Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 078

Количество 314 078

github логотип

GHSA-267g-j5c9-f8p4

почти 4 года назад

Buffer overflow in Webstar HTTP server allows remote attackers to cause a denial of service via a long GET request.

EPSS: Низкий
github логотип

GHSA-267g-8279-vj63

14 дней назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in favethemes Homey Core homey-core allows Reflected XSS.This issue affects Homey Core: from n/a through <= 2.4.3.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-267g-522c-qmvf

почти 4 года назад

Linux kernel 2.6.15.1 and earlier, when running on SPARC architectures, allows local users to cause a denial of service (hang) via a "date -s" command, which causes invalid sign extended arguments to be provided to the get_compat_timespec function call.

EPSS: Низкий
github логотип

GHSA-267f-c3x2-429g

около 4 лет назад

In UserDetailsActivity of AndroidManifest.xml, there is a possible DoS due to a tapjacking/overlay attack. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-183411279

EPSS: Низкий
github логотип

GHSA-267c-qjx5-xp7w

больше 3 лет назад

A remote authenticated stored cross-site scripting (xss) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-267c-6463-gj35

больше 3 лет назад

EQS Integrity Line through 2022-07-01 allows a stored XSS via a crafted whistleblower entry.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2679-jq7r-8cph

почти 3 года назад

A flaw was found in the Linux kernel. A use-after-free may be triggered in asus_kbd_backlight_set when plugging/disconnecting in a malicious USB device, which advertises itself as an Asus device. Similarly to the previous known CVE-2023-25012, but in asus devices, the work_struct may be scheduled by the LED controller while the device is disconnecting, triggering a use-after-free on the struct asus_kbd_leds *led structure. A malicious USB device may exploit the issue to cause memory corruption with controlled data.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-2679-hjp3-6965

больше 3 лет назад

The mintToken function of a smart contract implementation for VSCToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2678-mh77-mjgv

больше 3 лет назад

IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 206091.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2677-vh42-vx74

больше 3 лет назад

Vulnerability in the Oracle Financial Services Price Creation and Discovery product of Oracle Financial Services Applications (component: User Interface). The supported version that is affected is 8.0.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Price Creation and Discovery. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Price Creation and Discovery accessible data as well as unauthorized read access to a subset of Oracle Financial Services Price Creation and Discovery accessible data. CVSS 3.0 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).

EPSS: Низкий
github логотип

GHSA-2676-4vwj-wgm4

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Magento E-Commerce Platform 1.9.0.1.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2675-7qgw-hjvx

больше 3 лет назад

AVC_DuplicateConfig() at isomedia/avc_ext.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file. There is "cfg_new->AVCLevelIndication = cfg->AVCLevelIndication;" but cfg could be NULL.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2675-54p5-24ww

около 3 лет назад

A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.2, macOS Big Sur 11.7.2, macOS Ventura 13. An app may bypass Gatekeeper checks.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2673-vwc6-q3m5

больше 3 лет назад

The Missing Device feature in Lookout allows physically proximate attackers to provide arbitrary location data via a "commonly available simple GPS location spoofer."

EPSS: Низкий
github логотип

GHSA-2673-hcr2-rj4v

больше 2 лет назад

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.3, watchOS 9.4, tvOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, iOS 16.4 and iPadOS 16.4. An app may be able to execute arbitrary code with kernel privileges

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2672-vg22-4pj7

около 4 лет назад

Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious MXF file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

EPSS: Низкий
github логотип

GHSA-266x-3x8x-xj7x

больше 3 лет назад

An improper authorization vulnerability in Palo Alto Networks Cortex XSOAR enables a remote unauthenticated attacker with network access to the Cortex XSOAR server to perform unauthorized actions through the REST API. This issue impacts: Cortex XSOAR 6.1.0 builds later than 1016923 and earlier than 1271064; Cortex XSOAR 6.2.0 builds earlier than 1271065. This issue does not impact Cortex XSOAR 5.5.0, Cortex XSOAR 6.0.0, Cortex XSOAR 6.0.1, or Cortex XSOAR 6.0.2 versions. All Cortex XSOAR instances hosted by Palo Alto Networks are upgraded to resolve this vulnerability. No additional action is required for these instances.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-266w-r6vg-579f

около 1 месяца назад

Missing Authorization vulnerability in wpstream WpStream wpstream allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpStream: from n/a through <= 4.9.5.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-266w-j5c5-474h

больше 3 лет назад

PageLayer before 1.3.5 allows reflected XSS via the font-size parameter.

EPSS: Низкий
github логотип

GHSA-266v-q3gx-4vx4

больше 1 года назад

Authentication Bypass Using an Alternate Path or Channel vulnerability in MaanTheme MaanStore API allows Authentication Bypass.This issue affects MaanStore API: from n/a through 1.0.1.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-267g-j5c9-f8p4

Buffer overflow in Webstar HTTP server allows remote attackers to cause a denial of service via a long GET request.

1%
Низкий
почти 4 года назад
github логотип
GHSA-267g-8279-vj63

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in favethemes Homey Core homey-core allows Reflected XSS.This issue affects Homey Core: from n/a through <= 2.4.3.

CVSS3: 7.1
0%
Низкий
14 дней назад
github логотип
GHSA-267g-522c-qmvf

Linux kernel 2.6.15.1 and earlier, when running on SPARC architectures, allows local users to cause a denial of service (hang) via a "date -s" command, which causes invalid sign extended arguments to be provided to the get_compat_timespec function call.

0%
Низкий
почти 4 года назад
github логотип
GHSA-267f-c3x2-429g

In UserDetailsActivity of AndroidManifest.xml, there is a possible DoS due to a tapjacking/overlay attack. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-183411279

0%
Низкий
около 4 лет назад
github логотип
GHSA-267c-qjx5-xp7w

A remote authenticated stored cross-site scripting (xss) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-267c-6463-gj35

EQS Integrity Line through 2022-07-01 allows a stored XSS via a crafted whistleblower entry.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2679-jq7r-8cph

A flaw was found in the Linux kernel. A use-after-free may be triggered in asus_kbd_backlight_set when plugging/disconnecting in a malicious USB device, which advertises itself as an Asus device. Similarly to the previous known CVE-2023-25012, but in asus devices, the work_struct may be scheduled by the LED controller while the device is disconnecting, triggering a use-after-free on the struct asus_kbd_leds *led structure. A malicious USB device may exploit the issue to cause memory corruption with controlled data.

CVSS3: 6.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-2679-hjp3-6965

The mintToken function of a smart contract implementation for VSCToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2678-mh77-mjgv

IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 206091.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2677-vh42-vx74

Vulnerability in the Oracle Financial Services Price Creation and Discovery product of Oracle Financial Services Applications (component: User Interface). The supported version that is affected is 8.0.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Price Creation and Discovery. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Price Creation and Discovery accessible data as well as unauthorized read access to a subset of Oracle Financial Services Price Creation and Discovery accessible data. CVSS 3.0 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2676-4vwj-wgm4

Cross-site scripting (XSS) vulnerability in Magento E-Commerce Platform 1.9.0.1.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2675-7qgw-hjvx

AVC_DuplicateConfig() at isomedia/avc_ext.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file. There is "cfg_new->AVCLevelIndication = cfg->AVCLevelIndication;" but cfg could be NULL.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2675-54p5-24ww

A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.2, macOS Big Sur 11.7.2, macOS Ventura 13. An app may bypass Gatekeeper checks.

CVSS3: 5.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-2673-vwc6-q3m5

The Missing Device feature in Lookout allows physically proximate attackers to provide arbitrary location data via a "commonly available simple GPS location spoofer."

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2673-hcr2-rj4v

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.3, watchOS 9.4, tvOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, iOS 16.4 and iPadOS 16.4. An app may be able to execute arbitrary code with kernel privileges

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2672-vg22-4pj7

Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious MXF file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

2%
Низкий
около 4 лет назад
github логотип
GHSA-266x-3x8x-xj7x

An improper authorization vulnerability in Palo Alto Networks Cortex XSOAR enables a remote unauthenticated attacker with network access to the Cortex XSOAR server to perform unauthorized actions through the REST API. This issue impacts: Cortex XSOAR 6.1.0 builds later than 1016923 and earlier than 1271064; Cortex XSOAR 6.2.0 builds earlier than 1271065. This issue does not impact Cortex XSOAR 5.5.0, Cortex XSOAR 6.0.0, Cortex XSOAR 6.0.1, or Cortex XSOAR 6.0.2 versions. All Cortex XSOAR instances hosted by Palo Alto Networks are upgraded to resolve this vulnerability. No additional action is required for these instances.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-266w-r6vg-579f

Missing Authorization vulnerability in wpstream WpStream wpstream allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpStream: from n/a through <= 4.9.5.

CVSS3: 8.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-266w-j5c5-474h

PageLayer before 1.3.5 allows reflected XSS via the font-size parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-266v-q3gx-4vx4

Authentication Bypass Using an Alternate Path or Channel vulnerability in MaanTheme MaanStore API allows Authentication Bypass.This issue affects MaanStore API: from n/a through 1.0.1.

CVSS3: 9.8
0%
Низкий
больше 1 года назад

Уязвимостей на страницу