Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 300 405

Количество 300 405

github логотип

GHSA-23fm-v895-3qxq

больше 3 лет назад

jh_captcha for Typo3 XSS Vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-23fj-gx6v-3x6c

больше 3 лет назад

The determineWinner function of a smart contract implementation for HashHeroes Tiles, an Ethereum game, uses a certain blockhash value in an attempt to generate a random number for the case where NUM_TILES equals the number of people who purchased a tile, which allows an attacker to control the awarding of the prize by being the last person to purchase a tile.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-23fj-6rwp-5rq6

5 месяцев назад

Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-23fg-w3cv-jf6w

около 2 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fix possible memory leak if device_add() fails If device_add() returns error, the name allocated by dev_set_name() needs be freed. As the comment of device_add() says, put_device() should be used to decrease the reference count in the error path. So fix this by calling put_device(), then the name can be freed in kobject_cleanp().

EPSS: Низкий
github логотип

GHSA-23fg-rq88-2h56

больше 3 лет назад

IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI displays user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 207610.

EPSS: Низкий
github логотип

GHSA-23ff-wfv3-xrvg

11 месяцев назад

There exists a stack buffer overflow in libjxl. A specifically-crafted file can cause the JPEG XL decoder to use large amounts of stack space (up to 256mb is possible, maybe 512mb), potentially exhausting the stack. An attacker can craft a file that will cause excessive memory usage. We recommend upgrading past commit 65fbec56bc578b6b6ee02a527be70787bbd053b0.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-23ff-vxpg-784h

3 месяца назад

Xftp FTP Client version up to and including 3.0 (build 0238) contain a stack-based buffer overflow vulnerability triggered by a maliciously crafted PWD response from an FTP server. When the client connects to a server and receives an overly long directory string in response to the PWD command, the client fails to properly validate the length of the input before copying it into a fixed-size buffer. This results in memory corruption and allows remote attackers to execute arbitrary code on the client system.

EPSS: Средний
github логотип

GHSA-23ff-j3f9-vw6f

больше 3 лет назад

A flaw was found in libcaca. A buffer overflow of export.c in function export_troff might lead to memory corruption and other potential consequences.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-23fc-p3ph-rj82

больше 3 лет назад

Race condition in the IP logging feature in Cisco Intrusion Prevention System (IPS) Software 7.1(7)E4 and earlier allows remote attackers to cause a denial of service (device reload) via crafted IP traffic that matches a problematic rule, aka Bug ID CSCud82085.

EPSS: Низкий
github логотип

GHSA-23f9-rm56-9hw4

около 1 года назад

Easy test Online Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with regular privilege to inject arbitrary JavaScript code and perform Reflected Cross-site scripting attacks.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-23f8-vj3q-65w6

больше 3 лет назад

In Xymon through 4.3.28, an XSS vulnerability exists in the csvinfo CGI script due to insufficient filtering of the db parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-23f8-9p2x-67mg

больше 3 лет назад

An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_GetShapeBoundingBox() located in swfshape.c. It allows an attacker to cause Denial of Service.

EPSS: Низкий
github логотип

GHSA-23f8-73vw-v59q

больше 3 лет назад

WordPress 2.0.6, and 2.1Alpha 3 (SVN:4662), does not properly verify that the m parameter value has the string data type, which allows remote attackers to obtain sensitive information via an invalid m[] parameter, as demonstrated by obtaining the path, and obtaining certain SQL information such as the table prefix.

EPSS: Низкий
github логотип

GHSA-23f7-xfw7-g3wj

больше 3 лет назад

AtGuard 3.2 allows remote attackers to bypass firwall filters and execute prohibited programs by changing the filenames to permitted filenames.

EPSS: Низкий
github логотип

GHSA-23f7-99jx-m54r

почти 5 лет назад

Remote code execution in dependabot-core branch names when cloning

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-23f6-rghw-jmwg

больше 3 лет назад

The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 allows remote attackers to cause a denial of service (persistent application crash) via a crafted phsh hash attribute in a TXT key.

EPSS: Средний
github логотип

GHSA-23f6-j7x4-jrjh

9 месяцев назад

In SunGrow WiNet-SV200.001.00.P027 and earlier versions, when copying the timestamp read from an MQTT message, the underlying code does not check the bounds of the buffer that is used to store the message. This may lead to a stack-based buffer overflow.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-23f6-33xg-96c7

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in News Manager Lite 2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to comment_add.asp, (2) search parameter to search.asp, or (3) n parameter to category_news_headline.asp.

EPSS: Низкий
github логотип

GHSA-23f5-whxg-92j5

больше 3 лет назад

Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory read, integer overflow, and invalid pointer dereference, a different vulnerability than CVE-2011-0764.

EPSS: Низкий
github логотип

GHSA-23f5-wh7w-47gp

больше 3 лет назад

Directory traversal vulnerability in admin/preview.php in Limny 3.0.0 allows remote attackers to read arbitrary files via a ..%2F (encoded dot dot slash) in the theme parameter.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-23fm-v895-3qxq

jh_captcha for Typo3 XSS Vulnerability

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-23fj-gx6v-3x6c

The determineWinner function of a smart contract implementation for HashHeroes Tiles, an Ethereum game, uses a certain blockhash value in an attempt to generate a random number for the case where NUM_TILES equals the number of people who purchased a tile, which allows an attacker to control the awarding of the prize by being the last person to purchase a tile.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-23fj-6rwp-5rq6

Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-23fg-w3cv-jf6w

In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fix possible memory leak if device_add() fails If device_add() returns error, the name allocated by dev_set_name() needs be freed. As the comment of device_add() says, put_device() should be used to decrease the reference count in the error path. So fix this by calling put_device(), then the name can be freed in kobject_cleanp().

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-23fg-rq88-2h56

IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI displays user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 207610.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23ff-wfv3-xrvg

There exists a stack buffer overflow in libjxl. A specifically-crafted file can cause the JPEG XL decoder to use large amounts of stack space (up to 256mb is possible, maybe 512mb), potentially exhausting the stack. An attacker can craft a file that will cause excessive memory usage. We recommend upgrading past commit 65fbec56bc578b6b6ee02a527be70787bbd053b0.

CVSS3: 7.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-23ff-vxpg-784h

Xftp FTP Client version up to and including 3.0 (build 0238) contain a stack-based buffer overflow vulnerability triggered by a maliciously crafted PWD response from an FTP server. When the client connects to a server and receives an overly long directory string in response to the PWD command, the client fails to properly validate the length of the input before copying it into a fixed-size buffer. This results in memory corruption and allows remote attackers to execute arbitrary code on the client system.

59%
Средний
3 месяца назад
github логотип
GHSA-23ff-j3f9-vw6f

A flaw was found in libcaca. A buffer overflow of export.c in function export_troff might lead to memory corruption and other potential consequences.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-23fc-p3ph-rj82

Race condition in the IP logging feature in Cisco Intrusion Prevention System (IPS) Software 7.1(7)E4 and earlier allows remote attackers to cause a denial of service (device reload) via crafted IP traffic that matches a problematic rule, aka Bug ID CSCud82085.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23f9-rm56-9hw4

Easy test Online Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with regular privilege to inject arbitrary JavaScript code and perform Reflected Cross-site scripting attacks.

CVSS3: 5.4
0%
Низкий
около 1 года назад
github логотип
GHSA-23f8-vj3q-65w6

In Xymon through 4.3.28, an XSS vulnerability exists in the csvinfo CGI script due to insufficient filtering of the db parameter.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-23f8-9p2x-67mg

An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_GetShapeBoundingBox() located in swfshape.c. It allows an attacker to cause Denial of Service.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23f8-73vw-v59q

WordPress 2.0.6, and 2.1Alpha 3 (SVN:4662), does not properly verify that the m parameter value has the string data type, which allows remote attackers to obtain sensitive information via an invalid m[] parameter, as demonstrated by obtaining the path, and obtaining certain SQL information such as the table prefix.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-23f7-xfw7-g3wj

AtGuard 3.2 allows remote attackers to bypass firwall filters and execute prohibited programs by changing the filenames to permitted filenames.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23f7-99jx-m54r

Remote code execution in dependabot-core branch names when cloning

CVSS3: 8.7
1%
Низкий
почти 5 лет назад
github логотип
GHSA-23f6-rghw-jmwg

The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 allows remote attackers to cause a denial of service (persistent application crash) via a crafted phsh hash attribute in a TXT key.

10%
Средний
больше 3 лет назад
github логотип
GHSA-23f6-j7x4-jrjh

In SunGrow WiNet-SV200.001.00.P027 and earlier versions, when copying the timestamp read from an MQTT message, the underlying code does not check the bounds of the buffer that is used to store the message. This may lead to a stack-based buffer overflow.

CVSS3: 9.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-23f6-33xg-96c7

Multiple cross-site scripting (XSS) vulnerabilities in News Manager Lite 2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to comment_add.asp, (2) search parameter to search.asp, or (3) n parameter to category_news_headline.asp.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-23f5-whxg-92j5

Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory read, integer overflow, and invalid pointer dereference, a different vulnerability than CVE-2011-0764.

7%
Низкий
больше 3 лет назад
github логотип
GHSA-23f5-wh7w-47gp

Directory traversal vulnerability in admin/preview.php in Limny 3.0.0 allows remote attackers to read arbitrary files via a ..%2F (encoded dot dot slash) in the theme parameter.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу