Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 326 109

Количество 326 109

github логотип

GHSA-2g54-42rw-p43x

почти 4 года назад

The specific function in ASUS BMC’s firmware Web management page (Modify user’s information function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

EPSS: Низкий
github логотип

GHSA-2g53-pmw3-ccp9

почти 4 года назад

CheckSec Canopy 3.x before 3.0.7 has stored XSS via the Login Page Disclaimer, allowing attacks by low-privileged users against higher-privileged users.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2g53-3pj8-qvxv

почти 4 года назад

Use-after-free vulnerability in the path_openat function in fs/namei.c in the Linux kernel 3.x and 4.x before 4.0.4 allows local users to cause a denial of service or possibly have unspecified other impact via O_TMPFILE filesystem operations that leverage a duplicate cleanup operation.

EPSS: Низкий
github логотип

GHSA-2g52-qw8q-wfr9

больше 1 года назад

Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed. This vulnerability affects Firefox < 134.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-2g52-f4rf-8vm9

около 2 месяцев назад

A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf() function, where a task object is freed multiple times in certain error-handling paths. This redundant memory deallocation can lead to a double-free condition, potentially causing FFmpeg or any application using it to crash when processing TensorFlow-based DNN models. This results in a denial-of-service scenario but does not allow arbitrary code execution under normal conditions.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-2g4x-xxrm-h5mw

почти 4 года назад

Dell Encryption (formerly Dell Data Protection | Encryption) v10.1.0 and earlier contain an information disclosure vulnerability. A malicious user with physical access to the machine could potentially exploit this vulnerability to access the unencrypted RegBack folder that contains back-ups of sensitive system files.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2g4x-p9qv-phcg

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in Gallery 3 before 3.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) movie title to modules/gallery/controllers/movies.php or (2) key variable to modules/gallery/views/error_admin.html.php.

EPSS: Низкий
github логотип

GHSA-2g4x-fv7q-8jrf

почти 4 года назад

Insufficient data validation in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.

EPSS: Низкий
github логотип

GHSA-2g4x-3mj5-gvj6

почти 4 года назад

Multiple buffer overflows in the Broderbund Expressit 3DGreetings Player ActiveX control could allow remote attackers to execute arbitrary code via unspecified vectors.

EPSS: Средний
github логотип

GHSA-2g4w-xqhx-j2x8

почти 4 года назад

OpenSource Moddable v10.5.0 was discovered to contain a stack overflow via the component /moddable/xs/sources/xsScript.c.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2g4w-jfv5-fgmr

4 месяца назад

Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms FreshDesk Plugin gf-freshdesk allows Object Injection.This issue affects WP Gravity Forms FreshDesk Plugin: from n/a through <= 1.3.5.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2g4w-fv9w-h3mm

почти 4 года назад

SQL injection vulnerability in ArrayOS before AG 9.4.0.135, when the portal bookmark function is enabled, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2g4w-cqhh-m9w9

около 2 лет назад

VMware SD-WAN Edge contains a missing authentication and protection mechanism vulnerability. A malicious actor with physical access to the SD-WAN Edge appliance during activation can potentially exploit this vulnerability to access the BIOS configuration. In addition, the malicious actor may be able to exploit the default boot priority configured.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2g4w-262r-45rr

почти 4 года назад

In openlibrary versions deploy-2016-07-0 through deploy-2021-12-22 are vulnerable to Stored XSS.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2g4v-qc3v-672p

почти 4 года назад

Buffer overflow in ByteCatcher FTP client 1.04b allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP server banner.

EPSS: Средний
github логотип

GHSA-2g4v-8vvw-r8m9

почти 2 года назад

An issue discovered in skycaiji 2.8 allows attackers to run arbitrary code via crafted POST request to /index.php?s=/admin/develop/editor_save.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2g4r-w789-9wg5

почти 4 года назад

In macOS High Sierra before 10.13.4, there was an issue with the handling of smartcard PINs. This issue was addressed with additional logic.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2g4r-fqm7-xqfm

больше 2 лет назад

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, tvOS 16.6, Safari 16.6, watchOS 9.6. Processing web content may lead to arbitrary code execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2g4r-3v66-3h7f

около 1 года назад

Open5GS MME version <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Context Modification Failure` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-2g4q-9vm9-9fw4

почти 2 года назад

Jenkins Script Security Plugin sandbox bypass vulnerability

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2g54-42rw-p43x

The specific function in ASUS BMC’s firmware Web management page (Modify user’s information function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2g53-pmw3-ccp9

CheckSec Canopy 3.x before 3.0.7 has stored XSS via the Login Page Disclaimer, allowing attacks by low-privileged users against higher-privileged users.

CVSS3: 4.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-2g53-3pj8-qvxv

Use-after-free vulnerability in the path_openat function in fs/namei.c in the Linux kernel 3.x and 4.x before 4.0.4 allows local users to cause a denial of service or possibly have unspecified other impact via O_TMPFILE filesystem operations that leverage a duplicate cleanup operation.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2g52-qw8q-wfr9

Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed. This vulnerability affects Firefox < 134.

CVSS3: 3.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2g52-f4rf-8vm9

A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf() function, where a task object is freed multiple times in certain error-handling paths. This redundant memory deallocation can lead to a double-free condition, potentially causing FFmpeg or any application using it to crash when processing TensorFlow-based DNN models. This results in a denial-of-service scenario but does not allow arbitrary code execution under normal conditions.

CVSS3: 3.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2g4x-xxrm-h5mw

Dell Encryption (formerly Dell Data Protection | Encryption) v10.1.0 and earlier contain an information disclosure vulnerability. A malicious user with physical access to the machine could potentially exploit this vulnerability to access the unencrypted RegBack folder that contains back-ups of sensitive system files.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-2g4x-p9qv-phcg

Multiple cross-site scripting (XSS) vulnerabilities in Gallery 3 before 3.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) movie title to modules/gallery/controllers/movies.php or (2) key variable to modules/gallery/views/error_admin.html.php.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2g4x-fv7q-8jrf

Insufficient data validation in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2g4x-3mj5-gvj6

Multiple buffer overflows in the Broderbund Expressit 3DGreetings Player ActiveX control could allow remote attackers to execute arbitrary code via unspecified vectors.

11%
Средний
почти 4 года назад
github логотип
GHSA-2g4w-xqhx-j2x8

OpenSource Moddable v10.5.0 was discovered to contain a stack overflow via the component /moddable/xs/sources/xsScript.c.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-2g4w-jfv5-fgmr

Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms FreshDesk Plugin gf-freshdesk allows Object Injection.This issue affects WP Gravity Forms FreshDesk Plugin: from n/a through <= 1.3.5.

CVSS3: 9.8
0%
Низкий
4 месяца назад
github логотип
GHSA-2g4w-fv9w-h3mm

SQL injection vulnerability in ArrayOS before AG 9.4.0.135, when the portal bookmark function is enabled, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-2g4w-cqhh-m9w9

VMware SD-WAN Edge contains a missing authentication and protection mechanism vulnerability. A malicious actor with physical access to the SD-WAN Edge appliance during activation can potentially exploit this vulnerability to access the BIOS configuration. In addition, the malicious actor may be able to exploit the default boot priority configured.

CVSS3: 4.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-2g4w-262r-45rr

In openlibrary versions deploy-2016-07-0 through deploy-2021-12-22 are vulnerable to Stored XSS.

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-2g4v-qc3v-672p

Buffer overflow in ByteCatcher FTP client 1.04b allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP server banner.

25%
Средний
почти 4 года назад
github логотип
GHSA-2g4v-8vvw-r8m9

An issue discovered in skycaiji 2.8 allows attackers to run arbitrary code via crafted POST request to /index.php?s=/admin/develop/editor_save.

CVSS3: 9.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-2g4r-w789-9wg5

In macOS High Sierra before 10.13.4, there was an issue with the handling of smartcard PINs. This issue was addressed with additional logic.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-2g4r-fqm7-xqfm

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, tvOS 16.6, Safari 16.6, watchOS 9.6. Processing web content may lead to arbitrary code execution.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2g4r-3v66-3h7f

Open5GS MME version <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Context Modification Failure` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.

CVSS3: 8.6
0%
Низкий
около 1 года назад
github логотип
GHSA-2g4q-9vm9-9fw4

Jenkins Script Security Plugin sandbox bypass vulnerability

CVSS3: 8.8
0%
Низкий
почти 2 года назад

Уязвимостей на страницу