Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 323 805

Количество 323 805

github логотип

GHSA-26qp-7xwg-8f45

почти 4 года назад

Cross-site scripting (XSS) vulnerability in PHP-Fusion 9.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-26qm-jcfr-w44c

почти 4 года назад

Double free vulnerability in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary code via a Word document with crafted List Format Override (LFO) records, aka "Word Pointer Vulnerability."

EPSS: Средний
github логотип

GHSA-26qm-2594-mccv

почти 4 года назад

Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert (RTC) 2.0.0.x allows remote authenticated users to inject arbitrary web script or HTML via the name of a shared report.

EPSS: Низкий
github логотип

GHSA-26qj-cr27-r5c4

почти 4 года назад

Octopoller gem published with world-writable files

CVSS3: 2.5
EPSS: Низкий
github логотип

GHSA-26qj-5g3c-qwm4

7 месяцев назад

Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier). If this vulnerability is exploited, arbitrary files may be viewed by a remote unauthenticated attacker.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-26qh-mgjw-5hg7

почти 4 года назад

D-link DIR-816 A2 v1.10 is affected by a remote code injection vulnerability. An HTTP request parameter can be used in command string construction in the handler function of the /goform/dir_setWanWifi, which can lead to command injection via shell metacharacters in the statuscheckpppoeuser parameter.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-26qg-wc7f-8867

почти 4 года назад

net/ipv4/tcp_input.c in the Linux kernel before 4.7 does not properly determine the rate of challenge ACK segments, which makes it easier for remote attackers to hijack TCP sessions via a blind in-window attack.

CVSS3: 4.8
EPSS: Средний
github логотип

GHSA-26qg-4hpq-vwx9

почти 4 года назад

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 131853.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-26qf-c8f8-mrg9

больше 3 лет назад

In vcu, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07203500; Issue ID: ALPS07203500.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-26qf-34q8-32jq

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in the Virtual War (VWar) 1.5.0 R15 and earlier module for PHP-Nuke, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) memberlist parameter to extra/login.php and the (2) title parameter to extra/today.php.

EPSS: Низкий
github логотип

GHSA-26qf-2r89-746r

больше 1 года назад

Unrestricted Upload of File with Dangerous Type vulnerability in Shafiq Digital Lottery allows Upload a Web Shell to a Web Server.This issue affects Digital Lottery: from n/a through 3.0.5.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-26qc-f6w8-8qqq

почти 4 года назад

Untrusted search path vulnerability in Adobe On Location CS4 Build 315 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse ibfs32.dll that is located in the same folder as an OLPROJ file.

EPSS: Низкий
github логотип

GHSA-26qc-7vc3-c96r

больше 2 лет назад

The next parameter in the /accounts/login endpoint of Seafile 9.0.6 allows attackers to redirect users to arbitrary sites.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-26q9-c8pg-577f

почти 4 года назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop 16.6.3.84. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DWF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-12717.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-26q9-4p72-922v

почти 4 года назад

Unspecified vulnerability in the Mobile Server component in Oracle Database Mobile/Lite Server (formerly Oracle Database Lite) 10.3.0.3 and 11.1.0.0 allows remote attackers to affect confidentiality via unknown vectors, a different vulnerability than CVE-2013-0363 and CVE-2013-0364.

EPSS: Низкий
github логотип

GHSA-26q9-378g-g2f7

больше 2 лет назад

Improper Certificate Validation in FotaAgent prior to SMR Nov-2023 Release1 allows remote attacker to intercept the network traffic including Firmware information.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-26q8-whgc-65w9

почти 4 года назад

gpu/blink/webgraphicscontext3d_impl.cc in the WebGL implementation in Google Chrome before 42.0.2311.90 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WebGL program that triggers a state inconsistency.

EPSS: Низкий
github логотип

GHSA-26q8-4547-5jf2

почти 4 года назад

Buffer overflow in the XDMCP parsing code of GNOME gdm, KDE kdm, and wdm allows remote attackers to execute arbitrary commands or cause a denial of service via a long FORWARD_QUERY request.

EPSS: Низкий
github логотип

GHSA-26q8-3mmj-6qfx

около 2 лет назад

The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the 'modal' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-26q7-wp6g-349w

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix array out-of-bound access in SoC stats Currently, the ath12k_soc_dp_stats::hal_reo_error array is defined with a maximum size of DP_REO_DST_RING_MAX. However, the ath12k_dp_rx_process() function access ath12k_soc_dp_stats::hal_reo_error using the REO destination SRNG ring ID, which is incorrect. SRNG ring ID differ from normal ring ID, and this usage leads to out-of-bounds array access. To fix this issue, modify ath12k_dp_rx_process() to use the normal ring ID directly instead of the SRNG ring ID to avoid out-of-bounds array access. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.0.1-00029-QCAHKSWPL_SILICONZ-1

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-26qp-7xwg-8f45

Cross-site scripting (XSS) vulnerability in PHP-Fusion 9.

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-26qm-jcfr-w44c

Double free vulnerability in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary code via a Word document with crafted List Format Override (LFO) records, aka "Word Pointer Vulnerability."

66%
Средний
почти 4 года назад
github логотип
GHSA-26qm-2594-mccv

Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert (RTC) 2.0.0.x allows remote authenticated users to inject arbitrary web script or HTML via the name of a shared report.

0%
Низкий
почти 4 года назад
github логотип
GHSA-26qj-cr27-r5c4

Octopoller gem published with world-writable files

CVSS3: 2.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-26qj-5g3c-qwm4

Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier). If this vulnerability is exploited, arbitrary files may be viewed by a remote unauthenticated attacker.

CVSS3: 7.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-26qh-mgjw-5hg7

D-link DIR-816 A2 v1.10 is affected by a remote code injection vulnerability. An HTTP request parameter can be used in command string construction in the handler function of the /goform/dir_setWanWifi, which can lead to command injection via shell metacharacters in the statuscheckpppoeuser parameter.

CVSS3: 9.8
34%
Средний
почти 4 года назад
github логотип
GHSA-26qg-wc7f-8867

net/ipv4/tcp_input.c in the Linux kernel before 4.7 does not properly determine the rate of challenge ACK segments, which makes it easier for remote attackers to hijack TCP sessions via a blind in-window attack.

CVSS3: 4.8
33%
Средний
почти 4 года назад
github логотип
GHSA-26qg-4hpq-vwx9

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 131853.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-26qf-c8f8-mrg9

In vcu, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07203500; Issue ID: ALPS07203500.

CVSS3: 6.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-26qf-34q8-32jq

Multiple cross-site scripting (XSS) vulnerabilities in the Virtual War (VWar) 1.5.0 R15 and earlier module for PHP-Nuke, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) memberlist parameter to extra/login.php and the (2) title parameter to extra/today.php.

0%
Низкий
почти 4 года назад
github логотип
GHSA-26qf-2r89-746r

Unrestricted Upload of File with Dangerous Type vulnerability in Shafiq Digital Lottery allows Upload a Web Shell to a Web Server.This issue affects Digital Lottery: from n/a through 3.0.5.

CVSS3: 10
1%
Низкий
больше 1 года назад
github логотип
GHSA-26qc-f6w8-8qqq

Untrusted search path vulnerability in Adobe On Location CS4 Build 315 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse ibfs32.dll that is located in the same folder as an OLPROJ file.

3%
Низкий
почти 4 года назад
github логотип
GHSA-26qc-7vc3-c96r

The next parameter in the /accounts/login endpoint of Seafile 9.0.6 allows attackers to redirect users to arbitrary sites.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-26q9-c8pg-577f

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop 16.6.3.84. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DWF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-12717.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-26q9-4p72-922v

Unspecified vulnerability in the Mobile Server component in Oracle Database Mobile/Lite Server (formerly Oracle Database Lite) 10.3.0.3 and 11.1.0.0 allows remote attackers to affect confidentiality via unknown vectors, a different vulnerability than CVE-2013-0363 and CVE-2013-0364.

0%
Низкий
почти 4 года назад
github логотип
GHSA-26q9-378g-g2f7

Improper Certificate Validation in FotaAgent prior to SMR Nov-2023 Release1 allows remote attacker to intercept the network traffic including Firmware information.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-26q8-whgc-65w9

gpu/blink/webgraphicscontext3d_impl.cc in the WebGL implementation in Google Chrome before 42.0.2311.90 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WebGL program that triggers a state inconsistency.

1%
Низкий
почти 4 года назад
github логотип
GHSA-26q8-4547-5jf2

Buffer overflow in the XDMCP parsing code of GNOME gdm, KDE kdm, and wdm allows remote attackers to execute arbitrary commands or cause a denial of service via a long FORWARD_QUERY request.

7%
Низкий
почти 4 года назад
github логотип
GHSA-26q8-3mmj-6qfx

The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the 'modal' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

CVSS3: 9.8
3%
Низкий
около 2 лет назад
github логотип
GHSA-26q7-wp6g-349w

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix array out-of-bound access in SoC stats Currently, the ath12k_soc_dp_stats::hal_reo_error array is defined with a maximum size of DP_REO_DST_RING_MAX. However, the ath12k_dp_rx_process() function access ath12k_soc_dp_stats::hal_reo_error using the REO destination SRNG ring ID, which is incorrect. SRNG ring ID differ from normal ring ID, and this usage leads to out-of-bounds array access. To fix this issue, modify ath12k_dp_rx_process() to use the normal ring ID directly instead of the SRNG ring ID to avoid out-of-bounds array access. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.0.1-00029-QCAHKSWPL_SILICONZ-1

CVSS3: 7.8
0%
Низкий
больше 1 года назад

Уязвимостей на страницу