Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 362 078

Количество 362 078

github логотип

GHSA-3gmf-p6r4-q8m6

4 месяца назад

Apache Wicket has a Path Traversal issue

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3gmf-h2jg-hwv2

13 дней назад

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Check bounds in allocate_event_notification_slot The valid event ids go from 0 to KFD_SIGNAL_EVENT_LIMIT allocate_event_notification_slot has an option to specify an event id to allocate at, used by CRIU. We weren't checking the bounds on that value. Check them. v2: Lower bounds check is unecessary because of idr_alloc already rejecting negative numbers. Upper bounds check should be KFD_SIGNAL_EVENT_LIMIT since the signal mode mappings might not yet exist (cherry picked from commit 6853f1f6cbbeb3f53ebbbd7286536aeb2c5d5f50)

EPSS: Низкий
github логотип

GHSA-3gmf-fq2f-gwph

больше 1 года назад

Mailcow through 2024-11b has a session fixation vulnerability in the web panel. It allows remote attackers to set a session identifier when HSTS is disabled on a victim's browser. After a user logs in, they are authenticated and the session identifier is valid. Then, a remote attacker can access the victim's web panel with the same session identifier.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3gmf-fmhc-5qv9

больше 4 лет назад

The tubepress plugin before 1.6.5 for WordPress has XSS.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3gmf-2qwv-jgjx

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in index.php in TomatoCMS before 2.0.5 allow remote authenticated users, with certain creation privileges, to inject arbitrary web script or HTML via the (1) content parameter in conjunction with a /admin/poll/add PATH_INFO, the (2) meta parameter in conjunction with a /admin/category/add PATH_INFO, and the (3) keyword parameter in conjunction with a /admin/tag/add PATH_INFO.

EPSS: Низкий
github логотип

GHSA-3gmf-2m92-wrxq

7 месяцев назад

A vulnerability was determined in Free5GC up to 4.1.0. The impacted element is the function establishPfcpSession of the component SMF. Executing a manipulation can lead to null pointer dereference. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. It is best practice to apply a patch to resolve this issue.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3gm9-q84v-wvvw

больше 3 лет назад

Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3gm9-hwp2-84jv

больше 4 лет назад

Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3189.

EPSS: Средний
github логотип

GHSA-3gm9-977v-wxgv

больше 4 лет назад

IrfanView version 4.44 (32bit) has a "Data from Faulting Address controls Branch Selection starting at USER32!wvsprintfA+0x00000000000002f3" issue, which might allow attackers to execute arbitrary code via a crafted file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3gm8-9xxm-pmhh

около 4 лет назад

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2020 1.01rc001 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the webproc endpoint, which listens on TCP port 80 by default. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-12104.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3gm8-32vv-q8mp

больше 4 лет назад

Moodle Cross-site Scripting vulnerability in the KSES text cleaning filter

EPSS: Низкий
github логотип

GHSA-3gm8-2237-qv79

больше 4 лет назад

CubeCart 6.2.2 has Reflected XSS via a /{ADMIN-FILE}/ query string.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3gm7-x7gh-qcvp

больше 2 лет назад

The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘eae_custom_overlay_switcher’ attribute of the Thumbnail Slider widget in all versions up to, and including, 1.12.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-3gm7-v7vw-866c

около 7 лет назад

XML External Entity (XXE) Injection in Apache Solr

CVSS3: 7.2
EPSS: Высокий
github логотип

GHSA-3gm7-pcqj-26pm

больше 4 лет назад

Microsoft Edge allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via a crafted document, aka "Microsoft Edge Security Feature Bypass."

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-3gm7-cvc6-7rch

около 1 года назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

EPSS: Низкий
github логотип

GHSA-3gm7-8cfv-p8h9

больше 4 лет назад

The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-0169.

CVSS3: 5.9
EPSS: Высокий
github логотип

GHSA-3gm7-2gq6-fqjf

11 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: dmaengine: qcom: bam_dma: Fix DT error handling for num-channels/ees When we don't have a clock specified in the device tree, we have no way to ensure the BAM is on. This is often the case for remotely-controlled or remotely-powered BAM instances. In this case, we need to read num-channels from the DT to have all the necessary information to complete probing. However, at the moment invalid device trees without clock and without num-channels still continue probing, because the error handling is missing return statements. The driver will then later try to read the number of channels from the registers. This is unsafe, because it relies on boot firmware and lucky timing to succeed. Unfortunately, the lack of proper error handling here has been abused for several Qualcomm SoCs upstream, causing early boot crashes in several situations [1, 2]. Avoid these early crashes by erroring out when any of the required DT prop...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3gm6-xhv6-72q8

больше 4 лет назад

FreeBSD 7.1 through 8.1-PRERELEASE does not copy the read-only flag when creating a duplicate mbuf buffer reference, which allows local users to cause a denial of service (system file corruption) and gain privileges via the sendfile system call.

EPSS: Низкий
github логотип

GHSA-3gm6-f563-mhj8

около 1 года назад

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3gmf-p6r4-q8m6

Apache Wicket has a Path Traversal issue

CVSS3: 6.5
1%
Низкий
4 месяца назад
github логотип
GHSA-3gmf-h2jg-hwv2

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Check bounds in allocate_event_notification_slot The valid event ids go from 0 to KFD_SIGNAL_EVENT_LIMIT allocate_event_notification_slot has an option to specify an event id to allocate at, used by CRIU. We weren't checking the bounds on that value. Check them. v2: Lower bounds check is unecessary because of idr_alloc already rejecting negative numbers. Upper bounds check should be KFD_SIGNAL_EVENT_LIMIT since the signal mode mappings might not yet exist (cherry picked from commit 6853f1f6cbbeb3f53ebbbd7286536aeb2c5d5f50)

0%
Низкий
13 дней назад
github логотип
GHSA-3gmf-fq2f-gwph

Mailcow through 2024-11b has a session fixation vulnerability in the web panel. It allows remote attackers to set a session identifier when HSTS is disabled on a victim's browser. After a user logs in, they are authenticated and the session identifier is valid. Then, a remote attacker can access the victim's web panel with the same session identifier.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3gmf-fmhc-5qv9

The tubepress plugin before 1.6.5 for WordPress has XSS.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3gmf-2qwv-jgjx

Multiple cross-site scripting (XSS) vulnerabilities in index.php in TomatoCMS before 2.0.5 allow remote authenticated users, with certain creation privileges, to inject arbitrary web script or HTML via the (1) content parameter in conjunction with a /admin/poll/add PATH_INFO, the (2) meta parameter in conjunction with a /admin/category/add PATH_INFO, and the (3) keyword parameter in conjunction with a /admin/tag/add PATH_INFO.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3gmf-2m92-wrxq

A vulnerability was determined in Free5GC up to 4.1.0. The impacted element is the function establishPfcpSession of the component SMF. Executing a manipulation can lead to null pointer dereference. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. It is best practice to apply a patch to resolve this issue.

CVSS3: 5.3
1%
Низкий
7 месяцев назад
github логотип
GHSA-3gm9-q84v-wvvw

Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-3gm9-hwp2-84jv

Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3189.

28%
Средний
больше 4 лет назад
github логотип
GHSA-3gm9-977v-wxgv

IrfanView version 4.44 (32bit) has a "Data from Faulting Address controls Branch Selection starting at USER32!wvsprintfA+0x00000000000002f3" issue, which might allow attackers to execute arbitrary code via a crafted file.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3gm8-9xxm-pmhh

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2020 1.01rc001 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the webproc endpoint, which listens on TCP port 80 by default. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-12104.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-3gm8-32vv-q8mp

Moodle Cross-site Scripting vulnerability in the KSES text cleaning filter

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3gm8-2237-qv79

CubeCart 6.2.2 has Reflected XSS via a /{ADMIN-FILE}/ query string.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3gm7-x7gh-qcvp

The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘eae_custom_overlay_switcher’ attribute of the Thumbnail Slider widget in all versions up to, and including, 1.12.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3gm7-v7vw-866c

XML External Entity (XXE) Injection in Apache Solr

CVSS3: 7.2
84%
Высокий
около 7 лет назад
github логотип
GHSA-3gm7-pcqj-26pm

Microsoft Edge allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via a crafted document, aka "Microsoft Edge Security Feature Bypass."

CVSS3: 6.5
32%
Средний
больше 4 лет назад
github логотип
GHSA-3gm7-cvc6-7rch

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

около 1 года назад
github логотип
GHSA-3gm7-8cfv-p8h9

The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-0169.

CVSS3: 5.9
89%
Высокий
больше 4 лет назад
github логотип
GHSA-3gm7-2gq6-fqjf

In the Linux kernel, the following vulnerability has been resolved: dmaengine: qcom: bam_dma: Fix DT error handling for num-channels/ees When we don't have a clock specified in the device tree, we have no way to ensure the BAM is on. This is often the case for remotely-controlled or remotely-powered BAM instances. In this case, we need to read num-channels from the DT to have all the necessary information to complete probing. However, at the moment invalid device trees without clock and without num-channels still continue probing, because the error handling is missing return statements. The driver will then later try to read the number of channels from the registers. This is unsafe, because it relies on boot firmware and lucky timing to succeed. Unfortunately, the lack of proper error handling here has been abused for several Qualcomm SoCs upstream, causing early boot crashes in several situations [1, 2]. Avoid these early crashes by erroring out when any of the required DT prop...

CVSS3: 5.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-3gm6-xhv6-72q8

FreeBSD 7.1 through 8.1-PRERELEASE does not copy the read-only flag when creating a duplicate mbuf buffer reference, which allows local users to cause a denial of service (system file corruption) and gain privileges via the sendfile system call.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3gm6-f563-mhj8

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
около 1 года назад

Уязвимостей на страницу