Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 373 892

Количество 373 892

github логотип

GHSA-3p35-rr8v-cfg2

4 месяца назад

Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 148.0.7778.216 allowed a local attacker to execute arbitrary code via a malicious file. (Chromium security severity: High)

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3p35-pmr9-qf5c

больше 4 лет назад

SQL injection vulnerability in index.php in the RSGallery (com_rsgallery) 2.0 beta 5 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in an inline page action.

EPSS: Низкий
github логотип

GHSA-3p35-jq3v-gh22

10 месяцев назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий
github логотип

GHSA-3p35-64mh-v96v

больше 4 лет назад

Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consume excess CPU.

CVSS3: 7.5
EPSS: Высокий
github логотип

GHSA-3p34-w4f6-5xh2

3 месяца назад

better-helperjs Vulnerable to Directory Traversal via String Prefix Bypass in Static Server

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3p34-8x49-x9wx

больше 4 лет назад

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-3118, CVE-2015-3124, CVE-2015-3127, CVE-2015-3128, CVE-2015-3129, CVE-2015-3131, CVE-2015-3136, CVE-2015-3137, CVE-2015-4428, CVE-2015-4430, and CVE-2015-5117.

EPSS: Низкий
github логотип

GHSA-3p34-6p74-74v3

больше 4 лет назад

NETGEAR WAC510 devices before 5.0.10.2 are affected by disclosure of sensitive information.

EPSS: Низкий
github логотип

GHSA-3p33-32v8-fg8j

4 дня назад

Description `getNimbusConf` returned the complete daemon configuration without redaction after only a user-level authorization check. Where the cluster is configured with them, that response includes `storm.zookeeper.auth.payload` and the keystore and truststore passwords for the Thrift, Netty and ZooKeeper TLS configuration. The project masks passwords elsewhere before display, so the omission here is inconsistent rather than intended. The UI endpoint `/api/v1/cluster/configuration` compounded this. It carried no `@AuthNimbusOp` annotation, and the authorization filter treated a missing annotation as "no gate required" and returned immediately, so the endpoint applied no per-user check at all and proxied the request under the UI daemon's own principal. Any user able to pass `ui.filter` therefore received the full configuration, including principals that Nimbus itself would have refused.  Mitigation Upgrade to 3.1.0, where credential-bearing values are masked before the configu...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3p32-j457-pg5x

больше 5 лет назад

Query Binding Exploitation

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3p32-8vq4-qvph

почти 2 года назад

An issue in aedes v0.51.2 allows attackers to cause a Denial of Service(DoS) via a crafted request.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3p2x-p2h6-wp37

около 4 лет назад

Improper initialization in the Intel(R) Data Center Manager software before version 4.1 may allow an authenticated user to potentially enable denial of service via local access.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3p2x-hjxj-c7rv

6 месяцев назад

Duplicate Advisory: OpenClaw's system.run approval TOCTOU via mutable symlink cwd target on node host

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3p2x-hfrr-wj4w

больше 1 года назад

Denial of service due to allocation of resources without limits. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39904.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3p2x-fgmw-32pv

больше 2 лет назад

Windows Subsystem for Linux Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3p2x-2cfv-p7xm

больше 4 лет назад

Multiple vulnerabilities in Midnight Commander (mc) before 4.6.0, with unknown impact, related to "Insecure temporary file and directory creations."

EPSS: Низкий
github логотип

GHSA-3p2w-3263-9gr3

около 4 лет назад

Uncontrolled recursion in Decoder.Skip in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a deeply nested XML document.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3p2v-w863-5q4c

9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: i2c: cadence: cdns_i2c_master_xfer(): Fix runtime PM leak on error path The cdns_i2c_master_xfer() function gets a runtime PM reference when the function is entered. This reference is released when the function is exited. There is currently one error path where the function exits directly, which leads to a leak of the runtime PM reference. Make sure that this error path also releases the runtime PM reference.

EPSS: Низкий
github логотип

GHSA-3p2v-g86r-3rwm

3 дня назад

In VPU, there is a possible shared memory overwrite due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3p2v-4qj8-6w5f

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: media: v4l2-core: explicitly clear ioctl input data As seen from a recent syzbot bug report, mistakes in the compat ioctl implementation can lead to uninitialized kernel stack data getting used as input for driver ioctl handlers. The reported bug is now fixed, but it's possible that other related bugs are still present or get added in the future. As the drivers need to check user input already, the possible impact is fairly low, but it might still cause an information leak. To be on the safe side, always clear the entire ioctl buffer before calling the conversion handler functions that are meant to initialize them.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3p2r-ffrh-j979

7 месяцев назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Xerox CentreWare on Windows allows Stored XSS.This issue affects CentreWare: through 7.0.6.  Consider upgrading Xerox® CentreWare Web® to v7.2.2.25 via the software available on Xerox.com

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3p35-rr8v-cfg2

Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 148.0.7778.216 allowed a local attacker to execute arbitrary code via a malicious file. (Chromium security severity: High)

CVSS3: 7.8
0%
Низкий
4 месяца назад
github логотип
GHSA-3p35-pmr9-qf5c

SQL injection vulnerability in index.php in the RSGallery (com_rsgallery) 2.0 beta 5 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in an inline page action.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3p35-jq3v-gh22

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

10 месяцев назад
github логотип
GHSA-3p35-64mh-v96v

Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consume excess CPU.

CVSS3: 7.5
82%
Высокий
больше 4 лет назад
github логотип
GHSA-3p34-w4f6-5xh2

better-helperjs Vulnerable to Directory Traversal via String Prefix Bypass in Static Server

CVSS3: 7.5
3 месяца назад
github логотип
GHSA-3p34-8x49-x9wx

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-3118, CVE-2015-3124, CVE-2015-3127, CVE-2015-3128, CVE-2015-3129, CVE-2015-3131, CVE-2015-3136, CVE-2015-3137, CVE-2015-4428, CVE-2015-4430, and CVE-2015-5117.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-3p34-6p74-74v3

NETGEAR WAC510 devices before 5.0.10.2 are affected by disclosure of sensitive information.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3p33-32v8-fg8j

Description `getNimbusConf` returned the complete daemon configuration without redaction after only a user-level authorization check. Where the cluster is configured with them, that response includes `storm.zookeeper.auth.payload` and the keystore and truststore passwords for the Thrift, Netty and ZooKeeper TLS configuration. The project masks passwords elsewhere before display, so the omission here is inconsistent rather than intended. The UI endpoint `/api/v1/cluster/configuration` compounded this. It carried no `@AuthNimbusOp` annotation, and the authorization filter treated a missing annotation as "no gate required" and returned immediately, so the endpoint applied no per-user check at all and proxied the request under the UI daemon's own principal. Any user able to pass `ui.filter` therefore received the full configuration, including principals that Nimbus itself would have refused.  Mitigation Upgrade to 3.1.0, where credential-bearing values are masked before the configu...

CVSS3: 6.5
0%
Низкий
4 дня назад
github логотип
GHSA-3p32-j457-pg5x

Query Binding Exploitation

CVSS3: 7.2
2%
Низкий
больше 5 лет назад
github логотип
GHSA-3p32-8vq4-qvph

An issue in aedes v0.51.2 allows attackers to cause a Denial of Service(DoS) via a crafted request.

CVSS3: 7.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-3p2x-p2h6-wp37

Improper initialization in the Intel(R) Data Center Manager software before version 4.1 may allow an authenticated user to potentially enable denial of service via local access.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-3p2x-hjxj-c7rv

Duplicate Advisory: OpenClaw's system.run approval TOCTOU via mutable symlink cwd target on node host

CVSS3: 6.5
6 месяцев назад
github логотип
GHSA-3p2x-hfrr-wj4w

Denial of service due to allocation of resources without limits. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39904.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3p2x-fgmw-32pv

Windows Subsystem for Linux Elevation of Privilege Vulnerability

CVSS3: 7.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3p2x-2cfv-p7xm

Multiple vulnerabilities in Midnight Commander (mc) before 4.6.0, with unknown impact, related to "Insecure temporary file and directory creations."

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3p2w-3263-9gr3

Uncontrolled recursion in Decoder.Skip in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a deeply nested XML document.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-3p2v-w863-5q4c

In the Linux kernel, the following vulnerability has been resolved: i2c: cadence: cdns_i2c_master_xfer(): Fix runtime PM leak on error path The cdns_i2c_master_xfer() function gets a runtime PM reference when the function is entered. This reference is released when the function is exited. There is currently one error path where the function exits directly, which leads to a leak of the runtime PM reference. Make sure that this error path also releases the runtime PM reference.

0%
Низкий
9 месяцев назад
github логотип
GHSA-3p2v-g86r-3rwm

In VPU, there is a possible shared memory overwrite due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 6.7
0%
Низкий
3 дня назад
github логотип
GHSA-3p2v-4qj8-6w5f

In the Linux kernel, the following vulnerability has been resolved: media: v4l2-core: explicitly clear ioctl input data As seen from a recent syzbot bug report, mistakes in the compat ioctl implementation can lead to uninitialized kernel stack data getting used as input for driver ioctl handlers. The reported bug is now fixed, but it's possible that other related bugs are still present or get added in the future. As the drivers need to check user input already, the possible impact is fairly low, but it might still cause an information leak. To be on the safe side, always clear the entire ioctl buffer before calling the conversion handler functions that are meant to initialize them.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3p2r-ffrh-j979

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Xerox CentreWare on Windows allows Stored XSS.This issue affects CentreWare: through 7.0.6.  Consider upgrading Xerox® CentreWare Web® to v7.2.2.25 via the software available on Xerox.com

CVSS3: 5.3
0%
Низкий
7 месяцев назад

Уязвимостей на страницу