Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 267

Количество 359 267

github логотип

GHSA-3883-h64p-r3xm

около 3 лет назад

There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled “Allow public signup”.

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-3882-vm2r-v25j

около 4 лет назад

Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.18, 2.4.x prior to 2.4.14, 2.5.x prior to 2.5.10, and 2.6.x prior to 2.6.5, contains an invitations microservice which allows users to invite others to their organizations. A remote authenticated user can gain additional privileges by inviting themselves to spaces that they should not have access to.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3882-cp3m-6576

около 4 лет назад

Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. Lack of input sanitization in the upload mechanism is leads to reflected XSS.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-387x-jwqw-43f3

больше 4 лет назад

Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 2.2.2 allows remote attackers to affect integrity via unknown vectors related to Oracle Endeca Information Discovery (Formerly Latitude), a different vulnerability than CVE-2014-2400.

EPSS: Низкий
github логотип

GHSA-387x-hprp-5mf9

около 4 лет назад

This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.1-47117. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the xHCI component. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the hypervisor. Was ZDI-CAN-9428.

EPSS: Низкий
github логотип

GHSA-387w-v9hj-ph2g

около 4 лет назад

Machform prior to version 16 is vulnerable to an open redirect in Safari_init.php due to an improperly sanitized 'ref' parameter.

EPSS: Низкий
github логотип

GHSA-387w-9mx8-66cc

3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: 9p/xen: protect xen_9pfs_front_free against concurrent calls The xenwatch thread can race with other back-end change notifications and call xen_9pfs_front_free() twice, hitting the observed general protection fault due to a double-free. Guard the teardown path so only one caller can release the front-end state at a time, preventing the crash. This is a fix for the following double-free: [ 27.052347] Oops: general protection fault, probably for non-canonical address 0x6b6b6b6b6b6b6b6b: 0000 [#1] SMP DEBUG_PAGEALLOC NOPTI [ 27.052357] CPU: 0 UID: 0 PID: 32 Comm: xenwatch Not tainted 6.18.0-02087-g51ab33fc0a8b-dirty #60 PREEMPT(none) [ 27.052363] RIP: e030:xen_9pfs_front_free+0x1d/0x150 [ 27.052368] Code: 90 90 90 90 90 90 90 90 90 90 90 90 90 41 55 41 54 55 48 89 fd 48 c7 c7 48 d0 92 85 53 e8 cb cb 05 00 48 8b 45 08 48 8b 55 00 <48> 3b 28 0f 85 f9 28 35 fe 48 3b 6a 08 0f 85 ef 28 35 fe 48 89 42 [ 27.0523...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-387v-qw2x-rwg8

больше 1 года назад

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An attacker in a privileged position may be able to perform a denial-of-service.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-387v-pw76-m864

больше 4 лет назад

Buffer overflow in the IDENT daemon (identd) in Trillian 0.6351, 0.725, 0.73, 0.74 and 1.0 pro allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long request.

EPSS: Низкий
github логотип

GHSA-387v-g9vc-rrrf

больше 2 лет назад

Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 26.6.1.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-387v-84cv-9qmc

почти 8 лет назад

Improper Limitation of a Pathname ('Path Traversal') in org.apache.solr:solr-core

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-387r-w9pc-hjv4

8 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in artplacer ArtPlacer Widget artplacer-widget allows Blind SQL Injection.This issue affects ArtPlacer Widget: from n/a through <= 2.22.9.2.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-387q-wvj8-w6gg

больше 4 лет назад

An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0. A specifically crafted pdf can cause an image resizing after allocation has already occurred, resulting in heap corruption which can lead to code execution. An attacker controlled PDF file can be used to trigger this vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-387q-w9v4-q6qm

больше 4 лет назад

Integer overflow in the dissect_iscsi_pdu function in epan/dissectors/packet-iscsi.c in the iSCSI dissector in Wireshark 1.6.x before 1.6.12 and 1.8.x before 1.8.4 allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.

EPSS: Низкий
github логотип

GHSA-387q-r347-qf62

11 месяцев назад

A reflected cross-site scripted (XSS) vulnerability in the /admin/system/packages endpoint of Luci OpenWRT v18.06.2 allows attackers to execute arbitrary Javascript in the context of a user's browser via a crafted payload.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-387m-j3p9-3php

6 месяцев назад

NocoDB Vulnerable to User Enumeration via Password Reset Endpoint

EPSS: Низкий
github логотип

GHSA-387m-935m-c4vw

около 1 месяца назад

Micronaut doesn't set a maximum redirect count for its HTTP Client, enabling infinite loop DoS

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-387j-r6x5-3c3w

больше 4 лет назад

SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core/admin/modules/developer/modules/views/create.php. The attacker creates a crafted table name at admin/developer/modules/views/create/ and the injection is visible at admin/ajax/auto-modules/views/searchable-page/ or admin/modules_name.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-387j-qwmj-3pww

больше 4 лет назад

Buffer overflow in ccn-lite-ccnb2xml.c in CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact via vectors involving the vallen and len variables.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-387j-9qrx-3rh5

больше 4 лет назад

Unspecified vulnerability in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted H.263 encoded movie file that triggers memory corruption.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3883-h64p-r3xm

There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled “Allow public signup”.

CVSS3: 9.8
98%
Критический
около 3 лет назад
github логотип
GHSA-3882-vm2r-v25j

Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.18, 2.4.x prior to 2.4.14, 2.5.x prior to 2.5.10, and 2.6.x prior to 2.6.5, contains an invitations microservice which allows users to invite others to their organizations. A remote authenticated user can gain additional privileges by inviting themselves to spaces that they should not have access to.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-3882-cp3m-6576

Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. Lack of input sanitization in the upload mechanism is leads to reflected XSS.

CVSS3: 5.4
0%
Низкий
около 4 лет назад
github логотип
GHSA-387x-jwqw-43f3

Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 2.2.2 allows remote attackers to affect integrity via unknown vectors related to Oracle Endeca Information Discovery (Formerly Latitude), a different vulnerability than CVE-2014-2400.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-387x-hprp-5mf9

This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.1-47117. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the xHCI component. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the hypervisor. Was ZDI-CAN-9428.

1%
Низкий
около 4 лет назад
github логотип
GHSA-387w-v9hj-ph2g

Machform prior to version 16 is vulnerable to an open redirect in Safari_init.php due to an improperly sanitized 'ref' parameter.

1%
Низкий
около 4 лет назад
github логотип
GHSA-387w-9mx8-66cc

In the Linux kernel, the following vulnerability has been resolved: 9p/xen: protect xen_9pfs_front_free against concurrent calls The xenwatch thread can race with other back-end change notifications and call xen_9pfs_front_free() twice, hitting the observed general protection fault due to a double-free. Guard the teardown path so only one caller can release the front-end state at a time, preventing the crash. This is a fix for the following double-free: [ 27.052347] Oops: general protection fault, probably for non-canonical address 0x6b6b6b6b6b6b6b6b: 0000 [#1] SMP DEBUG_PAGEALLOC NOPTI [ 27.052357] CPU: 0 UID: 0 PID: 32 Comm: xenwatch Not tainted 6.18.0-02087-g51ab33fc0a8b-dirty #60 PREEMPT(none) [ 27.052363] RIP: e030:xen_9pfs_front_free+0x1d/0x150 [ 27.052368] Code: 90 90 90 90 90 90 90 90 90 90 90 90 90 41 55 41 54 55 48 89 fd 48 c7 c7 48 d0 92 85 53 e8 cb cb 05 00 48 8b 45 08 48 8b 55 00 <48> 3b 28 0f 85 f9 28 35 fe 48 3b 6a 08 0f 85 ef 28 35 fe 48 89 42 [ 27.0523...

CVSS3: 8.8
0%
Низкий
3 месяца назад
github логотип
GHSA-387v-qw2x-rwg8

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An attacker in a privileged position may be able to perform a denial-of-service.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-387v-pw76-m864

Buffer overflow in the IDENT daemon (identd) in Trillian 0.6351, 0.725, 0.73, 0.74 and 1.0 pro allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long request.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-387v-g9vc-rrrf

Missing Authorization vulnerability in Muffingroup Betheme.This issue affects Betheme: from n/a through 26.6.1.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-387v-84cv-9qmc

Improper Limitation of a Pathname ('Path Traversal') in org.apache.solr:solr-core

CVSS3: 7.5
7%
Низкий
почти 8 лет назад
github логотип
GHSA-387r-w9pc-hjv4

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in artplacer ArtPlacer Widget artplacer-widget allows Blind SQL Injection.This issue affects ArtPlacer Widget: from n/a through <= 2.22.9.2.

CVSS3: 9.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-387q-wvj8-w6gg

An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0. A specifically crafted pdf can cause an image resizing after allocation has already occurred, resulting in heap corruption which can lead to code execution. An attacker controlled PDF file can be used to trigger this vulnerability.

CVSS3: 8.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-387q-w9v4-q6qm

Integer overflow in the dissect_iscsi_pdu function in epan/dissectors/packet-iscsi.c in the iSCSI dissector in Wireshark 1.6.x before 1.6.12 and 1.8.x before 1.8.4 allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-387q-r347-qf62

A reflected cross-site scripted (XSS) vulnerability in the /admin/system/packages endpoint of Luci OpenWRT v18.06.2 allows attackers to execute arbitrary Javascript in the context of a user's browser via a crafted payload.

CVSS3: 5.4
0%
Низкий
11 месяцев назад
github логотип
GHSA-387m-j3p9-3php

NocoDB Vulnerable to User Enumeration via Password Reset Endpoint

1%
Низкий
6 месяцев назад
github логотип
GHSA-387m-935m-c4vw

Micronaut doesn't set a maximum redirect count for its HTTP Client, enabling infinite loop DoS

CVSS3: 7.5
около 1 месяца назад
github логотип
GHSA-387j-r6x5-3c3w

SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core/admin/modules/developer/modules/views/create.php. The attacker creates a crafted table name at admin/developer/modules/views/create/ and the injection is visible at admin/ajax/auto-modules/views/searchable-page/ or admin/modules_name.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-387j-qwmj-3pww

Buffer overflow in ccn-lite-ccnb2xml.c in CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact via vectors involving the vallen and len variables.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-387j-9qrx-3rh5

Unspecified vulnerability in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted H.263 encoded movie file that triggers memory corruption.

4%
Низкий
больше 4 лет назад

Уязвимостей на страницу