Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 323 339

Количество 323 339

github логотип

GHSA-257h-jgf3-638q

почти 4 года назад

Stack-based buffer overflow in the read_article function in getarticle.c in newsx 1.6 allows remote attackers to execute arbitrary code via a news article containing a large number of lines starting with a period.

EPSS: Средний
github логотип

GHSA-257h-h5gh-r9cx

почти 4 года назад

An issue was discovered in Enigmail before 1.9.9. Improper Random Secret Generation occurs because Math.Random() is used by pretty Easy privacy (pEp), aka TBE-01-001.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-257h-96j8-9qr2

5 месяцев назад

Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Folder Message Count and Size report.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-257h-84mq-c7cf

около 1 года назад

A vulnerability was found in phjounin TFTPD64 4.64. It has been declared as problematic. This vulnerability affects unknown code of the component DNS Handler. The manipulation leads to denial of service. The attack needs to be done within the local network. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-257g-8w4g-3cc3

почти 4 года назад

A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption that expressing a quoted single quote will require 3 characters, while it actually requires 4 characters which allows an attacker to corrupt memory by one byte for each quote in the input. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-257f-2fcf-f6v3

почти 4 года назад

A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/edit_group.php URI.

EPSS: Низкий
github логотип

GHSA-257c-mj87-mcqj

почти 4 года назад

In ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted database, which allows him to gain access to the application. Next, he can change the directory that the application uploads files to, which allows him to achieve remote code execution. This occurs because install/include/header.php does not restrict certain changes (to db_host, db_login, db_password, and content_dir) within install/include/step5.php.

EPSS: Средний
github логотип

GHSA-257c-fqr8-cm92

почти 4 года назад

Incorrect bound check can lead to potential buffer overwrite in WLAN function in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2579-mjx2-r625

почти 4 года назад

The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) before 6.2.0, does not properly enforce the method level restrictions for JAX-WS Service endpoints, which allows remote authenticated users to access otherwise restricted JAX-WS handlers by leveraging permissions to the EJB class.

EPSS: Низкий
github логотип

GHSA-2579-38w7-jc76

5 месяцев назад

IBM Cognos Analytics Certified Containers 12.1.0 could disclose package parameter information due to the presence of hidden pages.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2578-mq3j-6qq4

почти 4 года назад

An elevation of privilege vulnerability in Binder could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as Moderate because it first requires compromising a privileged process and is mitigated by current platform configurations. Product: Android. Versions: Kernel-3.18. Android ID: A-32394425.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-2577-j9hh-f6g7

5 месяцев назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and 9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-2576-m45c-p3gg

почти 4 года назад

The administration interface in the Planet VC-200M VDSL2 router allows remote attackers to cause a denial of service (administration interface outage) via an HTTP request without a Host header.

EPSS: Низкий
github логотип

GHSA-2575-pghm-6qqx

около 4 лет назад

Kubernetes Unsafe Cacheing

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-2575-mf38-hvqq

почти 4 года назад

Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Approval Framework). Supported versions that are affected are 9.1 and 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CC Common Application Objects. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise CC Common Application Objects accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2575-c77r-rr97

почти 4 года назад

gzip before 1.3 in Solaris 8, when called with the -f or -force flags, will change the permissions of files that are hard linked to the target files, which allows local users to view or modify these files.

EPSS: Низкий
github логотип

GHSA-2575-3228-j966

5 месяцев назад

Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2574-fqfw-fxcc

почти 4 года назад

Cross-site scripting (XSS) vulnerability in the DocumentLoader::maybeCreateArchive function in core/loader/DocumentLoader.cpp in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to inject arbitrary web script or HTML via crafted MHTML content, aka "Universal XSS (UXSS)."

EPSS: Низкий
github логотип

GHSA-2574-cw53-m29g

почти 3 года назад

PublicCMS <=V4.0.202302 is vulnerable to Insecure Permissions.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2573-wq7r-2x2r

почти 4 года назад

Heap buffer overflow in TabStrip in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-257h-jgf3-638q

Stack-based buffer overflow in the read_article function in getarticle.c in newsx 1.6 allows remote attackers to execute arbitrary code via a news article containing a large number of lines starting with a period.

25%
Средний
почти 4 года назад
github логотип
GHSA-257h-h5gh-r9cx

An issue was discovered in Enigmail before 1.9.9. Improper Random Secret Generation occurs because Math.Random() is used by pretty Easy privacy (pEp), aka TBE-01-001.

CVSS3: 7.3
1%
Низкий
почти 4 года назад
github логотип
GHSA-257h-96j8-9qr2

Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Folder Message Count and Size report.

CVSS3: 7.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-257h-84mq-c7cf

A vulnerability was found in phjounin TFTPD64 4.64. It has been declared as problematic. This vulnerability affects unknown code of the component DNS Handler. The manipulation leads to denial of service. The attack needs to be done within the local network. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.

CVSS3: 3.1
0%
Низкий
около 1 года назад
github логотип
GHSA-257g-8w4g-3cc3

A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption that expressing a quoted single quote will require 3 characters, while it actually requires 4 characters which allows an attacker to corrupt memory by one byte for each quote in the input. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 8.2
0%
Низкий
почти 4 года назад
github логотип
GHSA-257f-2fcf-f6v3

A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/edit_group.php URI.

0%
Низкий
почти 4 года назад
github логотип
GHSA-257c-mj87-mcqj

In ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted database, which allows him to gain access to the application. Next, he can change the directory that the application uploads files to, which allows him to achieve remote code execution. This occurs because install/include/header.php does not restrict certain changes (to db_host, db_login, db_password, and content_dir) within install/include/step5.php.

21%
Средний
почти 4 года назад
github логотип
GHSA-257c-fqr8-cm92

Incorrect bound check can lead to potential buffer overwrite in WLAN function in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-2579-mjx2-r625

The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) before 6.2.0, does not properly enforce the method level restrictions for JAX-WS Service endpoints, which allows remote authenticated users to access otherwise restricted JAX-WS handlers by leveraging permissions to the EJB class.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2579-38w7-jc76

IBM Cognos Analytics Certified Containers 12.1.0 could disclose package parameter information due to the presence of hidden pages.

CVSS3: 5.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-2578-mq3j-6qq4

An elevation of privilege vulnerability in Binder could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as Moderate because it first requires compromising a privileged process and is mitigated by current platform configurations. Product: Android. Versions: Kernel-3.18. Android ID: A-32394425.

CVSS3: 7
0%
Низкий
почти 4 года назад
github логотип
GHSA-2577-j9hh-f6g7

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and 9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
0%
Низкий
5 месяцев назад
github логотип
GHSA-2576-m45c-p3gg

The administration interface in the Planet VC-200M VDSL2 router allows remote attackers to cause a denial of service (administration interface outage) via an HTTP request without a Host header.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2575-pghm-6qqx

Kubernetes Unsafe Cacheing

CVSS3: 5
0%
Низкий
около 4 лет назад
github логотип
GHSA-2575-mf38-hvqq

Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Approval Framework). Supported versions that are affected are 9.1 and 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CC Common Application Objects. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise CC Common Application Objects accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVSS3: 5.3
1%
Низкий
почти 4 года назад
github логотип
GHSA-2575-c77r-rr97

gzip before 1.3 in Solaris 8, when called with the -f or -force flags, will change the permissions of files that are hard linked to the target files, which allows local users to view or modify these files.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2575-3228-j966

Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally.

CVSS3: 7.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-2574-fqfw-fxcc

Cross-site scripting (XSS) vulnerability in the DocumentLoader::maybeCreateArchive function in core/loader/DocumentLoader.cpp in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to inject arbitrary web script or HTML via crafted MHTML content, aka "Universal XSS (UXSS)."

0%
Низкий
почти 4 года назад
github логотип
GHSA-2574-cw53-m29g

PublicCMS <=V4.0.202302 is vulnerable to Insecure Permissions.

CVSS3: 9.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-2573-wq7r-2x2r

Heap buffer overflow in TabStrip in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
1%
Низкий
почти 4 года назад

Уязвимостей на страницу