Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 373 892

Количество 373 892

github логотип

GHSA-3p7f-hw68-ph5v

больше 4 лет назад

Nullsoft SHOUTcast server stores the administrative password in plaintext in a configuration file (sc_serv.conf), which could allow a local user to gain administrative privileges on the server.

EPSS: Низкий
github логотип

GHSA-3p7f-4r2q-wxmm

больше 2 лет назад

An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3p7c-r2j9-9rqv

около 1 месяца назад

In the Linux kernel, the following vulnerability has been resolved: media: pwc: Return queued buffers on start_streaming() failure The vb2 framework hands buffers to the driver via buf_queue() before calling start_streaming(). If start_streaming() returns an error without first returning those buffers via vb2_buffer_done(), vb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued buffers leak. pwc's start_streaming() had two early returns that hit this trap: -ENODEV when the USB device was already disconnected, and -ERESTARTSYS when mutex_lock_interruptible() was interrupted by a signal. Call the existing pwc_cleanup_queued_bufs() helper with VB2_BUF_STATE_QUEUED before returning (matching the state already used by the pwc_isoc_init() error path in the same function). This mirrors the uvcvideo fix in commit 4cf3b6fd54eb ("media: uvcvideo: Return queued buffers on start_streaming() failure").

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3p7c-m357-q3xv

почти 4 года назад

Use after free in Feedback service on Chrome OS in Google Chrome on Chrome OS prior to 107.0.5304.62 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific UI interaction. (Chrome security severity: Medium)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3p7c-fr6q-wvh6

9 дней назад

Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3p7c-89x3-6q88

больше 4 лет назад

The Intel Graphics Driver in Apple OS X through 10.9.2 does not properly validate a certain pointer, which allows attackers to execute arbitrary code via a crafted application.

EPSS: Низкий
github логотип

GHSA-3p7c-45px-fv4v

12 месяцев назад

Authorization Bypass Through User-Controlled Key vulnerability in Academy LMS Academy LMS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Academy LMS: from n/a through 3.3.4.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3p78-2x5r-gjpp

больше 4 лет назад

An issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x before 11.0.1. The wiki contains a persistent XSS issue due to a lack of output encoding affecting a specific markdown feature.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3p77-wg4c-qm24

больше 2 лет назад

Duplicate Advisory: Exposure of sensitive information in ClickHouse

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3p77-prh6-2vh7

больше 4 лет назад

Huawei Mate 30 Pro smartphones with versions earlier than 10.1.0.150(C00E136R5P3) have an improper authorization vulnerability. The system does not properly restrict the use of system service by applications, the attacker should trick the user into installing a malicious application, successful exploit could cause a denial of audio service.

EPSS: Низкий
github логотип

GHSA-3p76-rm7j-ghq5

больше 1 года назад

Windows SmartScreen Spoofing Vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3p76-j79h-ff2w

почти 5 лет назад

Improper access control vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior, WRC-1750GSV firmware v2.11 and prior, WRC-1900GST firmware v1.03 and prior, WRC-2533GST firmware v1.03 and prior, WRC-2533GSTA firmware v1.03 and prior, WRC-2533GST2 firmware v1.25 and prior, WRC-2533GST2SP firmware v1.25 and prior, WRC-2533GST2-G firmware v1.25 and prior, and EDWRC-2533GST2 firmware v1.25 and prior) allows a network-adjacent unauthenticated attacker to bypass access restriction, and to start the telnet service and execute an arbitrary OS command via unspecified vectors.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3p76-4rrp-wwv9

больше 1 года назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

EPSS: Низкий
github логотип

GHSA-3p75-q5cc-qmj7

больше 2 лет назад

Duplicate Advisory: Keycloak Open Redirect vulnerability

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-3p74-pwfx-pcgr

больше 4 лет назад

The IAX2 channel driver (chan_iax2) in Asterisk 1.2 before revision 72630 and 1.4 before revision 65679, when configured to allow unauthenticated calls, sends "early audio" to an unverified source IP address of a NEW message, which allows remote attackers to cause a denial of service (traffic amplification) via a spoofed NEW message.

EPSS: Низкий
github логотип

GHSA-3p74-fjhf-m5jm

около 1 года назад

An issue was discovered in Mahara 23.04.8 and 24.04.4. The use of a malicious export download URL can allow an attacker to download files that they do not have permission to download.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3p73-mm7v-4f6m

больше 3 лет назад

DoS vulnerability in MaliciousCode filter

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-3p73-7xw5-7gq3

9 дней назад

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3p73-75xq-v9wv

больше 2 лет назад

An unauthenticated remote attacker can write memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not always successful because of memory randomization.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-3p72-rmv7-7jc9

больше 4 лет назад

The ptvcursor_add function in the ptvcursor implementation in epan/proto.c in Wireshark 1.12.x before 1.12.7 does not check whether the expected amount of data is available, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3p7f-hw68-ph5v

Nullsoft SHOUTcast server stores the administrative password in plaintext in a configuration file (sc_serv.conf), which could allow a local user to gain administrative privileges on the server.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3p7f-4r2q-wxmm

An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.

CVSS3: 5.9
2%
Низкий
больше 2 лет назад
github логотип
GHSA-3p7c-r2j9-9rqv

In the Linux kernel, the following vulnerability has been resolved: media: pwc: Return queued buffers on start_streaming() failure The vb2 framework hands buffers to the driver via buf_queue() before calling start_streaming(). If start_streaming() returns an error without first returning those buffers via vb2_buffer_done(), vb2_start_streaming() fires WARN_ON(owned_by_drv_count) and the queued buffers leak. pwc's start_streaming() had two early returns that hit this trap: -ENODEV when the USB device was already disconnected, and -ERESTARTSYS when mutex_lock_interruptible() was interrupted by a signal. Call the existing pwc_cleanup_queued_bufs() helper with VB2_BUF_STATE_QUEUED before returning (matching the state already used by the pwc_isoc_init() error path in the same function). This mirrors the uvcvideo fix in commit 4cf3b6fd54eb ("media: uvcvideo: Return queued buffers on start_streaming() failure").

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3p7c-m357-q3xv

Use after free in Feedback service on Chrome OS in Google Chrome on Chrome OS prior to 107.0.5304.62 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific UI interaction. (Chrome security severity: Medium)

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-3p7c-fr6q-wvh6

Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine

CVSS3: 7.5
0%
Низкий
9 дней назад
github логотип
GHSA-3p7c-89x3-6q88

The Intel Graphics Driver in Apple OS X through 10.9.2 does not properly validate a certain pointer, which allows attackers to execute arbitrary code via a crafted application.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3p7c-45px-fv4v

Authorization Bypass Through User-Controlled Key vulnerability in Academy LMS Academy LMS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Academy LMS: from n/a through 3.3.4.

CVSS3: 5.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-3p78-2x5r-gjpp

An issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x before 11.0.1. The wiki contains a persistent XSS issue due to a lack of output encoding affecting a specific markdown feature.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3p77-wg4c-qm24

Duplicate Advisory: Exposure of sensitive information in ClickHouse

CVSS3: 8.8
больше 2 лет назад
github логотип
GHSA-3p77-prh6-2vh7

Huawei Mate 30 Pro smartphones with versions earlier than 10.1.0.150(C00E136R5P3) have an improper authorization vulnerability. The system does not properly restrict the use of system service by applications, the attacker should trick the user into installing a malicious application, successful exploit could cause a denial of audio service.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3p76-rm7j-ghq5

Windows SmartScreen Spoofing Vulnerability

CVSS3: 6.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-3p76-j79h-ff2w

Improper access control vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior, WRC-1750GSV firmware v2.11 and prior, WRC-1900GST firmware v1.03 and prior, WRC-2533GST firmware v1.03 and prior, WRC-2533GSTA firmware v1.03 and prior, WRC-2533GST2 firmware v1.25 and prior, WRC-2533GST2SP firmware v1.25 and prior, WRC-2533GST2-G firmware v1.25 and prior, and EDWRC-2533GST2 firmware v1.25 and prior) allows a network-adjacent unauthenticated attacker to bypass access restriction, and to start the telnet service and execute an arbitrary OS command via unspecified vectors.

CVSS3: 8.8
1%
Низкий
почти 5 лет назад
github логотип
GHSA-3p76-4rrp-wwv9

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

больше 1 года назад
github логотип
GHSA-3p75-q5cc-qmj7

Duplicate Advisory: Keycloak Open Redirect vulnerability

CVSS3: 4.6
больше 2 лет назад
github логотип
GHSA-3p74-pwfx-pcgr

The IAX2 channel driver (chan_iax2) in Asterisk 1.2 before revision 72630 and 1.4 before revision 65679, when configured to allow unauthenticated calls, sends "early audio" to an unverified source IP address of a NEW message, which allows remote attackers to cause a denial of service (traffic amplification) via a spoofed NEW message.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3p74-fjhf-m5jm

An issue was discovered in Mahara 23.04.8 and 24.04.4. The use of a malicious export download URL can allow an attacker to download files that they do not have permission to download.

CVSS3: 5.3
0%
Низкий
около 1 года назад
github логотип
GHSA-3p73-mm7v-4f6m

DoS vulnerability in MaliciousCode filter

CVSS3: 4.9
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3p73-7xw5-7gq3

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.

CVSS3: 5.4
0%
Низкий
9 дней назад
github логотип
GHSA-3p73-75xq-v9wv

An unauthenticated remote attacker can write memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not always successful because of memory randomization.

CVSS3: 7.4
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3p72-rmv7-7jc9

The ptvcursor_add function in the ptvcursor implementation in epan/proto.c in Wireshark 1.12.x before 1.12.7 does not check whether the expected amount of data is available, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

3%
Низкий
больше 4 лет назад

Уязвимостей на страницу