Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 315 253

Количество 315 253

github логотип

GHSA-2pr9-w7jf-v4v7

больше 3 лет назад

Philips SureSigns VS4, A.07.107 and prior. The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CVSS3: 2.1
EPSS: Низкий
github логотип

GHSA-2pr9-mv6f-chvj

больше 3 лет назад

A stack buffer overflow in V8 in Google Chrome prior to 62.0.3202.75 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2pr9-53x2-jqgh

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: nilfs2: handle inconsistent state in nilfs_btnode_create_block() Syzbot reported that a buffer state inconsistency was detected in nilfs_btnode_create_block(), triggering a kernel bug. It is not appropriate to treat this inconsistency as a bug; it can occur if the argument block address (the buffer index of the newly created block) is a virtual block number and has been reallocated due to corruption of the bitmap used to manage its allocation state. So, modify nilfs_btnode_create_block() and its callers to treat it as a possible filesystem error, rather than triggering a kernel bug.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2pr9-2h78-r68r

больше 3 лет назад

service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary DLL functions via the XF function, possibly related to an insecure exposed method.

EPSS: Высокий
github логотип

GHSA-2pr8-9hq9-m7pw

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the CMS Updater module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving the configuration page.

EPSS: Низкий
github логотип

GHSA-2pr7-vcjv-rp52

почти 4 года назад

Buffer overflow in the Foundation framework for Mac OS X 10.3.9 allows local users to execute arbitrary code via a long environment variable.

EPSS: Низкий
github логотип

GHSA-2pr7-6gvg-hcv8

больше 3 лет назад

Vulnerability in the Oracle Crystal Ball product of Oracle Construction and Engineering (component: Installation). Supported versions that are affected are 11.1.2.0.000-11.1.2.4.900. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Crystal Ball executes to compromise Oracle Crystal Ball. While the vulnerability is in Oracle Crystal Ball, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Crystal Ball. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2pr6-vhmf-w3qp

больше 3 лет назад

VMware vCenter Server (6.5 prior to 6.5 U1) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker with VC user privileges can inject malicious java-scripts which will get executed when other VC users access the page.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2pr6-h9cg-7rr7

больше 2 лет назад

Cross Site Request Forgery (CSRF) vulnerability in Archer Platform before v.6.13 and fixed in v.6.12.0.6 and v.6.13.0 allows an authenticated attacker to execute arbitrary code via a crafted request.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2pr6-76vf-7546

больше 6 лет назад

Denial of Service in js-yaml

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2pr5-qxg3-pfqf

6 месяцев назад

openjpeg v 2.5.0 was discovered to contain a NULL pointer dereference via the component /openjp2/dwt.c.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2pr3-v8qp-792f

7 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Delicious WP Delicious allows DOM-Based XSS. This issue affects WP Delicious: from n/a through 1.8.4.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2pr3-qrhm-jm7j

больше 3 лет назад

PoDoFo::Impose::PdfTranslator::setSource() in pdftranslator.cpp in PoDoFo 0.9.6 has a NULL pointer dereference that can (for example) be triggered by sending a crafted PDF file to the podofoimpose binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2pr3-956j-4qvg

больше 3 лет назад

Software Integrity Attacks vulnerability in Intel Security Anti-Virus Engine (AVE) 5200 through 5800 allows local users to bypass local security protection via a crafted input file.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2pr3-6gwh-9gvq

почти 4 года назад

Cross-site scripting (XSS) vulnerability in PostNuke 0.71 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) name parameter in modules.php and (2) catid parameter in index.php.

EPSS: Низкий
github логотип

GHSA-2pr3-45mh-ph8r

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in PHPDug 2.0.0 allow remote attackers to inject arbitrary web script or HTML via (1) the story_url parameter to add_story.php, (2) the email parameter to editprofile.php, (3) the title parameter to adm/content_add.php, or (4) the username parameter to adm/admin_edit.php.

EPSS: Низкий
github логотип

GHSA-2pr2-cxfq-398w

больше 3 лет назад

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "SQLite" component. A use-after-free vulnerability allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted SQL statement.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2pqx-426g-hrmc

больше 3 лет назад

The (1) bin/invscoutClient_VPD_Survey and (2) sbin/invscout_lsvpd programs in invscout.rte before 2.2.0.19 on IBM AIX 7.1, 6.1, 5.3, and earlier allow local users to delete arbitrary files, or trigger inventory scout operations on arbitrary files, via a symlink attack on an unspecified file.

EPSS: Низкий
github логотип

GHSA-2pqv-gjx5-j94f

больше 3 лет назад

A potential vulnerability has been identified in HP Remote Graphics Software’s certificate authentication process version 7.5.0 and earlier.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-2pqr-cp8m-m5vw

больше 3 лет назад

An issue was discovered in the pam_p11 component 0.2.0 and 0.3.0 for OpenSC. If a smart card creates a signature with a length longer than 256 bytes, this triggers a buffer overflow. This may be the case for RSA keys with 4096 bits depending on the signature scheme.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2pr9-w7jf-v4v7

Philips SureSigns VS4, A.07.107 and prior. The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CVSS3: 2.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2pr9-mv6f-chvj

A stack buffer overflow in V8 in Google Chrome prior to 62.0.3202.75 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2pr9-53x2-jqgh

In the Linux kernel, the following vulnerability has been resolved: nilfs2: handle inconsistent state in nilfs_btnode_create_block() Syzbot reported that a buffer state inconsistency was detected in nilfs_btnode_create_block(), triggering a kernel bug. It is not appropriate to treat this inconsistency as a bug; it can occur if the argument block address (the buffer index of the newly created block) is a virtual block number and has been reallocated due to corruption of the bitmap used to manage its allocation state. So, modify nilfs_btnode_create_block() and its callers to treat it as a possible filesystem error, rather than triggering a kernel bug.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2pr9-2h78-r68r

service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary DLL functions via the XF function, possibly related to an insecure exposed method.

72%
Высокий
больше 3 лет назад
github логотип
GHSA-2pr8-9hq9-m7pw

Cross-site scripting (XSS) vulnerability in the CMS Updater module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving the configuration page.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2pr7-vcjv-rp52

Buffer overflow in the Foundation framework for Mac OS X 10.3.9 allows local users to execute arbitrary code via a long environment variable.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2pr7-6gvg-hcv8

Vulnerability in the Oracle Crystal Ball product of Oracle Construction and Engineering (component: Installation). Supported versions that are affected are 11.1.2.0.000-11.1.2.4.900. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Crystal Ball executes to compromise Oracle Crystal Ball. While the vulnerability is in Oracle Crystal Ball, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Crystal Ball. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2pr6-vhmf-w3qp

VMware vCenter Server (6.5 prior to 6.5 U1) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker with VC user privileges can inject malicious java-scripts which will get executed when other VC users access the page.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2pr6-h9cg-7rr7

Cross Site Request Forgery (CSRF) vulnerability in Archer Platform before v.6.13 and fixed in v.6.12.0.6 and v.6.13.0 allows an authenticated attacker to execute arbitrary code via a crafted request.

CVSS3: 8.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2pr6-76vf-7546

Denial of Service in js-yaml

CVSS3: 5.9
больше 6 лет назад
github логотип
GHSA-2pr5-qxg3-pfqf

openjpeg v 2.5.0 was discovered to contain a NULL pointer dereference via the component /openjp2/dwt.c.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-2pr3-v8qp-792f

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Delicious WP Delicious allows DOM-Based XSS. This issue affects WP Delicious: from n/a through 1.8.4.

CVSS3: 6.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-2pr3-qrhm-jm7j

PoDoFo::Impose::PdfTranslator::setSource() in pdftranslator.cpp in PoDoFo 0.9.6 has a NULL pointer dereference that can (for example) be triggered by sending a crafted PDF file to the podofoimpose binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2pr3-956j-4qvg

Software Integrity Attacks vulnerability in Intel Security Anti-Virus Engine (AVE) 5200 through 5800 allows local users to bypass local security protection via a crafted input file.

CVSS3: 7.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2pr3-6gwh-9gvq

Cross-site scripting (XSS) vulnerability in PostNuke 0.71 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) name parameter in modules.php and (2) catid parameter in index.php.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2pr3-45mh-ph8r

Multiple cross-site scripting (XSS) vulnerabilities in PHPDug 2.0.0 allow remote attackers to inject arbitrary web script or HTML via (1) the story_url parameter to add_story.php, (2) the email parameter to editprofile.php, (3) the title parameter to adm/content_add.php, or (4) the username parameter to adm/admin_edit.php.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2pr2-cxfq-398w

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "SQLite" component. A use-after-free vulnerability allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted SQL statement.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-2pqx-426g-hrmc

The (1) bin/invscoutClient_VPD_Survey and (2) sbin/invscout_lsvpd programs in invscout.rte before 2.2.0.19 on IBM AIX 7.1, 6.1, 5.3, and earlier allow local users to delete arbitrary files, or trigger inventory scout operations on arbitrary files, via a symlink attack on an unspecified file.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2pqv-gjx5-j94f

A potential vulnerability has been identified in HP Remote Graphics Software’s certificate authentication process version 7.5.0 and earlier.

CVSS3: 9.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2pqr-cp8m-m5vw

An issue was discovered in the pam_p11 component 0.2.0 and 0.3.0 for OpenSC. If a smart card creates a signature with a length longer than 256 bytes, this triggers a buffer overflow. This may be the case for RSA keys with 4096 bits depending on the signature scheme.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу