Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 322 820

Количество 322 820

github логотип

GHSA-22wf-j8j6-f67g

почти 4 года назад

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D6100 before 1.0.0.58, D7800 before 1.0.1.40, R7500v2 before 1.0.3.34, R7800 before 1.0.2.52, R8900 before 1.0.4.2, R9000 before 1.0.3.16, RAX120 before 1.0.0.74, RBK20 before 2.3.0.22, RBR20 before 2.3.0.22, RBS20 before 2.3.0.22, RBK50 before 2.3.0.22, RBR50 before 2.3.0.22, RBS50 before 2.3.0.22, RBK40 before 2.3.0.22, RBS40 before 2.3.0.22, SRK60 before 2.2.0.64, SRR60 before 2.2.0.64, SRS60 before 2.2.0.64, WNDR3700v4 before 1.0.2.102, WNDR4300 before 1.0.2.104, WNDR4300v2 before 1.0.0.56, WNDR4500v3 before 1.0.0.56, and WNR2000v5 before 1.0.0.66.

EPSS: Низкий
github логотип

GHSA-22wf-h889-r7q7

12 месяцев назад

Improper permission control vulnerability in the OXARI ServiceDesk application could allow an attacker using a guest access or an unprivileged account to gain additional administrative permissions in the application.This issue affects OXARI ServiceDesk in versions before 2.0.324.0.

EPSS: Низкий
github логотип

GHSA-22wf-fg96-jprv

больше 2 лет назад

In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_417338 function obtains fields from the front-end, connects them through the snprintf function, and passes them to the CsteSystem function, resulting in a command execution vulnerability.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-22wc-c9wj-6q2v

почти 5 лет назад

VVE-2021-0001: Memory corruption using function calls within arrays

EPSS: Низкий
github логотип

GHSA-22wc-8hcq-634h

4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: ext4: fix deadlock due to mbcache entry corruption When manipulating xattr blocks, we can deadlock infinitely looping inside ext4_xattr_block_set() where we constantly keep finding xattr block for reuse in mbcache but we are unable to reuse it because its reference count is too big. This happens because cache entry for the xattr block is marked as reusable (e_reusable set) although its reference count is too big. When this inconsistency happens, this inconsistent state is kept indefinitely and so ext4_xattr_block_set() keeps retrying indefinitely. The inconsistent state is caused by non-atomic update of e_reusable bit. e_reusable is part of a bitfield and e_reusable update can race with update of e_referenced bit in the same bitfield resulting in loss of one of the updates. Fix the problem by using atomic bitops instead. This bug has been around for many years, but it became *much* easier to hit after commit 65f...

EPSS: Низкий
github логотип

GHSA-22wc-7wmm-v4cc

почти 4 года назад

Liferay Portal and Liferay DXP does not properly check user permission

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-22w9-x8p2-69rp

почти 4 года назад

SQL injection vulnerability in admin.php in CloudNine Interactive Links Manager 2006-06-12, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the nick parameter.

EPSS: Низкий
github логотип

GHSA-22w9-j288-8p9w

почти 4 года назад

OpenStack Nova Router metadata queries are not restricted by tenant

EPSS: Низкий
github логотип

GHSA-22w9-2h5w-c9pv

больше 3 лет назад

The Duplicate Page and Post Plugin WordPress plugin through 2.7 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-22w8-qmw3-m9gr

почти 4 года назад

The if_clone_list function in NetBSD-current before 20061027, NetBSD 3.0 and 3.0.1 before 20061027, and NetBSD 2.x before 20061119 allows local users to read potentially sensitive, uninitialized stack memory via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-22w8-2mrr-vh7h

17 дней назад

A security vulnerability has been detected in OWASP DefectDojo up to 2.55.4. This vulnerability affects the function input_zip.read of the file parser.py of the component SonarQubeParser/MSDefenderParser. The manipulation leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 2.56.0 is able to resolve this issue. The identifier of the patch is e8f1e5131535b8fd80a7b1b3085d676295fdcd41. Upgrading the affected component is recommended.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-22w8-27w2-f55c

почти 4 года назад

Heap-based buffer overflow in the EscapeParenthesis function in GraphicsMagick before 1.3.25 allows remote attackers to have unspecified impact via unknown vectors.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-22w7-m5f8-87vh

почти 3 года назад

Liferay Portal and Liferay DXP Vulnerable to Open Redirect via the Layout Module

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-22w7-gmrw-m5qp

почти 4 года назад

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. A malicious application may be able to elevate privileges.

EPSS: Низкий
github логотип

GHSA-22w7-7694-298f

почти 4 года назад

A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to disclose sensitive informatoin on affected installations.

CVSS3: 7.5
EPSS: Высокий
github логотип

GHSA-22w6-gp78-84rc

почти 4 года назад

The Red Hat mkdumprd script for kexec-tools, as distributed in the kexec-tools 1.x before 1.102pre-154 and 2.x before 2.0.0-209 packages in Red Hat Enterprise Linux, includes all of root's SSH private keys within a vmcore file, which allows context-dependent attackers to obtain sensitive information by inspecting the file content.

EPSS: Низкий
github логотип

GHSA-22w5-vw2x-wqp3

почти 4 года назад

Cross-site scripting (XSS) vulnerability in index.php in the PhotoSmash plugin 1.0.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the action parameter.

EPSS: Низкий
github логотип

GHSA-22w4-vm3c-6x82

почти 4 года назад

DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_pic_view.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.

EPSS: Низкий
github логотип

GHSA-22w2-qhqg-5898

почти 4 года назад

Multiple unspecified vulnerabilities in Google Chrome before 44.0.2403.89 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

EPSS: Низкий
github логотип

GHSA-22vx-vmhj-v8m6

больше 3 лет назад

Windows SmartScreen Security Feature Bypass Vulnerability.

CVSS3: 5.4
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-22wf-j8j6-f67g

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D6100 before 1.0.0.58, D7800 before 1.0.1.40, R7500v2 before 1.0.3.34, R7800 before 1.0.2.52, R8900 before 1.0.4.2, R9000 before 1.0.3.16, RAX120 before 1.0.0.74, RBK20 before 2.3.0.22, RBR20 before 2.3.0.22, RBS20 before 2.3.0.22, RBK50 before 2.3.0.22, RBR50 before 2.3.0.22, RBS50 before 2.3.0.22, RBK40 before 2.3.0.22, RBS40 before 2.3.0.22, SRK60 before 2.2.0.64, SRR60 before 2.2.0.64, SRS60 before 2.2.0.64, WNDR3700v4 before 1.0.2.102, WNDR4300 before 1.0.2.104, WNDR4300v2 before 1.0.0.56, WNDR4500v3 before 1.0.0.56, and WNR2000v5 before 1.0.0.66.

0%
Низкий
почти 4 года назад
github логотип
GHSA-22wf-h889-r7q7

Improper permission control vulnerability in the OXARI ServiceDesk application could allow an attacker using a guest access or an unprivileged account to gain additional administrative permissions in the application.This issue affects OXARI ServiceDesk in versions before 2.0.324.0.

0%
Низкий
12 месяцев назад
github логотип
GHSA-22wf-fg96-jprv

In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_417338 function obtains fields from the front-end, connects them through the snprintf function, and passes them to the CsteSystem function, resulting in a command execution vulnerability.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-22wc-c9wj-6q2v

VVE-2021-0001: Memory corruption using function calls within arrays

почти 5 лет назад
github логотип
GHSA-22wc-8hcq-634h

In the Linux kernel, the following vulnerability has been resolved: ext4: fix deadlock due to mbcache entry corruption When manipulating xattr blocks, we can deadlock infinitely looping inside ext4_xattr_block_set() where we constantly keep finding xattr block for reuse in mbcache but we are unable to reuse it because its reference count is too big. This happens because cache entry for the xattr block is marked as reusable (e_reusable set) although its reference count is too big. When this inconsistency happens, this inconsistent state is kept indefinitely and so ext4_xattr_block_set() keeps retrying indefinitely. The inconsistent state is caused by non-atomic update of e_reusable bit. e_reusable is part of a bitfield and e_reusable update can race with update of e_referenced bit in the same bitfield resulting in loss of one of the updates. Fix the problem by using atomic bitops instead. This bug has been around for many years, but it became *much* easier to hit after commit 65f...

0%
Низкий
4 месяца назад
github логотип
GHSA-22wc-7wmm-v4cc

Liferay Portal and Liferay DXP does not properly check user permission

CVSS3: 4.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-22w9-x8p2-69rp

SQL injection vulnerability in admin.php in CloudNine Interactive Links Manager 2006-06-12, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the nick parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-22w9-j288-8p9w

OpenStack Nova Router metadata queries are not restricted by tenant

1%
Низкий
почти 4 года назад
github логотип
GHSA-22w9-2h5w-c9pv

The Duplicate Page and Post Plugin WordPress plugin through 2.7 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-22w8-qmw3-m9gr

The if_clone_list function in NetBSD-current before 20061027, NetBSD 3.0 and 3.0.1 before 20061027, and NetBSD 2.x before 20061119 allows local users to read potentially sensitive, uninitialized stack memory via unspecified vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-22w8-2mrr-vh7h

A security vulnerability has been detected in OWASP DefectDojo up to 2.55.4. This vulnerability affects the function input_zip.read of the file parser.py of the component SonarQubeParser/MSDefenderParser. The manipulation leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 2.56.0 is able to resolve this issue. The identifier of the patch is e8f1e5131535b8fd80a7b1b3085d676295fdcd41. Upgrading the affected component is recommended.

CVSS3: 4.3
0%
Низкий
17 дней назад
github логотип
GHSA-22w8-27w2-f55c

Heap-based buffer overflow in the EscapeParenthesis function in GraphicsMagick before 1.3.25 allows remote attackers to have unspecified impact via unknown vectors.

CVSS3: 9.8
2%
Низкий
почти 4 года назад
github логотип
GHSA-22w7-m5f8-87vh

Liferay Portal and Liferay DXP Vulnerable to Open Redirect via the Layout Module

CVSS3: 6.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-22w7-gmrw-m5qp

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. A malicious application may be able to elevate privileges.

0%
Низкий
почти 4 года назад
github логотип
GHSA-22w7-7694-298f

A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to disclose sensitive informatoin on affected installations.

CVSS3: 7.5
83%
Высокий
почти 4 года назад
github логотип
GHSA-22w6-gp78-84rc

The Red Hat mkdumprd script for kexec-tools, as distributed in the kexec-tools 1.x before 1.102pre-154 and 2.x before 2.0.0-209 packages in Red Hat Enterprise Linux, includes all of root's SSH private keys within a vmcore file, which allows context-dependent attackers to obtain sensitive information by inspecting the file content.

0%
Низкий
почти 4 года назад
github логотип
GHSA-22w5-vw2x-wqp3

Cross-site scripting (XSS) vulnerability in index.php in the PhotoSmash plugin 1.0.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the action parameter.

0%
Низкий
почти 4 года назад
github логотип
GHSA-22w4-vm3c-6x82

DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_pic_view.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.

0%
Низкий
почти 4 года назад
github логотип
GHSA-22w2-qhqg-5898

Multiple unspecified vulnerabilities in Google Chrome before 44.0.2403.89 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

1%
Низкий
почти 4 года назад
github логотип
GHSA-22vx-vmhj-v8m6

Windows SmartScreen Security Feature Bypass Vulnerability.

CVSS3: 5.4
67%
Средний
больше 3 лет назад

Уязвимостей на страницу