Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 234

Количество 358 234

github логотип

GHSA-365f-xm5m-p3pr

около 2 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Add bounds check for firmware runtime memory Validate that the firmware runtime memory specified in the image header is properly aligned and sized to hold the firmware image. This prevents errors during memory allocation and image transfer.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-365f-6rq6-q4j4

больше 4 лет назад

Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1286, CVE-2010-1287, CVE-2010-1289, CVE-2010-1290, and CVE-2010-1291.

EPSS: Низкий
github логотип

GHSA-3659-qppf-7pgh

около 4 лет назад

The kernel in Apple iOS before 9.1 allows attackers to cause a denial of service via a crafted app.

EPSS: Низкий
github логотип

GHSA-3659-jjmv-v338

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: drm/bridge: sii902x: Fix probing race issue A null pointer dereference crash has been observed rarely on TI platforms using sii9022 bridge: [ 53.271356] sii902x_get_edid+0x34/0x70 [sii902x] [ 53.276066] sii902x_bridge_get_edid+0x14/0x20 [sii902x] [ 53.281381] drm_bridge_get_edid+0x20/0x34 [drm] [ 53.286305] drm_bridge_connector_get_modes+0x8c/0xcc [drm_kms_helper] [ 53.292955] drm_helper_probe_single_connector_modes+0x190/0x538 [drm_kms_helper] [ 53.300510] drm_client_modeset_probe+0x1f0/0xbd4 [drm] [ 53.305958] __drm_fb_helper_initial_config_and_unlock+0x50/0x510 [drm_kms_helper] [ 53.313611] drm_fb_helper_initial_config+0x48/0x58 [drm_kms_helper] [ 53.320039] drm_fbdev_dma_client_hotplug+0x84/0xd4 [drm_dma_helper] [ 53.326401] drm_client_register+0x5c/0xa0 [drm] [ 53.331216] drm_fbdev_dma_setup+0xc8/0x13c [drm_dma_helper] [ 53.336881] tidss_probe+0x128/0x264 [tidss] [ 53.34...

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-3659-9xv5-5669

больше 1 года назад

The Import Eventbrite Events plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.7.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3657-w454-hxhx

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in esp/editUser.esp in the Palo Alto Networks firewall 3.0.x before 3.0.9 and 3.1.x before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the role parameter.

EPSS: Низкий
github логотип

GHSA-3657-q433-mmpx

около 4 лет назад

Canvs Canvas Cross-site Scripting (XSS) via title and content fields

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3657-fjf8-53fm

около 4 лет назад

Heap buffer overflow in History in Google Chrome prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

EPSS: Низкий
github логотип

GHSA-3656-jvhv-q239

около 4 лет назад

SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_BlitCopy in video/SDL_blit_copy.c via a crafted .BMP file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3656-hc57-pfv2

больше 2 лет назад

Windows DNS Server Remote Code Execution Vulnerability

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3656-cj7q-mf85

4 дня назад

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3655-xq3q-xq2p

больше 4 лет назад

Format string vulnerability in Apple iPhoto 6.0.5 (316), and other versions before 6.0.6, allows remote user-assisted attackers to execute arbitrary code via a crafted photocast with format string specifiers in the title of an RSS iPhoto feed.

EPSS: Низкий
github логотип

GHSA-3654-wj8m-9hfq

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in OceanWP Ocean Extra.This issue affects Ocean Extra: from n/a through 2.2.2.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3654-94f7-vj6m

около 4 лет назад

Improper access control in Intel(R) Graphics Drivers before version 26.20.100.6912 may allow an authenticated user to potentially enable escalation of privilege via local access.

EPSS: Низкий
github логотип

GHSA-3654-92rm-xcmh

около 4 лет назад

In RegisterNotificationResponse::GetEvent of register_notification_packet.cc, there is a possible abort due to improper input validation. This could lead to remote denial of service of the Bluetooth service, over Bluetooth, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-144066833

EPSS: Низкий
github логотип

GHSA-3653-68v6-rq57

3 месяца назад

HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3652-xvjx-j36p

11 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 15.1 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed authenticated users to view administrator-only maintenance notes by accessing runner details through specific interfaces.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3652-93x3-2rrr

около 3 лет назад

** DISPUTED ** Lack of access control in wfc.exe in Malwarebytes Binisoft Windows Firewall Control 6.9.2.0 allows local unprivileged users to bypass Windows Firewall restrictions via the user interface's rules tab. NOTE: the vendor's perspective is "this is intended behavior as the application can be locked using a password."

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-364x-r3f5-mp8c

около 4 лет назад

Improper access control in the installer for Intel(R) Chipset Device Software INF Utility before version 10.1.18 may allow an authenticated user to potentially enable denial of service via local access.

EPSS: Низкий
github логотип

GHSA-364x-96mf-p447

больше 4 лет назад

The Lotus Notes 4.5 client may send a copy of encrypted mail in the clear across the network if the user does not set the "Encrypt Saved Mail" preference.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-365f-xm5m-p3pr

In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Add bounds check for firmware runtime memory Validate that the firmware runtime memory specified in the image header is properly aligned and sized to hold the firmware image. This prevents errors during memory allocation and image transfer.

CVSS3: 5.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-365f-6rq6-q4j4

Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1286, CVE-2010-1287, CVE-2010-1289, CVE-2010-1290, and CVE-2010-1291.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-3659-qppf-7pgh

The kernel in Apple iOS before 9.1 allows attackers to cause a denial of service via a crafted app.

2%
Низкий
около 4 лет назад
github логотип
GHSA-3659-jjmv-v338

In the Linux kernel, the following vulnerability has been resolved: drm/bridge: sii902x: Fix probing race issue A null pointer dereference crash has been observed rarely on TI platforms using sii9022 bridge: [ 53.271356] sii902x_get_edid+0x34/0x70 [sii902x] [ 53.276066] sii902x_bridge_get_edid+0x14/0x20 [sii902x] [ 53.281381] drm_bridge_get_edid+0x20/0x34 [drm] [ 53.286305] drm_bridge_connector_get_modes+0x8c/0xcc [drm_kms_helper] [ 53.292955] drm_helper_probe_single_connector_modes+0x190/0x538 [drm_kms_helper] [ 53.300510] drm_client_modeset_probe+0x1f0/0xbd4 [drm] [ 53.305958] __drm_fb_helper_initial_config_and_unlock+0x50/0x510 [drm_kms_helper] [ 53.313611] drm_fb_helper_initial_config+0x48/0x58 [drm_kms_helper] [ 53.320039] drm_fbdev_dma_client_hotplug+0x84/0xd4 [drm_dma_helper] [ 53.326401] drm_client_register+0x5c/0xa0 [drm] [ 53.331216] drm_fbdev_dma_setup+0xc8/0x13c [drm_dma_helper] [ 53.336881] tidss_probe+0x128/0x264 [tidss] [ 53.34...

CVSS3: 4.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3659-9xv5-5669

The Import Eventbrite Events plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.7.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-3657-w454-hxhx

Cross-site scripting (XSS) vulnerability in esp/editUser.esp in the Palo Alto Networks firewall 3.0.x before 3.0.9 and 3.1.x before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the role parameter.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-3657-q433-mmpx

Canvs Canvas Cross-site Scripting (XSS) via title and content fields

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-3657-fjf8-53fm

Heap buffer overflow in History in Google Chrome prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

1%
Низкий
около 4 лет назад
github логотип
GHSA-3656-jvhv-q239

SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_BlitCopy in video/SDL_blit_copy.c via a crafted .BMP file.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-3656-hc57-pfv2

Windows DNS Server Remote Code Execution Vulnerability

CVSS3: 7.2
2%
Низкий
больше 2 лет назад
github логотип
GHSA-3656-cj7q-mf85

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

CVSS3: 5.5
0%
Низкий
4 дня назад
github логотип
GHSA-3655-xq3q-xq2p

Format string vulnerability in Apple iPhoto 6.0.5 (316), and other versions before 6.0.6, allows remote user-assisted attackers to execute arbitrary code via a crafted photocast with format string specifiers in the title of an RSS iPhoto feed.

9%
Низкий
больше 4 лет назад
github логотип
GHSA-3654-wj8m-9hfq

Cross-Site Request Forgery (CSRF) vulnerability in OceanWP Ocean Extra.This issue affects Ocean Extra: from n/a through 2.2.2.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3654-94f7-vj6m

Improper access control in Intel(R) Graphics Drivers before version 26.20.100.6912 may allow an authenticated user to potentially enable escalation of privilege via local access.

0%
Низкий
около 4 лет назад
github логотип
GHSA-3654-92rm-xcmh

In RegisterNotificationResponse::GetEvent of register_notification_packet.cc, there is a possible abort due to improper input validation. This could lead to remote denial of service of the Bluetooth service, over Bluetooth, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-144066833

0%
Низкий
около 4 лет назад
github логотип
GHSA-3653-68v6-rq57

HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint

CVSS3: 7.5
0%
Низкий
3 месяца назад
github логотип
GHSA-3652-xvjx-j36p

An issue has been discovered in GitLab CE/EE affecting all versions from 15.1 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed authenticated users to view administrator-only maintenance notes by accessing runner details through specific interfaces.

CVSS3: 4.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-3652-93x3-2rrr

** DISPUTED ** Lack of access control in wfc.exe in Malwarebytes Binisoft Windows Firewall Control 6.9.2.0 allows local unprivileged users to bypass Windows Firewall restrictions via the user interface's rules tab. NOTE: the vendor's perspective is "this is intended behavior as the application can be locked using a password."

CVSS3: 7.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-364x-r3f5-mp8c

Improper access control in the installer for Intel(R) Chipset Device Software INF Utility before version 10.1.18 may allow an authenticated user to potentially enable denial of service via local access.

0%
Низкий
около 4 лет назад
github логотип
GHSA-364x-96mf-p447

The Lotus Notes 4.5 client may send a copy of encrypted mail in the clear across the network if the user does not set the "Encrypt Saved Mail" preference.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу