Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 354 225

Количество 354 225

github логотип

GHSA-2prg-gcgc-mm7v

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: avoid panic on init failure In case of an error during init, in_hw_restart will be set, but it will never get cleared. Instead, we will retry to init again, and then we will act like we are in a restart when we are actually not. This causes (among others) to a NULL pointer dereference when canceling rx_omi::finished_work, that was not even initialized, because we thought that we are in hw_restart. Set in_hw_restart to true only if the fw is running, then we know that FW was loaded successfully and we are not going to the retry loop.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2prc-vxg2-86hj

около 4 лет назад

Stack-based buffer overflow in the guac_client_plugin_open function in libguac in Guacamole before 0.6.3 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long protocol name.

EPSS: Средний
github логотип

GHSA-2prc-g792-pf54

почти 4 года назад

A vulnerability, which was classified as problematic, was found in Zephyr Project Manager up to 3.2.4. Affected is an unknown function of the file /v1/tasks/create/ of the component REST Call Handler. The manipulation of the argument onanimationstart leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 3.2.5 is able to address this issue. It is recommended to upgrade the affected component. VDB-209370 is the identifier assigned to this vulnerability.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2prc-85pp-97r9

около 2 месяцев назад

Contributor Privilege Escalation in LatePoint <= 5.5.1 versions.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2prc-4f47-p38v

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: vhost-vdpa: fix vm_flags for virtqueue doorbell mapping The virtqueue doorbell is usually implemented via registeres but we don't provide the necessary vma->flags like VM_PFNMAP. This may cause several issues e.g when userspace tries to map the doorbell via vhost IOTLB, kernel may panic due to the page is not backed by page structure. This patch fixes this by setting the necessary vm_flags. With this patch, try to map doorbell via IOTLB will fail with bad address.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2prc-3jm3-rh65

почти 2 года назад

A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /user_images/. The manipulation leads to direct request. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2pr9-w7jf-v4v7

около 4 лет назад

Philips SureSigns VS4, A.07.107 and prior. The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CVSS3: 2.1
EPSS: Низкий
github логотип

GHSA-2pr9-mv6f-chvj

около 4 лет назад

A stack buffer overflow in V8 in Google Chrome prior to 62.0.3202.75 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2pr9-fr5g-p8hm

4 месяца назад

V-SFT versions 6.2.10.0 and prior contain a stack-based buffer overflow in VS6ComFile!CSaveData::_conv_AnimationItem. Opening a crafted V7 file may lead to arbitrary code execution on the affected product.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2pr9-53x2-jqgh

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: nilfs2: handle inconsistent state in nilfs_btnode_create_block() Syzbot reported that a buffer state inconsistency was detected in nilfs_btnode_create_block(), triggering a kernel bug. It is not appropriate to treat this inconsistency as a bug; it can occur if the argument block address (the buffer index of the newly created block) is a virtual block number and has been reallocated due to corruption of the bitmap used to manage its allocation state. So, modify nilfs_btnode_create_block() and its callers to treat it as a possible filesystem error, rather than triggering a kernel bug.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2pr9-2h78-r68r

около 4 лет назад

service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary DLL functions via the XF function, possibly related to an insecure exposed method.

EPSS: Средний
github логотип

GHSA-2pr8-phx7-x9h3

3 месяца назад

protobuf.js: Denial of service from crafted field names in generated code

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2pr8-9hq9-m7pw

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the CMS Updater module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving the configuration page.

EPSS: Низкий
github логотип

GHSA-2pr7-vcjv-rp52

больше 4 лет назад

Buffer overflow in the Foundation framework for Mac OS X 10.3.9 allows local users to execute arbitrary code via a long environment variable.

EPSS: Низкий
github логотип

GHSA-2pr7-6gvg-hcv8

около 4 лет назад

Vulnerability in the Oracle Crystal Ball product of Oracle Construction and Engineering (component: Installation). Supported versions that are affected are 11.1.2.0.000-11.1.2.4.900. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Crystal Ball executes to compromise Oracle Crystal Ball. While the vulnerability is in Oracle Crystal Ball, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Crystal Ball. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2pr6-vhmf-w3qp

около 4 лет назад

VMware vCenter Server (6.5 prior to 6.5 U1) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker with VC user privileges can inject malicious java-scripts which will get executed when other VC users access the page.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2pr6-h9cg-7rr7

около 3 лет назад

Cross Site Request Forgery (CSRF) vulnerability in Archer Platform before v.6.13 and fixed in v.6.12.0.6 and v.6.13.0 allows an authenticated attacker to execute arbitrary code via a crafted request.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2pr6-76vf-7546

около 7 лет назад

Denial of Service in js-yaml

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2pr5-qxg3-pfqf

12 месяцев назад

openjpeg v 2.5.0 was discovered to contain a NULL pointer dereference via the component /openjp2/dwt.c.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2pr3-v8qp-792f

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Delicious WP Delicious allows DOM-Based XSS. This issue affects WP Delicious: from n/a through 1.8.4.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2prg-gcgc-mm7v

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: avoid panic on init failure In case of an error during init, in_hw_restart will be set, but it will never get cleared. Instead, we will retry to init again, and then we will act like we are in a restart when we are actually not. This causes (among others) to a NULL pointer dereference when canceling rx_omi::finished_work, that was not even initialized, because we thought that we are in hw_restart. Set in_hw_restart to true only if the fw is running, then we know that FW was loaded successfully and we are not going to the retry loop.

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2prc-vxg2-86hj

Stack-based buffer overflow in the guac_client_plugin_open function in libguac in Guacamole before 0.6.3 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long protocol name.

14%
Средний
около 4 лет назад
github логотип
GHSA-2prc-g792-pf54

A vulnerability, which was classified as problematic, was found in Zephyr Project Manager up to 3.2.4. Affected is an unknown function of the file /v1/tasks/create/ of the component REST Call Handler. The manipulation of the argument onanimationstart leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 3.2.5 is able to address this issue. It is recommended to upgrade the affected component. VDB-209370 is the identifier assigned to this vulnerability.

CVSS3: 5.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-2prc-85pp-97r9

Contributor Privilege Escalation in LatePoint <= 5.5.1 versions.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2prc-4f47-p38v

In the Linux kernel, the following vulnerability has been resolved: vhost-vdpa: fix vm_flags for virtqueue doorbell mapping The virtqueue doorbell is usually implemented via registeres but we don't provide the necessary vma->flags like VM_PFNMAP. This may cause several issues e.g when userspace tries to map the doorbell via vhost IOTLB, kernel may panic due to the page is not backed by page structure. This patch fixes this by setting the necessary vm_flags. With this patch, try to map doorbell via IOTLB will fail with bad address.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2prc-3jm3-rh65

A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /user_images/. The manipulation leads to direct request. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
1%
Низкий
почти 2 года назад
github логотип
GHSA-2pr9-w7jf-v4v7

Philips SureSigns VS4, A.07.107 and prior. The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CVSS3: 2.1
0%
Низкий
около 4 лет назад
github логотип
GHSA-2pr9-mv6f-chvj

A stack buffer overflow in V8 in Google Chrome prior to 62.0.3202.75 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2pr9-fr5g-p8hm

V-SFT versions 6.2.10.0 and prior contain a stack-based buffer overflow in VS6ComFile!CSaveData::_conv_AnimationItem. Opening a crafted V7 file may lead to arbitrary code execution on the affected product.

CVSS3: 7.8
0%
Низкий
4 месяца назад
github логотип
GHSA-2pr9-53x2-jqgh

In the Linux kernel, the following vulnerability has been resolved: nilfs2: handle inconsistent state in nilfs_btnode_create_block() Syzbot reported that a buffer state inconsistency was detected in nilfs_btnode_create_block(), triggering a kernel bug. It is not appropriate to treat this inconsistency as a bug; it can occur if the argument block address (the buffer index of the newly created block) is a virtual block number and has been reallocated due to corruption of the bitmap used to manage its allocation state. So, modify nilfs_btnode_create_block() and its callers to treat it as a possible filesystem error, rather than triggering a kernel bug.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-2pr9-2h78-r68r

service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary DLL functions via the XF function, possibly related to an insecure exposed method.

59%
Средний
около 4 лет назад
github логотип
GHSA-2pr8-phx7-x9h3

protobuf.js: Denial of service from crafted field names in generated code

CVSS3: 5.3
0%
Низкий
3 месяца назад
github логотип
GHSA-2pr8-9hq9-m7pw

Cross-site scripting (XSS) vulnerability in the CMS Updater module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving the configuration page.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2pr7-vcjv-rp52

Buffer overflow in the Foundation framework for Mac OS X 10.3.9 allows local users to execute arbitrary code via a long environment variable.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2pr7-6gvg-hcv8

Vulnerability in the Oracle Crystal Ball product of Oracle Construction and Engineering (component: Installation). Supported versions that are affected are 11.1.2.0.000-11.1.2.4.900. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Crystal Ball executes to compromise Oracle Crystal Ball. While the vulnerability is in Oracle Crystal Ball, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Crystal Ball. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-2pr6-vhmf-w3qp

VMware vCenter Server (6.5 prior to 6.5 U1) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker with VC user privileges can inject malicious java-scripts which will get executed when other VC users access the page.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-2pr6-h9cg-7rr7

Cross Site Request Forgery (CSRF) vulnerability in Archer Platform before v.6.13 and fixed in v.6.12.0.6 and v.6.13.0 allows an authenticated attacker to execute arbitrary code via a crafted request.

CVSS3: 8.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-2pr6-76vf-7546

Denial of Service in js-yaml

CVSS3: 5.9
около 7 лет назад
github логотип
GHSA-2pr5-qxg3-pfqf

openjpeg v 2.5.0 was discovered to contain a NULL pointer dereference via the component /openjp2/dwt.c.

CVSS3: 6.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-2pr3-v8qp-792f

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Delicious WP Delicious allows DOM-Based XSS. This issue affects WP Delicious: from n/a through 1.8.4.

CVSS3: 6.5
0%
Низкий
около 1 года назад

Уязвимостей на страницу