Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 300 093

Количество 300 093

github логотип

GHSA-23f8-9p2x-67mg

больше 3 лет назад

An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_GetShapeBoundingBox() located in swfshape.c. It allows an attacker to cause Denial of Service.

EPSS: Низкий
github логотип

GHSA-23f8-73vw-v59q

больше 3 лет назад

WordPress 2.0.6, and 2.1Alpha 3 (SVN:4662), does not properly verify that the m parameter value has the string data type, which allows remote attackers to obtain sensitive information via an invalid m[] parameter, as demonstrated by obtaining the path, and obtaining certain SQL information such as the table prefix.

EPSS: Низкий
github логотип

GHSA-23f7-xfw7-g3wj

больше 3 лет назад

AtGuard 3.2 allows remote attackers to bypass firwall filters and execute prohibited programs by changing the filenames to permitted filenames.

EPSS: Низкий
github логотип

GHSA-23f7-99jx-m54r

почти 5 лет назад

Remote code execution in dependabot-core branch names when cloning

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-23f6-rghw-jmwg

больше 3 лет назад

The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 allows remote attackers to cause a denial of service (persistent application crash) via a crafted phsh hash attribute in a TXT key.

EPSS: Средний
github логотип

GHSA-23f6-j7x4-jrjh

9 месяцев назад

In SunGrow WiNet-SV200.001.00.P027 and earlier versions, when copying the timestamp read from an MQTT message, the underlying code does not check the bounds of the buffer that is used to store the message. This may lead to a stack-based buffer overflow.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-23f6-33xg-96c7

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in News Manager Lite 2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to comment_add.asp, (2) search parameter to search.asp, or (3) n parameter to category_news_headline.asp.

EPSS: Низкий
github логотип

GHSA-23f5-whxg-92j5

больше 3 лет назад

Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory read, integer overflow, and invalid pointer dereference, a different vulnerability than CVE-2011-0764.

EPSS: Низкий
github логотип

GHSA-23f5-wh7w-47gp

больше 3 лет назад

Directory traversal vulnerability in admin/preview.php in Limny 3.0.0 allows remote attackers to read arbitrary files via a ..%2F (encoded dot dot slash) in the theme parameter.

EPSS: Низкий
github логотип

GHSA-23f5-q32q-xcxm

больше 3 лет назад

hw/rdma/vmw/pvrdma_cmd.c in QEMU allows create_cq and create_qp memory leaks because errors are mishandled.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-23f5-gr55-w97f

больше 2 лет назад

Sme.UP ERP TOKYO V6R1M220406 was discovered to contain an information disclosure vulnerability via the /debug endpoint. This vulnerability allows attackers to access cleartext credentials needed to authenticate to the AS400 system.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-23f5-2x6m-443f

больше 3 лет назад

The XML Sitemaps WordPress plugin before 4.1.3 does not sanitise and escape a settings before outputting it in the Debug page, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-23f4-r5mp-f393

больше 3 лет назад

In the default configuration of Rangee GmbH RangeeOS 8.0.4, all components are executed in the context of the privileged root user. This may allow a local attacker to break out of the restricted environment or inject malicious code into the application and fully compromise the operating system.

EPSS: Низкий
github логотип

GHSA-23f4-p98f-875g

больше 3 лет назад

Apple Mac OS X AppleTalk allows local users to cause a denial of service (kernel panic) by calling the AIOCREGLOCALZN ioctl command with a crafted data structure on an AppleTalk socket.

EPSS: Низкий
github логотип

GHSA-23f4-32qx-cg2x

больше 3 лет назад

The master-station DNP3 driver before driver19.exe, and Beta2041.exe, in IOServer allows remote attackers to cause a denial of service (infinite loop) via crafted DNP3 packets to TCP port 20000.

EPSS: Низкий
github логотип

GHSA-23f3-vhq3-gx53

больше 3 лет назад

AppCMS 2.0.101 in /admin/template/tpl_app.php has a cross site scripting attack vulnerability which allows the attacker to obtain sensitive information of other users.

EPSS: Низкий
github логотип

GHSA-23f3-rj2m-g7gq

больше 3 лет назад

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SSRSReport class. Due to the improper restriction of XML External Entity (XXE) references, a specially crafted document specifying a URI causes the XML parser to access the URI and embed the contents back into the XML document for further processing. An attacker can leverage this vulnerability to disclose file contents in the context of SYSTEM. Was ZDI-CAN-10709.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-23f3-58hp-h48q

около 2 лет назад

The FormCraft WordPress plugin before 1.2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-23f2-vgr6-fwv7

больше 3 лет назад

Command injection in librenms

EPSS: Низкий
github логотип

GHSA-23f2-m2wj-439r

больше 3 лет назад

In ImageMagick 7.0.6-5, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which allows attackers to cause a denial of service via a crafted file.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-23f8-9p2x-67mg

An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_GetShapeBoundingBox() located in swfshape.c. It allows an attacker to cause Denial of Service.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23f8-73vw-v59q

WordPress 2.0.6, and 2.1Alpha 3 (SVN:4662), does not properly verify that the m parameter value has the string data type, which allows remote attackers to obtain sensitive information via an invalid m[] parameter, as demonstrated by obtaining the path, and obtaining certain SQL information such as the table prefix.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-23f7-xfw7-g3wj

AtGuard 3.2 allows remote attackers to bypass firwall filters and execute prohibited programs by changing the filenames to permitted filenames.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23f7-99jx-m54r

Remote code execution in dependabot-core branch names when cloning

CVSS3: 8.7
1%
Низкий
почти 5 лет назад
github логотип
GHSA-23f6-rghw-jmwg

The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 allows remote attackers to cause a denial of service (persistent application crash) via a crafted phsh hash attribute in a TXT key.

10%
Средний
больше 3 лет назад
github логотип
GHSA-23f6-j7x4-jrjh

In SunGrow WiNet-SV200.001.00.P027 and earlier versions, when copying the timestamp read from an MQTT message, the underlying code does not check the bounds of the buffer that is used to store the message. This may lead to a stack-based buffer overflow.

CVSS3: 9.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-23f6-33xg-96c7

Multiple cross-site scripting (XSS) vulnerabilities in News Manager Lite 2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to comment_add.asp, (2) search parameter to search.asp, or (3) n parameter to category_news_headline.asp.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-23f5-whxg-92j5

Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory read, integer overflow, and invalid pointer dereference, a different vulnerability than CVE-2011-0764.

7%
Низкий
больше 3 лет назад
github логотип
GHSA-23f5-wh7w-47gp

Directory traversal vulnerability in admin/preview.php in Limny 3.0.0 allows remote attackers to read arbitrary files via a ..%2F (encoded dot dot slash) in the theme parameter.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-23f5-q32q-xcxm

hw/rdma/vmw/pvrdma_cmd.c in QEMU allows create_cq and create_qp memory leaks because errors are mishandled.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-23f5-gr55-w97f

Sme.UP ERP TOKYO V6R1M220406 was discovered to contain an information disclosure vulnerability via the /debug endpoint. This vulnerability allows attackers to access cleartext credentials needed to authenticate to the AS400 system.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-23f5-2x6m-443f

The XML Sitemaps WordPress plugin before 4.1.3 does not sanitise and escape a settings before outputting it in the Debug page, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-23f4-r5mp-f393

In the default configuration of Rangee GmbH RangeeOS 8.0.4, all components are executed in the context of the privileged root user. This may allow a local attacker to break out of the restricted environment or inject malicious code into the application and fully compromise the operating system.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23f4-p98f-875g

Apple Mac OS X AppleTalk allows local users to cause a denial of service (kernel panic) by calling the AIOCREGLOCALZN ioctl command with a crafted data structure on an AppleTalk socket.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-23f4-32qx-cg2x

The master-station DNP3 driver before driver19.exe, and Beta2041.exe, in IOServer allows remote attackers to cause a denial of service (infinite loop) via crafted DNP3 packets to TCP port 20000.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23f3-vhq3-gx53

AppCMS 2.0.101 in /admin/template/tpl_app.php has a cross site scripting attack vulnerability which allows the attacker to obtain sensitive information of other users.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23f3-rj2m-g7gq

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SSRSReport class. Due to the improper restriction of XML External Entity (XXE) references, a specially crafted document specifying a URI causes the XML parser to access the URI and embed the contents back into the XML document for further processing. An attacker can leverage this vulnerability to disclose file contents in the context of SYSTEM. Was ZDI-CAN-10709.

CVSS3: 7.5
22%
Средний
больше 3 лет назад
github логотип
GHSA-23f3-58hp-h48q

The FormCraft WordPress plugin before 1.2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 4.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-23f2-vgr6-fwv7

Command injection in librenms

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23f2-m2wj-439r

In ImageMagick 7.0.6-5, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which allows attackers to cause a denial of service via a crafted file.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу