Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 212

Количество 314 212

github логотип

GHSA-324r-273m-p2rj

больше 3 лет назад

An issue was discovered in Suricata 4.1.3. The function ftp_pasv_response lacks a check for the length of part1 and part2, leading to a crash within the ftp/mod.rs file.

EPSS: Низкий
github логотип

GHSA-324q-xqr3-9238

5 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: drm/bridge: anx7625: Fix overflow issue on reading EDID The length of EDID block can be longer than 256 bytes, so we should use `int` instead of `u8` for the `edid_pos` variable.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-324q-q2fm-hmf3

больше 3 лет назад

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on a targeted device via a web browser and with the privileges of the user. Cisco Bug IDs: CSCvf69805.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-324p-3f7r-2rf5

почти 2 года назад

Implementations of UDP application protocol are vulnerable to network loops. An unauthenticated attacker can use maliciously-crafted packets against a vulnerable implementation that can lead to Denial of Service (DOS) and/or abuse of resources.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-324m-p5mr-m7mp

больше 3 лет назад

An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE-2020-0626, CVE-2020-0627, CVE-2020-0628, CVE-2020-0629, CVE-2020-0630, CVE-2020-0631, CVE-2020-0632, CVE-2020-0633.

EPSS: Низкий
github логотип

GHSA-324m-7g42-gmmr

больше 3 лет назад

A vulnerability in Trend Micro ServerProtect for Storage 6.0, ServerProtect for EMC Celerra 5.8, ServerProtect for Network Appliance Filers 5.8, and ServerProtect for Microsoft Windows / Novell Netware 5.8 could allow a remote attacker to bypass authentication on affected installations.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-324j-grr2-6cg2

почти 4 года назад

Microsoft Windows Media Player (WMP) 9 on Windows XP SP2 invokes Internet Explorer to render HTML documents contained inside some media files, regardless of what default web browser is configured, which might allow remote attackers to exploit vulnerabilities in software that the user does not expect to run, as demonstrated by the HTMLView parameter in an .asx file.

EPSS: Средний
github логотип

GHSA-324j-gr3g-9jhv

больше 3 лет назад

Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows remote attackers to cause a denial of service via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-324h-vh92-m23h

почти 4 года назад

Incorrect security UI in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-324h-8gv8-f3xm

почти 4 года назад

Winamp 2.65 through 3.0 stores skin files in a predictable file location, which allows remote attackers to execute arbitrary code via a URL reference to (1) wsz and (2) wal files that contain embedded code.

EPSS: Низкий
github логотип

GHSA-324h-2v7h-q3xx

больше 3 лет назад

RCE vulnerability in Jenkins Yaml Axis Plugin

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-324g-rp4q-gr7p

больше 1 года назад

The XO Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘get_slider’ function in all versions up to, and including, 3.8.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-324f-g94h-3w6p

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in YAS Global Team Make Paths Relative plugin <= 1.3.0 versions.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-324f-g2g5-rj4m

больше 3 лет назад

Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 have an integer overflow vulnerability. Due to insufficient input validation, an authenticated, remote attacker could send malformed SOAP packets to the target device. Successful exploit could cause an integer overflow and might reset a process.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-324f-c4g7-9r7j

почти 2 года назад

A vulnerability, which was classified as problematic, has been found in Campcodes Online Event Management System 1.0. This issue affects some unknown processing of the file /views/process.php. The manipulation of the argument name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259895.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-324c-r2g2-547c

7 месяцев назад

Concurrent execution using shared resource with improper synchronization ('race condition') in Workspace Broker allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3249-ch6f-5vrf

почти 2 года назад

The ENL Newsletter WordPress plugin through 1.0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3248-f932-c76p

11 месяцев назад

DB-GPT vulnerable to Cross-Site Request Forgery

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3248-f5xr-jwg7

около 2 лет назад

Out-of-bounds vulnerability in the sensor module. Successful exploitation of this vulnerability may cause mistouch prevention errors on users' mobile phones.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3248-52cq-vhgx

почти 4 года назад

Buffer overflow in lscfg of unknown versions of AIX has unknown impact.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-324r-273m-p2rj

An issue was discovered in Suricata 4.1.3. The function ftp_pasv_response lacks a check for the length of part1 and part2, leading to a crash within the ftp/mod.rs file.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-324q-xqr3-9238

In the Linux kernel, the following vulnerability has been resolved: drm/bridge: anx7625: Fix overflow issue on reading EDID The length of EDID block can be longer than 256 bytes, so we should use `int` instead of `u8` for the `edid_pos` variable.

CVSS3: 5.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-324q-q2fm-hmf3

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on a targeted device via a web browser and with the privileges of the user. Cisco Bug IDs: CSCvf69805.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-324p-3f7r-2rf5

Implementations of UDP application protocol are vulnerable to network loops. An unauthenticated attacker can use maliciously-crafted packets against a vulnerable implementation that can lead to Denial of Service (DOS) and/or abuse of resources.

CVSS3: 7.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-324m-p5mr-m7mp

An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE-2020-0626, CVE-2020-0627, CVE-2020-0628, CVE-2020-0629, CVE-2020-0630, CVE-2020-0631, CVE-2020-0632, CVE-2020-0633.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-324m-7g42-gmmr

A vulnerability in Trend Micro ServerProtect for Storage 6.0, ServerProtect for EMC Celerra 5.8, ServerProtect for Network Appliance Filers 5.8, and ServerProtect for Microsoft Windows / Novell Netware 5.8 could allow a remote attacker to bypass authentication on affected installations.

CVSS3: 9.8
19%
Средний
больше 3 лет назад
github логотип
GHSA-324j-grr2-6cg2

Microsoft Windows Media Player (WMP) 9 on Windows XP SP2 invokes Internet Explorer to render HTML documents contained inside some media files, regardless of what default web browser is configured, which might allow remote attackers to exploit vulnerabilities in software that the user does not expect to run, as demonstrated by the HTMLView parameter in an .asx file.

33%
Средний
почти 4 года назад
github логотип
GHSA-324j-gr3g-9jhv

Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows remote attackers to cause a denial of service via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-324h-vh92-m23h

Incorrect security UI in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-324h-8gv8-f3xm

Winamp 2.65 through 3.0 stores skin files in a predictable file location, which allows remote attackers to execute arbitrary code via a URL reference to (1) wsz and (2) wal files that contain embedded code.

4%
Низкий
почти 4 года назад
github логотип
GHSA-324h-2v7h-q3xx

RCE vulnerability in Jenkins Yaml Axis Plugin

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-324g-rp4q-gr7p

The XO Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘get_slider’ function in all versions up to, and including, 3.8.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-324f-g94h-3w6p

Cross-Site Request Forgery (CSRF) vulnerability in YAS Global Team Make Paths Relative plugin <= 1.3.0 versions.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-324f-g2g5-rj4m

Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 have an integer overflow vulnerability. Due to insufficient input validation, an authenticated, remote attacker could send malformed SOAP packets to the target device. Successful exploit could cause an integer overflow and might reset a process.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-324f-c4g7-9r7j

A vulnerability, which was classified as problematic, has been found in Campcodes Online Event Management System 1.0. This issue affects some unknown processing of the file /views/process.php. The manipulation of the argument name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259895.

CVSS3: 3.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-324c-r2g2-547c

Concurrent execution using shared resource with improper synchronization ('race condition') in Workspace Broker allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-3249-ch6f-5vrf

The ENL Newsletter WordPress plugin through 1.0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVSS3: 5.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-3248-f932-c76p

DB-GPT vulnerable to Cross-Site Request Forgery

CVSS3: 7.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-3248-f5xr-jwg7

Out-of-bounds vulnerability in the sensor module. Successful exploitation of this vulnerability may cause mistouch prevention errors on users' mobile phones.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-3248-52cq-vhgx

Buffer overflow in lscfg of unknown versions of AIX has unknown impact.

1%
Низкий
почти 4 года назад

Уязвимостей на страницу