Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 883

Количество 353 883

github логотип

GHSA-2mh8-gx2m-mr75

почти 7 лет назад

Out-of-Memory Error in Bouncy Castle Crypto

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2mh8-69x2-q9m6

около 4 лет назад

The joomsport_md_load AJAX action of the JoomSport WordPress plugin before 5.1.8, registered for both unauthenticated and unauthenticated users, unserialised user input from the shattr POST parameter, leading to a PHP Object Injection issue. Even though the plugin does not have a suitable gadget chain to exploit this, other installed plugins could, which might lead to more severe issues such as RCE

EPSS: Низкий
github логотип

GHSA-2mh7-vhgj-ccgw

больше 1 года назад

Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

EPSS: Низкий
github логотип

GHSA-2mh7-qxcw-q39g

почти 4 года назад

francoisjacquet/rosariosis vulnerable to Cross-Site Scripting (XSS)

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2mh7-fwqw-352w

около 2 лет назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themewinter Eventin allows Stored XSS.This issue affects Eventin: from n/a through 3.3.57.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2mh6-g78c-5h6c

почти 3 года назад

The Shared Files WordPress plugin before 1.7.6 does not return the right Content-Type header for the specified uploaded file. Therefore, an attacker can upload an allowed file extension injected with malicious scripts.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2mh6-5954-wmgr

больше 4 лет назад

Denial of service through Solaris 2.5.1 telnet by sending ^D characters.

EPSS: Низкий
github логотип

GHSA-2mh5-3cw6-hrrq

3 месяца назад

Spring Cloud Config has an Authorization Bypass Through User-Controlled Key

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2mh3-x6j9-j554

почти 2 года назад

The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2mh3-566h-4f4x

около 4 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans.

EPSS: Низкий
github логотип

GHSA-2mh2-9xm5-m59q

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: bonding: change ipsec_lock from spin lock to mutex In the cited commit, bond->ipsec_lock is added to protect ipsec_list, hence xdo_dev_state_add and xdo_dev_state_delete are called inside this lock. As ipsec_lock is a spin lock and such xfrmdev ops may sleep, "scheduling while atomic" will be triggered when changing bond's active slave. [ 101.055189] BUG: scheduling while atomic: bash/902/0x00000200 [ 101.055726] Modules linked in: [ 101.058211] CPU: 3 PID: 902 Comm: bash Not tainted 6.9.0-rc4+ #1 [ 101.058760] Hardware name: [ 101.059434] Call Trace: [ 101.059436] <TASK> [ 101.060873] dump_stack_lvl+0x51/0x60 [ 101.061275] __schedule_bug+0x4e/0x60 [ 101.061682] __schedule+0x612/0x7c0 [ 101.062078] ? __mod_timer+0x25c/0x370 [ 101.062486] schedule+0x25/0xd0 [ 101.062845] schedule_timeout+0x77/0xf0 [ 101.063265] ? asm_common_interrupt+0x22/0x40 [ 101.063724] ? __bpf_trace_itimer_state+0x10/0x...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2mgx-x7qr-pm5v

больше 4 лет назад

Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB21 for Statistics and (2) DB22 for Upgrade & Downgrade. NOTE: as of 20060719, Oracle has not disputed a claim by a reliable researcher that DB21 is for a local SQL injection vulnerability in SYS.DBMS_STATS, and that DB22 is for SQL injection in SYS.DBMS_UPGRADE.

EPSS: Низкий
github логотип

GHSA-2mgx-qf67-h3rj

около 4 лет назад

Unbound before 1.9.5 allows an out-of-bounds write in sldns_bget_token_par.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2mgx-6c3j-cxmq

больше 4 лет назад

MUTE 0.4 allows remote attackers to cause a denial of service (messages not forwarded) and obtain sensitive information about a target by filling a client's mWebCache cache with malicious "zombie" nodes.

EPSS: Низкий
github логотип

GHSA-2mgx-226x-8pwv

около 4 лет назад

AVideo vulnerable to Improper Privilege Management

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2mgw-9wh3-7pf5

около 4 лет назад

Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to users being able to delete their submitted page through URL manipulation.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2mgw-7q6p-8grg

3 месяца назад

FPDI: Memory Exhaustion and Endless Loop in FPDI leads to Denial of Service

EPSS: Низкий
github логотип

GHSA-2mgw-4f9j-94xj

больше 4 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JP2 files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14897.

EPSS: Низкий
github логотип

GHSA-2mgv-chq6-566c

около 4 лет назад

The System Security Services Daemon (SSSD) 1.11.6 does not properly identify group membership when a non-POSIX group is in a group membership chain, which allows local users to bypass access restrictions via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2mgr-wwxh-g3g7

около 4 лет назад

SQL injection vulnerability in the RSS page (DNNArticleRSS.aspx) in the ZLDNN DNNArticle module before 10.1 for DotNetNuke allows remote attackers to execute arbitrary SQL commands via the categoryid parameter.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2mh8-gx2m-mr75

Out-of-Memory Error in Bouncy Castle Crypto

CVSS3: 7.5
9%
Низкий
почти 7 лет назад
github логотип
GHSA-2mh8-69x2-q9m6

The joomsport_md_load AJAX action of the JoomSport WordPress plugin before 5.1.8, registered for both unauthenticated and unauthenticated users, unserialised user input from the shattr POST parameter, leading to a PHP Object Injection issue. Even though the plugin does not have a suitable gadget chain to exploit this, other installed plugins could, which might lead to more severe issues such as RCE

2%
Низкий
около 4 лет назад
github логотип
GHSA-2mh7-vhgj-ccgw

Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

больше 1 года назад
github логотип
GHSA-2mh7-qxcw-q39g

francoisjacquet/rosariosis vulnerable to Cross-Site Scripting (XSS)

CVSS3: 5.4
1%
Низкий
почти 4 года назад
github логотип
GHSA-2mh7-fwqw-352w

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themewinter Eventin allows Stored XSS.This issue affects Eventin: from n/a through 3.3.57.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-2mh6-g78c-5h6c

The Shared Files WordPress plugin before 1.7.6 does not return the right Content-Type header for the specified uploaded file. Therefore, an attacker can upload an allowed file extension injected with malicious scripts.

CVSS3: 6.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-2mh6-5954-wmgr

Denial of service through Solaris 2.5.1 telnet by sending ^D characters.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2mh5-3cw6-hrrq

Spring Cloud Config has an Authorization Bypass Through User-Controlled Key

CVSS3: 7.5
0%
Низкий
3 месяца назад
github логотип
GHSA-2mh3-x6j9-j554

The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions.

CVSS3: 6.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-2mh3-566h-4f4x

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans.

7%
Низкий
около 4 лет назад
github логотип
GHSA-2mh2-9xm5-m59q

In the Linux kernel, the following vulnerability has been resolved: bonding: change ipsec_lock from spin lock to mutex In the cited commit, bond->ipsec_lock is added to protect ipsec_list, hence xdo_dev_state_add and xdo_dev_state_delete are called inside this lock. As ipsec_lock is a spin lock and such xfrmdev ops may sleep, "scheduling while atomic" will be triggered when changing bond's active slave. [ 101.055189] BUG: scheduling while atomic: bash/902/0x00000200 [ 101.055726] Modules linked in: [ 101.058211] CPU: 3 PID: 902 Comm: bash Not tainted 6.9.0-rc4+ #1 [ 101.058760] Hardware name: [ 101.059434] Call Trace: [ 101.059436] <TASK> [ 101.060873] dump_stack_lvl+0x51/0x60 [ 101.061275] __schedule_bug+0x4e/0x60 [ 101.061682] __schedule+0x612/0x7c0 [ 101.062078] ? __mod_timer+0x25c/0x370 [ 101.062486] schedule+0x25/0xd0 [ 101.062845] schedule_timeout+0x77/0xf0 [ 101.063265] ? asm_common_interrupt+0x22/0x40 [ 101.063724] ? __bpf_trace_itimer_state+0x10/0x...

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-2mgx-x7qr-pm5v

Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB21 for Statistics and (2) DB22 for Upgrade & Downgrade. NOTE: as of 20060719, Oracle has not disputed a claim by a reliable researcher that DB21 is for a local SQL injection vulnerability in SYS.DBMS_STATS, and that DB22 is for SQL injection in SYS.DBMS_UPGRADE.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-2mgx-qf67-h3rj

Unbound before 1.9.5 allows an out-of-bounds write in sldns_bget_token_par.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2mgx-6c3j-cxmq

MUTE 0.4 allows remote attackers to cause a denial of service (messages not forwarded) and obtain sensitive information about a target by filling a client's mWebCache cache with malicious "zombie" nodes.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2mgx-226x-8pwv

AVideo vulnerable to Improper Privilege Management

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2mgw-9wh3-7pf5

Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to users being able to delete their submitted page through URL manipulation.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2mgw-7q6p-8grg

FPDI: Memory Exhaustion and Endless Loop in FPDI leads to Denial of Service

0%
Низкий
3 месяца назад
github логотип
GHSA-2mgw-4f9j-94xj

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JP2 files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14897.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2mgv-chq6-566c

The System Security Services Daemon (SSSD) 1.11.6 does not properly identify group membership when a non-POSIX group is in a group membership chain, which allows local users to bypass access restrictions via unspecified vectors.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2mgr-wwxh-g3g7

SQL injection vulnerability in the RSS page (DNNArticleRSS.aspx) in the ZLDNN DNNArticle module before 10.1 for DotNetNuke allows remote attackers to execute arbitrary SQL commands via the categoryid parameter.

2%
Низкий
около 4 лет назад

Уязвимостей на страницу