Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 324 081

Количество 324 081

github логотип

GHSA-27g2-4mxr-gqmm

8 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in Laborator Kalium allows Cross Site Request Forgery. This issue affects Kalium: from n/a through 3.18.3.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-27fx-q398-q8vr

почти 4 года назад

masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping action.

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-27fw-r78j-h898

почти 4 года назад

Wikimedia MediaWiki allows CSRF

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-27fw-99r5-fg9c

почти 2 года назад

SQL Injection vulnerability in MegaBIP software allows attacker to obtain site administrator privileges, including access to the administration panel and the ability to change the administrator password. This issue affects MegaBIP software versions through 5.09.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-27fw-6hp8-fgww

почти 4 года назад

The av_color_primaries_name function in libavutil/pixdesc.c in FFmpeg 3.3.3 may return a NULL pointer depending on a value contained in a file, but callers do not anticipate this, as demonstrated by the avcodec_string function in libavcodec/utils.c, leading to a NULL pointer dereference. (It is also conceivable that there is security relevance for a NULL pointer dereference in av_color_primaries_name calls within the ffprobe command-line program.)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-27fv-rpgj-4c6m

5 месяцев назад

Drupal Currency allows Cross Site Request Forgery

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-27fr-v43j-r34m

около 2 лет назад

In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.

CVSS3: 2.8
EPSS: Низкий
github логотип

GHSA-27fq-8xxm-gqgw

2 месяца назад

A security flaw has been discovered in Open5GS up to 2.7.5. This issue affects some unknown processing of the component Timer Handler. The manipulation results in resource consumption. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The patch is identified as c7c131f8d2cb1195ada5e0e691b6868ebcd8a845. It is best practice to apply a patch to resolve this issue.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-27fp-j2gf-67vv

около 4 лет назад

peertube is vulnerable to Improper Access Control

EPSS: Низкий
github логотип

GHSA-27fp-c3m4-phwv

больше 1 года назад

A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228. It has been classified as critical. This affects the function setTracerouteCfg. The manipulation leads to os command injection. It is possible to initiate the attack remotely. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-27fp-57pm-cw48

почти 4 года назад

In register_app of btif_hd.cc, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-8.0 Android-8.1 Android-9. Android ID: A-119819889.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-27fj-mc8w-j9wg

почти 5 лет назад

RSA signature validation vulnerability on maleable encoded message in jsrsasign

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-27fj-7xp4-5c3r

больше 2 лет назад

Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-27fh-xm3c-9mq3

около 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Foliovision: Making the web work for you FV Flowplayer Video Player allows Stored XSS.This issue affects FV Flowplayer Video Player: from n/a through 7.5.41.7212.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-27fg-vf5m-qmjj

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: vfio/pci: fix potential memory leak in vfio_intx_enable() If vfio_irq_ctx_alloc() failed will lead to 'name' memory leak.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-27fg-888w-q9q3

9 месяцев назад

Improper Control of Generation of Code ('Code Injection') vulnerability in Bearsthemes Alone allows Remote Code Inclusion. This issue affects Alone: from n/a through 7.8.2.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-27fg-773w-qwfr

почти 4 года назад

An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2. When called with a regular file as a command-line argument, it delegates to a different program (based on the file type) without user confirmation. This could be used to achieve code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-27ff-f66w-789c

почти 4 года назад

Memory leak in the icmp_push_reply function in Linux 2.6 before 2.6.12.6 and 2.6.13 allows remote attackers to cause a denial of service (memory consumption) via a large number of crafted packets that cause the ip_append_data function to fail, aka "DST leak in icmp_push_reply."

EPSS: Низкий
github логотип

GHSA-27fc-vfp8-wfj8

почти 4 года назад

Cisco WebEx Meetings Server 1.5 presents the same CAPTCHA challenge for each login attempt, which makes it easier for remote attackers to obtain access via a brute-force approach of guessing usernames, aka Bug ID CSCuj40321.

EPSS: Низкий
github логотип

GHSA-27fc-mjrp-6g7x

4 месяца назад

XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted body of a POST request.

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-27g2-4mxr-gqmm

Cross-Site Request Forgery (CSRF) vulnerability in Laborator Kalium allows Cross Site Request Forgery. This issue affects Kalium: from n/a through 3.18.3.

CVSS3: 4.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-27fx-q398-q8vr

masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping action.

CVSS3: 9.8
94%
Критический
почти 4 года назад
github логотип
GHSA-27fw-r78j-h898

Wikimedia MediaWiki allows CSRF

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-27fw-99r5-fg9c

SQL Injection vulnerability in MegaBIP software allows attacker to obtain site administrator privileges, including access to the administration panel and the ability to change the administrator password. This issue affects MegaBIP software versions through 5.09.

CVSS3: 9.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-27fw-6hp8-fgww

The av_color_primaries_name function in libavutil/pixdesc.c in FFmpeg 3.3.3 may return a NULL pointer depending on a value contained in a file, but callers do not anticipate this, as demonstrated by the avcodec_string function in libavcodec/utils.c, leading to a NULL pointer dereference. (It is also conceivable that there is security relevance for a NULL pointer dereference in av_color_primaries_name calls within the ffprobe command-line program.)

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-27fv-rpgj-4c6m

Drupal Currency allows Cross Site Request Forgery

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-27fr-v43j-r34m

In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.

CVSS3: 2.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-27fq-8xxm-gqgw

A security flaw has been discovered in Open5GS up to 2.7.5. This issue affects some unknown processing of the component Timer Handler. The manipulation results in resource consumption. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The patch is identified as c7c131f8d2cb1195ada5e0e691b6868ebcd8a845. It is best practice to apply a patch to resolve this issue.

CVSS3: 5.3
0%
Низкий
2 месяца назад
github логотип
GHSA-27fp-j2gf-67vv

peertube is vulnerable to Improper Access Control

0%
Низкий
около 4 лет назад
github логотип
GHSA-27fp-c3m4-phwv

A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228. It has been classified as critical. This affects the function setTracerouteCfg. The manipulation leads to os command injection. It is possible to initiate the attack remotely. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
2%
Низкий
больше 1 года назад
github логотип
GHSA-27fp-57pm-cw48

In register_app of btif_hd.cc, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-8.0 Android-8.1 Android-9. Android ID: A-119819889.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-27fj-mc8w-j9wg

RSA signature validation vulnerability on maleable encoded message in jsrsasign

CVSS3: 9.1
0%
Низкий
почти 5 лет назад
github логотип
GHSA-27fj-7xp4-5c3r

Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

CVSS3: 7.2
1%
Низкий
больше 2 лет назад
github логотип
GHSA-27fh-xm3c-9mq3

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Foliovision: Making the web work for you FV Flowplayer Video Player allows Stored XSS.This issue affects FV Flowplayer Video Player: from n/a through 7.5.41.7212.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-27fg-vf5m-qmjj

In the Linux kernel, the following vulnerability has been resolved: vfio/pci: fix potential memory leak in vfio_intx_enable() If vfio_irq_ctx_alloc() failed will lead to 'name' memory leak.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-27fg-888w-q9q3

Improper Control of Generation of Code ('Code Injection') vulnerability in Bearsthemes Alone allows Remote Code Inclusion. This issue affects Alone: from n/a through 7.8.2.

CVSS3: 7.2
0%
Низкий
9 месяцев назад
github логотип
GHSA-27fg-773w-qwfr

An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2. When called with a regular file as a command-line argument, it delegates to a different program (based on the file type) without user confirmation. This could be used to achieve code execution.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-27ff-f66w-789c

Memory leak in the icmp_push_reply function in Linux 2.6 before 2.6.12.6 and 2.6.13 allows remote attackers to cause a denial of service (memory consumption) via a large number of crafted packets that cause the ip_append_data function to fail, aka "DST leak in icmp_push_reply."

7%
Низкий
почти 4 года назад
github логотип
GHSA-27fc-vfp8-wfj8

Cisco WebEx Meetings Server 1.5 presents the same CAPTCHA challenge for each login attempt, which makes it easier for remote attackers to obtain access via a brute-force approach of guessing usernames, aka Bug ID CSCuj40321.

0%
Низкий
почти 4 года назад
github логотип
GHSA-27fc-mjrp-6g7x

XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted body of a POST request.

CVSS3: 9.1
0%
Низкий
4 месяца назад

Уязвимостей на страницу