Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2jx3-m5vv-rvc6

почти 4 года назад

Stack-based buffer overflow in Far Manager 1.70beta1 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long pathname.

EPSS: Низкий
github логотип

GHSA-2jx3-fx5f-r2c6

больше 2 лет назад

FFmpeg discovered to contain a code injection vulnerability in the component net.bramp.ffmpeg.FFmpeg.<constructor>

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2jx3-5j9v-prpp

больше 3 лет назад

BlockWishList SQL Injection vulnerability

CVSS3: 8.1
EPSS: Средний
github логотип

GHSA-2jx2-x46f-wj52

10 месяцев назад

**UNSUPPORTED WHEN ASSIGNED** A path traversal vulnerability in the web management interface of the Zyxel AMG1302-T10B firmware version 2.00(AAJC.16)C0 could allow an authenticated attacker with administrator privileges to access restricted directories by sending a crafted HTTP request to an affected device.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-2jx2-r7f9-93pw

около 2 лет назад

Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.2.9.0 and earlier versions. If this vulnerability is exploited, a user with a contributor or higher privilege may execute an arbitrary script on the web browser of the user who accessed the website using the product.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2jx2-qcm4-rf9h

больше 2 лет назад

Incomplete Internal State Distinction in GRPCWebToHTTP2ServerCodec

EPSS: Низкий
github логотип

GHSA-2jx2-cgj2-48wc

9 месяцев назад

Lantronix Device installer is vulnerable to XML external entity (XXE) attacks in configuration files read from the network device. An attacker could obtain credentials, access these network devices, and modify their configurations. An attacker may also gain access to the host running the Device Installer software or the password hash of the user running the application.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-2jx2-7jpf-5pr4

около 1 месяца назад

In the Linux kernel, the following vulnerability has been resolved: pinctrl: at91-pio4: check return value of devm_kasprintf() devm_kasprintf() returns a pointer to dynamically allocated memory. Pointer could be NULL in case allocation fails. Check pointer validity. Identified with coccinelle (kmerr.cocci script). Depends-on: 1c4e5c470a56 ("pinctrl: at91: use devm_kasprintf() to avoid potential leaks") Depends-on: 5a8f9cf269e8 ("pinctrl: at91-pio4: use proper format specifier for unsigned int")

EPSS: Низкий
github логотип

GHSA-2jx2-76rc-2v7v

больше 4 лет назад

Kubernetes Privilege Escalation

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2jx2-275x-4xpq

больше 3 лет назад

Multiple off-by-one errors in the (1) token and (2) linetoken functions in backend/dvi/mdvi-lib/afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a DVI file containing a crafted Adobe Font Metrics (AFM) file, different vulnerabilities than CVE-2010-2642 and CVE-2011-0433.

EPSS: Низкий
github логотип

GHSA-2jwx-73fx-pwrv

около 2 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have, under certain circumstances, allowed an unauthenticated user to perform unauthorized actions on behalf of another user by injecting malicious external scripts into the Swagger UI."

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-2jww-vv25-vx2m

больше 3 лет назад

Unspecified vulnerability in the Oracle Retail MICROS C2 component in Oracle Retail Applications 9.89.0.0 allows local users to affect confidentiality via vectors related to POS.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2jww-8ppq-f5qp

больше 3 лет назад

A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The root_runner.64 binary is setuid root. This binary executes /opt/pia/ruby/64/ruby, which in turn attempts to load several libraries under /tmp/ruby-deploy.old/lib. A local unprivileged user can create a malicious library under this path to execute arbitrary code as the root user.

EPSS: Низкий
github логотип

GHSA-2jwv-jmq4-4j3r

почти 2 года назад

A malformed DNS message in response to a query can cause the Lookup functions to get stuck in an infinite loop.

EPSS: Низкий
github логотип

GHSA-2jwv-3p8q-v273

11 месяцев назад

Missing Authorization vulnerability in NotFound Interactive Page Hierarchy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Interactive Page Hierarchy: from n/a through 1.0.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2jwr-cm84-p3w4

больше 3 лет назад

An elevation of privilege vulnerability exists when the Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Elevation of Privilege Vulnerability'.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-2jwr-937v-hx6p

больше 1 года назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro allows PHP Local File Inclusion.This issue affects ListingPro: from n/a through 2.9.3.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-2jwq-w78h-4r89

больше 1 года назад

HaloITSM versions up to 2.146.1 are affected by a SAML XML Signature Wrapping (XSW) vulnerability. When having a SAML integration configured, anonymous actors could impersonate arbitrary HaloITSM users by just knowing their email address. HaloITSM versions past 2.146.1 (and patches starting from 2.143.61 ) fix the mentioned vulnerability.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2jwq-w43x-63xx

больше 3 лет назад

Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomponent: WebConnect). Supported versions that are affected are 8.10.1 and 8.10.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Suite8. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hospitality Suite8, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hospitality Suite8 accessible data. CVSS 3.0 Base Score 4.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N).

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-2jwp-fqrg-7h5j

больше 3 лет назад

Memory leak in the SNMP module in Cisco IOS XR allows remote authenticated users to cause a denial of service (memory consumption and process restart) via crafted SNMP packets, aka Bug ID CSCue31546.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2jx3-m5vv-rvc6

Stack-based buffer overflow in Far Manager 1.70beta1 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long pathname.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2jx3-fx5f-r2c6

FFmpeg discovered to contain a code injection vulnerability in the component net.bramp.ffmpeg.FFmpeg.<constructor>

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2jx3-5j9v-prpp

BlockWishList SQL Injection vulnerability

CVSS3: 8.1
30%
Средний
больше 3 лет назад
github логотип
GHSA-2jx2-x46f-wj52

**UNSUPPORTED WHEN ASSIGNED** A path traversal vulnerability in the web management interface of the Zyxel AMG1302-T10B firmware version 2.00(AAJC.16)C0 could allow an authenticated attacker with administrator privileges to access restricted directories by sending a crafted HTTP request to an affected device.

CVSS3: 4.9
1%
Низкий
10 месяцев назад
github логотип
GHSA-2jx2-r7f9-93pw

Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.2.9.0 and earlier versions. If this vulnerability is exploited, a user with a contributor or higher privilege may execute an arbitrary script on the web browser of the user who accessed the website using the product.

CVSS3: 5.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-2jx2-qcm4-rf9h

Incomplete Internal State Distinction in GRPCWebToHTTP2ServerCodec

1%
Низкий
больше 2 лет назад
github логотип
GHSA-2jx2-cgj2-48wc

Lantronix Device installer is vulnerable to XML external entity (XXE) attacks in configuration files read from the network device. An attacker could obtain credentials, access these network devices, and modify their configurations. An attacker may also gain access to the host running the Device Installer software or the password hash of the user running the application.

CVSS3: 6.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-2jx2-7jpf-5pr4

In the Linux kernel, the following vulnerability has been resolved: pinctrl: at91-pio4: check return value of devm_kasprintf() devm_kasprintf() returns a pointer to dynamically allocated memory. Pointer could be NULL in case allocation fails. Check pointer validity. Identified with coccinelle (kmerr.cocci script). Depends-on: 1c4e5c470a56 ("pinctrl: at91: use devm_kasprintf() to avoid potential leaks") Depends-on: 5a8f9cf269e8 ("pinctrl: at91-pio4: use proper format specifier for unsigned int")

0%
Низкий
около 1 месяца назад
github логотип
GHSA-2jx2-76rc-2v7v

Kubernetes Privilege Escalation

CVSS3: 9.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-2jx2-275x-4xpq

Multiple off-by-one errors in the (1) token and (2) linetoken functions in backend/dvi/mdvi-lib/afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a DVI file containing a crafted Adobe Font Metrics (AFM) file, different vulnerabilities than CVE-2010-2642 and CVE-2011-0433.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-2jwx-73fx-pwrv

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have, under certain circumstances, allowed an unauthenticated user to perform unauthorized actions on behalf of another user by injecting malicious external scripts into the Swagger UI."

CVSS3: 8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2jww-vv25-vx2m

Unspecified vulnerability in the Oracle Retail MICROS C2 component in Oracle Retail Applications 9.89.0.0 allows local users to affect confidentiality via vectors related to POS.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2jww-8ppq-f5qp

A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The root_runner.64 binary is setuid root. This binary executes /opt/pia/ruby/64/ruby, which in turn attempts to load several libraries under /tmp/ruby-deploy.old/lib. A local unprivileged user can create a malicious library under this path to execute arbitrary code as the root user.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2jwv-jmq4-4j3r

A malformed DNS message in response to a query can cause the Lookup functions to get stuck in an infinite loop.

0%
Низкий
почти 2 года назад
github логотип
GHSA-2jwv-3p8q-v273

Missing Authorization vulnerability in NotFound Interactive Page Hierarchy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Interactive Page Hierarchy: from n/a through 1.0.1.

CVSS3: 6.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-2jwr-cm84-p3w4

An elevation of privilege vulnerability exists when the Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Elevation of Privilege Vulnerability'.

CVSS3: 6.6
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2jwr-937v-hx6p

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro allows PHP Local File Inclusion.This issue affects ListingPro: from n/a through 2.9.3.

CVSS3: 8
1%
Низкий
больше 1 года назад
github логотип
GHSA-2jwq-w78h-4r89

HaloITSM versions up to 2.146.1 are affected by a SAML XML Signature Wrapping (XSW) vulnerability. When having a SAML integration configured, anonymous actors could impersonate arbitrary HaloITSM users by just knowing their email address. HaloITSM versions past 2.146.1 (and patches starting from 2.143.61 ) fix the mentioned vulnerability.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-2jwq-w43x-63xx

Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomponent: WebConnect). Supported versions that are affected are 8.10.1 and 8.10.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Suite8. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hospitality Suite8, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Hospitality Suite8 accessible data. CVSS 3.0 Base Score 4.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N).

CVSS3: 4.7
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2jwp-fqrg-7h5j

Memory leak in the SNMP module in Cisco IOS XR allows remote authenticated users to cause a denial of service (memory consumption and process restart) via crafted SNMP packets, aka Bug ID CSCue31546.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу