Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 375

Количество 314 375

github логотип

GHSA-2rxg-f4r2-fm3c

больше 3 лет назад

Sensitive passwords used in deployment and configuration of oVirt Metrics, all versions. were found to be insufficiently protected. Passwords could be disclosed in log files (if playbooks are run with -v) or in playbooks stored on Metrics or Bastion hosts.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2rxc-gjrp-vjhx

около 1 года назад

Unsoundness in anstream

EPSS: Низкий
github логотип

GHSA-2rxc-97gh-gwr2

больше 3 лет назад

pycdc commit 44a730f3a889503014fec94ae6e62d8401cb75e5 was discovered to contain a stack overflow via the component __sanitizer::StackDepotBase<__sanitizer::StackDepotNode.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2rxc-8f9w-fjq8

около 4 лет назад

Window may read from uninitialized memory locations in rdiff

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2rxc-55rq-5r4c

почти 4 года назад

Directory traversal vulnerability in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8, when using "flat" addons, allows remote attackers to read arbitrary Javascript, image, and stylesheet files via the chrome: URI scheme, as demonstrated by stealing session information from sessionstore.js.

EPSS: Средний
github логотип

GHSA-2rx9-6m9m-h79v

больше 3 лет назад

Insufficient session authentication in web server for Intel(R) Data Center Manager SDK before version 5.0.2 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2rx8-rxcr-mmfh

больше 3 лет назад

Virtua Cobranca before 12R allows SQL Injection on the login page.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-2rx7-vfcv-7r3v

больше 3 лет назад

An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25, 1.900.26, 1.900.27, 1.900.28, 1.900.29, 1.900.30, 1.900.31, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.0.7, 2.0.8, 2.0.9, 2.0.10, 2.0.11, 2.0.12, 2.0.13, 2.0.14, 2.0.15, 2.0.16. There is a heap-based buffer over-read of size 8 in the function jas_image_depalettize in libjasper/base/jas_image.c.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2rx6-j2f4-924g

больше 3 лет назад

TP-Link TD-W8961ND devices allow XSS via the hostname of a DHCP client.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2rx6-frrg-fjf2

больше 3 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of JPEG2000 files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-9414.

EPSS: Низкий
github логотип

GHSA-2rx6-8ww2-27g3

почти 4 года назад

Format string vulnerability in a logging function as used by various SFTP servers, including (1) AttachmateWRQ Reflection for Secure IT UNIX Server before 6.0.0.9, (2) Reflection for Secure IT Windows Server before 6.0 build 38, (3) F-Secure SSH Server for Windows before 5.3 build 35, (4) F-Secure SSH Server for UNIX 3.0 through 5.0.8, (5) SSH Tectia Server 4.3.6 and earlier and 4.4.0, and (6) SSH Shell Server 3.2.9 and earlier, allows remote authenticated users to execute arbitrary commands via unspecified vectors, involving crafted filenames and the stat command.

EPSS: Низкий
github логотип

GHSA-2rx6-8j2p-9gqq

почти 4 года назад

The WorkMan program can be used to overwrite any file to get root access.

EPSS: Низкий
github логотип

GHSA-2rx5-9p2p-hqx4

около 3 лет назад

3D Builder Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2023-21780, CVE-2023-21781, CVE-2023-21782, CVE-2023-21783, CVE-2023-21784, CVE-2023-21786, CVE-2023-21787, CVE-2023-21788, CVE-2023-21789, CVE-2023-21790, CVE-2023-21791, CVE-2023-21792, CVE-2023-21793.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2rx4-vrv5-3mjp

около 1 года назад

Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno Learning path allows PHP Local File Inclusion.This issue affects Opigno Learning path: from 0.0.0 before 3.1.2.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2rx4-9f5h-9gjf

больше 2 лет назад

Apache Airflow CNCF Kubernetes Provider: KubernetesPodOperator RCE via connection configuration

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2rx4-8xc8-6hf3

больше 3 лет назад

The RESTful control interface (aka RAPI or ganeti-rapi) in Ganeti before 2.9.7, 2.10.x before 2.10.8, 2.11.x before 2.11.8, 2.12.x before 2.12.6, 2.13.x before 2.13.3, 2.14.x before 2.14.2, and 2.15.x before 2.15.2 allows remote attackers to obtain the DRBD secret via instance information job results.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-2rx3-x88g-2wmx

больше 3 лет назад

In IP-AK2 Access Control Panel Version 1.04.07 and prior, the integrated web server of the affected devices could allow remote attackers to obtain web configuration data, which can be accessed without authentication over the network.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2rx2-wvh6-wg6m

почти 3 года назад

Authentication Bypass in Hub Business integration in Devolutions Workspace Desktop 2023.1.1.3 and earlier on Windows and macOS allows an attacker with access to the user interface to unlock a Hub Business space without being prompted to enter the password via an unimplemented "Force Login" security feature. This vulnerability occurs only if "Force Login" feature is enabled on the Hub Business instance and that an attacker has access to a locked Workspace desktop application configured with a Hub Business space.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2rx2-6g92-c889

больше 3 лет назад

SQL injection vulnerability in the WP-OliveCart versions prior to 3.1.3 and WP-OliveCartPro versions prior to 3.1.8 allows attackers with administrator rights to execute arbitrary SQL commands via unspecified vectors.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2rwx-xp6r-mhqf

больше 3 лет назад

LibTIFF 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6 and 4.0.7 allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted TIFF image, related to "READ of size 512" and libtiff/tif_unix.c:340:2.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2rxg-f4r2-fm3c

Sensitive passwords used in deployment and configuration of oVirt Metrics, all versions. were found to be insufficiently protected. Passwords could be disclosed in log files (if playbooks are run with -v) or in playbooks stored on Metrics or Bastion hosts.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rxc-gjrp-vjhx

Unsoundness in anstream

около 1 года назад
github логотип
GHSA-2rxc-97gh-gwr2

pycdc commit 44a730f3a889503014fec94ae6e62d8401cb75e5 was discovered to contain a stack overflow via the component __sanitizer::StackDepotBase<__sanitizer::StackDepotNode.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rxc-8f9w-fjq8

Window may read from uninitialized memory locations in rdiff

CVSS3: 7.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-2rxc-55rq-5r4c

Directory traversal vulnerability in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8, when using "flat" addons, allows remote attackers to read arbitrary Javascript, image, and stylesheet files via the chrome: URI scheme, as demonstrated by stealing session information from sessionstore.js.

39%
Средний
почти 4 года назад
github логотип
GHSA-2rx9-6m9m-h79v

Insufficient session authentication in web server for Intel(R) Data Center Manager SDK before version 5.0.2 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

CVSS3: 8.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-2rx8-rxcr-mmfh

Virtua Cobranca before 12R allows SQL Injection on the login page.

CVSS3: 7.5
63%
Средний
больше 3 лет назад
github логотип
GHSA-2rx7-vfcv-7r3v

An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25, 1.900.26, 1.900.27, 1.900.28, 1.900.29, 1.900.30, 1.900.31, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.0.7, 2.0.8, 2.0.9, 2.0.10, 2.0.11, 2.0.12, 2.0.13, 2.0.14, 2.0.15, 2.0.16. There is a heap-based buffer over-read of size 8 in the function jas_image_depalettize in libjasper/base/jas_image.c.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2rx6-j2f4-924g

TP-Link TD-W8961ND devices allow XSS via the hostname of a DHCP client.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rx6-frrg-fjf2

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of JPEG2000 files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-9414.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-2rx6-8ww2-27g3

Format string vulnerability in a logging function as used by various SFTP servers, including (1) AttachmateWRQ Reflection for Secure IT UNIX Server before 6.0.0.9, (2) Reflection for Secure IT Windows Server before 6.0 build 38, (3) F-Secure SSH Server for Windows before 5.3 build 35, (4) F-Secure SSH Server for UNIX 3.0 through 5.0.8, (5) SSH Tectia Server 4.3.6 and earlier and 4.4.0, and (6) SSH Shell Server 3.2.9 and earlier, allows remote authenticated users to execute arbitrary commands via unspecified vectors, involving crafted filenames and the stat command.

5%
Низкий
почти 4 года назад
github логотип
GHSA-2rx6-8j2p-9gqq

The WorkMan program can be used to overwrite any file to get root access.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2rx5-9p2p-hqx4

3D Builder Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2023-21780, CVE-2023-21781, CVE-2023-21782, CVE-2023-21783, CVE-2023-21784, CVE-2023-21786, CVE-2023-21787, CVE-2023-21788, CVE-2023-21789, CVE-2023-21790, CVE-2023-21791, CVE-2023-21792, CVE-2023-21793.

CVSS3: 7.8
2%
Низкий
около 3 лет назад
github логотип
GHSA-2rx4-vrv5-3mjp

Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno Learning path allows PHP Local File Inclusion.This issue affects Opigno Learning path: from 0.0.0 before 3.1.2.

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2rx4-9f5h-9gjf

Apache Airflow CNCF Kubernetes Provider: KubernetesPodOperator RCE via connection configuration

CVSS3: 7.2
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2rx4-8xc8-6hf3

The RESTful control interface (aka RAPI or ganeti-rapi) in Ganeti before 2.9.7, 2.10.x before 2.10.8, 2.11.x before 2.11.8, 2.12.x before 2.12.6, 2.13.x before 2.13.3, 2.14.x before 2.14.2, and 2.15.x before 2.15.2 allows remote attackers to obtain the DRBD secret via instance information job results.

CVSS3: 7.5
14%
Средний
больше 3 лет назад
github логотип
GHSA-2rx3-x88g-2wmx

In IP-AK2 Access Control Panel Version 1.04.07 and prior, the integrated web server of the affected devices could allow remote attackers to obtain web configuration data, which can be accessed without authentication over the network.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rx2-wvh6-wg6m

Authentication Bypass in Hub Business integration in Devolutions Workspace Desktop 2023.1.1.3 and earlier on Windows and macOS allows an attacker with access to the user interface to unlock a Hub Business space without being prompted to enter the password via an unimplemented "Force Login" security feature. This vulnerability occurs only if "Force Login" feature is enabled on the Hub Business instance and that an attacker has access to a locked Workspace desktop application configured with a Hub Business space.

CVSS3: 7.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-2rx2-6g92-c889

SQL injection vulnerability in the WP-OliveCart versions prior to 3.1.3 and WP-OliveCartPro versions prior to 3.1.8 allows attackers with administrator rights to execute arbitrary SQL commands via unspecified vectors.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-2rwx-xp6r-mhqf

LibTIFF 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6 and 4.0.7 allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted TIFF image, related to "READ of size 512" and libtiff/tif_unix.c:340:2.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу