Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 323 083

Количество 323 083

github логотип

GHSA-244w-g82v-mjgw

больше 2 лет назад

U-Boot vulnerability resulting in persistent Code Execution 

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-244w-39h6-2f5r

больше 2 лет назад

Microsoft Message Queuing Denial of Service Vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-244v-xghf-wq26

почти 4 года назад

MuPDF through 1.18.1 has an out-of-bounds write because the cached color converter does not properly consider the maximum key size of a hash table. This can, for example, be seen with crafted "mutool draw" input.

EPSS: Низкий
github логотип

GHSA-244v-h48v-v63v

почти 4 года назад

In ihevcd_parse_slice_header of ihevcd_parse_slice_header.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-143826590

EPSS: Низкий
github логотип

GHSA-244r-jx38-mgcg

больше 4 лет назад

Adobe After Effects version 18.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must open a specially crafted file to exploit this vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-244r-fcj3-ghjq

почти 5 лет назад

Exposure of class information in RESTEasy

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-244r-55j9-vqgp

больше 3 лет назад

In Progress WS_FTP Server prior to version 8.7.3, multiple reflected cross-site scripting (XSS) vulnerabilities exist in the administrative web interface. It is possible for a remote attacker to inject arbitrary JavaScript into a WS_FTP administrator's web session. This would allow the attacker to execute code within the context of the victim's browser.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-244r-4cqf-v63r

около 1 года назад

Improper input validation in UEFI firmware CseVariableStorageSmm for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-244q-c67c-j2h7

почти 4 года назад

DLL preloading vulnerability in Autodesk Design Review versions 2011, 2012, 2013, and 2018. An attacker may trick a user into opening a malicious DWF file that may leverage a DLL preloading vulnerability, which may result in code execution.

EPSS: Низкий
github логотип

GHSA-244q-6gfm-pphc

почти 4 года назад

Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect availability, related to Kernel/KSSL.

EPSS: Низкий
github логотип

GHSA-244m-v8jg-hv24

8 месяцев назад

A low privileged local attacker can abuse the affected service by using a hardcoded cryptographic key.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-244m-98g9-4pg8

11 месяцев назад

The WOOEXIM WordPress plugin through 5.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make an unauthenticated user vulnerable to reflected XSS via a CSRF attack.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-244j-xp9p-xr45

около 4 лет назад

IBM Security Guardium Insights 3.0 could allow an authenticated user to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 205256.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-244h-xwm8-582w

почти 4 года назад

Directory traversal vulnerability in TalkBack 2.3.6 and 2.3.6.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter to comments.php, a different vector than CVE-2008-3371.

EPSS: Низкий
github логотип

GHSA-244h-ff82-7fpw

3 месяца назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-244h-42j2-qqhw

почти 4 года назад

In ImageMagick 7.0.6-6, a memory leak vulnerability was found in the function formatIPTC in coders/meta.c, which allows attackers to cause a denial of service (WriteMETAImage memory consumption) via a crafted file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-244g-mc48-hxgx

около 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Start Booking Scheduling Plugin – Online Booking for WordPress allows Stored XSS.This issue affects Scheduling Plugin – Online Booking for WordPress: from n/a through 3.5.10.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-244g-8368-6wr9

почти 4 года назад

Apache Wicket allows attackers to check for third-party libraries

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-244g-3mq6-cqhx

почти 4 года назад

Unspecified vulnerability in the Oracle VM VirtualBox component before 5.0.28 and 5.1.x before 5.1.8 in Oracle Virtualization allows local users to affect confidentiality, integrity, and availability via vectors related to Core, a different vulnerability than CVE-2016-5501.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-244f-jjf4-gvqg

почти 4 года назад

ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows remote attackers to execute arbitrary code via a crafted OpenType font, aka "OpenType Font Parsing Vulnerability," a different vulnerability than CVE-2015-2458 and CVE-2015-2461.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-244w-g82v-mjgw

U-Boot vulnerability resulting in persistent Code Execution 

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-244w-39h6-2f5r

Microsoft Message Queuing Denial of Service Vulnerability

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-244v-xghf-wq26

MuPDF through 1.18.1 has an out-of-bounds write because the cached color converter does not properly consider the maximum key size of a hash table. This can, for example, be seen with crafted "mutool draw" input.

0%
Низкий
почти 4 года назад
github логотип
GHSA-244v-h48v-v63v

In ihevcd_parse_slice_header of ihevcd_parse_slice_header.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-143826590

0%
Низкий
почти 4 года назад
github логотип
GHSA-244r-jx38-mgcg

Adobe After Effects version 18.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must open a specially crafted file to exploit this vulnerability.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-244r-fcj3-ghjq

Exposure of class information in RESTEasy

CVSS3: 5.3
0%
Низкий
почти 5 лет назад
github логотип
GHSA-244r-55j9-vqgp

In Progress WS_FTP Server prior to version 8.7.3, multiple reflected cross-site scripting (XSS) vulnerabilities exist in the administrative web interface. It is possible for a remote attacker to inject arbitrary JavaScript into a WS_FTP administrator's web session. This would allow the attacker to execute code within the context of the victim's browser.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-244r-4cqf-v63r

Improper input validation in UEFI firmware CseVariableStorageSmm for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-244q-c67c-j2h7

DLL preloading vulnerability in Autodesk Design Review versions 2011, 2012, 2013, and 2018. An attacker may trick a user into opening a malicious DWF file that may leverage a DLL preloading vulnerability, which may result in code execution.

0%
Низкий
почти 4 года назад
github логотип
GHSA-244q-6gfm-pphc

Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect availability, related to Kernel/KSSL.

1%
Низкий
почти 4 года назад
github логотип
GHSA-244m-v8jg-hv24

A low privileged local attacker can abuse the affected service by using a hardcoded cryptographic key.

CVSS3: 5.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-244m-98g9-4pg8

The WOOEXIM WordPress plugin through 5.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make an unauthenticated user vulnerable to reflected XSS via a CSRF attack.

CVSS3: 6.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-244j-xp9p-xr45

IBM Security Guardium Insights 3.0 could allow an authenticated user to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 205256.

CVSS3: 2.7
0%
Низкий
около 4 лет назад
github логотип
GHSA-244h-xwm8-582w

Directory traversal vulnerability in TalkBack 2.3.6 and 2.3.6.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter to comments.php, a different vector than CVE-2008-3371.

7%
Низкий
почти 4 года назад
github логотип
GHSA-244h-ff82-7fpw

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

3 месяца назад
github логотип
GHSA-244h-42j2-qqhw

In ImageMagick 7.0.6-6, a memory leak vulnerability was found in the function formatIPTC in coders/meta.c, which allows attackers to cause a denial of service (WriteMETAImage memory consumption) via a crafted file.

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-244g-mc48-hxgx

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Start Booking Scheduling Plugin – Online Booking for WordPress allows Stored XSS.This issue affects Scheduling Plugin – Online Booking for WordPress: from n/a through 3.5.10.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-244g-8368-6wr9

Apache Wicket allows attackers to check for third-party libraries

CVSS3: 5.3
2%
Низкий
почти 4 года назад
github логотип
GHSA-244g-3mq6-cqhx

Unspecified vulnerability in the Oracle VM VirtualBox component before 5.0.28 and 5.1.x before 5.1.8 in Oracle Virtualization allows local users to affect confidentiality, integrity, and availability via vectors related to Core, a different vulnerability than CVE-2016-5501.

CVSS3: 6.7
0%
Низкий
почти 4 года назад
github логотип
GHSA-244f-jjf4-gvqg

ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows remote attackers to execute arbitrary code via a crafted OpenType font, aka "OpenType Font Parsing Vulnerability," a different vulnerability than CVE-2015-2458 and CVE-2015-2461.

55%
Средний
почти 4 года назад

Уязвимостей на страницу