Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 267

Количество 359 267

github логотип

GHSA-38ch-q6jv-v6f2

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: atm: Fix NULL pointer dereference When MPOA_cache_impos_rcvd() receives the msg, it can trigger Null Pointer Dereference Vulnerability if both entry and holding_time are NULL. Because there is only for the situation where entry is NULL and holding_time exists, it can be passed when both entry and holding_time are NULL. If these are NULL, the entry will be passd to eg_cache_put() as parameter and it is referenced by entry->use code in it. kasan log: [ 3.316691] Oops: general protection fault, probably for non-canonical address 0xdffffc0000000006:I [ 3.317568] KASAN: null-ptr-deref in range [0x0000000000000030-0x0000000000000037] [ 3.318188] CPU: 3 UID: 0 PID: 79 Comm: ex Not tainted 6.14.0-rc2 #102 [ 3.318601] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014 [ 3.319298] RIP: 0010:eg_cache_remove_entry+0xa5/0x470 [ 3.319677] Code: c1 f7 6e fd 48 c7 c7 00 7e 38 b2 e8...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-38ch-ph64-r3h5

7 месяцев назад

A vulnerability was identified in code-projects Online Product Reservation System 1.0. The impacted element is an unknown function of the file /app/checkout/update.php of the component Cart Update Handler. Such manipulation of the argument id/qty leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-38cg-gg9j-q9j9

около 7 лет назад

Improper Certificate Validation and Insufficient Verification of Data Authenticity in Keycloak

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-38cc-hm43-pvfh

около 4 лет назад

Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the following: Hijack a user session Execute arbitrary commands as a root user on the underlying operating system Conduct a cross-site scripting (XSS) attack Conduct an HTML injection attack For more information about these vulnerabilities, see the Details section of this advisory.

EPSS: Низкий
github логотип

GHSA-38cc-gg86-24ch

4 месяца назад

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-38cc-cmgp-9r6v

больше 4 лет назад

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-38cc-8h76-38hf

около 2 лет назад

Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to perform privilege escalation via a crafted Chrome Extension. (Chromium security severity: Low)

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-38c9-9r7r-r27j

больше 4 лет назад

There is an illegal address access in the Eval::operator function in eval.cpp in LibSass 3.4.5. A crafted input will lead to a remote denial of service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-38c9-7h78-x2jx

28 дней назад

In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: fix race between dump and ip_set_list resize The release path of ip_set_dump_do() and ip_set_dump_done() read inst->ip_set_list via ip_set_ref_netlink(), a plain rcu_dereference_raw() of the array pointer. These run from netlink_recvmsg() without the nfnl mutex and without an RCU read-side critical section. A concurrent ip_set_create() can grow the array: it publishes the new array, calls synchronize_net() and then kvfree()s the old one. Since the dump paths read the array outside any RCU reader, synchronize_net() does not wait for them and the old array can be freed while they still index into it, causing a use-after-free. The dumped set itself stays pinned via set->ref_netlink, so only the array load needs protecting. Take rcu_read_lock() around it, matching ip_set_get_byname() and __ip_set_put_byindex(). BUG: KASAN: slab-use-after-free in ip_set_dump_do (net/netfilter/ipset/ip_set_core.c:...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-38c9-5x95-x8fq

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: spi: uniphier: fix reference count leak in uniphier_spi_probe() The issue happens in several error paths in uniphier_spi_probe(). When either dma_get_slave_caps() or devm_spi_register_master() returns an error code, the function forgets to decrease the refcount of both `dma_rx` and `dma_tx` objects, which may lead to refcount leaks. Fix it by decrementing the reference count of specific objects in those error paths.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-38c8-mw66-j237

около 4 лет назад

Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-38c8-9gf3-wcfw

12 месяцев назад

IPFire 2.29 DNS management interface (dns.cgi) fails to properly sanitize user-supplied input in the NAMESERVER, REMARK, and TLS_HOSTNAME query parameters, resulting in a reflected cross-site scripting (XSS) vulnerability.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-38c7-23hj-2wgq

6 месяцев назад

n8n has Webhook Forgery on Zendesk Trigger Node

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-38c5-q7qw-gq24

больше 4 лет назад

Multiple SQL injection vulnerabilities in the admin section in e107 0.7.5 allow remote authenticated administrative users to execute arbitrary SQL commands via the (1) linkopentype, (2) linkrender, (3) link_class, and (4) link_id parameters in (a) links.php; the (5) searchquery parameter in (b) users.php; and the (6) download_category_class parameter in (c) download.php. NOTE: an e107 developer has disputed the significance of the vulnerability, stating that "If your admins are injecting you, you might want to reconsider their access."

EPSS: Низкий
github логотип

GHSA-38c5-483c-4qqp

4 месяца назад

Grid: Integer Overflow in Grid::expand_rows Leads to Safe-API Undefined Behavior

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-38c4-r59v-3vqw

6 месяцев назад

markdown-it is has a Regular Expression Denial of Service (ReDoS)

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-38c3-wv3c-v3xj

20 дней назад

swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-38c3-mwj9-557m

больше 4 лет назад

Unspecified vulnerability in the Siebel Core - Server Framework component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote attackers to affect confidentiality via vectors related to Services, a different vulnerability than CVE-2016-5460 and CVE-2016-5466.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-38c3-hhmq-4vwf

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in Cisco Unified Operations Manager allows remote attackers to inject arbitrary web script or HTML via a crafted URL in an unspecified HTTP header field, aka Bug ID CSCud80182.

EPSS: Низкий
github логотип

GHSA-38c3-62jh-m8g6

больше 4 лет назад

An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's password via index.php?m=core&f=panel&v=edit_info.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-38ch-q6jv-v6f2

In the Linux kernel, the following vulnerability has been resolved: atm: Fix NULL pointer dereference When MPOA_cache_impos_rcvd() receives the msg, it can trigger Null Pointer Dereference Vulnerability if both entry and holding_time are NULL. Because there is only for the situation where entry is NULL and holding_time exists, it can be passed when both entry and holding_time are NULL. If these are NULL, the entry will be passd to eg_cache_put() as parameter and it is referenced by entry->use code in it. kasan log: [ 3.316691] Oops: general protection fault, probably for non-canonical address 0xdffffc0000000006:I [ 3.317568] KASAN: null-ptr-deref in range [0x0000000000000030-0x0000000000000037] [ 3.318188] CPU: 3 UID: 0 PID: 79 Comm: ex Not tainted 6.14.0-rc2 #102 [ 3.318601] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014 [ 3.319298] RIP: 0010:eg_cache_remove_entry+0xa5/0x470 [ 3.319677] Code: c1 f7 6e fd 48 c7 c7 00 7e 38 b2 e8...

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-38ch-ph64-r3h5

A vulnerability was identified in code-projects Online Product Reservation System 1.0. The impacted element is an unknown function of the file /app/checkout/update.php of the component Cart Update Handler. Such manipulation of the argument id/qty leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

CVSS3: 6.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-38cg-gg9j-q9j9

Improper Certificate Validation and Insufficient Verification of Data Authenticity in Keycloak

CVSS3: 4.8
0%
Низкий
около 7 лет назад
github логотип
GHSA-38cc-hm43-pvfh

Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the following: Hijack a user session Execute arbitrary commands as a root user on the underlying operating system Conduct a cross-site scripting (XSS) attack Conduct an HTML injection attack For more information about these vulnerabilities, see the Details section of this advisory.

10%
Низкий
около 4 лет назад
github логотип
GHSA-38cc-gg86-24ch

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
4 месяца назад
github логотип
GHSA-38cc-cmgp-9r6v

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 6.5
9%
Низкий
больше 4 лет назад
github логотип
GHSA-38cc-8h76-38hf

Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to perform privilege escalation via a crafted Chrome Extension. (Chromium security severity: Low)

CVSS3: 6.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-38c9-9r7r-r27j

There is an illegal address access in the Eval::operator function in eval.cpp in LibSass 3.4.5. A crafted input will lead to a remote denial of service.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-38c9-7h78-x2jx

In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: fix race between dump and ip_set_list resize The release path of ip_set_dump_do() and ip_set_dump_done() read inst->ip_set_list via ip_set_ref_netlink(), a plain rcu_dereference_raw() of the array pointer. These run from netlink_recvmsg() without the nfnl mutex and without an RCU read-side critical section. A concurrent ip_set_create() can grow the array: it publishes the new array, calls synchronize_net() and then kvfree()s the old one. Since the dump paths read the array outside any RCU reader, synchronize_net() does not wait for them and the old array can be freed while they still index into it, causing a use-after-free. The dumped set itself stays pinned via set->ref_netlink, so only the array load needs protecting. Take rcu_read_lock() around it, matching ip_set_get_byname() and __ip_set_put_byindex(). BUG: KASAN: slab-use-after-free in ip_set_dump_do (net/netfilter/ipset/ip_set_core.c:...

CVSS3: 7.8
0%
Низкий
28 дней назад
github логотип
GHSA-38c9-5x95-x8fq

In the Linux kernel, the following vulnerability has been resolved: spi: uniphier: fix reference count leak in uniphier_spi_probe() The issue happens in several error paths in uniphier_spi_probe(). When either dma_get_slave_caps() or devm_spi_register_master() returns an error code, the function forgets to decrease the refcount of both `dma_rx` and `dma_tx` objects, which may lead to refcount leaks. Fix it by decrementing the reference count of specific objects in those error paths.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-38c8-mw66-j237

Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
65%
Средний
около 4 лет назад
github логотип
GHSA-38c8-9gf3-wcfw

IPFire 2.29 DNS management interface (dns.cgi) fails to properly sanitize user-supplied input in the NAMESERVER, REMARK, and TLS_HOSTNAME query parameters, resulting in a reflected cross-site scripting (XSS) vulnerability.

CVSS3: 6.1
0%
Низкий
12 месяцев назад
github логотип
GHSA-38c7-23hj-2wgq

n8n has Webhook Forgery on Zendesk Trigger Node

CVSS3: 4
6 месяцев назад
github логотип
GHSA-38c5-q7qw-gq24

Multiple SQL injection vulnerabilities in the admin section in e107 0.7.5 allow remote authenticated administrative users to execute arbitrary SQL commands via the (1) linkopentype, (2) linkrender, (3) link_class, and (4) link_id parameters in (a) links.php; the (5) searchquery parameter in (b) users.php; and the (6) download_category_class parameter in (c) download.php. NOTE: an e107 developer has disputed the significance of the vulnerability, stating that "If your admins are injecting you, you might want to reconsider their access."

1%
Низкий
больше 4 лет назад
github логотип
GHSA-38c5-483c-4qqp

Grid: Integer Overflow in Grid::expand_rows Leads to Safe-API Undefined Behavior

CVSS3: 6.2
0%
Низкий
4 месяца назад
github логотип
GHSA-38c4-r59v-3vqw

markdown-it is has a Regular Expression Denial of Service (ReDoS)

CVSS3: 5.3
1%
Низкий
6 месяцев назад
github логотип
GHSA-38c3-wv3c-v3xj

swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template

CVSS3: 8.3
0%
Низкий
20 дней назад
github логотип
GHSA-38c3-mwj9-557m

Unspecified vulnerability in the Siebel Core - Server Framework component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote attackers to affect confidentiality via vectors related to Services, a different vulnerability than CVE-2016-5460 and CVE-2016-5466.

CVSS3: 3.7
2%
Низкий
больше 4 лет назад
github логотип
GHSA-38c3-hhmq-4vwf

Cross-site scripting (XSS) vulnerability in Cisco Unified Operations Manager allows remote attackers to inject arbitrary web script or HTML via a crafted URL in an unspecified HTTP header field, aka Bug ID CSCud80182.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-38c3-62jh-m8g6

An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's password via index.php?m=core&f=panel&v=edit_info.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу