Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 691

Количество 314 691

github логотип

GHSA-2fr9-5jx9-gcx9

больше 2 лет назад

A buffer overflow has been identified in the BoardUpdateAcpiDxe driver in some Lenovo ThinkPad products which may allow an attacker with local access and elevated privileges to execute arbitrary code.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2fr9-2vmq-3h35

8 месяцев назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Devinim Software Library Software allows Reflected XSS.This issue affects Library Software: before 24.11.02.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-2fr8-xhpc-wf7p

больше 3 лет назад

Kibana versions after and including 4.3 and before 4.6.2 are vulnerable to a cross-site scripting (XSS) attack.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2fr8-jp4p-fff3

больше 3 лет назад

InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. A remote attacker could send a carefully crafted packet to exploit a stack-based buffer overflow vulnerability during tag, alarm, or event related actions such as read and write, with potential for code to be executed. If InduSoft Web Studio remote communication security was not enabled, or a password was left blank, a remote user could send a carefully crafted packet to invoke an arbitrary process, with potential for code to be executed. The code would be executed under the privileges of the InduSoft Web Studio or InTouch Edge HMI runtime and could lead to a compromise of the InduSoft Web Studio or InTouch Edge HMI server machine.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2fr8-9j8m-w8vx

больше 3 лет назад

pacman before 5.1.3 allows directory traversal when installing a remote package via a specified URL "pacman -U <url>" due to an unsanitized file name received from a Content-Disposition header. pacman renames the downloaded package file to match the name given in this header. However, pacman did not sanitize this name, which may contain slashes, before calling rename(). A malicious server (or a network MitM if downloading over HTTP) can send a Content-Disposition header to make pacman place the file anywhere in the filesystem, potentially leading to arbitrary root code execution. Notably, this bypasses pacman's package signature checking. This occurs in curl_download_internal in lib/libalpm/dload.c.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2fr8-8x69-5vrv

больше 2 лет назад

spring-boot-actuator-logview 0.2.13 allows Directory Traversal to sibling directories via LogViewEndpoint.view.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2fr8-3p25-cmr5

больше 3 лет назад

The getRunningAppProcesses function in services/core/java/com/android/server/am/ActivityManagerService.java in Android before 5.1.1 LMY48I allows attackers to bypass intended getRecentTasks restrictions and discover the name of the foreground application via a crafted application, aka internal bug 20034603.

EPSS: Низкий
github логотип

GHSA-2fr8-3m4g-cvp7

почти 4 года назад

Multiple unspecified vulnerabilities in PhpGedView before 4.1.5 have unknown impact and attack vectors related to "a fundamental design flaw in the interface (API) to connect phpGedView with external programs like content management systems."

EPSS: Низкий
github логотип

GHSA-2fr7-wcm8-348v

больше 3 лет назад

A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody software (V2.1.13 and prior) that could allow a stack-based buffer overflow to occur which could result in remote code execution when a malicious SSD file is uploaded and improperly parsed.

EPSS: Низкий
github логотип

GHSA-2fr7-cc7p-p45q

около 2 лет назад

Data leak of password hash through change requests

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-2fr6-xf6c-rwpx

больше 3 лет назад

An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1215, CVE-2019-1253, CVE-2019-1278.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2fr2-x46r-5xjg

около 3 лет назад

Open redirect vulnerability in DENSHI NYUSATSU CORE SYSTEM v6 R4 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2fqx-qm63-xqgr

больше 3 лет назад

The Hobby Lobby Stores (aka com.hobbylobbystores.android) application 2.1.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-2fqx-9j9h-4f77

12 месяцев назад

Missing Authorization vulnerability in NotFound LTL Freight Quotes – Unishippers Edition allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects LTL Freight Quotes – Unishippers Edition: from n/a through 2.5.8.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2fqw-v698-338m

больше 3 лет назад

Unrestricted file upload vulnerability in the yccms 3.3 project. The xhUp function's improper judgment of the request parameters, triggers remote code execution.

EPSS: Низкий
github логотип

GHSA-2fqw-684c-pvp7

около 4 лет назад

An issue in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via false link event messages sent to a master ONOS node.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2fqv-m268-vx6f

больше 3 лет назад

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Stored Procedure). Supported versions that are affected are 5.7.18 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-2fqv-h3r5-m4vf

больше 8 лет назад

Cross Site Scripting (XSS) in plotly.js

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2fqv-9f8v-r6j4

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: Fix NULL Dereference in asoc_qcom_lpass_cpu_platform_probe() A devm_kzalloc() in asoc_qcom_lpass_cpu_platform_probe() could possibly return NULL pointer. NULL Pointer Dereference may be triggerred without addtional check. Add a NULL check for the returned pointer.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2fqr-cx7q-3ph8

больше 1 года назад

openstack-heat may disclose sensitive information

CVSS3: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2fr9-5jx9-gcx9

A buffer overflow has been identified in the BoardUpdateAcpiDxe driver in some Lenovo ThinkPad products which may allow an attacker with local access and elevated privileges to execute arbitrary code.

CVSS3: 6.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2fr9-2vmq-3h35

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Devinim Software Library Software allows Reflected XSS.This issue affects Library Software: before 24.11.02.

CVSS3: 4.6
0%
Низкий
8 месяцев назад
github логотип
GHSA-2fr8-xhpc-wf7p

Kibana versions after and including 4.3 and before 4.6.2 are vulnerable to a cross-site scripting (XSS) attack.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2fr8-jp4p-fff3

InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. A remote attacker could send a carefully crafted packet to exploit a stack-based buffer overflow vulnerability during tag, alarm, or event related actions such as read and write, with potential for code to be executed. If InduSoft Web Studio remote communication security was not enabled, or a password was left blank, a remote user could send a carefully crafted packet to invoke an arbitrary process, with potential for code to be executed. The code would be executed under the privileges of the InduSoft Web Studio or InTouch Edge HMI runtime and could lead to a compromise of the InduSoft Web Studio or InTouch Edge HMI server machine.

CVSS3: 9.8
10%
Низкий
больше 3 лет назад
github логотип
GHSA-2fr8-9j8m-w8vx

pacman before 5.1.3 allows directory traversal when installing a remote package via a specified URL "pacman -U <url>" due to an unsanitized file name received from a Content-Disposition header. pacman renames the downloaded package file to match the name given in this header. However, pacman did not sanitize this name, which may contain slashes, before calling rename(). A malicious server (or a network MitM if downloading over HTTP) can send a Content-Disposition header to make pacman place the file anywhere in the filesystem, potentially leading to arbitrary root code execution. Notably, this bypasses pacman's package signature checking. This occurs in curl_download_internal in lib/libalpm/dload.c.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2fr8-8x69-5vrv

spring-boot-actuator-logview 0.2.13 allows Directory Traversal to sibling directories via LogViewEndpoint.view.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2fr8-3p25-cmr5

The getRunningAppProcesses function in services/core/java/com/android/server/am/ActivityManagerService.java in Android before 5.1.1 LMY48I allows attackers to bypass intended getRecentTasks restrictions and discover the name of the foreground application via a crafted application, aka internal bug 20034603.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2fr8-3m4g-cvp7

Multiple unspecified vulnerabilities in PhpGedView before 4.1.5 have unknown impact and attack vectors related to "a fundamental design flaw in the interface (API) to connect phpGedView with external programs like content management systems."

1%
Низкий
почти 4 года назад
github логотип
GHSA-2fr7-wcm8-348v

A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody software (V2.1.13 and prior) that could allow a stack-based buffer overflow to occur which could result in remote code execution when a malicious SSD file is uploaded and improperly parsed.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2fr7-cc7p-p45q

Data leak of password hash through change requests

CVSS3: 7.7
1%
Низкий
около 2 лет назад
github логотип
GHSA-2fr6-xf6c-rwpx

An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1215, CVE-2019-1253, CVE-2019-1278.

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2fr2-x46r-5xjg

Open redirect vulnerability in DENSHI NYUSATSU CORE SYSTEM v6 R4 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-2fqx-qm63-xqgr

The Hobby Lobby Stores (aka com.hobbylobbystores.android) application 2.1.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2fqx-9j9h-4f77

Missing Authorization vulnerability in NotFound LTL Freight Quotes – Unishippers Edition allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects LTL Freight Quotes – Unishippers Edition: from n/a through 2.5.8.

CVSS3: 6.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-2fqw-v698-338m

Unrestricted file upload vulnerability in the yccms 3.3 project. The xhUp function's improper judgment of the request parameters, triggers remote code execution.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-2fqw-684c-pvp7

An issue in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via false link event messages sent to a master ONOS node.

CVSS3: 8.1
0%
Низкий
около 4 лет назад
github логотип
GHSA-2fqv-m268-vx6f

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Stored Procedure). Supported versions that are affected are 5.7.18 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2fqv-h3r5-m4vf

Cross Site Scripting (XSS) in plotly.js

CVSS3: 6.1
1%
Низкий
больше 8 лет назад
github логотип
GHSA-2fqv-9f8v-r6j4

In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: Fix NULL Dereference in asoc_qcom_lpass_cpu_platform_probe() A devm_kzalloc() in asoc_qcom_lpass_cpu_platform_probe() could possibly return NULL pointer. NULL Pointer Dereference may be triggerred without addtional check. Add a NULL check for the returned pointer.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2fqr-cx7q-3ph8

openstack-heat may disclose sensitive information

CVSS3: 5
1%
Низкий
больше 1 года назад

Уязвимостей на страницу