Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-2qpc-3frw-rxpf

почти 4 года назад

Race condition in Cisco Adaptive Security Appliance (ASA) 7.0(0), 7.0(2), and 7.0(4), when running with an Active/Standby configuration and when the failover LAN interface fails, allows remote attackers to cause a denial of service (standby firewall failure) by sending spoofed ARP responses from an IP address of an active firewall, which prevents the standby firewall from becoming active, aka "failover denial of service."

EPSS: Низкий
github логотип

GHSA-2qp9-wg27-9pcv

больше 3 лет назад

Nimbus JOSE+JWT missing overflow check

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2qp9-qg33-hhf9

почти 4 года назад

Buffer overflow in the SYSTEM_CREATE_INSTANCE function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.

EPSS: Средний
github логотип

GHSA-2qp9-54h2-9wwv

больше 3 лет назад

A remote code execution vulnerability exists when the Base3D rendering engine improperly handles memory.An attacker who successfully exploited the vulnerability would gain execution on a victim system.The security update addresses the vulnerability by correcting how the Base3D rendering engine handles memory., aka 'Base3D Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-16918.

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-2qp9-4ph2-cj5q

больше 3 лет назад

Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Improper Restriction of XML External Entity Reference ('XXE') vulnerability. Successful exploitation could lead to Arbitrary read access to the file system in the context of the current user.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2qp6-v7mh-v798

27 дней назад

SAP Product Designer Web UI of Business Server Pages allows authenticated non-administrative users to access non-sensitive information. This results in a low impact on confidentiality, with no impact on integrity or availability of the application.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2qp6-q6vf-5x4c

больше 3 лет назад

Installers of Kaspersky Security Center and Kaspersky Security Center Web Console prior to 12 & prior to 12 Patch A were vulnerable to a DLL hijacking attack that allowed an attacker to elevate privileges in the system.

EPSS: Низкий
github логотип

GHSA-2qp5-wv2r-fqw5

почти 4 года назад

SAP NetWeaver 7.0 allows Remote Code Execution and Denial of Service caused by an error in the DiagTraceHex() function. By sending a specially-crafted packet, an attacker could exploit this vulnerability to cause the application to crash.

EPSS: Низкий
github логотип

GHSA-2qp5-r446-qvgh

больше 3 лет назад

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.

EPSS: Низкий
github логотип

GHSA-2qp5-3jc8-pprj

больше 2 лет назад

An improper check for an exceptional condition in the Insider Threat Management (ITM) Server could be used by an attacker to change the configuration of any already-registered agent so that all future agent communications are sent to an attacker-chosen URL. An attacker must first successfully obtain valid agent credentials and target agent hostname. All versions prior to 7.14.3.69 are affected.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2qp4-xpm8-6jmq

почти 4 года назад

TRIGONE Remote System Monitor 3.61 is vulnerable to an unquoted path service allowing local users to launch processes with elevated privileges.

EPSS: Низкий
github логотип

GHSA-2qp4-x94h-6q6w

больше 2 лет назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themesgrove Onepage Builder allows SQL Injection.This issue affects Onepage Builder: from n/a through 2.4.1.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2qp4-wwrv-gf4c

больше 3 лет назад

A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in avcodec_alloc_context3 at options.c.

EPSS: Низкий
github логотип

GHSA-2qp4-g3q3-f92w

почти 4 года назад

Improper Locking in JetBrains Kotlin

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2qp4-532r-wmc3

больше 3 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the Maestro module 7.x-1.x before 7.x-1.2 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) change workflows or (2) insert cross-site scripting (XSS) sequences.

EPSS: Низкий
github логотип

GHSA-2qp2-pf59-94fr

больше 3 лет назад

socat 1.2.0.0 before 1.7.2.2 and 2.0.0-b1 before 2.0.0-b6, when used for a listen type address and the fork option is enabled, allows remote attackers to cause a denial of service (file descriptor consumption) via multiple request that are refused based on the (1) sourceport, (2) lowport, (3) range, or (4) tcpwrap restrictions.

EPSS: Низкий
github логотип

GHSA-2qmx-rjgf-q7p7

больше 3 лет назад

In Eclipse Buildship versions prior to 3.1.1, the build files indicate that this project is resolving dependencies over HTTP instead of HTTPS. Any of these artifacts could have been MITM to maliciously compromise them and infect the build artifacts that were produced. Additionally, if any of these JARs or other dependencies were compromised, any developers using these could continue to be infected past updating to fix this.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2qmx-2jj7-w7qw

больше 3 лет назад

The GemFire broker for Cloud Foundry 1.6.x before 1.6.5 and 1.7.x before 1.7.1 has multiple API endpoints which do not require authentication and could be used to gain access to the cluster managed by the broker.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2qmw-pvf7-4mw6

больше 1 года назад

Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2qmw-g869-r668

3 месяца назад

Out-of-bounds Read in Shelly Pro 3EM (before v1.4.4) allows Overread Buffers.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2qpc-3frw-rxpf

Race condition in Cisco Adaptive Security Appliance (ASA) 7.0(0), 7.0(2), and 7.0(4), when running with an Active/Standby configuration and when the failover LAN interface fails, allows remote attackers to cause a denial of service (standby firewall failure) by sending spoofed ARP responses from an IP address of an active firewall, which prevents the standby firewall from becoming active, aka "failover denial of service."

1%
Низкий
почти 4 года назад
github логотип
GHSA-2qp9-wg27-9pcv

Nimbus JOSE+JWT missing overflow check

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2qp9-qg33-hhf9

Buffer overflow in the SYSTEM_CREATE_INSTANCE function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.

10%
Средний
почти 4 года назад
github логотип
GHSA-2qp9-54h2-9wwv

A remote code execution vulnerability exists when the Base3D rendering engine improperly handles memory.An attacker who successfully exploited the vulnerability would gain execution on a victim system.The security update addresses the vulnerability by correcting how the Base3D rendering engine handles memory., aka 'Base3D Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-16918.

CVSS3: 7.8
12%
Средний
больше 3 лет назад
github логотип
GHSA-2qp9-4ph2-cj5q

Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Improper Restriction of XML External Entity Reference ('XXE') vulnerability. Successful exploitation could lead to Arbitrary read access to the file system in the context of the current user.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2qp6-v7mh-v798

SAP Product Designer Web UI of Business Server Pages allows authenticated non-administrative users to access non-sensitive information. This results in a low impact on confidentiality, with no impact on integrity or availability of the application.

CVSS3: 4.3
0%
Низкий
27 дней назад
github логотип
GHSA-2qp6-q6vf-5x4c

Installers of Kaspersky Security Center and Kaspersky Security Center Web Console prior to 12 & prior to 12 Patch A were vulnerable to a DLL hijacking attack that allowed an attacker to elevate privileges in the system.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2qp5-wv2r-fqw5

SAP NetWeaver 7.0 allows Remote Code Execution and Denial of Service caused by an error in the DiagTraceHex() function. By sending a specially-crafted packet, an attacker could exploit this vulnerability to cause the application to crash.

2%
Низкий
почти 4 года назад
github логотип
GHSA-2qp5-r446-qvgh

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2qp5-3jc8-pprj

An improper check for an exceptional condition in the Insider Threat Management (ITM) Server could be used by an attacker to change the configuration of any already-registered agent so that all future agent communications are sent to an attacker-chosen URL. An attacker must first successfully obtain valid agent credentials and target agent hostname. All versions prior to 7.14.3.69 are affected.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2qp4-xpm8-6jmq

TRIGONE Remote System Monitor 3.61 is vulnerable to an unquoted path service allowing local users to launch processes with elevated privileges.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2qp4-x94h-6q6w

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themesgrove Onepage Builder allows SQL Injection.This issue affects Onepage Builder: from n/a through 2.4.1.

CVSS3: 7.2
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2qp4-wwrv-gf4c

A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in avcodec_alloc_context3 at options.c.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2qp4-g3q3-f92w

Improper Locking in JetBrains Kotlin

CVSS3: 5.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-2qp4-532r-wmc3

Multiple cross-site request forgery (CSRF) vulnerabilities in the Maestro module 7.x-1.x before 7.x-1.2 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) change workflows or (2) insert cross-site scripting (XSS) sequences.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2qp2-pf59-94fr

socat 1.2.0.0 before 1.7.2.2 and 2.0.0-b1 before 2.0.0-b6, when used for a listen type address and the fork option is enabled, allows remote attackers to cause a denial of service (file descriptor consumption) via multiple request that are refused based on the (1) sourceport, (2) lowport, (3) range, or (4) tcpwrap restrictions.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2qmx-rjgf-q7p7

In Eclipse Buildship versions prior to 3.1.1, the build files indicate that this project is resolving dependencies over HTTP instead of HTTPS. Any of these artifacts could have been MITM to maliciously compromise them and infect the build artifacts that were produced. Additionally, if any of these JARs or other dependencies were compromised, any developers using these could continue to be infected past updating to fix this.

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2qmx-2jj7-w7qw

The GemFire broker for Cloud Foundry 1.6.x before 1.6.5 and 1.7.x before 1.7.1 has multiple API endpoints which do not require authentication and could be used to gain access to the cluster managed by the broker.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-2qmw-pvf7-4mw6

Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2qmw-g869-r668

Out-of-bounds Read in Shelly Pro 3EM (before v1.4.4) allows Overread Buffers.

0%
Низкий
3 месяца назад

Уязвимостей на страницу