Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 315 253

Количество 315 253

github логотип

GHSA-2ppj-9hhv-grqq

больше 3 лет назад

SepCity Classified Ads stores the admin password in cleartext in data/classifieds.mdb, which allows context-dependent attackers to obtain sensitive information.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2pph-9j29-pp7r

почти 4 года назад

NetLeaf Limited NotJustBrowsing 1.0.3 stores the View Lock Password in plaintext in the notjustbrowsing.prf file, which allows local users to gain privileges.

EPSS: Низкий
github логотип

GHSA-2pph-66px-9x3w

6 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: media: ti: j721e-csi2rx: fix list_del corruption If ti_csi2rx_start_dma() fails in ti_csi2rx_dma_callback(), the buffer is marked done with VB2_BUF_STATE_ERROR but is not removed from the DMA queue. This causes the same buffer to be retried in the next iteration, resulting in a double list_del() and eventual list corruption. Fix this by removing the buffer from the queue before calling vb2_buffer_done() on error. This resolves a crash due to list_del corruption: [ 37.811243] j721e-csi2rx 30102000.ticsi2rx: Failed to queue the next buffer for DMA [ 37.832187] slab kmalloc-2k start ffff00000255b000 pointer offset 1064 size 2048 [ 37.839761] list_del corruption. next->prev should be ffff00000255bc28, but was ffff00000255d428. (next=ffff00000255b428) [ 37.850799] ------------[ cut here ]------------ [ 37.855424] kernel BUG at lib/list_debug.c:65! [ 37.859876] Internal error: Oops - BUG: 00000000f2000800...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2pph-3mjw-53c3

почти 4 года назад

GNOME OCRFeeder before 0.8.4 allows OS command injection via shell metacharacters in a PDF or image filename.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2ppg-mx5c-6pmw

около 4 лет назад

Adobe InDesign version 16.4 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious JPEG file.

EPSS: Низкий
github логотип

GHSA-2ppg-jmhh-7wx9

около 3 лет назад

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer overflow is in the function that manages the 'vpn l2tp advanced name WORD dns (yes|no) mtu <128-16384> mru <128-16384> auth (on|off) password (WORD|null) options WORD' command template.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2ppg-9297-h3vc

9 месяцев назад

When a Stream Control Transmission Protocol (SCTP) profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2ppg-88hg-fw2j

больше 3 лет назад

Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-2ppg-66j5-9h8g

больше 3 лет назад

GdiDrawHoriLineIAlt in Kingsoft WPS Office before 11.2.0.9403 allows remote heap corruption via a crafted PLTE chunk in PNG data within a Word document. This is related to QBrush::setMatrix in gui/painting/qbrush.cpp in Qt 4.x.

EPSS: Низкий
github логотип

GHSA-2ppf-gqj9-p969

6 месяцев назад

IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.03 could be susceptible to cross-site scripting due to no validation of URIs.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2ppf-g925-w5q9

11 месяцев назад

NVIDIA Hopper HGX for 8-GPU contains a vulnerability in the GPU vBIOS that may allow a malicious actor with tenant level GPU access to write to an unsupported registry causing a bad state. A successful exploit of this vulnerability may lead to denial of service.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-2ppf-7c48-6cc8

около 2 лет назад

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2ppf-2m6f-6v6f

около 1 года назад

OpenStack improperly deletes access rules

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2ppc-v4fh-g52h

почти 4 года назад

GuildFTPd 0.999.14, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long arguments to the CWD and LIST commands, which triggers heap corruption related to an improper free call, and possibly triggering a heap-based buffer overflow.

EPSS: Высокий
github логотип

GHSA-2ppc-m2x5-g88c

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Store Locator (locator) extension before 3.1.5 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2ppc-97gw-v7r8

больше 3 лет назад

dhcpcd before 7.2.1 contains a buffer overflow in dhcp6_findna in dhcp6.c when reading NA/TA addresses.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-2pp9-v2c7-29w7

7 месяцев назад

The Kallyas theme for WordPress is vulnerable to arbitrary folder deletion due to insufficient file path validation in the delete_font() function in all versions up to, and including, 4.21.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary folders on the server.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2pp9-r4rv-6p6j

больше 3 лет назад

Exposure of Sensitive Information to an Unauthorized Actor in Jenkins

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2pp9-pqc7-hf75

больше 3 лет назад

Buffer overflow in the Cisco WebEx Advanced Recording Format (ARF) player T27 L through SP11 EP26, T27 LB through SP21 EP10, T27 LC before SP25 EP11, T27 LD before SP32 CP2, and T28 L10N before SP1 allows remote attackers to execute arbitrary code via a crafted ARF file, aka Bug ID CSCtz72985.

EPSS: Низкий
github логотип

GHSA-2pp9-cmh9-mhg5

около 3 лет назад

Insufficient validation of untrusted input in CORS in Google Chrome on Android prior to 108.0.5359.71 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2ppj-9hhv-grqq

SepCity Classified Ads stores the admin password in cleartext in data/classifieds.mdb, which allows context-dependent attackers to obtain sensitive information.

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-2pph-9j29-pp7r

NetLeaf Limited NotJustBrowsing 1.0.3 stores the View Lock Password in plaintext in the notjustbrowsing.prf file, which allows local users to gain privileges.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2pph-66px-9x3w

In the Linux kernel, the following vulnerability has been resolved: media: ti: j721e-csi2rx: fix list_del corruption If ti_csi2rx_start_dma() fails in ti_csi2rx_dma_callback(), the buffer is marked done with VB2_BUF_STATE_ERROR but is not removed from the DMA queue. This causes the same buffer to be retried in the next iteration, resulting in a double list_del() and eventual list corruption. Fix this by removing the buffer from the queue before calling vb2_buffer_done() on error. This resolves a crash due to list_del corruption: [ 37.811243] j721e-csi2rx 30102000.ticsi2rx: Failed to queue the next buffer for DMA [ 37.832187] slab kmalloc-2k start ffff00000255b000 pointer offset 1064 size 2048 [ 37.839761] list_del corruption. next->prev should be ffff00000255bc28, but was ffff00000255d428. (next=ffff00000255b428) [ 37.850799] ------------[ cut here ]------------ [ 37.855424] kernel BUG at lib/list_debug.c:65! [ 37.859876] Internal error: Oops - BUG: 00000000f2000800...

CVSS3: 5.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-2pph-3mjw-53c3

GNOME OCRFeeder before 0.8.4 allows OS command injection via shell metacharacters in a PDF or image filename.

CVSS3: 9.8
3%
Низкий
почти 4 года назад
github логотип
GHSA-2ppg-mx5c-6pmw

Adobe InDesign version 16.4 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious JPEG file.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2ppg-jmhh-7wx9

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer overflow is in the function that manages the 'vpn l2tp advanced name WORD dns (yes|no) mtu <128-16384> mru <128-16384> auth (on|off) password (WORD|null) options WORD' command template.

CVSS3: 7.2
3%
Низкий
около 3 лет назад
github логотип
GHSA-2ppg-9297-h3vc

When a Stream Control Transmission Protocol (SCTP) profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 7.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-2ppg-88hg-fw2j

Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVSS3: 8.8
21%
Средний
больше 3 лет назад
github логотип
GHSA-2ppg-66j5-9h8g

GdiDrawHoriLineIAlt in Kingsoft WPS Office before 11.2.0.9403 allows remote heap corruption via a crafted PLTE chunk in PNG data within a Word document. This is related to QBrush::setMatrix in gui/painting/qbrush.cpp in Qt 4.x.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2ppf-gqj9-p969

IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.03 could be susceptible to cross-site scripting due to no validation of URIs.

CVSS3: 6.1
0%
Низкий
6 месяцев назад
github логотип
GHSA-2ppf-g925-w5q9

NVIDIA Hopper HGX for 8-GPU contains a vulnerability in the GPU vBIOS that may allow a malicious actor with tenant level GPU access to write to an unsupported registry causing a bad state. A successful exploit of this vulnerability may lead to denial of service.

CVSS3: 6.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-2ppf-7c48-6cc8

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVSS3: 7.8
4%
Низкий
около 2 лет назад
github логотип
GHSA-2ppf-2m6f-6v6f

OpenStack improperly deletes access rules

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2ppc-v4fh-g52h

GuildFTPd 0.999.14, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long arguments to the CWD and LIST commands, which triggers heap corruption related to an improper free call, and possibly triggering a heap-based buffer overflow.

77%
Высокий
почти 4 года назад
github логотип
GHSA-2ppc-m2x5-g88c

Cross-site scripting (XSS) vulnerability in the Store Locator (locator) extension before 3.1.5 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2ppc-97gw-v7r8

dhcpcd before 7.2.1 contains a buffer overflow in dhcp6_findna in dhcp6.c when reading NA/TA addresses.

CVSS3: 9.8
18%
Средний
больше 3 лет назад
github логотип
GHSA-2pp9-v2c7-29w7

The Kallyas theme for WordPress is vulnerable to arbitrary folder deletion due to insufficient file path validation in the delete_font() function in all versions up to, and including, 4.21.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary folders on the server.

CVSS3: 8.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-2pp9-r4rv-6p6j

Exposure of Sensitive Information to an Unauthorized Actor in Jenkins

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2pp9-pqc7-hf75

Buffer overflow in the Cisco WebEx Advanced Recording Format (ARF) player T27 L through SP11 EP26, T27 LB through SP21 EP10, T27 LC before SP25 EP11, T27 LD before SP32 CP2, and T28 L10N before SP1 allows remote attackers to execute arbitrary code via a crafted ARF file, aka Bug ID CSCtz72985.

4%
Низкий
больше 3 лет назад
github логотип
GHSA-2pp9-cmh9-mhg5

Insufficient validation of untrusted input in CORS in Google Chrome on Android prior to 108.0.5359.71 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 4.3
0%
Низкий
около 3 лет назад

Уязвимостей на страницу