Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 704

Количество 355 704

github логотип

GHSA-2wwf-v36q-j2m3

около 3 лет назад

A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.1.1.15289. A specially crafted PDF document can trigger the reuse of previously freed memory by manipulating form fields of a specific type. This can lead to memory corruption and arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2wwc-w2gw-4329

больше 5 лет назад

Out-of-bounds write

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-2wwc-pmg9-2f8m

около 4 лет назад

An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2wwc-hfmq-5q7x

больше 3 лет назад

A vulnerability was found in SourceCodester Employee Task Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file task-details.php. The manipulation of the argument task_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-221453 was assigned to this vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2wwc-c62q-7wrf

почти 3 года назад

The issue was addressed with improved memory handling. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, macOS Sonoma 14, Xcode 15. An app may be able to disclose kernel memory.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2wwc-57w4-gp7m

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: ACPI: GTDT: Don't corrupt interrupt mappings on watchdow probe failure When failing the driver probe because of invalid firmware properties, the GTDT driver unmaps the interrupt that it mapped earlier. However, it never checks whether the mapping of the interrupt actially succeeded. Even more, should the firmware report an illegal interrupt number that overlaps with the GIC SGI range, this can result in an IPI being unmapped, and subsequent fireworks (as reported by Dann Frazier). Rework the driver to have a slightly saner behaviour and actually check whether the interrupt has been mapped before unmapping things.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2ww8-pj73-gx5x

около 2 лет назад

Information disclosure while handling beacon probe frame during scan entry generation in client side.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2ww8-f9rj-2xg5

больше 3 лет назад

Connectwise Control 22.8.10013.8329 is vulnerable to Cross Origin Resource Sharing (CORS).

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2ww7-vv5p-929j

около 4 лет назад

PDFResurrect 0.15 has a buffer overflow via a crafted PDF file because data associated with startxref and %%EOF is mishandled.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2ww7-hqm8-2qhf

3 месяца назад

An OS Command Injection vulnerability exists in Aterm. If a malicious third person gains administrator access to the product’s web console, they may be able to execute arbitrary OS commands via adjacent network.

EPSS: Низкий
github логотип

GHSA-2ww6-hf35-mfjm

2 месяца назад

Capsule Namespace Hijacking via subresource

CVSS3: 3.9
EPSS: Низкий
github логотип

GHSA-2ww6-gh4g-5q93

почти 4 года назад

This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.5, watchOS 8.7, iOS 15.6 and iPadOS 15.6. An app may be able to execute arbitrary code with kernel privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2ww6-g8rg-vh7g

больше 4 лет назад

Buffer overflow in Whisper FTP Surfer 1.0.7 allows remote FTP servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long filename.

EPSS: Низкий
github логотип

GHSA-2ww6-c8hm-gqw6

6 месяцев назад

Reflected Cross-Site Scripting vulnerability in SOTESHOP, version 8.3.4. THis vulnerability allows an attacker execute JavaScript code in the victim's browser when a malicious URL with the 'id' parameter in '/adsTracker/checkAds' is sent to the victim. The vulnerability can be exploited to steal sensitive user information such as session cookies, or to perform actions on their behalf.

EPSS: Низкий
github логотип

GHSA-2ww6-868g-2c56

5 месяцев назад

OpenClaw Vulnerable to HTML injection via unvalidated image MIME type in data-URL interpolation

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-2ww6-2gwx-v942

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix variable not being completed when function returns When cmd_alloc_index(), fails cmd_work_handler() needs to complete ent->slotted before returning early. Otherwise the task which issued the command may hang: mlx5_core 0000:01:00.0: cmd_work_handler:877:(pid 3880418): failed to allocate command entry INFO: task kworker/13:2:4055883 blocked for more than 120 seconds. Not tainted 4.19.90-25.44.v2101.ky10.aarch64 #1 "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message. kworker/13:2 D 0 4055883 2 0x00000228 Workqueue: events mlx5e_tx_dim_work [mlx5_core] Call trace: __switch_to+0xe8/0x150 __schedule+0x2a8/0x9b8 schedule+0x2c/0x88 schedule_timeout+0x204/0x478 wait_for_common+0x154/0x250 wait_for_completion+0x28/0x38 cmd_exec+0x7a0/0xa00 [mlx5_core] mlx5_cmd_exec+0x54/0x80 [mlx5_core] mlx5_core_...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2ww5-g3p9-xg2r

больше 4 лет назад

Multiple PHP remote file inclusion vulnerabilities in FirmWorX 0.1.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) bank_data[root] parameter to modules/bank/includes/design/main.inc.php, or the (2) fm_data[root] parameter to (a) includes/config/master.inc.php or (b) includes/functions/master.inc.php.

EPSS: Низкий
github логотип

GHSA-2ww5-c4rg-76jh

больше 1 года назад

A cross-site scripting vulnerability was reported in the FileZ client that could allow execution of code if a crafted url is visited by a local user.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-2ww3-fxvq-293j

почти 5 лет назад

NLTK Vulnerable to REDoS

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2ww3-72rp-wpp4

6 месяцев назад

Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK

CVSS3: 9.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2wwf-v36q-j2m3

A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.1.1.15289. A specially crafted PDF document can trigger the reuse of previously freed memory by manipulating form fields of a specific type. This can lead to memory corruption and arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.

CVSS3: 8.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-2wwc-w2gw-4329

Out-of-bounds write

CVSS3: 7.5
10%
Средний
больше 5 лет назад
github логотип
GHSA-2wwc-pmg9-2f8m

An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2wwc-hfmq-5q7x

A vulnerability was found in SourceCodester Employee Task Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file task-details.php. The manipulation of the argument task_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-221453 was assigned to this vulnerability.

CVSS3: 8.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-2wwc-c62q-7wrf

The issue was addressed with improved memory handling. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, macOS Sonoma 14, Xcode 15. An app may be able to disclose kernel memory.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-2wwc-57w4-gp7m

In the Linux kernel, the following vulnerability has been resolved: ACPI: GTDT: Don't corrupt interrupt mappings on watchdow probe failure When failing the driver probe because of invalid firmware properties, the GTDT driver unmaps the interrupt that it mapped earlier. However, it never checks whether the mapping of the interrupt actially succeeded. Even more, should the firmware report an illegal interrupt number that overlaps with the GIC SGI range, this can result in an IPI being unmapped, and subsequent fireworks (as reported by Dann Frazier). Rework the driver to have a slightly saner behaviour and actually check whether the interrupt has been mapped before unmapping things.

CVSS3: 6.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2ww8-pj73-gx5x

Information disclosure while handling beacon probe frame during scan entry generation in client side.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-2ww8-f9rj-2xg5

Connectwise Control 22.8.10013.8329 is vulnerable to Cross Origin Resource Sharing (CORS).

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2ww7-vv5p-929j

PDFResurrect 0.15 has a buffer overflow via a crafted PDF file because data associated with startxref and %%EOF is mishandled.

CVSS3: 7.8
7%
Низкий
около 4 лет назад
github логотип
GHSA-2ww7-hqm8-2qhf

An OS Command Injection vulnerability exists in Aterm. If a malicious third person gains administrator access to the product’s web console, they may be able to execute arbitrary OS commands via adjacent network.

1%
Низкий
3 месяца назад
github логотип
GHSA-2ww6-hf35-mfjm

Capsule Namespace Hijacking via subresource

CVSS3: 3.9
0%
Низкий
2 месяца назад
github логотип
GHSA-2ww6-gh4g-5q93

This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.5, watchOS 8.7, iOS 15.6 and iPadOS 15.6. An app may be able to execute arbitrary code with kernel privileges.

CVSS3: 7.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-2ww6-g8rg-vh7g

Buffer overflow in Whisper FTP Surfer 1.0.7 allows remote FTP servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long filename.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2ww6-c8hm-gqw6

Reflected Cross-Site Scripting vulnerability in SOTESHOP, version 8.3.4. THis vulnerability allows an attacker execute JavaScript code in the victim's browser when a malicious URL with the 'id' parameter in '/adsTracker/checkAds' is sent to the victim. The vulnerability can be exploited to steal sensitive user information such as session cookies, or to perform actions on their behalf.

0%
Низкий
6 месяцев назад
github логотип
GHSA-2ww6-868g-2c56

OpenClaw Vulnerable to HTML injection via unvalidated image MIME type in data-URL interpolation

CVSS3: 4.6
0%
Низкий
5 месяцев назад
github логотип
GHSA-2ww6-2gwx-v942

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix variable not being completed when function returns When cmd_alloc_index(), fails cmd_work_handler() needs to complete ent->slotted before returning early. Otherwise the task which issued the command may hang: mlx5_core 0000:01:00.0: cmd_work_handler:877:(pid 3880418): failed to allocate command entry INFO: task kworker/13:2:4055883 blocked for more than 120 seconds. Not tainted 4.19.90-25.44.v2101.ky10.aarch64 #1 "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message. kworker/13:2 D 0 4055883 2 0x00000228 Workqueue: events mlx5e_tx_dim_work [mlx5_core] Call trace: __switch_to+0xe8/0x150 __schedule+0x2a8/0x9b8 schedule+0x2c/0x88 schedule_timeout+0x204/0x478 wait_for_common+0x154/0x250 wait_for_completion+0x28/0x38 cmd_exec+0x7a0/0xa00 [mlx5_core] mlx5_cmd_exec+0x54/0x80 [mlx5_core] mlx5_core_...

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2ww5-g3p9-xg2r

Multiple PHP remote file inclusion vulnerabilities in FirmWorX 0.1.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) bank_data[root] parameter to modules/bank/includes/design/main.inc.php, or the (2) fm_data[root] parameter to (a) includes/config/master.inc.php or (b) includes/functions/master.inc.php.

8%
Низкий
больше 4 лет назад
github логотип
GHSA-2ww5-c4rg-76jh

A cross-site scripting vulnerability was reported in the FileZ client that could allow execution of code if a crafted url is visited by a local user.

CVSS3: 5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2ww3-fxvq-293j

NLTK Vulnerable to REDoS

CVSS3: 7.5
2%
Низкий
почти 5 лет назад
github логотип
GHSA-2ww3-72rp-wpp4

Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK

CVSS3: 9.9
2%
Низкий
6 месяцев назад

Уязвимостей на страницу