Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2r57-8pgj-h27p

почти 2 года назад

An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starting from 16.10 before 16.10.1. It was possible for an attacker to cause a denial of service using malicious crafted description parameter for labels.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2r57-2mrh-ggjv

больше 1 года назад

ydata cross-site scripting

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2r55-qfh2-945m

около 3 лет назад

Adobe InCopy versions 18.0 (and earlier), 17.4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2r55-9wvv-jwfw

больше 3 лет назад

Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/admin/categories/view_category.php?id=.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2r55-58m5-vgxw

почти 4 года назад

MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorization checks on multiple API functions. An attacker may gain access to these functions and achieve remote code execution, create a denial-of-service condition, and obtain sensitive information.

EPSS: Низкий
github логотип

GHSA-2r54-3grc-9jjr

5 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: NFSD: Protect against send buffer overflow in NFSv3 READ Since before the git era, NFSD has conserved the number of pages held by each nfsd thread by combining the RPC receive and send buffers into a single array of pages. This works because there are no cases where an operation needs a large RPC Call message and a large RPC Reply at the same time. Once an RPC Call has been received, svc_process() updates svc_rqst::rq_res to describe the part of rq_pages that can be used for constructing the Reply. This means that the send buffer (rq_res) shrinks when the received RPC record containing the RPC Call is large. A client can force this shrinkage on TCP by sending a correctly- formed RPC Call header contained in an RPC record that is excessively large. The full maximum payload size cannot be constructed in that case.

EPSS: Низкий
github логотип

GHSA-2r54-3gg6-ggrc

больше 2 лет назад

An issue in DLINK DPH-400SE FRU 2.2.15.8 allows a remote attacker to escalate privileges via the User Modify function in the Maintenance/Access function component.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2r53-r7pv-pqcp

больше 1 года назад

Globitel KSA SpeechLog v8.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Save Query function.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-2r53-mrx4-q6h9

больше 3 лет назад

On Juniper Networks EX and QFX Series, an authentication bypass vulnerability may allow a user connected to the console port to login as root without any password. This issue might only occur in certain scenarios: • At the first reboot after performing device factory reset using the command “request system zeroize”; or • A temporary moment during the first reboot after the software upgrade when the device configured in Virtual Chassis mode. This issue affects Juniper Networks Junos OS on EX and QFX Series: 14.1X53 versions prior to 14.1X53-D53; 15.1 versions prior to 15.1R7-S4; 15.1X53 versions prior to 15.1X53-D593; 16.1 versions prior to 16.1R7-S4; 17.1 versions prior to 17.1R2-S11, 17.1R3-S1; 17.2 versions prior to 17.2R3-S3; 17.3 versions prior to 17.3R2-S5, 17.3R3-S6; 17.4 versions prior to 17.4R2-S9, 17.4R3; 18.1 versions prior to 18.1R3-S8; 18.2 versions prior to 18.2R2; 18.3 versions prior to 18.3R1-S7, 18.3R2. This issue does not affect Juniper Networks Junos OS 12.3.

EPSS: Низкий
github логотип

GHSA-2r53-j9wg-3c93

больше 3 лет назад

Integer overflow in SAP Network Interface Router (SAProuter) 40.4 allows remote attackers to cause a denial of service (resource consumption) via crafted requests.

EPSS: Низкий
github логотип

GHSA-2r53-9295-3m86

около 2 лет назад

Statamic CMS vulnerable to remote code execution via form uploads

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2r4x-wmr4-6f57

больше 3 лет назад

Stack-based buffer overflow in the ReadFile function in flt_BMP.dll in Chasys Draw IES before 4.11.02 allows remote attackers to execute arbitrary code via crafted biPlanes and biBitCount fields in a BMP file.

EPSS: Высокий
github логотип

GHSA-2r4x-v526-vv9j

больше 3 лет назад

A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authentication, could send specially crafted messages to its peer which would result in a crash or, potentially, other impacts.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2r4x-qmjj-x52w

4 месяца назад

Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2r4x-667f-mpfh

11 месяцев назад

Apache Seata Vulnerable to Deserialization of Untrusted Data

EPSS: Низкий
github логотип

GHSA-2r4w-c5qm-vpx8

больше 3 лет назад

Fine Free file before 5.17 allows context-dependent attackers to cause a denial of service (infinite recursion, CPU consumption, and crash) via a crafted indirect offset value in the magic of a file.

EPSS: Средний
github логотип

GHSA-2r4r-m4wg-6v86

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in index.php in Catviz 0.4.0 beta 1 allow remote attackers to inject arbitrary web script or HTML via the (1) userman_form and (2) webpages_form parameters.

EPSS: Низкий
github логотип

GHSA-2r4r-h566-5q6r

почти 4 года назад

Rit Research Labs The Bat! 1.51 for Windows allows a remote attacker to cause a denial of service by sending an email to a user's account containing a carriage return <CR> that is not followed by a line feed <LF>.

EPSS: Низкий
github логотип

GHSA-2r4r-fch4-mp55

больше 3 лет назад

An elevation of privilege vulnerability in the Android framework (ui framework). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35056974.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2r4r-f5qg-rq3g

больше 2 лет назад

Parameter verification vulnerability in the window module.Successful exploitation of this vulnerability may cause the size of an app window to be adjusted to that of a floating window.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2r57-8pgj-h27p

An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starting from 16.10 before 16.10.1. It was possible for an attacker to cause a denial of service using malicious crafted description parameter for labels.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-2r57-2mrh-ggjv

ydata cross-site scripting

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2r55-qfh2-945m

Adobe InCopy versions 18.0 (and earlier), 17.4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-2r55-9wvv-jwfw

Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/admin/categories/view_category.php?id=.

CVSS3: 7.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2r55-58m5-vgxw

MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorization checks on multiple API functions. An attacker may gain access to these functions and achieve remote code execution, create a denial-of-service condition, and obtain sensitive information.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2r54-3grc-9jjr

In the Linux kernel, the following vulnerability has been resolved: NFSD: Protect against send buffer overflow in NFSv3 READ Since before the git era, NFSD has conserved the number of pages held by each nfsd thread by combining the RPC receive and send buffers into a single array of pages. This works because there are no cases where an operation needs a large RPC Call message and a large RPC Reply at the same time. Once an RPC Call has been received, svc_process() updates svc_rqst::rq_res to describe the part of rq_pages that can be used for constructing the Reply. This means that the send buffer (rq_res) shrinks when the received RPC record containing the RPC Call is large. A client can force this shrinkage on TCP by sending a correctly- formed RPC Call header contained in an RPC record that is excessively large. The full maximum payload size cannot be constructed in that case.

5 месяцев назад
github логотип
GHSA-2r54-3gg6-ggrc

An issue in DLINK DPH-400SE FRU 2.2.15.8 allows a remote attacker to escalate privileges via the User Modify function in the Maintenance/Access function component.

CVSS3: 8.8
6%
Низкий
больше 2 лет назад
github логотип
GHSA-2r53-r7pv-pqcp

Globitel KSA SpeechLog v8.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Save Query function.

CVSS3: 4.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-2r53-mrx4-q6h9

On Juniper Networks EX and QFX Series, an authentication bypass vulnerability may allow a user connected to the console port to login as root without any password. This issue might only occur in certain scenarios: • At the first reboot after performing device factory reset using the command “request system zeroize”; or • A temporary moment during the first reboot after the software upgrade when the device configured in Virtual Chassis mode. This issue affects Juniper Networks Junos OS on EX and QFX Series: 14.1X53 versions prior to 14.1X53-D53; 15.1 versions prior to 15.1R7-S4; 15.1X53 versions prior to 15.1X53-D593; 16.1 versions prior to 16.1R7-S4; 17.1 versions prior to 17.1R2-S11, 17.1R3-S1; 17.2 versions prior to 17.2R3-S3; 17.3 versions prior to 17.3R2-S5, 17.3R3-S6; 17.4 versions prior to 17.4R2-S9, 17.4R3; 18.1 versions prior to 18.1R3-S8; 18.2 versions prior to 18.2R2; 18.3 versions prior to 18.3R1-S7, 18.3R2. This issue does not affect Juniper Networks Junos OS 12.3.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2r53-j9wg-3c93

Integer overflow in SAP Network Interface Router (SAProuter) 40.4 allows remote attackers to cause a denial of service (resource consumption) via crafted requests.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2r53-9295-3m86

Statamic CMS vulnerable to remote code execution via form uploads

CVSS3: 8.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-2r4x-wmr4-6f57

Stack-based buffer overflow in the ReadFile function in flt_BMP.dll in Chasys Draw IES before 4.11.02 allows remote attackers to execute arbitrary code via crafted biPlanes and biBitCount fields in a BMP file.

77%
Высокий
больше 3 лет назад
github логотип
GHSA-2r4x-v526-vv9j

A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authentication, could send specially crafted messages to its peer which would result in a crash or, potentially, other impacts.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2r4x-qmjj-x52w

Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.

CVSS3: 7.3
0%
Низкий
4 месяца назад
github логотип
GHSA-2r4x-667f-mpfh

Apache Seata Vulnerable to Deserialization of Untrusted Data

0%
Низкий
11 месяцев назад
github логотип
GHSA-2r4w-c5qm-vpx8

Fine Free file before 5.17 allows context-dependent attackers to cause a denial of service (infinite recursion, CPU consumption, and crash) via a crafted indirect offset value in the magic of a file.

21%
Средний
больше 3 лет назад
github логотип
GHSA-2r4r-m4wg-6v86

Multiple cross-site scripting (XSS) vulnerabilities in index.php in Catviz 0.4.0 beta 1 allow remote attackers to inject arbitrary web script or HTML via the (1) userman_form and (2) webpages_form parameters.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2r4r-h566-5q6r

Rit Research Labs The Bat! 1.51 for Windows allows a remote attacker to cause a denial of service by sending an email to a user's account containing a carriage return <CR> that is not followed by a line feed <LF>.

4%
Низкий
почти 4 года назад
github логотип
GHSA-2r4r-fch4-mp55

An elevation of privilege vulnerability in the Android framework (ui framework). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35056974.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-2r4r-f5qg-rq3g

Parameter verification vulnerability in the window module.Successful exploitation of this vulnerability may cause the size of an app window to be adjusted to that of a floating window.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу