Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 306 694

Количество 306 694

github логотип

GHSA-24w2-9p3v-m489

почти 3 года назад

A vulnerability classified as critical has been found in Netis Netcore Router. This affects an unknown part. The manipulation leads to use of hard-coded password. It is possible to initiate the attack remotely. The identifier VDB-217593 was assigned to this vulnerability.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-24vx-3r2r-h4mc

больше 3 лет назад

rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

EPSS: Критический
github логотип

GHSA-24vx-27hc-7h4h

больше 1 года назад

A potential security vulnerability has been identified in VSS Provider and CAPI Proxy software for certain HPE MSA storage products. This vulnerability could be exploited to gain elevated privilege on the system.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-24vw-fq64-647q

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix memory leak in mlx5_core_destroy_cq() error path Prior to this patch in case mlx5_core_destroy_cq() failed it returns without completing all destroy operations and that leads to memory leak. Instead, complete the destroy flow before return error. Also move mlx5_debug_cq_remove() to the beginning of mlx5_core_destroy_cq() to be symmetrical with mlx5_core_create_cq(). kmemleak complains on: unreferenced object 0xc000000038625100 (size 64): comm "ethtool", pid 28301, jiffies 4298062946 (age 785.380s) hex dump (first 32 bytes): 60 01 48 94 00 00 00 c0 b8 05 34 c3 00 00 00 c0 `.H.......4..... 02 00 00 00 00 00 00 00 00 db 7d c1 00 00 00 c0 ..........}..... backtrace: [<000000009e8643cb>] add_res_tree+0xd0/0x270 [mlx5_core] [<00000000e7cb8e6c>] mlx5_debug_cq_add+0x5c/0xc0 [mlx5_core] [<000000002a12918f>] mlx5_core_create_cq+0x1d0/0x2d0 [mlx5_core] [<00000000cef0a696>] ml...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-24vv-fh33-8gqp

больше 1 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BestWebSoft Contact Form to DB by BestWebSoft.This issue affects Contact Form to DB by BestWebSoft: from n/a through 1.7.2.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-24vr-m38m-hw6f

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: net: macsec: Fix offload support for NETDEV_UNREGISTER event Current macsec netdev notify handler handles NETDEV_UNREGISTER event by releasing relevant SW resources only, this causes resources leak in case of macsec HW offload, as the underlay driver was not notified to clean it's macsec offload resources. Fix by calling the underlay driver to clean it's relevant resources by moving offload handling from macsec_dellink() to macsec_common_dellink() when handling NETDEV_UNREGISTER event.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-24vr-fq5x-chmc

больше 3 лет назад

Stack-based buffer overflow in the IMAP service in Mercur Messaging 5.0 SP3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long string to the (1) LOGIN or (2) SELECT command, a different set of attack vectors and possibly a different vulnerability than CVE-2003-1177.

EPSS: Высокий
github логотип

GHSA-24vq-mf2r-c557

больше 2 лет назад

A cross-site scripting (XSS) vulnerability in Maid Hiring Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter of the /admin/contactus.php component.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-24vq-hqp2-48h9

больше 3 лет назад

Unspecified vulnerability in the Oracle Hyperion Smart View for Office component in Oracle Hyperion 11.1.2.5.216 and earlier, when running on Windows, allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core.

EPSS: Низкий
github логотип

GHSA-24vq-74h7-jvmq

больше 3 лет назад

The Ericsson-LG iPECS NMS A.1Ac web application discloses sensitive information such as the NMS admin credentials and the PostgreSQL database credentials to logged-in users via the responses to certain HTTP POST requests. In order to be able to see the credentials in cleartext, an attacker needs to be authenticated.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-24vp-v896-cq3c

больше 3 лет назад

In mruby 2.1.0, there is a stack-based buffer overflow in mrb_str_len_to_dbl in string.c.

EPSS: Низкий
github логотип

GHSA-24vm-48r8-7jq6

10 месяцев назад

While processing the authentication message in UE, improper authentication may lead to information disclosure.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-24vj-7479-5mqc

больше 3 лет назад

IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 218281.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-24vj-6vgj-xpcx

около 3 лет назад

The d8s-xml package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-html package. The affected version is 0.1.0.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-24vh-7f72-gr9q

больше 3 лет назад

NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

EPSS: Низкий
github логотип

GHSA-24vh-6wx3-73cw

6 месяцев назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий
github логотип

GHSA-24vh-3994-4wxm

около 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Mario Spinaci UPDATE NOTIFICATIONS allows Stored XSS.This issue affects UPDATE NOTIFICATIONS: from n/a through 0.3.4.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-24vg-fhqp-9wrx

больше 3 лет назад

The compat_alloc_user_space functions in include/asm/compat.h files in the Linux kernel before 2.6.36-rc4-git2 on 64-bit platforms do not properly allocate the userspace memory required for the 32-bit compatibility layer, which allows local users to gain privileges by leveraging the ability of the compat_mc_getsockopt function (aka the MCAST_MSFILTER getsockopt support) to control a certain length value, related to a "stack pointer underflow" issue, as exploited in the wild in September 2010.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-24vg-8cmx-c7xr

больше 1 года назад

Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through S3 Accounts (/admin/CloudAccounts). Exploitation of this vulnerability could allow a remote user to execute arbitrary code.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-24vf-v4v3-xgmr

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: uprobes: fix kernel info leak via "[uprobes]" vma xol_add_vma() maps the uninitialized page allocated by __create_xol_area() into userspace. On some architectures (x86) this memory is readable even without VM_READ, VM_EXEC results in the same pgprot_t as VM_EXEC|VM_READ, although this doesn't really matter, debugger can read this memory anyway.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-24w2-9p3v-m489

A vulnerability classified as critical has been found in Netis Netcore Router. This affects an unknown part. The manipulation leads to use of hard-coded password. It is possible to initiate the attack remotely. The identifier VDB-217593 was assigned to this vulnerability.

CVSS3: 9.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-24vx-3r2r-h4mc

rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

93%
Критический
больше 3 лет назад
github логотип
GHSA-24vx-27hc-7h4h

A potential security vulnerability has been identified in VSS Provider and CAPI Proxy software for certain HPE MSA storage products. This vulnerability could be exploited to gain elevated privilege on the system.

CVSS3: 7.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-24vw-fq64-647q

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix memory leak in mlx5_core_destroy_cq() error path Prior to this patch in case mlx5_core_destroy_cq() failed it returns without completing all destroy operations and that leads to memory leak. Instead, complete the destroy flow before return error. Also move mlx5_debug_cq_remove() to the beginning of mlx5_core_destroy_cq() to be symmetrical with mlx5_core_create_cq(). kmemleak complains on: unreferenced object 0xc000000038625100 (size 64): comm "ethtool", pid 28301, jiffies 4298062946 (age 785.380s) hex dump (first 32 bytes): 60 01 48 94 00 00 00 c0 b8 05 34 c3 00 00 00 c0 `.H.......4..... 02 00 00 00 00 00 00 00 00 db 7d c1 00 00 00 c0 ..........}..... backtrace: [<000000009e8643cb>] add_res_tree+0xd0/0x270 [mlx5_core] [<00000000e7cb8e6c>] mlx5_debug_cq_add+0x5c/0xc0 [mlx5_core] [<000000002a12918f>] mlx5_core_create_cq+0x1d0/0x2d0 [mlx5_core] [<00000000cef0a696>] ml...

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-24vv-fh33-8gqp

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BestWebSoft Contact Form to DB by BestWebSoft.This issue affects Contact Form to DB by BestWebSoft: from n/a through 1.7.2.

CVSS3: 8.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-24vr-m38m-hw6f

In the Linux kernel, the following vulnerability has been resolved: net: macsec: Fix offload support for NETDEV_UNREGISTER event Current macsec netdev notify handler handles NETDEV_UNREGISTER event by releasing relevant SW resources only, this causes resources leak in case of macsec HW offload, as the underlay driver was not notified to clean it's macsec offload resources. Fix by calling the underlay driver to clean it's relevant resources by moving offload handling from macsec_dellink() to macsec_common_dellink() when handling NETDEV_UNREGISTER event.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-24vr-fq5x-chmc

Stack-based buffer overflow in the IMAP service in Mercur Messaging 5.0 SP3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long string to the (1) LOGIN or (2) SELECT command, a different set of attack vectors and possibly a different vulnerability than CVE-2003-1177.

87%
Высокий
больше 3 лет назад
github логотип
GHSA-24vq-mf2r-c557

A cross-site scripting (XSS) vulnerability in Maid Hiring Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter of the /admin/contactus.php component.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-24vq-hqp2-48h9

Unspecified vulnerability in the Oracle Hyperion Smart View for Office component in Oracle Hyperion 11.1.2.5.216 and earlier, when running on Windows, allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-24vq-74h7-jvmq

The Ericsson-LG iPECS NMS A.1Ac web application discloses sensitive information such as the NMS admin credentials and the PostgreSQL database credentials to logged-in users via the responses to certain HTTP POST requests. In order to be able to see the credentials in cleartext, an attacker needs to be authenticated.

CVSS3: 8.8
4%
Низкий
больше 3 лет назад
github логотип
GHSA-24vp-v896-cq3c

In mruby 2.1.0, there is a stack-based buffer overflow in mrb_str_len_to_dbl in string.c.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-24vm-48r8-7jq6

While processing the authentication message in UE, improper authentication may lead to information disclosure.

CVSS3: 5.4
0%
Низкий
10 месяцев назад
github логотип
GHSA-24vj-7479-5mqc

IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 218281.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-24vj-6vgj-xpcx

The d8s-xml package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-html package. The affected version is 0.1.0.

CVSS3: 9.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-24vh-7f72-gr9q

NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-24vh-6wx3-73cw

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

6 месяцев назад
github логотип
GHSA-24vh-3994-4wxm

Cross-Site Request Forgery (CSRF) vulnerability in Mario Spinaci UPDATE NOTIFICATIONS allows Stored XSS.This issue affects UPDATE NOTIFICATIONS: from n/a through 0.3.4.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-24vg-fhqp-9wrx

The compat_alloc_user_space functions in include/asm/compat.h files in the Linux kernel before 2.6.36-rc4-git2 on 64-bit platforms do not properly allocate the userspace memory required for the 32-bit compatibility layer, which allows local users to gain privileges by leveraging the ability of the compat_mc_getsockopt function (aka the MCAST_MSFILTER getsockopt support) to control a certain length value, related to a "stack pointer underflow" issue, as exploited in the wild in September 2010.

CVSS3: 7.8
9%
Низкий
больше 3 лет назад
github логотип
GHSA-24vg-8cmx-c7xr

Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through S3 Accounts (/admin/CloudAccounts). Exploitation of this vulnerability could allow a remote user to execute arbitrary code.

CVSS3: 6.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-24vf-v4v3-xgmr

In the Linux kernel, the following vulnerability has been resolved: uprobes: fix kernel info leak via "[uprobes]" vma xol_add_vma() maps the uninitialized page allocated by __create_xol_area() into userspace. On some architectures (x86) this memory is readable even without VM_READ, VM_EXEC results in the same pgprot_t as VM_EXEC|VM_READ, although this doesn't really matter, debugger can read this memory anyway.

CVSS3: 5.5
0%
Низкий
около 1 года назад

Уязвимостей на страницу