Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 234

Количество 358 234

github логотип

GHSA-36h3-x748-qfw8

около 4 лет назад

Xen, when using x86 Intel processors and the VMX virtualization extension is enabled, does not properly handle cpuid instruction emulation when exiting the VM, which allows local guest users to cause a denial of service (guest crash) via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-36h3-8635-w5mx

около 4 лет назад

In FreeBSD 12.1-STABLE before r352509, 11.3-STABLE before r352509, and 11.3-RELEASE before p9, an unprivileged local user can trigger a use-after-free situation due to improper checking in SCTP when an application tries to update an SCTP-AUTH shared key.

EPSS: Низкий
github логотип

GHSA-36h3-7c54-j27r

6 месяцев назад

OpenClaw has browser trace/download path symlink escape in temp output handling

EPSS: Низкий
github логотип

GHSA-36h2-g4c8-9xcm

около 2 лет назад

Aim denial of service vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-36h2-95gj-w488

больше 4 лет назад

Open redirect in Gitea

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-36gx-rqg5-2fh6

почти 2 года назад

A SQL Injection vulnerability exists in the Downtime component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-36gx-mxh9-mx5r

7 месяцев назад

The Uniffle HTTP client is configured to trust all SSL certificates and disables hostname verification by default. This insecure configuration exposes all REST API communication between the Uniffle CLI/client and the Uniffle Coordinator service to potential Man-in-the-Middle (MITM) attacks. This issue affects all versions from before 0.10.0. Users are recommended to upgrade to version 0.10.0, which fixes the issue.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-36gx-9q6h-g429

больше 3 лет назад

vantage6 vulnerable to Observable Response Discrepancy

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-36gx-2v7r-qrqf

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Spymac Web OS 4.0 allow remote attackers to inject arbitrary web script or HTML via (a) the blogs module, including the (1) curr parameter in index.php, (2) inspire, (3) system, or (4) title parameter in blog_newentry.php, (5) entry parameter in blog_newentry_comment.php, (6) entry parameter in blog_edit_entry.php, or (7) caldate parameter in blog.php; and (b) the notes module, including the (1) forwardid parameter in a noteform action; (2) del_folder parameter in a delete_folder action; (3) isread, (4) dateorder, (5) subjectorder, (6) curr, (7) fromorder, or (8) action parameters; (9) ppp or (10) totalreplies parameter in an Inbox action; (11) totalnotes parameter; or (12) touserid parameter in a noteform action.

EPSS: Низкий
github логотип

GHSA-36gw-qm9m-236g

около 4 лет назад

Windows Network File System Denial of Service Vulnerability

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-36gw-3xf6-9pvq

около 4 лет назад

The python-qpid client (common/rpc/impl_qpid.py) in OpenStack Oslo before 2013.2 does not enforce SSL connections when qpid_protocol is set to ssl, which allows remote attackers to obtain sensitive information by sniffing the network.

EPSS: Низкий
github логотип

GHSA-36gw-23f9-q2qg

больше 4 лет назад

Heap-based buffer overflow in clipping region (aka crgn) atom handling in quicktime.qts in Apple QuickTime before 7.4.5 allows remote attackers to execute arbitrary code via a crafted movie.

EPSS: Низкий
github логотип

GHSA-36gv-vcm7-9gf5

больше 4 лет назад

Directory traversal vulnerability in admin.php in SkyBlueCanvas 1.1 r237 allows remote authenticated administrators to list directory contents via a .. (dot dot) in the dir parameter.

EPSS: Низкий
github логотип

GHSA-36gr-gw56-g35v

около 2 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size [Why & How] During HDCP 2.x repeater authentication over HDMI, the driver reads the sink's RxStatus register and extracts a 10-bit message size field (max value 1023). This value is used as the read length for the ReceiverID list without being clamped to the size of the destination buffer rx_id_list[177]. A malicious HDMI repeater could advertise a message size larger than the buffer, causing an out-of-bounds write during the I2C read. Clamp the read length in mod_hdcp_read_rx_id_list() to the size of the rx_id_list buffer, matching the approach already used in the DP branch. (cherry picked from commit 229212219e4247d9486f8ba41ef087358490be09)

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-36gq-6ffc-9cwj

около 4 лет назад

The Coca-Cola FM Guatemala (aka com.enyetech.radio.coca_cola.fm_gu) application 2.0.41725 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-36gq-4prj-vmxm

около 1 года назад

A vulnerability has been found in Tenda AC23 16.03.07.52 and classified as critical. Affected by this vulnerability is the function sub_46C940 of the file /goform/setMacFilterCfg of the component httpd. The manipulation of the argument deviceList leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-36gq-35j3-p9r9

больше 1 года назад

Excessive Platform Resource Consumption within a Loop when unmarshalling Compose file having recursive loop

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-36gq-2499-pq9x

почти 2 года назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Telemetry). Supported versions that are affected are 8.4.2 and prior and 9.0.1 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 2.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N).

CVSS3: 2.2
EPSS: Низкий
github логотип

GHSA-36gp-wrgh-j78w

24 дня назад

The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-36gp-vxxv-fjf3

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in thumbs.php in mmgallery 1.55 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-36h3-x748-qfw8

Xen, when using x86 Intel processors and the VMX virtualization extension is enabled, does not properly handle cpuid instruction emulation when exiting the VM, which allows local guest users to cause a denial of service (guest crash) via unspecified vectors.

0%
Низкий
около 4 лет назад
github логотип
GHSA-36h3-8635-w5mx

In FreeBSD 12.1-STABLE before r352509, 11.3-STABLE before r352509, and 11.3-RELEASE before p9, an unprivileged local user can trigger a use-after-free situation due to improper checking in SCTP when an application tries to update an SCTP-AUTH shared key.

0%
Низкий
около 4 лет назад
github логотип
GHSA-36h3-7c54-j27r

OpenClaw has browser trace/download path symlink escape in temp output handling

0%
Низкий
6 месяцев назад
github логотип
GHSA-36h2-g4c8-9xcm

Aim denial of service vulnerability

CVSS3: 7.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-36h2-95gj-w488

Open redirect in Gitea

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-36gx-rqg5-2fh6

A SQL Injection vulnerability exists in the Downtime component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.

CVSS3: 9.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-36gx-mxh9-mx5r

The Uniffle HTTP client is configured to trust all SSL certificates and disables hostname verification by default. This insecure configuration exposes all REST API communication between the Uniffle CLI/client and the Uniffle Coordinator service to potential Man-in-the-Middle (MITM) attacks. This issue affects all versions from before 0.10.0. Users are recommended to upgrade to version 0.10.0, which fixes the issue.

CVSS3: 9.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-36gx-9q6h-g429

vantage6 vulnerable to Observable Response Discrepancy

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-36gx-2v7r-qrqf

Multiple cross-site scripting (XSS) vulnerabilities in Spymac Web OS 4.0 allow remote attackers to inject arbitrary web script or HTML via (a) the blogs module, including the (1) curr parameter in index.php, (2) inspire, (3) system, or (4) title parameter in blog_newentry.php, (5) entry parameter in blog_newentry_comment.php, (6) entry parameter in blog_edit_entry.php, or (7) caldate parameter in blog.php; and (b) the notes module, including the (1) forwardid parameter in a noteform action; (2) del_folder parameter in a delete_folder action; (3) isread, (4) dateorder, (5) subjectorder, (6) curr, (7) fromorder, or (8) action parameters; (9) ppp or (10) totalreplies parameter in an Inbox action; (11) totalnotes parameter; or (12) touserid parameter in a noteform action.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-36gw-qm9m-236g

Windows Network File System Denial of Service Vulnerability

CVSS3: 6.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-36gw-3xf6-9pvq

The python-qpid client (common/rpc/impl_qpid.py) in OpenStack Oslo before 2013.2 does not enforce SSL connections when qpid_protocol is set to ssl, which allows remote attackers to obtain sensitive information by sniffing the network.

2%
Низкий
около 4 лет назад
github логотип
GHSA-36gw-23f9-q2qg

Heap-based buffer overflow in clipping region (aka crgn) atom handling in quicktime.qts in Apple QuickTime before 7.4.5 allows remote attackers to execute arbitrary code via a crafted movie.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-36gv-vcm7-9gf5

Directory traversal vulnerability in admin.php in SkyBlueCanvas 1.1 r237 allows remote authenticated administrators to list directory contents via a .. (dot dot) in the dir parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-36gr-gw56-g35v

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size [Why & How] During HDCP 2.x repeater authentication over HDMI, the driver reads the sink's RxStatus register and extracts a 10-bit message size field (max value 1023). This value is used as the read length for the ReceiverID list without being clamped to the size of the destination buffer rx_id_list[177]. A malicious HDMI repeater could advertise a message size larger than the buffer, causing an out-of-bounds write during the I2C read. Clamp the read length in mod_hdcp_read_rx_id_list() to the size of the rx_id_list buffer, matching the approach already used in the DP branch. (cherry picked from commit 229212219e4247d9486f8ba41ef087358490be09)

CVSS3: 7.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-36gq-6ffc-9cwj

The Coca-Cola FM Guatemala (aka com.enyetech.radio.coca_cola.fm_gu) application 2.0.41725 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
около 4 лет назад
github логотип
GHSA-36gq-4prj-vmxm

A vulnerability has been found in Tenda AC23 16.03.07.52 and classified as critical. Affected by this vulnerability is the function sub_46C940 of the file /goform/setMacFilterCfg of the component httpd. The manipulation of the argument deviceList leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
1%
Низкий
около 1 года назад
github логотип
GHSA-36gq-35j3-p9r9

Excessive Platform Resource Consumption within a Loop when unmarshalling Compose file having recursive loop

CVSS3: 5.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-36gq-2499-pq9x

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Telemetry). Supported versions that are affected are 8.4.2 and prior and 9.0.1 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 2.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N).

CVSS3: 2.2
1%
Низкий
почти 2 года назад
github логотип
GHSA-36gp-wrgh-j78w

The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

CVSS3: 8.6
0%
Низкий
24 дня назад
github логотип
GHSA-36gp-vxxv-fjf3

Cross-site scripting (XSS) vulnerability in thumbs.php in mmgallery 1.55 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу