Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2rmc-p46g-jmrv

почти 4 года назад

chfn in pwdutils 3.0.4 and earlier on SuSE Linux, and possibly other operating systems, does not properly check arguments for the GECOS field, which allows local users to gain privileges.

EPSS: Низкий
github логотип

GHSA-2rmc-f234-xhg3

больше 3 лет назад

A null pointer deference issue exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode.c:2337.

EPSS: Низкий
github логотип

GHSA-2rmc-2qhr-4jvg

больше 3 лет назад

A use-after-free can occur during buffer storage operations within the ANGLE graphics library, used for WebGL content. The buffer storage can be freed while still in use in some circumstances, leading to a potentially exploitable crash. Note: This issue is in "libGLES", which is only in use on Windows. Other operating systems are not affected. This vulnerability affects Firefox < 52 and Thunderbird < 52.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2rm9-pcmr-fvfj

8 месяцев назад

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2rm8-gh6q-8wpp

9 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in pimwick PW WooCommerce Bulk Edit allows Cross Site Request Forgery. This issue affects PW WooCommerce Bulk Edit: from n/a through 2.134.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2rm7-xxx8-35jh

больше 3 лет назад

MediaWiki Cross-site Scripting (XSS)

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2rm6-26jp-f4w2

больше 1 года назад

A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.4, macOS Ventura 13.6.8. An attacker may be able to read information belonging to another user.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2rm4-vgjw-r4jw

больше 3 лет назад

Unify OpenStage / OpenScape Desk Phone IP before V3 R3.11.0 SIP has an OS command injection vulnerability in the web based management interface

EPSS: Низкий
github логотип

GHSA-2rm4-pxv9-x75c

почти 4 года назад

The gdPngReadData function in libgd 2.0.34 allows user-assisted attackers to cause a denial of service (CPU consumption) via a crafted PNG image with truncated data, which causes an infinite loop in the png_read_info function in libpng.

EPSS: Низкий
github логотип

GHSA-2rm4-674c-43v5

3 месяца назад

Inappropriate implementation in Omnibox in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-2rm4-33m8-3gr6

больше 3 лет назад

The Electronic Funds Source (EFS) Mobile Driver Source app 2.5 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2rm3-j8qf-6fg4

около 2 лет назад

Improper neutralization of livestatus command delimiters in ajax_search in Checkmk <= 2.0.0p39, < 2.1.0p37, and < 2.2.0p15 allows arbitrary livestatus command execution for authorized users.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-2rm2-wchv-ghgw

почти 4 года назад

A URL redirection vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.9, 9.x prior to 9.2.20, 8.x prior to 8.2.27, and 7.x prior to 7.8.2.31, and controlled release 11.x prior to 11.1.3 allows a remote attacker to redirect a user to a malicious website controlled by the attacker. This is possible because SWG incorrectly creates a HTTP redirect response when a user clicks a carefully constructed URL. Following the redirect response, the new request is still filtered by the SWG policy.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2rm2-vwh2-fp52

больше 3 лет назад

Cloud Foundry UAA, all versions prior to 4.20.0 and Cloud Foundry UAA Release, all versions prior to 61.0, allows brute forcing of MFA codes. A remote unauthenticated malicious user in possession of a valid username and password can brute force MFA to login as the targeted user.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2rm2-mwc8-f72w

больше 1 года назад

Insufficient user input filtering leads to arbitrary file read by non-authenticated attacker, which results in sensitive information disclosure.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2rm2-h7r9-p8x4

около 1 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lodgix Lodgix.Com Vacation Rental Website Builder allows SQL Injection.This issue affects Lodgix.Com Vacation Rental Website Builder: from n/a through 3.9.73.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-2rm2-cr56-79w2

больше 3 лет назад

Directory traversal vulnerability in the rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to execute arbitrary code via unspecified vectors to the StartLog method.

EPSS: Низкий
github логотип

GHSA-2rm2-cf7c-m25m

9 месяцев назад

Tesla Model S Iris Modem QCMAP_ConnectionManager Improper Input Validation Sandbox Escape Vulnerability. This vulnerability allows local attackers to escape the sandbox on affected affected Tesla Model S vehicles. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the QCMAP_ConnectionManager component. An attacker can abuse the service to assign LAN addresses to the WWAN. An attacker can leverage this vulnerability to access network services that were only intended to be exposed to the internal LAN. Was ZDI-CAN-23199.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2rm2-3r73-2vfr

больше 3 лет назад

LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. Protection was added, to address CVE-2019-9848, to block calling LibreLogo from document event script handers, e.g. mouse over. However LibreOffice also has a separate feature where documents can specify that pre-installed scripts can be executed on various global script events such as document-open, etc. In the fixed versions, global script event handlers are validated equivalently to document script event handlers. This issue affects: Document Foundation LibreOffice versions prior to 6.2.6.

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-2rjx-xh92-v9vw

почти 4 года назад

Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.2, allows restricted administrators to obtain certificate passwords that are stored in plaintext in the HTML source code for Certificate Management pages.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2rmc-p46g-jmrv

chfn in pwdutils 3.0.4 and earlier on SuSE Linux, and possibly other operating systems, does not properly check arguments for the GECOS field, which allows local users to gain privileges.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2rmc-f234-xhg3

A null pointer deference issue exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode.c:2337.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rmc-2qhr-4jvg

A use-after-free can occur during buffer storage operations within the ANGLE graphics library, used for WebGL content. The buffer storage can be freed while still in use in some circumstances, leading to a potentially exploitable crash. Note: This issue is in "libGLES", which is only in use on Windows. Other operating systems are not affected. This vulnerability affects Firefox < 52 and Thunderbird < 52.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2rm9-pcmr-fvfj

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-2rm8-gh6q-8wpp

Cross-Site Request Forgery (CSRF) vulnerability in pimwick PW WooCommerce Bulk Edit allows Cross Site Request Forgery. This issue affects PW WooCommerce Bulk Edit: from n/a through 2.134.

CVSS3: 5.4
0%
Низкий
9 месяцев назад
github логотип
GHSA-2rm7-xxx8-35jh

MediaWiki Cross-site Scripting (XSS)

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rm6-26jp-f4w2

A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.4, macOS Ventura 13.6.8. An attacker may be able to read information belonging to another user.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2rm4-vgjw-r4jw

Unify OpenStage / OpenScape Desk Phone IP before V3 R3.11.0 SIP has an OS command injection vulnerability in the web based management interface

5%
Низкий
больше 3 лет назад
github логотип
GHSA-2rm4-pxv9-x75c

The gdPngReadData function in libgd 2.0.34 allows user-assisted attackers to cause a denial of service (CPU consumption) via a crafted PNG image with truncated data, which causes an infinite loop in the png_read_info function in libpng.

7%
Низкий
почти 4 года назад
github логотип
GHSA-2rm4-674c-43v5

Inappropriate implementation in Omnibox in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 4.2
0%
Низкий
3 месяца назад
github логотип
GHSA-2rm4-33m8-3gr6

The Electronic Funds Source (EFS) Mobile Driver Source app 2.5 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVSS3: 5.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rm3-j8qf-6fg4

Improper neutralization of livestatus command delimiters in ajax_search in Checkmk <= 2.0.0p39, < 2.1.0p37, and < 2.2.0p15 allows arbitrary livestatus command execution for authorized users.

CVSS3: 7.6
0%
Низкий
около 2 лет назад
github логотип
GHSA-2rm2-wchv-ghgw

A URL redirection vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.9, 9.x prior to 9.2.20, 8.x prior to 8.2.27, and 7.x prior to 7.8.2.31, and controlled release 11.x prior to 11.1.3 allows a remote attacker to redirect a user to a malicious website controlled by the attacker. This is possible because SWG incorrectly creates a HTTP redirect response when a user clicks a carefully constructed URL. Following the redirect response, the new request is still filtered by the SWG policy.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-2rm2-vwh2-fp52

Cloud Foundry UAA, all versions prior to 4.20.0 and Cloud Foundry UAA Release, all versions prior to 61.0, allows brute forcing of MFA codes. A remote unauthenticated malicious user in possession of a valid username and password can brute force MFA to login as the targeted user.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rm2-mwc8-f72w

Insufficient user input filtering leads to arbitrary file read by non-authenticated attacker, which results in sensitive information disclosure.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2rm2-h7r9-p8x4

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lodgix Lodgix.Com Vacation Rental Website Builder allows SQL Injection.This issue affects Lodgix.Com Vacation Rental Website Builder: from n/a through 3.9.73.

CVSS3: 8.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2rm2-cr56-79w2

Directory traversal vulnerability in the rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to execute arbitrary code via unspecified vectors to the StartLog method.

8%
Низкий
больше 3 лет назад
github логотип
GHSA-2rm2-cf7c-m25m

Tesla Model S Iris Modem QCMAP_ConnectionManager Improper Input Validation Sandbox Escape Vulnerability. This vulnerability allows local attackers to escape the sandbox on affected affected Tesla Model S vehicles. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the QCMAP_ConnectionManager component. An attacker can abuse the service to assign LAN addresses to the WWAN. An attacker can leverage this vulnerability to access network services that were only intended to be exposed to the internal LAN. Was ZDI-CAN-23199.

CVSS3: 7.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-2rm2-3r73-2vfr

LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. Protection was added, to address CVE-2019-9848, to block calling LibreLogo from document event script handers, e.g. mouse over. However LibreOffice also has a separate feature where documents can specify that pre-installed scripts can be executed on various global script events such as document-open, etc. In the fixed versions, global script event handlers are validated equivalently to document script event handlers. This issue affects: Document Foundation LibreOffice versions prior to 6.2.6.

CVSS3: 9.8
86%
Высокий
больше 3 лет назад
github логотип
GHSA-2rjx-xh92-v9vw

Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.2, allows restricted administrators to obtain certificate passwords that are stored in plaintext in the HTML source code for Certificate Management pages.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу