Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 691

Количество 314 691

github логотип

GHSA-2mcp-f38w-p5gf

больше 1 года назад

A logic bug in the code which disables kernel tracing for setuid programs meant that tracing was not disabled when it should have, allowing unprivileged users to trace and inspect the behavior of setuid programs. The bug may be used by an unprivileged user to read the contents of files to which they would not otherwise have access, such as the local password database.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2mcm-79hx-8fxw

7 дней назад

Django has Observable Timing Discrepancy

EPSS: Низкий
github логотип

GHSA-2mcj-95w7-7458

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RaminMT Links/Problem Reporter allows DOM-Based XSS.This issue affects Links/Problem Reporter: from n/a through 2.6.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2mcj-3r3r-v5wm

больше 3 лет назад

phpMyAdmin DoS Vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2mch-v567-5x6m

почти 4 года назад

Multiple unspecified vulnerabilities in Cryptocat Project Cryptocat 2.0.18 have unknown impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-2mch-fwv9-f98h

больше 3 лет назад

bit2spr 1992-06-07 has a stack-based buffer overflow (129-byte write) in conv_bitmap in bit2spr.c via a long line in a bitmap file.

EPSS: Низкий
github логотип

GHSA-2mcf-r7v5-r97j

больше 3 лет назад

Heap-based buffer overflow in the color_cmyk_to_rgb in common/color.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (crash) via a crafted .j2k file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2mcf-6v63-37m2

почти 4 года назад

SQL injection vulnerability in the Jom Comment 2.0 build 345 component for Joomla! allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-2mcc-mpmm-5889

почти 4 года назад

Argument injection vulnerability in the URI handler in Skype 2.0.*.104 and 2.5.*.0 through 2.5.*.78 for Windows allows remote authorized attackers to download arbitrary files via a URL that contains certain command-line switches.

EPSS: Низкий
github логотип

GHSA-2mcc-j5ch-qfx2

больше 3 лет назад

Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 10. Easily exploitable vulnerability allows unauthenticated attacker with network access via ICMP to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Solaris. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2mcc-4f9v-m34r

около 3 лет назад

Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-44670.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2mc9-wh89-6q44

больше 3 лет назад

On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.3, 12.1.0-12.1.3.7, and 11.6.0-11.6.3.2, a reflected Cross Site Scripting (XSS) vulnerability is present in an undisclosed page of the BIG-IP TMUI (Traffic Management User Interface) also known as the BIG-IP configuration utility.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2mc9-cvxq-r2xq

больше 3 лет назад

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, macOS Big Sur 11.0.1. A malicious application may be able to access private information.

EPSS: Низкий
github логотип

GHSA-2mc8-x568-88x3

около 3 лет назад

The External Media WordPress plugin before 1.0.36 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2mc7-7977-x6p5

больше 3 лет назад

Samsung Kies Air 2.1.207051 and 2.1.210161 allows remote attackers to cause a denial of service (crash) via a crafted request to www/apps/KiesAir/jws/ssd.php.

EPSS: Низкий
github логотип

GHSA-2mc6-x8h4-86rp

больше 3 лет назад

ConfBridge in Asterisk 11.x before 11.14.1 and Certified Asterisk 11.6 before 11.6-cert8 does not properly handle state changes, which allows remote attackers to cause a denial of service (channel hang and memory consumption) by causing transitions to be delayed, which triggers a state change from hung up to waiting for media.

EPSS: Низкий
github логотип

GHSA-2mc6-hfwx-q7vw

больше 3 лет назад

Winlogbeat versions before 5.6.16 and 6.6.2 had an insufficient logging flaw. An attacker able to inject certain characters into a log entry could prevent Winlogbeat from recording the event.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2mc5-3c8c-rg8r

6 месяцев назад

Exposure of sensitive information to an unauthorized actor in Storage Port Driver allows an authorized attacker to disclose information locally.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2mc4-vj63-6xf2

11 месяцев назад

A vulnerability, which was classified as critical, was found in PHPGurukul Boat Booking System 1.0. Affected is an unknown function of the file /boat-details.php. The manipulation of the argument bid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2mc4-f3f5-xmwp

больше 2 лет назад

A vulnerability was found in YFCMF up to 3.0.4. It has been rated as problematic. This issue affects some unknown processing of the file app/admin/controller/Ajax.php. The manipulation of the argument controllername leads to path traversal: '../filedir'. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-230543.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2mcp-f38w-p5gf

A logic bug in the code which disables kernel tracing for setuid programs meant that tracing was not disabled when it should have, allowing unprivileged users to trace and inspect the behavior of setuid programs. The bug may be used by an unprivileged user to read the contents of files to which they would not otherwise have access, such as the local password database.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2mcm-79hx-8fxw

Django has Observable Timing Discrepancy

0%
Низкий
7 дней назад
github логотип
GHSA-2mcj-95w7-7458

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RaminMT Links/Problem Reporter allows DOM-Based XSS.This issue affects Links/Problem Reporter: from n/a through 2.6.0.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2mcj-3r3r-v5wm

phpMyAdmin DoS Vulnerability

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2mch-v567-5x6m

Multiple unspecified vulnerabilities in Cryptocat Project Cryptocat 2.0.18 have unknown impact and attack vectors.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2mch-fwv9-f98h

bit2spr 1992-06-07 has a stack-based buffer overflow (129-byte write) in conv_bitmap in bit2spr.c via a long line in a bitmap file.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2mcf-r7v5-r97j

Heap-based buffer overflow in the color_cmyk_to_rgb in common/color.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (crash) via a crafted .j2k file.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2mcf-6v63-37m2

SQL injection vulnerability in the Jom Comment 2.0 build 345 component for Joomla! allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2mcc-mpmm-5889

Argument injection vulnerability in the URI handler in Skype 2.0.*.104 and 2.5.*.0 through 2.5.*.78 for Windows allows remote authorized attackers to download arbitrary files via a URL that contains certain command-line switches.

4%
Низкий
почти 4 года назад
github логотип
GHSA-2mcc-j5ch-qfx2

Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 10. Easily exploitable vulnerability allows unauthenticated attacker with network access via ICMP to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Solaris. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 7.5
6%
Низкий
больше 3 лет назад
github логотип
GHSA-2mcc-4f9v-m34r

Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-44670.

CVSS3: 8.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-2mc9-wh89-6q44

On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.3, 12.1.0-12.1.3.7, and 11.6.0-11.6.3.2, a reflected Cross Site Scripting (XSS) vulnerability is present in an undisclosed page of the BIG-IP TMUI (Traffic Management User Interface) also known as the BIG-IP configuration utility.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2mc9-cvxq-r2xq

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, macOS Big Sur 11.0.1. A malicious application may be able to access private information.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2mc8-x568-88x3

The External Media WordPress plugin before 1.0.36 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 4.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-2mc7-7977-x6p5

Samsung Kies Air 2.1.207051 and 2.1.210161 allows remote attackers to cause a denial of service (crash) via a crafted request to www/apps/KiesAir/jws/ssd.php.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2mc6-x8h4-86rp

ConfBridge in Asterisk 11.x before 11.14.1 and Certified Asterisk 11.6 before 11.6-cert8 does not properly handle state changes, which allows remote attackers to cause a denial of service (channel hang and memory consumption) by causing transitions to be delayed, which triggers a state change from hung up to waiting for media.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-2mc6-hfwx-q7vw

Winlogbeat versions before 5.6.16 and 6.6.2 had an insufficient logging flaw. An attacker able to inject certain characters into a log entry could prevent Winlogbeat from recording the event.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2mc5-3c8c-rg8r

Exposure of sensitive information to an unauthorized actor in Storage Port Driver allows an authorized attacker to disclose information locally.

CVSS3: 5.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-2mc4-vj63-6xf2

A vulnerability, which was classified as critical, was found in PHPGurukul Boat Booking System 1.0. Affected is an unknown function of the file /boat-details.php. The manipulation of the argument bid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-2mc4-f3f5-xmwp

A vulnerability was found in YFCMF up to 3.0.4. It has been rated as problematic. This issue affects some unknown processing of the file app/admin/controller/Ajax.php. The manipulation of the argument controllername leads to path traversal: '../filedir'. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-230543.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу