Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 212

Количество 314 212

github логотип

GHSA-2g8x-wxp8-jhpg

больше 1 года назад

A vulnerability in the DHCP Snooping feature of Cisco IOS XE Software on Software-Defined Access (SD-Access) fabric edge nodes could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected device, resulting in a denial of service (DoS) condition that requires a manual reload to recover. This vulnerability is due to improper handling of IPv4 DHCP packets. An attacker could exploit this vulnerability by sending certain IPv4 DHCP packets to an affected device. A successful exploit could allow the attacker to cause the device to exhaust CPU resources and stop processing traffic, resulting in a DoS condition that requires a manual reload to recover.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-2g8x-m9jv-c9cq

больше 3 лет назад

In loop of DnsTlsSocket.cpp, there is a possible heap memory corruption due to a use after free. This could lead to remote code execution in the netd server with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-122856181.

EPSS: Низкий
github логотип

GHSA-2g8x-g9vv-crxp

почти 4 года назад

Cross-site scripting (XSS) vulnerability in calendar/Visitor.cgi in KCScripts Calendar, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the sort_order parameter.

EPSS: Низкий
github логотип

GHSA-2g8x-g9fp-q786

почти 4 года назад

Improper size check in sapefd_parse_meta_HEADER function of libsapeextractor library prior to SMR Apr-2022 Release 1 allows out of bounds read via a crafted media file.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2g8x-3m62-h85f

больше 3 лет назад

In the GNU C Library (aka glibc or libc6) through 2.29, the memcmp function for the x32 architecture can incorrectly return zero (indicating that the inputs are equal) because the RDX most significant bit is mishandled.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2g8w-m86w-fcpc

больше 3 лет назад

Memory leak in coders/mpc.c in ImageMagick before 6.9.7-4 and 7.x before 7.0.4-4 allows remote attackers to cause a denial of service (memory consumption) via vectors involving a pixel cache.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-2g8w-9933-36vr

7 месяцев назад

Jenkins Warrior Framework Plugin vulnerability exposes unencrypted passwords to certain authenticated users

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2g8r-g5wp-xcxp

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: netfs: Only call folio_start_fscache() one time for each folio If a network filesystem using netfs implements a clamp_length() function, it can set subrequest lengths smaller than a page size. When we loop through the folios in netfs_rreq_unlock_folios() to set any folios to be written back, we need to make sure we only call folio_start_fscache() once for each folio. Otherwise, this simple testcase: mount -o fsc,rsize=1024,wsize=1024 127.0.0.1:/export /mnt/nfs dd if=/dev/zero of=/mnt/nfs/file.bin bs=4096 count=1 1+0 records in 1+0 records out 4096 bytes (4.1 kB, 4.0 KiB) copied, 0.0126359 s, 324 kB/s echo 3 > /proc/sys/vm/drop_caches cat /mnt/nfs/file.bin > /dev/null will trigger an oops similar to the following: page dumped because: VM_BUG_ON_FOLIO(folio_test_private_2(folio)) ------------[ cut here ]------------ kernel BUG at include/linux/netfs.h:44! ... CPU: 5 PID: 134 Comm: kworke...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2g8p-j2r6-vqpj

больше 2 лет назад

Withdrawn Advisory: October Cross-site Scripting vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2g8p-8mm7-ff75

больше 3 лет назад

Off-by-one error in the pcapng_read function in wiretap/pcapng.c in the pcapng file parser in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.4 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via an invalid Interface Statistics Block (ISB) interface ID in a crafted packet.

EPSS: Низкий
github логотип

GHSA-2g8m-x62g-5m9w

около 2 месяцев назад

RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of RealDefense SUPERAntiSpyware. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the SAS Core Service. The issue results from an exposed dangerous function. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-27659.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2g8j-3jgp-qrrv

5 месяцев назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Dmitry V. (CEO of "UKR Solution") UPC/EAN/GTIN Code Generator allows Path Traversal. This issue affects UPC/EAN/GTIN Code Generator: from n/a through 2.0.2.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-2g8j-23q2-f55c

6 месяцев назад

In GStreamer through 1.26.1, the subparse plugin's parse_subrip_time function may write data past the bounds of a stack buffer, leading to a crash.

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-2g8h-33rh-hp24

11 месяцев назад

The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.3.6 via the /wp-json/post-grid/v2/get_users REST API This makes it possible for unauthenticated attackers to extract sensitive data including including emails and other user data.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2g8g-jgx2-36mh

7 месяцев назад

A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been classified as critical. This affects an unknown part of the file /panel/schedule-staff.php. The manipulation of the argument staff_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2g8g-ghh7-j7r3

больше 3 лет назад

Improper input validation in obs-service-tar_scm of Open Build Service allows remote attackers to cause access and extract information outside the current build or cause the creation of file in attacker controlled locations. Affected releases are openSUSE Open Build Service: versions prior to 51a17c553b6ae2598820b7a90fd0c11502a49106.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2g8g-63j4-9w3r

около 4 лет назад

RCE vulnerability affecting v1beta3 templates in @backstage/plugin-scaffolder-backend

EPSS: Низкий
github логотип

GHSA-2g8g-29wv-3hm6

больше 3 лет назад

A vulnerability in the routine that loads DLL files in Cisco Meeting App for Windows could allow an authenticated, local attacker to run an executable file with privileges equivalent to those of Cisco Meeting App. The vulnerability is due to incomplete input validation of the path name for DLL files before they are loaded. An attacker could exploit this vulnerability by installing a crafted DLL file in a specific system directory. A successful exploit could allow the attacker to execute commands on the underlying Microsoft Windows host with privileges equivalent to those of Cisco Meeting App. The attacker would need valid user credentials to exploit this vulnerability. Cisco Bug IDs: CSCvd77907.

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-2g8f-vcw3-hp3m

больше 2 лет назад

In JetBrains TeamCity before 2023.05 stored XSS in the Show Connection page was possible

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-2g8f-fvqm-f24v

почти 3 года назад

SQL Injection in the Hardware Inventory report of Security Center 5.11.2.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2g8x-wxp8-jhpg

A vulnerability in the DHCP Snooping feature of Cisco IOS XE Software on Software-Defined Access (SD-Access) fabric edge nodes could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected device, resulting in a denial of service (DoS) condition that requires a manual reload to recover. This vulnerability is due to improper handling of IPv4 DHCP packets. An attacker could exploit this vulnerability by sending certain IPv4 DHCP packets to an affected device. A successful exploit could allow the attacker to cause the device to exhaust CPU resources and stop processing traffic, resulting in a DoS condition that requires a manual reload to recover.

CVSS3: 8.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-2g8x-m9jv-c9cq

In loop of DnsTlsSocket.cpp, there is a possible heap memory corruption due to a use after free. This could lead to remote code execution in the netd server with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-122856181.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2g8x-g9vv-crxp

Cross-site scripting (XSS) vulnerability in calendar/Visitor.cgi in KCScripts Calendar, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the sort_order parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2g8x-g9fp-q786

Improper size check in sapefd_parse_meta_HEADER function of libsapeextractor library prior to SMR Apr-2022 Release 1 allows out of bounds read via a crafted media file.

CVSS3: 7.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-2g8x-3m62-h85f

In the GNU C Library (aka glibc or libc6) through 2.29, the memcmp function for the x32 architecture can incorrectly return zero (indicating that the inputs are equal) because the RDX most significant bit is mishandled.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2g8w-m86w-fcpc

Memory leak in coders/mpc.c in ImageMagick before 6.9.7-4 and 7.x before 7.0.4-4 allows remote attackers to cause a denial of service (memory consumption) via vectors involving a pixel cache.

CVSS3: 7.5
11%
Средний
больше 3 лет назад
github логотип
GHSA-2g8w-9933-36vr

Jenkins Warrior Framework Plugin vulnerability exposes unencrypted passwords to certain authenticated users

CVSS3: 4.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-2g8r-g5wp-xcxp

In the Linux kernel, the following vulnerability has been resolved: netfs: Only call folio_start_fscache() one time for each folio If a network filesystem using netfs implements a clamp_length() function, it can set subrequest lengths smaller than a page size. When we loop through the folios in netfs_rreq_unlock_folios() to set any folios to be written back, we need to make sure we only call folio_start_fscache() once for each folio. Otherwise, this simple testcase: mount -o fsc,rsize=1024,wsize=1024 127.0.0.1:/export /mnt/nfs dd if=/dev/zero of=/mnt/nfs/file.bin bs=4096 count=1 1+0 records in 1+0 records out 4096 bytes (4.1 kB, 4.0 KiB) copied, 0.0126359 s, 324 kB/s echo 3 > /proc/sys/vm/drop_caches cat /mnt/nfs/file.bin > /dev/null will trigger an oops similar to the following: page dumped because: VM_BUG_ON_FOLIO(folio_test_private_2(folio)) ------------[ cut here ]------------ kernel BUG at include/linux/netfs.h:44! ... CPU: 5 PID: 134 Comm: kworke...

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-2g8p-j2r6-vqpj

Withdrawn Advisory: October Cross-site Scripting vulnerability

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2g8p-8mm7-ff75

Off-by-one error in the pcapng_read function in wiretap/pcapng.c in the pcapng file parser in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.4 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via an invalid Interface Statistics Block (ISB) interface ID in a crafted packet.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2g8m-x62g-5m9w

RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of RealDefense SUPERAntiSpyware. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the SAS Core Service. The issue results from an exposed dangerous function. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-27659.

CVSS3: 7.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2g8j-3jgp-qrrv

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Dmitry V. (CEO of "UKR Solution") UPC/EAN/GTIN Code Generator allows Path Traversal. This issue affects UPC/EAN/GTIN Code Generator: from n/a through 2.0.2.

CVSS3: 7.7
0%
Низкий
5 месяцев назад
github логотип
GHSA-2g8j-23q2-f55c

In GStreamer through 1.26.1, the subparse plugin's parse_subrip_time function may write data past the bounds of a stack buffer, leading to a crash.

CVSS3: 5.6
0%
Низкий
6 месяцев назад
github логотип
GHSA-2g8h-33rh-hp24

The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.3.6 via the /wp-json/post-grid/v2/get_users REST API This makes it possible for unauthenticated attackers to extract sensitive data including including emails and other user data.

CVSS3: 5.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-2g8g-jgx2-36mh

A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been classified as critical. This affects an unknown part of the file /panel/schedule-staff.php. The manipulation of the argument staff_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-2g8g-ghh7-j7r3

Improper input validation in obs-service-tar_scm of Open Build Service allows remote attackers to cause access and extract information outside the current build or cause the creation of file in attacker controlled locations. Affected releases are openSUSE Open Build Service: versions prior to 51a17c553b6ae2598820b7a90fd0c11502a49106.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2g8g-63j4-9w3r

RCE vulnerability affecting v1beta3 templates in @backstage/plugin-scaffolder-backend

около 4 лет назад
github логотип
GHSA-2g8g-29wv-3hm6

A vulnerability in the routine that loads DLL files in Cisco Meeting App for Windows could allow an authenticated, local attacker to run an executable file with privileges equivalent to those of Cisco Meeting App. The vulnerability is due to incomplete input validation of the path name for DLL files before they are loaded. An attacker could exploit this vulnerability by installing a crafted DLL file in a specific system directory. A successful exploit could allow the attacker to execute commands on the underlying Microsoft Windows host with privileges equivalent to those of Cisco Meeting App. The attacker would need valid user credentials to exploit this vulnerability. Cisco Bug IDs: CSCvd77907.

CVSS3: 4.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2g8f-vcw3-hp3m

In JetBrains TeamCity before 2023.05 stored XSS in the Show Connection page was possible

CVSS3: 4.6
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2g8f-fvqm-f24v

SQL Injection in the Hardware Inventory report of Security Center 5.11.2.

CVSS3: 8.8
0%
Низкий
почти 3 года назад

Уязвимостей на страницу