Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 325 176

Количество 325 176

github логотип

GHSA-29xx-hcv2-c4cp

около 3 лет назад

openssl-src subject to Invalid pointer dereference in `d2i_PKCS7` functions

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-29xx-fhff-36m7

около 2 лет назад

Liferay Portal vulnerable to Denial of Service

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-29xv-m659-vj7w

больше 1 года назад

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a a feature that could enable sub accounts or attackers to view and exfiltrate sensitive information from all cloud accounts registered to Ruijie's services

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-29xv-49r2-j45j

больше 3 лет назад

Improper input validation in the Intel(R) Distribution of OpenVINO(TM) Toolkit may allow an authenticated user to potentially enable denial of service via network access.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-29xr-xpp4-5783

больше 2 лет назад

Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to affect the availability of the device by changing settings of the device such as the IP address based on missing access control.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-29xr-v42j-r956

больше 3 лет назад

thenify before 3.3.1 made use of unsafe calls to `eval`.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-29xr-pwpr-24h3

почти 4 года назад

The process_stat function in (1) Memcached before 1.2.8 and (2) MemcacheDB 1.2.0 discloses (a) the contents of /proc/self/maps in response to a stats maps command and (b) memory-allocation statistics in response to a stats malloc command, which allows remote attackers to obtain sensitive information such as the locations of memory regions, and defeat ASLR protection, by sending a command to the daemon's TCP port.

EPSS: Низкий
github логотип

GHSA-29xr-58g9-8qfq

3 месяца назад

Authorization Bypass Through User-Controlled Key vulnerability in Crocoblock JetPopup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetPopup: from n/a through 2.0.20.1.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-29xq-r9ph-fp32

около 4 лет назад

A Cross Site Scripting vulnerabilty exists in Pixelimity 1.0 via the Site Description field in pixelimity/admin/setting.php

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-29xq-g636-c9r2

почти 4 года назад

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of arguments passed to the mailDoc function. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5770.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-29xq-869p-3chq

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix possible out-of-bound read in ath12k_htt_pull_ppdu_stats() len is extracted from HTT message and could be an unexpected value in case errors happen, so add validation before using to avoid possible out-of-bound read in the following message iteration and parsing. The same issue also applies to ppdu_info->ppdu_stats.common.num_users, so validate it before using too. These are found during code review. Compile test only.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-29xp-8fx4-phv8

почти 4 года назад

An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10. Android ID: A-32636619. References: N-CVE-2017-0429.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-29xp-429w-g6x4

10 месяцев назад

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-29xp-372q-xqph

5 месяцев назад

node-tar has a race condition leading to uninitialized memory exposure

EPSS: Низкий
github логотип

GHSA-29xm-9cvj-9ppc

почти 4 года назад

In ihevc_intra_pred_chroma_mode_3_to_9_av8 of ihevc_intra_pred_chroma_mode_3_to_9.s, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-144595488

EPSS: Низкий
github логотип

GHSA-29xm-2gqv-p5cq

больше 2 лет назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GuardGiant Brute Force Protection WordPress Brute Force Protection – Stop Brute Force Attacks.This issue affects WordPress Brute Force Protection – Stop Brute Force Attacks: from n/a through 2.2.5.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-29xj-vxf5-px46

почти 4 года назад

Directory traversal vulnerability in inc/lib/language.lib.php in Claroline before 1.8.6 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.

EPSS: Низкий
github логотип

GHSA-29xj-m56g-2pfp

почти 4 года назад

The TSymbolTableLevel class in ANGLE, as used in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 on Windows, allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact by triggering use of a WebGL shader that writes to an array.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-29xj-6jjp-m927

26 дней назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in levelfourdevelopment WP EasyCart wp-easycart allows Blind SQL Injection.This issue affects WP EasyCart: from n/a through <= 5.8.13.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-29xj-64r9-4j75

почти 4 года назад

Multiple SQL injection vulnerabilities in CuteFlow 2.10.0 allow remote authenticated users to execute arbitrary SQL commands via the (1) listid parameter to pages/editmailinglist_step1.php, the (2) userid parameter to pages/edituser.php, the (3) fieldid parameter to pages/editfield.php, and the (4) templateid to pages/edittemplate_step1.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-29xx-hcv2-c4cp

openssl-src subject to Invalid pointer dereference in `d2i_PKCS7` functions

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-29xx-fhff-36m7

Liferay Portal vulnerable to Denial of Service

CVSS3: 5
1%
Низкий
около 2 лет назад
github логотип
GHSA-29xv-m659-vj7w

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a a feature that could enable sub accounts or attackers to view and exfiltrate sensitive information from all cloud accounts registered to Ruijie's services

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-29xv-49r2-j45j

Improper input validation in the Intel(R) Distribution of OpenVINO(TM) Toolkit may allow an authenticated user to potentially enable denial of service via network access.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-29xr-xpp4-5783

Improper Access Control in the SICK ICR890-4 could allow an unauthenticated remote attacker to affect the availability of the device by changing settings of the device such as the IP address based on missing access control.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-29xr-v42j-r956

thenify before 3.3.1 made use of unsafe calls to `eval`.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-29xr-pwpr-24h3

The process_stat function in (1) Memcached before 1.2.8 and (2) MemcacheDB 1.2.0 discloses (a) the contents of /proc/self/maps in response to a stats maps command and (b) memory-allocation statistics in response to a stats malloc command, which allows remote attackers to obtain sensitive information such as the locations of memory regions, and defeat ASLR protection, by sending a command to the daemon's TCP port.

2%
Низкий
почти 4 года назад
github логотип
GHSA-29xr-58g9-8qfq

Authorization Bypass Through User-Controlled Key vulnerability in Crocoblock JetPopup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetPopup: from n/a through 2.0.20.1.

CVSS3: 4.3
0%
Низкий
3 месяца назад
github логотип
GHSA-29xq-r9ph-fp32

A Cross Site Scripting vulnerabilty exists in Pixelimity 1.0 via the Site Description field in pixelimity/admin/setting.php

CVSS3: 4.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-29xq-g636-c9r2

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of arguments passed to the mailDoc function. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5770.

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-29xq-869p-3chq

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix possible out-of-bound read in ath12k_htt_pull_ppdu_stats() len is extracted from HTT message and could be an unexpected value in case errors happen, so add validation before using to avoid possible out-of-bound read in the following message iteration and parsing. The same issue also applies to ppdu_info->ppdu_stats.common.num_users, so validate it before using too. These are found during code review. Compile test only.

CVSS3: 7.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-29xp-8fx4-phv8

An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10. Android ID: A-32636619. References: N-CVE-2017-0429.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-29xp-429w-g6x4

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
10 месяцев назад
github логотип
GHSA-29xp-372q-xqph

node-tar has a race condition leading to uninitialized memory exposure

0%
Низкий
5 месяцев назад
github логотип
GHSA-29xm-9cvj-9ppc

In ihevc_intra_pred_chroma_mode_3_to_9_av8 of ihevc_intra_pred_chroma_mode_3_to_9.s, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-144595488

0%
Низкий
почти 4 года назад
github логотип
GHSA-29xm-2gqv-p5cq

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GuardGiant Brute Force Protection WordPress Brute Force Protection – Stop Brute Force Attacks.This issue affects WordPress Brute Force Protection – Stop Brute Force Attacks: from n/a through 2.2.5.

CVSS3: 7.6
0%
Низкий
больше 2 лет назад
github логотип
GHSA-29xj-vxf5-px46

Directory traversal vulnerability in inc/lib/language.lib.php in Claroline before 1.8.6 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.

6%
Низкий
почти 4 года назад
github логотип
GHSA-29xj-m56g-2pfp

The TSymbolTableLevel class in ANGLE, as used in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 on Windows, allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact by triggering use of a WebGL shader that writes to an array.

CVSS3: 8.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-29xj-6jjp-m927

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in levelfourdevelopment WP EasyCart wp-easycart allows Blind SQL Injection.This issue affects WP EasyCart: from n/a through <= 5.8.13.

CVSS3: 8.5
0%
Низкий
26 дней назад
github логотип
GHSA-29xj-64r9-4j75

Multiple SQL injection vulnerabilities in CuteFlow 2.10.0 allow remote authenticated users to execute arbitrary SQL commands via the (1) listid parameter to pages/editmailinglist_step1.php, the (2) userid parameter to pages/edituser.php, the (3) fieldid parameter to pages/editfield.php, and the (4) templateid to pages/edittemplate_step1.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу