Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 453

Количество 375 453

github логотип

GHSA-4v4g-726h-xvfv

больше 5 лет назад

Padding Oracle Attack due to Observable Timing Discrepancy in jose-node-esm-runtime

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4v4f-rw7f-997r

больше 4 лет назад

Error messages generated by gdm with the VerboseAuth setting allows an attacker to identify valid users on a system.

EPSS: Низкий
github логотип

GHSA-4v4f-p5gf-h336

больше 4 лет назад

PyGIT.py in the Trac Git plugin (trac-git) before 0.0.20080710-3+lenny1 and before 0.0.20090320-1 on Debian GNU/Linux, when enabled in Trac, allows remote attackers to execute arbitrary commands via shell metacharacters in a crafted HTTP query that is used to generate a certain git command.

EPSS: Низкий
github логотип

GHSA-4v4f-2vvr-7hf5

больше 4 лет назад

The verify endpoint in YubiKey Validation Server before 2.40 does not check the length of SQL queries, which allows remote attackers to cause a denial of service, aka SQL injection. NOTE: this issue is potentially relevant to persons outside Yubico who operate a self-hosted OTP validation service; the issue does NOT affect YubiCloud.

EPSS: Низкий
github логотип

GHSA-4v4c-c278-r9q8

больше 4 лет назад

Unspecified vulnerability in the Hyperion Common Admin component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to User Interface.

EPSS: Низкий
github логотип

GHSA-4v4c-9v2r-r2qg

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the Host Client in VMware vSphere Hypervisor (aka ESXi) 5.5 and 6.0 allows remote authenticated users to inject arbitrary web script or HTML via a crafted VM.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4v4c-962p-vm5x

больше 4 лет назад

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:...

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4v4c-52hq-gphv

больше 4 лет назад

Buffer overflow in Symantec pcAnywhere 11.0.1, 11.5.1, and all other 32-bit versions allows remote attackers to cause a denial of service (application crash) via unknown attack vectors.

EPSS: Низкий
github логотип

GHSA-4v49-wc47-43g8

больше 4 лет назад

The __scm_destroy function in net/core/scm.c in the Linux kernel 2.6.27.4, 2.6.26, and earlier makes indirect recursive calls to itself through calls to the fput function, which allows local users to cause a denial of service (panic) via vectors related to sending an SCM_RIGHTS message through a UNIX domain socket and closing file descriptors.

EPSS: Низкий
github логотип

GHSA-4v49-vppm-4jh8

больше 4 лет назад

Heap-based buffer overflow in the syscall emulation functionality in Mac OS X before 10.3.9 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code via crafted parameters.

EPSS: Низкий
github логотип

GHSA-4v48-xr3m-vm7m

больше 4 лет назад

Multiple unspecified vulnerabilities in Oracle Application Server 9.0 up to 10.1.2.0 have unknown impact and attack vectors, as identified by Oracle Vuln# (1) AS02 in Containers for J2EE, (2) AS07 in Internet Directory, (3) AS09 in Report Server, and (4) AS11 in Web Cache.

EPSS: Низкий
github логотип

GHSA-4v48-c98q-4vpc

3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context There is a race between fastrpc_device_release() and the workqueue that processes DSP responses. When the user closes the file descriptor, fastrpc_device_release() frees the fastrpc_user structure. Concurrently, an in-flight DSP invocation can complete and fastrpc_rpmsg_callback() schedules context cleanup via schedule_work(&ctx->put_work). If the workqueue runs fastrpc_context_free() in parallel with or after fastrpc_device_release() has freed the user structure, it dereferences the freed fastrpc_user. Depending on the state of the context at the time of the race, any one of the following accesses can be hit: 1. fastrpc_buf_free() calls fastrpc_ipa_to_dma_addr(buf->fl->cctx, ...) to strip the SID bits from the stored IOVA before passing the physical address to dma_free_coherent(). 2. fastrpc_free_map() reads map->fl->cctx->vmperms[...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4v48-7f2r-g2xg

26 дней назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

EPSS: Низкий
github логотип

GHSA-4v48-4q5m-8vx4

почти 4 года назад

Prometheus vulnerable to basic authentication bypass

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-4v47-j6h7-7p73

больше 4 лет назад

Castle Rock Computing SNMPc before 2015-12-17 has SQL injection via the sc parameter.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4v47-7grv-98m6

больше 4 лет назад

The Horde_Ldap library before 2.0.6 for Horde allows remote attackers to bypass authentication by leveraging knowledge of the LDAP bind user DN.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-4v47-26g5-4434

больше 4 лет назад

LightCMS v1.3.5 contains a remote code execution vulnerability in /app/Http/Controllers/Admin/NEditorController.php during the downloading of external images.

EPSS: Низкий
github логотип

GHSA-4v46-qwhw-4224

больше 2 лет назад

Windows Kerberos Elevation of Privilege Vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4v46-g8g9-868m

больше 4 лет назад

Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) in the GitLab SAML integration had a validation issue that permitted an attacker to takeover another user's account.

EPSS: Низкий
github логотип

GHSA-4v46-84vc-5x84

почти 4 года назад

A vulnerability has been found in SourceCodester Simple Online Public Access Catalog 1.0 and classified as critical. This vulnerability affects unknown code of the file /opac/Actions.php?a=login of the component Admin Login. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-210784.

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4v4g-726h-xvfv

Padding Oracle Attack due to Observable Timing Discrepancy in jose-node-esm-runtime

CVSS3: 5.9
1%
Низкий
больше 5 лет назад
github логотип
GHSA-4v4f-rw7f-997r

Error messages generated by gdm with the VerboseAuth setting allows an attacker to identify valid users on a system.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4v4f-p5gf-h336

PyGIT.py in the Trac Git plugin (trac-git) before 0.0.20080710-3+lenny1 and before 0.0.20090320-1 on Debian GNU/Linux, when enabled in Trac, allows remote attackers to execute arbitrary commands via shell metacharacters in a crafted HTTP query that is used to generate a certain git command.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4v4f-2vvr-7hf5

The verify endpoint in YubiKey Validation Server before 2.40 does not check the length of SQL queries, which allows remote attackers to cause a denial of service, aka SQL injection. NOTE: this issue is potentially relevant to persons outside Yubico who operate a self-hosted OTP validation service; the issue does NOT affect YubiCloud.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4v4c-c278-r9q8

Unspecified vulnerability in the Hyperion Common Admin component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to User Interface.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v4c-9v2r-r2qg

Cross-site scripting (XSS) vulnerability in the Host Client in VMware vSphere Hypervisor (aka ESXi) 5.5 and 6.0 allows remote authenticated users to inject arbitrary web script or HTML via a crafted VM.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v4c-962p-vm5x

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:...

CVSS3: 4.3
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4v4c-52hq-gphv

Buffer overflow in Symantec pcAnywhere 11.0.1, 11.5.1, and all other 32-bit versions allows remote attackers to cause a denial of service (application crash) via unknown attack vectors.

9%
Низкий
больше 4 лет назад
github логотип
GHSA-4v49-wc47-43g8

The __scm_destroy function in net/core/scm.c in the Linux kernel 2.6.27.4, 2.6.26, and earlier makes indirect recursive calls to itself through calls to the fput function, which allows local users to cause a denial of service (panic) via vectors related to sending an SCM_RIGHTS message through a UNIX domain socket and closing file descriptors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v49-vppm-4jh8

Heap-based buffer overflow in the syscall emulation functionality in Mac OS X before 10.3.9 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code via crafted parameters.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4v48-xr3m-vm7m

Multiple unspecified vulnerabilities in Oracle Application Server 9.0 up to 10.1.2.0 have unknown impact and attack vectors, as identified by Oracle Vuln# (1) AS02 in Containers for J2EE, (2) AS07 in Internet Directory, (3) AS09 in Report Server, and (4) AS11 in Web Cache.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-4v48-c98q-4vpc

In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context There is a race between fastrpc_device_release() and the workqueue that processes DSP responses. When the user closes the file descriptor, fastrpc_device_release() frees the fastrpc_user structure. Concurrently, an in-flight DSP invocation can complete and fastrpc_rpmsg_callback() schedules context cleanup via schedule_work(&ctx->put_work). If the workqueue runs fastrpc_context_free() in parallel with or after fastrpc_device_release() has freed the user structure, it dereferences the freed fastrpc_user. Depending on the state of the context at the time of the race, any one of the following accesses can be hit: 1. fastrpc_buf_free() calls fastrpc_ipa_to_dma_addr(buf->fl->cctx, ...) to strip the SID bits from the stored IOVA before passing the physical address to dma_free_coherent(). 2. fastrpc_free_map() reads map->fl->cctx->vmperms[...

CVSS3: 7.8
0%
Низкий
3 месяца назад
github логотип
GHSA-4v48-7f2r-g2xg

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

26 дней назад
github логотип
GHSA-4v48-4q5m-8vx4

Prometheus vulnerable to basic authentication bypass

CVSS3: 7.2
почти 4 года назад
github логотип
GHSA-4v47-j6h7-7p73

Castle Rock Computing SNMPc before 2015-12-17 has SQL injection via the sc parameter.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v47-7grv-98m6

The Horde_Ldap library before 2.0.6 for Horde allows remote attackers to bypass authentication by leveraging knowledge of the LDAP bind user DN.

CVSS3: 8.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4v47-26g5-4434

LightCMS v1.3.5 contains a remote code execution vulnerability in /app/Http/Controllers/Admin/NEditorController.php during the downloading of external images.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4v46-qwhw-4224

Windows Kerberos Elevation of Privilege Vulnerability

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4v46-g8g9-868m

Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) in the GitLab SAML integration had a validation issue that permitted an attacker to takeover another user's account.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4v46-84vc-5x84

A vulnerability has been found in SourceCodester Simple Online Public Access Catalog 1.0 and classified as critical. This vulnerability affects unknown code of the file /opac/Actions.php?a=login of the component Admin Login. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-210784.

CVSS3: 7.2
1%
Низкий
почти 4 года назад

Уязвимостей на страницу