Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 324 758

Количество 324 758

github логотип

GHSA-28rf-jqpf-2x8g

почти 4 года назад

MitraStar GPT-2541GNAC-N1 (HGU) 100VNZ0b33 devices allow remote authenticated users to obtain root access by executing command "deviceinfo show file &&/bin/bash" because of incorrect sanitization of parameter "path".

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-28rc-mq4v-8p47

почти 4 года назад

Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."

EPSS: Средний
github логотип

GHSA-28rc-hxmf-wqhx

10 месяцев назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-28rc-f27x-5qwc

17 дней назад

Heap buffer overflow in PDFium in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-28rc-568h-qq5j

почти 4 года назад

The Telus Wi-Fi Hub (PRV65B444A-S-TS) with firmware version 3.00.20 is affected by an authenticated command injection vulnerability in multiple parameters passed to tr69_cmd.cgi. A remote attacker connected to the router's LAN and authenticated with a super user account, or using a bypass authentication vulnerability like CVE-2021-20090 could leverage this issue to run commands or gain a shell as root on the target device.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-28r9-r5gx-vxvg

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix UBSAN warning in kv_dpm.c Adds bounds check for sumo_vid_mapping_entry.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-28r9-pq4c-wp3c

больше 3 лет назад

personnummer/rust vulnerable to Improper Input Validation

EPSS: Низкий
github логотип

GHSA-28r9-jxmr-8hgr

12 дней назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Mixtape mixtape allows PHP Local File Inclusion.This issue affects Mixtape: from n/a through <= 2.1.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-28r9-hhcv-7c73

почти 4 года назад

Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X 10.5 before 10.5.8 makes it easier for user-assisted remote attackers to execute arbitrary JavaScript via a web page that offers a download with a Content-Type value that is not on the list of possibly unsafe content types for Safari.

EPSS: Низкий
github логотип

GHSA-28r9-967h-xvcv

почти 4 года назад

Open Information Security Foundation Suricata prior to version 4.1.2 is affected by: Denial of Service - DNS detection bypass. The impact is: An attacker can evade a signature detection with a specialy formed network packet. The component is: app-layer-detect-proto.c, decode.c, decode-teredo.c and decode-ipv6.c (https://github.com/OISF/suricata/pull/3590/commits/11f3659f64a4e42e90cb3c09fcef66894205aefe, https://github.com/OISF/suricata/pull/3590/commits/8357ef3f8ffc7d99ef6571350724160de356158b). The attack vector is: An attacker can trigger the vulnerability by sending a specifically crafted network request. The fixed version is: 4.1.2.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-28r9-5f3v-j8fw

почти 4 года назад

When a user opens manipulated Portable Document Format (.pdf, PDFView.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-28r9-4273-pm3w

почти 4 года назад

An insecure transport protocol used by Drobo Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to intercept network traffic.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-28r8-9g34-2x25

почти 4 года назад

A vulnerability in the web UI of Cisco Umbrella could allow an unauthenticated, remote attacker to negatively affect the performance of this service. The vulnerability exists due to insufficient rate limiting controls in the web UI. An attacker could exploit this vulnerability by sending crafted HTTPS packets at a high and sustained rate. A successful exploit could allow the attacker to negatively affect the performance of the web UI. Cisco has addressed this vulnerability.

EPSS: Низкий
github логотип

GHSA-28r8-6q2m-x9g4

почти 4 года назад

The XD Forum (aka com.tapatalk.xdforumcomforum) application 3.9.17 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-28r7-8r62-w9hj

6 месяцев назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki WebAuthn extension allows Stored XSS.This issue affects MediaWiki WebAuthn extension: 1.39, 1.43, 1.44.

EPSS: Низкий
github логотип

GHSA-28r6-jm5h-mrgg

около 4 лет назад

Access control bypass in Beego

EPSS: Низкий
github логотип

GHSA-28r4-58h5-m5rr

почти 4 года назад

In JetBrains YouTrack before 2021.3.21051, a user could see boards without having corresponding permissions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-28r2-q6m8-9hpx

почти 4 года назад

HashiCorp go-getter unsafe downloads could lead to asymmetric resource exhaustion

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-28qw-8jmg-32wx

больше 2 лет назад

Transient DOS when processing a NULL buffer while parsing WLAN vdev.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-28qr-hqrv-mhvr

почти 4 года назад

libdwarf 2016-10-21 allows context-dependent attackers to obtain sensitive information or cause a denial of service by using the "malformed dwarf file" approach, related to a "Heap Buffer Over-read" issue affecting the dwarf_util.c component, aka DW201611-006.

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-28rf-jqpf-2x8g

MitraStar GPT-2541GNAC-N1 (HGU) 100VNZ0b33 devices allow remote authenticated users to obtain root access by executing command "deviceinfo show file &&/bin/bash" because of incorrect sanitization of parameter "path".

CVSS3: 8.8
40%
Средний
почти 4 года назад
github логотип
GHSA-28rc-mq4v-8p47

Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."

43%
Средний
почти 4 года назад
github логотип
GHSA-28rc-hxmf-wqhx

Rejected reason: Not used

10 месяцев назад
github логотип
GHSA-28rc-f27x-5qwc

Heap buffer overflow in PDFium in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)

CVSS3: 8.8
0%
Низкий
17 дней назад
github логотип
GHSA-28rc-568h-qq5j

The Telus Wi-Fi Hub (PRV65B444A-S-TS) with firmware version 3.00.20 is affected by an authenticated command injection vulnerability in multiple parameters passed to tr69_cmd.cgi. A remote attacker connected to the router's LAN and authenticated with a super user account, or using a bypass authentication vulnerability like CVE-2021-20090 could leverage this issue to run commands or gain a shell as root on the target device.

CVSS3: 7.2
9%
Низкий
почти 4 года назад
github логотип
GHSA-28r9-r5gx-vxvg

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix UBSAN warning in kv_dpm.c Adds bounds check for sumo_vid_mapping_entry.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-28r9-pq4c-wp3c

personnummer/rust vulnerable to Improper Input Validation

больше 3 лет назад
github логотип
GHSA-28r9-jxmr-8hgr

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Mixtape mixtape allows PHP Local File Inclusion.This issue affects Mixtape: from n/a through <= 2.1.

CVSS3: 8.1
0%
Низкий
12 дней назад
github логотип
GHSA-28r9-hhcv-7c73

Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X 10.5 before 10.5.8 makes it easier for user-assisted remote attackers to execute arbitrary JavaScript via a web page that offers a download with a Content-Type value that is not on the list of possibly unsafe content types for Safari.

1%
Низкий
почти 4 года назад
github логотип
GHSA-28r9-967h-xvcv

Open Information Security Foundation Suricata prior to version 4.1.2 is affected by: Denial of Service - DNS detection bypass. The impact is: An attacker can evade a signature detection with a specialy formed network packet. The component is: app-layer-detect-proto.c, decode.c, decode-teredo.c and decode-ipv6.c (https://github.com/OISF/suricata/pull/3590/commits/11f3659f64a4e42e90cb3c09fcef66894205aefe, https://github.com/OISF/suricata/pull/3590/commits/8357ef3f8ffc7d99ef6571350724160de356158b). The attack vector is: An attacker can trigger the vulnerability by sending a specifically crafted network request. The fixed version is: 4.1.2.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-28r9-5f3v-j8fw

When a user opens manipulated Portable Document Format (.pdf, PDFView.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-28r9-4273-pm3w

An insecure transport protocol used by Drobo Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to intercept network traffic.

CVSS3: 9.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-28r8-9g34-2x25

A vulnerability in the web UI of Cisco Umbrella could allow an unauthenticated, remote attacker to negatively affect the performance of this service. The vulnerability exists due to insufficient rate limiting controls in the web UI. An attacker could exploit this vulnerability by sending crafted HTTPS packets at a high and sustained rate. A successful exploit could allow the attacker to negatively affect the performance of the web UI. Cisco has addressed this vulnerability.

0%
Низкий
почти 4 года назад
github логотип
GHSA-28r8-6q2m-x9g4

The XD Forum (aka com.tapatalk.xdforumcomforum) application 3.9.17 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
почти 4 года назад
github логотип
GHSA-28r7-8r62-w9hj

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki WebAuthn extension allows Stored XSS.This issue affects MediaWiki WebAuthn extension: 1.39, 1.43, 1.44.

0%
Низкий
6 месяцев назад
github логотип
GHSA-28r6-jm5h-mrgg

Access control bypass in Beego

0%
Низкий
около 4 лет назад
github логотип
GHSA-28r4-58h5-m5rr

In JetBrains YouTrack before 2021.3.21051, a user could see boards without having corresponding permissions.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-28r2-q6m8-9hpx

HashiCorp go-getter unsafe downloads could lead to asymmetric resource exhaustion

CVSS3: 8.6
1%
Низкий
почти 4 года назад
github логотип
GHSA-28qw-8jmg-32wx

Transient DOS when processing a NULL buffer while parsing WLAN vdev.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-28qr-hqrv-mhvr

libdwarf 2016-10-21 allows context-dependent attackers to obtain sensitive information or cause a denial of service by using the "malformed dwarf file" approach, related to a "Heap Buffer Over-read" issue affecting the dwarf_util.c component, aka DW201611-006.

CVSS3: 9.1
0%
Низкий
почти 4 года назад

Уязвимостей на страницу