Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 362 385

Количество 362 385

github логотип

GHSA-3hjh-p587-3c92

около 3 лет назад

A vulnerability classified as problematic has been found in Bug Finder MineStack 1.0. This affects an unknown part of the file /user/ticket/create of the component Ticket Handler. The manipulation of the argument message leads to cross site scripting. It is possible to initiate the attack remotely. The identifier VDB-235161 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-3hjh-jh2h-vrg6

около 2 лет назад

Denial of service in langchain-community

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-3hjh-cjx8-8c83

около 1 года назад

A flaw was found in the Linux kernel's ksmbd component. A memory leak can occur if a client sends a session setup request with an unknown NTLMSSP message type, potentially leading to resource exhaustion.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3hjh-9vcg-w788

больше 4 лет назад

libautotrace.a in AutoTrace 0.31.1 has a "cannot be represented in type int" issue in input-bmp.c:309:7.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3hjh-72vp-2mx6

больше 4 лет назад

The web interface in BitTorrent allows remote attackers to execute arbitrary commands by leveraging knowledge of the pairing values and a crafted request to port 10000.

EPSS: Низкий
github логотип

GHSA-3hjh-5hgx-f5wh

больше 3 лет назад

Path traversal vulnerability in glance

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3hjh-36cf-mgj5

около 1 года назад

Improper array index verification vulnerability in the audio codec module. Impact: Successful exploitation of this vulnerability may affect the audio decoding function.

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-3hjg-vc7r-rcrw

больше 4 лет назад

Denial of Service vulnerability in @podium/layout and @podium/proxy

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3hjg-cghv-22ww

больше 3 лет назад

org.xwiki.platform:xwiki-platform-attachment-ui vulnerable to Code Injection

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3hjg-c8jc-c68f

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in Invision Power Board 2.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via an IFRAME tag in the signature.

EPSS: Низкий
github логотип

GHSA-3hjf-m6vc-vh7h

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: btrfs: don't BUG_ON on ENOMEM from btrfs_lookup_extent_info() in walk_down_proc() We handle errors here properly, ENOMEM isn't fatal, return the error.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3hjf-h43w-9frf

больше 2 лет назад

PDF-XChange Editor Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-20891.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-3hjc-gv2m-96gh

около 3 лет назад

Windows SMB Witness Service Security Feature Bypass Vulnerability

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3hjc-876w-6wxx

4 месяца назад

A weakness has been identified in Open5GS up to 2.7.7. Affected is the function ogs_id_get_value of the file /src/amf/nudm-handler.c of the component AMF. This manipulation causes denial of service. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3hj9-v3ch-6rc4

больше 4 лет назад

In __wlan_hdd_cfg80211_vendor_scan(), a buffer overwrite can potentially occur in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3hj8-gm24-v3p6

4 месяца назад

Rejected reason: This CVE has the been REJECTED and will not be published by the CNA.

EPSS: Низкий
github логотип

GHSA-3hj8-7626-3gc8

больше 4 лет назад

Buffer overflow vulnerability in Core FTP Server v1.2 Build 583, via a crafted username.

EPSS: Низкий
github логотип

GHSA-3hj7-rw79-jh5m

10 месяцев назад

Improper locking vulnerability in Softing Industrial Automation GmbH gateways allows infected memory and/or resource leak exposure.This issue affects smartLink HW-PN: from 1.02 through 1.03 smartLink HW-DP: 1.31

EPSS: Низкий
github логотип

GHSA-3hj7-97m3-822h

больше 4 лет назад

Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "/VPortal/mgtconsole/Subscribers.jsp" has reflected XSS via the ConnPoolName or GroupId parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3hj6-r5c9-q8f3

больше 1 года назад

Frappe has possibility of SQL injection due to improper validations

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3hjh-p587-3c92

A vulnerability classified as problematic has been found in Bug Finder MineStack 1.0. This affects an unknown part of the file /user/ticket/create of the component Ticket Handler. The manipulation of the argument message leads to cross site scripting. It is possible to initiate the attack remotely. The identifier VDB-235161 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-3hjh-jh2h-vrg6

Denial of service in langchain-community

CVSS3: 4.2
0%
Низкий
около 2 лет назад
github логотип
GHSA-3hjh-cjx8-8c83

A flaw was found in the Linux kernel's ksmbd component. A memory leak can occur if a client sends a session setup request with an unknown NTLMSSP message type, potentially leading to resource exhaustion.

CVSS3: 5.3
0%
Низкий
около 1 года назад
github логотип
GHSA-3hjh-9vcg-w788

libautotrace.a in AutoTrace 0.31.1 has a "cannot be represented in type int" issue in input-bmp.c:309:7.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3hjh-72vp-2mx6

The web interface in BitTorrent allows remote attackers to execute arbitrary commands by leveraging knowledge of the pairing values and a crafted request to port 10000.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3hjh-5hgx-f5wh

Path traversal vulnerability in glance

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3hjh-36cf-mgj5

Improper array index verification vulnerability in the audio codec module. Impact: Successful exploitation of this vulnerability may affect the audio decoding function.

CVSS3: 4.2
0%
Низкий
около 1 года назад
github логотип
GHSA-3hjg-vc7r-rcrw

Denial of Service vulnerability in @podium/layout and @podium/proxy

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3hjg-cghv-22ww

org.xwiki.platform:xwiki-platform-attachment-ui vulnerable to Code Injection

CVSS3: 8.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3hjg-c8jc-c68f

Cross-site scripting (XSS) vulnerability in Invision Power Board 2.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via an IFRAME tag in the signature.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3hjf-m6vc-vh7h

In the Linux kernel, the following vulnerability has been resolved: btrfs: don't BUG_ON on ENOMEM from btrfs_lookup_extent_info() in walk_down_proc() We handle errors here properly, ENOMEM isn't fatal, return the error.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-3hjf-h43w-9frf

PDF-XChange Editor Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. By performing actions in JavaScript, an attacker can trigger a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-20891.

CVSS3: 3.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3hjc-gv2m-96gh

Windows SMB Witness Service Security Feature Bypass Vulnerability

CVSS3: 7.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-3hjc-876w-6wxx

A weakness has been identified in Open5GS up to 2.7.7. Affected is the function ogs_id_get_value of the file /src/amf/nudm-handler.c of the component AMF. This manipulation causes denial of service. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 4.3
0%
Низкий
4 месяца назад
github логотип
GHSA-3hj9-v3ch-6rc4

In __wlan_hdd_cfg80211_vendor_scan(), a buffer overwrite can potentially occur in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3hj8-gm24-v3p6

Rejected reason: This CVE has the been REJECTED and will not be published by the CNA.

4 месяца назад
github логотип
GHSA-3hj8-7626-3gc8

Buffer overflow vulnerability in Core FTP Server v1.2 Build 583, via a crafted username.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3hj7-rw79-jh5m

Improper locking vulnerability in Softing Industrial Automation GmbH gateways allows infected memory and/or resource leak exposure.This issue affects smartLink HW-PN: from 1.02 through 1.03 smartLink HW-DP: 1.31

0%
Низкий
10 месяцев назад
github логотип
GHSA-3hj7-97m3-822h

Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "/VPortal/mgtconsole/Subscribers.jsp" has reflected XSS via the ConnPoolName or GroupId parameter.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3hj6-r5c9-q8f3

Frappe has possibility of SQL injection due to improper validations

0%
Низкий
больше 1 года назад

Уязвимостей на страницу