Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 313 159

Количество 313 159

github логотип

GHSA-262c-877p-cgmx

больше 3 лет назад

TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-enable variable in the pptp_server.lua file.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-262c-7vhp-vjrh

больше 2 лет назад

In music service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-2628-4jvp-96vc

2 месяца назад

Use-after-free in the Audio/Video: GMP component. This vulnerability affects Firefox < 146.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2627-h6q4-h8xq

10 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: dp: drm_err => dev_err in HPD path to avoid NULL ptr The function mtk_dp_wait_hpd_asserted() may be called before the `mtk_dp->drm_dev` pointer is assigned in mtk_dp_bridge_attach(). Specifically it can be called via this callpath: - mtk_edp_wait_hpd_asserted - [panel probe] - dp_aux_ep_probe Using "drm" level prints anywhere in this callpath causes a NULL pointer dereference. Change the error message directly in mtk_dp_wait_hpd_asserted() to dev_err() to avoid this. Also change the error messages in mtk_dp_parse_capabilities(), which is called by mtk_dp_wait_hpd_asserted(). While touching these prints, also add the error code to them to make future debugging easier.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2626-fg73-6xgq

больше 3 лет назад

An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. The issue involves the "Wi-Fi" component. It might allow remote attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via crafted Wi-Fi traffic that leverages a race condition.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2625-j643-gg22

больше 1 года назад

libmodbus v3.1.6 was discovered to contain a use-after-free via the ctx->backend pointer. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted message sent to the unit-test-server.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2624-69c2-835g

больше 3 лет назад

Improper authentication in the installer for the Intel(R) NUC M15 Laptop Kit Management Engine driver pack before version 15.0.10.1508 may allow an authenticated user to potentially enable denial of service via local access.

EPSS: Низкий
github логотип

GHSA-2623-h3mc-wm8w

около 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in RaymondDesign Post & Page Notes allows Stored XSS.This issue affects Post & Page Notes: from n/a through 0.1.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2623-fqch-p6pf

почти 4 года назад

Datalex PLC BookIt! Consumer before 2.2 stores usernames and passwords in plaintext in a cookie, which could allow remote attackers to gain privileges via Cross-site scripting or sniffing attacks.

EPSS: Низкий
github логотип

GHSA-2623-9jvf-x9v2

больше 3 лет назад

An authorization bypass vulnerability in Monitorr v1.7.6m in Monitorr/assets/config/_installation/_register.php allows an unauthorized person to create valid credentials.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2623-7ghf-34hg

около 2 лет назад

A vulnerability classified as problematic has been found in DeShang DSCMS up to 3.1.2/7.1. Affected is an unknown function of the file public/install.php. The manipulation leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-250434 is the identifier assigned to this vulnerability.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-25xx-rcpp-w7mf

больше 3 лет назад

Use-after-free vulnerability in Google Chrome before 23.0.1271.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to printing.

EPSS: Низкий
github логотип

GHSA-25xx-qj5q-8gm9

больше 3 лет назад

The _rsvg_node_poly_build_path function in rsvg-shapes.c in librsvg before 2.40.7 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via an odd number of elements in a coordinate pair in an SVG document.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-25xv-g2pj-97p3

почти 4 года назад

Integer signedness error in vserver in SAP MaxDB 7.6.0.37, and possibly other versions, allows remote attackers to execute arbitrary code via unknown vectors that trigger heap corruption.

EPSS: Низкий
github логотип

GHSA-25xv-9777-w8wm

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in privmsg.php in phpBB 2.0.6 allow remote attackers to execute arbitrary script or HTML via the (1) folder or (2) mode variables.

EPSS: Низкий
github логотип

GHSA-25xr-qqmw-vc8p

больше 3 лет назад

Multiple integer overflows in minzip/SysUtil.c in the Recovery Procedure in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allow attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26960931.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-25xr-qj8w-c4vf

7 месяцев назад

Apache Tomcat Coyote vulnerable to Denial of Service via excessive HTTP/2 streams

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-25xq-f8xm-q632

11 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in wpsolutions SoundCloud Ultimate allows Cross Site Request Forgery. This issue affects SoundCloud Ultimate: from n/a through 1.5.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-25xp-q574-q8mf

больше 3 лет назад

Vulnerability in the Oracle Advanced Outbound Telephony component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Advanced Outbound Telephony, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Outbound Telephony accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Outbound Telephony accessible data. CVSS v3.0 Base Score 8.2 (Confidentiality and Integrity impacts).

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-25xp-grv3-xwjh

больше 3 лет назад

Use-after-free vulnerability in Foxit Reader and PhantomPDF 7.3.4.311 and earlier on Windows allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via a crafted PDF file.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-262c-877p-cgmx

TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-enable variable in the pptp_server.lua file.

CVSS3: 7.2
1%
Низкий
больше 3 лет назад
github логотип
GHSA-262c-7vhp-vjrh

In music service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

CVSS3: 3.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2628-4jvp-96vc

Use-after-free in the Audio/Video: GMP component. This vulnerability affects Firefox < 146.

CVSS3: 9.8
0%
Низкий
2 месяца назад
github логотип
GHSA-2627-h6q4-h8xq

In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: dp: drm_err => dev_err in HPD path to avoid NULL ptr The function mtk_dp_wait_hpd_asserted() may be called before the `mtk_dp->drm_dev` pointer is assigned in mtk_dp_bridge_attach(). Specifically it can be called via this callpath: - mtk_edp_wait_hpd_asserted - [panel probe] - dp_aux_ep_probe Using "drm" level prints anywhere in this callpath causes a NULL pointer dereference. Change the error message directly in mtk_dp_wait_hpd_asserted() to dev_err() to avoid this. Also change the error messages in mtk_dp_parse_capabilities(), which is called by mtk_dp_wait_hpd_asserted(). While touching these prints, also add the error code to them to make future debugging easier.

CVSS3: 5.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-2626-fg73-6xgq

An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. The issue involves the "Wi-Fi" component. It might allow remote attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via crafted Wi-Fi traffic that leverages a race condition.

CVSS3: 8.1
8%
Низкий
больше 3 лет назад
github логотип
GHSA-2625-j643-gg22

libmodbus v3.1.6 was discovered to contain a use-after-free via the ctx->backend pointer. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted message sent to the unit-test-server.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2624-69c2-835g

Improper authentication in the installer for the Intel(R) NUC M15 Laptop Kit Management Engine driver pack before version 15.0.10.1508 may allow an authenticated user to potentially enable denial of service via local access.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2623-h3mc-wm8w

Cross-Site Request Forgery (CSRF) vulnerability in RaymondDesign Post & Page Notes allows Stored XSS.This issue affects Post & Page Notes: from n/a through 0.1.1.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-2623-fqch-p6pf

Datalex PLC BookIt! Consumer before 2.2 stores usernames and passwords in plaintext in a cookie, which could allow remote attackers to gain privileges via Cross-site scripting or sniffing attacks.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2623-9jvf-x9v2

An authorization bypass vulnerability in Monitorr v1.7.6m in Monitorr/assets/config/_installation/_register.php allows an unauthorized person to create valid credentials.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2623-7ghf-34hg

A vulnerability classified as problematic has been found in DeShang DSCMS up to 3.1.2/7.1. Affected is an unknown function of the file public/install.php. The manipulation leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-250434 is the identifier assigned to this vulnerability.

CVSS3: 5.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-25xx-rcpp-w7mf

Use-after-free vulnerability in Google Chrome before 23.0.1271.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to printing.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-25xx-qj5q-8gm9

The _rsvg_node_poly_build_path function in rsvg-shapes.c in librsvg before 2.40.7 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via an odd number of elements in a coordinate pair in an SVG document.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-25xv-g2pj-97p3

Integer signedness error in vserver in SAP MaxDB 7.6.0.37, and possibly other versions, allows remote attackers to execute arbitrary code via unknown vectors that trigger heap corruption.

4%
Низкий
почти 4 года назад
github логотип
GHSA-25xv-9777-w8wm

Multiple cross-site scripting (XSS) vulnerabilities in privmsg.php in phpBB 2.0.6 allow remote attackers to execute arbitrary script or HTML via the (1) folder or (2) mode variables.

7%
Низкий
почти 4 года назад
github логотип
GHSA-25xr-qqmw-vc8p

Multiple integer overflows in minzip/SysUtil.c in the Recovery Procedure in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allow attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26960931.

CVSS3: 8.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-25xr-qj8w-c4vf

Apache Tomcat Coyote vulnerable to Denial of Service via excessive HTTP/2 streams

CVSS3: 7.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-25xq-f8xm-q632

Cross-Site Request Forgery (CSRF) vulnerability in wpsolutions SoundCloud Ultimate allows Cross Site Request Forgery. This issue affects SoundCloud Ultimate: from n/a through 1.5.

CVSS3: 4.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-25xp-q574-q8mf

Vulnerability in the Oracle Advanced Outbound Telephony component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Advanced Outbound Telephony, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Outbound Telephony accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Outbound Telephony accessible data. CVSS v3.0 Base Score 8.2 (Confidentiality and Integrity impacts).

CVSS3: 8.2
1%
Низкий
больше 3 лет назад
github логотип
GHSA-25xp-grv3-xwjh

Use-after-free vulnerability in Foxit Reader and PhantomPDF 7.3.4.311 and earlier on Windows allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via a crafted PDF file.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу