Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 377 914

Количество 377 914

github логотип

GHSA-52rr-5975-mg2x

4 месяца назад

Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain a stack overflow in the IPMacBindRuleIp parameter of the formIPMacBindModify function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-52rq-v884-rfrr

больше 4 лет назад

A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the AVRDL unpacking module component used in certain F-Secure products can crash while scanning a fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the Anti-Virus engine.

EPSS: Низкий
github логотип

GHSA-52rq-q237-rxxg

больше 4 лет назад

Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 16.1 allows remote authenticated users to affect confidentiality and integrity via vectors related to OpenUI.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-52rq-pjr4-f69g

почти 5 лет назад

D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the function sub_8003183C in /fromLogin. This vulnerability is triggered via a crafted POST request.

EPSS: Низкий
github логотип

GHSA-52rq-cpwv-rvvm

12 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: fs, fix UAF in flow counter release Fix a kernel trace [1] caused by releasing an HWS action of a local flow counter in mlx5_cmd_hws_delete_fte(), where the HWS action refcount and mutex were not initialized and the counter struct could already be freed when deleting the rule. Fix it by adding the missing initializations and adding refcount for the local flow counter struct. [1] Kernel log: Call Trace: <TASK> dump_stack_lvl+0x34/0x48 mlx5_fs_put_hws_action.part.0.cold+0x21/0x94 [mlx5_core] mlx5_fc_put_hws_action+0x96/0xad [mlx5_core] mlx5_fs_destroy_fs_actions+0x8b/0x152 [mlx5_core] mlx5_cmd_hws_delete_fte+0x5a/0xa0 [mlx5_core] del_hw_fte+0x1ce/0x260 [mlx5_core] mlx5_del_flow_rules+0x12d/0x240 [mlx5_core] ? ttwu_queue_wakelist+0xf4/0x110 mlx5_ib_destroy_flow+0x103/0x1b0 [mlx5_ib] uverbs_free_flow+0x20/0x50 [ib_uverbs] destroy_hw_idr_uobject+0x1b/0x50 [ib_uverbs] uverbs_destro...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-52rq-4m29-jc22

5 месяцев назад

An improper input validation vulnerability within the AMD Platform Management Framework (PMF) Driver can allow a local attacker to write Out-of-Bounds, potentially resulting in privilege escalation.

EPSS: Низкий
github логотип

GHSA-52rp-xrf8-52vj

больше 4 лет назад

Directory traversal vulnerability in WebAccess in Novell GroupWise before 8.03 allows remote attackers to read arbitrary files via the User.interface parameter.

EPSS: Низкий
github логотип

GHSA-52rp-w429-m5h3

больше 4 лет назад

SQL injection vulnerability in includes/funcs_vendors.php in Censura 1.15.04, and other versions before 1.16.04, allows remote attackers to execute arbitrary SQL commands via the vendorid parameter in a vendor_info cmd action to censura.php.

EPSS: Низкий
github логотип

GHSA-52rp-v38p-8vgp

больше 4 лет назад

Directory traversal vulnerability in page.php in EntertainmentScript 1.4.0 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the page parameter.

EPSS: Низкий
github логотип

GHSA-52rm-r39v-fwv9

6 месяцев назад

In systemd 258 before 260, a local unprivileged user can trigger an assert when a Delegate=yes and User=<unset> unit exists and is running.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-52rm-ch56-6jhr

около 3 лет назад

The websocket configuration endpoint of the Loxone Miniserver Go Gen.2 before 14.1.5.9 allows remote authenticated administrators to inject arbitrary OS commands via the timezone parameter.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-52rm-98j7-2qqh

больше 4 лет назад

Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to discover the usernames of users via an enumeration vulnerability in the password reset page. The affected versions are before version 8.5.10, and from version 8.6.0 before 8.13.1.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-52rj-c24h-m8wr

11 месяцев назад

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-52rj-7m6g-jf9j

больше 3 лет назад

In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-52rj-2977-r9p2

больше 4 лет назад

A security misconfiguration vulnerability exists in Schneider Electric's IGSS SCADA Software versions 12 and prior. Security configuration settings such as Address Space Layout Randomization (ASLR) and Data Execution prevention (DEP) were not properly configured resulting in weak security.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-52rh-vv3q-8jrh

почти 3 года назад

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Apollo13Themes Apollo13 Framework Extensions plugin <= 1.9.0 versions.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-52rh-8xjj-29g8

больше 4 лет назад

SQL injection vulnerability in default2.asp in fipsForum 2.6 and earlier allows remote attackers to execute arbitrary SQL commands via the kat parameter.

EPSS: Низкий
github логотип

GHSA-52rh-5rpj-c3w6

больше 4 лет назад

Improper handling of multiline messages in node-irc

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-52rg-mg9f-p465

больше 4 лет назад

Microsoft Internet Explorer 10 and 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Information Disclosure Vulnerability."

EPSS: Средний
github логотип

GHSA-52rg-hpwq-qp56

больше 4 лет назад

Allocation of Resources Without Limits or Throttling in Keycloak

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-52rr-5975-mg2x

Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain a stack overflow in the IPMacBindRuleIp parameter of the formIPMacBindModify function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

CVSS3: 7.5
1%
Низкий
4 месяца назад
github логотип
GHSA-52rq-v884-rfrr

A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the AVRDL unpacking module component used in certain F-Secure products can crash while scanning a fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the Anti-Virus engine.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-52rq-q237-rxxg

Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 16.1 allows remote authenticated users to affect confidentiality and integrity via vectors related to OpenUI.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-52rq-pjr4-f69g

D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer overflow vulnerability in the function sub_8003183C in /fromLogin. This vulnerability is triggered via a crafted POST request.

4%
Низкий
почти 5 лет назад
github логотип
GHSA-52rq-cpwv-rvvm

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: fs, fix UAF in flow counter release Fix a kernel trace [1] caused by releasing an HWS action of a local flow counter in mlx5_cmd_hws_delete_fte(), where the HWS action refcount and mutex were not initialized and the counter struct could already be freed when deleting the rule. Fix it by adding the missing initializations and adding refcount for the local flow counter struct. [1] Kernel log: Call Trace: <TASK> dump_stack_lvl+0x34/0x48 mlx5_fs_put_hws_action.part.0.cold+0x21/0x94 [mlx5_core] mlx5_fc_put_hws_action+0x96/0xad [mlx5_core] mlx5_fs_destroy_fs_actions+0x8b/0x152 [mlx5_core] mlx5_cmd_hws_delete_fte+0x5a/0xa0 [mlx5_core] del_hw_fte+0x1ce/0x260 [mlx5_core] mlx5_del_flow_rules+0x12d/0x240 [mlx5_core] ? ttwu_queue_wakelist+0xf4/0x110 mlx5_ib_destroy_flow+0x103/0x1b0 [mlx5_ib] uverbs_free_flow+0x20/0x50 [ib_uverbs] destroy_hw_idr_uobject+0x1b/0x50 [ib_uverbs] uverbs_destro...

CVSS3: 7.8
0%
Низкий
12 месяцев назад
github логотип
GHSA-52rq-4m29-jc22

An improper input validation vulnerability within the AMD Platform Management Framework (PMF) Driver can allow a local attacker to write Out-of-Bounds, potentially resulting in privilege escalation.

0%
Низкий
5 месяцев назад
github логотип
GHSA-52rp-xrf8-52vj

Directory traversal vulnerability in WebAccess in Novell GroupWise before 8.03 allows remote attackers to read arbitrary files via the User.interface parameter.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-52rp-w429-m5h3

SQL injection vulnerability in includes/funcs_vendors.php in Censura 1.15.04, and other versions before 1.16.04, allows remote attackers to execute arbitrary SQL commands via the vendorid parameter in a vendor_info cmd action to censura.php.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-52rp-v38p-8vgp

Directory traversal vulnerability in page.php in EntertainmentScript 1.4.0 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the page parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-52rm-r39v-fwv9

In systemd 258 before 260, a local unprivileged user can trigger an assert when a Delegate=yes and User=<unset> unit exists and is running.

CVSS3: 4.7
0%
Низкий
6 месяцев назад
github логотип
GHSA-52rm-ch56-6jhr

The websocket configuration endpoint of the Loxone Miniserver Go Gen.2 before 14.1.5.9 allows remote authenticated administrators to inject arbitrary OS commands via the timezone parameter.

CVSS3: 7.2
1%
Низкий
около 3 лет назад
github логотип
GHSA-52rm-98j7-2qqh

Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to discover the usernames of users via an enumeration vulnerability in the password reset page. The affected versions are before version 8.5.10, and from version 8.6.0 before 8.13.1.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-52rj-c24h-m8wr

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
11 месяцев назад
github логотип
GHSA-52rj-7m6g-jf9j

In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-52rj-2977-r9p2

A security misconfiguration vulnerability exists in Schneider Electric's IGSS SCADA Software versions 12 and prior. Security configuration settings such as Address Space Layout Randomization (ASLR) and Data Execution prevention (DEP) were not properly configured resulting in weak security.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-52rh-vv3q-8jrh

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Apollo13Themes Apollo13 Framework Extensions plugin <= 1.9.0 versions.

CVSS3: 5.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-52rh-8xjj-29g8

SQL injection vulnerability in default2.asp in fipsForum 2.6 and earlier allows remote attackers to execute arbitrary SQL commands via the kat parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-52rh-5rpj-c3w6

Improper handling of multiline messages in node-irc

CVSS3: 8
больше 4 лет назад
github логотип
GHSA-52rg-mg9f-p465

Microsoft Internet Explorer 10 and 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Information Disclosure Vulnerability."

19%
Средний
больше 4 лет назад
github логотип
GHSA-52rg-hpwq-qp56

Allocation of Resources Without Limits or Throttling in Keycloak

CVSS3: 7.5
2%
Низкий
больше 4 лет назад

Уязвимостей на страницу