Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2gmr-48xr-j34m

почти 4 года назад

Stack-based buffer overflow in emacs allows user-assisted attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a large precision value in an integer format string specifier to the format function, as demonstrated via a certain "emacs -batch -eval" command line.

EPSS: Низкий
github логотип

GHSA-2gmr-34h7-prwx

8 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpsoul Greenshift allows DOM-Based XSS. This issue affects Greenshift: from n/a through 11.5.5.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2gmr-2pr2-53jf

почти 4 года назад

Multiple stack-based buffer overflows in CFProfile.exe in Toshiba ConfigFree Utility 8.0.38 allow user-assisted attackers to execute arbitrary code.

EPSS: Низкий
github логотип

GHSA-2gmq-r86r-gvhw

больше 3 лет назад

Stack-based buffer overflow in the "Add from text file" feature in the DameWare Exporter tool (DWExporter.exe) in DameWare Remote Support 10.0.0.372, 9.0.1.247, and earlier allows user-assisted attackers to execute arbitrary code via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2gmq-m9wq-x923

больше 3 лет назад

In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06493873; Issue ID: ALPS06493899.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2gmq-3r6v-g7jx

почти 4 года назад

Stack-based buffer overflow in the IASystemInfo.dll ActiveX control in (1) InterActual Player 2.60.12.0717, (2) Roxio CinePlayer 3.2, (3) WinDVD 7.0.27.172, and possibly other products, allows remote attackers to execute arbitrary code via a long ApplicationType property.

EPSS: Высокий
github логотип

GHSA-2gmp-x9r7-xp6q

больше 1 года назад

Improper Null Termination vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of10::Port:unpack. This issue affects libfluid: 0.1.0.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2gmp-hjmm-v2wx

около 3 лет назад

Incorrect Access Control issue discoverd in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to write arbitrary files via improper sanitation on the source for COPY and MOVE operations.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-2gmp-cvhp-m5qp

больше 3 лет назад

Cisco AnyConnect Secure Mobility Client before 4.2.05015 and 4.3.x before 4.3.02039 mishandles pathnames, which allows local users to gain privileges via a crafted INF file, aka Bug ID CSCuz92464.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2gmp-8pr5-3jc6

больше 3 лет назад

In JetBrains TeamCity before 2020.2.4, there was an insecure deserialization.

EPSS: Низкий
github логотип

GHSA-2gmp-3cgc-4vg7

больше 3 лет назад

JetBrains YouTrack before 2021.3.24402 is vulnerable to stored XSS.

EPSS: Низкий
github логотип

GHSA-2gmm-fh28-fr6w

около 1 года назад

vmir e8117 was discovered to contain a segmentation violation via the import_function function at /src/vmir_wasm_parser.c.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2gmm-8x35-3cmg

почти 4 года назад

V8 in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android was missing a neutering check, which allowed a remote attacker to read values in memory via a crafted HTML page.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2gmm-4f9j-mw4p

больше 2 лет назад

Use after free in Tab Groups in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2gmj-rvcm-f6j2

больше 3 лет назад

An Improper Data Validation Vulnerability exists in Webmin 1.941 and earlier affecting the Command Shell Endpoint. A user may enter HTML code into the Command field and submit it. Then, after visiting the Action Logs Menu and displaying logs, the HTML code will be rendered (however, JavaScript is not executed). Changes are kept across users.

EPSS: Низкий
github логотип

GHSA-2gmh-429f-mh43

почти 3 года назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2gmf-r44x-7p56

больше 3 лет назад

Open redirect vulnerability in track-click.php in the Ad-Manager plugin 1.1.2 for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the out parameter.

EPSS: Низкий
github логотип

GHSA-2gmf-r36r-hhcw

больше 3 лет назад

cfg_init in confuse.c in libConfuse 3.2.2 has a memory leak.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2gmf-mp9h-g5xw

около 2 лет назад

Non-Transparent Sharing of Microarchitectural Resources in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable information disclosure via local access.

CVSS3: 4.1
EPSS: Низкий
github логотип

GHSA-2gmf-jvqr-r553

больше 3 лет назад

SQL Injection exists in the JS Jobs 1.1.9 component for Joomla! via the zipcode parameter in a newest-jobs request, or the ta parameter in a view_resume request.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2gmr-48xr-j34m

Stack-based buffer overflow in emacs allows user-assisted attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a large precision value in an integer format string specifier to the format function, as demonstrated via a certain "emacs -batch -eval" command line.

3%
Низкий
почти 4 года назад
github логотип
GHSA-2gmr-34h7-prwx

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpsoul Greenshift allows DOM-Based XSS. This issue affects Greenshift: from n/a through 11.5.5.

CVSS3: 6.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-2gmr-2pr2-53jf

Multiple stack-based buffer overflows in CFProfile.exe in Toshiba ConfigFree Utility 8.0.38 allow user-assisted attackers to execute arbitrary code.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2gmq-r86r-gvhw

Stack-based buffer overflow in the "Add from text file" feature in the DameWare Exporter tool (DWExporter.exe) in DameWare Remote Support 10.0.0.372, 9.0.1.247, and earlier allows user-assisted attackers to execute arbitrary code via unspecified vectors.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-2gmq-m9wq-x923

In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06493873; Issue ID: ALPS06493899.

CVSS3: 6.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2gmq-3r6v-g7jx

Stack-based buffer overflow in the IASystemInfo.dll ActiveX control in (1) InterActual Player 2.60.12.0717, (2) Roxio CinePlayer 3.2, (3) WinDVD 7.0.27.172, and possibly other products, allows remote attackers to execute arbitrary code via a long ApplicationType property.

72%
Высокий
почти 4 года назад
github логотип
GHSA-2gmp-x9r7-xp6q

Improper Null Termination vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of10::Port:unpack. This issue affects libfluid: 0.1.0.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2gmp-hjmm-v2wx

Incorrect Access Control issue discoverd in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to write arbitrary files via improper sanitation on the source for COPY and MOVE operations.

CVSS3: 9.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-2gmp-cvhp-m5qp

Cisco AnyConnect Secure Mobility Client before 4.2.05015 and 4.3.x before 4.3.02039 mishandles pathnames, which allows local users to gain privileges via a crafted INF file, aka Bug ID CSCuz92464.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2gmp-8pr5-3jc6

In JetBrains TeamCity before 2020.2.4, there was an insecure deserialization.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2gmp-3cgc-4vg7

JetBrains YouTrack before 2021.3.24402 is vulnerable to stored XSS.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2gmm-fh28-fr6w

vmir e8117 was discovered to contain a segmentation violation via the import_function function at /src/vmir_wasm_parser.c.

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2gmm-8x35-3cmg

V8 in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android was missing a neutering check, which allowed a remote attacker to read values in memory via a crafted HTML page.

CVSS3: 4.3
3%
Низкий
почти 4 года назад
github логотип
GHSA-2gmm-4f9j-mw4p

Use after free in Tab Groups in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2gmj-rvcm-f6j2

An Improper Data Validation Vulnerability exists in Webmin 1.941 and earlier affecting the Command Shell Endpoint. A user may enter HTML code into the Command field and submit it. Then, after visiting the Action Logs Menu and displaying logs, the HTML code will be rendered (however, JavaScript is not executed). Changes are kept across users.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-2gmh-429f-mh43

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 6.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-2gmf-r44x-7p56

Open redirect vulnerability in track-click.php in the Ad-Manager plugin 1.1.2 for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the out parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2gmf-r36r-hhcw

cfg_init in confuse.c in libConfuse 3.2.2 has a memory leak.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2gmf-mp9h-g5xw

Non-Transparent Sharing of Microarchitectural Resources in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable information disclosure via local access.

CVSS3: 4.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-2gmf-jvqr-r553

SQL Injection exists in the JS Jobs 1.1.9 component for Joomla! via the zipcode parameter in a newest-jobs request, or the ta parameter in a view_resume request.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу