Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 306 694

Количество 306 694

github логотип

GHSA-248j-q36m-hvq3

больше 3 лет назад

imcat 4.4 allows remote attackers to obtain potentially sensitive configuration information via the root/tools/adbug/check.php URI.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-248j-6c4g-f66m

больше 3 лет назад

server/notification/NotificationManagerService.java in the Notification Manager Service in Android 6.x before 2016-09-01 and 7.0 before 2016-09-01 lacks uid checks, which allows attackers to bypass intended restrictions on method calls via a crafted application, aka internal bug 29421441.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-248h-xgcm-3q77

больше 3 лет назад

In Wireshark 3.2.0 to 3.2.2, 3.0.0 to 3.0.9, and 2.6.0 to 2.6.15, the BACapp dissector could crash. This was addressed in epan/dissectors/packet-bacapp.c by limiting the amount of recursion.

EPSS: Низкий
github логотип

GHSA-248g-v9x5-ppvq

больше 3 лет назад

Heap-based buffer overflow in Borland idsql32.dll 5.1.0.4, as used by RevilloC MailServer; 5.2.0.2 as used by Borland Developer Studio 2006; and possibly other versions allows remote attackers to execute arbitrary code via a long SQL statement, related to use of the DbiQExec function.

EPSS: Низкий
github логотип

GHSA-248g-g9j5-m344

больше 3 лет назад

An elevation of privilege vulnerability in the Qualcomm ADSPRPC driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31695439. References: QC-CR#1086123, QC-CR#1100695.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-248c-9vj8-9325

больше 3 лет назад

Unspecified vulnerability in DCE in HP HP-UX B.11.11, B.11.23, and B.11.31 allows remote attackers to cause a denial of service via unknown vectors.

EPSS: Низкий
github логотип

GHSA-2489-xfhx-mcfj

больше 3 лет назад

Unrestricted file upload vulnerability in myaccount.php in Easy Scripts Answer and Question Script allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the uploads/[username] directory.

EPSS: Низкий
github логотип

GHSA-2489-fj5v-q8w2

больше 3 лет назад

A configuration issue was addressed with additional restrictions. This issue affected versions prior to macOS Mojave 10.14.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2488-w585-72ch

3 месяца назад

counterpart vulnerable to prototype pollution

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2488-pfc2-g3x9

больше 3 лет назад

The sell function of a smart contract implementation for ETHEREUMBLACK (ETCBK), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2488-c4gj-6g77

3 дня назад

Nagios XI versions prior to 2026R1.1 are vulnerable to local privilege escalation due to an unsafe interaction between sudo permissions and application file permissions. A user‑accessible maintenance script may be executed as root via sudo and includes an application file that is writable by a lower‑privileged user. A local attacker with access to the application account can modify this file to introduce malicious code, which is then executed with elevated privileges when the script is run. Successful exploitation results in arbitrary code execution as the root user.

EPSS: Низкий
github логотип

GHSA-2488-7mjj-wx6f

больше 3 лет назад

Stack-based buffer overflow in the reply_netbios_packet function in nmbd/nmbd_packets.c in nmbd in Samba 3.0.0 through 3.0.26a, when operating as a WINS server, allows remote attackers to execute arbitrary code via crafted WINS Name Registration requests followed by a WINS Name Query request.

EPSS: Средний
github логотип

GHSA-2487-9f55-2vg9

7 месяцев назад

OZI-Project/ozi-publish Code Injection vulnerability

EPSS: Низкий
github логотип

GHSA-2486-f4hq-9m5c

больше 3 лет назад

The Hide-Thread-Content plugin through 2021-01-27 for MyBB allows remote attackers to bypass intended content-reading restrictions by clicking on reply or quote in the postbit.

EPSS: Средний
github логотип

GHSA-2486-25fw-2vf4

больше 3 лет назад

Intesync Solismed 3.3sp allows Insecure File Upload.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2484-xfxv-q77x

около 1 года назад

The Product Filter by WooBeWoo plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 1.4.9 due to missing authorization checks on various functions. This makes it possible for unauthenticated attackers to perform unauthorized actions such as creating new filters and injecting malicious javascript into a vulnerable site. This was actively exploited at the time of discovery.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2482-hx3h-75g4

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: io_uring: Fix a null-ptr-deref in io_tctx_exit_cb() Syzkaller reports a NULL deref bug as follows: BUG: KASAN: null-ptr-deref in io_tctx_exit_cb+0x53/0xd3 Read of size 4 at addr 0000000000000138 by task file1/1955 CPU: 1 PID: 1955 Comm: file1 Not tainted 6.1.0-rc7-00103-gef4d3ea40565 #75 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.11.0-2.el7 04/01/2014 Call Trace: <TASK> dump_stack_lvl+0xcd/0x134 ? io_tctx_exit_cb+0x53/0xd3 kasan_report+0xbb/0x1f0 ? io_tctx_exit_cb+0x53/0xd3 kasan_check_range+0x140/0x190 io_tctx_exit_cb+0x53/0xd3 task_work_run+0x164/0x250 ? task_work_cancel+0x30/0x30 get_signal+0x1c3/0x2440 ? lock_downgrade+0x6e0/0x6e0 ? lock_downgrade+0x6e0/0x6e0 ? exit_signals+0x8b0/0x8b0 ? do_raw_read_unlock+0x3b/0x70 ? do_raw_spin_unlock+0x50/0x230 arch_do_signal_or_restart+0x82/0x2470 ? kmem_cache_free+0x260/0x4b0 ? putname+0xfe/0x140 ? get_sigfra...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2482-gr3v-f3f3

больше 2 лет назад

Jenkins Fogbugz Plugin has missing permissions check

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-247x-w9wc-8gvv

больше 3 лет назад

An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. The default management application is delivered over cleartext HTTP with Basic Authentication, as demonstrated by the /admin/index.html URI.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-247x-jv5h-grf9

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Luzuk Luzuk Testimonials allows Stored XSS.This issue affects Luzuk Testimonials: from n/a through 0.0.1.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-248j-q36m-hvq3

imcat 4.4 allows remote attackers to obtain potentially sensitive configuration information via the root/tools/adbug/check.php URI.

CVSS3: 5.3
3%
Низкий
больше 3 лет назад
github логотип
GHSA-248j-6c4g-f66m

server/notification/NotificationManagerService.java in the Notification Manager Service in Android 6.x before 2016-09-01 and 7.0 before 2016-09-01 lacks uid checks, which allows attackers to bypass intended restrictions on method calls via a crafted application, aka internal bug 29421441.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-248h-xgcm-3q77

In Wireshark 3.2.0 to 3.2.2, 3.0.0 to 3.0.9, and 2.6.0 to 2.6.15, the BACapp dissector could crash. This was addressed in epan/dissectors/packet-bacapp.c by limiting the amount of recursion.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-248g-v9x5-ppvq

Heap-based buffer overflow in Borland idsql32.dll 5.1.0.4, as used by RevilloC MailServer; 5.2.0.2 as used by Borland Developer Studio 2006; and possibly other versions allows remote attackers to execute arbitrary code via a long SQL statement, related to use of the DbiQExec function.

5%
Низкий
больше 3 лет назад
github логотип
GHSA-248g-g9j5-m344

An elevation of privilege vulnerability in the Qualcomm ADSPRPC driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31695439. References: QC-CR#1086123, QC-CR#1100695.

CVSS3: 7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-248c-9vj8-9325

Unspecified vulnerability in DCE in HP HP-UX B.11.11, B.11.23, and B.11.31 allows remote attackers to cause a denial of service via unknown vectors.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-2489-xfhx-mcfj

Unrestricted file upload vulnerability in myaccount.php in Easy Scripts Answer and Question Script allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the uploads/[username] directory.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-2489-fj5v-q8w2

A configuration issue was addressed with additional restrictions. This issue affected versions prior to macOS Mojave 10.14.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2488-w585-72ch

counterpart vulnerable to prototype pollution

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-2488-pfc2-g3x9

The sell function of a smart contract implementation for ETHEREUMBLACK (ETCBK), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2488-c4gj-6g77

Nagios XI versions prior to 2026R1.1 are vulnerable to local privilege escalation due to an unsafe interaction between sudo permissions and application file permissions. A user‑accessible maintenance script may be executed as root via sudo and includes an application file that is writable by a lower‑privileged user. A local attacker with access to the application account can modify this file to introduce malicious code, which is then executed with elevated privileges when the script is run. Successful exploitation results in arbitrary code execution as the root user.

0%
Низкий
3 дня назад
github логотип
GHSA-2488-7mjj-wx6f

Stack-based buffer overflow in the reply_netbios_packet function in nmbd/nmbd_packets.c in nmbd in Samba 3.0.0 through 3.0.26a, when operating as a WINS server, allows remote attackers to execute arbitrary code via crafted WINS Name Registration requests followed by a WINS Name Query request.

41%
Средний
больше 3 лет назад
github логотип
GHSA-2487-9f55-2vg9

OZI-Project/ozi-publish Code Injection vulnerability

0%
Низкий
7 месяцев назад
github логотип
GHSA-2486-f4hq-9m5c

The Hide-Thread-Content plugin through 2021-01-27 for MyBB allows remote attackers to bypass intended content-reading restrictions by clicking on reply or quote in the postbit.

16%
Средний
больше 3 лет назад
github логотип
GHSA-2486-25fw-2vf4

Intesync Solismed 3.3sp allows Insecure File Upload.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2484-xfxv-q77x

The Product Filter by WooBeWoo plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 1.4.9 due to missing authorization checks on various functions. This makes it possible for unauthenticated attackers to perform unauthorized actions such as creating new filters and injecting malicious javascript into a vulnerable site. This was actively exploited at the time of discovery.

CVSS3: 7.3
0%
Низкий
около 1 года назад
github логотип
GHSA-2482-hx3h-75g4

In the Linux kernel, the following vulnerability has been resolved: io_uring: Fix a null-ptr-deref in io_tctx_exit_cb() Syzkaller reports a NULL deref bug as follows: BUG: KASAN: null-ptr-deref in io_tctx_exit_cb+0x53/0xd3 Read of size 4 at addr 0000000000000138 by task file1/1955 CPU: 1 PID: 1955 Comm: file1 Not tainted 6.1.0-rc7-00103-gef4d3ea40565 #75 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.11.0-2.el7 04/01/2014 Call Trace: <TASK> dump_stack_lvl+0xcd/0x134 ? io_tctx_exit_cb+0x53/0xd3 kasan_report+0xbb/0x1f0 ? io_tctx_exit_cb+0x53/0xd3 kasan_check_range+0x140/0x190 io_tctx_exit_cb+0x53/0xd3 task_work_run+0x164/0x250 ? task_work_cancel+0x30/0x30 get_signal+0x1c3/0x2440 ? lock_downgrade+0x6e0/0x6e0 ? lock_downgrade+0x6e0/0x6e0 ? exit_signals+0x8b0/0x8b0 ? do_raw_read_unlock+0x3b/0x70 ? do_raw_spin_unlock+0x50/0x230 arch_do_signal_or_restart+0x82/0x2470 ? kmem_cache_free+0x260/0x4b0 ? putname+0xfe/0x140 ? get_sigfra...

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2482-gr3v-f3f3

Jenkins Fogbugz Plugin has missing permissions check

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-247x-w9wc-8gvv

An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. The default management application is delivered over cleartext HTTP with Basic Authentication, as demonstrated by the /admin/index.html URI.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-247x-jv5h-grf9

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Luzuk Luzuk Testimonials allows Stored XSS.This issue affects Luzuk Testimonials: from n/a through 0.0.1.

CVSS3: 6.5
0%
Низкий
около 1 года назад

Уязвимостей на страницу