Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2rwr-j5mc-pp8c

больше 3 лет назад

Multiple integer overflows in xine-lib 1.1.12, and other 1.1.15 and earlier versions, allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via (1) crafted width and height values that are not validated by the mymng_process_header function in demux_mng.c before use in an allocation calculation or (2) crafted current_atom_size and string_size values processed by the parse_reference_atom function in demux_qt.c for an RDRF_ATOM string.

EPSS: Низкий
github логотип

GHSA-2rwq-m686-fwcg

больше 3 лет назад

Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2rwq-3mr3-vq32

около 2 лет назад

In alac decoder, there is a possible out of bounds write due to an incorrect error handling. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08441150; Issue ID: ALPS08441150.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2rwq-335q-72xp

почти 2 года назад

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in CodeRevolution WP Setup Wizard.This issue affects WP Setup Wizard: from n/a through 1.0.8.1.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2rwp-xr6x-9ppc

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix kernel NULL pointer dereference in gfs2_rgrp_dump Syzkaller has reported a NULL pointer dereference when accessing rgd->rd_rgl in gfs2_rgrp_dump(). This can happen when creating rgd->rd_gl fails in read_rindex_entry(). Add a NULL pointer check in gfs2_rgrp_dump() to prevent that.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2rwp-q9wg-42qm

около 3 лет назад

A vulnerability classified as critical was found in Arthmoor QSF-Portal. This vulnerability affects unknown code of the file index.php. The manipulation of the argument a leads to path traversal. The name of the patch is ea4f61e23ecb83247d174bc2e2cbab521c751a7d. It is recommended to apply a patch to fix this issue. VDB-217558 is the identifier assigned to this vulnerability.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2rwm-xv5j-777p

больше 1 года назад

Eclipse Parsson stack overflow when parsing deeply nested input

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-2rwj-7xq8-4gx4

больше 1 года назад

Qwik has a potential mXSS vulnerability due to improper HTML escaping

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2rwh-262r-r85j

больше 3 лет назад

Dolibarr ERP and CRM malicious executable loading

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2rwg-3hx2-q599

3 месяца назад

The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.5.5 via the 'wps_rma_cancel_return_request' AJAX endpoint due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete other users refund requests.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2rwf-gw57-98vq

около 2 лет назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Matthew Fries MF Gig Calendar.This issue affects MF Gig Calendar: from n/a through 1.2.1.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-2rwf-8q5w-q673

больше 3 лет назад

In the Android kernel in sync debug fs driver there is a kernel pointer leak due to the usage of printf with %p. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-2rwc-w9h2-83r7

больше 3 лет назад

IBM Security Guardium 11.2 performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses. IBM X-Force ID: 174802..

EPSS: Низкий
github логотип

GHSA-2rwc-6qx6-pv67

около 1 месяца назад

Missing Authorization vulnerability in merkulove Slider for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Slider for Elementor: from n/a through 1.0.10.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2rw9-q6xx-mmw5

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Developer Tools (aka DevTools) subsystem in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux allows remote attackers to inject arbitrary web script or HTML via the settings parameter in a chrome-devtools-frontend.appspot.com URL's query string.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2rw9-g27f-ppp3

больше 1 года назад

Windows Hyper-V Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2rw7-4xg9-x3cw

больше 2 лет назад

BT SDP dissector infinite loop in Wireshark 4.0.0 to 4.0.7 and 3.6.0 to 3.6.15 allows denial of service via packet injection or crafted capture file

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2rw6-f687-5qwg

больше 3 лет назад

Unspecified vulnerability in the Java SE and Java SE Embedded components in Oracle Java SE 6u105, 7u91, and 8u66 and Java SE Embedded 8u65 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

EPSS: Низкий
github логотип

GHSA-2rw4-j3h5-72xp

больше 1 года назад

The Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's text effect widget in all versions up to, and including, 1.1.37 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2rw3-qjj7-c6qf

около 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hanusek imPress allows Reflected XSS.This issue affects imPress: from n/a through 0.1.4.

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2rwr-j5mc-pp8c

Multiple integer overflows in xine-lib 1.1.12, and other 1.1.15 and earlier versions, allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via (1) crafted width and height values that are not validated by the mymng_process_header function in demux_mng.c before use in an allocation calculation or (2) crafted current_atom_size and string_size values processed by the parse_reference_atom function in demux_qt.c for an RDRF_ATOM string.

6%
Низкий
больше 3 лет назад
github логотип
GHSA-2rwq-m686-fwcg

Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

CVSS3: 7.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-2rwq-3mr3-vq32

In alac decoder, there is a possible out of bounds write due to an incorrect error handling. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08441150; Issue ID: ALPS08441150.

CVSS3: 8.8
4%
Низкий
около 2 лет назад
github логотип
GHSA-2rwq-335q-72xp

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in CodeRevolution WP Setup Wizard.This issue affects WP Setup Wizard: from n/a through 1.0.8.1.

CVSS3: 8.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-2rwp-xr6x-9ppc

In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix kernel NULL pointer dereference in gfs2_rgrp_dump Syzkaller has reported a NULL pointer dereference when accessing rgd->rd_rgl in gfs2_rgrp_dump(). This can happen when creating rgd->rd_gl fails in read_rindex_entry(). Add a NULL pointer check in gfs2_rgrp_dump() to prevent that.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-2rwp-q9wg-42qm

A vulnerability classified as critical was found in Arthmoor QSF-Portal. This vulnerability affects unknown code of the file index.php. The manipulation of the argument a leads to path traversal. The name of the patch is ea4f61e23ecb83247d174bc2e2cbab521c751a7d. It is recommended to apply a patch to fix this issue. VDB-217558 is the identifier assigned to this vulnerability.

CVSS3: 5.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-2rwm-xv5j-777p

Eclipse Parsson stack overflow when parsing deeply nested input

CVSS3: 8.6
1%
Низкий
больше 1 года назад
github логотип
GHSA-2rwj-7xq8-4gx4

Qwik has a potential mXSS vulnerability due to improper HTML escaping

CVSS3: 6.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-2rwh-262r-r85j

Dolibarr ERP and CRM malicious executable loading

CVSS3: 8.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-2rwg-3hx2-q599

The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.5.5 via the 'wps_rma_cancel_return_request' AJAX endpoint due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete other users refund requests.

CVSS3: 4.3
0%
Низкий
3 месяца назад
github логотип
GHSA-2rwf-gw57-98vq

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Matthew Fries MF Gig Calendar.This issue affects MF Gig Calendar: from n/a through 1.2.1.

CVSS3: 8.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-2rwf-8q5w-q673

In the Android kernel in sync debug fs driver there is a kernel pointer leak due to the usage of printf with %p. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 4.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rwc-w9h2-83r7

IBM Security Guardium 11.2 performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses. IBM X-Force ID: 174802..

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rwc-6qx6-pv67

Missing Authorization vulnerability in merkulove Slider for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Slider for Elementor: from n/a through 1.0.10.

CVSS3: 5.4
0%
Низкий
около 1 месяца назад
github логотип
GHSA-2rw9-q6xx-mmw5

Cross-site scripting (XSS) vulnerability in the Developer Tools (aka DevTools) subsystem in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux allows remote attackers to inject arbitrary web script or HTML via the settings parameter in a chrome-devtools-frontend.appspot.com URL's query string.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rw9-g27f-ppp3

Windows Hyper-V Elevation of Privilege Vulnerability

CVSS3: 7.8
8%
Низкий
больше 1 года назад
github логотип
GHSA-2rw7-4xg9-x3cw

BT SDP dissector infinite loop in Wireshark 4.0.0 to 4.0.7 and 3.6.0 to 3.6.15 allows denial of service via packet injection or crafted capture file

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2rw6-f687-5qwg

Unspecified vulnerability in the Java SE and Java SE Embedded components in Oracle Java SE 6u105, 7u91, and 8u66 and Java SE Embedded 8u65 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

9%
Низкий
больше 3 лет назад
github логотип
GHSA-2rw4-j3h5-72xp

The Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's text effect widget in all versions up to, and including, 1.1.37 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-2rw3-qjj7-c6qf

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hanusek imPress allows Reflected XSS.This issue affects imPress: from n/a through 0.1.4.

CVSS3: 7.1
0%
Низкий
около 1 года назад

Уязвимостей на страницу