Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 315 672

Количество 315 672

github логотип

GHSA-229x-53vm-m4f4

почти 4 года назад

kernel drivers before version 4.17-rc1 are vulnerable to a weakness in the Linux kernel's implementation of random seed data. Programs, early in the boot sequence, could use the data allocated for the seed before it was sufficiently generated.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-229x-22xc-2f2w

больше 1 года назад

Zendframework Local file disclosure via XXE injection in Zend_XmlRpc

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-229w-w68g-gcf2

почти 4 года назад

HP eSupportDiagnostics ActiveX control (hpediag.dll) 1.0.11.0 exports dangerous methods, which allows remote attackers to (1) read arbitrary files via the ReadTextFile method, or (2) read arbitrary registry values via the ReadValue method.

EPSS: Низкий
github логотип

GHSA-229w-c447-wm6p

почти 4 года назад

The faxrunq and faxrunqd in the mgetty package allows local users to create or modify arbitrary files via a symlink attack which creates a symlink in from /var/spool/fax/outgoing/.last_run to the target file.

EPSS: Низкий
github логотип

GHSA-229w-7xcx-5jhf

больше 3 лет назад

The Magic Balloonman Marty Boone (aka com.app_martyboone.layout) application 1.400 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-229v-p5vr-f583

больше 3 лет назад

Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100 version 9.0.0.3 and earlier.

CVSS3: 7.5
EPSS: Критический
github логотип

GHSA-229v-5p54-p9xc

больше 1 года назад

Vulnerability of insufficient permission verification in the NearLink module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-229r-rxf9-m7pj

почти 4 года назад

The gmp plugin in strongSwan before 5.5.3 does not properly validate RSA public keys before calling mpz_powm_sec, which allows remote peers to cause a denial of service (floating point exception and process crash) via a crafted certificate.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-229r-prfj-6g65

почти 4 года назад

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, and SD 850, if the size parameter passed to TZ_PR_CMD_CONTENT_SET_PROP is small, an integer underflow occurs.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-229r-pqp6-8w6g

больше 8 лет назад

sprout Arbitrary Code Execution vulnerability

EPSS: Низкий
github логотип

GHSA-229r-cp46-m292

больше 2 лет назад

An issue was discovered in the Linux kernel before 6.3.8. fs/smb/server/connection.c in ksmbd does not validate the relationship between the NetBIOS header's length field and the SMB header sizes, via pdu_size in ksmbd_conn_handler_loop, leading to an out-of-bounds read.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-229q-96qr-8qq9

около 1 месяца назад

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.4, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2.0 through 7.2.10, FortiClientEMS 7.0 all versions may allow an authenticated attacker with at least read-only admin permission to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-229q-863f-g82c

больше 3 лет назад

components/Modals/HelpModal.jsx in BloodHound 2.2.0 allows remote attackers to execute arbitrary OS commands (by spawning a child process as the current user on the victim's machine) when the search function's autocomplete feature is used. The victim must import data from an Active Directory with a GPO containing JavaScript in its name.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-229m-w66g-mjph

больше 2 лет назад

A vulnerability was found in Beijing Baichuo Smart S85F Management Platform up to 20231012. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /importexport.php. The manipulation leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-243061 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-229j-rfxx-8ppq

около 1 года назад

The FAQ And Answers – Create Frequently Asked Questions Area on WP Sites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'faq' shortcode in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-229j-2335-rg3h

больше 3 лет назад

** UNSUPPORTED WHEN ASSIGNED ** Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the /WebCM/Applications/Reports/index.jsp file via the by parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-229h-qp2g-jhr9

больше 3 лет назад

minerstat msOS before 2019-10-23 does not have a unique SSH key for each instance of the product.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-229h-mpm4-83qq

почти 4 года назад

Drupal 6.x before 6.13 does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote authenticated users to inject arbitrary web script, HTML, and possibly PHP code via a crafted user signature.

EPSS: Низкий
github логотип

GHSA-229g-v59m-656v

почти 4 года назад

Buffer overflow in ddicgi.exe in Mobius DocumentDirect for the Internet 1.2 allows remote attackers to execute arbitrary commands via a long User-Agent parameter.

EPSS: Низкий
github логотип

GHSA-229f-x533-c4r4

2 месяца назад

The HTML Forms – Simple WordPress Forms Plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.0 due to insufficient sanitization of fabricated file upload field metadata before displaying it in the WordPress admin dashboard. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute whenever an administrator accesses the form submissions page.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-229x-53vm-m4f4

kernel drivers before version 4.17-rc1 are vulnerable to a weakness in the Linux kernel's implementation of random seed data. Programs, early in the boot sequence, could use the data allocated for the seed before it was sufficiently generated.

CVSS3: 5.9
0%
Низкий
почти 4 года назад
github логотип
GHSA-229x-22xc-2f2w

Zendframework Local file disclosure via XXE injection in Zend_XmlRpc

CVSS3: 8.6
больше 1 года назад
github логотип
GHSA-229w-w68g-gcf2

HP eSupportDiagnostics ActiveX control (hpediag.dll) 1.0.11.0 exports dangerous methods, which allows remote attackers to (1) read arbitrary files via the ReadTextFile method, or (2) read arbitrary registry values via the ReadValue method.

9%
Низкий
почти 4 года назад
github логотип
GHSA-229w-c447-wm6p

The faxrunq and faxrunqd in the mgetty package allows local users to create or modify arbitrary files via a symlink attack which creates a symlink in from /var/spool/fax/outgoing/.last_run to the target file.

0%
Низкий
почти 4 года назад
github логотип
GHSA-229w-7xcx-5jhf

The Magic Balloonman Marty Boone (aka com.app_martyboone.layout) application 1.400 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-229v-p5vr-f583

Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100 version 9.0.0.3 and earlier.

CVSS3: 7.5
94%
Критический
больше 3 лет назад
github логотип
GHSA-229v-5p54-p9xc

Vulnerability of insufficient permission verification in the NearLink module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS3: 4
0%
Низкий
больше 1 года назад
github логотип
GHSA-229r-rxf9-m7pj

The gmp plugin in strongSwan before 5.5.3 does not properly validate RSA public keys before calling mpz_powm_sec, which allows remote peers to cause a denial of service (floating point exception and process crash) via a crafted certificate.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-229r-prfj-6g65

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, and SD 850, if the size parameter passed to TZ_PR_CMD_CONTENT_SET_PROP is small, an integer underflow occurs.

CVSS3: 9.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-229r-pqp6-8w6g

sprout Arbitrary Code Execution vulnerability

1%
Низкий
больше 8 лет назад
github логотип
GHSA-229r-cp46-m292

An issue was discovered in the Linux kernel before 6.3.8. fs/smb/server/connection.c in ksmbd does not validate the relationship between the NetBIOS header's length field and the SMB header sizes, via pdu_size in ksmbd_conn_handler_loop, leading to an out-of-bounds read.

CVSS3: 9.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-229q-96qr-8qq9

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.4, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2.0 through 7.2.10, FortiClientEMS 7.0 all versions may allow an authenticated attacker with at least read-only admin permission to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.

CVSS3: 7.2
0%
Низкий
около 1 месяца назад
github логотип
GHSA-229q-863f-g82c

components/Modals/HelpModal.jsx in BloodHound 2.2.0 allows remote attackers to execute arbitrary OS commands (by spawning a child process as the current user on the victim's machine) when the search function's autocomplete feature is used. The victim must import data from an Active Directory with a GPO containing JavaScript in its name.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-229m-w66g-mjph

A vulnerability was found in Beijing Baichuo Smart S85F Management Platform up to 20231012. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /importexport.php. The manipulation leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-243061 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.7
8%
Низкий
больше 2 лет назад
github логотип
GHSA-229j-rfxx-8ppq

The FAQ And Answers – Create Frequently Asked Questions Area on WP Sites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'faq' shortcode in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
около 1 года назад
github логотип
GHSA-229j-2335-rg3h

** UNSUPPORTED WHEN ASSIGNED ** Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the /WebCM/Applications/Reports/index.jsp file via the by parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-229h-qp2g-jhr9

minerstat msOS before 2019-10-23 does not have a unique SSH key for each instance of the product.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-229h-mpm4-83qq

Drupal 6.x before 6.13 does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote authenticated users to inject arbitrary web script, HTML, and possibly PHP code via a crafted user signature.

1%
Низкий
почти 4 года назад
github логотип
GHSA-229g-v59m-656v

Buffer overflow in ddicgi.exe in Mobius DocumentDirect for the Internet 1.2 allows remote attackers to execute arbitrary commands via a long User-Agent parameter.

6%
Низкий
почти 4 года назад
github логотип
GHSA-229f-x533-c4r4

The HTML Forms – Simple WordPress Forms Plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.0 due to insufficient sanitization of fabricated file upload field metadata before displaying it in the WordPress admin dashboard. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute whenever an administrator accesses the form submissions page.

CVSS3: 6.1
0%
Низкий
2 месяца назад

Уязвимостей на страницу