Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 313 049

Количество 313 049

github логотип

GHSA-2pcc-vj7h-7frv

почти 4 года назад

On Arista Strata family products which have “TCAM profile” feature enabled when Port IPv4 access-list has a rule which matches on “vxlan” as protocol then that rule and subsequent rules ( rules declared after it in ACL ) do not match on IP protocol field as expected.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2pc9-4j83-qjmr

18 дней назад

vLLM affected by RCE via auto_map dynamic module loading during model initialization

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2pc7-q5qc-x4v8

больше 3 лет назад

Ittiam libmpeg2 before 2022-07-27 uses memcpy with overlapping memory blocks in impeg2_mc_fullx_fully_8x8.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2pc6-768q-99h7

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 12.2 through 12.2.1. The project import API could be used to bypass project visibility restrictions.

EPSS: Низкий
github логотип

GHSA-2pc6-68rr-693p

8 месяцев назад

PDF-XChange Editor U3D File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26644.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2pc5-gx8g-j846

11 месяцев назад

SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ip.php.

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-2pc5-c325-6frx

почти 2 года назад

A vulnerability was found in Tenda 4G300 1.01.42. It has been declared as critical. This vulnerability affects the function sub_42775C/sub_4279CC. The manipulation of the argument page leads to stack-based buffer overflow. The attack can be initiated remotely. The identifier of this vulnerability is VDB-261988. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2pc3-p36x-gxgx

больше 3 лет назад

libsecurity in Apple Mac OS X before 10.7.2 does not properly handle errors during processing of a nonstandard extension in a Certificate Revocation list (CRL), which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) a crafted (1) web site or (2) e-mail message.

EPSS: Низкий
github логотип

GHSA-2pc3-m7w9-6vv5

больше 3 лет назад

The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the 1) sdm_active_tab GET parameter and 2) sdm_stats_start_date/sdm_stats_end_date POST parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

EPSS: Низкий
github логотип

GHSA-2pc2-xr96-6c7v

около 3 лет назад

To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

EPSS: Низкий
github логотип

GHSA-2pc2-wxgf-m9mm

больше 1 года назад

Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted javascript payload to an authenticated user and partially take over their browser session via the 'id' and 'view' parameters in '/user/index.php'.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2pc2-h97h-2mmw

почти 2 года назад

Jenkins iceScrum Plugin vulnerable to stored Cross-site Scripting

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-2p9x-qhg2-q4vr

больше 3 лет назад

The hardware security module of Mate 9 and Mate 9 Pro Huawei smart phones with the versions earlier before MHA-AL00BC00B156, versions earlier before MHA-CL00BC00B156, versions earlier before MHA-DL00BC00B156, versions earlier before MHA-TL00BC00B156, versions earlier before LON-AL00BC00B156, versions earlier before LON-CL00BC00B156, versions earlier before LON-DL00BC00B156, versions earlier before LON-TL00BC00B156 has a arbitrary memory read/write vulnerability due to the input parameters validation. An attacker with the root privilege of the Android system could exploit this vulnerability to read and write memory data anywhere or execute arbitrary code in the TrustZone.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2p9x-h657-5mg3

больше 1 года назад

Victure PC420 1.1.39 was discovered to use a weak and partially hardcoded key to encrypt data.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2p9x-6v53-f7f4

больше 3 лет назад

Insufficient sanitization of inputs in QoE application input field could lead to stored and Dom based XSS attack. This issue is fixed and released in SolarWinds Platform (2022.3.0).

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2p9w-qq57-w5jv

почти 4 года назад

CarbonCore in Apple Mac OS X 10.4.11 and 10.5.8 allows attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a file with a crafted resource fork.

EPSS: Низкий
github логотип

GHSA-2p9w-9f6v-m3cp

больше 3 лет назад

An issue was discovered in Sysax Multi Server 6.90. There is reflected XSS via the /scgi sid parameter.

EPSS: Низкий
github логотип

GHSA-2p9w-5q3p-g7cv

больше 2 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.7 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A Regular Expression Denial of Service was possible via sending crafted payloads to the preview_markdown endpoint.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2p9w-4jwx-hjx2

4 месяца назад

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view items on the "Why" page.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2p9r-433v-xm34

больше 3 лет назад

In ixheaacd_extract_frame_info_ld of ixheaacd_env_extr.c there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112765917

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2pcc-vj7h-7frv

On Arista Strata family products which have “TCAM profile” feature enabled when Port IPv4 access-list has a rule which matches on “vxlan” as protocol then that rule and subsequent rules ( rules declared after it in ACL ) do not match on IP protocol field as expected.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-2pc9-4j83-qjmr

vLLM affected by RCE via auto_map dynamic module loading during model initialization

CVSS3: 8.8
0%
Низкий
18 дней назад
github логотип
GHSA-2pc7-q5qc-x4v8

Ittiam libmpeg2 before 2022-07-27 uses memcpy with overlapping memory blocks in impeg2_mc_fullx_fully_8x8.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2pc6-768q-99h7

An issue was discovered in GitLab Community and Enterprise Edition 12.2 through 12.2.1. The project import API could be used to bypass project visibility restrictions.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2pc6-68rr-693p

PDF-XChange Editor U3D File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26644.

CVSS3: 7.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-2pc5-gx8g-j846

SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ip.php.

CVSS3: 5.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-2pc5-c325-6frx

A vulnerability was found in Tenda 4G300 1.01.42. It has been declared as critical. This vulnerability affects the function sub_42775C/sub_4279CC. The manipulation of the argument page leads to stack-based buffer overflow. The attack can be initiated remotely. The identifier of this vulnerability is VDB-261988. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-2pc3-p36x-gxgx

libsecurity in Apple Mac OS X before 10.7.2 does not properly handle errors during processing of a nonstandard extension in a Certificate Revocation list (CRL), which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) a crafted (1) web site or (2) e-mail message.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2pc3-m7w9-6vv5

The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the 1) sdm_active_tab GET parameter and 2) sdm_stats_start_date/sdm_stats_end_date POST parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2pc2-xr96-6c7v

To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

около 3 лет назад
github логотип
GHSA-2pc2-wxgf-m9mm

Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted javascript payload to an authenticated user and partially take over their browser session via the 'id' and 'view' parameters in '/user/index.php'.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-2pc2-h97h-2mmw

Jenkins iceScrum Plugin vulnerable to stored Cross-site Scripting

CVSS3: 8
0%
Низкий
почти 2 года назад
github логотип
GHSA-2p9x-qhg2-q4vr

The hardware security module of Mate 9 and Mate 9 Pro Huawei smart phones with the versions earlier before MHA-AL00BC00B156, versions earlier before MHA-CL00BC00B156, versions earlier before MHA-DL00BC00B156, versions earlier before MHA-TL00BC00B156, versions earlier before LON-AL00BC00B156, versions earlier before LON-CL00BC00B156, versions earlier before LON-DL00BC00B156, versions earlier before LON-TL00BC00B156 has a arbitrary memory read/write vulnerability due to the input parameters validation. An attacker with the root privilege of the Android system could exploit this vulnerability to read and write memory data anywhere or execute arbitrary code in the TrustZone.

CVSS3: 6.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2p9x-h657-5mg3

Victure PC420 1.1.39 was discovered to use a weak and partially hardcoded key to encrypt data.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2p9x-6v53-f7f4

Insufficient sanitization of inputs in QoE application input field could lead to stored and Dom based XSS attack. This issue is fixed and released in SolarWinds Platform (2022.3.0).

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2p9w-qq57-w5jv

CarbonCore in Apple Mac OS X 10.4.11 and 10.5.8 allows attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a file with a crafted resource fork.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2p9w-9f6v-m3cp

An issue was discovered in Sysax Multi Server 6.90. There is reflected XSS via the /scgi sid parameter.

9%
Низкий
больше 3 лет назад
github логотип
GHSA-2p9w-5q3p-g7cv

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.7 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A Regular Expression Denial of Service was possible via sending crafted payloads to the preview_markdown endpoint.

CVSS3: 7.5
2%
Низкий
больше 2 лет назад
github логотип
GHSA-2p9w-4jwx-hjx2

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view items on the "Why" page.

CVSS3: 4.3
0%
Низкий
4 месяца назад
github логотип
GHSA-2p9r-433v-xm34

In ixheaacd_extract_frame_info_ld of ixheaacd_env_extr.c there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112765917

CVSS3: 8.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу