Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2hhv-v3hc-2xgx

больше 3 лет назад

The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7288, CVE-2016-7296, and CVE-2016-7297.

CVSS3: 7.5
EPSS: Высокий
github логотип

GHSA-2hhr-r74q-p8fq

больше 3 лет назад

The xdr_status_vector function in Firebird before 2.1.7 and 2.5.x before 2.5.3 SU1 allows remote attackers to cause a denial of service (NULL pointer dereference, segmentation fault, and crash) via an op_response action with a non-empty status.

EPSS: Низкий
github логотип

GHSA-2hhq-96pp-rf56

больше 3 лет назад

Incorrect origin serialization of URLs with IPv6 addresses could lead to incorrect security checks. This vulnerability affects Firefox < 76.

EPSS: Низкий
github логотип

GHSA-2hhp-wrh5-g527

около 1 месяца назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-2hhp-r87h-qvgj

почти 4 года назад

Directory traversal vulnerability in Hyperion FTP server 2.8.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the LS command.

EPSS: Низкий
github логотип

GHSA-2hhp-373f-h757

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in addguest.cgi in Big Webmaster Guestbook Script 1.02 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mail, (2) site, (3) city, (4) state, (5) country, and possibly (6) name fields, which are viewed via viewguest.cgi.

EPSS: Низкий
github логотип

GHSA-2hhm-gh43-f53h

почти 4 года назад

Cross-site scripting (XSS) vulnerability in 404.php in Domain Technologie Control (DTC) before 0.25.9 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (REQUEST_URI). NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-2hhm-535h-jfpf

около 1 года назад

In Modem, there is a possible escalation of privilege due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01395886; Issue ID: MSV-1871.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2hhh-gxpg-w8vr

больше 3 лет назад

The DNS server in Microsoft Windows Server 2003 SP2 and Windows Server 2008 SP2, R2, and R2 SP1 does not properly initialize memory, which allows remote attackers to cause a denial of service (service outage) via a query for a nonexistent domain, aka "DNS Uninitialized Memory Corruption Vulnerability."

EPSS: Средний
github логотип

GHSA-2hhg-c3w2-vgr6

почти 4 года назад

The check_referer() function in Formmail.php 5.0 and earlier allows remote attackers to bypass access restrictions via an empty or spoofed HTTP Referer, as demonstrated using an application on the same web server that contains a cross-site scripting (XSS) issue.

EPSS: Низкий
github логотип

GHSA-2hhg-24wg-6mmv

около 1 года назад

Missing Authorization vulnerability in Leap13 Premium Addons for Elementor allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Premium Addons for Elementor: from n/a through 4.10.56.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2hhf-q463-9hv4

почти 4 года назад

Cross-site scripting (XSS) vulnerability in index.php for CMSimple 2.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter in the search function.

EPSS: Низкий
github логотип

GHSA-2hhf-gxff-r59q

больше 2 лет назад

A reflected cross-site scripting (XSS) vulnerability in msaad1999's PHP-Login-System 2.0.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'selector' parameter in '/reset-password'.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2hhf-9f74-3jqg

2 месяца назад

File upload vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store arbitrary files on the filesystem.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2hhc-f86x-x74f

больше 3 лет назад

Inefficient Regular Expression Complexity in Jenkins Build Failure Analyzer Plugin

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2hhc-539m-8qw5

больше 3 лет назад

The WPG parser in ImageMagick before 6.9.4-4 and 7.x before 7.0.1-5, when a memory limit is set, allows remote attackers to have unspecified impact via vectors related to the SetImageExtent return-value check, which trigger (1) a heap-based buffer overflow in the SetPixelIndex function or an invalid write operation in the (2) ScaleCharToQuantum or (3) SetPixelIndex functions.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2hh9-vfrm-8f6w

больше 3 лет назад

In ImageMagick before 6.9.7-10, there is a crash (rather than a "width or height exceeds limit" error report) if the image dimensions are too large, as demonstrated by use of the mpc coder.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2hh8-gpv5-pc93

11 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix racy issue from session lookup and expire Increment the session reference count within the lock for lookup to avoid racy issue with session expire.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2hh7-f3x9-8mgq

больше 3 лет назад

An insecure direct object reference in webmail in totemo totemomail 7.0.0 allows an authenticated remote user to read and modify mail folder names of other users via enumeration.

EPSS: Низкий
github логотип

GHSA-2hh7-5899-hfpg

5 месяцев назад

ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic WPA2-PSK, which can be easily derived.

CVSS3: 6.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2hhv-v3hc-2xgx

The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7288, CVE-2016-7296, and CVE-2016-7297.

CVSS3: 7.5
82%
Высокий
больше 3 лет назад
github логотип
GHSA-2hhr-r74q-p8fq

The xdr_status_vector function in Firebird before 2.1.7 and 2.5.x before 2.5.3 SU1 allows remote attackers to cause a denial of service (NULL pointer dereference, segmentation fault, and crash) via an op_response action with a non-empty status.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-2hhq-96pp-rf56

Incorrect origin serialization of URLs with IPv6 addresses could lead to incorrect security checks. This vulnerability affects Firefox < 76.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2hhp-wrh5-g527

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

около 1 месяца назад
github логотип
GHSA-2hhp-r87h-qvgj

Directory traversal vulnerability in Hyperion FTP server 2.8.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the LS command.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2hhp-373f-h757

Multiple cross-site scripting (XSS) vulnerabilities in addguest.cgi in Big Webmaster Guestbook Script 1.02 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mail, (2) site, (3) city, (4) state, (5) country, and possibly (6) name fields, which are viewed via viewguest.cgi.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2hhm-gh43-f53h

Cross-site scripting (XSS) vulnerability in 404.php in Domain Technologie Control (DTC) before 0.25.9 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (REQUEST_URI). NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2hhm-535h-jfpf

In Modem, there is a possible escalation of privilege due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01395886; Issue ID: MSV-1871.

CVSS3: 6.7
0%
Низкий
около 1 года назад
github логотип
GHSA-2hhh-gxpg-w8vr

The DNS server in Microsoft Windows Server 2003 SP2 and Windows Server 2008 SP2, R2, and R2 SP1 does not properly initialize memory, which allows remote attackers to cause a denial of service (service outage) via a query for a nonexistent domain, aka "DNS Uninitialized Memory Corruption Vulnerability."

55%
Средний
больше 3 лет назад
github логотип
GHSA-2hhg-c3w2-vgr6

The check_referer() function in Formmail.php 5.0 and earlier allows remote attackers to bypass access restrictions via an empty or spoofed HTTP Referer, as demonstrated using an application on the same web server that contains a cross-site scripting (XSS) issue.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2hhg-24wg-6mmv

Missing Authorization vulnerability in Leap13 Premium Addons for Elementor allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Premium Addons for Elementor: from n/a through 4.10.56.

CVSS3: 5.4
0%
Низкий
около 1 года назад
github логотип
GHSA-2hhf-q463-9hv4

Cross-site scripting (XSS) vulnerability in index.php for CMSimple 2.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter in the search function.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2hhf-gxff-r59q

A reflected cross-site scripting (XSS) vulnerability in msaad1999's PHP-Login-System 2.0.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'selector' parameter in '/reset-password'.

CVSS3: 6.1
8%
Низкий
больше 2 лет назад
github логотип
GHSA-2hhf-9f74-3jqg

File upload vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store arbitrary files on the filesystem.

CVSS3: 4.3
0%
Низкий
2 месяца назад
github логотип
GHSA-2hhc-f86x-x74f

Inefficient Regular Expression Complexity in Jenkins Build Failure Analyzer Plugin

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hhc-539m-8qw5

The WPG parser in ImageMagick before 6.9.4-4 and 7.x before 7.0.1-5, when a memory limit is set, allows remote attackers to have unspecified impact via vectors related to the SetImageExtent return-value check, which trigger (1) a heap-based buffer overflow in the SetPixelIndex function or an invalid write operation in the (2) ScaleCharToQuantum or (3) SetPixelIndex functions.

CVSS3: 8.1
2%
Низкий
больше 3 лет назад
github логотип
GHSA-2hh9-vfrm-8f6w

In ImageMagick before 6.9.7-10, there is a crash (rather than a "width or height exceeds limit" error report) if the image dimensions are too large, as demonstrated by use of the mpc coder.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hh8-gpv5-pc93

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix racy issue from session lookup and expire Increment the session reference count within the lock for lookup to avoid racy issue with session expire.

CVSS3: 8.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-2hh7-f3x9-8mgq

An insecure direct object reference in webmail in totemo totemomail 7.0.0 allows an authenticated remote user to read and modify mail folder names of other users via enumeration.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2hh7-5899-hfpg

ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic WPA2-PSK, which can be easily derived.

CVSS3: 6.3
0%
Низкий
5 месяцев назад

Уязвимостей на страницу