Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 364 920

Количество 364 920

github логотип

GHSA-3rff-rg87-9c8x

5 месяцев назад

Use after free in Compositing in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-3rff-mqc6-jp26

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Deepak Khokhar Listings for Buildium allows Stored XSS. This issue affects Listings for Buildium: from n/a through 0.1.4.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3rff-g889-h6g3

больше 4 лет назад

The mac80211 subsystem in the Linux kernel before 2.6.32-rc8-next-20091201 allows remote attackers to cause a denial of service (panic) via a crafted Delete Block ACK (aka DELBA) packet, related to an erroneous "code shuffling patch."

EPSS: Низкий
github логотип

GHSA-3rfc-7v55-gmrf

около 1 месяца назад

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix folio->private handling in netfs_perform_write() Under some circumstances, netfs_perform_write() doesn't correctly manipulate folio->private between NULL, NETFS_FOLIO_COPY_TO_CACHE, pointing to a group and pointing to a netfs_folio struct, leading to potential multiple attachments of private data with associated folio ref leaks and also leaks of netfs_folio structs or netfs_group refs. Fix this by consolidating the place at which a folio is marked uptodate in one place and having that look at what's attached to folio->private and decide how to clean it up and then set the new group. Also, the content shouldn't be flushed if group is NULL, even if a group is specified in the netfs_group parameter, as that would be the case for a new folio. A filesystem should always specify netfs_group or never specify netfs_group. The Sashiko auto-review tool noted that it was theoretically possible that the fpos >=...

EPSS: Низкий
github логотип

GHSA-3rf9-jvj9-2299

больше 4 лет назад

Use-after-free vulnerability in nginx before 1.0.14 and 1.1.x before 1.1.17 allows remote HTTP servers to obtain sensitive information from process memory via a crafted backend response, in conjunction with a client request.

EPSS: Средний
github логотип

GHSA-3rf9-fc8c-hj8h

больше 4 лет назад

Unspecified vulnerability in the browser engine in Mozilla Firefox before 3.0.16, SeaMonkey before 2.0.1, and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

EPSS: Низкий
github логотип

GHSA-3rf8-mgfc-9vfp

около 2 месяцев назад

A vulnerability was determined in zhinianboke xianyu-auto-reply on Server. Affected by this vulnerability is an unknown functionality of the file /api/v1/payment/withdraw/review?action=approve. Executing a manipulation can lead to trusting http permission methods on the server side. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. This patch is called 19fc3282a1bb78a05c34945c088525d20e081cbd. It is best practice to apply a patch to resolve this issue.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3rf7-cxmv-24rp

почти 4 года назад

Memory corruption in BTHOST due to double free while music playback and calls over bluetooth headset in Snapdragon Mobile

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3rf7-6c99-mx43

почти 5 лет назад

An authenticated user could potentially execute code via an SQLi vulnerability in the user portal of SG UTM before version 9.708 MR8.

EPSS: Низкий
github логотип

GHSA-3rf6-x59v-5jfv

4 месяца назад

dash-uploader has a directory traversal vulnerability

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3rf6-9xhv-wrqx

больше 4 лет назад

The Nigerias Business Directory (aka com.wNigeriasBusinessDirectory) application 0.70.13414.17619 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-3rf6-9vpq-q3h4

около 1 месяца назад

HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-3rf6-3w37-m7h7

больше 4 лет назад

Adobe Photoshop CC 2018 before 19.1.6 and Photoshop CC 2017 before 18.1.6 have a memory corruption vulnerability. Successful exploitation could lead to remote code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3rf6-3v84-w7f8

почти 3 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Moriyan Jay WP Site Protector plugin <= 2.0 versions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3rf5-gg5c-jh3p

больше 4 лет назад

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may lead to arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-3rf5-756g-4w3q

больше 4 лет назад

Online Shopping Portal v3.1 was discovered to contain multiple time-based SQL injection vulnerabilities via the email and contactno parameters.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3rf4-wqcv-f4q7

больше 4 лет назад

Cisco IOS 15.3 and 15.4, Cisco IOS XE 3.8 through 3.11, and Cisco Unified Communications Manager allow remote attackers to cause a denial of service (device reload) via malformed SIP messages, aka Bug ID CSCuj23293.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3rf4-hfh4-9ww3

больше 4 лет назад

There is an Input verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability.

EPSS: Низкий
github логотип

GHSA-3rf4-9569-4jw7

больше 4 лет назад

The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.

EPSS: Средний
github логотип

GHSA-3rf3-mp77-8jf5

больше 4 лет назад

cPanel before 60.0.25 allows file-create and file-chmod operations during ModSecurity Audit logfile processing (SEC-165).

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3rff-rg87-9c8x

Use after free in Compositing in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 9.6
0%
Низкий
5 месяцев назад
github логотип
GHSA-3rff-mqc6-jp26

Cross-Site Request Forgery (CSRF) vulnerability in Deepak Khokhar Listings for Buildium allows Stored XSS. This issue affects Listings for Buildium: from n/a through 0.1.4.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-3rff-g889-h6g3

The mac80211 subsystem in the Linux kernel before 2.6.32-rc8-next-20091201 allows remote attackers to cause a denial of service (panic) via a crafted Delete Block ACK (aka DELBA) packet, related to an erroneous "code shuffling patch."

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3rfc-7v55-gmrf

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix folio->private handling in netfs_perform_write() Under some circumstances, netfs_perform_write() doesn't correctly manipulate folio->private between NULL, NETFS_FOLIO_COPY_TO_CACHE, pointing to a group and pointing to a netfs_folio struct, leading to potential multiple attachments of private data with associated folio ref leaks and also leaks of netfs_folio structs or netfs_group refs. Fix this by consolidating the place at which a folio is marked uptodate in one place and having that look at what's attached to folio->private and decide how to clean it up and then set the new group. Also, the content shouldn't be flushed if group is NULL, even if a group is specified in the netfs_group parameter, as that would be the case for a new folio. A filesystem should always specify netfs_group or never specify netfs_group. The Sashiko auto-review tool noted that it was theoretically possible that the fpos >=...

0%
Низкий
около 1 месяца назад
github логотип
GHSA-3rf9-jvj9-2299

Use-after-free vulnerability in nginx before 1.0.14 and 1.1.x before 1.1.17 allows remote HTTP servers to obtain sensitive information from process memory via a crafted backend response, in conjunction with a client request.

11%
Средний
больше 4 лет назад
github логотип
GHSA-3rf9-fc8c-hj8h

Unspecified vulnerability in the browser engine in Mozilla Firefox before 3.0.16, SeaMonkey before 2.0.1, and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-3rf8-mgfc-9vfp

A vulnerability was determined in zhinianboke xianyu-auto-reply on Server. Affected by this vulnerability is an unknown functionality of the file /api/v1/payment/withdraw/review?action=approve. Executing a manipulation can lead to trusting http permission methods on the server side. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. This patch is called 19fc3282a1bb78a05c34945c088525d20e081cbd. It is best practice to apply a patch to resolve this issue.

CVSS3: 5.4
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3rf7-cxmv-24rp

Memory corruption in BTHOST due to double free while music playback and calls over bluetooth headset in Snapdragon Mobile

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-3rf7-6c99-mx43

An authenticated user could potentially execute code via an SQLi vulnerability in the user portal of SG UTM before version 9.708 MR8.

1%
Низкий
почти 5 лет назад
github логотип
GHSA-3rf6-x59v-5jfv

dash-uploader has a directory traversal vulnerability

CVSS3: 9.8
6%
Низкий
4 месяца назад
github логотип
GHSA-3rf6-9xhv-wrqx

The Nigerias Business Directory (aka com.wNigeriasBusinessDirectory) application 0.70.13414.17619 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3rf6-9vpq-q3h4

HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

CVSS3: 4.2
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3rf6-3w37-m7h7

Adobe Photoshop CC 2018 before 19.1.6 and Photoshop CC 2017 before 18.1.6 have a memory corruption vulnerability. Successful exploitation could lead to remote code execution.

CVSS3: 9.8
6%
Низкий
больше 4 лет назад
github логотип
GHSA-3rf6-3v84-w7f8

Cross-Site Request Forgery (CSRF) vulnerability in Moriyan Jay WP Site Protector plugin <= 2.0 versions.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-3rf5-gg5c-jh3p

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may lead to arbitrary code execution.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3rf5-756g-4w3q

Online Shopping Portal v3.1 was discovered to contain multiple time-based SQL injection vulnerabilities via the email and contactno parameters.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3rf4-wqcv-f4q7

Cisco IOS 15.3 and 15.4, Cisco IOS XE 3.8 through 3.11, and Cisco Unified Communications Manager allow remote attackers to cause a denial of service (device reload) via malformed SIP messages, aka Bug ID CSCuj23293.

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-3rf4-hfh4-9ww3

There is an Input verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3rf4-9569-4jw7

The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.

14%
Средний
больше 4 лет назад
github логотип
GHSA-3rf3-mp77-8jf5

cPanel before 60.0.25 allows file-create and file-chmod operations during ModSecurity Audit logfile processing (SEC-165).

CVSS3: 8.1
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу