Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-2f5w-6r7r-5vgh

больше 3 лет назад

An information disclosure vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-28823681.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2f5v-p83c-vrjp

больше 3 лет назад

Path traversal vulnerability in GROWI versions v4.2.2 and earlier allows an attacker with administrator rights to read and/or delete an arbitrary path via a specially crafted URL.

EPSS: Низкий
github логотип

GHSA-2f5v-8r3f-8pww

почти 4 года назад

Improper access control allows admin privilege escalation in Argo CD

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-2f5r-r4jx-hh42

10 месяцев назад

Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hello allows an unauthorized attacker to perform spoofing locally.

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-2f5r-p45g-vr7g

12 месяцев назад

A vulnerability classified as critical has been found in TOTOLINK X18 9.1.0cu.2024_B20220329. Affected is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi. The manipulation as part of String leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2f5r-9f46-7fh6

больше 3 лет назад

An issue was discovered in PbootCMS v1.0.9. There is a SQL Injection that can get important information from the database via the \apps\home\controller\ParserController.php scode parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2f5q-9jjp-h29j

больше 3 лет назад

Integer overflow in the gray_render_span function in smooth/ftgrays.c in FreeType before 2.4.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.

EPSS: Низкий
github логотип

GHSA-2f5q-2vvh-mm3g

около 1 года назад

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `Handover Required` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2f5p-xhq6-2f67

больше 1 года назад

Vulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Security). Supported versions that are affected are 19.0.5, 20.0.3, 20.0.4, 22.0.0 and 23.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Office. While the vulnerability is in Oracle Retail Xstore Office, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Retail Xstore Office accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).

CVSS3: 8.6
EPSS: Средний
github логотип

GHSA-2f5p-v6hx-m53v

больше 3 лет назад

cPanel before 68.0.15 allows string format injection in dovecot-xaps-plugin (SEC-318).

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2f5p-8xjh-f2m8

больше 3 лет назад

CFNetwork in Apple iOS before 10 and OS X before 10.12 mishandles Local Storage deletion, which allows local users to discover the visited web sites of arbitrary users via unspecified vectors.

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-2f5j-prvf-gf42

больше 3 лет назад

** DISPUTED ** An issue has been found in HTSlib 1.8. It is a memory leak in fai_read in faidx.c. NOTE: This has been disputed with the assertion that this vulnerability exists in the test harness and HTSlib users would be aware of the need to destruct this object returned by fai_load() in their own code.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2f5j-gg85-mxm9

больше 3 лет назад

A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka 'Windows Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0627, CVE-2019-0631.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2f5j-3w2j-7mxv

больше 3 лет назад

ZyXEL PK5001Z devices have zyad5001 as the su password, which makes it easier for remote attackers to obtain root access if a non-root account password is known (or a non-root default account exists within an ISP's deployment of these devices).

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-2f5j-3mhq-xv58

больше 4 лет назад

Double free in sys-info

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2f5h-28fw-gwx2

больше 3 лет назад

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.6 and iPadOS 13.6, Safari 13.1.2. An issue in Safari Reader mode may allow a remote attacker to bypass the Same Origin Policy.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2f5g-rwwg-jqh6

больше 3 лет назад

A vulnerability has been identified in JT2Go (All Versions < V13.1.0), Teamcenter Visualization (All Versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing CGM files. This could lead to a stack based buffer overflow while trying to copy to a buffer in the font index handling function. An attacker could leverage this vulnerability to execute code in the context of the current process.

EPSS: Низкий
github логотип

GHSA-2f5g-328g-96qh

почти 2 года назад

A vulnerability has been found in Demososo DM Enterprise Website Building System up to 2022.8 and classified as critical. Affected by this vulnerability is the function dmlogin of the file indexDM_load.php of the component Cookie Handler. The manipulation of the argument is_admin with the input y leads to improper authentication. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-254605 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2f5f-jxgm-vf88

почти 4 года назад

Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0, 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to cause a denial of service (crash) via a BuildContextW request with a large (1) UuidString or (2) GuidIn of a certain length, which causes an out-of-range memory access, aka the MSDTC Denial of Service Vulnerability. NOTE: this is a variant of CVE-2005-2119.

EPSS: Средний
github логотип

GHSA-2f5f-872q-h83q

почти 4 года назад

Marcus S. Xenakis directory.php script allows remote attackers to execute arbitrary commands via shell metacharacters in the dir parameter.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2f5w-6r7r-5vgh

An information disclosure vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-28823681.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2f5v-p83c-vrjp

Path traversal vulnerability in GROWI versions v4.2.2 and earlier allows an attacker with administrator rights to read and/or delete an arbitrary path via a specially crafted URL.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2f5v-8r3f-8pww

Improper access control allows admin privilege escalation in Argo CD

CVSS3: 9.9
0%
Низкий
почти 4 года назад
github логотип
GHSA-2f5r-r4jx-hh42

Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hello allows an unauthorized attacker to perform spoofing locally.

CVSS3: 5.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-2f5r-p45g-vr7g

A vulnerability classified as critical has been found in TOTOLINK X18 9.1.0cu.2024_B20220329. Affected is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi. The manipulation as part of String leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
0%
Низкий
12 месяцев назад
github логотип
GHSA-2f5r-9f46-7fh6

An issue was discovered in PbootCMS v1.0.9. There is a SQL Injection that can get important information from the database via the \apps\home\controller\ParserController.php scode parameter.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2f5q-9jjp-h29j

Integer overflow in the gray_render_span function in smooth/ftgrays.c in FreeType before 2.4.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-2f5q-2vvh-mm3g

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `Handover Required` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.

CVSS3: 6.3
0%
Низкий
около 1 года назад
github логотип
GHSA-2f5p-xhq6-2f67

Vulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Security). Supported versions that are affected are 19.0.5, 20.0.3, 20.0.4, 22.0.0 and 23.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Office. While the vulnerability is in Oracle Retail Xstore Office, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Retail Xstore Office accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).

CVSS3: 8.6
42%
Средний
больше 1 года назад
github логотип
GHSA-2f5p-v6hx-m53v

cPanel before 68.0.15 allows string format injection in dovecot-xaps-plugin (SEC-318).

CVSS3: 6.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2f5p-8xjh-f2m8

CFNetwork in Apple iOS before 10 and OS X before 10.12 mishandles Local Storage deletion, which allows local users to discover the visited web sites of arbitrary users via unspecified vectors.

CVSS3: 4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2f5j-prvf-gf42

** DISPUTED ** An issue has been found in HTSlib 1.8. It is a memory leak in fai_read in faidx.c. NOTE: This has been disputed with the assertion that this vulnerability exists in the test harness and HTSlib users would be aware of the need to destruct this object returned by fai_load() in their own code.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2f5j-gg85-mxm9

A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka 'Windows Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0627, CVE-2019-0631.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2f5j-3w2j-7mxv

ZyXEL PK5001Z devices have zyad5001 as the su password, which makes it easier for remote attackers to obtain root access if a non-root account password is known (or a non-root default account exists within an ISP's deployment of these devices).

CVSS3: 8.8
36%
Средний
больше 3 лет назад
github логотип
GHSA-2f5j-3mhq-xv58

Double free in sys-info

CVSS3: 9.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-2f5h-28fw-gwx2

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.6 and iPadOS 13.6, Safari 13.1.2. An issue in Safari Reader mode may allow a remote attacker to bypass the Same Origin Policy.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2f5g-rwwg-jqh6

A vulnerability has been identified in JT2Go (All Versions < V13.1.0), Teamcenter Visualization (All Versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing CGM files. This could lead to a stack based buffer overflow while trying to copy to a buffer in the font index handling function. An attacker could leverage this vulnerability to execute code in the context of the current process.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2f5g-328g-96qh

A vulnerability has been found in Demososo DM Enterprise Website Building System up to 2022.8 and classified as critical. Affected by this vulnerability is the function dmlogin of the file indexDM_load.php of the component Cookie Handler. The manipulation of the argument is_admin with the input y leads to improper authentication. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-254605 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-2f5f-jxgm-vf88

Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0, 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to cause a denial of service (crash) via a BuildContextW request with a large (1) UuidString or (2) GuidIn of a certain length, which causes an out-of-range memory access, aka the MSDTC Denial of Service Vulnerability. NOTE: this is a variant of CVE-2005-2119.

38%
Средний
почти 4 года назад
github логотип
GHSA-2f5f-872q-h83q

Marcus S. Xenakis directory.php script allows remote attackers to execute arbitrary commands via shell metacharacters in the dir parameter.

3%
Низкий
почти 4 года назад

Уязвимостей на страницу