Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 366 653

Количество 366 653

github логотип

GHSA-443g-xxfv-37vx

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: mm/swapfile: add cond_resched() in get_swap_pages() The softlockup still occurs in get_swap_pages() under memory pressure. 64 CPU cores, 64GB memory, and 28 zram devices, the disksize of each zram device is 50MB with same priority as si. Use the stress-ng tool to increase memory pressure, causing the system to oom frequently. The plist_for_each_entry_safe() loops in get_swap_pages() could reach tens of thousands of times to find available space (extreme case: cond_resched() is not called in scan_swap_map_slots()). Let's add cond_resched() into get_swap_pages() when failed to find available space to avoid softlockup.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-443g-gwgp-49x4

2 месяца назад

zebrad vulnerable to getblocks/getheaders locator CPU amplification via uncapped vector length

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-443f-w88g-369p

больше 4 лет назад

importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not require that authentication be enabled, which allows remote attackers to obtain sensitive information, or overwrite or delete files, via vectors involving a (1) direct request, (2) step=1 request, (3) step=2 or step=3 request, or (4) step=7 request.

EPSS: Низкий
github логотип

GHSA-443f-8vj4-c2c4

2 месяца назад

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-443c-w3hv-6grh

больше 4 лет назад

cPanel before 88.0.3 allows attackers to bypass the SMTP greylisting protection mechanism (SEC-491).

EPSS: Низкий
github логотип

GHSA-4439-mj69-f3rc

больше 4 лет назад

The Solaris Management Console (SMC) in Sun Solaris 8 and 9 generates different 404 error messages when a file does not exist versus when a file exists but is otherwise inaccessible, which could allow remote attackers to obtain sensitive information in conjunction with a directory traversal (..) attack.

EPSS: Низкий
github логотип

GHSA-4439-7p27-rx63

почти 3 года назад

A potential use-after-free vulnerability was reported in the Lenovo View driver that could result in denial of service.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4439-4hh6-5j2w

4 месяца назад

Macaron Notes 5.5 contains a denial of service vulnerability that allows attackers to crash the application by creating notes with excessively long character strings. Attackers can generate a payload containing 350000 repeated characters and paste it into a note field to trigger application crash and stop functionality.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4438-qr8f-3p3v

почти 2 года назад

A logic issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15. Privacy Indicators for microphone or camera access may be attributed incorrectly.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4438-jh32-8rr9

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in ardguest.php in Ardguest 1.8 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

EPSS: Низкий
github логотип

GHSA-4438-hp9q-vrqf

больше 4 лет назад

Multiple SQL injection vulnerabilities in Qsoft K-Rate Premium allow remote attackers to execute arbitrary SQL commands via (1) the $id variable in admin/includes/dele_cpac.php, (2) $ord[order_id] variable in payments/payment_received.php, (3) $id variable in includes/functions.php, and (4) unspecified variables in modules/chat.php, as demonstrated via the (a) show parameter in an online action to index.php; (b) PATH_INTO to the room/ handler; (c) image and (d) id parameters in a vote action to index.php; (e) PATH_INFO to the blog/ handler; and (f) id parameter in a blog_edit action to index.php.

EPSS: Низкий
github логотип

GHSA-4438-c9gx-hx64

2 месяца назад

Unauthenticated Cross Site Request Forgery (CSRF) in Booked <= 3.0.0 versions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4438-62q8-6hf2

больше 4 лет назад

After Junos OS device reboot or upgrade, the stateless firewall filter configuration may not take effect. This issue can be verified by running the command: user@re0> show interfaces <interface_name> extensive | match filters" CAM destination filters: 0, CAM source filters: 0 Note: when the issue occurs, it does not show the applied firewall filter. The correct output should show the applied firewall filter, for example: user@re0> show interfaces <interface_name> extensive | match filters" CAM destination filters: 0, CAM source filters: 0 Input Filters: FIREWAL_FILTER_NAME-<interface_name> This issue affects firewall filters for every address family. Affected releases are Juniper Networks Junos OS: 15.1R4, 15.1R5, 15.1R6 and SRs based on these MRs. 15.1X8 versions prior to 15.1X8.3.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4437-j8j7-wqjr

почти 2 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ketan Patel Featured product by category name allows DOM-Based XSS.This issue affects Featured product by category name: from n/a through 1.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4437-82vp-x78f

больше 4 лет назад

Remote arbitrary code execution in Micro Focus Data Protector, version 10.03 this vulnerability could allow remote arbitrary code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4435-w7hr-8qwm

около 1 года назад

An unauthenticated local attacker can inject a command that is subsequently executed as root, leading to a privilege escalation.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-4435-vfjh-hg77

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the web management interface in ZyWALL 10 4.07 allows remote attackers to inject arbitrary web script or HTML via the rpAuth_1 page.

EPSS: Средний
github логотип

GHSA-4435-hcqq-9f9v

около 1 года назад

A vulnerability classified as critical has been found in TOTOLINK X15 up to 1.0.0-B20230714.1105. Affected is an unknown function of the file /boafrm/formParentControl of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4435-f3hr-hpq3

около 1 года назад

An authenticated user with file access privilege via FTP access can cause the Relion 670/650 and SAM600-IO series device to reboot due to improper disk space management.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4435-68hj-c5gh

больше 4 лет назад

Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a long packet in a (1) Accellent 5Views (aka .5vw) file, (2) I4B trace file, or (3) NETMON 2 capture file.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-443g-xxfv-37vx

In the Linux kernel, the following vulnerability has been resolved: mm/swapfile: add cond_resched() in get_swap_pages() The softlockup still occurs in get_swap_pages() under memory pressure. 64 CPU cores, 64GB memory, and 28 zram devices, the disksize of each zram device is 50MB with same priority as si. Use the stress-ng tool to increase memory pressure, causing the system to oom frequently. The plist_for_each_entry_safe() loops in get_swap_pages() could reach tens of thousands of times to find available space (extreme case: cond_resched() is not called in scan_swap_map_slots()). Let's add cond_resched() into get_swap_pages() when failed to find available space to avoid softlockup.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-443g-gwgp-49x4

zebrad vulnerable to getblocks/getheaders locator CPU amplification via uncapped vector length

CVSS3: 3.7
2 месяца назад
github логотип
GHSA-443f-w88g-369p

importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not require that authentication be enabled, which allows remote attackers to obtain sensitive information, or overwrite or delete files, via vectors involving a (1) direct request, (2) step=1 request, (3) step=2 or step=3 request, or (4) step=7 request.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-443f-8vj4-c2c4

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 5.4
0%
Низкий
2 месяца назад
github логотип
GHSA-443c-w3hv-6grh

cPanel before 88.0.3 allows attackers to bypass the SMTP greylisting protection mechanism (SEC-491).

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4439-mj69-f3rc

The Solaris Management Console (SMC) in Sun Solaris 8 and 9 generates different 404 error messages when a file does not exist versus when a file exists but is otherwise inaccessible, which could allow remote attackers to obtain sensitive information in conjunction with a directory traversal (..) attack.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-4439-7p27-rx63

A potential use-after-free vulnerability was reported in the Lenovo View driver that could result in denial of service.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-4439-4hh6-5j2w

Macaron Notes 5.5 contains a denial of service vulnerability that allows attackers to crash the application by creating notes with excessively long character strings. Attackers can generate a payload containing 350000 repeated characters and paste it into a note field to trigger application crash and stop functionality.

CVSS3: 7.5
0%
Низкий
4 месяца назад
github логотип
GHSA-4438-qr8f-3p3v

A logic issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15. Privacy Indicators for microphone or camera access may be attributed incorrectly.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-4438-jh32-8rr9

Cross-site scripting (XSS) vulnerability in ardguest.php in Ardguest 1.8 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4438-hp9q-vrqf

Multiple SQL injection vulnerabilities in Qsoft K-Rate Premium allow remote attackers to execute arbitrary SQL commands via (1) the $id variable in admin/includes/dele_cpac.php, (2) $ord[order_id] variable in payments/payment_received.php, (3) $id variable in includes/functions.php, and (4) unspecified variables in modules/chat.php, as demonstrated via the (a) show parameter in an online action to index.php; (b) PATH_INTO to the room/ handler; (c) image and (d) id parameters in a vote action to index.php; (e) PATH_INFO to the blog/ handler; and (f) id parameter in a blog_edit action to index.php.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4438-c9gx-hx64

Unauthenticated Cross Site Request Forgery (CSRF) in Booked <= 3.0.0 versions.

CVSS3: 6.5
0%
Низкий
2 месяца назад
github логотип
GHSA-4438-62q8-6hf2

After Junos OS device reboot or upgrade, the stateless firewall filter configuration may not take effect. This issue can be verified by running the command: user@re0> show interfaces <interface_name> extensive | match filters" CAM destination filters: 0, CAM source filters: 0 Note: when the issue occurs, it does not show the applied firewall filter. The correct output should show the applied firewall filter, for example: user@re0> show interfaces <interface_name> extensive | match filters" CAM destination filters: 0, CAM source filters: 0 Input Filters: FIREWAL_FILTER_NAME-<interface_name> This issue affects firewall filters for every address family. Affected releases are Juniper Networks Junos OS: 15.1R4, 15.1R5, 15.1R6 and SRs based on these MRs. 15.1X8 versions prior to 15.1X8.3.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4437-j8j7-wqjr

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ketan Patel Featured product by category name allows DOM-Based XSS.This issue affects Featured product by category name: from n/a through 1.1.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-4437-82vp-x78f

Remote arbitrary code execution in Micro Focus Data Protector, version 10.03 this vulnerability could allow remote arbitrary code execution.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4435-w7hr-8qwm

An unauthenticated local attacker can inject a command that is subsequently executed as root, leading to a privilege escalation.

CVSS3: 8.4
0%
Низкий
около 1 года назад
github логотип
GHSA-4435-vfjh-hg77

Cross-site scripting (XSS) vulnerability in the web management interface in ZyWALL 10 4.07 allows remote attackers to inject arbitrary web script or HTML via the rpAuth_1 page.

11%
Средний
больше 4 лет назад
github логотип
GHSA-4435-hcqq-9f9v

A vulnerability classified as critical has been found in TOTOLINK X15 up to 1.0.0-B20230714.1105. Affected is an unknown function of the file /boafrm/formParentControl of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
1%
Низкий
около 1 года назад
github логотип
GHSA-4435-f3hr-hpq3

An authenticated user with file access privilege via FTP access can cause the Relion 670/650 and SAM600-IO series device to reboot due to improper disk space management.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-4435-68hj-c5gh

Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a long packet in a (1) Accellent 5Views (aka .5vw) file, (2) I4B trace file, or (3) NETMON 2 capture file.

3%
Низкий
больше 4 лет назад

Уязвимостей на страницу