Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2xvm-c65w-9fhf

6 месяцев назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-2xvj-x73g-2j9w

почти 4 года назад

mod_auth (http_auth.c) in lighttpd before 1.4.16 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors involving (1) a memory leak, (2) use of md5-sess without a cnonce, (3) base64 encoded strings, and (4) trailing whitespace in the Auth-Digest header.

EPSS: Низкий
github логотип

GHSA-2xvj-j4wx-pf4c

около 1 года назад

This issue was addressed through improved state management. This issue is fixed in macOS Ventura 13.7.2, visionOS 2.2, tvOS 18.2, watchOS 11.2, iOS 18.2 and iPadOS 18.2, macOS Sonoma 14.7.2, macOS Sequoia 15.2. An app may be able to access user-sensitive data.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2xvj-j3qh-x8c3

больше 7 лет назад

private_address_check contains race condition

EPSS: Низкий
github логотип

GHSA-2xvj-hf56-gj27

больше 3 лет назад

SQL injection vulnerability in index.php in GesGaleri, a module for XOOPS, allows remote attackers to execute arbitrary SQL commands via the no parameter.

EPSS: Низкий
github логотип

GHSA-2xvj-f2r6-3cg7

больше 3 лет назад

IBM InfoSphere Information Server 8.1, 8.5, and 8,7 could allow a remote authenticated attacker to obtain sensitive information, caused by improper restrictions on directories. An attacker could exploit this vulnerability via the DataStage application to load or import content functionality to view arbitrary files on the system.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2xvj-8wm9-m26w

3 месяца назад

Heap-based buffer overflow in Windows OLE allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2xvj-698r-hvrg

почти 3 года назад

Cross Site Scripting vulnerability in YMFE yapo v1.9.1 allows attacker to execute arbitrary code via the remark parameter of the interface edit page.

EPSS: Низкий
github логотип

GHSA-2xvh-gjg5-mj5g

больше 3 лет назад

Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Activity Guide). Supported versions that are affected are 8.55, 8.56 and 8.57. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).

EPSS: Низкий
github логотип

GHSA-2xvh-27wv-vhhr

больше 1 года назад

An issue in Plasmoapp RPShare Fabric mod v.1.0.0 allows a remote attacker to execute arbitrary code via the build method in DonwloadPromptScreen

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2xvg-pp8h-v32g

около 1 года назад

Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2xvg-5jxp-pccg

больше 2 лет назад

Code injection vulnerability in Drive Explorer for macOS versions 3.5.4 and earlier allows an attacker who can login to the client where the affected product is installed to inject arbitrary code while processing the product execution. Since a full disk access privilege is required to execute LINE WORKS Drive Explorer, the attacker may be able to read and/or write to arbitrary files without the access privileges.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2xvf-jhh8-xv4f

почти 2 года назад

** DISPUTED ** A vulnerability, which was classified as problematic, was found in Intelbras MHDX 1004, MHDX 1008, MHDX 1016, MHDX 5016, HDCVI 1008 and HDCVI 1016 up to 20240401. This affects an unknown part of the file /cap.js of the component HTTP GET Request Handler. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The identifier VDB-258933 was assigned to this vulnerability. NOTE: The vendor explains that they do not classify the information shown as sensitive and therefore there is no vulnerability which is about to harm the user.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2xvc-p88c-94vw

больше 2 лет назад

SAP UI5 Variant Management - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, UI_700 200, does not sufficiently encode user-controlled inputs on reading data from the server, resulting in Stored Cross-Site Scripting (Stored XSS) vulnerability. After successful exploitation, an attacker with user level access can cause high impact on confidentiality, modify some information and can cause unavailability of the application at user level.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-2xv9-ghh9-xc69

9 месяцев назад

radashi Allows Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

EPSS: Низкий
github логотип

GHSA-2xv9-5p9r-jvw2

больше 3 лет назад

A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious server or user can send an invalid mood to trigger this vulnerability.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2xv7-rgc5-4ccg

больше 3 лет назад

In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:1074, which allows attackers to cause a denial of service via a crafted file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2xv7-mq7h-x6hc

больше 3 лет назад

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0889, CVE-2019-0890, CVE-2019-0891, CVE-2019-0893, CVE-2019-0894, CVE-2019-0895, CVE-2019-0896, CVE-2019-0897, CVE-2019-0898, CVE-2019-0899, CVE-2019-0900, CVE-2019-0901.

EPSS: Средний
github логотип

GHSA-2xv7-fwh6-x7fc

больше 3 лет назад

Subrion Cross-site scripting (XSS) vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2xv7-55qq-fqg6

почти 4 года назад

Local Security Authority (LSA) Elevation of Privilege Vulnerability.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2xvm-c65w-9fhf

Rejected reason: Not used

6 месяцев назад
github логотип
GHSA-2xvj-x73g-2j9w

mod_auth (http_auth.c) in lighttpd before 1.4.16 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors involving (1) a memory leak, (2) use of md5-sess without a cnonce, (3) base64 encoded strings, and (4) trailing whitespace in the Auth-Digest header.

5%
Низкий
почти 4 года назад
github логотип
GHSA-2xvj-j4wx-pf4c

This issue was addressed through improved state management. This issue is fixed in macOS Ventura 13.7.2, visionOS 2.2, tvOS 18.2, watchOS 11.2, iOS 18.2 and iPadOS 18.2, macOS Sonoma 14.7.2, macOS Sequoia 15.2. An app may be able to access user-sensitive data.

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2xvj-j3qh-x8c3

private_address_check contains race condition

0%
Низкий
больше 7 лет назад
github логотип
GHSA-2xvj-hf56-gj27

SQL injection vulnerability in index.php in GesGaleri, a module for XOOPS, allows remote attackers to execute arbitrary SQL commands via the no parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xvj-f2r6-3cg7

IBM InfoSphere Information Server 8.1, 8.5, and 8,7 could allow a remote authenticated attacker to obtain sensitive information, caused by improper restrictions on directories. An attacker could exploit this vulnerability via the DataStage application to load or import content functionality to view arbitrary files on the system.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xvj-8wm9-m26w

Heap-based buffer overflow in Windows OLE allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
0%
Низкий
3 месяца назад
github логотип
GHSA-2xvj-698r-hvrg

Cross Site Scripting vulnerability in YMFE yapo v1.9.1 allows attacker to execute arbitrary code via the remark parameter of the interface edit page.

почти 3 года назад
github логотип
GHSA-2xvh-gjg5-mj5g

Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Activity Guide). Supported versions that are affected are 8.55, 8.56 and 8.57. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2xvh-27wv-vhhr

An issue in Plasmoapp RPShare Fabric mod v.1.0.0 allows a remote attacker to execute arbitrary code via the build method in DonwloadPromptScreen

CVSS3: 8.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-2xvg-pp8h-v32g

Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2xvg-5jxp-pccg

Code injection vulnerability in Drive Explorer for macOS versions 3.5.4 and earlier allows an attacker who can login to the client where the affected product is installed to inject arbitrary code while processing the product execution. Since a full disk access privilege is required to execute LINE WORKS Drive Explorer, the attacker may be able to read and/or write to arbitrary files without the access privileges.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2xvf-jhh8-xv4f

** DISPUTED ** A vulnerability, which was classified as problematic, was found in Intelbras MHDX 1004, MHDX 1008, MHDX 1016, MHDX 5016, HDCVI 1008 and HDCVI 1016 up to 20240401. This affects an unknown part of the file /cap.js of the component HTTP GET Request Handler. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The identifier VDB-258933 was assigned to this vulnerability. NOTE: The vendor explains that they do not classify the information shown as sensitive and therefore there is no vulnerability which is about to harm the user.

CVSS3: 5.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-2xvc-p88c-94vw

SAP UI5 Variant Management - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, UI_700 200, does not sufficiently encode user-controlled inputs on reading data from the server, resulting in Stored Cross-Site Scripting (Stored XSS) vulnerability. After successful exploitation, an attacker with user level access can cause high impact on confidentiality, modify some information and can cause unavailability of the application at user level.

CVSS3: 8.2
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2xv9-ghh9-xc69

radashi Allows Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

1%
Низкий
9 месяцев назад
github логотип
GHSA-2xv9-5p9r-jvw2

A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious server or user can send an invalid mood to trigger this vulnerability.

CVSS3: 5.9
2%
Низкий
больше 3 лет назад
github логотип
GHSA-2xv7-rgc5-4ccg

In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:1074, which allows attackers to cause a denial of service via a crafted file.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xv7-mq7h-x6hc

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0889, CVE-2019-0890, CVE-2019-0891, CVE-2019-0893, CVE-2019-0894, CVE-2019-0895, CVE-2019-0896, CVE-2019-0897, CVE-2019-0898, CVE-2019-0899, CVE-2019-0900, CVE-2019-0901.

30%
Средний
больше 3 лет назад
github логотип
GHSA-2xv7-fwh6-x7fc

Subrion Cross-site scripting (XSS) vulnerability

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xv7-55qq-fqg6

Local Security Authority (LSA) Elevation of Privilege Vulnerability.

CVSS3: 7.8
0%
Низкий
почти 4 года назад

Уязвимостей на страницу