Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 972

Количество 353 972

github логотип

GHSA-2p2p-xpf9-5p78

больше 4 лет назад

In the GNU C Library (aka glibc or libc6) before 2.28, parse_reg_exp in posix/regcomp.c misparses alternatives, which allows attackers to cause a denial of service (assertion failure and application exit) or trigger an incorrect result by attempting a regular-expression match.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2p2m-395c-w8p7

около 4 лет назад

Unspecified vulnerability in GraphicsMagick before 1.2.3 allows remote attackers to cause a denial of service (crash) via unspecified vectors in DPX images. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-2p2j-5crh-g4rm

около 4 лет назад

An XML external entity (XXE) vulnerability in Pulse Connect Secure (PCS) before 9.1R9 and Pulse Policy Secure (PPS) before 9.1R9 allows remote authenticated admins to conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2p2g-mpv8-7wjq

около 4 лет назад

The groonga-httpd package 6.1.5-1 for Debian sets the /var/log/groonga ownership to the groonga account, which might let local users obtain root access because of unsafe interaction with logrotate. For example, an attacker can exploit a race condition to insert a symlink from /var/log/groonga/httpd to /etc/bash_completion.d. NOTE: this is an issue in the Debian packaging of the Groonga HTTP server.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-2p2f-w34f-c527

больше 4 лет назад

The frag3 preprocessor in Sourcefire Snort 2.4.3 does not properly reassemble certain fragmented packets with IP options, which allows remote attackers to evade detection of certain attacks, possibly related to IP option lengths.

EPSS: Низкий
github логотип

GHSA-2p2f-px33-4vv5

20 дней назад

nebula-mesh: CA private key not zeroized on web mobile-bundle error paths

EPSS: Низкий
github логотип

GHSA-2p2f-cx99-h5rw

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: ext4: add EXT4_INODE_HAS_XATTR_SPACE macro in xattr.h When adding an xattr to an inode, we must ensure that the inode_size is not less than EXT4_GOOD_OLD_INODE_SIZE + extra_isize + pad. Otherwise, the end position may be greater than the start position, resulting in UAF.

EPSS: Низкий
github логотип

GHSA-2p2c-vwq7-7vg6

около 4 лет назад

Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Denial of Service with large HTTP headers: By using a combination of many requests with maximum sized headers (almost 80 KB per connection), and carefully timed completion of the headers, it is possible to cause the HTTP server to abort from heap allocation failure. Attack potential is mitigated by the use of a load balancer or other proxy layer.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-2p2c-qgqr-9ghc

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: powerpc/bpf: Fix detecting BPF atomic instructions Commit 91c960b0056672 ("bpf: Rename BPF_XADD and prepare to encode other atomics in .imm") converted BPF_XADD to BPF_ATOMIC and added a way to distinguish instructions based on the immediate field. Existing JIT implementations were updated to check for the immediate field and to reject programs utilizing anything more than BPF_ADD (such as BPF_FETCH) in the immediate field. However, the check added to powerpc64 JIT did not look at the correct BPF instruction. Due to this, such programs would be accepted and incorrectly JIT'ed resulting in soft lockups, as seen with the atomic bounds test. Fix this by looking at the correct immediate value.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-2p29-98c8-mc4x

больше 3 лет назад

The TeraWallet plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 1.4.3. This is due to insufficient validation of the user-controlled key on the lock_unlock_terawallet AJAX action. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to lock/unlock other users wallets.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2p28-95f5-q8q3

3 месяца назад

NVIDIA NemoClaw contains a vulnerability in the validateEndpointUrl() SSRF protection component, where an attacker could cause a server-side request forgery by supplying a crafted endpoint URL referencing the 0.0.0.0/8 address range through a blueprint configuration file or CLI flag. A successful exploit of this vulnerability may lead to information disclosure.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2p28-5mvp-2j2r

около 4 лет назад

Drupal Comment reply form allows access to restricted content

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2p27-jf57-w2j7

больше 3 лет назад

Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This allows an attacker to fully compromise the underlying operating system on the device running ArubaOS.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2p27-3gqf-86g7

около 4 лет назад

Haraj v3.7 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Post Ads component.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2p26-r2gp-7xc2

5 месяцев назад

Improper verification of cryptographic signature in Font Settings prior to SMR Mar-2026 Release 1 allows physical attackers to use custom font.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-2p26-p43x-fhp8

25 дней назад

mint: Unbounded CONTINUATION/HEADERS frame accumulation (CONTINUATION flood)

EPSS: Низкий
github логотип

GHSA-2p26-9483-vh42

больше 4 лет назад

Mozilla Firefox allows for cookies to be set with a null domain (aka "domainless cookies"), which allows remote attackers to pass information between arbitrary domains and track user activity, as demonstrated by the domain attribute in the document.cookie variable in a javascript: window.

EPSS: Низкий
github логотип

GHSA-2p25-wrwc-3qp8

около 4 лет назад

An elevation of privilege vulnerability in the Broadcom bcmdhd driver. Product: Android. Versions: Android kernel. Android ID: A-63374465. References: B-V2017081501.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2p25-vjp8-gcmp

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Preliot Cache control by Cacholong allows Cross Site Request Forgery. This issue affects Cache control by Cacholong: from n/a through 5.4.1.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2p25-rmjx-pfqv

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: clk: imx: Remove CLK_SET_PARENT_GATE for DRAM mux for i.MX7D For i.MX7D DRAM related mux clock, the clock source change should ONLY be done done in low level asm code without accessing DRAM, and then calling clk API to sync the HW clock status with clk tree, it should never touch real clock source switch via clk API, so CLK_SET_PARENT_GATE flag should NOT be added, otherwise, DRAM's clock parent will be disabled when DRAM is active, and system will hang.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2p2p-xpf9-5p78

In the GNU C Library (aka glibc or libc6) before 2.28, parse_reg_exp in posix/regcomp.c misparses alternatives, which allows attackers to cause a denial of service (assertion failure and application exit) or trigger an incorrect result by attempting a regular-expression match.

CVSS3: 7.5
4%
Низкий
больше 4 лет назад
github логотип
GHSA-2p2m-395c-w8p7

Unspecified vulnerability in GraphicsMagick before 1.2.3 allows remote attackers to cause a denial of service (crash) via unspecified vectors in DPX images. NOTE: some of these details are obtained from third party information.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2p2j-5crh-g4rm

An XML external entity (XXE) vulnerability in Pulse Connect Secure (PCS) before 9.1R9 and Pulse Policy Secure (PPS) before 9.1R9 allows remote authenticated admins to conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.

CVSS3: 7.2
3%
Низкий
около 4 лет назад
github логотип
GHSA-2p2g-mpv8-7wjq

The groonga-httpd package 6.1.5-1 for Debian sets the /var/log/groonga ownership to the groonga account, which might let local users obtain root access because of unsafe interaction with logrotate. For example, an attacker can exploit a race condition to insert a symlink from /var/log/groonga/httpd to /etc/bash_completion.d. NOTE: this is an issue in the Debian packaging of the Groonga HTTP server.

CVSS3: 7
0%
Низкий
около 4 лет назад
github логотип
GHSA-2p2f-w34f-c527

The frag3 preprocessor in Sourcefire Snort 2.4.3 does not properly reassemble certain fragmented packets with IP options, which allows remote attackers to evade detection of certain attacks, possibly related to IP option lengths.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2p2f-px33-4vv5

nebula-mesh: CA private key not zeroized on web mobile-bundle error paths

20 дней назад
github логотип
GHSA-2p2f-cx99-h5rw

In the Linux kernel, the following vulnerability has been resolved: ext4: add EXT4_INODE_HAS_XATTR_SPACE macro in xattr.h When adding an xattr to an inode, we must ensure that the inode_size is not less than EXT4_GOOD_OLD_INODE_SIZE + extra_isize + pad. Otherwise, the end position may be greater than the start position, resulting in UAF.

около 1 года назад
github логотип
GHSA-2p2c-vwq7-7vg6

Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Denial of Service with large HTTP headers: By using a combination of many requests with maximum sized headers (almost 80 KB per connection), and carefully timed completion of the headers, it is possible to cause the HTTP server to abort from heap allocation failure. Attack potential is mitigated by the use of a load balancer or other proxy layer.

CVSS3: 7.5
10%
Средний
около 4 лет назад
github логотип
GHSA-2p2c-qgqr-9ghc

In the Linux kernel, the following vulnerability has been resolved: powerpc/bpf: Fix detecting BPF atomic instructions Commit 91c960b0056672 ("bpf: Rename BPF_XADD and prepare to encode other atomics in .imm") converted BPF_XADD to BPF_ATOMIC and added a way to distinguish instructions based on the immediate field. Existing JIT implementations were updated to check for the immediate field and to reject programs utilizing anything more than BPF_ADD (such as BPF_FETCH) in the immediate field. However, the check added to powerpc64 JIT did not look at the correct BPF instruction. Due to this, such programs would be accepted and incorrectly JIT'ed resulting in soft lockups, as seen with the atomic bounds test. Fix this by looking at the correct immediate value.

CVSS3: 3.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-2p29-98c8-mc4x

The TeraWallet plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 1.4.3. This is due to insufficient validation of the user-controlled key on the lock_unlock_terawallet AJAX action. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to lock/unlock other users wallets.

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2p28-95f5-q8q3

NVIDIA NemoClaw contains a vulnerability in the validateEndpointUrl() SSRF protection component, where an attacker could cause a server-side request forgery by supplying a crafted endpoint URL referencing the 0.0.0.0/8 address range through a blueprint configuration file or CLI flag. A successful exploit of this vulnerability may lead to information disclosure.

CVSS3: 6.3
0%
Низкий
3 месяца назад
github логотип
GHSA-2p28-5mvp-2j2r

Drupal Comment reply form allows access to restricted content

CVSS3: 8.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-2p27-jf57-w2j7

Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This allows an attacker to fully compromise the underlying operating system on the device running ArubaOS.

CVSS3: 7.2
2%
Низкий
больше 3 лет назад
github логотип
GHSA-2p27-3gqf-86g7

Haraj v3.7 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Post Ads component.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-2p26-r2gp-7xc2

Improper verification of cryptographic signature in Font Settings prior to SMR Mar-2026 Release 1 allows physical attackers to use custom font.

CVSS3: 2.4
0%
Низкий
5 месяцев назад
github логотип
GHSA-2p26-p43x-fhp8

mint: Unbounded CONTINUATION/HEADERS frame accumulation (CONTINUATION flood)

0%
Низкий
25 дней назад
github логотип
GHSA-2p26-9483-vh42

Mozilla Firefox allows for cookies to be set with a null domain (aka "domainless cookies"), which allows remote attackers to pass information between arbitrary domains and track user activity, as demonstrated by the domain attribute in the document.cookie variable in a javascript: window.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2p25-wrwc-3qp8

An elevation of privilege vulnerability in the Broadcom bcmdhd driver. Product: Android. Versions: Android kernel. Android ID: A-63374465. References: B-V2017081501.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-2p25-vjp8-gcmp

Cross-Site Request Forgery (CSRF) vulnerability in Preliot Cache control by Cacholong allows Cross Site Request Forgery. This issue affects Cache control by Cacholong: from n/a through 5.4.1.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2p25-rmjx-pfqv

In the Linux kernel, the following vulnerability has been resolved: clk: imx: Remove CLK_SET_PARENT_GATE for DRAM mux for i.MX7D For i.MX7D DRAM related mux clock, the clock source change should ONLY be done done in low level asm code without accessing DRAM, and then calling clk API to sync the HW clock status with clk tree, it should never touch real clock source switch via clk API, so CLK_SET_PARENT_GATE flag should NOT be added, otherwise, DRAM's clock parent will be disabled when DRAM is active, and system will hang.

CVSS3: 5.5
больше 1 года назад

Уязвимостей на страницу