Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 313 854

Количество 313 854

github логотип

GHSA-23c5-vp3g-x496

почти 4 года назад

gfax 0.4.2 and probably other versions creates temporary files insecurely, which allows local users to execute arbitrary commands via unknown vectors.

EPSS: Низкий
github логотип

GHSA-23c4-jq8q-2m9j

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management, Maximo Asset Management Essentials, Maximo for Government, Maximo for Nuclear Power, Maximo for Transportation, Maximo for Life Sciences, Maximo for Oil and Gas, and Maximo for Utilities 7.1.x through 7.1.1.12, 7.1.2, 7.5 before 7.5.0.3 IFIX014, and 7.5.0.5 before IFIX003; SmartCloud Control Desk (SCCD) 7.5 before 7.5.0.3 IFIX014 and 7.5.0.5 before IFIX003; and Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB) 7.1.x through 7.1.1.12, 7.1.2, and 7.2.x through 7.2.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-23c4-87c4-jw89

больше 3 лет назад

A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing, resulting in denial of service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-23c4-2wcp-ccr7

больше 3 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in Nibbleblog before 4.0.5 allow remote attackers to hijack the authentication of administrators for requests that (1) create a post via a new_simple action to admin.php or (2) conduct cross-site scripting (XSS) attacks via the content parameter in a new_simple action to admin.php.

EPSS: Низкий
github логотип

GHSA-23c3-237c-6x4c

больше 3 лет назад

In CMS Made Simple 2.2.3.1, the is_file_acceptable function in modules/FileManager/action.upload.php only blocks file extensions that begin or end with a "php" substring, which allows remote attackers to bypass intended access restrictions or trigger XSS via other extensions, as demonstrated by .phtml, .pht, .html, or .svg.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-23c2-w636-5rhm

больше 3 лет назад

Jenkins SiteMonitor Plugin globally and unconditionally disables SSL/TLS certificate validation

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-23c2-hg9m-2pw8

почти 2 года назад

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a Null-pointer dereferences in sub_41C488(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-23c2-gwp5-pxw9

около 3 лет назад

ReDoS based DoS vulnerability in GlobalID

EPSS: Низкий
github логотип

GHSA-23c2-5fj7-4rv3

почти 4 года назад

The smtp_filter function in spamdyke before 3.1.8 does not filter RCPT commands after encountering the first DATA command, which allows remote attackers to use the server as an open mail relay by sending RCPT commands with invalid recipients, followed by a DATA command, followed by arbitrary RCPT commands and a second DATA command.

EPSS: Низкий
github логотип

GHSA-239x-qr9g-j39q

больше 3 лет назад

This issue was addressed with improved checks. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. A remote user may be able to cause unexpected system termination or corrupt kernel memory.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-239x-f9cm-qgpx

около 1 месяца назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-239w-f2px-h2wv

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. Improper output encoding could lead to XSS if CSP is not enabled.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-239w-4f3w-cfcv

больше 3 лет назад

Liferay Portal Vulnerable to Cross-Site Scripting (XSS) via Categories Admin Page

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-239v-mcw5-wrfq

больше 3 лет назад

Buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 L through SP11 EP26, T27 LB through SP21 EP10, T27 LC before SP25 EP11, T27 LD before SP32 CP2, and T28 L10N before SP1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted WRF file, aka Bug ID CSCtz72946.

EPSS: Низкий
github логотип

GHSA-239v-6rvp-q7p2

почти 4 года назад

viksoe GMail Drive shell extension allows remote attackers to perform virtual filesystem actions via e-mail messages with certain subject lines, as demonstrated by (1) a GMAILFS: [13;a;1] message with a new filename and a file attachment, which injects a new file into the filesystem; (2) a GMAILFS: [13;a;1] message with an existing filename and a file attachment, which overwrites existing file content; and (3) a GMAILFS: [14;a;1] message, which creates a folder.

EPSS: Низкий
github логотип

GHSA-239v-3pc9-55cf

12 месяцев назад

Abacus ERP is versions older than 2024.210.16036, 2023.205.15833, 2022.105.15542 are affected by an authenticated arbitrary file read vulnerability.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-239r-qg7g-cjfp

больше 3 лет назад

Acronis True Image 2019 update 1 through 2021 update 1 on macOS allows local privilege escalation due to an insecure XPC service configuration.

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-239r-c744-9rfp

почти 4 года назад

The CICS listener in IBM TXSeries for Multiplatforms 6.2 GA waits for a forcepurge acknowledgement from the CICS Application Server (CICSAS) after an eci response timeout, which might allow remote authenticated users to cause a denial of service (forcepurge handling delay), or have unspecified other impact, via vectors involving slow or nonexistent acknowledgement.

EPSS: Низкий
github логотип

GHSA-239r-933r-8pjv

почти 4 года назад

FreeType2 before 2.3.6 allow context-dependent attackers to execute arbitrary code via an invalid "number of axes" field in a Printer Font Binary (PFB) file, which triggers a free of arbitrary memory locations, leading to memory corruption.

EPSS: Низкий
github логотип

GHSA-239r-76x2-4c6j

почти 4 года назад

Directory traversal vulnerability in phpThumb.php in PinkCrow Designs Gallery or maGAZIn 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the src parameter.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-23c5-vp3g-x496

gfax 0.4.2 and probably other versions creates temporary files insecurely, which allows local users to execute arbitrary commands via unknown vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-23c4-jq8q-2m9j

Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management, Maximo Asset Management Essentials, Maximo for Government, Maximo for Nuclear Power, Maximo for Transportation, Maximo for Life Sciences, Maximo for Oil and Gas, and Maximo for Utilities 7.1.x through 7.1.1.12, 7.1.2, 7.5 before 7.5.0.3 IFIX014, and 7.5.0.5 before IFIX003; SmartCloud Control Desk (SCCD) 7.5 before 7.5.0.3 IFIX014 and 7.5.0.5 before IFIX003; and Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB) 7.1.x through 7.1.1.12, 7.1.2, and 7.2.x through 7.2.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23c4-87c4-jw89

A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing, resulting in denial of service.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-23c4-2wcp-ccr7

Multiple cross-site request forgery (CSRF) vulnerabilities in Nibbleblog before 4.0.5 allow remote attackers to hijack the authentication of administrators for requests that (1) create a post via a new_simple action to admin.php or (2) conduct cross-site scripting (XSS) attacks via the content parameter in a new_simple action to admin.php.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-23c3-237c-6x4c

In CMS Made Simple 2.2.3.1, the is_file_acceptable function in modules/FileManager/action.upload.php only blocks file extensions that begin or end with a "php" substring, which allows remote attackers to bypass intended access restrictions or trigger XSS via other extensions, as demonstrated by .phtml, .pht, .html, or .svg.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-23c2-w636-5rhm

Jenkins SiteMonitor Plugin globally and unconditionally disables SSL/TLS certificate validation

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-23c2-hg9m-2pw8

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a Null-pointer dereferences in sub_41C488(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-23c2-gwp5-pxw9

ReDoS based DoS vulnerability in GlobalID

1%
Низкий
около 3 лет назад
github логотип
GHSA-23c2-5fj7-4rv3

The smtp_filter function in spamdyke before 3.1.8 does not filter RCPT commands after encountering the first DATA command, which allows remote attackers to use the server as an open mail relay by sending RCPT commands with invalid recipients, followed by a DATA command, followed by arbitrary RCPT commands and a second DATA command.

1%
Низкий
почти 4 года назад
github логотип
GHSA-239x-qr9g-j39q

This issue was addressed with improved checks. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. A remote user may be able to cause unexpected system termination or corrupt kernel memory.

CVSS3: 9.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-239x-f9cm-qgpx

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

около 1 месяца назад
github логотип
GHSA-239w-f2px-h2wv

An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. Improper output encoding could lead to XSS if CSP is not enabled.

CVSS3: 5.4
1%
Низкий
около 1 года назад
github логотип
GHSA-239w-4f3w-cfcv

Liferay Portal Vulnerable to Cross-Site Scripting (XSS) via Categories Admin Page

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-239v-mcw5-wrfq

Buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 L through SP11 EP26, T27 LB through SP21 EP10, T27 LC before SP25 EP11, T27 LD before SP32 CP2, and T28 L10N before SP1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted WRF file, aka Bug ID CSCtz72946.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-239v-6rvp-q7p2

viksoe GMail Drive shell extension allows remote attackers to perform virtual filesystem actions via e-mail messages with certain subject lines, as demonstrated by (1) a GMAILFS: [13;a;1] message with a new filename and a file attachment, which injects a new file into the filesystem; (2) a GMAILFS: [13;a;1] message with an existing filename and a file attachment, which overwrites existing file content; and (3) a GMAILFS: [14;a;1] message, which creates a folder.

1%
Низкий
почти 4 года назад
github логотип
GHSA-239v-3pc9-55cf

Abacus ERP is versions older than 2024.210.16036, 2023.205.15833, 2022.105.15542 are affected by an authenticated arbitrary file read vulnerability.

CVSS3: 6.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-239r-qg7g-cjfp

Acronis True Image 2019 update 1 through 2021 update 1 on macOS allows local privilege escalation due to an insecure XPC service configuration.

CVSS3: 7.8
20%
Средний
больше 3 лет назад
github логотип
GHSA-239r-c744-9rfp

The CICS listener in IBM TXSeries for Multiplatforms 6.2 GA waits for a forcepurge acknowledgement from the CICS Application Server (CICSAS) after an eci response timeout, which might allow remote authenticated users to cause a denial of service (forcepurge handling delay), or have unspecified other impact, via vectors involving slow or nonexistent acknowledgement.

1%
Низкий
почти 4 года назад
github логотип
GHSA-239r-933r-8pjv

FreeType2 before 2.3.6 allow context-dependent attackers to execute arbitrary code via an invalid "number of axes" field in a Printer Font Binary (PFB) file, which triggers a free of arbitrary memory locations, leading to memory corruption.

5%
Низкий
почти 4 года назад
github логотип
GHSA-239r-76x2-4c6j

Directory traversal vulnerability in phpThumb.php in PinkCrow Designs Gallery or maGAZIn 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the src parameter.

12%
Средний
почти 4 года назад

Уязвимостей на страницу