Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2vj6-wmm6-q722

4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: smb: client: let recv_done verify data_offset, data_length and remaining_data_length This is inspired by the related server fixes.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2vj6-p9c5-8h3v

больше 3 лет назад

main/translate.c in Sangoma Asterisk 13.28.0 and 16.5.0 allows a remote attacker to send a specific RTP packet during a call and cause a crash in a specific scenario.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2vj6-mvxm-4f5f

больше 3 лет назад

The _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in GnuTLS 2.12.23 allows remote attackers to cause a denial of service (buffer over-read and crash) via a crafted padding length. NOTE: this might be due to an incorrect fix for CVE-2013-0169.

EPSS: Низкий
github логотип

GHSA-2vj5-r237-wrxw

11 месяцев назад

Out-of-bounds read in applying binary of voice content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2vj5-px25-gjrp

около 4 лет назад

pytorch-lightning is vulnerable to Deserialization of Untrusted Data

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2vj4-mfcc-xffc

больше 3 лет назад

MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 uses the thumbnail ImageMagick command line argument, which allows remote attackers to obtain the installation path by reading the metadata of a PNG thumbnail file.

EPSS: Низкий
github логотип

GHSA-2vj4-82m3-c6h5

почти 4 года назад

Buffer overflow in efax 0.9 and earlier, when installed setuid root, allows local users to execute arbitrary code via a long -x argument.

EPSS: Низкий
github логотип

GHSA-2vj3-wf4c-q7hg

больше 3 лет назад

In Gxlcms QY v1.0.0713, Lib\Lib\Action\Admin\DataAction.class.php allows remote attackers to delete any file via directory traversal sequences in the id parameter of an Admin-Data-del request.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2vj3-75qw-x4pm

почти 4 года назад

SQL injection vulnerability in pblguestbook.php in Pixelated By Lev (PBL) Guestbook 1.32 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) name, (2) email, (3) website, (4) comments, (5) rate, and (6) private parameters.

EPSS: Низкий
github логотип

GHSA-2vhx-gg9g-r3h4

больше 3 лет назад

The official drupal docker images before 8.5.10-fpm-alpine (Alpine specific) contain a blank password for a root user. System using the drupal docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.

EPSS: Средний
github логотип

GHSA-2vhx-cw73-6rc9

больше 3 лет назад

Buffer overflow in HECI subsystem in Intel(R) CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 and Intel(R) TXE version before 3.1.60 or 4.0.10, or Intel(R) Server Platform Services before version 5.00.04.012 may allow an unauthenticated user to potentially execute arbitrary code via physical access.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-2vhw-q36q-j3v5

больше 2 лет назад

BASupSrvcUpdater.exe in N-able Take Control Agent through 7.0.41.1141 before 7.0.43 has a TOCTOU Race Condition via a pseudo-symlink at %PROGRAMDATA%\GetSupportService_N-Central\PushUpdates, leading to arbitrary file deletion.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-2vhw-f897-f2qr

больше 3 лет назад

An issue was discovered on Samsung mobile devices with P(9.0) software. Gallery leaks cached data. The Samsung IDs are SVE-2019-16010, SVE-2019-16011, SVE-2019-16012 (January 2020).

EPSS: Низкий
github логотип

GHSA-2vhw-3h86-29h4

больше 3 лет назад

An uninitialized memory buffer leak exists in Fortinet FortiOS 5.6.1 to 5.6.3, 5.4.6 to 5.4.7, 5.2 all versions under web proxy's disclaimer response web pages, potentially causing sensitive data to be displayed in the HTTP response.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2vhw-349f-2gq5

больше 3 лет назад

An authentication bypass by spoofing vulnerability exists in the authentication daemon and User-ID components of Palo Alto Networks PAN-OS by failing to verify the integrity of the Kerberos key distribution center (KDC) before authenticating users. This affects all forms of authentication that use a Kerberos authentication profile. A man-in-the-middle type of attacker with the ability to intercept communication between PAN-OS and KDC can login to PAN-OS as an administrator. This issue affects: PAN-OS 7.1 versions earlier than 7.1.26; PAN-OS 8.0 versions earlier than 8.0.21; PAN-OS 8.1 versions earlier than 8.1.13; PAN-OS 9.0 versions earlier than 9.0.6.

EPSS: Низкий
github логотип

GHSA-2vhv-xj4g-f2fq

больше 3 лет назад

Cross-site scripting vulnerability in Modern Events Calendar Lite versions prior to 6.3.0 allows remote an authenticated attacker to inject an arbitrary script via unspecified vectors.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2vhv-mf9g-gm93

10 месяцев назад

Missing Authorization vulnerability in AlphaEfficiencyTeam Custom Login and Registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Custom Login and Registration: from n/a through 1.0.0.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2vhr-xgfv-6w53

больше 3 лет назад

Huawei PC client software HiSuite 4.0.5.300_OVE has an information leak vulnerability; an attacker who can log in to the system can copy out the user's proxy password, causing information leaks.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2vhr-q545-p6f9

больше 2 лет назад

A improper neutralization of special elements used in an sql command ('sql injection') vulnerability [CWE-89] in Fortinet FortiSandbox version 4.2.0, 4.0.0 through 4.0.2, 3.2.0 through 3.2.3, 3.1.x and 3.0.x allows a remote and authenticated attacker with read permission to retrieve arbitrary files from the underlying Linux system via a crafted HTTP request.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2vhr-4mhq-m35c

больше 3 лет назад

Moodle does not properly restrict access

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2vj6-wmm6-q722

In the Linux kernel, the following vulnerability has been resolved: smb: client: let recv_done verify data_offset, data_length and remaining_data_length This is inspired by the related server fixes.

CVSS3: 5.5
0%
Низкий
4 месяца назад
github логотип
GHSA-2vj6-p9c5-8h3v

main/translate.c in Sangoma Asterisk 13.28.0 and 16.5.0 allows a remote attacker to send a specific RTP packet during a call and cause a crash in a specific scenario.

CVSS3: 7.5
9%
Низкий
больше 3 лет назад
github логотип
GHSA-2vj6-mvxm-4f5f

The _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in GnuTLS 2.12.23 allows remote attackers to cause a denial of service (buffer over-read and crash) via a crafted padding length. NOTE: this might be due to an incorrect fix for CVE-2013-0169.

9%
Низкий
больше 3 лет назад
github логотип
GHSA-2vj5-r237-wrxw

Out-of-bounds read in applying binary of voice content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.

CVSS3: 5.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-2vj5-px25-gjrp

pytorch-lightning is vulnerable to Deserialization of Untrusted Data

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-2vj4-mfcc-xffc

MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 uses the thumbnail ImageMagick command line argument, which allows remote attackers to obtain the installation path by reading the metadata of a PNG thumbnail file.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2vj4-82m3-c6h5

Buffer overflow in efax 0.9 and earlier, when installed setuid root, allows local users to execute arbitrary code via a long -x argument.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2vj3-wf4c-q7hg

In Gxlcms QY v1.0.0713, Lib\Lib\Action\Admin\DataAction.class.php allows remote attackers to delete any file via directory traversal sequences in the id parameter of an Admin-Data-del request.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2vj3-75qw-x4pm

SQL injection vulnerability in pblguestbook.php in Pixelated By Lev (PBL) Guestbook 1.32 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) name, (2) email, (3) website, (4) comments, (5) rate, and (6) private parameters.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2vhx-gg9g-r3h4

The official drupal docker images before 8.5.10-fpm-alpine (Alpine specific) contain a blank password for a root user. System using the drupal docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.

20%
Средний
больше 3 лет назад
github логотип
GHSA-2vhx-cw73-6rc9

Buffer overflow in HECI subsystem in Intel(R) CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 and Intel(R) TXE version before 3.1.60 or 4.0.10, or Intel(R) Server Platform Services before version 5.00.04.012 may allow an unauthenticated user to potentially execute arbitrary code via physical access.

CVSS3: 7.6
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2vhw-q36q-j3v5

BASupSrvcUpdater.exe in N-able Take Control Agent through 7.0.41.1141 before 7.0.43 has a TOCTOU Race Condition via a pseudo-symlink at %PROGRAMDATA%\GetSupportService_N-Central\PushUpdates, leading to arbitrary file deletion.

CVSS3: 7
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2vhw-f897-f2qr

An issue was discovered on Samsung mobile devices with P(9.0) software. Gallery leaks cached data. The Samsung IDs are SVE-2019-16010, SVE-2019-16011, SVE-2019-16012 (January 2020).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2vhw-3h86-29h4

An uninitialized memory buffer leak exists in Fortinet FortiOS 5.6.1 to 5.6.3, 5.4.6 to 5.4.7, 5.2 all versions under web proxy's disclaimer response web pages, potentially causing sensitive data to be displayed in the HTTP response.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2vhw-349f-2gq5

An authentication bypass by spoofing vulnerability exists in the authentication daemon and User-ID components of Palo Alto Networks PAN-OS by failing to verify the integrity of the Kerberos key distribution center (KDC) before authenticating users. This affects all forms of authentication that use a Kerberos authentication profile. A man-in-the-middle type of attacker with the ability to intercept communication between PAN-OS and KDC can login to PAN-OS as an administrator. This issue affects: PAN-OS 7.1 versions earlier than 7.1.26; PAN-OS 8.0 versions earlier than 8.0.21; PAN-OS 8.1 versions earlier than 8.1.13; PAN-OS 9.0 versions earlier than 9.0.6.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2vhv-xj4g-f2fq

Cross-site scripting vulnerability in Modern Events Calendar Lite versions prior to 6.3.0 allows remote an authenticated attacker to inject an arbitrary script via unspecified vectors.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2vhv-mf9g-gm93

Missing Authorization vulnerability in AlphaEfficiencyTeam Custom Login and Registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Custom Login and Registration: from n/a through 1.0.0.

CVSS3: 5.4
0%
Низкий
10 месяцев назад
github логотип
GHSA-2vhr-xgfv-6w53

Huawei PC client software HiSuite 4.0.5.300_OVE has an information leak vulnerability; an attacker who can log in to the system can copy out the user's proxy password, causing information leaks.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2vhr-q545-p6f9

A improper neutralization of special elements used in an sql command ('sql injection') vulnerability [CWE-89] in Fortinet FortiSandbox version 4.2.0, 4.0.0 through 4.0.2, 3.2.0 through 3.2.3, 3.1.x and 3.0.x allows a remote and authenticated attacker with read permission to retrieve arbitrary files from the underlying Linux system via a crafted HTTP request.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2vhr-4mhq-m35c

Moodle does not properly restrict access

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу