Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-2467-jr62-j23f

8 месяцев назад

A vulnerability was found in WebAssembly wabt up to 1.0.37. It has been classified as problematic. Affected is the function OnDataCount of the file src/interp/binary-reader-interp.cc. The manipulation leads to resource consumption. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. A similar issue reported during the same timeframe was disputed by the code maintainer because it might not affect "real world wasm programs". Therefore, this entry might get disputed as well in the future.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-2467-h365-j7hm

почти 4 года назад

Improper Input Validation in Apache Solr

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2467-gpx7-r99c

больше 3 лет назад

A security feature bypass vulnerability exists when Click2Play protection in Microsoft Edge improperly handles flash objects. By itself, this bypass vulnerability does not allow arbitrary code execution, aka 'Microsoft Edge Security Feature Bypass Vulnerability'.

CVSS3: 5.3
EPSS: Средний
github логотип

GHSA-2467-cw25-7vww

почти 2 года назад

IBM Maximo Application Suite 8.10, 8.11 and IBM Maximo Asset Management 7.6.1.3 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 255075.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-2466-4485-4pxj

11 месяцев назад

LocalS3 Project Bucket Operations Vulnerable to XML External Entity (XXE) Injection

EPSS: Низкий
github логотип

GHSA-2465-pwjf-6h5f

почти 4 года назад

SQL injection vulnerability in signup.asp in Pre Classified Listings ASP allows remote attackers to execute arbitrary SQL commands via the email parameter.

EPSS: Низкий
github логотип

GHSA-2464-8j7c-4cjm

6 месяцев назад

go-viper's mapstructure May Leak Sensitive Information in Logs When Processing Malformed Data

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2463-wg6r-r9mf

больше 3 лет назад

PNGDec commit 8abf6be was discovered to contain a memory allocation problem via asan_malloc_linux.cpp.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2463-g988-qqpj

больше 2 лет назад

ABB is aware of vulnerabilities in the product versions listed below. An update is available that resolves the reported vulnerabilities in the product versions under maintenance. An attacker who successfully exploited one or more of these vulnerabilities could cause the product to stop or make the product inaccessible.  Numeric Range Comparison Without Minimum Check vulnerability in ABB Freelance controllers AC 700F (Controller modules), ABB Freelance controllers AC 900F (controller modules).This issue affects: Freelance controllers AC 700F:  from 9.0;0 through V9.2 SP2, through Freelance 2013, through Freelance 2013SP1, through Freelance 2016, through Freelance 2016SP1, through Freelance 2019, through Freelance 2019 SP1, through Freelance 2019 SP1 FP1;  Freelance controllers AC 900F:  Freelance 2013, through Freelance 2013SP1, through Freelance 2016, through Freelance 2016SP1, through Freelance 2019, through Freelance 2019 SP1, through Freelance 2019 SP1 FP1.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-2463-7265-h8r4

больше 3 лет назад

Jenkins Matrix Reloaded Plugin vulnerable to Stored XSS

CVSS3: 7.1
EPSS: Средний
github логотип

GHSA-2462-qrqm-7hxr

почти 2 года назад

Cross Site Scripting (XSS) vulnerability in sourcecodester oretnom23 pos point sale system 1.0, allows attackers to execute arbitrary code via the code, name, and description inputs in file Main.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-245x-m5cp-vv6q

больше 3 лет назад

WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.

EPSS: Низкий
github логотип

GHSA-245x-752w-r292

больше 1 года назад

The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘content’ parameter in all versions up to, and including, 6.4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-245w-hx5r-x6jq

8 месяцев назад

tcpreplay v4.4.4 was discovered to contain an infinite loop via the tcprewrite function at get.c.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-245w-9j9c-6g45

больше 3 лет назад

Free Simple Software 1.0 stores passwords in cleartext, which allows context-dependent attackers to obtain sensitive information.

EPSS: Низкий
github логотип

GHSA-245r-96m5-w336

больше 3 лет назад

Gnome gdk-pixbuf 2.36.8 and older is vulnerable to several integer overflow in the gif_get_lzw function resulting in memory corruption and potential code execution

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-245q-vh9m-g4gm

больше 3 лет назад

The SSLClientSocketNSS::Core::OwnAuthCertHandler function in net/socket/ssl_client_socket_nss.cc in Google Chrome before 33.0.1750.117 does not prevent changes to server X.509 certificates during renegotiations, which allows remote SSL servers to trigger use of a new certificate chain, inconsistent with the user's expectations, by initiating a TLS renegotiation.

EPSS: Низкий
github логотип

GHSA-245p-53xv-r43v

больше 3 лет назад

In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, buffer Over-read in Display due to the lack of an upper-bound validation when reading "num_of_cea_blocks" from the untrusted source (EDID), kernel memory can be exposed.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-245p-293f-hm6f

больше 3 лет назад

In Combodo iTop 2.2.0 through 2.6.0, if the configuration file is writable, then execution of arbitrary code can be accomplished by calling ajax.dataloader with a maliciously crafted payload. Many conditions can place the configuration file into a writable state: during installation; during upgrade; in certain cases, an error during modification of the file from the web interface leaves the file writable (can be triggered with XSS); a race condition can be triggered by the hub-connector module (community version only from 2.4.1 to 2.6.0); or editing the file in a CLI.

EPSS: Низкий
github логотип

GHSA-245m-v6j6-g3gr

почти 3 года назад

A vulnerability was found in SourceCodester Online Payroll System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/cashadvance_row.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-224989 was assigned to this vulnerability.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2467-jr62-j23f

A vulnerability was found in WebAssembly wabt up to 1.0.37. It has been classified as problematic. Affected is the function OnDataCount of the file src/interp/binary-reader-interp.cc. The manipulation leads to resource consumption. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. A similar issue reported during the same timeframe was disputed by the code maintainer because it might not affect "real world wasm programs". Therefore, this entry might get disputed as well in the future.

CVSS3: 3.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-2467-h365-j7hm

Improper Input Validation in Apache Solr

CVSS3: 8.8
3%
Низкий
почти 4 года назад
github логотип
GHSA-2467-gpx7-r99c

A security feature bypass vulnerability exists when Click2Play protection in Microsoft Edge improperly handles flash objects. By itself, this bypass vulnerability does not allow arbitrary code execution, aka 'Microsoft Edge Security Feature Bypass Vulnerability'.

CVSS3: 5.3
14%
Средний
больше 3 лет назад
github логотип
GHSA-2467-cw25-7vww

IBM Maximo Application Suite 8.10, 8.11 and IBM Maximo Asset Management 7.6.1.3 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 255075.

CVSS3: 3.7
0%
Низкий
почти 2 года назад
github логотип
GHSA-2466-4485-4pxj

LocalS3 Project Bucket Operations Vulnerable to XML External Entity (XXE) Injection

11 месяцев назад
github логотип
GHSA-2465-pwjf-6h5f

SQL injection vulnerability in signup.asp in Pre Classified Listings ASP allows remote attackers to execute arbitrary SQL commands via the email parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2464-8j7c-4cjm

go-viper's mapstructure May Leak Sensitive Information in Logs When Processing Malformed Data

CVSS3: 5.3
6 месяцев назад
github логотип
GHSA-2463-wg6r-r9mf

PNGDec commit 8abf6be was discovered to contain a memory allocation problem via asan_malloc_linux.cpp.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2463-g988-qqpj

ABB is aware of vulnerabilities in the product versions listed below. An update is available that resolves the reported vulnerabilities in the product versions under maintenance. An attacker who successfully exploited one or more of these vulnerabilities could cause the product to stop or make the product inaccessible.  Numeric Range Comparison Without Minimum Check vulnerability in ABB Freelance controllers AC 700F (Controller modules), ABB Freelance controllers AC 900F (controller modules).This issue affects: Freelance controllers AC 700F:  from 9.0;0 through V9.2 SP2, through Freelance 2013, through Freelance 2013SP1, through Freelance 2016, through Freelance 2016SP1, through Freelance 2019, through Freelance 2019 SP1, through Freelance 2019 SP1 FP1;  Freelance controllers AC 900F:  Freelance 2013, through Freelance 2013SP1, through Freelance 2016, through Freelance 2016SP1, through Freelance 2019, through Freelance 2019 SP1, through Freelance 2019 SP1 FP1.

CVSS3: 8.6
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2463-7265-h8r4

Jenkins Matrix Reloaded Plugin vulnerable to Stored XSS

CVSS3: 7.1
14%
Средний
больше 3 лет назад
github логотип
GHSA-2462-qrqm-7hxr

Cross Site Scripting (XSS) vulnerability in sourcecodester oretnom23 pos point sale system 1.0, allows attackers to execute arbitrary code via the code, name, and description inputs in file Main.php.

CVSS3: 6.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-245x-m5cp-vv6q

WebKit, as used in Apple iTunes before 10.5, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-10-11-1.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-245x-752w-r292

The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘content’ parameter in all versions up to, and including, 6.4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVSS3: 4.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-245w-hx5r-x6jq

tcpreplay v4.4.4 was discovered to contain an infinite loop via the tcprewrite function at get.c.

CVSS3: 7.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-245w-9j9c-6g45

Free Simple Software 1.0 stores passwords in cleartext, which allows context-dependent attackers to obtain sensitive information.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-245r-96m5-w336

Gnome gdk-pixbuf 2.36.8 and older is vulnerable to several integer overflow in the gif_get_lzw function resulting in memory corruption and potential code execution

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-245q-vh9m-g4gm

The SSLClientSocketNSS::Core::OwnAuthCertHandler function in net/socket/ssl_client_socket_nss.cc in Google Chrome before 33.0.1750.117 does not prevent changes to server X.509 certificates during renegotiations, which allows remote SSL servers to trigger use of a new certificate chain, inconsistent with the user's expectations, by initiating a TLS renegotiation.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-245p-53xv-r43v

In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, buffer Over-read in Display due to the lack of an upper-bound validation when reading "num_of_cea_blocks" from the untrusted source (EDID), kernel memory can be exposed.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-245p-293f-hm6f

In Combodo iTop 2.2.0 through 2.6.0, if the configuration file is writable, then execution of arbitrary code can be accomplished by calling ajax.dataloader with a maliciously crafted payload. Many conditions can place the configuration file into a writable state: during installation; during upgrade; in certain cases, an error during modification of the file from the web interface leaves the file writable (can be triggered with XSS); a race condition can be triggered by the hub-connector module (community version only from 2.4.1 to 2.6.0); or editing the file in a CLI.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-245m-v6j6-g3gr

A vulnerability was found in SourceCodester Online Payroll System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/cashadvance_row.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-224989 was assigned to this vulnerability.

CVSS3: 9.8
0%
Низкий
почти 3 года назад

Уязвимостей на страницу