Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 375

Количество 314 375

github логотип

GHSA-2vq3-7wqx-v4r2

почти 4 года назад

Unspecified vulnerability in the SMB component in Apple Mac OS X 10.4.11 and 10.5.6 allows remote SMB servers to cause a denial of service (memory exhaustion and system shutdown) via a crafted file system name.

EPSS: Низкий
github логотип

GHSA-2vq2-xc55-3j5m

больше 3 лет назад

libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2vq2-p76v-j88p

почти 4 года назад

Format string vulnerability in ypserv in Mandrake Linux 7.1 and earlier, and possibly other Linux operating systems, allows an attacker to gain root privileges when ypserv is built without a vsyslog() function.

EPSS: Низкий
github логотип

GHSA-2vq2-77wm-755c

почти 4 года назад

Computer Associates (CA) InoculateIT 6.0, eTrust Antivirus r6.0 through r7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content Manager, eTrust Intrusion Detection, EZ-Armor 2.0 through 2.4, and EZ-Antivirus 6.1 through 6.3 allow remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.

EPSS: Средний
github логотип

GHSA-2vpx-p529-jx74

больше 3 лет назад

Use-after-free vulnerability in the SVG implementation in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

EPSS: Низкий
github логотип

GHSA-2vpx-j6gq-83g2

24 дня назад

Multiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data buffers. Due to insufficient validation of maximum buffer size values, the process may attempt to read beyond the intended memory region. Under specific conditions, this can result in a crash of the affected process and a potential denial-of-service of the compromised process.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2vpx-cqm4-rqhq

больше 3 лет назад

An issue was discovered in Joomla! 3.0.0 through 3.9.27. Inadequate escaping in the rules field of the JForm API leads to a XSS vulnerability.

EPSS: Низкий
github логотип

GHSA-2vpw-vxmx-p733

больше 2 лет назад

Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on certain sensitive ones allowing media exploitation from a malicious mattermost server

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-2vpw-mvv7-vfx4

10 месяцев назад

Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/SystemSettings.php?f=update_settings. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2vpw-h4q9-62fp

почти 4 года назад

Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c.

EPSS: Средний
github логотип

GHSA-2vpv-qp3f-2f8m

10 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gopiplus@hotmail.com Anything Popup allows Reflected XSS. This issue affects Anything Popup: from n/a through 7.3.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2vpv-3c94-j6hf

больше 3 лет назад

oBike relies on Hangzhou Luoping Smart Locker to lock bicycles, which allows attackers to bypass the locking mechanism by using Bluetooth Low Energy (BLE) to replay ciphertext based on a predictable nonce used in the locking protocol.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2vpr-vq4j-xqcm

почти 4 года назад

SQL injection vulnerability in admin/news.php in PHP Forge 3.0 beta 2 allows remote attackers to execute arbitrary SQL commands via the id parameter in the news module to admin.php.

EPSS: Низкий
github логотип

GHSA-2vpr-464c-8pg4

больше 3 лет назад

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing VENDOR specific action frame in the function lim_process_action_vendor_specific(), a comparison is performed with the incoming action frame body without validating if the action frame body received is of valid length, potentially leading to an out-of-bounds access.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2vpq-rpjx-r98w

почти 4 года назад

Unspecified vulnerability in HP ProCurve Manager and HP ProCurve Manager Plus 2.3 and earlier allows remote attackers to obtain sensitive information from the ProCurve Manager server via unknown attack vectors.

EPSS: Низкий
github логотип

GHSA-2vpq-fh52-j3wv

около 1 года назад

snowflake-connector-python vulnerable to SQL Injection in write_pandas

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-2vpq-2h36-8fq9

больше 1 года назад

Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settings" page. An unauthenticated attacker can leverage this functionality to upload a malicious PHP file instead. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as the user running the web server.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-2vpp-qc37-v798

около 2 лет назад

Rejected reason: Accidental request.

EPSS: Низкий
github логотип

GHSA-2vpp-jh6p-cxcg

5 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tuyennv TZ PlusGallery allows Stored XSS. This issue affects TZ PlusGallery: from n/a through 1.5.5.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2vpj-c9hx-wv3q

больше 3 лет назад

The Notices WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/notices.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 6.1.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2vq3-7wqx-v4r2

Unspecified vulnerability in the SMB component in Apple Mac OS X 10.4.11 and 10.5.6 allows remote SMB servers to cause a denial of service (memory exhaustion and system shutdown) via a crafted file system name.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2vq2-xc55-3j5m

libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2vq2-p76v-j88p

Format string vulnerability in ypserv in Mandrake Linux 7.1 and earlier, and possibly other Linux operating systems, allows an attacker to gain root privileges when ypserv is built without a vsyslog() function.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2vq2-77wm-755c

Computer Associates (CA) InoculateIT 6.0, eTrust Antivirus r6.0 through r7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content Manager, eTrust Intrusion Detection, EZ-Armor 2.0 through 2.4, and EZ-Antivirus 6.1 through 6.3 allow remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.

30%
Средний
почти 4 года назад
github логотип
GHSA-2vpx-p529-jx74

Use-after-free vulnerability in the SVG implementation in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2vpx-j6gq-83g2

Multiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data buffers. Due to insufficient validation of maximum buffer size values, the process may attempt to read beyond the intended memory region. Under specific conditions, this can result in a crash of the affected process and a potential denial-of-service of the compromised process.

CVSS3: 5.3
0%
Низкий
24 дня назад
github логотип
GHSA-2vpx-cqm4-rqhq

An issue was discovered in Joomla! 3.0.0 through 3.9.27. Inadequate escaping in the rules field of the JForm API leads to a XSS vulnerability.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-2vpw-vxmx-p733

Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on certain sensitive ones allowing media exploitation from a malicious mattermost server

CVSS3: 3.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2vpw-mvv7-vfx4

Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/SystemSettings.php?f=update_settings. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

CVSS3: 9.8
1%
Низкий
10 месяцев назад
github логотип
GHSA-2vpw-h4q9-62fp

Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c.

64%
Средний
почти 4 года назад
github логотип
GHSA-2vpv-qp3f-2f8m

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gopiplus@hotmail.com Anything Popup allows Reflected XSS. This issue affects Anything Popup: from n/a through 7.3.

CVSS3: 7.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-2vpv-3c94-j6hf

oBike relies on Hangzhou Luoping Smart Locker to lock bicycles, which allows attackers to bypass the locking mechanism by using Bluetooth Low Energy (BLE) to replay ciphertext based on a predictable nonce used in the locking protocol.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2vpr-vq4j-xqcm

SQL injection vulnerability in admin/news.php in PHP Forge 3.0 beta 2 allows remote attackers to execute arbitrary SQL commands via the id parameter in the news module to admin.php.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2vpr-464c-8pg4

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing VENDOR specific action frame in the function lim_process_action_vendor_specific(), a comparison is performed with the incoming action frame body without validating if the action frame body received is of valid length, potentially leading to an out-of-bounds access.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2vpq-rpjx-r98w

Unspecified vulnerability in HP ProCurve Manager and HP ProCurve Manager Plus 2.3 and earlier allows remote attackers to obtain sensitive information from the ProCurve Manager server via unknown attack vectors.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2vpq-fh52-j3wv

snowflake-connector-python vulnerable to SQL Injection in write_pandas

CVSS3: 7
0%
Низкий
около 1 года назад
github логотип
GHSA-2vpq-2h36-8fq9

Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settings" page. An unauthenticated attacker can leverage this functionality to upload a malicious PHP file instead. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as the user running the web server.

CVSS3: 9.8
42%
Средний
больше 1 года назад
github логотип
GHSA-2vpp-qc37-v798

Rejected reason: Accidental request.

около 2 лет назад
github логотип
GHSA-2vpp-jh6p-cxcg

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tuyennv TZ PlusGallery allows Stored XSS. This issue affects TZ PlusGallery: from n/a through 1.5.5.

CVSS3: 5.9
0%
Низкий
5 месяцев назад
github логотип
GHSA-2vpj-c9hx-wv3q

The Notices WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/notices.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 6.1.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу