Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2rq5-qmgj-689w

больше 3 лет назад

Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, PerformanceBridge Focal Point Version A.01, IntelliVue patient monitors MX100, MX400-MX850, and MP2-MP90 Versions N and prior, IntelliVue X3 and X2 Versions N and prior. The product receives input that is expected to be well-formed (i.e., to comply with a certain syntax) but it does not validate or incorrectly validates that the input complies with the syntax, causing the certificate enrollment service to crash. It does not impact monitoring but prevents new devices from enrolling.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2rq5-mvp2-q8g4

почти 4 года назад

Out-of-bounds read in the Intel(R) Trace Analyzer and Collector before version 2021.5 may allow an authenticated user to potentially enable denial of service via local access.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2rq5-699j-x7p6

почти 3 года назад

Arbitrary local file read vulnerability during template rendering

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2rq5-68hm-h4j8

больше 4 лет назад

Cross-Site Request Forgery in OpenNMS Horizon

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2rq5-3pp8-hc24

больше 3 лет назад

In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity check for loading PI System libraries. This exploitation can target another local user of PI System software on the computer to escalate privilege and result in unauthorized information disclosure, deletion, or modification.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2rq4-xq7w-xw4p

12 месяцев назад

Mintty Sixel Image Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Mintty. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of sixel images. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-23382.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2rq4-xq62-qph5

больше 3 лет назад

The 10000 Kindle Books Downloads (aka com.ww10000KindleBooksLatestnBestSellers) application 0.312 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-2rq4-3vf7-x5vg

больше 3 лет назад

Adobe Illustrator versions 26.3.1 (and earlier) and 25.4.6 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2rq3-x44v-xx2w

10 месяцев назад

Yubico YubiKey 5.4.1 through 5.7.3 before 5.7.4 has an incorrect FIDO CTAP PIN/UV Auth Protocol Two implementation. It uses the signature length from CTAP PIN/UV Auth Protocol One, even when CTAP PIN/UV Auth Protocol Two was chosen, resulting in a partial signature verification.

CVSS3: 2.2
EPSS: Низкий
github логотип

GHSA-2rq3-28ph-m8mh

больше 3 лет назад

Adobe After Effects version 18.2.1 (and earlier) is affected by an out-of-bounds Write vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

EPSS: Низкий
github логотип

GHSA-2rq2-hm3x-v2v9

20 дней назад

A vulnerability was found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. This affects an unknown part of the file /php/api_patient_schedule.php. Performing a manipulation of the argument Reason results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and could be used.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-2rq2-48fh-56v5

почти 4 года назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante DICOM Viewer Pro 11.8.8.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of J2K images. Crafted data in a J2K file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15161.

EPSS: Низкий
github логотип

GHSA-2rpx-x533-qfww

больше 3 лет назад

Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how affected Microsoft scripting engines handle objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11794 and CVE-2017-11803.

CVSS3: 4.3
EPSS: Средний
github логотип

GHSA-2rpx-x37c-9w5p

больше 2 лет назад

Use after free in WebXR in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-2rpx-jj49-wf29

больше 3 лет назад

Byobu Apport hook may disclose sensitive information since it automatically uploads the local user's .screenrc which may contain private hostnames, usernames and passwords. This issue affects: byobu

EPSS: Низкий
github логотип

GHSA-2rpw-x26f-wmg7

больше 3 лет назад

Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53, 8.54, and 8.55 allows remote attackers to affect confidentiality and integrity via vectors related to File Processing.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2rpw-3w88-97r6

больше 2 лет назад

TP-Link Archer AX21(US)_V3_1.1.4 Build 20230219 and AX21(US)_V3.6_1.1.4 Build 20230219 are vulnerable to Buffer Overflow.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2rpv-px67-6xcc

почти 2 года назад

Rejected reason: This is unused.

EPSS: Низкий
github логотип

GHSA-2rpv-m9vg-g7g3

10 месяцев назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-2rpv-jjj3-r2m2

больше 3 лет назад

A buffer overflow vulnerability was observed in divby function of Artifex Software, Inc. MuJS before 8c805b4eb19cf2af689c860b77e6111d2ee439d5. A successful exploitation of this issue can lead to code execution or denial of service condition.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2rq5-qmgj-689w

Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, PerformanceBridge Focal Point Version A.01, IntelliVue patient monitors MX100, MX400-MX850, and MP2-MP90 Versions N and prior, IntelliVue X3 and X2 Versions N and prior. The product receives input that is expected to be well-formed (i.e., to comply with a certain syntax) but it does not validate or incorrectly validates that the input complies with the syntax, causing the certificate enrollment service to crash. It does not impact monitoring but prevents new devices from enrolling.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rq5-mvp2-q8g4

Out-of-bounds read in the Intel(R) Trace Analyzer and Collector before version 2021.5 may allow an authenticated user to potentially enable denial of service via local access.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-2rq5-699j-x7p6

Arbitrary local file read vulnerability during template rendering

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-2rq5-68hm-h4j8

Cross-Site Request Forgery in OpenNMS Horizon

CVSS3: 8.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-2rq5-3pp8-hc24

In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity check for loading PI System libraries. This exploitation can target another local user of PI System software on the computer to escalate privilege and result in unauthorized information disclosure, deletion, or modification.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rq4-xq7w-xw4p

Mintty Sixel Image Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Mintty. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of sixel images. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-23382.

CVSS3: 8.8
0%
Низкий
12 месяцев назад
github логотип
GHSA-2rq4-xq62-qph5

The 10000 Kindle Books Downloads (aka com.ww10000KindleBooksLatestnBestSellers) application 0.312 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rq4-3vf7-x5vg

Adobe Illustrator versions 26.3.1 (and earlier) and 25.4.6 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rq3-x44v-xx2w

Yubico YubiKey 5.4.1 through 5.7.3 before 5.7.4 has an incorrect FIDO CTAP PIN/UV Auth Protocol Two implementation. It uses the signature length from CTAP PIN/UV Auth Protocol One, even when CTAP PIN/UV Auth Protocol Two was chosen, resulting in a partial signature verification.

CVSS3: 2.2
0%
Низкий
10 месяцев назад
github логотип
GHSA-2rq3-28ph-m8mh

Adobe After Effects version 18.2.1 (and earlier) is affected by an out-of-bounds Write vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-2rq2-hm3x-v2v9

A vulnerability was found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. This affects an unknown part of the file /php/api_patient_schedule.php. Performing a manipulation of the argument Reason results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and could be used.

CVSS3: 3.5
0%
Низкий
20 дней назад
github логотип
GHSA-2rq2-48fh-56v5

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante DICOM Viewer Pro 11.8.8.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of J2K images. Crafted data in a J2K file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15161.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2rpx-x533-qfww

Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how affected Microsoft scripting engines handle objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11794 and CVE-2017-11803.

CVSS3: 4.3
11%
Средний
больше 3 лет назад
github логотип
GHSA-2rpx-x37c-9w5p

Use after free in WebXR in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
17%
Средний
больше 2 лет назад
github логотип
GHSA-2rpx-jj49-wf29

Byobu Apport hook may disclose sensitive information since it automatically uploads the local user's .screenrc which may contain private hostnames, usernames and passwords. This issue affects: byobu

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2rpw-x26f-wmg7

Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53, 8.54, and 8.55 allows remote attackers to affect confidentiality and integrity via vectors related to File Processing.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rpw-3w88-97r6

TP-Link Archer AX21(US)_V3_1.1.4 Build 20230219 and AX21(US)_V3.6_1.1.4 Build 20230219 are vulnerable to Buffer Overflow.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2rpv-px67-6xcc

Rejected reason: This is unused.

почти 2 года назад
github логотип
GHSA-2rpv-m9vg-g7g3

Rejected reason: Not used

10 месяцев назад
github логотип
GHSA-2rpv-jjj3-r2m2

A buffer overflow vulnerability was observed in divby function of Artifex Software, Inc. MuJS before 8c805b4eb19cf2af689c860b77e6111d2ee439d5. A successful exploitation of this issue can lead to code execution or denial of service condition.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу