Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 212

Количество 314 212

github логотип

GHSA-26pq-gvcv-rc9v

3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: tty: goldfish: Fix free_irq() on remove Pass the correct dev_id to free_irq() to fix this splat when the driver is unbound: WARNING: CPU: 0 PID: 30 at kernel/irq/manage.c:1895 free_irq Trying to free already-free IRQ 65 Call Trace: warn_slowpath_fmt free_irq goldfish_tty_remove platform_remove device_remove device_release_driver_internal device_driver_detach unbind_store drv_attr_store ...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-26pq-6hf6-mh32

8 месяцев назад

In wlan STA driver, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00413200; Issue ID: MSV-3304.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-26pq-368c-c8f2

почти 4 года назад

Format string vulnerability in the foreign_option function in options.c for OpenVPN 2.0.x allows remote clients to execute arbitrary code via format string specifiers in a push of the dhcp-option command option.

EPSS: Низкий
github логотип

GHSA-26pp-wmv6-ph7r

больше 3 лет назад

Unspecified vulnerability in the ILOM component in Oracle Sun Systems Products Suite 3.0, 3.1, and 3.2 allows remote attackers to affect integrity via vectors related to Web.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-26pp-v5jf-7qcc

больше 3 лет назад

In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can start telnet without authorization because the default username and password exists in the firmware.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-26pm-xqvm-vjf3

почти 4 года назад

Multiple buffer overflows in apcupsd before 3.8.6, and 3.10.x before 3.10.5, may allow attackers to cause a denial of service or execute arbitrary code, related to usage of the vsprintf function.

EPSS: Низкий
github логотип

GHSA-26pm-x559-r4h2

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in common.php in Post Revolution before 0.8.0c-2 allow remote attackers to inject arbitrary web script or HTML via an attribute of a (1) P, a (2) STRONG, a (3) A, a (4) EM, a (5) I, a (6) IMG, a (7) LI, an (8) OL, a (9) VIDEO, or a (10) BLOCKQUOTE element.

EPSS: Низкий
github логотип

GHSA-26pm-g3r3-95jw

больше 3 лет назад

Multiple SQL injection vulnerabilities in DevelopItEasy Events Calendar 1.2 allow remote attackers to execute arbitrary SQL commands via (1) the user_name parameter (aka user field) to admin/index.php, (2) the user_pass parameter (aka pass field) to admin/index.php, or (3) the id parameter to calendar_details.php. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-26pm-fw5r-c84w

больше 3 лет назад

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-26pm-785p-xwg4

больше 3 лет назад

The Guess The Actor (aka com.gamelikeinc.actors) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-26pg-vhv9-6fgm

больше 3 лет назад

In some SAP standard roles, in SAP_ABA versions, 7.00 to 7.02, 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50, 75C to 75D, a transaction code reserved for customer is used. By implementing such transaction code a malicious user may execute unauthorized transaction functionality.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-26pf-mq6p-g9cx

больше 3 лет назад

Directory traversal vulnerability in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 allows remote authenticated users to execute arbitrary code via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-26pc-wx8w-v5vj

почти 4 года назад

The connect method in lib/net/http.rb in the (1) Net::HTTP and (2) Net::HTTPS libraries in Ruby 1.8.5 and 1.8.6 does not verify that the commonName (CN) field in a server certificate matches the domain name in an HTTPS request, which makes it easier for remote attackers to intercept SSL transmissions via a man-in-the-middle attack or spoofed web site.

EPSS: Низкий
github логотип

GHSA-26p9-q8r9-v77f

больше 3 лет назад

A vulnerability in the installation procedure for Cisco Prime Network Software could allow an authenticated, local attacker to elevate their privileges to root privileges. More Information: CSCvd47343. Known Affected Releases: 4.2(2.1)PP1 4.2(3.0)PP6 4.3(0.0)PP4 4.3(1.0)PP2. Known Fixed Releases: 4.3(2).

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-26p9-7f96-xrcg

9 месяцев назад

Use of implicit intent for sensitive communication in translation in Samsung Notes prior to version 4.4.29.23 allows local attackers to get sensitive information. User interaction is required for triggering this vulnerability.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-26p8-xrj2-mv53

около 6 лет назад

Apache NiFi process group information disclosure

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-26p7-g5hj-f2q3

больше 3 лет назад

The log-gather implementation in the web administration interface in EMC Isilon OneFS 6.5.x.x through 7.1.1.x before 7.1.1.5 and 7.2.0.x before 7.2.0.2 allows remote authenticated users to execute arbitrary commands with root privileges via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-26p6-rjxq-3xwv

4 месяца назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-26p6-8m4j-3q9m

больше 3 лет назад

Directory traversal vulnerability in the HTTP Server in Sybase EAServer 6.3.1 Developer Edition allows remote attackers to read arbitrary files via a /.\../\../\ sequence in a path.

EPSS: Средний
github логотип

GHSA-26p6-46xq-35v9

около 4 лет назад

HwPCAssistant has a Path Traversal vulnerability .Successful exploitation of this vulnerability may write any file.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-26pq-gvcv-rc9v

In the Linux kernel, the following vulnerability has been resolved: tty: goldfish: Fix free_irq() on remove Pass the correct dev_id to free_irq() to fix this splat when the driver is unbound: WARNING: CPU: 0 PID: 30 at kernel/irq/manage.c:1895 free_irq Trying to free already-free IRQ 65 Call Trace: warn_slowpath_fmt free_irq goldfish_tty_remove platform_remove device_remove device_release_driver_internal device_driver_detach unbind_store drv_attr_store ...

CVSS3: 7.8
0%
Низкий
3 месяца назад
github логотип
GHSA-26pq-6hf6-mh32

In wlan STA driver, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00413200; Issue ID: MSV-3304.

CVSS3: 5.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-26pq-368c-c8f2

Format string vulnerability in the foreign_option function in options.c for OpenVPN 2.0.x allows remote clients to execute arbitrary code via format string specifiers in a push of the dhcp-option command option.

2%
Низкий
почти 4 года назад
github логотип
GHSA-26pp-wmv6-ph7r

Unspecified vulnerability in the ILOM component in Oracle Sun Systems Products Suite 3.0, 3.1, and 3.2 allows remote attackers to affect integrity via vectors related to Web.

CVSS3: 4.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-26pp-v5jf-7qcc

In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can start telnet without authorization because the default username and password exists in the firmware.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-26pm-xqvm-vjf3

Multiple buffer overflows in apcupsd before 3.8.6, and 3.10.x before 3.10.5, may allow attackers to cause a denial of service or execute arbitrary code, related to usage of the vsprintf function.

0%
Низкий
почти 4 года назад
github логотип
GHSA-26pm-x559-r4h2

Multiple cross-site scripting (XSS) vulnerabilities in common.php in Post Revolution before 0.8.0c-2 allow remote attackers to inject arbitrary web script or HTML via an attribute of a (1) P, a (2) STRONG, a (3) A, a (4) EM, a (5) I, a (6) IMG, a (7) LI, an (8) OL, a (9) VIDEO, or a (10) BLOCKQUOTE element.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-26pm-g3r3-95jw

Multiple SQL injection vulnerabilities in DevelopItEasy Events Calendar 1.2 allow remote attackers to execute arbitrary SQL commands via (1) the user_name parameter (aka user field) to admin/index.php, (2) the user_pass parameter (aka pass field) to admin/index.php, or (3) the id parameter to calendar_details.php. NOTE: some of these details are obtained from third party information.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-26pm-fw5r-c84w

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 7.5
23%
Средний
больше 3 лет назад
github логотип
GHSA-26pm-785p-xwg4

The Guess The Actor (aka com.gamelikeinc.actors) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-26pg-vhv9-6fgm

In some SAP standard roles, in SAP_ABA versions, 7.00 to 7.02, 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50, 75C to 75D, a transaction code reserved for customer is used. By implementing such transaction code a malicious user may execute unauthorized transaction functionality.

CVSS3: 7.2
1%
Низкий
больше 3 лет назад
github логотип
GHSA-26pf-mq6p-g9cx

Directory traversal vulnerability in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 allows remote authenticated users to execute arbitrary code via unspecified vectors.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-26pc-wx8w-v5vj

The connect method in lib/net/http.rb in the (1) Net::HTTP and (2) Net::HTTPS libraries in Ruby 1.8.5 and 1.8.6 does not verify that the commonName (CN) field in a server certificate matches the domain name in an HTTPS request, which makes it easier for remote attackers to intercept SSL transmissions via a man-in-the-middle attack or spoofed web site.

1%
Низкий
почти 4 года назад
github логотип
GHSA-26p9-q8r9-v77f

A vulnerability in the installation procedure for Cisco Prime Network Software could allow an authenticated, local attacker to elevate their privileges to root privileges. More Information: CSCvd47343. Known Affected Releases: 4.2(2.1)PP1 4.2(3.0)PP6 4.3(0.0)PP4 4.3(1.0)PP2. Known Fixed Releases: 4.3(2).

CVSS3: 6.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-26p9-7f96-xrcg

Use of implicit intent for sensitive communication in translation in Samsung Notes prior to version 4.4.29.23 allows local attackers to get sensitive information. User interaction is required for triggering this vulnerability.

CVSS3: 3.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-26p8-xrj2-mv53

Apache NiFi process group information disclosure

CVSS3: 5.3
0%
Низкий
около 6 лет назад
github логотип
GHSA-26p7-g5hj-f2q3

The log-gather implementation in the web administration interface in EMC Isilon OneFS 6.5.x.x through 7.1.1.x before 7.1.1.5 and 7.2.0.x before 7.2.0.2 allows remote authenticated users to execute arbitrary commands with root privileges via unspecified vectors.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-26p6-rjxq-3xwv

Rejected reason: Not used

4 месяца назад
github логотип
GHSA-26p6-8m4j-3q9m

Directory traversal vulnerability in the HTTP Server in Sybase EAServer 6.3.1 Developer Edition allows remote attackers to read arbitrary files via a /.\../\../\ sequence in a path.

12%
Средний
больше 3 лет назад
github логотип
GHSA-26p6-46xq-35v9

HwPCAssistant has a Path Traversal vulnerability .Successful exploitation of this vulnerability may write any file.

0%
Низкий
около 4 лет назад

Уязвимостей на страницу