Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 374 825

Количество 374 825

github логотип

GHSA-4pfr-7rwh-xm44

больше 4 лет назад

An information disclosure vulnerability in the kernel binder driver. Product: Android. Versions: Android kernel. Android ID A-36007193.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4pfq-9qw7-52fw

больше 4 лет назад

The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted audio file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4pfp-w4vm-364q

больше 4 лет назад

A flaw was found in the Linux kernel. A use-after-free was found in the way the console subsystem was using ioctls KDGKBSENT and KDSKBSENT. A local user could use this flaw to get read memory access out of bounds. The highest threat from this vulnerability is to data confidentiality.

CVSS3: 4.1
EPSS: Низкий
github логотип

GHSA-4pfp-qxm8-vq65

больше 4 лет назад

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3. An attacker in a privileged network position may be able to execute arbitrary code.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4pfp-mmjh-x8v9

больше 4 лет назад

In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improved access restrictions.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4pfm-pggq-vxqq

3 месяца назад

Dreamweaver Desktop versions 21.7 and earlier are affected by an Incorrect Authorization vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-4pfj-xhf6-v58f

больше 1 года назад

In the spiral-rs crate 0.2.0 for Rust, allocation can be attempted for a ZST (zero-sized type).

CVSS3: 2.9
EPSS: Низкий
github логотип

GHSA-4pfj-29xq-qrx4

почти 4 года назад

A vulnerability classified as critical has been found in Axiomatic Bento4. Affected is the function AP4_BitStream::WriteBytes of the file Ap4BitStream.cpp of the component avcinfo. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-212004.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4pfh-v638-25xp

больше 4 лет назад

The oratclsh interpreter in Oracle 8.x Intelligent Agent for Unix allows local users to execute Tcl commands as root.

EPSS: Низкий
github логотип

GHSA-4pfh-pqfv-vhrc

больше 4 лет назад

Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Service Operation Management Software Module allows remote attackers to bypass authentication via unknown vectors, aka ZDI-CAN-1644.

EPSS: Средний
github логотип

GHSA-4pfh-329g-gqpr

12 месяцев назад

danny-avila/librechat is affected by an authorization bypass vulnerability due to improper access control checks. The `checkAccess` function in `api/server/middleware/roles/access.js` uses `permissions.some()` to validate permissions, which incorrectly grants access if only one of multiple required permissions is present. This allows users with the 'USER' role to create agents despite having `CREATE: false` permission, as the check for `['USE', 'CREATE']` passes with just `USE: true`. This vulnerability affects other permission checks as well, such as `PROMPTS`. The issue is present in all versions prior to the fix.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4pfh-2w89-vqv4

больше 4 лет назад

The JMX servlet in Red Hat JBoss Enterprise Application Platform (EAP) 4 and 5 allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via a crafted serialized Java object.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-4pfg-q7wv-6rq4

6 месяцев назад

A vulnerability was determined in itsourcecode Construction Management System 1.0. The impacted element is an unknown function of the file /borrowed_equip.php of the component Parameter Handler. This manipulation of the argument emp causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-4pfg-92mj-fx5w

больше 4 лет назад

Microsoft Visio Security Feature Bypass Vulnerability

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-4pfg-7qf4-p79c

около 3 лет назад

IBM Aspera Faspex 5.0.5 does not restrict or incorrectly restricts access to a resource from an unauthorized actor. IBM X-Force ID: 246713.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-4pfg-2mw5-f8jx

около 1 года назад

Cloudflare Vite plugin exposes secrets over the built-in dev server

EPSS: Низкий
github логотип

GHSA-4pfg-2frf-f67v

больше 4 лет назад

MoinMoin Cross-site Scripting (XSS) vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4pff-rvgp-gggv

19 дней назад

A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. The impacted element is the function MD5Importer::MakeDataUnique of the file code/AssetLib/MD5/MD5Loader.cpp. The manipulation of the argument iNewIndex leads to heap-based buffer overflow. The attack can only be performed from a local environment. The identifier of the patch is bf9dabb617c46e5133dac65cca6bff177917afcb. Applying a patch is the recommended action to fix this issue.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4pff-25fv-cm83

больше 2 лет назад

Grafana is an open-source platform for monitoring and observability. The CSV datasource plugin is a Grafana Labs maintained plugin for Grafana that allows for retrieving and processing CSV data from a remote endpoint configured by an administrator. If this plugin was configured to send requests to a bare host with no path (e.g. https://www.example.com/ https://www.example.com/` ), requests to an endpoint other than the one configured by the administrator could be triggered by a specially crafted request from any user, resulting in an SSRF vector. AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-4pfc-4qw7-wq28

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TaskMeister Accessibility Task Manager allows Reflected XSS. This issue affects Accessibility Task Manager: from n/a through 1.2.1.

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4pfr-7rwh-xm44

An information disclosure vulnerability in the kernel binder driver. Product: Android. Versions: Android kernel. Android ID A-36007193.

CVSS3: 7.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4pfq-9qw7-52fw

The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted audio file.

CVSS3: 6.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4pfp-w4vm-364q

A flaw was found in the Linux kernel. A use-after-free was found in the way the console subsystem was using ioctls KDGKBSENT and KDSKBSENT. A local user could use this flaw to get read memory access out of bounds. The highest threat from this vulnerability is to data confidentiality.

CVSS3: 4.1
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4pfp-qxm8-vq65

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3. An attacker in a privileged network position may be able to execute arbitrary code.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4pfp-mmjh-x8v9

In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improved access restrictions.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4pfm-pggq-vxqq

Dreamweaver Desktop versions 21.7 and earlier are affected by an Incorrect Authorization vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

CVSS3: 6.3
0%
Низкий
3 месяца назад
github логотип
GHSA-4pfj-xhf6-v58f

In the spiral-rs crate 0.2.0 for Rust, allocation can be attempted for a ZST (zero-sized type).

CVSS3: 2.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-4pfj-29xq-qrx4

A vulnerability classified as critical has been found in Axiomatic Bento4. Affected is the function AP4_BitStream::WriteBytes of the file Ap4BitStream.cpp of the component avcinfo. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-212004.

CVSS3: 7.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-4pfh-v638-25xp

The oratclsh interpreter in Oracle 8.x Intelligent Agent for Unix allows local users to execute Tcl commands as root.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4pfh-pqfv-vhrc

Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Service Operation Management Software Module allows remote attackers to bypass authentication via unknown vectors, aka ZDI-CAN-1644.

24%
Средний
больше 4 лет назад
github логотип
GHSA-4pfh-329g-gqpr

danny-avila/librechat is affected by an authorization bypass vulnerability due to improper access control checks. The `checkAccess` function in `api/server/middleware/roles/access.js` uses `permissions.some()` to validate permissions, which incorrectly grants access if only one of multiple required permissions is present. This allows users with the 'USER' role to create agents despite having `CREATE: false` permission, as the check for `['USE', 'CREATE']` passes with just `USE: true`. This vulnerability affects other permission checks as well, such as `PROMPTS`. The issue is present in all versions prior to the fix.

CVSS3: 5.3
0%
Низкий
12 месяцев назад
github логотип
GHSA-4pfh-2w89-vqv4

The JMX servlet in Red Hat JBoss Enterprise Application Platform (EAP) 4 and 5 allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via a crafted serialized Java object.

CVSS3: 8.8
12%
Средний
больше 4 лет назад
github логотип
GHSA-4pfg-q7wv-6rq4

A vulnerability was determined in itsourcecode Construction Management System 1.0. The impacted element is an unknown function of the file /borrowed_equip.php of the component Parameter Handler. This manipulation of the argument emp causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.

CVSS3: 6.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-4pfg-92mj-fx5w

Microsoft Visio Security Feature Bypass Vulnerability

CVSS3: 7
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4pfg-7qf4-p79c

IBM Aspera Faspex 5.0.5 does not restrict or incorrectly restricts access to a resource from an unauthorized actor. IBM X-Force ID: 246713.

CVSS3: 5.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-4pfg-2mw5-f8jx

Cloudflare Vite plugin exposes secrets over the built-in dev server

0%
Низкий
около 1 года назад
github логотип
GHSA-4pfg-2frf-f67v

MoinMoin Cross-site Scripting (XSS) vulnerability

CVSS3: 6.1
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4pff-rvgp-gggv

A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. The impacted element is the function MD5Importer::MakeDataUnique of the file code/AssetLib/MD5/MD5Loader.cpp. The manipulation of the argument iNewIndex leads to heap-based buffer overflow. The attack can only be performed from a local environment. The identifier of the patch is bf9dabb617c46e5133dac65cca6bff177917afcb. Applying a patch is the recommended action to fix this issue.

CVSS3: 5.3
0%
Низкий
19 дней назад
github логотип
GHSA-4pff-25fv-cm83

Grafana is an open-source platform for monitoring and observability. The CSV datasource plugin is a Grafana Labs maintained plugin for Grafana that allows for retrieving and processing CSV data from a remote endpoint configured by an administrator. If this plugin was configured to send requests to a bare host with no path (e.g. https://www.example.com/ https://www.example.com/` ), requests to an endpoint other than the one configured by the administrator could be triggered by a specially crafted request from any user, resulting in an SSRF vector. AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator

CVSS3: 5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4pfc-4qw7-wq28

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TaskMeister Accessibility Task Manager allows Reflected XSS. This issue affects Accessibility Task Manager: from n/a through 1.2.1.

CVSS3: 7.1
0%
Низкий
больше 1 года назад

Уязвимостей на страницу