Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 212

Количество 314 212

github логотип

GHSA-2j5v-fc74-j9q2

почти 7 лет назад

Cross-Site Scripting in editor.md

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2j5v-7wgm-q5gw

больше 3 лет назад

WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.

EPSS: Низкий
github логотип

GHSA-2j5r-64m5-jpx3

почти 4 года назад

An improper authorization handling flaw was found in Foreman. The Salt plugin for the smart-proxy allows foreman clients to execute actions that should be limited to the Foreman Server. This flaw allows an authenticated local attacker to access and delete limited resources and also causes a denial of service on the Foreman server. The highest threat from this vulnerability is to integrity and system availability.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2j5q-x2p7-vgw7

больше 3 лет назад

Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution .

EPSS: Низкий
github логотип

GHSA-2j5q-ph68-3hp6

больше 3 лет назад

Incomplete blacklist vulnerability in SuiteCRM 7.2.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2j5q-9qj3-658m

больше 3 лет назад

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2j5q-8vp4-fjw9

больше 3 лет назад

TP-Link TL-WVR and TL-WAR devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the interface field of an admin/wportal command to cgi-bin/luci, related to the get_device_byif function in /usr/lib/lua/luci/controller/admin/wportal.lua in uhttpd.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2j5q-4fj9-xmqw

больше 3 лет назад

The get_option function in dhcpcd 4.0.0 through 6.x before 6.4.3 allows remote DHCP servers to cause a denial of service by resetting the DHO_OPTIONSOVERLOADED option in the (1) bootfile or (2) servername section, which triggers the option to be processed again.

EPSS: Низкий
github логотип

GHSA-2j5p-cf62-8pj2

больше 3 лет назад

An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0 V15.03.05.19_multi_TD01, and AC18 V15.03.05.19(6318_)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the /goform/addressNat entrys and mitInterface parameters for a POST request, a value is directly used in a sprintf to a local variable placed on the stack, which overwrites the return address of a function. An attacker can construct a payload to carry out arbitrary code execution attacks.

EPSS: Низкий
github логотип

GHSA-2j5p-8qm3-j27m

почти 4 года назад

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2j5m-fjjv-cj2h

больше 3 лет назад

A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the browsing context. This could leak cookies in private browsing mode or across different "containers" for people who use the Firefox Multi-Account Containers Web Extension. This vulnerability affects Firefox < 68.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2j5j-f58p-g63q

больше 3 лет назад

XPDF commit ffaf11c was discovered to contain a segmentation violation via DCTStream::readMCURow() at /xpdf/Stream.cc.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2j5j-7jpr-whqc

больше 3 лет назад

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, Safari 13.1.2. Visiting a malicious website may lead to address bar spoofing.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2j5j-53gg-96g7

около 1 года назад

Missing Authorization vulnerability in Lenderd 1003 Mortgage Application allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects 1003 Mortgage Application: from n/a through 1.87.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2j5h-v47w-vfqp

больше 3 лет назад

Optergy Proton/Enterprise devices allow Open Redirect.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-2j5h-jch9-hqpj

больше 3 лет назад

The web framework in Cisco Unified Computing System (UCS) Performance Manager 2.0.0 and earlier allows remote authenticated users to execute arbitrary commands via crafted parameters in a GET request, aka Bug ID CSCuy07827.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2j5g-w3c2-pj99

больше 3 лет назад

Unauthenticated SQL Injection in Huge-IT Video Gallery v1.0.9 for Joomla

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2j5g-89m6-j53g

больше 3 лет назад

Mitsubishi E-Designer, Version 7.52 Build 344 contains six code sections which may be exploited to overwrite the stack. This can result in arbitrary code execution, compromised data integrity, denial of service, and system crash.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2j5g-6x52-988w

больше 3 лет назад

SAP ERP and SAP S/4 HANA allows an authenticated user to see cost records to objects to which he has no authorization in PS reporting, leading to Missing Authorization check.

EPSS: Низкий
github логотип

GHSA-2j5g-62c3-j9jj

около 1 месяца назад

In the Linux kernel, the following vulnerability has been resolved: powerpc/pseries: fix possible memory leak in ibmebus_bus_init() If device_register() returns error in ibmebus_bus_init(), name of kobject which is allocated in dev_set_name() called in device_add() is leaked. As comment of device_add() says, it should call put_device() to drop the reference count that was set in device_initialize() when it fails, so the name can be freed in kobject_cleanup().

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2j5v-fc74-j9q2

Cross-Site Scripting in editor.md

CVSS3: 6.1
0%
Низкий
почти 7 лет назад
github логотип
GHSA-2j5v-7wgm-q5gw

WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-2j5r-64m5-jpx3

An improper authorization handling flaw was found in Foreman. The Salt plugin for the smart-proxy allows foreman clients to execute actions that should be limited to the Foreman Server. This flaw allows an authenticated local attacker to access and delete limited resources and also causes a denial of service on the Foreman server. The highest threat from this vulnerability is to integrity and system availability.

CVSS3: 7.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-2j5q-x2p7-vgw7

Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution .

8%
Низкий
больше 3 лет назад
github логотип
GHSA-2j5q-ph68-3hp6

Incomplete blacklist vulnerability in SuiteCRM 7.2.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j5q-9qj3-658m

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

CVSS3: 8.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-2j5q-8vp4-fjw9

TP-Link TL-WVR and TL-WAR devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the interface field of an admin/wportal command to cgi-bin/luci, related to the get_device_byif function in /usr/lib/lua/luci/controller/admin/wportal.lua in uhttpd.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2j5q-4fj9-xmqw

The get_option function in dhcpcd 4.0.0 through 6.x before 6.4.3 allows remote DHCP servers to cause a denial of service by resetting the DHO_OPTIONSOVERLOADED option in the (1) bootfile or (2) servername section, which triggers the option to be processed again.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j5p-cf62-8pj2

An issue was discovered on Tenda AC6 V1.0 V15.03.05.19_multi_TD01, AC9 V1.0 V15.03.05.19(6318)_CN, AC9 V3.0 V15.03.06.42_multi, AC15 V1.0 V15.03.05.19_multi_TD01, and AC18 V15.03.05.19(6318_)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the /goform/addressNat entrys and mitInterface parameters for a POST request, a value is directly used in a sprintf to a local variable placed on the stack, which overwrites the return address of a function. An attacker can construct a payload to carry out arbitrary code execution attacks.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-2j5p-8qm3-j27m

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-2j5m-fjjv-cj2h

A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the browsing context. This could leak cookies in private browsing mode or across different "containers" for people who use the Firefox Multi-Account Containers Web Extension. This vulnerability affects Firefox < 68.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j5j-f58p-g63q

XPDF commit ffaf11c was discovered to contain a segmentation violation via DCTStream::readMCURow() at /xpdf/Stream.cc.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j5j-7jpr-whqc

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, Safari 13.1.2. Visiting a malicious website may lead to address bar spoofing.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j5j-53gg-96g7

Missing Authorization vulnerability in Lenderd 1003 Mortgage Application allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects 1003 Mortgage Application: from n/a through 1.87.

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2j5h-v47w-vfqp

Optergy Proton/Enterprise devices allow Open Redirect.

CVSS3: 6.1
66%
Средний
больше 3 лет назад
github логотип
GHSA-2j5h-jch9-hqpj

The web framework in Cisco Unified Computing System (UCS) Performance Manager 2.0.0 and earlier allows remote authenticated users to execute arbitrary commands via crafted parameters in a GET request, aka Bug ID CSCuy07827.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2j5g-w3c2-pj99

Unauthenticated SQL Injection in Huge-IT Video Gallery v1.0.9 for Joomla

CVSS3: 9.8
6%
Низкий
больше 3 лет назад
github логотип
GHSA-2j5g-89m6-j53g

Mitsubishi E-Designer, Version 7.52 Build 344 contains six code sections which may be exploited to overwrite the stack. This can result in arbitrary code execution, compromised data integrity, denial of service, and system crash.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2j5g-6x52-988w

SAP ERP and SAP S/4 HANA allows an authenticated user to see cost records to objects to which he has no authorization in PS reporting, leading to Missing Authorization check.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j5g-62c3-j9jj

In the Linux kernel, the following vulnerability has been resolved: powerpc/pseries: fix possible memory leak in ibmebus_bus_init() If device_register() returns error in ibmebus_bus_init(), name of kobject which is allocated in dev_set_name() called in device_add() is leaked. As comment of device_add() says, it should call put_device() to drop the reference count that was set in device_initialize() when it fails, so the name can be freed in kobject_cleanup().

0%
Низкий
около 1 месяца назад

Уязвимостей на страницу