Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 324 922

Количество 324 922

github логотип

GHSA-29h4-jchc-9446

почти 4 года назад

WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.

EPSS: Низкий
github логотип

GHSA-29h4-7v22-wvxg

больше 2 лет назад

Cross site scripting vulnerability in web portal in Snow Software License Manager from version 9.0.0 up to and including 9.30.1 on Windows allows an authenticated user with high privileges to trigger cross site scripting attack via the web browser

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-29h3-7qgp-vff3

почти 4 года назад

A vulnerability in lack of validation of user-supplied parameters pass to XML-RPC calls on SonicWall Global Management System (GMS) virtual appliance's, allow remote user to execute arbitrary code. This vulnerability affected GMS version 8.1 and earlier.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-29h2-5h98-8vhx

9 месяцев назад

Bluebird devices contain a pre-loaded barcode scanner application. This application exposes an unsecured broadcast receiver "kr.co.bluebird.android.bbsettings.BootReceiver". A local attacker can call the receiver to overwrite file containing ".json" keyword with default barcode config file. It is possible to overwrite file in any location due to lack of protection against path traversal in name of the file. This issue affects all versions before 1.3.3.

EPSS: Низкий
github логотип

GHSA-29gx-jmhj-rrx9

почти 4 года назад

Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control EM Base Platform 10.2.0.5 and 11.1.0.1; EM DB Control 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3; and EM Plugin for DB 12.1.0.1 and 12.1.0.2 allows remote attackers to affect integrity via unknown vectors related to Resource Manager.

EPSS: Низкий
github логотип

GHSA-29gx-388f-w262

почти 4 года назад

Cross-site scripting (XSS) vulnerability in phpRank 1.8 allows remote attackers to inject arbitrary web script or HTML via the (1) the email parameter of add.php or (2) the banner URL (banurl parameter) in the main list.

EPSS: Низкий
github логотип

GHSA-29gw-r2hj-fm58

больше 2 лет назад

Through the exploitation of active user sessions, an attacker could send custom requests to cause a denial-of-service condition on the device.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-29gw-9793-fvw7

около 3 лет назад

IPython vulnerable to command injection via set_term_title

CVSS3: 4.5
EPSS: Низкий
github логотип

GHSA-29gv-cv9c-r93w

3 месяца назад

This vulnerability allows authenticated attackers to execute commands via the NTP-configuration of the device.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-29gr-w57f-rpfw

больше 8 лет назад

actionpack vulnerable to Path Traversal

EPSS: Низкий
github логотип

GHSA-29gq-wq8x-vfcr

около 3 лет назад

The use of the cyclic redundancy check (CRC) algorithm for integrity check during firmware update makes TRENDnet TV-IP651WI Network Camera firmware version v1.07.01 and earlier vulnerable to firmware modification attacks. An attacker can conduct a man-in-the-middle (MITM) attack to modify the new firmware image and bypass the checksum verification.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-29gq-rw72-mrqg

почти 2 года назад

In RTI Connext Professional 5.3.1 through 6.1.0 before 6.1.1, a buffer overflow in XML parsing from Routing Service, Recording Service, Queuing Service, and Cloud Discovery Service allows attackers to execute code with the affected service's privileges, compromise the service's integrity, leak sensitive information, or crash the service. These attacks could be done via a remote malicious RTPS message; a compromised call with malicious parameters to the RTI_RoutingService_new, rti::recording::Service, RTI_QueuingService_new, or RTI_CDS_Service_new public APIs; or a compromised local file system containing a malicious XML file.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-29gq-h27w-54qf

почти 4 года назад

Jenkins VS Team Services Continuous Deployment Plugin stores credentials in plain text

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-29gp-96hf-p856

больше 3 лет назад

Proofpoint Enterprise Protection (PPS/PoD) contains a vulnerability which allows the pps user to escalate to root privileges due to unnecessary permissions. This affects all versions 8.19.0 and below.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-29gp-92wp-94q8

больше 7 лет назад

react-dev-utils on Windows vulnerable to Remote Code Execution

EPSS: Низкий
github логотип

GHSA-29gp-2c3m-3j6m

около 4 лет назад

Sandbox Escape by math function in smarty

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-29gm-gchh-5j4j

около 1 года назад

Microsoft Office Visio Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-29gj-xrph-g435

почти 4 года назад

A denial of service exists in Microsoft IIS Server when the optional request filtering feature improperly handles requests, aka 'Microsoft IIS Server Denial of Service Vulnerability'.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-29gj-jj49-x9g7

больше 2 лет назад

Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-29gh-89p4-ffqv

почти 3 года назад

European Chemicals Agency IUCLID 6.x before 6.27.6 allows authentication bypass because a weak hard-coded secret is used for JWT signing. The affected versions are 5.15.0 through 6.27.5.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-29h4-jchc-9446

WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.

2%
Низкий
почти 4 года назад
github логотип
GHSA-29h4-7v22-wvxg

Cross site scripting vulnerability in web portal in Snow Software License Manager from version 9.0.0 up to and including 9.30.1 on Windows allows an authenticated user with high privileges to trigger cross site scripting attack via the web browser

CVSS3: 4.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-29h3-7qgp-vff3

A vulnerability in lack of validation of user-supplied parameters pass to XML-RPC calls on SonicWall Global Management System (GMS) virtual appliance's, allow remote user to execute arbitrary code. This vulnerability affected GMS version 8.1 and earlier.

CVSS3: 9.8
11%
Средний
почти 4 года назад
github логотип
GHSA-29h2-5h98-8vhx

Bluebird devices contain a pre-loaded barcode scanner application. This application exposes an unsecured broadcast receiver "kr.co.bluebird.android.bbsettings.BootReceiver". A local attacker can call the receiver to overwrite file containing ".json" keyword with default barcode config file. It is possible to overwrite file in any location due to lack of protection against path traversal in name of the file. This issue affects all versions before 1.3.3.

0%
Низкий
9 месяцев назад
github логотип
GHSA-29gx-jmhj-rrx9

Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control EM Base Platform 10.2.0.5 and 11.1.0.1; EM DB Control 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3; and EM Plugin for DB 12.1.0.1 and 12.1.0.2 allows remote attackers to affect integrity via unknown vectors related to Resource Manager.

0%
Низкий
почти 4 года назад
github логотип
GHSA-29gx-388f-w262

Cross-site scripting (XSS) vulnerability in phpRank 1.8 allows remote attackers to inject arbitrary web script or HTML via the (1) the email parameter of add.php or (2) the banner URL (banurl parameter) in the main list.

0%
Низкий
почти 4 года назад
github логотип
GHSA-29gw-r2hj-fm58

Through the exploitation of active user sessions, an attacker could send custom requests to cause a denial-of-service condition on the device.

CVSS3: 9.6
0%
Низкий
больше 2 лет назад
github логотип
GHSA-29gw-9793-fvw7

IPython vulnerable to command injection via set_term_title

CVSS3: 4.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-29gv-cv9c-r93w

This vulnerability allows authenticated attackers to execute commands via the NTP-configuration of the device.

CVSS3: 8.6
0%
Низкий
3 месяца назад
github логотип
GHSA-29gr-w57f-rpfw

actionpack vulnerable to Path Traversal

0%
Низкий
больше 8 лет назад
github логотип
GHSA-29gq-wq8x-vfcr

The use of the cyclic redundancy check (CRC) algorithm for integrity check during firmware update makes TRENDnet TV-IP651WI Network Camera firmware version v1.07.01 and earlier vulnerable to firmware modification attacks. An attacker can conduct a man-in-the-middle (MITM) attack to modify the new firmware image and bypass the checksum verification.

CVSS3: 5.9
0%
Низкий
около 3 лет назад
github логотип
GHSA-29gq-rw72-mrqg

In RTI Connext Professional 5.3.1 through 6.1.0 before 6.1.1, a buffer overflow in XML parsing from Routing Service, Recording Service, Queuing Service, and Cloud Discovery Service allows attackers to execute code with the affected service's privileges, compromise the service's integrity, leak sensitive information, or crash the service. These attacks could be done via a remote malicious RTPS message; a compromised call with malicious parameters to the RTI_RoutingService_new, rti::recording::Service, RTI_QueuingService_new, or RTI_CDS_Service_new public APIs; or a compromised local file system containing a malicious XML file.

CVSS3: 7.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-29gq-h27w-54qf

Jenkins VS Team Services Continuous Deployment Plugin stores credentials in plain text

CVSS3: 4.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-29gp-96hf-p856

Proofpoint Enterprise Protection (PPS/PoD) contains a vulnerability which allows the pps user to escalate to root privileges due to unnecessary permissions. This affects all versions 8.19.0 and below.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-29gp-92wp-94q8

react-dev-utils on Windows vulnerable to Remote Code Execution

1%
Низкий
больше 7 лет назад
github логотип
GHSA-29gp-2c3m-3j6m

Sandbox Escape by math function in smarty

CVSS3: 8.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-29gm-gchh-5j4j

Microsoft Office Visio Remote Code Execution Vulnerability

CVSS3: 7.8
1%
Низкий
около 1 года назад
github логотип
GHSA-29gj-xrph-g435

A denial of service exists in Microsoft IIS Server when the optional request filtering feature improperly handles requests, aka 'Microsoft IIS Server Denial of Service Vulnerability'.

CVSS3: 4.4
3%
Низкий
почти 4 года назад
github логотип
GHSA-29gj-jj49-x9g7

Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-29gh-89p4-ffqv

European Chemicals Agency IUCLID 6.x before 6.27.6 allows authentication bypass because a weak hard-coded secret is used for JWT signing. The affected versions are 5.15.0 through 6.27.5.

CVSS3: 9.8
0%
Низкий
почти 3 года назад

Уязвимостей на страницу