Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 377 914

Количество 377 914

github логотип

GHSA-52xv-r53x-5xpw

больше 4 лет назад

An improper access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows unauthorized users to retrieve or modify storage information.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-52xv-3j2w-p329

больше 1 года назад

libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause an spvxml-helpers.c spvxml_parse_attributes out-of-bounds read, related to extra content at the end of a document.

CVSS3: 2.9
EPSS: Низкий
github логотип

GHSA-52xv-2c78-m29x

больше 4 лет назад

The Imagination Technologies driver in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application, aka internal bug 24673908.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-52xr-wx26-9rfg

больше 4 лет назад

GeniXCMS Cross-site Scripting (XSS)

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-52xr-h9vp-pxcj

6 месяцев назад

A security vulnerability has been detected in JeecgBoot 3.9.0/3.9.1. The impacted element is an unknown function of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/airag/JeecgBizToolsProvider.java of the component AI Chat Module. Such manipulation leads to missing authentication. The attack can be executed remotely. The name of the patch is b7c9aeba7aefda9e008ea8fe4fc3daf08d0c5b39/2c1cc88b8d983868df8c520a343d6ff4369d9e59. It is best practice to apply a patch to resolve this issue. The project fixed the issue with a commit which shall be part of the next official release.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-52xq-wv9w-6fxm

больше 4 лет назад

SUSE Linux Enterprise 10 SP3 (SLE10-SP3) and openSUSE 11.2 configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access restrictions.

EPSS: Низкий
github логотип

GHSA-52xq-v6m6-c8pw

больше 4 лет назад

PHP remote file inclusion vulnerability in portfolio/commentaires/derniers_commentaires.php in Cyberfolio 7.12, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the rep parameter.

EPSS: Низкий
github логотип

GHSA-52xq-j7v9-v4v2

больше 2 лет назад

Vyper negative array index bounds checks

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-52xq-4j7g-g3fj

9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: smc91x: fix broken irq-context in PREEMPT_RT When smc91x.c is built with PREEMPT_RT, the following splat occurs in FVP_RevC: [ 13.055000] smc91x LNRO0003:00 eth0: link up, 10Mbps, half-duplex, lpa 0x0000 [ 13.062137] BUG: workqueue leaked atomic, lock or RCU: kworker/2:1[106] [ 13.062137] preempt=0x00000000 lock=0->0 RCU=0->1 workfn=mld_ifc_work [ 13.062266] C ** replaying previous printk message ** [ 13.062266] CPU: 2 UID: 0 PID: 106 Comm: kworker/2:1 Not tainted 6.18.0-dirty #179 PREEMPT_{RT,(full)} [ 13.062353] Hardware name: , BIOS [ 13.062382] Workqueue: mld mld_ifc_work [ 13.062469] Call trace: [ 13.062494] show_stack+0x24/0x40 (C) [ 13.062602] __dump_stack+0x28/0x48 [ 13.062710] dump_stack_lvl+0x7c/0xb0 [ 13.062818] dump_stack+0x18/0x34 [ 13.062926] process_scheduled_works+0x294/0x450 [ 13.063043] worker_thread+0x260/0x3d8 [ 13.063124] kthread+0x1c4/0x228 [ 13.0...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-52xp-w8hr-xv3c

26 дней назад

Filament: Multi-factor authentication (app) can be bypassed when recovery codes are enabled

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-52xm-jhx6-v67c

около 3 лет назад

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPO365 | Mail Integration for Office 365 / Outlook plugin <= 1.9.0 versions.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-52xm-jh2q-v993

больше 1 года назад

Cross-Site Scripting vulnerability in OpenCart versions prior to 4.1.0. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the search in the /product/search endpoint. This vulnerability could be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-52xj-xx8j-p5vw

около 2 месяцев назад

Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-52xj-vx8w-46qj

8 месяцев назад

We have identified a bug in Node.js error handling where "Maximum call stack size exceeded" errors become uncatchable when `async_hooks.createHook()` is enabled. Instead of reaching `process.on('uncaughtException')`, the process terminates, making the crash unrecoverable. Applications that rely on `AsyncLocalStorage` (v22, v20) or `async_hooks.createHook()` (v24, v22, v20) become vulnerable to denial-of-service crashes triggered by deep recursion under specific conditions.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-52xj-gr8m-2fv8

больше 4 лет назад

In RIOT 2019.07, the MQTT-SN implementation (asymcute) mishandles errors occurring during a read operation on a UDP socket. The receive loop ends. This allows an attacker (via a large packet) to prevent a RIOT MQTT-SN client from working until the device is restarted.

EPSS: Низкий
github логотип

GHSA-52xj-6c8j-4pv2

больше 4 лет назад

Huawei Mate8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and NXT-TL before NXT-TL00C01B182 allows attackers to bypass permission checks and delete user data via a crafted app.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-52xh-m68f-gh6g

около 1 месяца назад

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory corruption vulnerability exists in the AIX IPsec ESP decapsulation handler. Successful exploitation may corrupt kernel stack state and cause a system crash, resulting in denial of service.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-52xh-59wj-pf75

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aviplugins.com Thumbnail Editor allows Stored XSS. This issue affects Thumbnail Editor: from n/a through 2.3.3.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-52xg-ww6x-gh3x

почти 5 лет назад

Inappropriate implementation in input in Google Chrome prior to 96.0.4664.45 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.

EPSS: Низкий
github логотип

GHSA-52xg-w6c8-rp56

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the formatHTML function in includes/api/ApiFormatBase.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 allows remote attackers to inject arbitrary web script or HTML via a crafted string located after http:// in the text parameter to api.php.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-52xv-r53x-5xpw

An improper access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows unauthorized users to retrieve or modify storage information.

CVSS3: 8.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-52xv-3j2w-p329

libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause an spvxml-helpers.c spvxml_parse_attributes out-of-bounds read, related to extra content at the end of a document.

CVSS3: 2.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-52xv-2c78-m29x

The Imagination Technologies driver in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application, aka internal bug 24673908.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-52xr-wx26-9rfg

GeniXCMS Cross-site Scripting (XSS)

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-52xr-h9vp-pxcj

A security vulnerability has been detected in JeecgBoot 3.9.0/3.9.1. The impacted element is an unknown function of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/airag/JeecgBizToolsProvider.java of the component AI Chat Module. Such manipulation leads to missing authentication. The attack can be executed remotely. The name of the patch is b7c9aeba7aefda9e008ea8fe4fc3daf08d0c5b39/2c1cc88b8d983868df8c520a343d6ff4369d9e59. It is best practice to apply a patch to resolve this issue. The project fixed the issue with a commit which shall be part of the next official release.

CVSS3: 7.3
1%
Низкий
6 месяцев назад
github логотип
GHSA-52xq-wv9w-6fxm

SUSE Linux Enterprise 10 SP3 (SLE10-SP3) and openSUSE 11.2 configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access restrictions.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-52xq-v6m6-c8pw

PHP remote file inclusion vulnerability in portfolio/commentaires/derniers_commentaires.php in Cyberfolio 7.12, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the rep parameter.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-52xq-j7v9-v4v2

Vyper negative array index bounds checks

CVSS3: 9.8
2%
Низкий
больше 2 лет назад
github логотип
GHSA-52xq-4j7g-g3fj

In the Linux kernel, the following vulnerability has been resolved: smc91x: fix broken irq-context in PREEMPT_RT When smc91x.c is built with PREEMPT_RT, the following splat occurs in FVP_RevC: [ 13.055000] smc91x LNRO0003:00 eth0: link up, 10Mbps, half-duplex, lpa 0x0000 [ 13.062137] BUG: workqueue leaked atomic, lock or RCU: kworker/2:1[106] [ 13.062137] preempt=0x00000000 lock=0->0 RCU=0->1 workfn=mld_ifc_work [ 13.062266] C ** replaying previous printk message ** [ 13.062266] CPU: 2 UID: 0 PID: 106 Comm: kworker/2:1 Not tainted 6.18.0-dirty #179 PREEMPT_{RT,(full)} [ 13.062353] Hardware name: , BIOS [ 13.062382] Workqueue: mld mld_ifc_work [ 13.062469] Call trace: [ 13.062494] show_stack+0x24/0x40 (C) [ 13.062602] __dump_stack+0x28/0x48 [ 13.062710] dump_stack_lvl+0x7c/0xb0 [ 13.062818] dump_stack+0x18/0x34 [ 13.062926] process_scheduled_works+0x294/0x450 [ 13.063043] worker_thread+0x260/0x3d8 [ 13.063124] kthread+0x1c4/0x228 [ 13.0...

CVSS3: 5.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-52xp-w8hr-xv3c

Filament: Multi-factor authentication (app) can be bypassed when recovery codes are enabled

CVSS3: 8.1
1%
Низкий
26 дней назад
github логотип
GHSA-52xm-jhx6-v67c

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPO365 | Mail Integration for Office 365 / Outlook plugin <= 1.9.0 versions.

CVSS3: 5.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-52xm-jh2q-v993

Cross-Site Scripting vulnerability in OpenCart versions prior to 4.1.0. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the search in the /product/search endpoint. This vulnerability could be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-52xj-xx8j-p5vw

Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-52xj-vx8w-46qj

We have identified a bug in Node.js error handling where "Maximum call stack size exceeded" errors become uncatchable when `async_hooks.createHook()` is enabled. Instead of reaching `process.on('uncaughtException')`, the process terminates, making the crash unrecoverable. Applications that rely on `AsyncLocalStorage` (v22, v20) or `async_hooks.createHook()` (v24, v22, v20) become vulnerable to denial-of-service crashes triggered by deep recursion under specific conditions.

CVSS3: 5.9
1%
Низкий
8 месяцев назад
github логотип
GHSA-52xj-gr8m-2fv8

In RIOT 2019.07, the MQTT-SN implementation (asymcute) mishandles errors occurring during a read operation on a UDP socket. The receive loop ends. This allows an attacker (via a large packet) to prevent a RIOT MQTT-SN client from working until the device is restarted.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-52xj-6c8j-4pv2

Huawei Mate8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and NXT-TL before NXT-TL00C01B182 allows attackers to bypass permission checks and delete user data via a crafted app.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-52xh-m68f-gh6g

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory corruption vulnerability exists in the AIX IPsec ESP decapsulation handler. Successful exploitation may corrupt kernel stack state and cause a system crash, resulting in denial of service.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-52xh-59wj-pf75

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aviplugins.com Thumbnail Editor allows Stored XSS. This issue affects Thumbnail Editor: from n/a through 2.3.3.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-52xg-ww6x-gh3x

Inappropriate implementation in input in Google Chrome prior to 96.0.4664.45 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.

1%
Низкий
почти 5 лет назад
github логотип
GHSA-52xg-w6c8-rp56

Cross-site scripting (XSS) vulnerability in the formatHTML function in includes/api/ApiFormatBase.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 allows remote attackers to inject arbitrary web script or HTML via a crafted string located after http:// in the text parameter to api.php.

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу