Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 313 854

Количество 313 854

github логотип

GHSA-232p-99pf-h332

больше 3 лет назад

Umlet version < 14.3 contains a XML External Entity (XXE) vulnerability in File parsing that can result in disclosure of confidential data, denial of service, server side request forgery. This attack appear to be exploitable via Specially crafted UXF file. This vulnerability appears to have been fixed in 14.3.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-232p-59mg-f98p

больше 3 лет назад

Microweber Cross-site Scripting can result in redirection to a malicious site

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-232m-xvr4-2347

больше 3 лет назад

A Cross-site Scripting vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.7, 5.2 and earlier, allows attacker to inject arbitrary web script or HTML via maliciously crafted "Host" header in user HTTP requests.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-232m-53gr-9v22

почти 4 года назад

The (1) agp_generic_alloc_page and (2) agp_generic_alloc_pages functions in drivers/char/agp/generic.c in the agp subsystem in the Linux kernel before 2.6.30-rc3 do not zero out pages that may later be available to a user-space process, which allows local users to obtain sensitive information by reading these pages.

EPSS: Низкий
github логотип

GHSA-232g-vj6v-88w6

больше 3 лет назад

An exploitable local privilege elevation vulnerability exists in the file system permissions of GOG Galaxy's “Games” directory, version 1.2.48.36 (Windows 64-bit Installer). An attacker can overwrite executables of installed games to exploit this vulnerability and execute arbitrary code with elevated privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-232g-h7w4-2pxj

почти 4 года назад

Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to 1.0.8.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-232f-9f2g-m34q

почти 4 года назад

Unspecified vulnerability in Sun Java System Web Server 6.0 and 6.1 before 20070315 allows remote attackers to "gain unauthorized access to data", possibly involving a sample application.

EPSS: Низкий
github логотип

GHSA-232f-8fc5-f649

почти 4 года назад

Multiple SQL injection vulnerabilities in Advanced Webhost Billing System (AWBS) before 2.6.0, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: this can be leveraged for XSS attacks that "bypass AWBS's anti-XSS input validation."

EPSS: Низкий
github логотип

GHSA-232f-66gw-9wfc

больше 3 лет назад

A SQL Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to directly modify the SQL query.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2328-vc59-64q8

больше 3 лет назад

The key-management component in Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allows remote attackers to trigger unintended content in outbound e-mail messages via a crafted key UID value in an inbound e-mail message, as demonstrated by the outbound Subject header.

EPSS: Низкий
github логотип

GHSA-2328-876m-g2rg

больше 2 лет назад

In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2327-x98x-57c5

3 месяца назад

Inappropriate implementation in Downloads in Google Chrome on Windows prior to 140.0.7339.80 allowed a remote attacker to bypass Mark of the Web via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2327-m5w2-rg7f

почти 4 года назад

The icmp_send function in net/ipv4/icmp.c in the Linux kernel before 2.6.25, when configured as a router with a REJECT route, does not properly manage the Protocol Independent Destination Cache (aka DST) in some situations involving transmission of an ICMP Host Unreachable message, which allows remote attackers to cause a denial of service (connectivity outage) by sending a large series of packets to many destination IP addresses within this REJECT route, related to an "rt_cache leak."

EPSS: Низкий
github логотип

GHSA-2326-xfc9-g293

больше 3 лет назад

SQL injection vulnerability in related.php in Milw0rm Clone Script 1.0 allows remote attackers to execute arbitrary SQL commands via the program parameter.

EPSS: Низкий
github логотип

GHSA-2326-pfpj-vx3h

больше 1 года назад

lexical-core has multiple soundness issues

EPSS: Низкий
github логотип

GHSA-2326-jr9x-m329

3 месяца назад

A SQL injection vulnerability exists in CSZ-CMS <=1.3.0 in the Form Builder view functionality. The vulnerability is located in the field parameter of the form viewing feature, allowing authenticated administrators to execute arbitrary SQL queries.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2326-hx7g-3m9r

больше 1 года назад

Apache MINA SSHD: integrity check bypass

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2326-85qm-8gr9

больше 3 лет назад

Integer overflow in the rwpng_read_image24_libpng function in rwpng.c in pngquant 2.7.0 allows remote attackers to have unspecified impact via a crafted PNG file, which triggers a buffer overflow.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2325-58pf-r6qj

больше 2 лет назад

Incorrect Default Permissions vulnerability due to incomplete fix to address CVE-2020-14496 in Mitsubishi Electric Corporation FA engineering software products allows a malicious local attacker to execute a malicious code, which could result in information disclosure, tampering with and deletion, or a denial-of-service (DoS) condition. However, if the mitigated version described in the advisory for CVE-2020-14496 is used and installed in the default installation folder, this vulnerability does not affect the products.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-2324-wjjf-834r

больше 3 лет назад

The Soccer Blitz (aka soccer.blitz) application 1.06 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-232p-99pf-h332

Umlet version < 14.3 contains a XML External Entity (XXE) vulnerability in File parsing that can result in disclosure of confidential data, denial of service, server side request forgery. This attack appear to be exploitable via Specially crafted UXF file. This vulnerability appears to have been fixed in 14.3.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-232p-59mg-f98p

Microweber Cross-site Scripting can result in redirection to a malicious site

CVSS3: 6.1
16%
Средний
больше 3 лет назад
github логотип
GHSA-232m-xvr4-2347

A Cross-site Scripting vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.7, 5.2 and earlier, allows attacker to inject arbitrary web script or HTML via maliciously crafted "Host" header in user HTTP requests.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-232m-53gr-9v22

The (1) agp_generic_alloc_page and (2) agp_generic_alloc_pages functions in drivers/char/agp/generic.c in the agp subsystem in the Linux kernel before 2.6.30-rc3 do not zero out pages that may later be available to a user-space process, which allows local users to obtain sensitive information by reading these pages.

0%
Низкий
почти 4 года назад
github логотип
GHSA-232g-vj6v-88w6

An exploitable local privilege elevation vulnerability exists in the file system permissions of GOG Galaxy's “Games” directory, version 1.2.48.36 (Windows 64-bit Installer). An attacker can overwrite executables of installed games to exploit this vulnerability and execute arbitrary code with elevated privileges.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-232g-h7w4-2pxj

Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to 1.0.8.

CVSS3: 9.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-232f-9f2g-m34q

Unspecified vulnerability in Sun Java System Web Server 6.0 and 6.1 before 20070315 allows remote attackers to "gain unauthorized access to data", possibly involving a sample application.

1%
Низкий
почти 4 года назад
github логотип
GHSA-232f-8fc5-f649

Multiple SQL injection vulnerabilities in Advanced Webhost Billing System (AWBS) before 2.6.0, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: this can be leveraged for XSS attacks that "bypass AWBS's anti-XSS input validation."

0%
Низкий
почти 4 года назад
github логотип
GHSA-232f-66gw-9wfc

A SQL Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to directly modify the SQL query.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2328-vc59-64q8

The key-management component in Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allows remote attackers to trigger unintended content in outbound e-mail messages via a crafted key UID value in an inbound e-mail message, as demonstrated by the outbound Subject header.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2328-876m-g2rg

In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2327-x98x-57c5

Inappropriate implementation in Downloads in Google Chrome on Windows prior to 140.0.7339.80 allowed a remote attacker to bypass Mark of the Web via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 5.4
0%
Низкий
3 месяца назад
github логотип
GHSA-2327-m5w2-rg7f

The icmp_send function in net/ipv4/icmp.c in the Linux kernel before 2.6.25, when configured as a router with a REJECT route, does not properly manage the Protocol Independent Destination Cache (aka DST) in some situations involving transmission of an ICMP Host Unreachable message, which allows remote attackers to cause a denial of service (connectivity outage) by sending a large series of packets to many destination IP addresses within this REJECT route, related to an "rt_cache leak."

1%
Низкий
почти 4 года назад
github логотип
GHSA-2326-xfc9-g293

SQL injection vulnerability in related.php in Milw0rm Clone Script 1.0 allows remote attackers to execute arbitrary SQL commands via the program parameter.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2326-pfpj-vx3h

lexical-core has multiple soundness issues

больше 1 года назад
github логотип
GHSA-2326-jr9x-m329

A SQL injection vulnerability exists in CSZ-CMS <=1.3.0 in the Form Builder view functionality. The vulnerability is located in the field parameter of the form viewing feature, allowing authenticated administrators to execute arbitrary SQL queries.

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-2326-hx7g-3m9r

Apache MINA SSHD: integrity check bypass

CVSS3: 5.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-2326-85qm-8gr9

Integer overflow in the rwpng_read_image24_libpng function in rwpng.c in pngquant 2.7.0 allows remote attackers to have unspecified impact via a crafted PNG file, which triggers a buffer overflow.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2325-58pf-r6qj

Incorrect Default Permissions vulnerability due to incomplete fix to address CVE-2020-14496 in Mitsubishi Electric Corporation FA engineering software products allows a malicious local attacker to execute a malicious code, which could result in information disclosure, tampering with and deletion, or a denial-of-service (DoS) condition. However, if the mitigated version described in the advisory for CVE-2020-14496 is used and installed in the default installation folder, this vulnerability does not affect the products.

CVSS3: 9.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2324-wjjf-834r

The Soccer Blitz (aka soccer.blitz) application 1.06 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу