Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 313 159

Количество 313 159

github логотип

GHSA-252h-69rw-g2rp

больше 3 лет назад

The str_buf_cat function in string.c in Ruby 1.9.3, 2.0.0, and 2.1 allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string.

EPSS: Низкий
github логотип

GHSA-252h-2cmq-pmr6

около 3 лет назад

easywebpack-cli Path Traversal vulnerability

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-252g-gw8q-x2cc

больше 3 лет назад

OpenShift Container Platform before version 4.1.3 writes OAuth tokens in plaintext to the audit logs for the Kubernetes API server and OpenShift API server. A user with sufficient privileges could recover OAuth tokens from these audit logs and use them to access other resources.

EPSS: Низкий
github логотип

GHSA-252g-9rpq-c6xw

почти 4 года назад

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis VSS Doctor (Windows) before build 53

EPSS: Низкий
github логотип

GHSA-252f-47x2-rgxx

больше 3 лет назад

A SQL injection vulnerability in a Trend Micro Email Encryption Gateway 5.5 policy script could allow an attacker to execute SQL commands to upload and execute arbitrary code that may harm the target system.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-252c-46fv-6xqv

больше 3 лет назад

ServerManagement master branch as of commit 49491cc6f94980e6be7791d17be947c27071eb56 is affected by a directory traversal vulnerability. This vulnerability can be used to extract credentials which can in turn be used to execute code.

EPSS: Низкий
github логотип

GHSA-2529-rwp4-75f6

больше 3 лет назад

It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed article -> Website" or in the standard format of "View -> Feed article -> default format". This vulnerability affects Thunderbird < 52.5.2.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2529-cmp4-x7vg

почти 4 года назад

HP-UX aserver program allows local users to gain privileges via a symlink attack.

EPSS: Низкий
github логотип

GHSA-2528-h86j-954v

больше 3 лет назад

In JetBrains TeamCity before 2021.1.3, a newly created project could take settings from an already deleted project.

EPSS: Низкий
github логотип

GHSA-2527-g53r-vw26

почти 4 года назад

In HarmfulAppWarningActivity of HarmfulAppWarningActivity.java, there is a possible way to trick victim to install harmful app due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-205595291

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2526-24jx-77pp

больше 3 лет назад

Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file. This is achieved through running a malicious script or program on the target machine.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2524-6f4r-2jq9

больше 3 лет назад

SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious commands with root privileges in SAP Host Agent via SAP Landscape Management.

EPSS: Низкий
github логотип

GHSA-2524-2jp2-r468

больше 1 года назад

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2523-xvgc-mmh8

больше 1 года назад

Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2523-vcxw-6v95

больше 3 лет назад

In libhidcommand_jni, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the USB service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111363077

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-2523-v9j2-g44c

около 4 лет назад

Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6) Vulnerable parameters: &post_title, &downloadable_file_version[0].

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2523-mx65-hm92

почти 3 года назад

NASM 2.16 (development) is vulnerable to 476: Null Pointer Dereference via output/outaout.c.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2522-v35m-2r22

около 4 лет назад

jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2522-mrjc-m688

почти 2 года назад

Apache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config used

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2522-8f97-8gg8

почти 4 года назад

Unspecified vulnerability in Adobe Breeze 5 Licensed Server and Breeze 5.1 Licensed Server allows attackers to read arbitrary files via unknown vectors related to "URL parsing."

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-252h-69rw-g2rp

The str_buf_cat function in string.c in Ruby 1.9.3, 2.0.0, and 2.1 allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-252h-2cmq-pmr6

easywebpack-cli Path Traversal vulnerability

CVSS3: 5.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-252g-gw8q-x2cc

OpenShift Container Platform before version 4.1.3 writes OAuth tokens in plaintext to the audit logs for the Kubernetes API server and OpenShift API server. A user with sufficient privileges could recover OAuth tokens from these audit logs and use them to access other resources.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-252g-9rpq-c6xw

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis VSS Doctor (Windows) before build 53

0%
Низкий
почти 4 года назад
github логотип
GHSA-252f-47x2-rgxx

A SQL injection vulnerability in a Trend Micro Email Encryption Gateway 5.5 policy script could allow an attacker to execute SQL commands to upload and execute arbitrary code that may harm the target system.

CVSS3: 9.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-252c-46fv-6xqv

ServerManagement master branch as of commit 49491cc6f94980e6be7791d17be947c27071eb56 is affected by a directory traversal vulnerability. This vulnerability can be used to extract credentials which can in turn be used to execute code.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2529-rwp4-75f6

It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed article -> Website" or in the standard format of "View -> Feed article -> default format". This vulnerability affects Thunderbird < 52.5.2.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2529-cmp4-x7vg

HP-UX aserver program allows local users to gain privileges via a symlink attack.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2528-h86j-954v

In JetBrains TeamCity before 2021.1.3, a newly created project could take settings from an already deleted project.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2527-g53r-vw26

In HarmfulAppWarningActivity of HarmfulAppWarningActivity.java, there is a possible way to trick victim to install harmful app due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-205595291

CVSS3: 7.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-2526-24jx-77pp

Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file. This is achieved through running a malicious script or program on the target machine.

CVSS3: 6.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2524-6f4r-2jq9

SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious commands with root privileges in SAP Host Agent via SAP Landscape Management.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2524-2jp2-r468

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

CVSS3: 8.8
2%
Низкий
больше 1 года назад
github логотип
GHSA-2523-xvgc-mmh8

Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability

CVSS3: 7.8
4%
Низкий
больше 1 года назад
github логотип
GHSA-2523-vcxw-6v95

In libhidcommand_jni, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the USB service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111363077

CVSS3: 6.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2523-v9j2-g44c

Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6) Vulnerable parameters: &post_title, &downloadable_file_version[0].

CVSS3: 4.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-2523-mx65-hm92

NASM 2.16 (development) is vulnerable to 476: Null Pointer Dereference via output/outaout.c.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-2522-v35m-2r22

jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2522-mrjc-m688

Apache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config used

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-2522-8f97-8gg8

Unspecified vulnerability in Adobe Breeze 5 Licensed Server and Breeze 5.1 Licensed Server allows attackers to read arbitrary files via unknown vectors related to "URL parsing."

3%
Низкий
почти 4 года назад

Уязвимостей на страницу