Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 325 176

Количество 325 176

github логотип

GHSA-2c64-xxfm-j63g

около 2 лет назад

A Cross Site Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker to execute unauthorized actions on behalf of an unsuspecting user. A mitigating factor is that user interaction is required. This vulnerability affected GitHub Enterprise Server 3.12.0 and was fixed in versions 3.12.1. This vulnerability was reported via the GitHub Bug Bounty program. 

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2c64-vmv2-hgfc

5 месяцев назад

OpenFGA Improper Policy Enforcement

EPSS: Низкий
github логотип

GHSA-2c64-vj8g-vwrq

почти 5 лет назад

Incorrect handling of credential expiry by /nats-io/nats-server

EPSS: Низкий
github логотип

GHSA-2c64-8vwr-5pjm

почти 4 года назад

Buffer overflows in the DHCP server for NetWare 6.0 SP1 allow remote attackers to cause a denial of service (reboot) via long DHCP requests.

EPSS: Низкий
github логотип

GHSA-2c64-8v4j-vw3m

почти 4 года назад

Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2c64-5hcr-p4hq

почти 4 года назад

The Apple Music (aka com.apple.android.music) application before 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2c63-x392-hx7w

больше 1 года назад

IBM MaaS360 for Android 6.31 through 8.60 is using hard coded credentials that can be obtained by a user with physical access to the device.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-2c63-vgrp-m7w4

почти 4 года назад

SQL injection vulnerability in the Cybozu Garoon 4.0.0 to 4.10.0 allows attacker with administrator rights to execute arbitrary SQL commands via the Log Search function of application 'logging'.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2c63-fqw2-3fhm

больше 2 лет назад

A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an implementation error within the SSL/TLS session handling process that can prevent the release of a session handler under specific conditions. An attacker could exploit this vulnerability by sending crafted SSL/TLS traffic to an affected device, increasing the probability of session handler leaks. A successful exploit could allow the attacker to eventually deplete the available session handler pool, preventing new sessions from being established and causing a DoS condition.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-2c63-6xjj-gp6q

7 месяцев назад

Information disclosure

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2c63-4337-p6h8

больше 1 года назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Spider-themes EazyDocs.This issue affects EazyDocs: from n/a through 2.5.5.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2c62-8p8p-hh5w

почти 4 года назад

Libgcrypt before 1.6.5 does not properly perform elliptic-point curve multiplication during decryption, which makes it easier for physically proximate attackers to extract ECDH keys by measuring electromagnetic emanations.

CVSS3: 2
EPSS: Низкий
github логотип

GHSA-2c5x-r53j-239w

4 месяца назад

The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 13.2.4 due to insufficient input sanitization and output escaping on Google Reviews data imported by the plugin. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that will execute in the admin panel (and potentially on the frontend) whenever a user accesses imported reviews, granted they can add a malicious review to a Google Place that is connected to the vulnerable site.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2c5w-8p3h-w8f6

3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: cifs: fix potential race when tree connecting ipc Protect access of TCP_Server_Info::hostname when building the ipc tree name as it might get freed in cifsd thread and thus causing an use-after-free bug in __tree_connect_dfs_target(). Also, while at it, update status of IPC tcon on success and then avoid any extra tree connects.

EPSS: Низкий
github логотип

GHSA-2c5w-43q3-9h56

почти 2 года назад

D-Link D-View coreservice_action_script Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link D-View. Authentication is not required to exploit this vulnerability. The specific flaw exists within the coreservice_action_script action. The issue results from the exposure of a dangerous function. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-19573.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2c5v-4pcw-67jx

почти 4 года назад

Format string vulnerability in Lithium II mod 1.24 for Quake 2 allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via format string specifiers in the nickname.

EPSS: Низкий
github логотип

GHSA-2c5r-8h52-phwr

почти 3 года назад

Zoom for Windows clients prior to 5.13.5 contain an improper verification of cryptographic signature vulnerability. A malicious user may potentially downgrade Zoom Client components to previous versions.

CVSS3: 2.8
EPSS: Низкий
github логотип

GHSA-2c5p-v6r6-q8xj

больше 1 года назад

In wlan driver, there is a possible out of bound read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998291; Issue ID: MSV-1604.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2c5p-55qj-5p58

около 4 лет назад

A CWE-614 Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain an unauthorized access over a hijacked session to the charger station web server even after the legitimate user account holder has changed his password. Affected Products: EVlink City EVC1S22P4 / EVC1S7P4 (All versions prior to R8 V3.4.0.2 ), EVlink Parking EVW2 / EVF2 / EVP2PE (All versions prior to R8 V3.4.0.2), and EVlink Smart Wallbox EVB1A (All versions prior to R8 V3.4.0.2)

EPSS: Низкий
github логотип

GHSA-2c5p-3g7v-4hc2

почти 4 года назад

Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, and 7u67, and Java SE Embedded 7u60, allows remote attackers to affect confidentiality via unknown vectors related to Hotspot.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2c64-xxfm-j63g

A Cross Site Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker to execute unauthorized actions on behalf of an unsuspecting user. A mitigating factor is that user interaction is required. This vulnerability affected GitHub Enterprise Server 3.12.0 and was fixed in versions 3.12.1. This vulnerability was reported via the GitHub Bug Bounty program. 

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-2c64-vmv2-hgfc

OpenFGA Improper Policy Enforcement

0%
Низкий
5 месяцев назад
github логотип
GHSA-2c64-vj8g-vwrq

Incorrect handling of credential expiry by /nats-io/nats-server

почти 5 лет назад
github логотип
GHSA-2c64-8vwr-5pjm

Buffer overflows in the DHCP server for NetWare 6.0 SP1 allow remote attackers to cause a denial of service (reboot) via long DHCP requests.

4%
Низкий
почти 4 года назад
github логотип
GHSA-2c64-8v4j-vw3m

Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-2c64-5hcr-p4hq

The Apple Music (aka com.apple.android.music) application before 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVSS3: 4.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-2c63-x392-hx7w

IBM MaaS360 for Android 6.31 through 8.60 is using hard coded credentials that can be obtained by a user with physical access to the device.

CVSS3: 4.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-2c63-vgrp-m7w4

SQL injection vulnerability in the Cybozu Garoon 4.0.0 to 4.10.0 allows attacker with administrator rights to execute arbitrary SQL commands via the Log Search function of application 'logging'.

CVSS3: 7.2
0%
Низкий
почти 4 года назад
github логотип
GHSA-2c63-fqw2-3fhm

A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an implementation error within the SSL/TLS session handling process that can prevent the release of a session handler under specific conditions. An attacker could exploit this vulnerability by sending crafted SSL/TLS traffic to an affected device, increasing the probability of session handler leaks. A successful exploit could allow the attacker to eventually deplete the available session handler pool, preventing new sessions from being established and causing a DoS condition.

CVSS3: 6.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2c63-6xjj-gp6q

Information disclosure

CVSS3: 7.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-2c63-4337-p6h8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Spider-themes EazyDocs.This issue affects EazyDocs: from n/a through 2.5.5.

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-2c62-8p8p-hh5w

Libgcrypt before 1.6.5 does not properly perform elliptic-point curve multiplication during decryption, which makes it easier for physically proximate attackers to extract ECDH keys by measuring electromagnetic emanations.

CVSS3: 2
0%
Низкий
почти 4 года назад
github логотип
GHSA-2c5x-r53j-239w

The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 13.2.4 due to insufficient input sanitization and output escaping on Google Reviews data imported by the plugin. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that will execute in the admin panel (and potentially on the frontend) whenever a user accesses imported reviews, granted they can add a malicious review to a Google Place that is connected to the vulnerable site.

CVSS3: 7.2
0%
Низкий
4 месяца назад
github логотип
GHSA-2c5w-8p3h-w8f6

In the Linux kernel, the following vulnerability has been resolved: cifs: fix potential race when tree connecting ipc Protect access of TCP_Server_Info::hostname when building the ipc tree name as it might get freed in cifsd thread and thus causing an use-after-free bug in __tree_connect_dfs_target(). Also, while at it, update status of IPC tcon on success and then avoid any extra tree connects.

0%
Низкий
3 месяца назад
github логотип
GHSA-2c5w-43q3-9h56

D-Link D-View coreservice_action_script Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link D-View. Authentication is not required to exploit this vulnerability. The specific flaw exists within the coreservice_action_script action. The issue results from the exposure of a dangerous function. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-19573.

CVSS3: 9.8
4%
Низкий
почти 2 года назад
github логотип
GHSA-2c5v-4pcw-67jx

Format string vulnerability in Lithium II mod 1.24 for Quake 2 allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via format string specifiers in the nickname.

2%
Низкий
почти 4 года назад
github логотип
GHSA-2c5r-8h52-phwr

Zoom for Windows clients prior to 5.13.5 contain an improper verification of cryptographic signature vulnerability. A malicious user may potentially downgrade Zoom Client components to previous versions.

CVSS3: 2.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-2c5p-v6r6-q8xj

In wlan driver, there is a possible out of bound read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998291; Issue ID: MSV-1604.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2c5p-55qj-5p58

A CWE-614 Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain an unauthorized access over a hijacked session to the charger station web server even after the legitimate user account holder has changed his password. Affected Products: EVlink City EVC1S22P4 / EVC1S7P4 (All versions prior to R8 V3.4.0.2 ), EVlink Parking EVW2 / EVF2 / EVP2PE (All versions prior to R8 V3.4.0.2), and EVlink Smart Wallbox EVB1A (All versions prior to R8 V3.4.0.2)

1%
Низкий
около 4 лет назад
github логотип
GHSA-2c5p-3g7v-4hc2

Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, and 7u67, and Java SE Embedded 7u60, allows remote attackers to affect confidentiality via unknown vectors related to Hotspot.

2%
Низкий
почти 4 года назад

Уязвимостей на страницу