Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 365 324

Количество 365 324

github логотип

GHSA-3wq8-wfw2-w4xm

больше 4 лет назад

The replace_map_fd_with_map_ptr function in kernel/bpf/verifier.c in the Linux kernel before 4.5.5 does not properly maintain an fd data structure, which allows local users to gain privileges or cause a denial of service (use-after-free) via crafted BPF instructions that reference an incorrect file descriptor.

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-3wq8-22r5-x325

больше 4 лет назад

cPanel before 71.9980.37 does not enforce the Mime::list_hotlinks API feature restriction (SEC-432).

EPSS: Низкий
github логотип

GHSA-3wq7-w8r7-pmvh

около 2 лет назад

Clipboard code failed to check the index on an array access. This could have lead to an out-of-bounds read. This vulnerability affects Firefox < 128.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3wq7-rqq7-wx6j

5 месяцев назад

AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS

EPSS: Низкий
github логотип

GHSA-3wq7-jqg2-g9mh

больше 4 лет назад

Use after free in audio in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3wq7-2q97-v54v

больше 4 лет назад

SQL-Ledger 2.8.24 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

EPSS: Низкий
github логотип

GHSA-3wq6-8f7g-92vm

больше 4 лет назад

HCL Verse v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of message content. An unauthenticated remote attacker could exploit this vulnerability using specially-crafted markup to execute script in a victim's web browser within the security context of the hosting Web site and/or steal the victim's cookie-based authentication credentials.

EPSS: Низкий
github логотип

GHSA-3wq5-x8p8-2v3p

5 месяцев назад

Rapid7 Velociraptor versions prior to 0.76.2 contain an improper input validation vulnerability in the client monitoring message handler on the Velociraptor server (primarily Linux) that allows an authenticated remote attacker to write to arbitrary internal server queues via a crafted monitoring message with a malicious queue name. The server handler that receives client monitoring messages does not sufficiently validate the queue name supplied by the client, allowing a rogue client to write arbitrary messages to privileged internal queues. This may lead to remote code execution on the Velociraptor server. Rapid7 Hosted Velociraptor instances are not affected by this vulnerability.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-3wq5-3f56-v5xc

больше 3 лет назад

Mattermost vulnerable to information disclosure

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3wq5-2gjw-q95m

около 4 лет назад

Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in PluginlySpeaking Floating Div plugin <= 3.0 at WordPress.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3wq4-xjpf-pj4j

3 месяца назад

NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3wq4-w788-rhg3

около 1 месяца назад

Inappropriate implementation in Editing in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-3wq4-pg59-r5hj

9 дней назад

In D-Link DI-8100G 17.12.20A1, the flag parameter in msp_info can be exploited to execute arbitrary code.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3wq4-hqw7-6x4f

9 месяцев назад

An issue in Austrian Academy of Sciences (AW) Austrian Archaeological Institute OpenAtlas v.8.12.0 allows a remote attacker to obtain sensitive information via the login error messages

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3wq4-8fhv-h6wv

около 1 года назад

Missing Authorization vulnerability in Drupal Layout Builder Advanced Permissions allows Forceful Browsing.This issue affects Layout Builder Advanced Permissions: from 0.0.0 before 2.2.0.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3wq4-5xg6-q6v6

11 месяцев назад

SQL injection vulnerability in Prevengos v2.44 by Nedatec Consulting. This vulnerability allows an attacker to retrieve, create, update, and delete databases by sending a POST request using the parameters “mpsCentroin”, “mpsEmpresa”, “mpsProyecto”, and “mpsContrata” in “/servicios/autorizaciones.asmx/mfsRecuperarListado”.

EPSS: Низкий
github логотип

GHSA-3wq3-vrpr-9c55

18 дней назад

In the Linux kernel, the following vulnerability has been resolved: ALSA: 6fire: Fix UAF at error handling during probe Although 6fire driver had a few fixes for dealing with the early error handling during the probe phase, it forgot a pending URB before freeing the resources, which may lead to a UAF. This patch addresses it by doing the almost same cleanup procedure like the normal disconnect phase at the error path.

EPSS: Низкий
github логотип

GHSA-3wq3-fv46-cvpq

больше 4 лет назад

Race condition in run_posix_cpu_timers in Linux kernel before 2.6.16.21 allows local users to cause a denial of service (BUG_ON crash) by causing one CPU to attach a timer to a process that is exiting.

EPSS: Низкий
github логотип

GHSA-3wq3-9c8f-wfpw

около 2 лет назад

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_log.php?clear=1

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-3wq3-8mrj-pgjf

больше 4 лет назад

Directory traversal vulnerability in the Management Console on the Symantec NetBackup (NBU) appliance 2.0.x allows remote attackers to read arbitrary files via unspecified vectors.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3wq8-wfw2-w4xm

The replace_map_fd_with_map_ptr function in kernel/bpf/verifier.c in the Linux kernel before 4.5.5 does not properly maintain an fd data structure, which allows local users to gain privileges or cause a denial of service (use-after-free) via crafted BPF instructions that reference an incorrect file descriptor.

CVSS3: 7.8
10%
Средний
больше 4 лет назад
github логотип
GHSA-3wq8-22r5-x325

cPanel before 71.9980.37 does not enforce the Mime::list_hotlinks API feature restriction (SEC-432).

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3wq7-w8r7-pmvh

Clipboard code failed to check the index on an array access. This could have lead to an out-of-bounds read. This vulnerability affects Firefox < 128.

CVSS3: 9.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-3wq7-rqq7-wx6j

AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS

0%
Низкий
5 месяцев назад
github логотип
GHSA-3wq7-jqg2-g9mh

Use after free in audio in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3wq7-2q97-v54v

SQL-Ledger 2.8.24 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3wq6-8f7g-92vm

HCL Verse v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of message content. An unauthenticated remote attacker could exploit this vulnerability using specially-crafted markup to execute script in a victim's web browser within the security context of the hosting Web site and/or steal the victim's cookie-based authentication credentials.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3wq5-x8p8-2v3p

Rapid7 Velociraptor versions prior to 0.76.2 contain an improper input validation vulnerability in the client monitoring message handler on the Velociraptor server (primarily Linux) that allows an authenticated remote attacker to write to arbitrary internal server queues via a crafted monitoring message with a malicious queue name. The server handler that receives client monitoring messages does not sufficiently validate the queue name supplied by the client, allowing a rogue client to write arbitrary messages to privileged internal queues. This may lead to remote code execution on the Velociraptor server. Rapid7 Hosted Velociraptor instances are not affected by this vulnerability.

CVSS3: 8.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-3wq5-3f56-v5xc

Mattermost vulnerable to information disclosure

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3wq5-2gjw-q95m

Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in PluginlySpeaking Floating Div plugin <= 3.0 at WordPress.

CVSS3: 4.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-3wq4-xjpf-pj4j

NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.

CVSS3: 8.8
1%
Низкий
3 месяца назад
github логотип
GHSA-3wq4-w788-rhg3

Inappropriate implementation in Editing in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 3.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3wq4-pg59-r5hj

In D-Link DI-8100G 17.12.20A1, the flag parameter in msp_info can be exploited to execute arbitrary code.

CVSS3: 8.1
0%
Низкий
9 дней назад
github логотип
GHSA-3wq4-hqw7-6x4f

An issue in Austrian Academy of Sciences (AW) Austrian Archaeological Institute OpenAtlas v.8.12.0 allows a remote attacker to obtain sensitive information via the login error messages

CVSS3: 5.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-3wq4-8fhv-h6wv

Missing Authorization vulnerability in Drupal Layout Builder Advanced Permissions allows Forceful Browsing.This issue affects Layout Builder Advanced Permissions: from 0.0.0 before 2.2.0.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-3wq4-5xg6-q6v6

SQL injection vulnerability in Prevengos v2.44 by Nedatec Consulting. This vulnerability allows an attacker to retrieve, create, update, and delete databases by sending a POST request using the parameters “mpsCentroin”, “mpsEmpresa”, “mpsProyecto”, and “mpsContrata” in “/servicios/autorizaciones.asmx/mfsRecuperarListado”.

0%
Низкий
11 месяцев назад
github логотип
GHSA-3wq3-vrpr-9c55

In the Linux kernel, the following vulnerability has been resolved: ALSA: 6fire: Fix UAF at error handling during probe Although 6fire driver had a few fixes for dealing with the early error handling during the probe phase, it forgot a pending URB before freeing the resources, which may lead to a UAF. This patch addresses it by doing the almost same cleanup procedure like the normal disconnect phase at the error path.

0%
Низкий
18 дней назад
github логотип
GHSA-3wq3-fv46-cvpq

Race condition in run_posix_cpu_timers in Linux kernel before 2.6.16.21 allows local users to cause a denial of service (BUG_ON crash) by causing one CPU to attach a timer to a process that is exiting.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3wq3-9c8f-wfpw

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_log.php?clear=1

CVSS3: 5.7
0%
Низкий
около 2 лет назад
github логотип
GHSA-3wq3-8mrj-pgjf

Directory traversal vulnerability in the Management Console on the Symantec NetBackup (NBU) appliance 2.0.x allows remote attackers to read arbitrary files via unspecified vectors.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу