Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 691

Количество 314 691

github логотип

GHSA-2mgx-6c3j-cxmq

почти 4 года назад

MUTE 0.4 allows remote attackers to cause a denial of service (messages not forwarded) and obtain sensitive information about a target by filling a client's mWebCache cache with malicious "zombie" nodes.

EPSS: Низкий
github логотип

GHSA-2mgx-226x-8pwv

больше 3 лет назад

AVideo vulnerable to Improper Privilege Management

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2mgw-9wh3-7pf5

больше 3 лет назад

Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to users being able to delete their submitted page through URL manipulation.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2mgw-4f9j-94xj

около 4 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JP2 files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14897.

EPSS: Низкий
github логотип

GHSA-2mgv-chq6-566c

больше 3 лет назад

The System Security Services Daemon (SSSD) 1.11.6 does not properly identify group membership when a non-POSIX group is in a group membership chain, which allows local users to bypass access restrictions via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2mgr-wwxh-g3g7

больше 3 лет назад

SQL injection vulnerability in the RSS page (DNNArticleRSS.aspx) in the ZLDNN DNNArticle module before 10.1 for DotNetNuke allows remote attackers to execute arbitrary SQL commands via the categoryid parameter.

EPSS: Низкий
github логотип

GHSA-2mgr-rf47-4329

около 1 года назад

An attacker authenticated as an administrator can use an exposed webservice to upload or download a custom PDF font file on the system server. Using the upload functionality to copy an internal file into a font file and subsequently using the download functionality to retrieve that file allows the attacker to read any file on the server with no effect on integrity or availability

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-2mgq-r8qg-4f9c

больше 3 лет назад

Vulnerability in the Oracle Retail Xstore Payment component of Oracle Retail Applications (subcomponent: Security). The supported version that is affected is 3.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Payment. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Retail Xstore Payment accessible data as well as unauthorized update, insert or delete access to some of Oracle Retail Xstore Payment accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Retail Xstore Payment. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-2mgp-xj4h-v78w

почти 4 года назад

Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.10.2 have unknown impact and attack vectors related to (a) Advanced Pricing, aka (1) APP01 and (2) APP10; and (b) Applications Framework, aka (3) APP05.

EPSS: Низкий
github логотип

GHSA-2mgp-rv5h-ggjm

больше 3 лет назад

WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1268 and CVE-2014-1269.

EPSS: Низкий
github логотип

GHSA-2mgp-6265-vwf6

больше 3 лет назад

A use-after-free vulnerability can occur while playing a sound notification in Thunderbird. The memory storing the sound data is immediately freed, although the sound is still being played asynchronously, leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 60.5.

EPSS: Низкий
github логотип

GHSA-2mgm-x4fm-vrg8

почти 4 года назад

The Batch::BatchRun module 1.03 for Perl does not properly handle temporary files.

EPSS: Низкий
github логотип

GHSA-2mgm-8w3p-2gr4

больше 3 лет назад

Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

EPSS: Низкий
github логотип

GHSA-2mgm-7frw-wmjm

почти 4 года назад

Argument injection vulnerability involving Microsoft Outlook and Outlook Express, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in an unspecified URI, which are inserted into the command line when invoking the handling process, a similar issue to CVE-2007-3670.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-2mgm-5g5q-v3cw

около 4 лет назад

NetMaster 12.2 Network Management for TCP/IP and NetMaster File Transfer Management contain a XSS (Cross-Site Scripting) vulnerability in ReportCenter UI due to insufficient input validation that could potentially allow an attacker to execute code on the affected machine.

EPSS: Низкий
github логотип

GHSA-2mgj-rr5x-hxrj

почти 2 года назад

Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the doc_number parameter at his_admin_view_single_employee.php.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-2mgj-mwvf-mpg5

почти 4 года назад

Missing permission checks in Jenkins Proxmox Plugin

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2mgh-x98w-w25p

больше 3 лет назад

The Dr. Sheikh Adnan Ibrahim (aka com.amitaff.adnanIbrahim) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-2mgg-5ppq-j685

3 месяца назад

A stack-based buffer overflow vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in the guestSsid parameter of the /goform/WifiGuestSet interface. Remote attackers can exploit this vulnerability by sending oversized data to the guestSsid parameter, leading to denial of service (device crash) or potential remote code execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2mgf-58rr-j7mr

больше 3 лет назад

An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is heap-based buffer overflow in the function ReadGF_IPMPX_WatermarkingInit() in odf/ipmpx_code.c.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2mgx-6c3j-cxmq

MUTE 0.4 allows remote attackers to cause a denial of service (messages not forwarded) and obtain sensitive information about a target by filling a client's mWebCache cache with malicious "zombie" nodes.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2mgx-226x-8pwv

AVideo vulnerable to Improper Privilege Management

CVSS3: 8.8
5%
Низкий
больше 3 лет назад
github логотип
GHSA-2mgw-9wh3-7pf5

Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to users being able to delete their submitted page through URL manipulation.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2mgw-4f9j-94xj

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JP2 files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14897.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2mgv-chq6-566c

The System Security Services Daemon (SSSD) 1.11.6 does not properly identify group membership when a non-POSIX group is in a group membership chain, which allows local users to bypass access restrictions via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2mgr-wwxh-g3g7

SQL injection vulnerability in the RSS page (DNNArticleRSS.aspx) in the ZLDNN DNNArticle module before 10.1 for DotNetNuke allows remote attackers to execute arbitrary SQL commands via the categoryid parameter.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2mgr-rf47-4329

An attacker authenticated as an administrator can use an exposed webservice to upload or download a custom PDF font file on the system server. Using the upload functionality to copy an internal file into a font file and subsequently using the download functionality to retrieve that file allows the attacker to read any file on the server with no effect on integrity or availability

CVSS3: 6.8
0%
Низкий
около 1 года назад
github логотип
GHSA-2mgq-r8qg-4f9c

Vulnerability in the Oracle Retail Xstore Payment component of Oracle Retail Applications (subcomponent: Security). The supported version that is affected is 3.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Payment. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Retail Xstore Payment accessible data as well as unauthorized update, insert or delete access to some of Oracle Retail Xstore Payment accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Retail Xstore Payment. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).

CVSS3: 8.6
2%
Низкий
больше 3 лет назад
github логотип
GHSA-2mgp-xj4h-v78w

Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.10.2 have unknown impact and attack vectors related to (a) Advanced Pricing, aka (1) APP01 and (2) APP10; and (b) Applications Framework, aka (3) APP05.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2mgp-rv5h-ggjm

WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1268 and CVE-2014-1269.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2mgp-6265-vwf6

A use-after-free vulnerability can occur while playing a sound notification in Thunderbird. The memory storing the sound data is immediately freed, although the sound is still being played asynchronously, leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 60.5.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2mgm-x4fm-vrg8

The Batch::BatchRun module 1.03 for Perl does not properly handle temporary files.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2mgm-8w3p-2gr4

Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

3%
Низкий
больше 3 лет назад
github логотип
GHSA-2mgm-7frw-wmjm

Argument injection vulnerability involving Microsoft Outlook and Outlook Express, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in an unspecified URI, which are inserted into the command line when invoking the handling process, a similar issue to CVE-2007-3670.

CVSS3: 8.8
17%
Средний
почти 4 года назад
github логотип
GHSA-2mgm-5g5q-v3cw

NetMaster 12.2 Network Management for TCP/IP and NetMaster File Transfer Management contain a XSS (Cross-Site Scripting) vulnerability in ReportCenter UI due to insufficient input validation that could potentially allow an attacker to execute code on the affected machine.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2mgj-rr5x-hxrj

Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the doc_number parameter at his_admin_view_single_employee.php.

CVSS3: 2.7
0%
Низкий
почти 2 года назад
github логотип
GHSA-2mgj-mwvf-mpg5

Missing permission checks in Jenkins Proxmox Plugin

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-2mgh-x98w-w25p

The Dr. Sheikh Adnan Ibrahim (aka com.amitaff.adnanIbrahim) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2mgg-5ppq-j685

A stack-based buffer overflow vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in the guestSsid parameter of the /goform/WifiGuestSet interface. Remote attackers can exploit this vulnerability by sending oversized data to the guestSsid parameter, leading to denial of service (device crash) or potential remote code execution.

CVSS3: 8.8
0%
Низкий
3 месяца назад
github логотип
GHSA-2mgf-58rr-j7mr

An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is heap-based buffer overflow in the function ReadGF_IPMPX_WatermarkingInit() in odf/ipmpx_code.c.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу