Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 356 366

Количество 356 366

github логотип

GHSA-2xxj-gwfx-rr2c

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: calipso: fix memory leak in netlbl_calipso_add_pass() If IPv6 support is disabled at boot (ipv6.disable=1), the calipso_init() -> netlbl_calipso_ops_register() function isn't called, and the netlbl_calipso_ops_get() function always returns NULL. In this case, the netlbl_calipso_add_pass() function allocates memory for the doi_def variable but doesn't free it with the calipso_doi_free(). BUG: memory leak unreferenced object 0xffff888011d68180 (size 64): comm "syz-executor.1", pid 10746, jiffies 4295410986 (age 17.928s) hex dump (first 32 bytes): 00 00 00 00 02 00 00 00 00 00 00 00 00 00 00 00 ................ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace: [<...>] kmalloc include/linux/slab.h:552 [inline] [<...>] netlbl_calipso_add_pass net/netlabel/netlabel_calipso.c:76 [inline] [<...>] netlbl_calipso_add+0x22e/0x4f0 net/netlabel/netlabel_calipso.c:111 [...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2xxj-7m67-w75h

около 4 лет назад

MagickCore/memory.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds access) via a crafted PDB file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2xxj-53mf-4884

около 4 лет назад

The crafty-social-buttons plugin before 1.5.8 for WordPress has XSS.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2xxh-xxr9-5c4q

около 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in assets/misc/fallback-page.php in the Profile Builder plugin before 2.0.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) site_name, (2) message, or (3) site_url parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2xxh-hp4f-fg97

около 4 лет назад

GlobalProtect Agent 4.1.0 for Windows and GlobalProtect Agent 4.1.10 and earlier for macOS may allow a local authenticated attacker who has compromised the end-user account and gained the ability to inspect memory, to access authentication and/or session tokens and replay them to spoof the VPN session and gain access as the user.

CVSS3: 2.5
EPSS: Низкий
github логотип

GHSA-2xxh-f8r3-hvvr

около 4 лет назад

Improper Access Control in MySQL Connectors Java

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-2xxh-f2h8-792v

4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Fix base address calculation in kvm_eiointc_regs_access() In function kvm_eiointc_regs_access(), the register base address is caculated from array base address plus offset, the offset is absolute value from the base address. The data type of array base address is u64, it should be converted into the "void *" type and then plus the offset.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2xxg-j453-5c23

около 4 лет назад

A code injection in Nextcloud Desktop Client 2.6.2 for macOS allowed to load arbitrary code when starting the client with DYLD_INSERT_LIBRARIES set in the environment.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2xxc-cxf2-h97v

около 2 лет назад

Improper neutralization in Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2xxc-73fv-36f7

почти 3 года назад

llama-index vulnerable to arbitrary code execution

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2xx9-w5qw-9796

около 4 лет назад

Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters). Supported versions that are affected are 8.5.3 and 8.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology. Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS score depend on the software that uses the Outside In Technology code. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology code, but if data is not received over a network the CVSS score may be lower. CVSS 3.0 Base Score 6.5 (Confidentiality and Availability impacts). CV...

EPSS: Низкий
github логотип

GHSA-2xx8-j85v-j7wh

4 месяца назад

Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2xx8-62cr-6w92

около 4 лет назад

Metaways Tine 2.0 allows remote attackers to obtain sensitive information via unknown vectors in (1) Crm/Controller.php, (2) Crm/Export/Csv.php, or (3) Calendar/Model/Attender.php, which reveal the full installation path.

EPSS: Низкий
github логотип

GHSA-2xx6-qf7x-grqh

3 месяца назад

next-npm-version is vulnerable to Command injection

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2xx6-c8x3-p4jj

около 4 лет назад

Improper sanitization of dynamic user expressions in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated privileged users to escape from the dynamic expression sandbox and execute arbitrary code on the hosting system.

EPSS: Низкий
github логотип

GHSA-2xx6-8p93-4g88

около 4 лет назад

The Q.933 parser in tcpdump before 4.9.0 has a buffer overflow in print-fr.c:q933_print(), a different vulnerability than CVE-2016-8575.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2xx6-2jh9-8wmx

около 2 месяцев назад

Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-2xx5-rm9h-fw44

около 4 лет назад

The get_free_port function in Xen allows local authenticated DomU users to cause a denial of service or possibly gain privileges via unspecified vectors involving a new event channel port.

EPSS: Низкий
github логотип

GHSA-2xx5-jpqr-vq6g

около 4 лет назад

** DISPUTED ** Liferay 6.2.x and before has an FCKeditor configuration that allows an attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment via a browser/liferay/browser.html?Type= or html/js/editor/fckeditor/editor/filemanager/browser/liferay/browser.html URI. NOTE: the vendor disputes this issue because file upload is an expected feature, subject to Role Based Access Control checks where only authenticated users with proper permissions can upload files.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2xx5-285p-w456

почти 4 года назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_T files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18351.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2xxj-gwfx-rr2c

In the Linux kernel, the following vulnerability has been resolved: calipso: fix memory leak in netlbl_calipso_add_pass() If IPv6 support is disabled at boot (ipv6.disable=1), the calipso_init() -> netlbl_calipso_ops_register() function isn't called, and the netlbl_calipso_ops_get() function always returns NULL. In this case, the netlbl_calipso_add_pass() function allocates memory for the doi_def variable but doesn't free it with the calipso_doi_free(). BUG: memory leak unreferenced object 0xffff888011d68180 (size 64): comm "syz-executor.1", pid 10746, jiffies 4295410986 (age 17.928s) hex dump (first 32 bytes): 00 00 00 00 02 00 00 00 00 00 00 00 00 00 00 00 ................ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace: [<...>] kmalloc include/linux/slab.h:552 [inline] [<...>] netlbl_calipso_add_pass net/netlabel/netlabel_calipso.c:76 [inline] [<...>] netlbl_calipso_add+0x22e/0x4f0 net/netlabel/netlabel_calipso.c:111 [...

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-2xxj-7m67-w75h

MagickCore/memory.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds access) via a crafted PDB file.

CVSS3: 6.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-2xxj-53mf-4884

The crafty-social-buttons plugin before 1.5.8 for WordPress has XSS.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-2xxh-xxr9-5c4q

Multiple cross-site scripting (XSS) vulnerabilities in assets/misc/fallback-page.php in the Profile Builder plugin before 2.0.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) site_name, (2) message, or (3) site_url parameter.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-2xxh-hp4f-fg97

GlobalProtect Agent 4.1.0 for Windows and GlobalProtect Agent 4.1.10 and earlier for macOS may allow a local authenticated attacker who has compromised the end-user account and gained the ability to inspect memory, to access authentication and/or session tokens and replay them to spoof the VPN session and gain access as the user.

CVSS3: 2.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-2xxh-f8r3-hvvr

Improper Access Control in MySQL Connectors Java

CVSS3: 8.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-2xxh-f2h8-792v

In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Fix base address calculation in kvm_eiointc_regs_access() In function kvm_eiointc_regs_access(), the register base address is caculated from array base address plus offset, the offset is absolute value from the base address. The data type of array base address is u64, it should be converted into the "void *" type and then plus the offset.

CVSS3: 5.5
0%
Низкий
4 месяца назад
github логотип
GHSA-2xxg-j453-5c23

A code injection in Nextcloud Desktop Client 2.6.2 for macOS allowed to load arbitrary code when starting the client with DYLD_INSERT_LIBRARIES set in the environment.

CVSS3: 6.7
1%
Низкий
около 4 лет назад
github логотип
GHSA-2xxc-cxf2-h97v

Improper neutralization in Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 8.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-2xxc-73fv-36f7

llama-index vulnerable to arbitrary code execution

CVSS3: 9.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-2xx9-w5qw-9796

Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters). Supported versions that are affected are 8.5.3 and 8.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology. Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS score depend on the software that uses the Outside In Technology code. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology code, but if data is not received over a network the CVSS score may be lower. CVSS 3.0 Base Score 6.5 (Confidentiality and Availability impacts). CV...

2%
Низкий
около 4 лет назад
github логотип
GHSA-2xx8-j85v-j7wh

Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php

CVSS3: 8.1
0%
Низкий
4 месяца назад
github логотип
GHSA-2xx8-62cr-6w92

Metaways Tine 2.0 allows remote attackers to obtain sensitive information via unknown vectors in (1) Crm/Controller.php, (2) Crm/Export/Csv.php, or (3) Calendar/Model/Attender.php, which reveal the full installation path.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2xx6-qf7x-grqh

next-npm-version is vulnerable to Command injection

CVSS3: 9.8
2%
Низкий
3 месяца назад
github логотип
GHSA-2xx6-c8x3-p4jj

Improper sanitization of dynamic user expressions in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated privileged users to escape from the dynamic expression sandbox and execute arbitrary code on the hosting system.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2xx6-8p93-4g88

The Q.933 parser in tcpdump before 4.9.0 has a buffer overflow in print-fr.c:q933_print(), a different vulnerability than CVE-2016-8575.

CVSS3: 9.8
6%
Низкий
около 4 лет назад
github логотип
GHSA-2xx6-2jh9-8wmx

Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152 and Firefox ESR 140.12.

CVSS3: 9.6
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2xx5-rm9h-fw44

The get_free_port function in Xen allows local authenticated DomU users to cause a denial of service or possibly gain privileges via unspecified vectors involving a new event channel port.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2xx5-jpqr-vq6g

** DISPUTED ** Liferay 6.2.x and before has an FCKeditor configuration that allows an attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment via a browser/liferay/browser.html?Type= or html/js/editor/fckeditor/editor/filemanager/browser/liferay/browser.html URI. NOTE: the vendor disputes this issue because file upload is an expected feature, subject to Role Based Access Control checks where only authenticated users with proper permissions can upload files.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2xx5-285p-w456

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of X_T files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18351.

CVSS3: 7.8
1%
Низкий
почти 4 года назад

Уязвимостей на страницу