Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 364 867

Количество 364 867

github логотип

GHSA-3qwv-9mh7-f8fm

23 дня назад

In the Linux kernel, the following vulnerability has been resolved: smb/client: Fix error code in smb2_aead_req_alloc() The "*num_sgs" variable is a u32 so "ERR_PTR(*num_sgs)" doesn't work. We would have to do something similar to the previous line where it's cast to int and then long. However, it's simpler to store the return in an int ret variable. This bug would eventually result in a crash when dereference the invalid error pointer.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3qwv-82r7-qfr8

больше 4 лет назад

In JFrog Artifactory before 6.18, it is not possible to restrict either system or repository imports by any admin user in the enterprise, which can lead to "undesirable results."

EPSS: Низкий
github логотип

GHSA-3qwr-mfh2-wggm

больше 4 лет назад

The Sophos UTM VPN endpoint interacts with client software provided by NPC Engineering (www.ncp-e.com). The affected client software, "Sophos IPSec Client" 11.04 is a rebranded version of NCP "Secure Entry Client" 10.11 r32792. A vulnerability in the software update feature of the VPN client allows a man-in-the-middle (MITM) or man-on-the-side (MOTS) attacker to execute arbitrary, malicious software on a target user's computer. This is related to SIC_V11.04-64.exe (Sophos), NCP_EntryCl_Windows_x86_1004_31799.exe (NCP), and ncpmon.exe (both Sophos and NCP). The vulnerability exists because: (1) the VPN client requests update metadata over an insecure HTTP connection; and (2) the client software does not check if the software update is signed before running it.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3qwr-jvvx-5665

больше 4 лет назад

checkinstall 1.6.2, when used to create a package that contains a symlink, may trigger the creation of a mode 0777 executable file.

EPSS: Низкий
github логотип

GHSA-3qwr-42gg-9mx6

24 дня назад

The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.16. This is due to missing or incorrect nonce validation on the `process_bulk_action()` function of `MWTSA_Stats_Table`. This makes it possible for unauthenticated attackers to delete arbitrary search-term records, including all associated search-history rows, via a forged request granted they can trick a user with access to the plugin's "Search Analytics" dashboard page (Administrator by default) into performing an action such as clicking on a link.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3qwq-q9vm-5j42

5 месяцев назад

Spring Cloud Config Server: Path Traversal via Profile Parameter Allows Arbitrary File Access

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-3qwq-pwj3-576h

6 месяцев назад

In multiple functions of btm_ble_sec.cc, there is a possible unencrypted communication due to Invalid error handling. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3qwq-p88c-9vwf

больше 4 лет назад

/var/lib/ovirt-engine/setup/engine-DC-config.py in Red Hat QuickStart Cloud Installer (QCI) before 1.0 GA is created world readable and contains the root password of the deployed system.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3qwq-8wfq-2pfc

больше 4 лет назад

The Countdown Block WordPress plugin before 1.1.2 does not have authorisation in the eb_write_block_css AJAX action, which allows any authenticated user, such as Subscriber, to modify post contents displayed to users.

EPSS: Низкий
github логотип

GHSA-3qwm-q2c3-qv6x

больше 4 лет назад

IBM UrbanCode Deploy (UCD) 7.0.5 could allow a user with special permissions to obtain sensitive information via generic processes. IBM X-Force ID: 175639.

EPSS: Низкий
github логотип

GHSA-3qwj-q697-4ppr

около 2 месяцев назад

U-Boot through 2026.04-rc3 contains an integer underflow vulnerability in the tcp_rx_state_machine() function (net/tcp.c) that allows a network-adjacent attacker to crash the bootloader by sending a malformed TCP SYN+ACK packet with a manipulated data offset field causing payload_len to become negative. When the TCP_SYN_SENT handler calls tcp_rx_user_data() without invoking tcp_seg_in_wnd() validation, the negative payload_len is implicitly converted to a large unsigned integer (e.g., 0xFFFFFFD8) and passed to memcpy() in store_block(), causing an immediate crash that prevents device boot and may enable memory corruption when CONFIG_LMB is disabled.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3qwj-pv6x-95j3

больше 4 лет назад

The trace functionality in libvdpau before 1.1.1, when used in a setuid or setgid application, allows local users to write to arbitrary files via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3qwj-cx3m-c3pj

больше 2 лет назад

SmartStar Software CWS is a web-based integration platform, it has a vulnerability of missing authorization and users are able to access data or perform actions that they should not be allowed to perform via commands. An authenticated with normal user privilege can execute administrator privilege, resulting in performing arbitrary system operations or disrupting service.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3qwj-7p4f-cf9r

больше 4 лет назад

platform/msm_shared/partition_parser.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 and 7 (2013) devices does not validate certain GUID Partition Table (GPT) data, which allows attackers to bypass intended access restrictions via a crafted MultiMediaCard (MMC), aka Android internal bug 28822878 and Qualcomm internal bug CR823461.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3qwh-w55v-784g

больше 4 лет назад

Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter.

EPSS: Средний
github логотип

GHSA-3qwh-j562-h8h6

почти 3 года назад

Path transversal in some Intel(R) NUC Kits NUC7i3DN, NUC7i5DN, NUC7i7DN HDMI firmware update tool software before version 1.79.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3qwh-g5rx-3xc3

больше 4 лет назад

Unspecified vulnerability in HP WebInspect 7.x through 10.4 before 10.4 update 1 allows remote authenticated users to bypass intended access restrictions via unknown vectors.

EPSS: Низкий
github логотип

GHSA-3qwg-vch4-4r45

больше 4 лет назад

A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcScreenSaverSuspend function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3qwg-rjm5-wq8p

больше 1 года назад

in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-3qwg-qhg3-83g6

больше 4 лет назад

In a display driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, a variable controlled by userspace is used to calculate offsets and sizes for copy operations, which could result in heap overflow.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3qwv-9mh7-f8fm

In the Linux kernel, the following vulnerability has been resolved: smb/client: Fix error code in smb2_aead_req_alloc() The "*num_sgs" variable is a u32 so "ERR_PTR(*num_sgs)" doesn't work. We would have to do something similar to the previous line where it's cast to int and then long. However, it's simpler to store the return in an int ret variable. This bug would eventually result in a crash when dereference the invalid error pointer.

CVSS3: 8.8
0%
Низкий
23 дня назад
github логотип
GHSA-3qwv-82r7-qfr8

In JFrog Artifactory before 6.18, it is not possible to restrict either system or repository imports by any admin user in the enterprise, which can lead to "undesirable results."

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3qwr-mfh2-wggm

The Sophos UTM VPN endpoint interacts with client software provided by NPC Engineering (www.ncp-e.com). The affected client software, "Sophos IPSec Client" 11.04 is a rebranded version of NCP "Secure Entry Client" 10.11 r32792. A vulnerability in the software update feature of the VPN client allows a man-in-the-middle (MITM) or man-on-the-side (MOTS) attacker to execute arbitrary, malicious software on a target user's computer. This is related to SIC_V11.04-64.exe (Sophos), NCP_EntryCl_Windows_x86_1004_31799.exe (NCP), and ncpmon.exe (both Sophos and NCP). The vulnerability exists because: (1) the VPN client requests update metadata over an insecure HTTP connection; and (2) the client software does not check if the software update is signed before running it.

CVSS3: 8.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3qwr-jvvx-5665

checkinstall 1.6.2, when used to create a package that contains a symlink, may trigger the creation of a mode 0777 executable file.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3qwr-42gg-9mx6

The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.16. This is due to missing or incorrect nonce validation on the `process_bulk_action()` function of `MWTSA_Stats_Table`. This makes it possible for unauthenticated attackers to delete arbitrary search-term records, including all associated search-history rows, via a forged request granted they can trick a user with access to the plugin's "Search Analytics" dashboard page (Administrator by default) into performing an action such as clicking on a link.

CVSS3: 8.1
0%
Низкий
24 дня назад
github логотип
GHSA-3qwq-q9vm-5j42

Spring Cloud Config Server: Path Traversal via Profile Parameter Allows Arbitrary File Access

CVSS3: 8.6
1%
Низкий
5 месяцев назад
github логотип
GHSA-3qwq-pwj3-576h

In multiple functions of btm_ble_sec.cc, there is a possible unencrypted communication due to Invalid error handling. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-3qwq-p88c-9vwf

/var/lib/ovirt-engine/setup/engine-DC-config.py in Red Hat QuickStart Cloud Installer (QCI) before 1.0 GA is created world readable and contains the root password of the deployed system.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3qwq-8wfq-2pfc

The Countdown Block WordPress plugin before 1.1.2 does not have authorisation in the eb_write_block_css AJAX action, which allows any authenticated user, such as Subscriber, to modify post contents displayed to users.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3qwm-q2c3-qv6x

IBM UrbanCode Deploy (UCD) 7.0.5 could allow a user with special permissions to obtain sensitive information via generic processes. IBM X-Force ID: 175639.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3qwj-q697-4ppr

U-Boot through 2026.04-rc3 contains an integer underflow vulnerability in the tcp_rx_state_machine() function (net/tcp.c) that allows a network-adjacent attacker to crash the bootloader by sending a malformed TCP SYN+ACK packet with a manipulated data offset field causing payload_len to become negative. When the TCP_SYN_SENT handler calls tcp_rx_user_data() without invoking tcp_seg_in_wnd() validation, the negative payload_len is implicitly converted to a large unsigned integer (e.g., 0xFFFFFFD8) and passed to memcpy() in store_block(), causing an immediate crash that prevents device boot and may enable memory corruption when CONFIG_LMB is disabled.

CVSS3: 7.5
1%
Низкий
около 2 месяцев назад
github логотип
GHSA-3qwj-pv6x-95j3

The trace functionality in libvdpau before 1.1.1, when used in a setuid or setgid application, allows local users to write to arbitrary files via unspecified vectors.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3qwj-cx3m-c3pj

SmartStar Software CWS is a web-based integration platform, it has a vulnerability of missing authorization and users are able to access data or perform actions that they should not be allowed to perform via commands. An authenticated with normal user privilege can execute administrator privilege, resulting in performing arbitrary system operations or disrupting service.

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3qwj-7p4f-cf9r

platform/msm_shared/partition_parser.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 and 7 (2013) devices does not validate certain GUID Partition Table (GPT) data, which allows attackers to bypass intended access restrictions via a crafted MultiMediaCard (MMC), aka Android internal bug 28822878 and Qualcomm internal bug CR823461.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3qwh-w55v-784g

Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter.

61%
Средний
больше 4 лет назад
github логотип
GHSA-3qwh-j562-h8h6

Path transversal in some Intel(R) NUC Kits NUC7i3DN, NUC7i5DN, NUC7i7DN HDMI firmware update tool software before version 1.79.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 6.7
0%
Низкий
почти 3 года назад
github логотип
GHSA-3qwh-g5rx-3xc3

Unspecified vulnerability in HP WebInspect 7.x through 10.4 before 10.4 update 1 allows remote authenticated users to bypass intended access restrictions via unknown vectors.

8%
Низкий
больше 4 лет назад
github логотип
GHSA-3qwg-vch4-4r45

A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcScreenSaverSuspend function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3qwg-rjm5-wq8p

in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.

CVSS3: 3.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3qwg-qhg3-83g6

In a display driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, a variable controlled by userspace is used to calculate offsets and sizes for copy operations, which could result in heap overflow.

CVSS3: 8.8
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу