Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 325 176

Количество 325 176

github логотип

GHSA-2c4q-6j77-737f

почти 4 года назад

Directory traversal vulnerability in bs_disp_as_mime_type.php in the BLOB streaming feature in phpMyAdmin before 3.1.3.1 allows remote attackers to read arbitrary files via directory traversal sequences in the file_path parameter ($filename variable).

EPSS: Низкий
github логотип

GHSA-2c4q-25x9-p644

почти 4 года назад

Zoho ManageEngine ServiceDesk Plus MSP before 10521 allows an attacker to access internal data.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-2c4m-g7rx-63q7

около 2 месяцев назад

set-in Affected by Prototype Pollution

EPSS: Низкий
github логотип

GHSA-2c4m-59x9-fr2g

почти 3 года назад

Gin Web Framework does not properly sanitize filename parameter of Context.FileAttachment function

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2c4m-3h92-jwwp

почти 4 года назад

A remote code execution vulnerability exists in Microsoft Outlook when the software fails to properly handle objects in memory, aka 'Microsoft Outlook Memory Corruption Vulnerability'.

CVSS3: 5
EPSS: Средний
github логотип

GHSA-2c4j-ph78-gmjg

5 месяцев назад

The WP Count Down Timer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'wp_countdown_timer' shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2c4h-r267-mgv3

почти 4 года назад

APT 0.7.x before 0.7.25 and 0.8.x before 0.8.16, when using the apt-key net-update to import keyrings, relies on GnuPG argument order and does not check GPG subkeys, which might allow remote attackers to install Trojan horse packages via a man-in-the-middle (MITM) attack.

EPSS: Низкий
github логотип

GHSA-2c4h-jg67-pgcw

больше 1 года назад

IrfanView DXF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24749.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2c4h-2ghg-m6fj

4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: fix potential memory leak in mlx5e_init_rep_rx The memory pointed to by the priv->rx_res pointer is not freed in the error path of mlx5e_init_rep_rx, which can lead to a memory leak. Fix by freeing the memory in the error path, thereby making the error path identical to mlx5e_cleanup_rep_rx().

EPSS: Низкий
github логотип

GHSA-2c4g-qfqp-42mh

почти 4 года назад

Network Time Protocol (NTP), as specified in RFC 5905, uses port 123 even for modes where a fixed port number is not required, which makes it easier for remote attackers to conduct off-path attacks.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2c4f-vgwr-82q6

больше 2 лет назад

A missing allocation check in sftp server processing read requests may cause a NULL dereference on low-memory conditions. The malicious client can request up to 4GB SFTP reads, causing allocation of up to 4GB buffers, which was not being checked for failure. This will likely crash the authenticated user's sftp server connection (if implemented as forking as recommended). For thread-based servers, this might also cause DoS for legitimate users. Given this code is not in any released versions, no security releases have been issued.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-2c4f-hmhx-8647

почти 4 года назад

Under certain conditions on F5 BIG-IP 13.0.0, 12.1.0-12.1.2, 11.6.0-11.6.3.1, or 11.5.0-11.5.6, TMM may core while processing SSL forward proxy traffic.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2c4f-g4mj-r79j

около 2 лет назад

A CWE-1269 “Product Released in Non-Release Configuration” vulnerability in the Django web framework used by the web application (due to the “debug” configuration parameter set to “True”) allows a remote unauthenticated attacker to access critical information and have other unspecified impacts to the confidentiality, integrity, and availability of the application. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2c4f-33fr-h9q2

почти 4 года назад

Cisco TelePresence Recording Server devices with software 1.6.x allow remote attackers to cause a denial of service (thread consumption and device outage) via a malformed request, related to an "ad hoc recording" issue, aka Bug ID CSCtf97205.

EPSS: Низкий
github логотип

GHSA-2c4c-5wf5-f8m7

около 1 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Starto starto allows Reflected XSS.This issue affects Starto: from n/a through <= 2.1.9.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2c47-m757-32g6

11 месяцев назад

Insufficient input sanitization in ejson2env

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-2c47-2hjq-x2f9

почти 4 года назад

Vulnerability in the Oracle Human Resources component of Oracle E-Business Suite (subcomponent: General Utilities). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Human Resources. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Human Resources accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2c46-qg5h-fq8x

почти 4 года назад

In unixODBC before 2.3.5, there is a buffer overflow in the unicode_to_ansi_copy() function in DriverManager/__info.c.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2c46-3v56-p8mq

почти 4 года назад

The raw_release function in net/can/raw.c in the Linux kernel before 2.6.39-rc6 does not properly validate a socket data structure, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a crafted release operation.

EPSS: Низкий
github логотип

GHSA-2c45-r34f-w6v8

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Coronavirus (COVID-19) Outbreak Data Widgets allows Reflected XSS. This issue affects Coronavirus (COVID-19) Outbreak Data Widgets: from n/a through 1.1.1.

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2c4q-6j77-737f

Directory traversal vulnerability in bs_disp_as_mime_type.php in the BLOB streaming feature in phpMyAdmin before 3.1.3.1 allows remote attackers to read arbitrary files via directory traversal sequences in the file_path parameter ($filename variable).

1%
Низкий
почти 4 года назад
github логотип
GHSA-2c4q-25x9-p644

Zoho ManageEngine ServiceDesk Plus MSP before 10521 allows an attacker to access internal data.

CVSS3: 7.5
10%
Средний
почти 4 года назад
github логотип
GHSA-2c4m-g7rx-63q7

set-in Affected by Prototype Pollution

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2c4m-59x9-fr2g

Gin Web Framework does not properly sanitize filename parameter of Context.FileAttachment function

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-2c4m-3h92-jwwp

A remote code execution vulnerability exists in Microsoft Outlook when the software fails to properly handle objects in memory, aka 'Microsoft Outlook Memory Corruption Vulnerability'.

CVSS3: 5
19%
Средний
почти 4 года назад
github логотип
GHSA-2c4j-ph78-gmjg

The WP Count Down Timer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'wp_countdown_timer' shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
5 месяцев назад
github логотип
GHSA-2c4h-r267-mgv3

APT 0.7.x before 0.7.25 and 0.8.x before 0.8.16, when using the apt-key net-update to import keyrings, relies on GnuPG argument order and does not check GPG subkeys, which might allow remote attackers to install Trojan horse packages via a man-in-the-middle (MITM) attack.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2c4h-jg67-pgcw

IrfanView DXF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24749.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2c4h-2ghg-m6fj

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: fix potential memory leak in mlx5e_init_rep_rx The memory pointed to by the priv->rx_res pointer is not freed in the error path of mlx5e_init_rep_rx, which can lead to a memory leak. Fix by freeing the memory in the error path, thereby making the error path identical to mlx5e_cleanup_rep_rx().

0%
Низкий
4 месяца назад
github логотип
GHSA-2c4g-qfqp-42mh

Network Time Protocol (NTP), as specified in RFC 5905, uses port 123 even for modes where a fixed port number is not required, which makes it easier for remote attackers to conduct off-path attacks.

CVSS3: 8.1
2%
Низкий
почти 4 года назад
github логотип
GHSA-2c4f-vgwr-82q6

A missing allocation check in sftp server processing read requests may cause a NULL dereference on low-memory conditions. The malicious client can request up to 4GB SFTP reads, causing allocation of up to 4GB buffers, which was not being checked for failure. This will likely crash the authenticated user's sftp server connection (if implemented as forking as recommended). For thread-based servers, this might also cause DoS for legitimate users. Given this code is not in any released versions, no security releases have been issued.

CVSS3: 3.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2c4f-hmhx-8647

Under certain conditions on F5 BIG-IP 13.0.0, 12.1.0-12.1.2, 11.6.0-11.6.3.1, or 11.5.0-11.5.6, TMM may core while processing SSL forward proxy traffic.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-2c4f-g4mj-r79j

A CWE-1269 “Product Released in Non-Release Configuration” vulnerability in the Django web framework used by the web application (due to the “debug” configuration parameter set to “True”) allows a remote unauthenticated attacker to access critical information and have other unspecified impacts to the confidentiality, integrity, and availability of the application. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-2c4f-33fr-h9q2

Cisco TelePresence Recording Server devices with software 1.6.x allow remote attackers to cause a denial of service (thread consumption and device outage) via a malformed request, related to an "ad hoc recording" issue, aka Bug ID CSCtf97205.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2c4c-5wf5-f8m7

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Starto starto allows Reflected XSS.This issue affects Starto: from n/a through <= 2.1.9.

CVSS3: 7.1
0%
Низкий
около 1 месяца назад
github логотип
GHSA-2c47-m757-32g6

Insufficient input sanitization in ejson2env

CVSS3: 6.6
1%
Низкий
11 месяцев назад
github логотип
GHSA-2c47-2hjq-x2f9

Vulnerability in the Oracle Human Resources component of Oracle E-Business Suite (subcomponent: General Utilities). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Human Resources. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Human Resources accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVSS3: 5.3
1%
Низкий
почти 4 года назад
github логотип
GHSA-2c46-qg5h-fq8x

In unixODBC before 2.3.5, there is a buffer overflow in the unicode_to_ansi_copy() function in DriverManager/__info.c.

CVSS3: 9.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-2c46-3v56-p8mq

The raw_release function in net/can/raw.c in the Linux kernel before 2.6.39-rc6 does not properly validate a socket data structure, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a crafted release operation.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2c45-r34f-w6v8

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Coronavirus (COVID-19) Outbreak Data Widgets allows Reflected XSS. This issue affects Coronavirus (COVID-19) Outbreak Data Widgets: from n/a through 1.1.1.

CVSS3: 7.1
0%
Низкий
около 1 года назад

Уязвимостей на страницу