Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2vqh-xv99-28cc

больше 3 лет назад

The putcontig8bitCIELab function in tif_getimage.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a packed TIFF image.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2vqh-h684-hcw9

около 1 месяца назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий
github логотип

GHSA-2vqg-h6qw-2r32

больше 2 лет назад

SQL injection vulnerability in Arconte Áurea, in its 1.5.0.0 version. The exploitation of this vulnerability could allow an attacker to read sensitive data from the database, modify data (insert/update/delete), perform database administration operations and, in some cases, execute commands on the operating system.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2vqg-gr4m-v458

больше 3 лет назад

A stored Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.7 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious Jira API responses

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2vqc-674h-xh9w

около 1 года назад

An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used in an OS command, an unauthenticated attacker is able to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test.

CVSS3: 10
EPSS: Критический
github логотип

GHSA-2vq9-xxfq-v5cf

больше 3 лет назад

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Processing a maliciously crafted image may lead to arbitrary code execution.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2vq9-x634-p9m5

почти 4 года назад

An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue a xattr request via glusterfs FUSE to determine the existence of any file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2vq9-q9w6-2hh6

больше 3 лет назад

The remember me feature in portal/scr_authentif.php in POSH (aka Posh portal or Portaneo) 3.0, 3.2.1, 3.3.0, and earlier stores the username and MD5 digest of the password in cleartext in a cookie, which allows attackers to obtain sensitive information by reading this cookie.

EPSS: Низкий
github логотип

GHSA-2vq8-2cg2-c3hv

больше 3 лет назад

Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to bypass authentication via a web-administration request that lacks a password parameter.

EPSS: Низкий
github логотип

GHSA-2vq7-p8mj-cpc6

7 месяцев назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий
github логотип

GHSA-2vq7-c2r9-jgpf

больше 3 лет назад

Windows Fast FAT File System Driver Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-38662.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2vq7-8vvf-w66v

почти 2 года назад

Exim libspf2 Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Exim libspf2. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parsing of SPF macros. When parsing SPF macros, the process does not properly validate user-supplied data, which can result in an integer underflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-17578.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2vq6-f897-g2gx

больше 3 лет назад

Stack-based buffer overflow in the main function in util/lpci_main.c in Csound before 5.17.2, when converting a file, allows user-assisted remote attackers to execute arbitrary code via a crafted file.

EPSS: Низкий
github логотип

GHSA-2vq6-7g93-mrhp

больше 3 лет назад

The Register Plus plugin 3.5.1 and earlier for WordPress allows remote attackers to obtain sensitive information via a direct request to (1) dash_widget.php and (2) register-plus.php, which reveals the installation path in an error message.

EPSS: Низкий
github логотип

GHSA-2vq4-6g9q-2xjq

больше 3 лет назад

The Eat Spray Love mobile app for both iOS and Android contains logic that allows users to bypass authentication and retrieve or modify information that they would not normally have access to.

EPSS: Низкий
github логотип

GHSA-2vq3-r375-cjhg

9 месяцев назад

Use after free in WebAudio in Google Chrome prior to 136.0.7103.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2vq3-9f5g-9jr5

почти 2 года назад

Substance3D - Designer versions 13.1.0 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2vq3-7wqx-v4r2

почти 4 года назад

Unspecified vulnerability in the SMB component in Apple Mac OS X 10.4.11 and 10.5.6 allows remote SMB servers to cause a denial of service (memory exhaustion and system shutdown) via a crafted file system name.

EPSS: Низкий
github логотип

GHSA-2vq2-xc55-3j5m

больше 3 лет назад

libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2vq2-p76v-j88p

почти 4 года назад

Format string vulnerability in ypserv in Mandrake Linux 7.1 and earlier, and possibly other Linux operating systems, allows an attacker to gain root privileges when ypserv is built without a vsyslog() function.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2vqh-xv99-28cc

The putcontig8bitCIELab function in tif_getimage.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a packed TIFF image.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2vqh-h684-hcw9

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

около 1 месяца назад
github логотип
GHSA-2vqg-h6qw-2r32

SQL injection vulnerability in Arconte Áurea, in its 1.5.0.0 version. The exploitation of this vulnerability could allow an attacker to read sensitive data from the database, modify data (insert/update/delete), perform database administration operations and, in some cases, execute commands on the operating system.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2vqg-gr4m-v458

A stored Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.7 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious Jira API responses

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2vqc-674h-xh9w

An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used in an OS command, an unauthenticated attacker is able to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test.

CVSS3: 10
94%
Критический
около 1 года назад
github логотип
GHSA-2vq9-xxfq-v5cf

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Processing a maliciously crafted image may lead to arbitrary code execution.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2vq9-x634-p9m5

An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue a xattr request via glusterfs FUSE to determine the existence of any file.

CVSS3: 6.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-2vq9-q9w6-2hh6

The remember me feature in portal/scr_authentif.php in POSH (aka Posh portal or Portaneo) 3.0, 3.2.1, 3.3.0, and earlier stores the username and MD5 digest of the password in cleartext in a cookie, which allows attackers to obtain sensitive information by reading this cookie.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2vq8-2cg2-c3hv

Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to bypass authentication via a web-administration request that lacks a password parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2vq7-p8mj-cpc6

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

7 месяцев назад
github логотип
GHSA-2vq7-c2r9-jgpf

Windows Fast FAT File System Driver Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-38662.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2vq7-8vvf-w66v

Exim libspf2 Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Exim libspf2. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parsing of SPF macros. When parsing SPF macros, the process does not properly validate user-supplied data, which can result in an integer underflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-17578.

CVSS3: 7.5
3%
Низкий
почти 2 года назад
github логотип
GHSA-2vq6-f897-g2gx

Stack-based buffer overflow in the main function in util/lpci_main.c in Csound before 5.17.2, when converting a file, allows user-assisted remote attackers to execute arbitrary code via a crafted file.

6%
Низкий
больше 3 лет назад
github логотип
GHSA-2vq6-7g93-mrhp

The Register Plus plugin 3.5.1 and earlier for WordPress allows remote attackers to obtain sensitive information via a direct request to (1) dash_widget.php and (2) register-plus.php, which reveals the installation path in an error message.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2vq4-6g9q-2xjq

The Eat Spray Love mobile app for both iOS and Android contains logic that allows users to bypass authentication and retrieve or modify information that they would not normally have access to.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2vq3-r375-cjhg

Use after free in WebAudio in Google Chrome prior to 136.0.7103.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 8.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-2vq3-9f5g-9jr5

Substance3D - Designer versions 13.1.0 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-2vq3-7wqx-v4r2

Unspecified vulnerability in the SMB component in Apple Mac OS X 10.4.11 and 10.5.6 allows remote SMB servers to cause a denial of service (memory exhaustion and system shutdown) via a crafted file system name.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2vq2-xc55-3j5m

libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2vq2-p76v-j88p

Format string vulnerability in ypserv in Mandrake Linux 7.1 and earlier, and possibly other Linux operating systems, allows an attacker to gain root privileges when ypserv is built without a vsyslog() function.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу