Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 928

Количество 314 928

github логотип

GHSA-2p4q-q7j4-q23g

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check BIOS images before it is used BIOS images may fail to load and null checks are added before they are used. This fixes 6 NULL_RETURNS issues reported by Coverity.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2p4q-pg24-pmp6

больше 3 лет назад

IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server 5.5 before 5.5.6.1, 6.3 before 6.3.1.5, 6.4 before 6.4.1.7, and 7.1 before 7.1.2; Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server 5.5 before 5.5.1.1, 6.1 before 6.1.3.7, 6.3 before 6.3.1.5, 6.4 before 6.4.1.7, and 7.1 before 7.1.2; and Tivoli Storage FlashCopy Manager 3.1 before 3.1.1.5, 3.2 before 3.2.1.7, and 4.1 before 4.1.2, when application tracing is used, place cleartext passwords in exception messages, which allows physically proximate attackers to obtain sensitive information by reading trace output, a different vulnerability than CVE-2015-4949.

EPSS: Низкий
github логотип

GHSA-2p4q-mvv4-rjr2

8 месяцев назад

Netbox Community 4.1.7 is vulnerable to Cross Site Scripting (XSS) via the maintenance banner` in maintenance mode.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2p4j-8pc7-8jg8

почти 4 года назад

The vCard functions in Joomla! 1.0.5 use predictable sequential IDs for vcards and do not restrict access to them, which allows remote attackers to obtain valid e-mail addresses to conduct spam attacks by modifying the contact_id parameter to index2.php.

EPSS: Низкий
github логотип

GHSA-2p4j-7hmq-hf5r

5 месяцев назад

A stored cross-site scripting (XSS) vulnerability exists in the WebAuthn Relying Party field within the Datacenter configuration of Proxmox Virtual Environment (PVE) 8.4. Authenticated users can inject JavaScript code that is later executed in the browsers of users who view the configuration page, enabling client-side attacks.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2p4j-3h9f-v3pj

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Red Hat JBoss Enterprise Portal Platform before 5.2.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2p4h-6x4f-47jj

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in David Pokorny Replace Word plugin <= 2.1 versions.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2p4g-jrmx-r34m

больше 3 лет назад

Rancher Login Parameter Can Be Edited

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-2p4f-vc9q-r5vp

больше 1 года назад

Typo3 Arbitrary file upload and XML External Entity processing

EPSS: Низкий
github логотип

GHSA-2p4f-q7g6-g44m

больше 3 лет назад

A code injection vulnerability has been discovered in the Upgrade function of QibosoftX1 v1.0. An attacker is able execute arbitrary PHP code via exploitation of client_upgrade_edition.php and Upgrade.php.

EPSS: Низкий
github логотип

GHSA-2p4f-5m6f-7653

почти 4 года назад

GNU make follows symlinks when it reads a Makefile from stdin, which allows other local users to execute commands.

EPSS: Низкий
github логотип

GHSA-2p49-45hj-7mc9

21 день назад

@backstage/cli-common has a possible `resolveSafeChildPath` Symlink Chain Bypass

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2p48-prhc-qmgx

почти 4 года назад

The connection_state_machine function (connections.c) in lighttpd 1.4.19 and earlier, and 1.5.x before 1.5.0, allows remote attackers to cause a denial of service (active SSL connection loss) by triggering an SSL error, such as disconnecting before a download has finished, which causes all active SSL connections to be lost.

EPSS: Низкий
github логотип

GHSA-2p48-mg67-hr6x

больше 3 лет назад

General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to obtain sensitive cleartext account information via unspecified vectors.

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-2p47-xxcr-5mcp

почти 4 года назад

mmap function in BSD allows local attackers in the kmem group to modify memory through devices.

EPSS: Низкий
github логотип

GHSA-2p47-m3g8-8549

больше 3 лет назад

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-2p46-76mg-wxvh

почти 2 года назад

Information exposure vulnerability in Planet IGS-4215-16T2S, affecting firmware version 1.305b210528. This vulnerability could allow a remote attacker to access some administrative resources due to lack of proper management of the Switch web interface.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-2p45-q6vq-5r25

больше 3 лет назад

Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dReadPsr, Jt3dReadPsr modules in KeyShot Versions v10.1 and prior lack proper validation of user-supplied data when parsing STP files. This could result in a stack-based buffer overflow. An attacker could leverage this vulnerability to execute code in the context of the current process.

EPSS: Низкий
github логотип

GHSA-2p45-j2vr-jcrg

больше 3 лет назад

Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1735, CVE-2015-1740, CVE-2015-1744, and CVE-2015-1745.

EPSS: Средний
github логотип

GHSA-2p45-cjpq-qrf9

больше 3 лет назад

There is an out of bounds write vulnerability in Huawei Smartphone HUAWEI P30 versions 9.1.0.131(C00E130R1P21) when processing a message. An unauthenticated attacker can exploit this vulnerability by sending specific message to the target device. Due to insufficient validation of the input parameter, successful exploit can cause the process and the service to be abnormal.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2p4q-q7j4-q23g

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check BIOS images before it is used BIOS images may fail to load and null checks are added before they are used. This fixes 6 NULL_RETURNS issues reported by Coverity.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2p4q-pg24-pmp6

IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server 5.5 before 5.5.6.1, 6.3 before 6.3.1.5, 6.4 before 6.4.1.7, and 7.1 before 7.1.2; Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server 5.5 before 5.5.1.1, 6.1 before 6.1.3.7, 6.3 before 6.3.1.5, 6.4 before 6.4.1.7, and 7.1 before 7.1.2; and Tivoli Storage FlashCopy Manager 3.1 before 3.1.1.5, 3.2 before 3.2.1.7, and 4.1 before 4.1.2, when application tracing is used, place cleartext passwords in exception messages, which allows physically proximate attackers to obtain sensitive information by reading trace output, a different vulnerability than CVE-2015-4949.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2p4q-mvv4-rjr2

Netbox Community 4.1.7 is vulnerable to Cross Site Scripting (XSS) via the maintenance banner` in maintenance mode.

CVSS3: 7.1
0%
Низкий
8 месяцев назад
github логотип
GHSA-2p4j-8pc7-8jg8

The vCard functions in Joomla! 1.0.5 use predictable sequential IDs for vcards and do not restrict access to them, which allows remote attackers to obtain valid e-mail addresses to conduct spam attacks by modifying the contact_id parameter to index2.php.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2p4j-7hmq-hf5r

A stored cross-site scripting (XSS) vulnerability exists in the WebAuthn Relying Party field within the Datacenter configuration of Proxmox Virtual Environment (PVE) 8.4. Authenticated users can inject JavaScript code that is later executed in the browsers of users who view the configuration page, enabling client-side attacks.

CVSS3: 5.4
0%
Низкий
5 месяцев назад
github логотип
GHSA-2p4j-3h9f-v3pj

Multiple cross-site scripting (XSS) vulnerabilities in Red Hat JBoss Enterprise Portal Platform before 5.2.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2p4h-6x4f-47jj

Cross-Site Request Forgery (CSRF) vulnerability in David Pokorny Replace Word plugin <= 2.1 versions.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2p4g-jrmx-r34m

Rancher Login Parameter Can Be Edited

CVSS3: 4.7
6%
Низкий
больше 3 лет назад
github логотип
GHSA-2p4f-vc9q-r5vp

Typo3 Arbitrary file upload and XML External Entity processing

больше 1 года назад
github логотип
GHSA-2p4f-q7g6-g44m

A code injection vulnerability has been discovered in the Upgrade function of QibosoftX1 v1.0. An attacker is able execute arbitrary PHP code via exploitation of client_upgrade_edition.php and Upgrade.php.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2p4f-5m6f-7653

GNU make follows symlinks when it reads a Makefile from stdin, which allows other local users to execute commands.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2p49-45hj-7mc9

@backstage/cli-common has a possible `resolveSafeChildPath` Symlink Chain Bypass

CVSS3: 6.3
0%
Низкий
21 день назад
github логотип
GHSA-2p48-prhc-qmgx

The connection_state_machine function (connections.c) in lighttpd 1.4.19 and earlier, and 1.5.x before 1.5.0, allows remote attackers to cause a denial of service (active SSL connection loss) by triggering an SSL error, such as disconnecting before a download has finished, which causes all active SSL connections to be lost.

3%
Низкий
почти 4 года назад
github логотип
GHSA-2p48-mg67-hr6x

General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to obtain sensitive cleartext account information via unspecified vectors.

CVSS3: 6.5
19%
Средний
больше 3 лет назад
github логотип
GHSA-2p47-xxcr-5mcp

mmap function in BSD allows local attackers in the kmem group to modify memory through devices.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2p47-m3g8-8549

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to arbitrary code execution.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2p46-76mg-wxvh

Information exposure vulnerability in Planet IGS-4215-16T2S, affecting firmware version 1.305b210528. This vulnerability could allow a remote attacker to access some administrative resources due to lack of proper management of the Switch web interface.

CVSS3: 7.7
0%
Низкий
почти 2 года назад
github логотип
GHSA-2p45-q6vq-5r25

Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dReadPsr, Jt3dReadPsr modules in KeyShot Versions v10.1 and prior lack proper validation of user-supplied data when parsing STP files. This could result in a stack-based buffer overflow. An attacker could leverage this vulnerability to execute code in the context of the current process.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2p45-j2vr-jcrg

Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1735, CVE-2015-1740, CVE-2015-1744, and CVE-2015-1745.

24%
Средний
больше 3 лет назад
github логотип
GHSA-2p45-cjpq-qrf9

There is an out of bounds write vulnerability in Huawei Smartphone HUAWEI P30 versions 9.1.0.131(C00E130R1P21) when processing a message. An unauthenticated attacker can exploit this vulnerability by sending specific message to the target device. Due to insufficient validation of the input parameter, successful exploit can cause the process and the service to be abnormal.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу