Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2h39-83vm-vq42

больше 1 года назад

A denial of service exists in Gvisor Sandbox where a bug in reference counting code in mount point tracking could lead to a panic, making it possible for an attacker running as root and with permission to mount volumes to kill the sandbox. We recommend upgrading past commit 6a112c60a257dadac59962e0bc9e9b5aee70b5b6

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2h38-rw9c-6j5p

больше 3 лет назад

Admin Framework in Apple OS X before 10.10.4 does not properly restrict the location of writeconfig clients, which allows local users to obtain root privileges by moving and then modifying Directory Utility.

EPSS: Низкий
github логотип

GHSA-2h38-3p2h-p683

почти 4 года назад

Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Survey Maker WordPress plugin (versions <= 2.0.6).

EPSS: Низкий
github логотип

GHSA-2h37-p8hq-v395

больше 3 лет назад

A reflected cross-site scripting vulnerability exists in Geutebrueck re_porter 16 before 7.8.974.20 by appending a query string to /modifychannel/exec or /images/*.png on TCP port 12005.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2h36-h7fr-hrvc

почти 4 года назад

In RuoYi v4.7.2 through the WebUI, user test1 does not have permission to reset the password of user test3, but the password of user test3 can be reset through the /system/user/resetPwd request.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2h36-2cxh-4whm

больше 3 лет назад

A lock screen issue was addressed with improved state management. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16, macOS Ventura 13. A user may be able to view restricted content from the lock screen.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-2h35-xq9p-w64x

больше 2 лет назад

Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of weak password requirements. A remote attacker with regular user privilege can easily infer the administrator password from system information after logging system, resulting in admin access and performing arbitrary system operations or disrupt service.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2h35-rff7-6q25

почти 4 года назад

Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as used in multiple CA products including BrightStor ARCserve Backup R11.5, Desktop Management Suite r11.1 through r11.2, and Unicenter products r11.1 through r11.2, allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a long argument to the AddColumn method.

EPSS: Высокий
github логотип

GHSA-2h35-j3ph-hx4j

почти 4 года назад

Cross-site scripting (XSS) vulnerability in TigerTom TTCalc 1.0 allows remote attackers to inject arbitrary web script or HTML via the year parameter in (1) loan.php and (2) mortgage.php.

EPSS: Низкий
github логотип

GHSA-2h35-g555-434h

около 4 лет назад

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16.6, RBK852 before 3.2.16.6, RBR850 before 3.2.16.6, and RBS850 before 3.2.16.6.

EPSS: Низкий
github логотип

GHSA-2h34-mpx5-85mq

около 3 лет назад

Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SafeEmailFilter.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2h34-774g-95vx

больше 3 лет назад

The ssl-proxy-openssl.c function in Dovecot before 2.2.17, when SSLv3 is disabled, allow remote attackers to cause a denial of service (login process crash) via vectors related to handshake failures.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2h34-5q7q-g4h6

больше 2 лет назад

In startInput of AudioPolicyInterfaceImpl.cpp, there is a possible way of erroneously displaying the microphone privacy indicator due to a race condition. This could lead to false user expectations. User interaction is needed for exploitation.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-2h33-8gg4-v626

больше 3 лет назад

Cisco IOS before 15.1(1)SY allows local users to cause a denial of service (device reload) by establishing an outbound SSH session, aka Bug ID CSCto00318.

EPSS: Низкий
github логотип

GHSA-2h32-xchg-737h

больше 3 лет назад

A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook. This CVE ID is unique from CVE-2018-8524, CVE-2018-8576, CVE-2018-8582.

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-2h32-w2mf-v4c7

4 месяца назад

When Diffie-Hellman (DH) group Elliptic Curve Cryptography (ECC) Brainpool curves are configured in an SSL profile's Cipher Rule or Cipher Group, and that profile is applied to a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2h32-h397-qgv2

около 2 лет назад

An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. If the publisher criteria is selected, it defines the name of a publisher that must be present in the certificate (and also requires that the certificate is valid). If an Add Admin token is protected by this criteria, it can be leveraged by a malicious actor to achieve Elevation of Privileges from standard user to administrator.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2h32-fhf6-xhh5

больше 3 лет назад

Microsoft MSHTML Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Критический
github логотип

GHSA-2h32-8m9m-ccc3

около 3 лет назад

Information disclosure due to buffer over-read in Bluetooth HOST while pairing and connecting A2DP. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2h2x-qrfm-pcx6

почти 4 года назад

The HxTocCtrl ActiveX control (hxvz.dll), as used in Microsoft Internet Explorer 5.01 SP4 and 6 SP1, in Windows XP SP2, Server 2003 SP1 and SP2, Vista SP1, and Server 2008, allows remote attackers to execute arbitrary code via malformed arguments, which triggers memory corruption.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2h39-83vm-vq42

A denial of service exists in Gvisor Sandbox where a bug in reference counting code in mount point tracking could lead to a panic, making it possible for an attacker running as root and with permission to mount volumes to kill the sandbox. We recommend upgrading past commit 6a112c60a257dadac59962e0bc9e9b5aee70b5b6

CVSS3: 4.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2h38-rw9c-6j5p

Admin Framework in Apple OS X before 10.10.4 does not properly restrict the location of writeconfig clients, which allows local users to obtain root privileges by moving and then modifying Directory Utility.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-2h38-3p2h-p683

Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Survey Maker WordPress plugin (versions <= 2.0.6).

1%
Низкий
почти 4 года назад
github логотип
GHSA-2h37-p8hq-v395

A reflected cross-site scripting vulnerability exists in Geutebrueck re_porter 16 before 7.8.974.20 by appending a query string to /modifychannel/exec or /images/*.png on TCP port 12005.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2h36-h7fr-hrvc

In RuoYi v4.7.2 through the WebUI, user test1 does not have permission to reset the password of user test3, but the password of user test3 can be reset through the /system/user/resetPwd request.

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-2h36-2cxh-4whm

A lock screen issue was addressed with improved state management. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16, macOS Ventura 13. A user may be able to view restricted content from the lock screen.

CVSS3: 4.6
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2h35-xq9p-w64x

Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of weak password requirements. A remote attacker with regular user privilege can easily infer the administrator password from system information after logging system, resulting in admin access and performing arbitrary system operations or disrupt service.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2h35-rff7-6q25

Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as used in multiple CA products including BrightStor ARCserve Backup R11.5, Desktop Management Suite r11.1 through r11.2, and Unicenter products r11.1 through r11.2, allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a long argument to the AddColumn method.

76%
Высокий
почти 4 года назад
github логотип
GHSA-2h35-j3ph-hx4j

Cross-site scripting (XSS) vulnerability in TigerTom TTCalc 1.0 allows remote attackers to inject arbitrary web script or HTML via the year parameter in (1) loan.php and (2) mortgage.php.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2h35-g555-434h

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16.6, RBK852 before 3.2.16.6, RBR850 before 3.2.16.6, and RBS850 before 3.2.16.6.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2h34-mpx5-85mq

Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SafeEmailFilter.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-2h34-774g-95vx

The ssl-proxy-openssl.c function in Dovecot before 2.2.17, when SSLv3 is disabled, allow remote attackers to cause a denial of service (login process crash) via vectors related to handshake failures.

CVSS3: 5.9
8%
Низкий
больше 3 лет назад
github логотип
GHSA-2h34-5q7q-g4h6

In startInput of AudioPolicyInterfaceImpl.cpp, there is a possible way of erroneously displaying the microphone privacy indicator due to a race condition. This could lead to false user expectations. User interaction is needed for exploitation.

CVSS3: 3.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2h33-8gg4-v626

Cisco IOS before 15.1(1)SY allows local users to cause a denial of service (device reload) by establishing an outbound SSH session, aka Bug ID CSCto00318.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2h32-xchg-737h

A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook. This CVE ID is unique from CVE-2018-8524, CVE-2018-8576, CVE-2018-8582.

CVSS3: 7.8
25%
Средний
больше 3 лет назад
github логотип
GHSA-2h32-w2mf-v4c7

When Diffie-Hellman (DH) group Elliptic Curve Cryptography (ECC) Brainpool curves are configured in an SSL profile's Cipher Rule or Cipher Group, and that profile is applied to a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 7.5
0%
Низкий
4 месяца назад
github логотип
GHSA-2h32-h397-qgv2

An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. If the publisher criteria is selected, it defines the name of a publisher that must be present in the certificate (and also requires that the certificate is valid). If an Add Admin token is protected by this criteria, it can be leveraged by a malicious actor to achieve Elevation of Privileges from standard user to administrator.

CVSS3: 7.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-2h32-fhf6-xhh5

Microsoft MSHTML Remote Code Execution Vulnerability

CVSS3: 7.8
94%
Критический
больше 3 лет назад
github логотип
GHSA-2h32-8m9m-ccc3

Information disclosure due to buffer over-read in Bluetooth HOST while pairing and connecting A2DP. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVSS3: 8.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-2h2x-qrfm-pcx6

The HxTocCtrl ActiveX control (hxvz.dll), as used in Microsoft Internet Explorer 5.01 SP4 and 6 SP1, in Windows XP SP2, Server 2003 SP1 and SP2, Vista SP1, and Server 2008, allows remote attackers to execute arbitrary code via malformed arguments, which triggers memory corruption.

59%
Средний
почти 4 года назад

Уязвимостей на страницу