Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 325 903

Количество 325 903

github логотип

GHSA-2fj9-2rp2-mmg4

почти 4 года назад

Windows Hyper-V Denial of Service Vulnerability.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2fj8-grv4-35fw

почти 4 года назад

MultiTheftAuto 0.5 patch 1 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted command 40 that causes a -1 length to be used and triggers an out-of-bounds read.

EPSS: Низкий
github логотип

GHSA-2fj7-x5rw-vhgp

почти 4 года назад

u'Possible buffer overflow in Fastrpc while handling received parameters due to lack of validation on input parameters' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in APQ8098, MSM8998, QCM4290, QCM6125, QCS410, QCS4290, QCS610, QCS6125, QSM8250, QSM8350, SA6145P, SA6150P, SA6155, SA6155P, SA8150P, SA8155, SA8155P, SA8195P, SC7180, SDA640, SDA660, SDA845, SDA855, SDM640, SDM660, SDM830, SDM845, SDM850, SDX50M, SDX55, SDX55M, SM4250, SM4250P, SM6115, SM6115P, SM6125, SM6150, SM6150P, SM6250, SM6250P, SM6350, SM7125, SM7150, SM7150P, SM7225, SM7250, SM7250P, SM8150, SM8150P, SM8250, SM8350, SM8350P, SXR2130, SXR2130P

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2fj7-pwvv-p427

почти 4 года назад

An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'.

EPSS: Средний
github логотип

GHSA-2fj7-8rfc-4ffg

почти 4 года назад

Unspecified vulnerability in Oracle Solaris 10 allows remote attackers to affect confidentiality, related to Network Services Library (libnsl).

EPSS: Низкий
github логотип

GHSA-2fj7-8prf-hq8g

почти 4 года назад

This vulnerability allows local attackers to escalate privileges on affected installations of Foxit Reader 10.0.0.35798. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of the configuration files used by the Foxit Reader Update Service. The issue results from incorrect permissions set on a resource used by the service. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of SYSTEM. Was ZDI-CAN-11229.

EPSS: Низкий
github логотип

GHSA-2fj7-8jvc-76xv

почти 4 года назад

Buffer overflow in wu-ftp from PASV command causes a core dump.

EPSS: Низкий
github логотип

GHSA-2fj5-qrfc-r9c5

почти 4 года назад

Unspecified vulnerability in the Java plugin in IBM WebSphere Application Server 5.0.2 allows untrusted applets to gain privileges via unknown attack vectors.

EPSS: Низкий
github логотип

GHSA-2fj5-45wv-94qc

почти 4 года назад

Unspecified vulnerability in Cisco CiscoWorks Common Services 3.0.3 through 3.1.1 allows remote attackers to execute arbitrary code on a client machine via unknown vectors.

EPSS: Низкий
github логотип

GHSA-2fj3-qvr8-q2c6

16 дней назад

Deserialization of Untrusted Data vulnerability in thememount Apicona apicona allows Object Injection.This issue affects Apicona: from n/a through <= 24.1.0.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2fj3-jhcw-972x

почти 4 года назад

Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.01 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.

EPSS: Низкий
github логотип

GHSA-2fj3-3wfr-c7r6

больше 2 лет назад

DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2fj2-f362-29wp

почти 4 года назад

Buffer overflow in the changevalue function in libcgi.h for Marcos Luiz Onisto Lib CGI 0.1 allows remote attackers to execute arbitrary code via a long argument.

EPSS: Низкий
github логотип

GHSA-2fj2-4h38-3c72

почти 4 года назад

The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu kernel to allow unprivileged overlay mounts, an attacker could use this to gain elevated privileges.

CVSS3: 7.8
EPSS: Высокий
github логотип

GHSA-2fj2-4833-36ww

почти 4 года назад

Insufficient key management for Intel(R) Data Center Manager SDK before version 5.0.2 may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2fhx-5jj5-pjhv

около 2 месяцев назад

Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable data corruption. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-2fhx-4cr3-fgxc

почти 4 года назад

A stack-based buffer overflow in the LAN UPnP service running on UDP port 1900 of Swisscom Internet-Box (2, Standard, and Plus) prior to v09.04.00 and Internet-Box light prior to v08.05.02 allows remote code execution. No authentication is required to exploit this vulnerability. Sending a simple UDP packet to port 1900 allows an attacker to execute code on a remote device. However, this is only possible if the attacker is inside the LAN. Because of ASLR, the success rate is not 100% and leads instead to a DoS of the UPnP service. The remaining functionality of the Internet Box is not affected. A reboot of the Internet Box is necessary to attempt the exploit again.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2fhw-h5f5-45gf

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in noonnoo Gravel allows Reflected XSS.This issue affects Gravel: from n/a through 1.6.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2fhw-2j7m-mr4m

7 месяцев назад

TYPO3 backend modules have Broken Access Control

EPSS: Низкий
github логотип

GHSA-2fhv-pxmp-gpwh

около 1 года назад

On most desktop platforms, Brave Browser versions 1.70.x-1.73.x included a feature to show a site's origin on the OS-provided file selector dialog when a site prompts the user to upload or download a file. However the origin was not correctly inferred in some cases. When combined with an open redirector vulnerability on a trusted site, this could allow a malicious site to initiate a download whose origin in the file select dialog appears as the trusted site which initiated the redirect.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2fj9-2rp2-mmg4

Windows Hyper-V Denial of Service Vulnerability.

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-2fj8-grv4-35fw

MultiTheftAuto 0.5 patch 1 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted command 40 that causes a -1 length to be used and triggers an out-of-bounds read.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2fj7-x5rw-vhgp

u'Possible buffer overflow in Fastrpc while handling received parameters due to lack of validation on input parameters' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in APQ8098, MSM8998, QCM4290, QCM6125, QCS410, QCS4290, QCS610, QCS6125, QSM8250, QSM8350, SA6145P, SA6150P, SA6155, SA6155P, SA8150P, SA8155, SA8155P, SA8195P, SC7180, SDA640, SDA660, SDA845, SDA855, SDM640, SDM660, SDM830, SDM845, SDM850, SDX50M, SDX55, SDX55M, SM4250, SM4250P, SM6115, SM6115P, SM6125, SM6150, SM6150P, SM6250, SM6250P, SM6350, SM7125, SM7150, SM7150P, SM7225, SM7250, SM7250P, SM8150, SM8150P, SM8250, SM8350, SM8350P, SXR2130, SXR2130P

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-2fj7-pwvv-p427

An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'.

13%
Средний
почти 4 года назад
github логотип
GHSA-2fj7-8rfc-4ffg

Unspecified vulnerability in Oracle Solaris 10 allows remote attackers to affect confidentiality, related to Network Services Library (libnsl).

0%
Низкий
почти 4 года назад
github логотип
GHSA-2fj7-8prf-hq8g

This vulnerability allows local attackers to escalate privileges on affected installations of Foxit Reader 10.0.0.35798. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of the configuration files used by the Foxit Reader Update Service. The issue results from incorrect permissions set on a resource used by the service. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of SYSTEM. Was ZDI-CAN-11229.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2fj7-8jvc-76xv

Buffer overflow in wu-ftp from PASV command causes a core dump.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2fj5-qrfc-r9c5

Unspecified vulnerability in the Java plugin in IBM WebSphere Application Server 5.0.2 allows untrusted applets to gain privileges via unknown attack vectors.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2fj5-45wv-94qc

Unspecified vulnerability in Cisco CiscoWorks Common Services 3.0.3 through 3.1.1 allows remote attackers to execute arbitrary code on a client machine via unknown vectors.

5%
Низкий
почти 4 года назад
github логотип
GHSA-2fj3-qvr8-q2c6

Deserialization of Untrusted Data vulnerability in thememount Apicona apicona allows Object Injection.This issue affects Apicona: from n/a through <= 24.1.0.

CVSS3: 8.8
0%
Низкий
16 дней назад
github логотип
GHSA-2fj3-jhcw-972x

Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.01 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2fj3-3wfr-c7r6

DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2fj2-f362-29wp

Buffer overflow in the changevalue function in libcgi.h for Marcos Luiz Onisto Lib CGI 0.1 allows remote attackers to execute arbitrary code via a long argument.

6%
Низкий
почти 4 года назад
github логотип
GHSA-2fj2-4h38-3c72

The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu kernel to allow unprivileged overlay mounts, an attacker could use this to gain elevated privileges.

CVSS3: 7.8
76%
Высокий
почти 4 года назад
github логотип
GHSA-2fj2-4833-36ww

Insufficient key management for Intel(R) Data Center Manager SDK before version 5.0.2 may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-2fhx-5jj5-pjhv

Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable data corruption. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS3: 3.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2fhx-4cr3-fgxc

A stack-based buffer overflow in the LAN UPnP service running on UDP port 1900 of Swisscom Internet-Box (2, Standard, and Plus) prior to v09.04.00 and Internet-Box light prior to v08.05.02 allows remote code execution. No authentication is required to exploit this vulnerability. Sending a simple UDP packet to port 1900 allows an attacker to execute code on a remote device. However, this is only possible if the attacker is inside the LAN. Because of ASLR, the success rate is not 100% and leads instead to a DoS of the UPnP service. The remaining functionality of the Internet Box is not affected. A reboot of the Internet Box is necessary to attempt the exploit again.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-2fhw-h5f5-45gf

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in noonnoo Gravel allows Reflected XSS.This issue affects Gravel: from n/a through 1.6.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-2fhw-2j7m-mr4m

TYPO3 backend modules have Broken Access Control

0%
Низкий
7 месяцев назад
github логотип
GHSA-2fhv-pxmp-gpwh

On most desktop platforms, Brave Browser versions 1.70.x-1.73.x included a feature to show a site's origin on the OS-provided file selector dialog when a site prompts the user to upload or download a file. However the origin was not correctly inferred in some cases. When combined with an open redirector vulnerability on a trusted site, this could allow a malicious site to initiate a download whose origin in the file select dialog appears as the trusted site which initiated the redirect.

CVSS3: 6.1
0%
Низкий
около 1 года назад

Уязвимостей на страницу