Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 313 854

Количество 313 854

github логотип

GHSA-2454-558w-967q

почти 4 года назад

PHP remote file inclusion vulnerability in includes/profilcp_constants.php in the Profile Control Panel (CPanel) module for mxBB 0.91c allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.

EPSS: Средний
github логотип

GHSA-2454-3wfw-h893

больше 3 лет назад

The startread function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted wav file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2454-2h9h-6wx6

6 месяцев назад

An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Once access is gained either by default, common, or cracked passwords, the video recordings (containing sensitive routes, conversations, and footage) are open for downloading by creating a socket to command port 7777, and then downloading video via port 7778 and audio via port 7779.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2453-p5w4-2rh4

10 месяцев назад

Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent network access.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-2452-xqvj-2c63

больше 3 лет назад

In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to trick the victim to grant notification access to the wrong app due to improper input validation. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228178437

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2452-6xj8-jh47

около 1 года назад

Opening a malicious website while running a Nuxt dev server could allow read-only access to code

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2452-3rwv-x89c

почти 5 лет назад

Out-of-bounds write

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-244x-f55f-vxmr

больше 2 лет назад

IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 240454.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-244x-c938-j3qj

7 месяцев назад

Use of hardcoded cryptographic key in BlowFish.cpp in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passwords used in database connections from hMailServer.ini config file.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-244w-wm8j-4mcg

около 2 лет назад

An issue in sanTas mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-244w-g82v-mjgw

около 2 лет назад

U-Boot vulnerability resulting in persistent Code Execution 

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-244w-39h6-2f5r

больше 2 лет назад

Microsoft Message Queuing Denial of Service Vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-244v-xghf-wq26

больше 3 лет назад

MuPDF through 1.18.1 has an out-of-bounds write because the cached color converter does not properly consider the maximum key size of a hash table. This can, for example, be seen with crafted "mutool draw" input.

EPSS: Низкий
github логотип

GHSA-244v-h48v-v63v

больше 3 лет назад

In ihevcd_parse_slice_header of ihevcd_parse_slice_header.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-143826590

EPSS: Низкий
github логотип

GHSA-244r-jx38-mgcg

около 4 лет назад

Adobe After Effects version 18.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must open a specially crafted file to exploit this vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-244r-fcj3-ghjq

почти 5 лет назад

Exposure of class information in RESTEasy

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-244r-55j9-vqgp

больше 3 лет назад

In Progress WS_FTP Server prior to version 8.7.3, multiple reflected cross-site scripting (XSS) vulnerabilities exist in the administrative web interface. It is possible for a remote attacker to inject arbitrary JavaScript into a WS_FTP administrator's web session. This would allow the attacker to execute code within the context of the victim's browser.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-244r-4cqf-v63r

12 месяцев назад

Improper input validation in UEFI firmware CseVariableStorageSmm for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-244q-c67c-j2h7

больше 3 лет назад

DLL preloading vulnerability in Autodesk Design Review versions 2011, 2012, 2013, and 2018. An attacker may trick a user into opening a malicious DWF file that may leverage a DLL preloading vulnerability, which may result in code execution.

EPSS: Низкий
github логотип

GHSA-244q-6gfm-pphc

больше 3 лет назад

Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect availability, related to Kernel/KSSL.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2454-558w-967q

PHP remote file inclusion vulnerability in includes/profilcp_constants.php in the Profile Control Panel (CPanel) module for mxBB 0.91c allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.

11%
Средний
почти 4 года назад
github логотип
GHSA-2454-3wfw-h893

The startread function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted wav file.

CVSS3: 5.5
5%
Низкий
больше 3 лет назад
github логотип
GHSA-2454-2h9h-6wx6

An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Once access is gained either by default, common, or cracked passwords, the video recordings (containing sensitive routes, conversations, and footage) are open for downloading by creating a socket to command port 7777, and then downloading video via port 7778 and audio via port 7779.

CVSS3: 9.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-2453-p5w4-2rh4

Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent network access.

CVSS3: 4.6
0%
Низкий
10 месяцев назад
github логотип
GHSA-2452-xqvj-2c63

In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to trick the victim to grant notification access to the wrong app due to improper input validation. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228178437

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2452-6xj8-jh47

Opening a malicious website while running a Nuxt dev server could allow read-only access to code

CVSS3: 5.3
0%
Низкий
около 1 года назад
github логотип
GHSA-2452-3rwv-x89c

Out-of-bounds write

CVSS3: 7.5
5%
Низкий
почти 5 лет назад
github логотип
GHSA-244x-f55f-vxmr

IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 240454.

CVSS3: 2.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-244x-c938-j3qj

Use of hardcoded cryptographic key in BlowFish.cpp in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passwords used in database connections from hMailServer.ini config file.

CVSS3: 4.6
0%
Низкий
7 месяцев назад
github логотип
GHSA-244w-wm8j-4mcg

An issue in sanTas mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

CVSS3: 5.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-244w-g82v-mjgw

U-Boot vulnerability resulting in persistent Code Execution 

CVSS3: 9.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-244w-39h6-2f5r

Microsoft Message Queuing Denial of Service Vulnerability

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-244v-xghf-wq26

MuPDF through 1.18.1 has an out-of-bounds write because the cached color converter does not properly consider the maximum key size of a hash table. This can, for example, be seen with crafted "mutool draw" input.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-244v-h48v-v63v

In ihevcd_parse_slice_header of ihevcd_parse_slice_header.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-143826590

0%
Низкий
больше 3 лет назад
github логотип
GHSA-244r-jx38-mgcg

Adobe After Effects version 18.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must open a specially crafted file to exploit this vulnerability.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-244r-fcj3-ghjq

Exposure of class information in RESTEasy

CVSS3: 5.3
0%
Низкий
почти 5 лет назад
github логотип
GHSA-244r-55j9-vqgp

In Progress WS_FTP Server prior to version 8.7.3, multiple reflected cross-site scripting (XSS) vulnerabilities exist in the administrative web interface. It is possible for a remote attacker to inject arbitrary JavaScript into a WS_FTP administrator's web session. This would allow the attacker to execute code within the context of the victim's browser.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-244r-4cqf-v63r

Improper input validation in UEFI firmware CseVariableStorageSmm for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS3: 7.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-244q-c67c-j2h7

DLL preloading vulnerability in Autodesk Design Review versions 2011, 2012, 2013, and 2018. An attacker may trick a user into opening a malicious DWF file that may leverage a DLL preloading vulnerability, which may result in code execution.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-244q-6gfm-pphc

Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect availability, related to Kernel/KSSL.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу