Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 373 892

Количество 373 892

github логотип

GHSA-3p97-hgvq-jvxr

больше 4 лет назад

The backtrack compilation code in the Irregex package (aka IrRegular Expressions) before 0.9.6 for Scheme allows remote attackers to cause a denial of service (memory consumption) via a crafted regular expression with a repeating pattern.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3p96-wrm7-xc3m

около 2 лет назад

An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlaceMetaData of Public CMS v.4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3p95-q82m-f2fv

11 месяцев назад

ELOG allows an authenticated user to modify or overwrite the configuration file, resulting in denial of service. If the execute facility is specifically enabled with the "-x" command line flag, attackers could execute OS commands on the host machine. By default, ELOG is not configured to allow shell commands or self-registration.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3p95-fjgp-pggx

больше 4 лет назад

Unspecified vulnerability in Adobe Flash Player 11.1.102.55 on Windows and Mac OS X allows remote attackers to execute arbitrary code via a crafted SWF file, as demonstrated by the second of two vulnerabilities exploited by the Intevydis vd_adobe_fp module in VulnDisco Step Ahead (SA). NOTE: as of 20111207, this disclosure has no actionable information. However, because the module author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

EPSS: Низкий
github логотип

GHSA-3p95-f3g8-fcgq

почти 5 лет назад

The BPF subsystem in the Linux kernel before 4.17 mishandles situations with a long jump over an instruction sequence where inner instructions require substantial expansions into multiple BPF instructions, leading to an overflow. This affects kernel/bpf/core.c and net/core/filter.c.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3p94-vj97-fm4q

почти 5 лет назад

OS Command Injection in fsa

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3p94-98w5-cmg9

3 дня назад

This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3p93-j4fw-gpx2

больше 4 лет назад

Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 or earlier allows untrusted applets and applications to read arbitrary memory via a crafted ZIP file.

EPSS: Низкий
github логотип

GHSA-3p92-jw9p-xx95

больше 4 лет назад

The PPP wvdial.lxdialog script in wvdial 1.4 and earlier creates a .config file with world readable permissions, which allows a local attacker in the dialout group to access login and password information.

EPSS: Низкий
github логотип

GHSA-3p92-886g-qxpq

больше 7 лет назад

Remote Memory Exposure in floody

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-3p92-82mx-28gc

6 месяцев назад

Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disclose information over a network.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-3p92-26vx-7f7j

около 3 лет назад

A vulnerability was found in SourceCodester Free Hospital Management System for Small Practices 1.0. It has been classified as critical. This affects an unknown part of the file appointment.php. The manipulation of the argument sheduledate leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-237561 was assigned to this vulnerability.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3p92-24w5-4jr6

больше 4 лет назад

SQL injection vulnerability in the Seed Coupon plugin before 1.6 for EC-CUBE allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3p8x-pc99-4p67

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to handling of .nessus files.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3p8x-c3hm-xmp2

9 месяцев назад

An improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.1, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow information disclosure to an authenticated attacker via crafted requests

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3p8v-w8mr-m3x8

почти 2 года назад

Butterfly has path/URL confusion in resource handling leading to multiple weaknesses

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-3p8v-593f-mgx8

12 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: tcp: fix skb_copy_ubufs() vs BIG TCP David Ahern reported crashes in skb_copy_ubufs() caused by TCP tx zerocopy using hugepages, and skb length bigger than ~68 KB. skb_copy_ubufs() assumed it could copy all payload using up to MAX_SKB_FRAGS order-0 pages. This assumption broke when BIG TCP was able to put up to 512 KB per skb. We did not hit this bug at Google because we use CONFIG_MAX_SKB_FRAGS=45 and limit gso_max_size to 180000. A solution is to use higher order pages if needed. v2: add missing __GFP_COMP, or we leak memory.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3p8r-p4q5-mc44

больше 4 лет назад

Violation Comments to GitLab Plugin has Insufficiently Protected Credentials

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3p8r-f28v-66f3

12 месяцев назад

Improper Encoding or Escaping of Output vulnerability in Hallo Welt! GmbH BlueSpice (Extension:BlueSpiceAvatars) allows Cross-Site Scripting (XSS). This issue affects BlueSpice: from 5 through 5.1.1.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-3p8q-7cfq-r67x

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in Octopus Deploy 3.7.0-3.17.13 (fixed in 3.17.14) allows remote authenticated users to inject arbitrary web script or HTML via the Step Template Name parameter.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3p97-hgvq-jvxr

The backtrack compilation code in the Irregex package (aka IrRegular Expressions) before 0.9.6 for Scheme allows remote attackers to cause a denial of service (memory consumption) via a crafted regular expression with a repeating pattern.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3p96-wrm7-xc3m

An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlaceMetaData of Public CMS v.4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.

CVSS3: 8.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-3p95-q82m-f2fv

ELOG allows an authenticated user to modify or overwrite the configuration file, resulting in denial of service. If the execute facility is specifically enabled with the "-x" command line flag, attackers could execute OS commands on the host machine. By default, ELOG is not configured to allow shell commands or self-registration.

CVSS3: 7.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-3p95-fjgp-pggx

Unspecified vulnerability in Adobe Flash Player 11.1.102.55 on Windows and Mac OS X allows remote attackers to execute arbitrary code via a crafted SWF file, as demonstrated by the second of two vulnerabilities exploited by the Intevydis vd_adobe_fp module in VulnDisco Step Ahead (SA). NOTE: as of 20111207, this disclosure has no actionable information. However, because the module author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

8%
Низкий
больше 4 лет назад
github логотип
GHSA-3p95-f3g8-fcgq

The BPF subsystem in the Linux kernel before 4.17 mishandles situations with a long jump over an instruction sequence where inner instructions require substantial expansions into multiple BPF instructions, leading to an overflow. This affects kernel/bpf/core.c and net/core/filter.c.

CVSS3: 7.8
1%
Низкий
почти 5 лет назад
github логотип
GHSA-3p94-vj97-fm4q

OS Command Injection in fsa

CVSS3: 7.8
1%
Низкий
почти 5 лет назад
github логотип
GHSA-3p94-98w5-cmg9

This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.

CVSS3: 7.8
0%
Низкий
3 дня назад
github логотип
GHSA-3p93-j4fw-gpx2

Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 or earlier allows untrusted applets and applications to read arbitrary memory via a crafted ZIP file.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3p92-jw9p-xx95

The PPP wvdial.lxdialog script in wvdial 1.4 and earlier creates a .config file with world readable permissions, which allows a local attacker in the dialout group to access login and password information.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3p92-886g-qxpq

Remote Memory Exposure in floody

CVSS3: 5.1
больше 7 лет назад
github логотип
GHSA-3p92-82mx-28gc

Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disclose information over a network.

CVSS3: 8.6
1%
Низкий
6 месяцев назад
github логотип
GHSA-3p92-26vx-7f7j

A vulnerability was found in SourceCodester Free Hospital Management System for Small Practices 1.0. It has been classified as critical. This affects an unknown part of the file appointment.php. The manipulation of the argument sheduledate leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-237561 was assigned to this vulnerability.

CVSS3: 6.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-3p92-24w5-4jr6

SQL injection vulnerability in the Seed Coupon plugin before 1.6 for EC-CUBE allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3p8x-pc99-4p67

Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to handling of .nessus files.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3p8x-c3hm-xmp2

An improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.1, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow information disclosure to an authenticated attacker via crafted requests

CVSS3: 6.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-3p8v-w8mr-m3x8

Butterfly has path/URL confusion in resource handling leading to multiple weaknesses

CVSS3: 9.1
2%
Низкий
почти 2 года назад
github логотип
GHSA-3p8v-593f-mgx8

In the Linux kernel, the following vulnerability has been resolved: tcp: fix skb_copy_ubufs() vs BIG TCP David Ahern reported crashes in skb_copy_ubufs() caused by TCP tx zerocopy using hugepages, and skb length bigger than ~68 KB. skb_copy_ubufs() assumed it could copy all payload using up to MAX_SKB_FRAGS order-0 pages. This assumption broke when BIG TCP was able to put up to 512 KB per skb. We did not hit this bug at Google because we use CONFIG_MAX_SKB_FRAGS=45 and limit gso_max_size to 180000. A solution is to use higher order pages if needed. v2: add missing __GFP_COMP, or we leak memory.

CVSS3: 5.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-3p8r-p4q5-mc44

Violation Comments to GitLab Plugin has Insufficiently Protected Credentials

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3p8r-f28v-66f3

Improper Encoding or Escaping of Output vulnerability in Hallo Welt! GmbH BlueSpice (Extension:BlueSpiceAvatars) allows Cross-Site Scripting (XSS). This issue affects BlueSpice: from 5 through 5.1.1.

CVSS3: 6.4
0%
Низкий
12 месяцев назад
github логотип
GHSA-3p8q-7cfq-r67x

Cross-site scripting (XSS) vulnerability in Octopus Deploy 3.7.0-3.17.13 (fixed in 3.17.14) allows remote authenticated users to inject arbitrary web script or HTML via the Step Template Name parameter.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу