Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 364 920

Количество 364 920

github логотип

GHSA-3rp4-j8x5-r3q5

8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: arm64: set __exception_irq_entry with __irq_entry as a default filter_irq_stacks() is supposed to cut entries which are related irq entries from its call stack. And in_irqentry_text() which is called by filter_irq_stacks() uses __irqentry_text_start/end symbol to find irq entries in callstack. But it doesn't work correctly as without "CONFIG_FUNCTION_GRAPH_TRACER", arm64 kernel doesn't include gic_handle_irq which is entry point of arm64 irq between __irqentry_text_start and __irqentry_text_end as we discussed in below link. https://lore.kernel.org/all/CACT4Y+aReMGLYua2rCLHgFpS9io5cZC04Q8GLs-uNmrn1ezxYQ@mail.gmail.com/#t This problem can makes unintentional deep call stack entries especially in KASAN enabled situation as below. [ 2479.383395]I[0:launcher-loader: 1719] Stack depot reached limit capacity [ 2479.383538]I[0:launcher-loader: 1719] WARNING: CPU: 0 PID: 1719 at lib/stackdepot.c:129 __stack_depot_save+...

EPSS: Низкий
github логотип

GHSA-3rp4-72jw-qwwp

больше 4 лет назад

PHP remote file inclusion vulnerability in tourney/index.php in phpMyTourney 2 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

EPSS: Низкий
github логотип

GHSA-3rp3-24hq-749r

больше 2 лет назад

The Delta Electronics DVW-W02W2-E2 devices expose a web administration interface to users. This interface implements two features (access control lists management, WPS pin setup) that are affected by command injections and stack overflows vulnerabilities. Successful exploitation of these flaws would allow remote authenticated attackers to gain remote command execution with elevated privileges on the affected devices. This issue affects DVW-W02W2-E2 through version 2.5.2.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3rp2-pwr4-xjcw

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in admin_loginok.html in the Administrator web interface in Wing FTP Server for Windows 3.5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted POST request.

EPSS: Низкий
github логотип

GHSA-3rmx-2chr-mp38

больше 4 лет назад

An exploitable code execution vulnerability exists in the HTTP packet-parsing functionality of the LIVE555 RTSP server library version 0.92. A specially crafted packet can cause a stack-based buffer overflow, resulting in code execution. An attacker can send a packet to trigger this vulnerability.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3rmx-2462-5g54

4 месяца назад

Inappropriate implementation in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3rmw-wm6w-rmcr

больше 4 лет назад

A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. In addition, the prior bug fix for CVE-2020-10753 did not account for the use of \r as a header separator, thus a new flaw has been created.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3rmw-pprm-gfpw

6 месяцев назад

A security vulnerability has been detected in ContiNew Admin up to 4.2.0. This issue affects the function URI.create of the file continew-system/src/main/java/top/continew/admin/system/factory/S3ClientFactory.java of the component Storage Management Module. The manipulation leads to server-side request forgery. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-3rmw-76m6-4gjc

почти 2 года назад

User Registration Bypass in Zitadel

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3rmv-9mqg-h4q2

больше 4 лет назад

Race condition in Tunnelblick 3.3beta20 and earlier allows local users to kill unintended processes by waiting for a specific PID value to be assigned to a target process.

EPSS: Низкий
github логотип

GHSA-3rmv-2pg5-xvqj

почти 8 лет назад

Spring Framework has Improperly Implemented Security Check for Standard

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-3rmr-gxf2-f3fc

больше 3 лет назад

Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3rmr-75jg-fq5f

больше 4 лет назад

Cisco IOS XE before 3.7.5S on ASR 1000 devices does not properly handle route adjacencies, which allows remote attackers to cause a denial of service (device hang) via crafted IP packets, aka Bug ID CSCub31873.

EPSS: Низкий
github логотип

GHSA-3rmp-xjxw-cprh

больше 3 лет назад

A heap out of bounds read vulnerability exists in the OpenImageIO master-branch-9aeece7a when parsing the image file directory part of a PSD image file. A specially-crafted .psd file can cause a read of arbitrary memory address which can lead to denial of service. An attacker can provide a malicious file to trigger this vulnerability.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3rmp-rcwp-h568

больше 4 лет назад

The MAC module in Netfilter in Linux kernel 2.4.1 through 2.4.11, when configured to filter based on MAC addresses, allows remote attackers to bypass packet filters via small packets.

EPSS: Низкий
github логотип

GHSA-3rmj-h269-qjg5

около 3 лет назад

Memory safety bugs present in Firefox 115. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 116.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3rmj-9m5h-8fpv

5 месяцев назад

Astro: Memory exhaustion DoS due to missing request body size limit in Server Islands

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3rmj-3mrh-fv5j

больше 4 лет назад

GnuPG (GPG) 1.0.2, and other versions up to 1.2.3, creates ElGamal type 20 (sign+encrypt) keys using the same key component for encryption as for signing, which allows attackers to determine the private key from a signature.

EPSS: Низкий
github логотип

GHSA-3rmh-h5vq-pvv5

больше 4 лет назад

An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromising a privileged process and is mitigated by current platform configurations. Product: Android. Versions: Kernel-3.10. Android ID: A-31707909. References: B-RB#32094.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-3rmh-cwqh-9crc

больше 4 лет назад

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, and 14.1.x versions prior to 14.1.4.6, when a Session Initiation Protocol (SIP) message routing framework (MRF) application layer gateway (ALG) profile is configured on a Message Routing virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3rp4-j8x5-r3q5

In the Linux kernel, the following vulnerability has been resolved: arm64: set __exception_irq_entry with __irq_entry as a default filter_irq_stacks() is supposed to cut entries which are related irq entries from its call stack. And in_irqentry_text() which is called by filter_irq_stacks() uses __irqentry_text_start/end symbol to find irq entries in callstack. But it doesn't work correctly as without "CONFIG_FUNCTION_GRAPH_TRACER", arm64 kernel doesn't include gic_handle_irq which is entry point of arm64 irq between __irqentry_text_start and __irqentry_text_end as we discussed in below link. https://lore.kernel.org/all/CACT4Y+aReMGLYua2rCLHgFpS9io5cZC04Q8GLs-uNmrn1ezxYQ@mail.gmail.com/#t This problem can makes unintentional deep call stack entries especially in KASAN enabled situation as below. [ 2479.383395]I[0:launcher-loader: 1719] Stack depot reached limit capacity [ 2479.383538]I[0:launcher-loader: 1719] WARNING: CPU: 0 PID: 1719 at lib/stackdepot.c:129 __stack_depot_save+...

0%
Низкий
8 месяцев назад
github логотип
GHSA-3rp4-72jw-qwwp

PHP remote file inclusion vulnerability in tourney/index.php in phpMyTourney 2 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3rp3-24hq-749r

The Delta Electronics DVW-W02W2-E2 devices expose a web administration interface to users. This interface implements two features (access control lists management, WPS pin setup) that are affected by command injections and stack overflows vulnerabilities. Successful exploitation of these flaws would allow remote authenticated attackers to gain remote command execution with elevated privileges on the affected devices. This issue affects DVW-W02W2-E2 through version 2.5.2.

CVSS3: 7.2
2%
Низкий
больше 2 лет назад
github логотип
GHSA-3rp2-pwr4-xjcw

Cross-site scripting (XSS) vulnerability in admin_loginok.html in the Administrator web interface in Wing FTP Server for Windows 3.5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted POST request.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3rmx-2chr-mp38

An exploitable code execution vulnerability exists in the HTTP packet-parsing functionality of the LIVE555 RTSP server library version 0.92. A specially crafted packet can cause a stack-based buffer overflow, resulting in code execution. An attacker can send a packet to trigger this vulnerability.

CVSS3: 9.8
10%
Низкий
больше 4 лет назад
github логотип
GHSA-3rmx-2462-5g54

Inappropriate implementation in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)

CVSS3: 7.8
0%
Низкий
4 месяца назад
github логотип
GHSA-3rmw-wm6w-rmcr

A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. In addition, the prior bug fix for CVE-2020-10753 did not account for the use of \r as a header separator, thus a new flaw has been created.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3rmw-pprm-gfpw

A security vulnerability has been detected in ContiNew Admin up to 4.2.0. This issue affects the function URI.create of the file continew-system/src/main/java/top/continew/admin/system/factory/S3ClientFactory.java of the component Storage Management Module. The manipulation leads to server-side request forgery. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.7
0%
Низкий
6 месяцев назад
github логотип
GHSA-3rmw-76m6-4gjc

User Registration Bypass in Zitadel

CVSS3: 7.5
3%
Низкий
почти 2 года назад
github логотип
GHSA-3rmv-9mqg-h4q2

Race condition in Tunnelblick 3.3beta20 and earlier allows local users to kill unintended processes by waiting for a specific PID value to be assigned to a target process.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3rmv-2pg5-xvqj

Spring Framework has Improperly Implemented Security Check for Standard

CVSS3: 9.8
58%
Средний
почти 8 лет назад
github логотип
GHSA-3rmr-gxf2-f3fc

Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-3rmr-75jg-fq5f

Cisco IOS XE before 3.7.5S on ASR 1000 devices does not properly handle route adjacencies, which allows remote attackers to cause a denial of service (device hang) via crafted IP packets, aka Bug ID CSCub31873.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3rmp-xjxw-cprh

A heap out of bounds read vulnerability exists in the OpenImageIO master-branch-9aeece7a when parsing the image file directory part of a PSD image file. A specially-crafted .psd file can cause a read of arbitrary memory address which can lead to denial of service. An attacker can provide a malicious file to trigger this vulnerability.

CVSS3: 5.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3rmp-rcwp-h568

The MAC module in Netfilter in Linux kernel 2.4.1 through 2.4.11, when configured to filter based on MAC addresses, allows remote attackers to bypass packet filters via small packets.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3rmj-h269-qjg5

Memory safety bugs present in Firefox 115. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 116.

CVSS3: 9.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-3rmj-9m5h-8fpv

Astro: Memory exhaustion DoS due to missing request body size limit in Server Islands

CVSS3: 5.9
0%
Низкий
5 месяцев назад
github логотип
GHSA-3rmj-3mrh-fv5j

GnuPG (GPG) 1.0.2, and other versions up to 1.2.3, creates ElGamal type 20 (sign+encrypt) keys using the same key component for encryption as for signing, which allows attackers to determine the private key from a signature.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3rmh-h5vq-pvv5

An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromising a privileged process and is mitigated by current platform configurations. Product: Android. Versions: Kernel-3.10. Android ID: A-31707909. References: B-RB#32094.

CVSS3: 7
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3rmh-cwqh-9crc

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, and 14.1.x versions prior to 14.1.4.6, when a Session Initiation Protocol (SIP) message routing framework (MRF) application layer gateway (ALG) profile is configured on a Message Routing virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVSS3: 7.5
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу