Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 325 176

Количество 325 176

github логотип

GHSA-2c6h-4899-wjxr

5 дней назад

scaly: Multiple soundness issues in Rust safe APIs

EPSS: Низкий
github логотип

GHSA-2c6g-pfx3-w7h8

около 1 года назад

Insecure Temporary File in RESTEasy

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2c6f-q4p6-g2x2

почти 4 года назад

wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section length headers, aka "Microsoft Works File Converter Input Validation Vulnerability."

EPSS: Высокий
github логотип

GHSA-2c6f-jjmq-4hv4

почти 4 года назад

Multiple SQL injection vulnerabilities in cgi/admin.cgi in Interlogy Profile Manager Basic allow remote attackers to execute arbitrary SQL commands via a pmadm cookie in (1) an edittemp action or (2) a users action.

EPSS: Низкий
github логотип

GHSA-2c6f-95j4-4v9m

около 4 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JT files. Crafted data in a JT file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14830.

EPSS: Низкий
github логотип

GHSA-2c6f-5h2f-xj25

4 месяца назад

Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass download protections via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2c6c-w342-prhc

почти 4 года назад

The convolution implementation in Skia, as used in Google Chrome before 47.0.2526.73, does not properly constrain row lengths, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via crafted graphics data.

EPSS: Низкий
github логотип

GHSA-2c6c-mrq5-cw27

23 дня назад

in OpenHarmony v5.0.3 and prior versions allow a local attacker case sensitive information leak through use of uninitialized resource.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2c6c-f4qw-3vqh

почти 4 года назад

Buffer overflow in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to inject system commands via the "hook" URL parameter.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2c6c-5vmc-49j8

почти 2 года назад

A stack-based buffer overflow vulnerability exists in the boa rollback_control_code functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to arbitrary code execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2c69-wcv6-7xgx

почти 4 года назад

Unspecified vulnerability in Simple Machines Forum (SMF) 1.1.2 allows remote attackers to execute arbitrary PHP code during (1) creation or (2) editing of a message.

EPSS: Низкий
github логотип

GHSA-2c69-r2jh-xjvm

почти 3 года назад

This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SecurityRequestFilter class. The issue results from improper implementation of the authentication algorithm. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-19226.

CVSS3: 8.2
EPSS: Средний
github логотип

GHSA-2c69-52h7-cm65

почти 4 года назад

Microsoft Internet Explorer 5.01, 6, and 7 accesses uninitialized memory in certain conditions, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via vectors related to a document object "appended in a specific order," aka "HTML Objects Memory Corruption Vulnerability" or "XHTML Rendering Memory Corruption Vulnerability," a different vulnerability than CVE-2008-2258.

EPSS: Средний
github логотип

GHSA-2c67-p4xh-m34w

почти 3 года назад

Cross-site Scripting (XSS) in Website Settings name field

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2c67-m4vp-q6p7

почти 4 года назад

DelphiTurk CodeBank (aka KodBank) 3.1 and earlier stores usernames and passwords in the Codebank registry key, which allows local users to gain privileges.

EPSS: Низкий
github логотип

GHSA-2c67-fjgj-8c9f

почти 4 года назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 20.0 and SeaMonkey before 2.17 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the nsContentUtils::HoldJSObjects function and the nsAutoPtr class, and other vectors.

EPSS: Низкий
github логотип

GHSA-2c66-c7h7-6vc9

почти 4 года назад

Google Chrome before 14.0.835.163 allows user-assisted remote attackers to spoof the URL bar via vectors related to "unusual user interaction."

EPSS: Низкий
github логотип

GHSA-2c66-48xv-6vjf

почти 4 года назад

An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the third-party "PCRE" product. Versions before 8.40 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2c66-2j8q-97x2

почти 4 года назад

SGI MachineInfo CGI program, installed by default on some web servers, prints potentially sensitive system status information, which could be used by remote attackers for information gathering activities.

EPSS: Низкий
github логотип

GHSA-2c65-rq62-fqhq

почти 4 года назад

Path traversal in Gitblit

CVSS3: 7.5
EPSS: Критический

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2c6h-4899-wjxr

scaly: Multiple soundness issues in Rust safe APIs

5 дней назад
github логотип
GHSA-2c6g-pfx3-w7h8

Insecure Temporary File in RESTEasy

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2c6f-q4p6-g2x2

wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section length headers, aka "Microsoft Works File Converter Input Validation Vulnerability."

71%
Высокий
почти 4 года назад
github логотип
GHSA-2c6f-jjmq-4hv4

Multiple SQL injection vulnerabilities in cgi/admin.cgi in Interlogy Profile Manager Basic allow remote attackers to execute arbitrary SQL commands via a pmadm cookie in (1) an edittemp action or (2) a users action.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2c6f-95j4-4v9m

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JT files. Crafted data in a JT file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14830.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2c6f-5h2f-xj25

Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass download protections via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 5.3
0%
Низкий
4 месяца назад
github логотип
GHSA-2c6c-w342-prhc

The convolution implementation in Skia, as used in Google Chrome before 47.0.2526.73, does not properly constrain row lengths, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via crafted graphics data.

2%
Низкий
почти 4 года назад
github логотип
GHSA-2c6c-mrq5-cw27

in OpenHarmony v5.0.3 and prior versions allow a local attacker case sensitive information leak through use of uninitialized resource.

CVSS3: 6.5
0%
Низкий
23 дня назад
github логотип
GHSA-2c6c-f4qw-3vqh

Buffer overflow in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to inject system commands via the "hook" URL parameter.

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-2c6c-5vmc-49j8

A stack-based buffer overflow vulnerability exists in the boa rollback_control_code functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to arbitrary code execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVSS3: 7.2
1%
Низкий
почти 2 года назад
github логотип
GHSA-2c69-wcv6-7xgx

Unspecified vulnerability in Simple Machines Forum (SMF) 1.1.2 allows remote attackers to execute arbitrary PHP code during (1) creation or (2) editing of a message.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2c69-r2jh-xjvm

This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SecurityRequestFilter class. The issue results from improper implementation of the authentication algorithm. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-19226.

CVSS3: 8.2
45%
Средний
почти 3 года назад
github логотип
GHSA-2c69-52h7-cm65

Microsoft Internet Explorer 5.01, 6, and 7 accesses uninitialized memory in certain conditions, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via vectors related to a document object "appended in a specific order," aka "HTML Objects Memory Corruption Vulnerability" or "XHTML Rendering Memory Corruption Vulnerability," a different vulnerability than CVE-2008-2258.

63%
Средний
почти 4 года назад
github логотип
GHSA-2c67-p4xh-m34w

Cross-site Scripting (XSS) in Website Settings name field

CVSS3: 5.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-2c67-m4vp-q6p7

DelphiTurk CodeBank (aka KodBank) 3.1 and earlier stores usernames and passwords in the Codebank registry key, which allows local users to gain privileges.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2c67-fjgj-8c9f

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 20.0 and SeaMonkey before 2.17 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the nsContentUtils::HoldJSObjects function and the nsAutoPtr class, and other vectors.

2%
Низкий
почти 4 года назад
github логотип
GHSA-2c66-c7h7-6vc9

Google Chrome before 14.0.835.163 allows user-assisted remote attackers to spoof the URL bar via vectors related to "unusual user interaction."

1%
Низкий
почти 4 года назад
github логотип
GHSA-2c66-48xv-6vjf

An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the third-party "PCRE" product. Versions before 8.40 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.

CVSS3: 9.8
2%
Низкий
почти 4 года назад
github логотип
GHSA-2c66-2j8q-97x2

SGI MachineInfo CGI program, installed by default on some web servers, prints potentially sensitive system status information, which could be used by remote attackers for information gathering activities.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2c65-rq62-fqhq

Path traversal in Gitblit

CVSS3: 7.5
90%
Критический
почти 4 года назад

Уязвимостей на страницу