Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 323 419

Количество 323 419

github логотип

GHSA-25g8-2mcf-fcx9

25 дней назад

changedetection.io has Zip Slip vulnerability in the backup restore functionality

EPSS: Низкий
github логотип

GHSA-25g7-4hx6-524h

больше 4 лет назад

Certain NETGEAR devices are affected by authentication bypass. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, RBR852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-25g4-wcf4-xhmc

почти 4 года назад

IBM StoredIQ 7.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 158699.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-25g4-p347-x748

почти 4 года назад

Improper authorization due to caching in Jenkins Role-based Authorization Strategy Plugin

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-25g4-4hrr-66h4

почти 4 года назад

SQL injection vulnerability in search_run.asp in Keyvan1 (aka Keyvan Janghorbani) EShoppingPro 1.0 allows remote attackers to execute arbitrary SQL commands via the order parameter.

EPSS: Низкий
github логотип

GHSA-25g3-v2pj-968v

почти 2 года назад

An issue in dc2niix before v.1.0.20240202 allows a local attacker to execute arbitrary code via the generated file name is not properly escaped and injected into a system call when certain types of compression are used.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-25g3-q597-79m8

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: binder: fix use-after-free in shinker's callback The mmap read lock is used during the shrinker's callback, which means that using alloc->vma pointer isn't safe as it can race with munmap(). As of commit dd2283f2605e ("mm: mmap: zap pages with read mmap_sem in munmap") the mmap lock is downgraded after the vma has been isolated. I was able to reproduce this issue by manually adding some delays and triggering page reclaiming through the shrinker's debug sysfs. The following KASAN report confirms the UAF: ================================================================== BUG: KASAN: slab-use-after-free in zap_page_range_single+0x470/0x4b8 Read of size 8 at addr ffff356ed50e50f0 by task bash/478 CPU: 1 PID: 478 Comm: bash Not tainted 6.6.0-rc5-00055-g1c8b86a3799f-dirty #70 Hardware name: linux,dummy-virt (DT) Call trace: zap_page_range_single+0x470/0x4b8 binder_alloc_free_page+0x608/0xadc __li...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-25g3-p7c7-27pp

почти 4 года назад

A vulnerability in the implementation of the Intermediate System–to–Intermediate System (IS–IS) routing protocol functionality in Cisco IOS XR Software could allow an unauthenticated attacker who is in the same IS–IS area to cause a denial of service (DoS) condition. The vulnerability is due to incorrect processing of crafted IS–IS link-state protocol data units (PDUs). An attacker could exploit this vulnerability by sending a crafted link-state PDU to an affected system to be processed. A successful exploit could allow the attacker to cause all routers within the IS–IS area to unexpectedly restart the IS–IS process, resulting in a DoS condition. This vulnerability affects Cisco devices if they are running a vulnerable release of Cisco IOS XR Software earlier than Release 6.6.3 and are configured with the IS–IS routing protocol. Cisco has confirmed that this vulnerability affects both Cisco IOS XR 32-bit Software and Cisco IOS XR 64-bit So...

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-25g2-qhvf-25wf

почти 4 года назад

In libxaac there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-117496180

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-25g2-j4cw-5mpg

больше 2 лет назад

Microsoft Office Security Feature Bypass Vulnerability

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-25g2-7m3f-4wgf

почти 4 года назад

The Track My Mobile feature in the SamsungDive subsystem for Android on Samsung Galaxy devices does not properly implement Location APIs, which allows physically proximate attackers to provide arbitrary location data via a "commonly available simple GPS location spoofer."

EPSS: Низкий
github логотип

GHSA-25fx-qmph-2r67

около 4 лет назад

Wasm3 0.5.0 has an out-of-bounds write in CompileBlock (called from CompileElseBlock and Compile_If).

EPSS: Низкий
github логотип

GHSA-25fx-mxc2-76g7

больше 4 лет назад

Sylius PayPal Plugin allows unauthorized access to Credit card form, exposing payer name and not requiring 3DS

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-25fx-h7f5-3vfr

около 3 лет назад

Reflected Cross-Site Scripting (XSS) vulnerability in Michael Winkler teachPress plugin <= 8.1.8 versions.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-25fx-gxgp-m24r

почти 4 года назад

In WLAN driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06535950; Issue ID: ALPS06535950.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-25fx-9jj6-385f

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpWax Product Carousel Slider & Grid Ultimate for WooCommerce allows Stored XSS. This issue affects Product Carousel Slider & Grid Ultimate for WooCommerce: from n/a through 1.10.0.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-25fx-3c2q-cq46

почти 3 года назад

pimcore/customer-management-framework-bundle has SQL Injection vulnerability in Segment Assignment query

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-25fw-rhx6-pmwr

почти 4 года назад

IBM WebSphere MQ V7.1, 7.5, IBM MQ V8, IBM MQ V9.0LTS, IBM MQ V9.1 LTS, and IBM MQ V9.1 CD are vulnerable to a denial of service attack caused by specially crafted messages. IBM X-Force ID: 160013.

EPSS: Низкий
github логотип

GHSA-25fw-mv96-59fm

почти 2 года назад

Kofax Power PDF PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22928.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-25fv-pc88-fq56

8 месяцев назад

A vulnerability, which was classified as problematic, has been found in bsc Peru Cocktails App 1.0.0 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component bsc.devy.peru_cocktails. The manipulation leads to improper export of android application components. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-25g8-2mcf-fcx9

changedetection.io has Zip Slip vulnerability in the backup restore functionality

0%
Низкий
25 дней назад
github логотип
GHSA-25g7-4hx6-524h

Certain NETGEAR devices are affected by authentication bypass. This affects CBR40 before 2.5.0.24, CBR750 before 4.6.3.6, RBR852 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.

CVSS3: 9.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-25g4-wcf4-xhmc

IBM StoredIQ 7.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 158699.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-25g4-p347-x748

Improper authorization due to caching in Jenkins Role-based Authorization Strategy Plugin

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-25g4-4hrr-66h4

SQL injection vulnerability in search_run.asp in Keyvan1 (aka Keyvan Janghorbani) EShoppingPro 1.0 allows remote attackers to execute arbitrary SQL commands via the order parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-25g3-v2pj-968v

An issue in dc2niix before v.1.0.20240202 allows a local attacker to execute arbitrary code via the generated file name is not properly escaped and injected into a system call when certain types of compression are used.

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-25g3-q597-79m8

In the Linux kernel, the following vulnerability has been resolved: binder: fix use-after-free in shinker's callback The mmap read lock is used during the shrinker's callback, which means that using alloc->vma pointer isn't safe as it can race with munmap(). As of commit dd2283f2605e ("mm: mmap: zap pages with read mmap_sem in munmap") the mmap lock is downgraded after the vma has been isolated. I was able to reproduce this issue by manually adding some delays and triggering page reclaiming through the shrinker's debug sysfs. The following KASAN report confirms the UAF: ================================================================== BUG: KASAN: slab-use-after-free in zap_page_range_single+0x470/0x4b8 Read of size 8 at addr ffff356ed50e50f0 by task bash/478 CPU: 1 PID: 478 Comm: bash Not tainted 6.6.0-rc5-00055-g1c8b86a3799f-dirty #70 Hardware name: linux,dummy-virt (DT) Call trace: zap_page_range_single+0x470/0x4b8 binder_alloc_free_page+0x608/0xadc __li...

CVSS3: 7.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-25g3-p7c7-27pp

A vulnerability in the implementation of the Intermediate System&ndash;to&ndash;Intermediate System (IS&ndash;IS) routing protocol functionality in Cisco IOS XR Software could allow an unauthenticated attacker who is in the same IS&ndash;IS area to cause a denial of service (DoS) condition. The vulnerability is due to incorrect processing of crafted IS&ndash;IS link-state protocol data units (PDUs). An attacker could exploit this vulnerability by sending a crafted link-state PDU to an affected system to be processed. A successful exploit could allow the attacker to cause all routers within the IS&ndash;IS area to unexpectedly restart the IS&ndash;IS process, resulting in a DoS condition. This vulnerability affects Cisco devices if they are running a vulnerable release of Cisco IOS XR Software earlier than Release 6.6.3 and are configured with the IS–IS routing protocol. Cisco has confirmed that this vulnerability affects both Cisco IOS XR 32-bit Software and Cisco IOS XR 64-bit So...

CVSS3: 7.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-25g2-qhvf-25wf

In libxaac there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-117496180

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-25g2-j4cw-5mpg

Microsoft Office Security Feature Bypass Vulnerability

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-25g2-7m3f-4wgf

The Track My Mobile feature in the SamsungDive subsystem for Android on Samsung Galaxy devices does not properly implement Location APIs, which allows physically proximate attackers to provide arbitrary location data via a "commonly available simple GPS location spoofer."

0%
Низкий
почти 4 года назад
github логотип
GHSA-25fx-qmph-2r67

Wasm3 0.5.0 has an out-of-bounds write in CompileBlock (called from CompileElseBlock and Compile_If).

0%
Низкий
около 4 лет назад
github логотип
GHSA-25fx-mxc2-76g7

Sylius PayPal Plugin allows unauthorized access to Credit card form, exposing payer name and not requiring 3DS

CVSS3: 7.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-25fx-h7f5-3vfr

Reflected Cross-Site Scripting (XSS) vulnerability in Michael Winkler teachPress plugin <= 8.1.8 versions.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-25fx-gxgp-m24r

In WLAN driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06535950; Issue ID: ALPS06535950.

CVSS3: 4.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-25fx-9jj6-385f

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpWax Product Carousel Slider & Grid Ultimate for WooCommerce allows Stored XSS. This issue affects Product Carousel Slider & Grid Ultimate for WooCommerce: from n/a through 1.10.0.

CVSS3: 5.9
0%
Низкий
около 1 года назад
github логотип
GHSA-25fx-3c2q-cq46

pimcore/customer-management-framework-bundle has SQL Injection vulnerability in Segment Assignment query

CVSS3: 7.2
7%
Низкий
почти 3 года назад
github логотип
GHSA-25fw-rhx6-pmwr

IBM WebSphere MQ V7.1, 7.5, IBM MQ V8, IBM MQ V9.0LTS, IBM MQ V9.1 LTS, and IBM MQ V9.1 CD are vulnerable to a denial of service attack caused by specially crafted messages. IBM X-Force ID: 160013.

0%
Низкий
почти 4 года назад
github логотип
GHSA-25fw-mv96-59fm

Kofax Power PDF PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-22928.

CVSS3: 7.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-25fv-pc88-fq56

A vulnerability, which was classified as problematic, has been found in bsc Peru Cocktails App 1.0.0 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component bsc.devy.peru_cocktails. The manipulation leads to improper export of android application components. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
0%
Низкий
8 месяцев назад

Уязвимостей на страницу