Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 366 653

Количество 366 653

github логотип

GHSA-436g-fhfc-9g5w

5 месяцев назад

D-Tale: Remote Code Execution through redis/shelf storage

EPSS: Низкий
github логотип

GHSA-436g-2f92-cvhh

больше 3 лет назад

Jenkins Role-based Authorization Strategy Plugin grants permissions even after they’ve been disabled

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-436f-fmh9-32gq

5 месяцев назад

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty could provide weaker than expected security when administering security settings.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-436f-chr9-2p6r

больше 4 лет назад

The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and configuration information via a direct request.

EPSS: Низкий
github логотип

GHSA-436c-96vr-9jcq

больше 4 лет назад

Integer overflow in the plist_from_bin function in bplist.c in libimobiledevice/libplist before 2017-04-19 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted plist file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4369-x39w-2545

больше 4 лет назад

VMware ESX Server 1.5.2 before Patch 4 allows local users to execute arbitrary programs as root via certain modified VMware ESX Server environment variables.

EPSS: Низкий
github логотип

GHSA-4369-mg8x-jq9f

больше 1 года назад

An authorization bypass vulnerability exists in the Mavenir SCE Application Provisioning Portal, version PORTAL-LBS-R_1_0_24_0, which allows an authenticated 'guest' user to perform unauthorized administrative actions, such as accessing the 'add user' feature, by bypassing client-side access controls.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4368-7mjc-5763

5 месяцев назад

A resample query can be used to trigger out-of-memory crashes in Grafana.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4368-3x2v-g4cm

больше 4 лет назад

Google V8, as used in Google Chrome before 28.0.1500.95, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion."

EPSS: Низкий
github логотип

GHSA-4368-2cqv-7wjv

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in Daverave Simplog 1.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a blog post.

EPSS: Низкий
github логотип

GHSA-4367-vj5g-xqcr

больше 4 лет назад

Double free vulnerability in Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allows attackers to execute arbitrary code via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-4367-rch8-6vrp

больше 4 лет назад

PHP remote file inclusion vulnerability in SmartSiteCMS 1.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the root parameter in (1) comment.php, (2) admin/comedit.php, (3) admin/test.php, (4) admin/index.php, and (5) admin/include/inc_adminfoot.php, a different set of vectors than CVE-2006-3162.

EPSS: Низкий
github логотип

GHSA-4367-pw62-mx9j

больше 2 лет назад

The IBM Integration Bus for z/OS 10.1 through 10.1.0.2 AdminAPI is vulnerable to a denial of service due to file system exhaustion. IBM X-Force ID: 279972.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4367-8h95-cxcx

3 месяца назад

An issue in ClipBucket v5 v.5.5.2 allows an attacker to execute arbitrary code via the Authentication interface, login page endpoint and HTTP response security headers components

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4367-36c5-2mx8

почти 4 года назад

DedeCMS V5.7.99 was discovered to contain an arbitrary file upload vulnerability via the component /dede/file_manage_control.php.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-4366-c9hw-r9qg

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: xen: privcmd: Fix possible access to a freed kirqfd instance Nothing prevents simultaneous ioctl calls to privcmd_irqfd_assign() and privcmd_irqfd_deassign(). If that happens, it is possible that a kirqfd created and added to the irqfds_list by privcmd_irqfd_assign() may get removed by another thread executing privcmd_irqfd_deassign(), while the former is still using it after dropping the locks. This can lead to a situation where an already freed kirqfd instance may be accessed and cause kernel oops. Use SRCU locking to prevent the same, as is done for the KVM implementation for irqfds.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4365-vm8j-8w63

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the Notifications form in Red Hat Subscription Asset Manager before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the username field.

EPSS: Низкий
github логотип

GHSA-4365-fhm5-qcrx

почти 5 лет назад

Maliciously Crafted Model Archive Can Lead To Arbitrary File Write

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4364-jq2q-6hrc

7 месяцев назад

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an authenticated user to cause a denial of service due to improper allocation of resources.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4363-x42f-xph6

около 6 лет назад

Malicious Package in hw-trnasport-u2f

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-436g-fhfc-9g5w

D-Tale: Remote Code Execution through redis/shelf storage

1%
Низкий
5 месяцев назад
github логотип
GHSA-436g-2f92-cvhh

Jenkins Role-based Authorization Strategy Plugin grants permissions even after they’ve been disabled

CVSS3: 5.9
1%
Низкий
больше 3 лет назад
github логотип
GHSA-436f-fmh9-32gq

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty could provide weaker than expected security when administering security settings.

CVSS3: 6.7
0%
Низкий
5 месяцев назад
github логотип
GHSA-436f-chr9-2p6r

The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and configuration information via a direct request.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-436c-96vr-9jcq

Integer overflow in the plist_from_bin function in bplist.c in libimobiledevice/libplist before 2017-04-19 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted plist file.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4369-x39w-2545

VMware ESX Server 1.5.2 before Patch 4 allows local users to execute arbitrary programs as root via certain modified VMware ESX Server environment variables.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4369-mg8x-jq9f

An authorization bypass vulnerability exists in the Mavenir SCE Application Provisioning Portal, version PORTAL-LBS-R_1_0_24_0, which allows an authenticated 'guest' user to perform unauthorized administrative actions, such as accessing the 'add user' feature, by bypassing client-side access controls.

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-4368-7mjc-5763

A resample query can be used to trigger out-of-memory crashes in Grafana.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-4368-3x2v-g4cm

Google V8, as used in Google Chrome before 28.0.1500.95, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion."

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4368-2cqv-7wjv

Cross-site scripting (XSS) vulnerability in Daverave Simplog 1.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a blog post.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4367-vj5g-xqcr

Double free vulnerability in Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allows attackers to execute arbitrary code via unspecified vectors.

8%
Низкий
больше 4 лет назад
github логотип
GHSA-4367-rch8-6vrp

PHP remote file inclusion vulnerability in SmartSiteCMS 1.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the root parameter in (1) comment.php, (2) admin/comedit.php, (3) admin/test.php, (4) admin/index.php, and (5) admin/include/inc_adminfoot.php, a different set of vectors than CVE-2006-3162.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-4367-pw62-mx9j

The IBM Integration Bus for z/OS 10.1 through 10.1.0.2 AdminAPI is vulnerable to a denial of service due to file system exhaustion. IBM X-Force ID: 279972.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4367-8h95-cxcx

An issue in ClipBucket v5 v.5.5.2 allows an attacker to execute arbitrary code via the Authentication interface, login page endpoint and HTTP response security headers components

CVSS3: 7.3
0%
Низкий
3 месяца назад
github логотип
GHSA-4367-36c5-2mx8

DedeCMS V5.7.99 was discovered to contain an arbitrary file upload vulnerability via the component /dede/file_manage_control.php.

CVSS3: 7.2
1%
Низкий
почти 4 года назад
github логотип
GHSA-4366-c9hw-r9qg

In the Linux kernel, the following vulnerability has been resolved: xen: privcmd: Fix possible access to a freed kirqfd instance Nothing prevents simultaneous ioctl calls to privcmd_irqfd_assign() and privcmd_irqfd_deassign(). If that happens, it is possible that a kirqfd created and added to the irqfds_list by privcmd_irqfd_assign() may get removed by another thread executing privcmd_irqfd_deassign(), while the former is still using it after dropping the locks. This can lead to a situation where an already freed kirqfd instance may be accessed and cause kernel oops. Use SRCU locking to prevent the same, as is done for the KVM implementation for irqfds.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-4365-vm8j-8w63

Cross-site scripting (XSS) vulnerability in the Notifications form in Red Hat Subscription Asset Manager before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the username field.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4365-fhm5-qcrx

Maliciously Crafted Model Archive Can Lead To Arbitrary File Write

CVSS3: 7.3
1%
Низкий
почти 5 лет назад
github логотип
GHSA-4364-jq2q-6hrc

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an authenticated user to cause a denial of service due to improper allocation of resources.

CVSS3: 6.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-4363-x42f-xph6

Malicious Package in hw-trnasport-u2f

CVSS3: 9.1
около 6 лет назад

Уязвимостей на страницу