Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 727

Количество 375 727

github логотип

GHSA-4vw8-4q9m-v76p

7 месяцев назад

Missing Authorization vulnerability in Smartypants SP Project & Document Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SP Project & Document Manager: from n/a through 4.70.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4vw7-fjrf-474c

12 месяцев назад

Missing Authorization vulnerability in HivePress HivePress Claim Listings allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects HivePress Claim Listings: from n/a through 1.1.3.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4vw6-hh56-rxvj

около 4 лет назад

A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by the vhost-user slave. By sending such messages continuously, the vhost-user master exhausts available fd in the vhost-user slave process, leading to a denial of service.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4vw6-c9w3-qj7g

больше 4 лет назад

The (1) parse_str, (2) preg_match, (3) unpack, and (4) pack functions; the (5) ZEND_FETCH_RW, (6) ZEND_CONCAT, and (7) ZEND_ASSIGN_CONCAT opcodes; and the (8) ArrayObject::uasort method in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) or trigger memory corruption by causing a userspace interruption of an internal function or handler. NOTE: vectors 2 through 4 are related to the call time pass by reference feature.

EPSS: Низкий
github логотип

GHSA-4vw6-7m58-5hqv

больше 4 лет назад

u'During execution after Address Space Layout Randomization is turned on for QTEE, part of code is still mapped at known address including code segments' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in Bitra, Kamorta, Nicobar, QCS404, QCS610, Rennell, SA6155P, SA8155P, Saipan, SC7180, SC8180X, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130

EPSS: Низкий
github логотип

GHSA-4vw5-pwf9-rvmv

больше 4 лет назад

Race condition in the kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to bypass the Low Integrity protection mechanism and write to files by leveraging unspecified object-manager features, aka "Windows File System Security Feature Bypass."

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-4vw5-2p3h-m4gx

около 4 лет назад

Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function formSetClientState.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4vw4-hr9f-mq5c

больше 4 лет назад

An SQL Injection vulnerability exists in Sourcecodester Online Resort Management System 1.0 via the id parameterv in /orms/ node.

EPSS: Низкий
github логотип

GHSA-4vw3-f445-4gxj

больше 4 лет назад

An improper access control vulnerability in FortiManager versions 6.4.0 to 6.4.3 may allow an authenticated attacker with a restricted user profile to access the SD-WAN Orchestrator panel via directly visiting its URL.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4vw2-74q5-jc2q

больше 4 лет назад

A vulnerability in the FTP daemon on MikroTik routers through 6.44.3 could allow remote attackers to exhaust all available memory, causing the device to reboot because of uncontrolled resource management.

EPSS: Низкий
github логотип

GHSA-4vvx-w2jg-w5cm

больше 4 лет назад

CloudForms stores user passwords in recoverable format

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4vvx-v299-79g8

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: net: sched: fix ordering of qlen adjustment Changes to sch->q.qlen around qdisc_tree_reduce_backlog() need to happen _before_ a call to said function because otherwise it may fail to notify parent qdiscs when the child is about to become empty.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4vvw-xxg7-3qfj

почти 2 года назад

Memory corruption while unmapping the fastrpc map when two threads can free the same map in concurrent scenario.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-4vvw-cw7c-jq92

больше 4 лет назад

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to read and write specific files due to weak file permissions. IBM X-Force ID: 192469.

EPSS: Низкий
github логотип

GHSA-4vvv-prmp-rg2c

больше 4 лет назад

Multiple SQL injection vulnerabilities in TAGWORX.CMS 3.00.02 allow remote attackers to execute arbitrary SQL commands via the (1) cid parameter to contact.php and the (2) nid parameter to news.php.

EPSS: Низкий
github логотип

GHSA-4vvr-j4mv-4xcv

больше 4 лет назад

An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as Moderate because it is mitigated by current platform configurations. Product: Android. Versions: N/A. Android ID: A-32917432.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4vvr-gjmg-w366

больше 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codeboxr CBX Map for Google Map & OpenStreetMap allows Stored XSS.This issue affects CBX Map for Google Map & OpenStreetMap: from n/a through 1.1.11.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4vvr-9gf5-xjc4

больше 4 лет назад

Lack of length check of response buffer can lead to buffer over-flow while GP command response buffer handling in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8017, APQ8053, APQ8098, MDM9206, MDM9607, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8998, QM215, SDA660, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660

EPSS: Низкий
github логотип

GHSA-4vvr-5h54-mv77

9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: staging: r8712: Fix memory leak in _r8712_init_xmit_priv() In the above mentioned routine, memory is allocated in several places. If the first succeeds and a later one fails, the routine will leak memory. This patch fixes commit 2865d42c78a9 ("staging: r8712u: Add the new driver to the mainline kernel"). A potential memory leak in r8712_xmit_resource_alloc() is also addressed.

EPSS: Низкий
github логотип

GHSA-4vvq-7gfj-3jv6

почти 4 года назад

SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via DCTStream::readHuffSym(DCTHuffTable*) at /xpdf/Stream.cc.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4vw8-4q9m-v76p

Missing Authorization vulnerability in Smartypants SP Project & Document Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SP Project & Document Manager: from n/a through 4.70.

CVSS3: 6.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-4vw7-fjrf-474c

Missing Authorization vulnerability in HivePress HivePress Claim Listings allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects HivePress Claim Listings: from n/a through 1.1.3.

CVSS3: 4.3
0%
Низкий
12 месяцев назад
github логотип
GHSA-4vw6-hh56-rxvj

A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by the vhost-user slave. By sending such messages continuously, the vhost-user master exhausts available fd in the vhost-user slave process, leading to a denial of service.

CVSS3: 6.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-4vw6-c9w3-qj7g

The (1) parse_str, (2) preg_match, (3) unpack, and (4) pack functions; the (5) ZEND_FETCH_RW, (6) ZEND_CONCAT, and (7) ZEND_ASSIGN_CONCAT opcodes; and the (8) ArrayObject::uasort method in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) or trigger memory corruption by causing a userspace interruption of an internal function or handler. NOTE: vectors 2 through 4 are related to the call time pass by reference feature.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4vw6-7m58-5hqv

u'During execution after Address Space Layout Randomization is turned on for QTEE, part of code is still mapped at known address including code segments' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in Bitra, Kamorta, Nicobar, QCS404, QCS610, Rennell, SA6155P, SA8155P, Saipan, SC7180, SC8180X, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4vw5-pwf9-rvmv

Race condition in the kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to bypass the Low Integrity protection mechanism and write to files by leveraging unspecified object-manager features, aka "Windows File System Security Feature Bypass."

CVSS3: 4.7
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4vw5-2p3h-m4gx

Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function formSetClientState.

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-4vw4-hr9f-mq5c

An SQL Injection vulnerability exists in Sourcecodester Online Resort Management System 1.0 via the id parameterv in /orms/ node.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4vw3-f445-4gxj

An improper access control vulnerability in FortiManager versions 6.4.0 to 6.4.3 may allow an authenticated attacker with a restricted user profile to access the SD-WAN Orchestrator panel via directly visiting its URL.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4vw2-74q5-jc2q

A vulnerability in the FTP daemon on MikroTik routers through 6.44.3 could allow remote attackers to exhaust all available memory, causing the device to reboot because of uncontrolled resource management.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4vvx-w2jg-w5cm

CloudForms stores user passwords in recoverable format

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4vvx-v299-79g8

In the Linux kernel, the following vulnerability has been resolved: net: sched: fix ordering of qlen adjustment Changes to sch->q.qlen around qdisc_tree_reduce_backlog() need to happen _before_ a call to said function because otherwise it may fail to notify parent qdiscs when the child is about to become empty.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-4vvw-xxg7-3qfj

Memory corruption while unmapping the fastrpc map when two threads can free the same map in concurrent scenario.

CVSS3: 6.7
0%
Низкий
почти 2 года назад
github логотип
GHSA-4vvw-cw7c-jq92

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to read and write specific files due to weak file permissions. IBM X-Force ID: 192469.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4vvv-prmp-rg2c

Multiple SQL injection vulnerabilities in TAGWORX.CMS 3.00.02 allow remote attackers to execute arbitrary SQL commands via the (1) cid parameter to contact.php and the (2) nid parameter to news.php.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4vvr-j4mv-4xcv

An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as Moderate because it is mitigated by current platform configurations. Product: Android. Versions: N/A. Android ID: A-32917432.

CVSS3: 7.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4vvr-gjmg-w366

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codeboxr CBX Map for Google Map & OpenStreetMap allows Stored XSS.This issue affects CBX Map for Google Map & OpenStreetMap: from n/a through 1.1.11.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4vvr-9gf5-xjc4

Lack of length check of response buffer can lead to buffer over-flow while GP command response buffer handling in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8017, APQ8053, APQ8098, MDM9206, MDM9607, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8998, QM215, SDA660, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4vvr-5h54-mv77

In the Linux kernel, the following vulnerability has been resolved: staging: r8712: Fix memory leak in _r8712_init_xmit_priv() In the above mentioned routine, memory is allocated in several places. If the first succeeds and a later one fails, the routine will leak memory. This patch fixes commit 2865d42c78a9 ("staging: r8712u: Add the new driver to the mainline kernel"). A potential memory leak in r8712_xmit_resource_alloc() is also addressed.

0%
Низкий
9 месяцев назад
github логотип
GHSA-4vvq-7gfj-3jv6

SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via DCTStream::readHuffSym(DCTHuffTable*) at /xpdf/Stream.cc.

CVSS3: 5.5
0%
Низкий
почти 4 года назад

Уязвимостей на страницу