Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-2g5f-4p47-mx3m

11 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: nvmem: core: fix cleanup after dev_set_name() If dev_set_name() fails, we leak nvmem->wp_gpio as the cleanup does not put this. While a minimal fix for this would be to add the gpiod_put() call, we can do better if we split device_register(), and use the tested nvmem_release() cleanup code by initialising the device early, and putting the device. This results in a slightly larger fix, but results in clear code. Note: this patch depends on "nvmem: core: initialise nvmem->id early" and "nvmem: core: remove nvmem_config wp_gpio". [Srini: Fixed subject line and error code handing with wp_gpio while applying.]

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2g5c-228j-p52x

больше 3 лет назад

XWiki Platform Applications Tag and XWiki Platform Tag UI vulnerable to Eval Injection

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-2g59-pjjw-j55p

больше 3 лет назад

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, an authenticated attacker (via the admin web interface) can send a specially crafted message resulting in a stack buffer overflow.

CVSS3: 7.2
EPSS: Средний
github логотип

GHSA-2g59-m95p-pgfq

18 дней назад

Chainlit contain a server-side request forgery (SSRF) vulnerability

EPSS: Низкий
github логотип

GHSA-2g58-j9wc-pg3h

больше 3 лет назад

The Passcode Lock implementation in Apple iOS before 6.0.1 does not properly manage the lock state, which allows physically proximate attackers to bypass an intended passcode requirement and access Passbook passes via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2g58-2x39-qh45

больше 1 года назад

OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2g58-2r94-f674

больше 1 года назад

A vulnerability classified as problematic was found in itsourcecode Online Blood Bank Management System 1.0. This vulnerability affects unknown code of the file signup.php of the component User Registration Handler. The manipulation of the argument user leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273232.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2g56-8jc9-jg87

5 месяцев назад

In validateUriSchemeAndPermission of DisclaimersParserImpl.java , there is a possible way to access data from another user due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2g56-7jv7-wxxq

больше 3 лет назад

Missing Cryptographic Step in OWASP Enterprise Security API for Java

EPSS: Низкий
github логотип

GHSA-2g55-8gcv-fc24

5 месяцев назад

Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2g55-8535-gp6f

около 2 лет назад

Splicecom Maximiser Soft PBX v1.5 and before was discovered to contain a cross-site scripting (XSS) vulnerability via the CLIENT_NAME and DEVICE_GUID fields in the login component.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2g55-7wqw-h2c5

больше 3 лет назад

Heap-based buffer overflow in the __zzip_get32 function in fetch.c in zziplib 0.13.62, 0.13.61, 0.13.60, 0.13.59, 0.13.58, 0.13.57, 0.13.56 allows remote attackers to cause a denial of service (crash) via a crafted ZIP file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2g54-42rw-p43x

больше 3 лет назад

The specific function in ASUS BMC’s firmware Web management page (Modify user’s information function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

EPSS: Низкий
github логотип

GHSA-2g53-pmw3-ccp9

больше 3 лет назад

CheckSec Canopy 3.x before 3.0.7 has stored XSS via the Login Page Disclaimer, allowing attacks by low-privileged users against higher-privileged users.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2g53-3pj8-qvxv

больше 3 лет назад

Use-after-free vulnerability in the path_openat function in fs/namei.c in the Linux kernel 3.x and 4.x before 4.0.4 allows local users to cause a denial of service or possibly have unspecified other impact via O_TMPFILE filesystem operations that leverage a duplicate cleanup operation.

EPSS: Низкий
github логотип

GHSA-2g52-qw8q-wfr9

около 1 года назад

Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed. This vulnerability affects Firefox < 134.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-2g4x-xxrm-h5mw

больше 3 лет назад

Dell Encryption (formerly Dell Data Protection | Encryption) v10.1.0 and earlier contain an information disclosure vulnerability. A malicious user with physical access to the machine could potentially exploit this vulnerability to access the unencrypted RegBack folder that contains back-ups of sensitive system files.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2g4x-p9qv-phcg

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Gallery 3 before 3.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) movie title to modules/gallery/controllers/movies.php or (2) key variable to modules/gallery/views/error_admin.html.php.

EPSS: Низкий
github логотип

GHSA-2g4x-fv7q-8jrf

больше 3 лет назад

Insufficient data validation in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.

EPSS: Низкий
github логотип

GHSA-2g4x-3mj5-gvj6

почти 4 года назад

Multiple buffer overflows in the Broderbund Expressit 3DGreetings Player ActiveX control could allow remote attackers to execute arbitrary code via unspecified vectors.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2g5f-4p47-mx3m

In the Linux kernel, the following vulnerability has been resolved: nvmem: core: fix cleanup after dev_set_name() If dev_set_name() fails, we leak nvmem->wp_gpio as the cleanup does not put this. While a minimal fix for this would be to add the gpiod_put() call, we can do better if we split device_register(), and use the tested nvmem_release() cleanup code by initialising the device early, and putting the device. This results in a slightly larger fix, but results in clear code. Note: this patch depends on "nvmem: core: initialise nvmem->id early" and "nvmem: core: remove nvmem_config wp_gpio". [Srini: Fixed subject line and error code handing with wp_gpio while applying.]

CVSS3: 5.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-2g5c-228j-p52x

XWiki Platform Applications Tag and XWiki Platform Tag UI vulnerable to Eval Injection

CVSS3: 9.9
8%
Низкий
больше 3 лет назад
github логотип
GHSA-2g59-pjjw-j55p

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, an authenticated attacker (via the admin web interface) can send a specially crafted message resulting in a stack buffer overflow.

CVSS3: 7.2
49%
Средний
больше 3 лет назад
github логотип
GHSA-2g59-m95p-pgfq

Chainlit contain a server-side request forgery (SSRF) vulnerability

0%
Низкий
18 дней назад
github логотип
GHSA-2g58-j9wc-pg3h

The Passcode Lock implementation in Apple iOS before 6.0.1 does not properly manage the lock state, which allows physically proximate attackers to bypass an intended passcode requirement and access Passbook passes via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2g58-2x39-qh45

OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function.

CVSS3: 9.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2g58-2r94-f674

A vulnerability classified as problematic was found in itsourcecode Online Blood Bank Management System 1.0. This vulnerability affects unknown code of the file signup.php of the component User Registration Handler. The manipulation of the argument user leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273232.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2g56-8jc9-jg87

In validateUriSchemeAndPermission of DisclaimersParserImpl.java , there is a possible way to access data from another user due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-2g56-7jv7-wxxq

Missing Cryptographic Step in OWASP Enterprise Security API for Java

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2g55-8gcv-fc24

Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.

CVSS3: 5.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-2g55-8535-gp6f

Splicecom Maximiser Soft PBX v1.5 and before was discovered to contain a cross-site scripting (XSS) vulnerability via the CLIENT_NAME and DEVICE_GUID fields in the login component.

CVSS3: 6.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-2g55-7wqw-h2c5

Heap-based buffer overflow in the __zzip_get32 function in fetch.c in zziplib 0.13.62, 0.13.61, 0.13.60, 0.13.59, 0.13.58, 0.13.57, 0.13.56 allows remote attackers to cause a denial of service (crash) via a crafted ZIP file.

CVSS3: 5.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2g54-42rw-p43x

The specific function in ASUS BMC’s firmware Web management page (Modify user’s information function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2g53-pmw3-ccp9

CheckSec Canopy 3.x before 3.0.7 has stored XSS via the Login Page Disclaimer, allowing attacks by low-privileged users against higher-privileged users.

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2g53-3pj8-qvxv

Use-after-free vulnerability in the path_openat function in fs/namei.c in the Linux kernel 3.x and 4.x before 4.0.4 allows local users to cause a denial of service or possibly have unspecified other impact via O_TMPFILE filesystem operations that leverage a duplicate cleanup operation.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2g52-qw8q-wfr9

Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed. This vulnerability affects Firefox < 134.

CVSS3: 3.3
0%
Низкий
около 1 года назад
github логотип
GHSA-2g4x-xxrm-h5mw

Dell Encryption (formerly Dell Data Protection | Encryption) v10.1.0 and earlier contain an information disclosure vulnerability. A malicious user with physical access to the machine could potentially exploit this vulnerability to access the unencrypted RegBack folder that contains back-ups of sensitive system files.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2g4x-p9qv-phcg

Multiple cross-site scripting (XSS) vulnerabilities in Gallery 3 before 3.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) movie title to modules/gallery/controllers/movies.php or (2) key variable to modules/gallery/views/error_admin.html.php.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2g4x-fv7q-8jrf

Insufficient data validation in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2g4x-3mj5-gvj6

Multiple buffer overflows in the Broderbund Expressit 3DGreetings Player ActiveX control could allow remote attackers to execute arbitrary code via unspecified vectors.

11%
Средний
почти 4 года назад

Уязвимостей на страницу