Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 928

Количество 314 928

github логотип

GHSA-2p57-rm9w-gvfp

больше 1 года назад

ip SSRF improper categorization in isPublic

CVSS3: 8.1
EPSS: Высокий
github логотип

GHSA-2p56-r36q-fx99

почти 4 года назад

The ispell_op function in ee on FreeBSD 4.10 to 6.0 uses predictable filenames and does not confirm which file is being written, which allows local users to overwrite arbitrary files via a symlink attack when ee invokes ispell.

EPSS: Низкий
github логотип

GHSA-2p56-f9g8-8p2x

больше 3 лет назад

analyzer/protocol/dnp3/DNP3.cc in Bro before 2.3.2 does not reject certain non-zero values of a packet length, which allows remote attackers to cause a denial of service (buffer overflow or buffer over-read) via a crafted DNP3 packet.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2p55-vr4g-qm2r

больше 3 лет назад

Genymotion Desktop v3.2.1 was discovered to contain a DLL hijacking vulnerability which allows attackers to escalate privileges and execute arbitrary code via a crafted binary.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2p55-mr3x-rqxj

почти 4 года назад

src/configure.in in Vim 5.0 through 7.1, when used for a build with Python support, does not ensure that the Makefile-conf temporary file has the intended ownership and permissions, which allows local users to execute arbitrary code by modifying this file during a time window, or by creating it ahead of time with permissions that prevent its modification by configure.

EPSS: Низкий
github логотип

GHSA-2p55-j483-368p

почти 4 года назад

Integer overflow in the Vector Markup Language (VML) implementation (vgx.dll) in Microsoft Internet Explorer 5.01, 6, and 7 on Windows 2000 SP4, XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted web page that contains unspecified integer properties that cause insufficient memory allocation and trigger a buffer overflow, aka the "VML Buffer Overrun Vulnerability."

EPSS: Средний
github логотип

GHSA-2p54-q56g-9668

27 дней назад

TestLink versions 1.16 through 1.19 contain an unauthenticated file download vulnerability in the attachmentdownload.php endpoint. Attackers can download arbitrary files by iterating file IDs through the 'id' parameter with 'skipCheck=1' to bypass access controls.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2p54-cq77-wrjr

больше 3 лет назад

There is a resource management error vulnerability in the verisions V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC200 of USG9500. An authentication attacker needs to perform specific operations to exploit the vulnerability on the affected device. Due to improper resource management of the function, the vulnerability can be exploited to cause service abnormal on affected devices.

EPSS: Низкий
github логотип

GHSA-2p53-823g-x3xx

почти 4 года назад

Buffer overflow in the sppp driver in FreeBSD 4.11 through 6.1, NetBSD 2.0 through 4.0 beta before 20060823, and OpenBSD 3.8 and 3.9 before 20060902 allows remote attackers to cause a denial of service (panic), obtain sensitive information, and possibly execute arbitrary code via crafted Link Control Protocol (LCP) packets with an option length that exceeds the overall length, which triggers the overflow in (1) pppoe and (2) ippp. NOTE: this issue was originally incorrectly reported for the ppp driver.

EPSS: Низкий
github логотип

GHSA-2p53-7wvg-49xh

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.29, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.0, when OAuth is used, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2p4x-63mg-m275

почти 3 года назад

An arbitrary file upload vulnerability in the upload function of GDidees CMS 3.9.1 allows attackers to execute arbitrary code via a crafted file.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2p4x-3pfm-qg42

больше 3 лет назад

A door-unlocking issue was discovered on Software House iStar Ultra devices through 6.5.2.20569 when used in conjunction with the IP-ACM Ethernet Door Module. The communications between the IP-ACM and the iStar Ultra is encrypted using a fixed AES key and IV. Each message is encrypted in CBC mode and restarts with the fixed IV, leading to replay attacks of entire messages. There is no authentication of messages beyond the use of the fixed AES key, so message forgery is also possible.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-2p4w-vvgf-h24f

больше 3 лет назад

SmokeDetector intentionally does automatic deployments of updated copies of SmokeDetector without server operator authority.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2p4v-cp2q-5hx3

около 1 года назад

In updateInternal of MediaProvider.java , there is a possible access of another app's files due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2p4v-c3cg-43pp

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in PHP 4.4.1 and 5.1.1, when display_errors and html_errors are on, allow remote attackers to inject arbitrary web script or HTML via inputs to PHP applications that are not filtered when they are included in the resulting error message.

EPSS: Низкий
github логотип

GHSA-2p4v-83h2-m772

больше 3 лет назад

Incorrect security UI in TabStrip and Navigation in Google Chrome on Android prior to 89.0.4389.72 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

EPSS: Низкий
github логотип

GHSA-2p4v-77rh-r7fj

больше 3 лет назад

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer handler where improper handling of values may cause a denial of service on the system.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2p4r-xjwx-3whg

больше 1 года назад

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Tips and Tricks HQ Stripe Payments allows Code Injection.This issue affects Stripe Payments: from n/a through 2.0.79.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2p4r-h63c-pgmr

больше 1 года назад

The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 2.0.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2p4q-qc9j-27gx

около 1 года назад

Windows Hyper-V Denial of Service Vulnerability

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2p57-rm9w-gvfp

ip SSRF improper categorization in isPublic

CVSS3: 8.1
88%
Высокий
больше 1 года назад
github логотип
GHSA-2p56-r36q-fx99

The ispell_op function in ee on FreeBSD 4.10 to 6.0 uses predictable filenames and does not confirm which file is being written, which allows local users to overwrite arbitrary files via a symlink attack when ee invokes ispell.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2p56-f9g8-8p2x

analyzer/protocol/dnp3/DNP3.cc in Bro before 2.3.2 does not reject certain non-zero values of a packet length, which allows remote attackers to cause a denial of service (buffer overflow or buffer over-read) via a crafted DNP3 packet.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2p55-vr4g-qm2r

Genymotion Desktop v3.2.1 was discovered to contain a DLL hijacking vulnerability which allows attackers to escalate privileges and execute arbitrary code via a crafted binary.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2p55-mr3x-rqxj

src/configure.in in Vim 5.0 through 7.1, when used for a build with Python support, does not ensure that the Makefile-conf temporary file has the intended ownership and permissions, which allows local users to execute arbitrary code by modifying this file during a time window, or by creating it ahead of time with permissions that prevent its modification by configure.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2p55-j483-368p

Integer overflow in the Vector Markup Language (VML) implementation (vgx.dll) in Microsoft Internet Explorer 5.01, 6, and 7 on Windows 2000 SP4, XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted web page that contains unspecified integer properties that cause insufficient memory allocation and trigger a buffer overflow, aka the "VML Buffer Overrun Vulnerability."

40%
Средний
почти 4 года назад
github логотип
GHSA-2p54-q56g-9668

TestLink versions 1.16 through 1.19 contain an unauthenticated file download vulnerability in the attachmentdownload.php endpoint. Attackers can download arbitrary files by iterating file IDs through the 'id' parameter with 'skipCheck=1' to bypass access controls.

CVSS3: 9.8
27 дней назад
github логотип
GHSA-2p54-cq77-wrjr

There is a resource management error vulnerability in the verisions V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC200 of USG9500. An authentication attacker needs to perform specific operations to exploit the vulnerability on the affected device. Due to improper resource management of the function, the vulnerability can be exploited to cause service abnormal on affected devices.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2p53-823g-x3xx

Buffer overflow in the sppp driver in FreeBSD 4.11 through 6.1, NetBSD 2.0 through 4.0 beta before 20060823, and OpenBSD 3.8 and 3.9 before 20060902 allows remote attackers to cause a denial of service (panic), obtain sensitive information, and possibly execute arbitrary code via crafted Link Control Protocol (LCP) packets with an option length that exceeds the overall length, which triggers the overflow in (1) pppoe and (2) ippp. NOTE: this issue was originally incorrectly reported for the ppp driver.

6%
Низкий
почти 4 года назад
github логотип
GHSA-2p53-7wvg-49xh

Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.29, 8.0 before 8.0.0.7, and 8.5 before 8.5.5.0, when OAuth is used, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2p4x-63mg-m275

An arbitrary file upload vulnerability in the upload function of GDidees CMS 3.9.1 allows attackers to execute arbitrary code via a crafted file.

CVSS3: 9.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-2p4x-3pfm-qg42

A door-unlocking issue was discovered on Software House iStar Ultra devices through 6.5.2.20569 when used in conjunction with the IP-ACM Ethernet Door Module. The communications between the IP-ACM and the iStar Ultra is encrypted using a fixed AES key and IV. Each message is encrypted in CBC mode and restarts with the fixed IV, leading to replay attacks of entire messages. There is no authentication of messages beyond the use of the fixed AES key, so message forgery is also possible.

CVSS3: 7.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2p4w-vvgf-h24f

SmokeDetector intentionally does automatic deployments of updated copies of SmokeDetector without server operator authority.

CVSS3: 7.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2p4v-cp2q-5hx3

In updateInternal of MediaProvider.java , there is a possible access of another app's files due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-2p4v-c3cg-43pp

Multiple cross-site scripting (XSS) vulnerabilities in PHP 4.4.1 and 5.1.1, when display_errors and html_errors are on, allow remote attackers to inject arbitrary web script or HTML via inputs to PHP applications that are not filtered when they are included in the resulting error message.

2%
Низкий
почти 4 года назад
github логотип
GHSA-2p4v-83h2-m772

Incorrect security UI in TabStrip and Navigation in Google Chrome on Android prior to 89.0.4389.72 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2p4v-77rh-r7fj

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer handler where improper handling of values may cause a denial of service on the system.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2p4r-xjwx-3whg

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Tips and Tricks HQ Stripe Payments allows Code Injection.This issue affects Stripe Payments: from n/a through 2.0.79.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2p4r-h63c-pgmr

The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 2.0.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-2p4q-qc9j-27gx

Windows Hyper-V Denial of Service Vulnerability

CVSS3: 6.5
0%
Низкий
около 1 года назад

Уязвимостей на страницу