Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 883

Количество 353 883

github логотип

GHSA-2m7q-4j9m-89vh

2 месяца назад

In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-2m7p-qcqr-gfv2

около 4 лет назад

The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr operations, which allows local users to bypass intended access restrictions and modify the attributes of arbitrary overlay files via a crafted application.

CVSS3: 6.7
EPSS: Средний
github логотип

GHSA-2m7m-jhx5-8crh

около 2 лет назад

IBM Aspera Orchestrator 4.0.1 could allow a remote attacker to enumerate usernames due to observable response discrepancies. IBM X-Force ID: 248545.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2m7m-j3mq-9g6p

около 1 года назад

A vulnerability, which was classified as critical, has been found in gmg137 snap7-rs up to 1.142.1. Affected by this issue is the function pthread_cond_destroy of the component Public API. The manipulation leads to memory corruption. The exploit has been disclosed to the public and may be used.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2m7m-3qp3-4h9x

около 4 лет назад

IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190741.

EPSS: Низкий
github логотип

GHSA-2m7j-prfm-384p

больше 4 лет назад

Buffer overflow in mah-jong 1.5.6 and earlier allows remote attackers to execute arbitrary code.

EPSS: Низкий
github логотип

GHSA-2m7j-4ff8-h52q

больше 1 года назад

Northern.tech Mender before 3.6.5 and 3.7.x before 3.7.5 has Incorrect Access Control.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2m7h-86qq-fp4v

около 4 лет назад

Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-2m7h-5m38-vhh4

10 месяцев назад

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'move_as_original_file' function in all versions up to, and including, 4.2.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2m7g-9q74-9m3q

около 6 лет назад

Improper Certificate Validation in Apache Beam

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2m7g-9m2h-fmjg

больше 3 лет назад

Cross-site Scripting (XSS) - Reflected in GitHub repository lirantal/daloradius prior to master-branch.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2m7g-78xc-qr55

около 4 лет назад

Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0, 10.3.6.0, 12.1.1.0, and 12.1.2.0 allows remote attackers to affect integrity via unknown vectors related to Console.

EPSS: Низкий
github логотип

GHSA-2m7f-2c58-jfxc

9 месяцев назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and 9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-2m79-pc7w-p467

больше 2 лет назад

A vulnerability was found in KylinSoft hedron-domain-hook up to 3.8.0.12-0k0.5. It has been declared as critical. This vulnerability affects the function init_kcm of the component DBus Handler. The manipulation leads to improper access controls. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. VDB-248578 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2m78-3m48-94h8

больше 3 лет назад

SQL-Injection vulnerability caused by the lack of verification of input values for the table name of DB used by the Mangboard bulletin board. A remote attacker can use this vulnerability to execute arbitrary code on the server where the bulletin board is running.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2m77-r9w3-w44v

3 месяца назад

A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in libsoup/soup-message-headers.c unconditionally appends each header value without validating for duplicate or conflicting Content-Length fields. This allows an attacker to send HTTP requests containing multiple Content-Length headers with differing values.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-2m77-r88p-x375

около 2 лет назад

Dell Peripheral Manager, versions prior to 1.7.6, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through preloading malicious DLL or symbolic link exploitation, leading to arbitrary code execution and escalation of privilege

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2m76-xr87-v8p2

около 4 лет назад

The WiFi component in Apple iOS before 5 stores WiFi credentials in an unspecified file, which makes it easier for remote attackers to obtain sensitive information via a crafted application.

EPSS: Низкий
github логотип

GHSA-2m76-jw89-jx9c

около 4 лет назад

The decode_frame function in libavcodec/eamad.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted Electronic Arts Madcow video data, which triggers an out-of-bounds array access.

EPSS: Низкий
github логотип

GHSA-2m76-j3f4-m2c2

8 месяцев назад

The Access Control Bypass vulnerability found in ALC WebCTRL and Carrier i-Vu in versions up to and including 8.5 allows a malicious actor to bypass intended access restrictions and expose sensitive information via the web based building automation server.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2m7q-4j9m-89vh

In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes.

CVSS3: 4.4
0%
Низкий
2 месяца назад
github логотип
GHSA-2m7p-qcqr-gfv2

The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr operations, which allows local users to bypass intended access restrictions and modify the attributes of arbitrary overlay files via a crafted application.

CVSS3: 6.7
22%
Средний
около 4 лет назад
github логотип
GHSA-2m7m-jhx5-8crh

IBM Aspera Orchestrator 4.0.1 could allow a remote attacker to enumerate usernames due to observable response discrepancies. IBM X-Force ID: 248545.

CVSS3: 5.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-2m7m-j3mq-9g6p

A vulnerability, which was classified as critical, has been found in gmg137 snap7-rs up to 1.142.1. Affected by this issue is the function pthread_cond_destroy of the component Public API. The manipulation leads to memory corruption. The exploit has been disclosed to the public and may be used.

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2m7m-3qp3-4h9x

IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190741.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2m7j-prfm-384p

Buffer overflow in mah-jong 1.5.6 and earlier allows remote attackers to execute arbitrary code.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-2m7j-4ff8-h52q

Northern.tech Mender before 3.6.5 and 3.7.x before 3.7.5 has Incorrect Access Control.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2m7h-86qq-fp4v

Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params

CVSS3: 8.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-2m7h-5m38-vhh4

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'move_as_original_file' function in all versions up to, and including, 4.2.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS3: 9.8
1%
Низкий
10 месяцев назад
github логотип
GHSA-2m7g-9q74-9m3q

Improper Certificate Validation in Apache Beam

CVSS3: 7.5
1%
Низкий
около 6 лет назад
github логотип
GHSA-2m7g-9m2h-fmjg

Cross-site Scripting (XSS) - Reflected in GitHub repository lirantal/daloradius prior to master-branch.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2m7g-78xc-qr55

Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0, 10.3.6.0, 12.1.1.0, and 12.1.2.0 allows remote attackers to affect integrity via unknown vectors related to Console.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2m7f-2c58-jfxc

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and 9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
1%
Низкий
9 месяцев назад
github логотип
GHSA-2m79-pc7w-p467

A vulnerability was found in KylinSoft hedron-domain-hook up to 3.8.0.12-0k0.5. It has been declared as critical. This vulnerability affects the function init_kcm of the component DBus Handler. The manipulation leads to improper access controls. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. VDB-248578 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2m78-3m48-94h8

SQL-Injection vulnerability caused by the lack of verification of input values for the table name of DB used by the Mangboard bulletin board. A remote attacker can use this vulnerability to execute arbitrary code on the server where the bulletin board is running.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2m77-r9w3-w44v

A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in libsoup/soup-message-headers.c unconditionally appends each header value without validating for duplicate or conflicting Content-Length fields. This allows an attacker to send HTTP requests containing multiple Content-Length headers with differing values.

CVSS3: 3.7
0%
Низкий
3 месяца назад
github логотип
GHSA-2m77-r88p-x375

Dell Peripheral Manager, versions prior to 1.7.6, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through preloading malicious DLL or symbolic link exploitation, leading to arbitrary code execution and escalation of privilege

CVSS3: 7.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-2m76-xr87-v8p2

The WiFi component in Apple iOS before 5 stores WiFi credentials in an unspecified file, which makes it easier for remote attackers to obtain sensitive information via a crafted application.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2m76-jw89-jx9c

The decode_frame function in libavcodec/eamad.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted Electronic Arts Madcow video data, which triggers an out-of-bounds array access.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2m76-j3f4-m2c2

The Access Control Bypass vulnerability found in ALC WebCTRL and Carrier i-Vu in versions up to and including 8.5 allows a malicious actor to bypass intended access restrictions and expose sensitive information via the web based building automation server.

0%
Низкий
8 месяцев назад

Уязвимостей на страницу