Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 326 121

Количество 326 121

github логотип

GHSA-2gp2-mfg4-q5mv

около 2 месяцев назад

IBM Cloud Pak System 2.3.3.6, 2.3.3.7, 2.3.4.0, 2.3.4.1, and 2.3.5.0 could disclose folder location information to an unauthenticated attacker that could aid in further attacks against the system.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2gmw-j4qh-8xwv

почти 4 года назад

Directory traversal vulnerability in rss.php in fuzzylime (cms) 3.01a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the p parameter, as demonstrated using content.php, a different vector than CVE-2007-4805.

EPSS: Низкий
github логотип

GHSA-2gmw-gg2v-3ffg

почти 4 года назад

An issue was discovered in the Linux kernel before 5.2. There is a NULL pointer dereference in tw5864_handle_frame() in drivers/media/pci/tw5864/tw5864-video.c, which may cause denial of service, aka CID-2e7682ebfc75.

EPSS: Низкий
github логотип

GHSA-2gmw-4qv6-96c6

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in jobseekers/forgot.php in Diesel Job Site allow remote attackers to inject arbitrary web script or HTML via the (1) uname or (2) SEmail parameters.

EPSS: Низкий
github логотип

GHSA-2gmw-2prf-4jf5

5 дней назад

The LightPress Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `group` attribute in the `[gallery]` shortcode in all versions up to, and including, 2.3.4. This is due to the plugin modifying gallery shortcode output to include the `group` attribute value without proper escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2gmv-qx2q-7g63

почти 3 года назад

A vulnerability, which was classified as problematic, has been found in Icons for Features Plugin 1.0.0 on WordPress. Affected by this issue is some unknown functionality of the file classes/class-icons-for-features-admin.php. The manipulation of the argument redirect_url leads to open redirect. The attack may be launched remotely. Upgrading to version 1.0.1 is able to address this issue. The name of the patch is 63124c021ae24b68e56872530df26eb4268ad633. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-227756.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-2gmv-2r3v-jxj2

25 дней назад

Stored XSS in PySpector HTML Report Generation leads to Javascript Code Execution

EPSS: Низкий
github логотип

GHSA-2gmr-x2wc-4g5j

почти 4 года назад

Heap-based buffer overflow in the read_u32 function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG image.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2gmr-vqp5-r9qg

3 месяца назад

A vulnerability was detected in quickjs-ng quickjs up to 0.11.0. Affected is an unknown function of the file quickjs.c of the component Atomics Ops Handler. The manipulation results in use after free. The attack can be executed remotely. The exploit is now public and may be used. The patch is identified as ea3e9d77454e8fc9cb3ef3c504e9c16af5a80141. Applying a patch is advised to resolve this issue.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2gmr-g5v4-9cch

больше 1 года назад

A vulnerability, which was classified as critical, was found in X1a0He Adobe Downloader up to 1.3.1 on macOS. Affected is the function shouldAcceptNewConnection of the file com.x1a0he.macOS.Adobe-Downloader.helper of the component XPC Service. The manipulation leads to improper privilege management. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. This product is not affiliated with the company Adobe.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2gmr-48xr-j34m

почти 4 года назад

Stack-based buffer overflow in emacs allows user-assisted attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a large precision value in an integer format string specifier to the format function, as demonstrated via a certain "emacs -batch -eval" command line.

EPSS: Низкий
github логотип

GHSA-2gmr-34h7-prwx

10 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpsoul Greenshift allows DOM-Based XSS. This issue affects Greenshift: from n/a through 11.5.5.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2gmr-2pr2-53jf

почти 4 года назад

Multiple stack-based buffer overflows in CFProfile.exe in Toshiba ConfigFree Utility 8.0.38 allow user-assisted attackers to execute arbitrary code.

EPSS: Низкий
github логотип

GHSA-2gmq-r86r-gvhw

почти 4 года назад

Stack-based buffer overflow in the "Add from text file" feature in the DameWare Exporter tool (DWExporter.exe) in DameWare Remote Support 10.0.0.372, 9.0.1.247, and earlier allows user-assisted attackers to execute arbitrary code via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2gmq-m9wq-x923

почти 4 года назад

In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06493873; Issue ID: ALPS06493899.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2gmq-3r6v-g7jx

почти 4 года назад

Stack-based buffer overflow in the IASystemInfo.dll ActiveX control in (1) InterActual Player 2.60.12.0717, (2) Roxio CinePlayer 3.2, (3) WinDVD 7.0.27.172, and possibly other products, allows remote attackers to execute arbitrary code via a long ApplicationType property.

EPSS: Высокий
github логотип

GHSA-2gmp-x9r7-xp6q

больше 1 года назад

Improper Null Termination vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of10::Port:unpack. This issue affects libfluid: 0.1.0.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2gmp-hjmm-v2wx

около 3 лет назад

Incorrect Access Control issue discoverd in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to write arbitrary files via improper sanitation on the source for COPY and MOVE operations.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-2gmp-cvhp-m5qp

почти 4 года назад

Cisco AnyConnect Secure Mobility Client before 4.2.05015 and 4.3.x before 4.3.02039 mishandles pathnames, which allows local users to gain privileges via a crafted INF file, aka Bug ID CSCuz92464.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2gmp-8pr5-3jc6

почти 4 года назад

In JetBrains TeamCity before 2020.2.4, there was an insecure deserialization.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2gp2-mfg4-q5mv

IBM Cloud Pak System 2.3.3.6, 2.3.3.7, 2.3.4.0, 2.3.4.1, and 2.3.5.0 could disclose folder location information to an unauthenticated attacker that could aid in further attacks against the system.

CVSS3: 5.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2gmw-j4qh-8xwv

Directory traversal vulnerability in rss.php in fuzzylime (cms) 3.01a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the p parameter, as demonstrated using content.php, a different vector than CVE-2007-4805.

7%
Низкий
почти 4 года назад
github логотип
GHSA-2gmw-gg2v-3ffg

An issue was discovered in the Linux kernel before 5.2. There is a NULL pointer dereference in tw5864_handle_frame() in drivers/media/pci/tw5864/tw5864-video.c, which may cause denial of service, aka CID-2e7682ebfc75.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2gmw-4qv6-96c6

Multiple cross-site scripting (XSS) vulnerabilities in jobseekers/forgot.php in Diesel Job Site allow remote attackers to inject arbitrary web script or HTML via the (1) uname or (2) SEmail parameters.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2gmw-2prf-4jf5

The LightPress Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `group` attribute in the `[gallery]` shortcode in all versions up to, and including, 2.3.4. This is due to the plugin modifying gallery shortcode output to include the `group` attribute value without proper escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
5 дней назад
github логотип
GHSA-2gmv-qx2q-7g63

A vulnerability, which was classified as problematic, has been found in Icons for Features Plugin 1.0.0 on WordPress. Affected by this issue is some unknown functionality of the file classes/class-icons-for-features-admin.php. The manipulation of the argument redirect_url leads to open redirect. The attack may be launched remotely. Upgrading to version 1.0.1 is able to address this issue. The name of the patch is 63124c021ae24b68e56872530df26eb4268ad633. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-227756.

CVSS3: 3.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-2gmv-2r3v-jxj2

Stored XSS in PySpector HTML Report Generation leads to Javascript Code Execution

0%
Низкий
25 дней назад
github логотип
GHSA-2gmr-x2wc-4g5j

Heap-based buffer overflow in the read_u32 function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG image.

CVSS3: 6.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-2gmr-vqp5-r9qg

A vulnerability was detected in quickjs-ng quickjs up to 0.11.0. Affected is an unknown function of the file quickjs.c of the component Atomics Ops Handler. The manipulation results in use after free. The attack can be executed remotely. The exploit is now public and may be used. The patch is identified as ea3e9d77454e8fc9cb3ef3c504e9c16af5a80141. Applying a patch is advised to resolve this issue.

CVSS3: 6.3
0%
Низкий
3 месяца назад
github логотип
GHSA-2gmr-g5v4-9cch

A vulnerability, which was classified as critical, was found in X1a0He Adobe Downloader up to 1.3.1 on macOS. Affected is the function shouldAcceptNewConnection of the file com.x1a0he.macOS.Adobe-Downloader.helper of the component XPC Service. The manipulation leads to improper privilege management. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. This product is not affiliated with the company Adobe.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2gmr-48xr-j34m

Stack-based buffer overflow in emacs allows user-assisted attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a large precision value in an integer format string specifier to the format function, as demonstrated via a certain "emacs -batch -eval" command line.

3%
Низкий
почти 4 года назад
github логотип
GHSA-2gmr-34h7-prwx

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpsoul Greenshift allows DOM-Based XSS. This issue affects Greenshift: from n/a through 11.5.5.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-2gmr-2pr2-53jf

Multiple stack-based buffer overflows in CFProfile.exe in Toshiba ConfigFree Utility 8.0.38 allow user-assisted attackers to execute arbitrary code.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2gmq-r86r-gvhw

Stack-based buffer overflow in the "Add from text file" feature in the DameWare Exporter tool (DWExporter.exe) in DameWare Remote Support 10.0.0.372, 9.0.1.247, and earlier allows user-assisted attackers to execute arbitrary code via unspecified vectors.

3%
Низкий
почти 4 года назад
github логотип
GHSA-2gmq-m9wq-x923

In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06493873; Issue ID: ALPS06493899.

CVSS3: 6.7
0%
Низкий
почти 4 года назад
github логотип
GHSA-2gmq-3r6v-g7jx

Stack-based buffer overflow in the IASystemInfo.dll ActiveX control in (1) InterActual Player 2.60.12.0717, (2) Roxio CinePlayer 3.2, (3) WinDVD 7.0.27.172, and possibly other products, allows remote attackers to execute arbitrary code via a long ApplicationType property.

73%
Высокий
почти 4 года назад
github логотип
GHSA-2gmp-x9r7-xp6q

Improper Null Termination vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of10::Port:unpack. This issue affects libfluid: 0.1.0.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2gmp-hjmm-v2wx

Incorrect Access Control issue discoverd in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to write arbitrary files via improper sanitation on the source for COPY and MOVE operations.

CVSS3: 9.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-2gmp-cvhp-m5qp

Cisco AnyConnect Secure Mobility Client before 4.2.05015 and 4.3.x before 4.3.02039 mishandles pathnames, which allows local users to gain privileges via a crafted INF file, aka Bug ID CSCuz92464.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-2gmp-8pr5-3jc6

In JetBrains TeamCity before 2020.2.4, there was an insecure deserialization.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу