Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 212

Количество 314 212

github логотип

GHSA-2j4c-4vw2-9r77

больше 3 лет назад

A potential Remote Arbitrary Code Execution vulnerability has been identified in Micro Focus' Real User Monitoring software, versions 9.26IP, 9.30, 9.40 and 9.50. The vulnerability could be exploited to execute arbitrary code.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2j49-q898-whm9

больше 3 лет назад

Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-2j49-6mmc-22jj

больше 3 лет назад

All FLIR AX8 thermal sensor cameras versions up to and including 1.46.16 are vulnerable to Cross Site Scripting (XSS) due to improper input sanitization. An authenticated remote attacker can execute arbitrary JavaScript code in the web management interface. A successful exploit could allow the attacker to insert malicious JavaScript code.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2j49-4qxc-q53v

больше 3 лет назад

Cross-site scripting vulnerability in Click Ranker Ver.3.5 allows remote attackers to inject an arbitrary script via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2j49-3cqv-33p2

почти 4 года назад

unzoo.c, as used in multiple products including AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.

EPSS: Низкий
github логотип

GHSA-2j48-x5hc-4xv7

больше 3 лет назад

IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 make it easier for remote attackers to obtain sensitive information by sniffing the network during use of a weak algorithm in an SSL cipher suite.

EPSS: Низкий
github логотип

GHSA-2j48-mrqm-r4w9

больше 3 лет назад

CimWebServer in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process Systems with CIMPLICITY, allows remote attackers to execute arbitrary commands or cause a denial of service (daemon crash) via a crafted packet.

EPSS: Низкий
github логотип

GHSA-2j47-qm67-hvhx

больше 3 лет назад

The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as the management of access rights for such IP, including improperly specified HDL syntax allows use of an EDA tool as a decryption oracle. The methods are flawed and, in the most egregious cases, enable attack vectors that allow recovery of the entire underlying plaintext IP. Implementations of IEEE P1735 may be weak to cryptographic attacks that allow an attacker to obtain plaintext intellectual property without the key, among other impacts.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2j47-jhvw-fgmm

5 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix OOB read/write in network-coding decode batadv_nc_skb_decode_packet() trusts coded_len and checks only against skb->len. XOR starts at sizeof(struct batadv_unicast_packet), reducing payload headroom, and the source skb length is not verified, allowing an out-of-bounds read and a small out-of-bounds write. Validate that coded_len fits within the payload area of both destination and source sk_buffs before XORing.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2j47-26hx-p54j

около 4 лет назад

Vulnerability in the Oracle Communications Convergence product of Oracle Communications Applications (component: General Framework). The supported version that is affected is 3.0.2.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Convergence. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communications Convergence accessible data as well as unauthorized read access to a subset of Oracle Communications Convergence accessible data. CVSS 3.1 Base Score 4.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N).

EPSS: Низкий
github логотип

GHSA-2j46-xfp6-wgfm

почти 3 года назад

Reflective Cross-Site-Scripting in Webconf in Tribe29 Checkmk Appliance before 1.6.4.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2j46-98gf-6xf6

больше 3 лет назад

Python 2.6 through 3.2 creates ~/.pypirc with world-readable permissions before changing them after data has been written, which introduces a race condition that allows local users to obtain a username and password by reading this file.

EPSS: Низкий
github логотип

GHSA-2j46-6r67-vrpr

12 месяцев назад

The Zigaform – Form Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zgfm_rfvar' shortcode in all versions up to, and including, 7.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2j46-43q5-rfcp

10 месяцев назад

BEC Technologies Multiple Routers Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of BEC Technologies routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web-based user interface. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-25894.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2j45-xr49-x8qc

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: riscv: kexec: Avoid deadlock in kexec crash path If the kexec crash code is called in the interrupt context, the machine_kexec_mask_interrupts() function will trigger a deadlock while trying to acquire the irqdesc spinlock and then deactivate irqchip in irq_set_irqchip_state() function. Unlike arm64, riscv only requires irq_eoi handler to complete EOI and keeping irq_set_irqchip_state() will only leave this possible deadlock without any use. So we simply remove it.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2j45-pj39-84jw

больше 3 лет назад

XXE in GE Proficy Cimplicity GDS versions 9.0 R2, 9.5, 10.0

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-2j44-h693-7vr3

почти 2 года назад

Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-2j44-59r4-mjvh

больше 3 лет назад

Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2j42-h78h-q4fg

10 месяцев назад

Beego allows Reflected/Stored XSS in Beego's RenderForm() Function Due to Unescaped User Input

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-2j3x-r9v2-2733

больше 3 лет назад

libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer over-read in the GET_COLOR function in color.c:18:11.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2j4c-4vw2-9r77

A potential Remote Arbitrary Code Execution vulnerability has been identified in Micro Focus' Real User Monitoring software, versions 9.26IP, 9.30, 9.40 and 9.50. The vulnerability could be exploited to execute arbitrary code.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2j49-q898-whm9

Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function.

CVSS3: 9.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2j49-6mmc-22jj

All FLIR AX8 thermal sensor cameras versions up to and including 1.46.16 are vulnerable to Cross Site Scripting (XSS) due to improper input sanitization. An authenticated remote attacker can execute arbitrary JavaScript code in the web management interface. A successful exploit could allow the attacker to insert malicious JavaScript code.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j49-4qxc-q53v

Cross-site scripting vulnerability in Click Ranker Ver.3.5 allows remote attackers to inject an arbitrary script via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j49-3cqv-33p2

unzoo.c, as used in multiple products including AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2j48-x5hc-4xv7

IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 make it easier for remote attackers to obtain sensitive information by sniffing the network during use of a weak algorithm in an SSL cipher suite.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j48-mrqm-r4w9

CimWebServer in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process Systems with CIMPLICITY, allows remote attackers to execute arbitrary commands or cause a denial of service (daemon crash) via a crafted packet.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2j47-qm67-hvhx

The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as the management of access rights for such IP, including improperly specified HDL syntax allows use of an EDA tool as a decryption oracle. The methods are flawed and, in the most egregious cases, enable attack vectors that allow recovery of the entire underlying plaintext IP. Implementations of IEEE P1735 may be weak to cryptographic attacks that allow an attacker to obtain plaintext intellectual property without the key, among other impacts.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j47-jhvw-fgmm

In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix OOB read/write in network-coding decode batadv_nc_skb_decode_packet() trusts coded_len and checks only against skb->len. XOR starts at sizeof(struct batadv_unicast_packet), reducing payload headroom, and the source skb length is not verified, allowing an out-of-bounds read and a small out-of-bounds write. Validate that coded_len fits within the payload area of both destination and source sk_buffs before XORing.

CVSS3: 7.1
0%
Низкий
5 месяцев назад
github логотип
GHSA-2j47-26hx-p54j

Vulnerability in the Oracle Communications Convergence product of Oracle Communications Applications (component: General Framework). The supported version that is affected is 3.0.2.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Convergence. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communications Convergence accessible data as well as unauthorized read access to a subset of Oracle Communications Convergence accessible data. CVSS 3.1 Base Score 4.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N).

0%
Низкий
около 4 лет назад
github логотип
GHSA-2j46-xfp6-wgfm

Reflective Cross-Site-Scripting in Webconf in Tribe29 Checkmk Appliance before 1.6.4.

CVSS3: 6.1
1%
Низкий
почти 3 года назад
github логотип
GHSA-2j46-98gf-6xf6

Python 2.6 through 3.2 creates ~/.pypirc with world-readable permissions before changing them after data has been written, which introduces a race condition that allows local users to obtain a username and password by reading this file.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j46-6r67-vrpr

The Zigaform – Form Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zgfm_rfvar' shortcode in all versions up to, and including, 7.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
12 месяцев назад
github логотип
GHSA-2j46-43q5-rfcp

BEC Technologies Multiple Routers Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of BEC Technologies routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web-based user interface. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-25894.

CVSS3: 5.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-2j45-xr49-x8qc

In the Linux kernel, the following vulnerability has been resolved: riscv: kexec: Avoid deadlock in kexec crash path If the kexec crash code is called in the interrupt context, the machine_kexec_mask_interrupts() function will trigger a deadlock while trying to acquire the irqdesc spinlock and then deactivate irqchip in irq_set_irqchip_state() function. Unlike arm64, riscv only requires irq_eoi handler to complete EOI and keeping irq_set_irqchip_state() will only leave this possible deadlock without any use. So we simply remove it.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2j45-pj39-84jw

XXE in GE Proficy Cimplicity GDS versions 9.0 R2, 9.5, 10.0

CVSS3: 9.1
2%
Низкий
больше 3 лет назад
github логотип
GHSA-2j44-h693-7vr3

Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access.

CVSS3: 9.6
0%
Низкий
почти 2 года назад
github логотип
GHSA-2j44-59r4-mjvh

Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j42-h78h-q4fg

Beego allows Reflected/Stored XSS in Beego's RenderForm() Function Due to Unescaped User Input

CVSS3: 9.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-2j3x-r9v2-2733

libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer over-read in the GET_COLOR function in color.c:18:11.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу