Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2r84-qc2q-g26r

больше 3 лет назад

Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 2.8.0 through 3.1.0, 5.0.2 through 5.0.5, and 5.3.0 through 5.3.4 allows remote authenticated users to affect confidentiality via vectors related to CTF.

EPSS: Низкий
github логотип

GHSA-2r84-jvgc-hgc4

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in admin/picture_modify.php in the photo-edit subsystem in Piwigo 2.6.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the associate[] field, a different vulnerability than CVE-2014-4649.

EPSS: Низкий
github логотип

GHSA-2r82-r48p-65qf

больше 3 лет назад

Windows DirectX Information Disclosure Vulnerability

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2r7x-gm4g-xxwx

больше 3 лет назад

Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to have unspecified impact via a crafted BMP image, a different vulnerability than CVE-2016-8698, CVE-2016-8699, CVE-2016-8701, CVE-2016-8702, and CVE-2016-8703.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2r7x-944h-423g

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_transport_requested_window_size We need to protect the reader reading the sysctl value because the value can be changed concurrently.

EPSS: Низкий
github логотип

GHSA-2r7w-r6xm-q2q9

больше 3 лет назад

In IXP EasyInstall 6.2.13723, it is possible to temporarily disable UAC by using the Agent Service on a client system. An authenticated attacker (non-admin) can disable UAC for other users by renaming and replacing %SYSTEMDRIVE%\IXP\DATA\IXPAS.IXP.

EPSS: Низкий
github логотип

GHSA-2r7w-mhqc-r7r6

около 4 лет назад

Microsoft Edge for Android Spoofing Vulnerability.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2r7w-h968-j92j

почти 4 года назад

Unknown vulnerability in ns-ldapd for Sun ONE Directory Server 4.16, 5.0, and 5.1 allows LDAP clients to cause a denial of service (service halt).

EPSS: Низкий
github логотип

GHSA-2r7w-6p29-5vf5

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Tim Eckel Minify HTML plugin <= 2.1.7 vulnerability.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2r7v-v86r-776v

больше 3 лет назад

The ioapic_read_indirect function in virt/kvm/ioapic.c in the Linux kernel through 3.8.4 does not properly handle a certain combination of invalid IOAPIC_REG_SELECT and IOAPIC_REG_WINDOW operations, which allows guest OS users to obtain sensitive information from host OS memory or cause a denial of service (host OS OOPS) via a crafted application.

EPSS: Низкий
github логотип

GHSA-2r7v-cmch-5x26

около 3 лет назад

muhammara and hummus vulnerable to Unchecked Return Value to NULL Pointer Dereference

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2r7v-857w-j9f5

почти 4 года назад

NetEpi Case Manager before 0.98 generates different error messages depending on whether or not a username is valid, which allows remote attackers to enumerate valid usernames.

EPSS: Низкий
github логотип

GHSA-2r7r-6rh2-7qc9

7 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed an authenticated user to perform cross-site scripting attacks when the instance is served through certain content delivery networks.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-2r7q-w9hc-4rq3

больше 3 лет назад

app\admin\controller\RouteController.php in ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code by using vectors involving portal/List/index and list/:id to inject this code into data\conf\route.php, as demonstrated by a file_put_contents call.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2r7q-8h3w-q3pc

почти 4 года назад

make_catalog_backup in Bacula 2.2.5, and probably earlier, sends a MySQL password as a command line argument, and sometimes transmits cleartext e-mail containing this command line, which allows context-dependent attackers to obtain the password by listing the process and its arguments, or by sniffing the network.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2r7q-76h8-63hq

больше 3 лет назад

functions.php in WHMCompleteSolution (WHMCS) 4.0.x through 5.0.x allows remote attackers to trigger arbitrary code execution in the Smarty templating system by submitting a crafted ticket, related to improper handling of characters in the subject field.

EPSS: Низкий
github логотип

GHSA-2r7j-vm47-9h8m

больше 3 лет назад

Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-2r7h-jv72-f7xp

9 месяцев назад

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Solid Plugins AnalyticsWP allows Retrieve Embedded Sensitive Data.This issue affects AnalyticsWP: from n/a through 2.1.2.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2r7g-mf5h-9gcw

почти 4 года назад

Microsoft Windows XP SP2 and SP3, and Server 2003 SP1 and SP2, does not properly validate the option length field in Pragmatic General Multicast (PGM) packets, which allows remote attackers to cause a denial of service (infinite loop and system hang) via a crafted PGM packet, aka the "PGM Invalid Length Vulnerability."

EPSS: Средний
github логотип

GHSA-2r7g-chxq-57q7

больше 3 лет назад

Multiple buffer overflows in the Cisco WebEx Recording Format (WRF) and Advanced Recording Format (ARF) Players T27LB before SP21 EP3 and T27LC before SP22 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted (1) .wrf or (2) .arf file, a different vulnerability than CVE-2010-3041, CVE-2010-3043, and CVE-2010-3044.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2r84-qc2q-g26r

Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 2.8.0 through 3.1.0, 5.0.2 through 5.0.5, and 5.3.0 through 5.3.4 allows remote authenticated users to affect confidentiality via vectors related to CTF.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2r84-jvgc-hgc4

Cross-site scripting (XSS) vulnerability in admin/picture_modify.php in the photo-edit subsystem in Piwigo 2.6.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the associate[] field, a different vulnerability than CVE-2014-4649.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2r82-r48p-65qf

Windows DirectX Information Disclosure Vulnerability

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2r7x-gm4g-xxwx

Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to have unspecified impact via a crafted BMP image, a different vulnerability than CVE-2016-8698, CVE-2016-8699, CVE-2016-8701, CVE-2016-8702, and CVE-2016-8703.

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2r7x-944h-423g

In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_transport_requested_window_size We need to protect the reader reading the sysctl value because the value can be changed concurrently.

больше 1 года назад
github логотип
GHSA-2r7w-r6xm-q2q9

In IXP EasyInstall 6.2.13723, it is possible to temporarily disable UAC by using the Agent Service on a client system. An authenticated attacker (non-admin) can disable UAC for other users by renaming and replacing %SYSTEMDRIVE%\IXP\DATA\IXPAS.IXP.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2r7w-mhqc-r7r6

Microsoft Edge for Android Spoofing Vulnerability.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-2r7w-h968-j92j

Unknown vulnerability in ns-ldapd for Sun ONE Directory Server 4.16, 5.0, and 5.1 allows LDAP clients to cause a denial of service (service halt).

1%
Низкий
почти 4 года назад
github логотип
GHSA-2r7w-6p29-5vf5

Cross-Site Request Forgery (CSRF) vulnerability in Tim Eckel Minify HTML plugin <= 2.1.7 vulnerability.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2r7v-v86r-776v

The ioapic_read_indirect function in virt/kvm/ioapic.c in the Linux kernel through 3.8.4 does not properly handle a certain combination of invalid IOAPIC_REG_SELECT and IOAPIC_REG_WINDOW operations, which allows guest OS users to obtain sensitive information from host OS memory or cause a denial of service (host OS OOPS) via a crafted application.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2r7v-cmch-5x26

muhammara and hummus vulnerable to Unchecked Return Value to NULL Pointer Dereference

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-2r7v-857w-j9f5

NetEpi Case Manager before 0.98 generates different error messages depending on whether or not a username is valid, which allows remote attackers to enumerate valid usernames.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2r7r-6rh2-7qc9

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed an authenticated user to perform cross-site scripting attacks when the instance is served through certain content delivery networks.

CVSS3: 7.7
0%
Низкий
7 месяцев назад
github логотип
GHSA-2r7q-w9hc-4rq3

app\admin\controller\RouteController.php in ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code by using vectors involving portal/List/index and list/:id to inject this code into data\conf\route.php, as demonstrated by a file_put_contents call.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2r7q-8h3w-q3pc

make_catalog_backup in Bacula 2.2.5, and probably earlier, sends a MySQL password as a command line argument, and sometimes transmits cleartext e-mail containing this command line, which allows context-dependent attackers to obtain the password by listing the process and its arguments, or by sniffing the network.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-2r7q-76h8-63hq

functions.php in WHMCompleteSolution (WHMCS) 4.0.x through 5.0.x allows remote attackers to trigger arbitrary code execution in the Smarty templating system by submitting a crafted ticket, related to improper handling of characters in the subject field.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-2r7j-vm47-9h8m

Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).

CVSS3: 3.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2r7h-jv72-f7xp

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Solid Plugins AnalyticsWP allows Retrieve Embedded Sensitive Data.This issue affects AnalyticsWP: from n/a through 2.1.2.

CVSS3: 5.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-2r7g-mf5h-9gcw

Microsoft Windows XP SP2 and SP3, and Server 2003 SP1 and SP2, does not properly validate the option length field in Pragmatic General Multicast (PGM) packets, which allows remote attackers to cause a denial of service (infinite loop and system hang) via a crafted PGM packet, aka the "PGM Invalid Length Vulnerability."

51%
Средний
почти 4 года назад
github логотип
GHSA-2r7g-chxq-57q7

Multiple buffer overflows in the Cisco WebEx Recording Format (WRF) and Advanced Recording Format (ARF) Players T27LB before SP21 EP3 and T27LC before SP22 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted (1) .wrf or (2) .arf file, a different vulnerability than CVE-2010-3041, CVE-2010-3043, and CVE-2010-3044.

3%
Низкий
больше 3 лет назад

Уязвимостей на страницу