Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2xr8-cfj3-j3g6

почти 4 года назад

The Sun Java System (SJS) Access Manager Policy Agent module 2.2 for SJS Web Proxy Server 4.0 allows remote attackers to cause a denial of service (daemon crash) via a GET request.

EPSS: Низкий
github логотип

GHSA-2xr8-8pmh-25v6

больше 3 лет назад

The ff_hevc_decode_nal_sps function in libavcodec/hevc_ps.c in FFMpeg before 2.1.6, 2.2.x through 2.3.x, and 2.4.x before 2.4.4 allows remote attackers to cause a denial of service (out-of-bounds access) via a crafted .bit file.

EPSS: Низкий
github логотип

GHSA-2xr8-28cv-28vv

больше 3 лет назад

A memory leak in the kernel_read_file function in fs/exec.c in the Linux kernel through 4.20.11 allows attackers to cause a denial of service (memory consumption) by triggering vfs_read failures.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2xr7-wx8r-phrv

больше 3 лет назад

Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when processing the Flash Video container file format. Successful exploitation could lead to arbitrary code execution.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-2xr7-8r47-7mc6

почти 4 года назад

SQL injection vulnerability in form.php in 360 Web Manager 3.0 allows remote attackers to execute arbitrary SQL commands via the IDFM parameter.

EPSS: Низкий
github логотип

GHSA-2xr7-8qgr-hch2

около 2 месяцев назад

A use-after-free vulnerability exists in the AcroForm handling of Foxit PDF Reader and Foxit PDF Editor before 2025.2.1,14.0.1 and 13.2.1 on Windows . When opening a PDF containing specially crafted JavaScript, a pointer to memory that has already been freed may be accessed or dereferenced, potentially allowing a remote attacker to execute arbitrary code.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2xr6-hq4p-xw85

почти 4 года назад

Pioneers meta-server before 0.9.55, when the server-console is not installed, allows remote attackers to cause a denial of service (crash) via certain requests from an older gnocatan client to create a new game.

EPSS: Низкий
github логотип

GHSA-2xr3-fxm9-q75h

около 2 лет назад

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2xr3-2r6g-cgx8

5 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: drm/msm/dpu: Add a null ptr check for dpu_encoder_needs_modeset The drm_atomic_get_new_connector_state() can return NULL if the connector is not part of the atomic state. Add a check to prevent a NULL pointer dereference. This follows the same pattern used in dpu_encoder_update_topology() within the same file, which checks for NULL before using conn_state. Patchwork: https://patchwork.freedesktop.org/patch/665188/

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2xr2-2545-997q

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in CartWIZ ASP Cart allow remote attackers to inject arbitrary web script or HTML via the idProduct parameter to (1) tellAFriend.asp or (2) addToWishlist.asp, redirect parameter to (3) access.asp or (4) login.asp, message parameter to (5) login.asp or (6) error.asp, or (7) sku or (8) name parameter to searchResults.asp.

EPSS: Низкий
github логотип

GHSA-2xqw-mg48-p4j5

9 месяцев назад

A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. A sandboxed app may be able to access sensitive user data.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2xqv-jq2p-7rr6

почти 4 года назад

An exception is thrown from a function in AVEVA System Platform versions 2017 through 2020 R2 P01, but it is not caught, which may cause a denial-of-service condition.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2xqv-ggw6-mr8h

больше 2 лет назад

A vulnerability was found in Onest CRM 1.0. It has been classified as problematic. This affects an unknown part of the file /admin/project/update/2 of the component Project List Handler. The manipulation of the argument name with the input <script>alert(1)</script> leads to cross site scripting. It is possible to initiate the attack remotely. The identifier VDB-232953 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-2xqv-f63h-r6rj

больше 3 лет назад

SOGo before 2.3.12 and 3.x before 3.1.1 does not restrict access to the UID and DTSTAMP attributes, which allows remote authenticated users to obtain sensitive information about appointments with the "View the Date & Time" restriction, as demonstrated by correlating UIDs and DTSTAMPs between all users.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2xqr-c8hh-496c

больше 3 лет назад

HEVC Video Extensions Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-24110, CVE-2021-26902, CVE-2021-27047, CVE-2021-27048, CVE-2021-27049, CVE-2021-27050, CVE-2021-27051, CVE-2021-27061, CVE-2021-27062.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2xqq-rhmm-h69h

больше 3 лет назад

A stack-based buffer overflow in zap_parse_args in zap.c in zap in Ruckus Unleashed through 200.7.10.102.64 allows remote code execution via an unauthenticated HTTP request.

EPSS: Средний
github логотип

GHSA-2xqm-cm83-qxwh

больше 3 лет назад

An issue was discovered in Mattermost Server before 5.11.0. An attacker can interfere with a channel's post loading via one crafted post.

EPSS: Низкий
github логотип

GHSA-2xqm-8vg5-2563

больше 3 лет назад

Unspecified vulnerability in Oracle Java SE 6u75, 7u60, and 8u5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.

EPSS: Низкий
github логотип

GHSA-2xqm-7gh5-cjmc

больше 3 лет назад

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e41b8.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2xqj-cmwx-35rp

8 месяцев назад

Rejected reason: Not used

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2xr8-cfj3-j3g6

The Sun Java System (SJS) Access Manager Policy Agent module 2.2 for SJS Web Proxy Server 4.0 allows remote attackers to cause a denial of service (daemon crash) via a GET request.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2xr8-8pmh-25v6

The ff_hevc_decode_nal_sps function in libavcodec/hevc_ps.c in FFMpeg before 2.1.6, 2.2.x through 2.3.x, and 2.4.x before 2.4.4 allows remote attackers to cause a denial of service (out-of-bounds access) via a crafted .bit file.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2xr8-28cv-28vv

A memory leak in the kernel_read_file function in fs/exec.c in the Linux kernel through 4.20.11 allows attackers to cause a denial of service (memory consumption) by triggering vfs_read failures.

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-2xr7-wx8r-phrv

Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when processing the Flash Video container file format. Successful exploitation could lead to arbitrary code execution.

CVSS3: 9.8
69%
Средний
больше 3 лет назад
github логотип
GHSA-2xr7-8r47-7mc6

SQL injection vulnerability in form.php in 360 Web Manager 3.0 allows remote attackers to execute arbitrary SQL commands via the IDFM parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2xr7-8qgr-hch2

A use-after-free vulnerability exists in the AcroForm handling of Foxit PDF Reader and Foxit PDF Editor before 2025.2.1,14.0.1 and 13.2.1 on Windows . When opening a PDF containing specially crafted JavaScript, a pointer to memory that has already been freed may be accessed or dereferenced, potentially allowing a remote attacker to execute arbitrary code.

CVSS3: 7.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2xr6-hq4p-xw85

Pioneers meta-server before 0.9.55, when the server-console is not installed, allows remote attackers to cause a denial of service (crash) via certain requests from an older gnocatan client to create a new game.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2xr3-fxm9-q75h

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVSS3: 7.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-2xr3-2r6g-cgx8

In the Linux kernel, the following vulnerability has been resolved: drm/msm/dpu: Add a null ptr check for dpu_encoder_needs_modeset The drm_atomic_get_new_connector_state() can return NULL if the connector is not part of the atomic state. Add a check to prevent a NULL pointer dereference. This follows the same pattern used in dpu_encoder_update_topology() within the same file, which checks for NULL before using conn_state. Patchwork: https://patchwork.freedesktop.org/patch/665188/

CVSS3: 5.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-2xr2-2545-997q

Multiple cross-site scripting (XSS) vulnerabilities in CartWIZ ASP Cart allow remote attackers to inject arbitrary web script or HTML via the idProduct parameter to (1) tellAFriend.asp or (2) addToWishlist.asp, redirect parameter to (3) access.asp or (4) login.asp, message parameter to (5) login.asp or (6) error.asp, or (7) sku or (8) name parameter to searchResults.asp.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2xqw-mg48-p4j5

A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.6, macOS Sequoia 15.5, macOS Sonoma 14.7.6. A sandboxed app may be able to access sensitive user data.

CVSS3: 7.1
0%
Низкий
9 месяцев назад
github логотип
GHSA-2xqv-jq2p-7rr6

An exception is thrown from a function in AVEVA System Platform versions 2017 through 2020 R2 P01, but it is not caught, which may cause a denial-of-service condition.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-2xqv-ggw6-mr8h

A vulnerability was found in Onest CRM 1.0. It has been classified as problematic. This affects an unknown part of the file /admin/project/update/2 of the component Project List Handler. The manipulation of the argument name with the input <script>alert(1)</script> leads to cross site scripting. It is possible to initiate the attack remotely. The identifier VDB-232953 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2xqv-f63h-r6rj

SOGo before 2.3.12 and 3.x before 3.1.1 does not restrict access to the UID and DTSTAMP attributes, which allows remote authenticated users to obtain sensitive information about appointments with the "View the Date & Time" restriction, as demonstrated by correlating UIDs and DTSTAMPs between all users.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xqr-c8hh-496c

HEVC Video Extensions Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-24110, CVE-2021-26902, CVE-2021-27047, CVE-2021-27048, CVE-2021-27049, CVE-2021-27050, CVE-2021-27051, CVE-2021-27061, CVE-2021-27062.

CVSS3: 7.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-2xqq-rhmm-h69h

A stack-based buffer overflow in zap_parse_args in zap.c in zap in Ruckus Unleashed through 200.7.10.102.64 allows remote code execution via an unauthenticated HTTP request.

22%
Средний
больше 3 лет назад
github логотип
GHSA-2xqm-cm83-qxwh

An issue was discovered in Mattermost Server before 5.11.0. An attacker can interfere with a channel's post loading via one crafted post.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xqm-8vg5-2563

Unspecified vulnerability in Oracle Java SE 6u75, 7u60, and 8u5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.

8%
Низкий
больше 3 лет назад
github логотип
GHSA-2xqm-7gh5-cjmc

OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e41b8.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2xqj-cmwx-35rp

Rejected reason: Not used

8 месяцев назад

Уязвимостей на страницу