-387p-hxf5

An issue in the CSV Import function of ChurchCRM v4.5.3 and below allows attackers to execute arbitrary code via importing a crafted CSV file.

CVSS3: 4.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-32cj-5wx4-gq8p

HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims

CVSS3: 2.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-32ch-w695-p5qw

Unrestricted upload of file with dangerous type in WallacePOS 1.4.3 allows a remote, authenticated attacker to execute arbitrary code by uploading a malicious PHP file.

CVSS3: 7.2
2%
Низкий
больше 3 лет назад
github логотип
GHSA-32ch-hx5j-xxhq

in.lpd in the print service in Sun Solaris 8 and 9 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors that trigger a "fork()/exec() bomb."

2%
Низкий
почти 4 года назад
github логотип
GHSA-32ch-6x54-q4h9

When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as "Authorization" or "Cookie". For example, a redirect from foo.com to www.foo.com will forward the Authorization header, but a redirect to bar.com will not. A maliciously crafted HTTP redirect could cause sensitive headers to be unexpectedly forwarded.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-32cf-974m-jh3r

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in cifs_stats_proc_show() Skip sessions that are being teared down (status == SES_EXITING) to avoid UAF.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-32cf-6454-vhqx

In the Linux kernel, the following vulnerability has been resolved: media: [next] staging: media: atomisp: fix memory leak of object flash In the case where the call to lm3554_platform_data_func returns an error there is a memory leak on the error return path of object flash. Fix this by adding an error return path that will free flash and rename labels fail2 to fail3 and fail1 to fail2.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-32cc-x95p-fxcg

FUXA Unauthenticated Remote Code Execution via Hardcoded JWT Secret in Default Configuration

4 дня назад
github логотип
GHSA-32cc-f5gm-cv4r

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Daisycon Daisycon prijsvergelijkers allows SQL Injection. This issue affects Daisycon prijsvergelijkers: from n/a through 4.8.4.

CVSS3: 8.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-32c9-pf87-q237

Microsoft Asha OS on the Microsoft Mobile Nokia Asha 501 phone 14.0.4 allows physically proximate attackers to bypass the lock-screen protection mechanism, and read or modify contact information or dial arbitrary telephone numbers, by tapping the SOS Option and then tapping the Green Call Option.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-32c9-9352-jvgc

A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious code into shipping options configuration. This could lead to potential theft of sensitive data by executing malicious scripts in users' browsers.

CVSS3: 4.6
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-32c9-8jgc-9c8c

heartbeat.c in heartbeat before 2.0.6 sets insecure permissions in a shmget call for shared memory, which allows local users to cause an unspecified denial of service via unknown vectors, possibly during a short time window on startup.

0%
Низкий
почти 4 года назад
github логотип
GHSA-32c8-f69v-cf4f

Use after free in Extensions in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install an extension to potentially exploit heap corruption via a crafted Chrome Extension and UI interaction. (Chromium security severity: High)

CVSS3: 8.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-32c8-2q94-9pqj

includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress allows unauthenticated options changes.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-32c7-mv5c-m5rr

Improper access control allows any project member to retrieve the service desk email address in GitLab CE/EE versions starting 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-32c7-72q6-p3cg

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Supported versions that are affected are 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу