Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 377 914

Количество 377 914

github логотип

GHSA-52xg-h2f5-qwqf

больше 4 лет назад

The ProcessVolumeDeviceControlIrp function in Ntdriver.c in TrueCrypt 7.1a allows local users to bypass access restrictions and obtain sensitive information about arbitrary files via a (1) TC_IOCTL_OPEN_TEST or (2) TC_IOCTL_GET_SYSTEM_DRIVE_CONFIG IOCTL call.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-52xg-g8gg-f2f7

больше 4 лет назад

Lack of input validation for data received from user space can lead to an out of bound array issue in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in version MDM9150, MDM9206, MDM9607, MDM9650, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 636, SD 820A, SD 835, SDM630, SDM660, SDX20.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-52xg-8f7c-27c9

5 месяцев назад

TransMac 12.2 contains a buffer overflow vulnerability in the license key input field that allows local attackers to crash the application by submitting an oversized string. Attackers can generate a payload file containing 4000 bytes of data, paste it into the License Key field, and trigger a denial of service condition.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-52xg-258x-mphm

почти 2 года назад

Substance3D - Painter versions 10.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-52xg-2453-vmhx

больше 4 лет назад

Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows remote attackers to affect confidentiality via vectors related to Server: Connection.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-52xf-qwx9-xfxq

больше 4 лет назад

SHA1 implementation in JetBrains Ktor Native before 2.0.1 was returning the same value

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-52xf-jjg9-gfxx

почти 5 лет назад

Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 on an object’s date attribute(s) allows an authenticated remote attacker with Object Modification privileges to insert an unexpected format into date fields, which leads to breaking the object page that the date field is present.

EPSS: Низкий
github логотип

GHSA-52xf-h226-pfgx

больше 1 года назад

Leantime allows Refelected Cross-Site Scripting (XSS)

EPSS: Низкий
github логотип

GHSA-52xf-5p2m-9wrv

больше 2 лет назад

s2n-tls has a potentially observable differences in RSA premaster secret handling

EPSS: Низкий
github логотип

GHSA-52xc-q9g5-mc6m

9 месяцев назад

An insufficient input validation vulnerability in NETGEAR Orbi routers allows attackers connected to the router's LAN to execute OS command injections.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-52x9-rwm6-j2f3

больше 4 лет назад

"HCL Connections Security Update for Reflected Cross-Site Scripting (XSS) Vulnerability"

EPSS: Низкий
github логотип

GHSA-52x9-5h4h-vq3v

почти 2 года назад

A SQL Injection vulnerability was found in /admin/add_subject.php in kashipara E-learning Management System Project 1.0 via the subject_code parameter.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-52x8-q22p-3rrf

11 дней назад

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-52x8-4mc9-26r2

больше 4 лет назад

On Juniper Networks Junos OS and Junos OS Evolved devices, processing a specific BGP packet can lead to a routing process daemon (RPD) crash and restart. This issue can occur even before the BGP session with the peer is established. Repeated receipt of this specific BGP packet can result in an extended Denial of Service (DoS) condition. This issue affects: Juniper Networks Junos OS: 18.2X75 versions starting from 18.2X75-D50.8, 18.2X75-D60 and later versions, prior to 18.2X75-D52.8, 18.2X75-D53, 18.2X75-D60.2, 18.2X75-D65.1, 18.2X75-D70; 19.4 versions 19.4R1 and 19.4R1-S1; 20.1 versions prior to 20.1R1-S2, 20.1R2. Juniper Networks Junos OS Evolved: 19.4-EVO versions prior to 19.4R2-S2-EVO; 20.1-EVO versions prior to 20.1R2-EVO. This issue does not affect: Juniper Networks Junos OS releases prior to 19.4R1. Juniper Networks Junos OS Evolved releases prior to 19.4R1-EVO.

EPSS: Низкий
github логотип

GHSA-52x8-2f4w-q8mm

почти 3 года назад

In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink attack against a temporary file such as TMP2-00.permall.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-52x7-wcqq-wfjp

больше 2 лет назад

A use-after-free flaw was found in the netfilter subsystem of the Linux kernel. If the catchall element is garbage-collected when the pipapo set is removed, the element can be deactivated twice. This can cause a use-after-free issue on an NFT_CHAIN object or NFT_OBJECT object, allowing a local unprivileged user to escalate their privileges on the system.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-52x7-vqgq-5mww

больше 4 лет назад

Multiple integer overflows in process_bin_update function in Memcached, which is responsible for processing multiple commands of Memcached binary protocol, can be abused to cause heap overflow and lead to remote code execution.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-52x7-8654-5f6q

больше 4 лет назад

common/password.c in Pengutronix barebox through 2021.07.0 leaks timing information because strncmp is used during hash comparison.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-52x6-gq3r-vpf4

3 месяца назад

pypdf: Possible infinite loop when retrieving fonts for layout-mode text extraction

EPSS: Низкий
github логотип

GHSA-52x6-3hmc-r83m

больше 4 лет назад

The KCHARTXYLib.KChartXY ActiveX control in KChartXY.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 does not properly restrict SaveToFile method calls, which allows remote attackers to create or overwrite arbitrary files, and subsequently execute arbitrary programs, via the single pathname argument, as demonstrated by a directory traversal attack.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-52xg-h2f5-qwqf

The ProcessVolumeDeviceControlIrp function in Ntdriver.c in TrueCrypt 7.1a allows local users to bypass access restrictions and obtain sensitive information about arbitrary files via a (1) TC_IOCTL_OPEN_TEST or (2) TC_IOCTL_GET_SYSTEM_DRIVE_CONFIG IOCTL call.

CVSS3: 3.3
0%
Низкий
больше 4 лет назад
github логотип
GHSA-52xg-g8gg-f2f7

Lack of input validation for data received from user space can lead to an out of bound array issue in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in version MDM9150, MDM9206, MDM9607, MDM9650, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 636, SD 820A, SD 835, SDM630, SDM660, SDX20.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-52xg-8f7c-27c9

TransMac 12.2 contains a buffer overflow vulnerability in the license key input field that allows local attackers to crash the application by submitting an oversized string. Attackers can generate a payload file containing 4000 bytes of data, paste it into the License Key field, and trigger a denial of service condition.

CVSS3: 6.2
0%
Низкий
5 месяцев назад
github логотип
GHSA-52xg-258x-mphm

Substance3D - Painter versions 10.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-52xg-2453-vmhx

Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows remote attackers to affect confidentiality via vectors related to Server: Connection.

CVSS3: 3.7
4%
Низкий
больше 4 лет назад
github логотип
GHSA-52xf-qwx9-xfxq

SHA1 implementation in JetBrains Ktor Native before 2.0.1 was returning the same value

CVSS3: 4.9
1%
Низкий
больше 4 лет назад
github логотип
GHSA-52xf-jjg9-gfxx

Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 on an object’s date attribute(s) allows an authenticated remote attacker with Object Modification privileges to insert an unexpected format into date fields, which leads to breaking the object page that the date field is present.

1%
Низкий
почти 5 лет назад
github логотип
GHSA-52xf-h226-pfgx

Leantime allows Refelected Cross-Site Scripting (XSS)

больше 1 года назад
github логотип
GHSA-52xf-5p2m-9wrv

s2n-tls has a potentially observable differences in RSA premaster secret handling

больше 2 лет назад
github логотип
GHSA-52xc-q9g5-mc6m

An insufficient input validation vulnerability in NETGEAR Orbi routers allows attackers connected to the router's LAN to execute OS command injections.

CVSS3: 8
0%
Низкий
9 месяцев назад
github логотип
GHSA-52x9-rwm6-j2f3

"HCL Connections Security Update for Reflected Cross-Site Scripting (XSS) Vulnerability"

0%
Низкий
больше 4 лет назад
github логотип
GHSA-52x9-5h4h-vq3v

A SQL Injection vulnerability was found in /admin/add_subject.php in kashipara E-learning Management System Project 1.0 via the subject_code parameter.

CVSS3: 3.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-52x8-q22p-3rrf

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.

CVSS3: 9.8
1%
Низкий
11 дней назад
github логотип
GHSA-52x8-4mc9-26r2

On Juniper Networks Junos OS and Junos OS Evolved devices, processing a specific BGP packet can lead to a routing process daemon (RPD) crash and restart. This issue can occur even before the BGP session with the peer is established. Repeated receipt of this specific BGP packet can result in an extended Denial of Service (DoS) condition. This issue affects: Juniper Networks Junos OS: 18.2X75 versions starting from 18.2X75-D50.8, 18.2X75-D60 and later versions, prior to 18.2X75-D52.8, 18.2X75-D53, 18.2X75-D60.2, 18.2X75-D65.1, 18.2X75-D70; 19.4 versions 19.4R1 and 19.4R1-S1; 20.1 versions prior to 20.1R1-S2, 20.1R2. Juniper Networks Junos OS Evolved: 19.4-EVO versions prior to 19.4R2-S2-EVO; 20.1-EVO versions prior to 20.1R2-EVO. This issue does not affect: Juniper Networks Junos OS releases prior to 19.4R1. Juniper Networks Junos OS Evolved releases prior to 19.4R1-EVO.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-52x8-2f4w-q8mm

In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink attack against a temporary file such as TMP2-00.permall.

CVSS3: 7.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-52x7-wcqq-wfjp

A use-after-free flaw was found in the netfilter subsystem of the Linux kernel. If the catchall element is garbage-collected when the pipapo set is removed, the element can be deactivated twice. This can cause a use-after-free issue on an NFT_CHAIN object or NFT_OBJECT object, allowing a local unprivileged user to escalate their privileges on the system.

CVSS3: 7.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-52x7-vqgq-5mww

Multiple integer overflows in process_bin_update function in Memcached, which is responsible for processing multiple commands of Memcached binary protocol, can be abused to cause heap overflow and lead to remote code execution.

CVSS3: 9.8
20%
Средний
больше 4 лет назад
github логотип
GHSA-52x7-8654-5f6q

common/password.c in Pengutronix barebox through 2021.07.0 leaks timing information because strncmp is used during hash comparison.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-52x6-gq3r-vpf4

pypdf: Possible infinite loop when retrieving fonts for layout-mode text extraction

0%
Низкий
3 месяца назад
github логотип
GHSA-52x6-3hmc-r83m

The KCHARTXYLib.KChartXY ActiveX control in KChartXY.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 does not properly restrict SaveToFile method calls, which allows remote attackers to create or overwrite arbitrary files, and subsequently execute arbitrary programs, via the single pathname argument, as demonstrated by a directory traversal attack.

3%
Низкий
больше 4 лет назад

Уязвимостей на страницу