Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-2hxx-r3w3-pc94

около 4 лет назад

An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2019-0549, CVE-2019-0554, CVE-2019-0569.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2hxx-m8v6-fcm5

2 месяца назад

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn4: Prevent OOB reads when parsing IB Rewrite the IB parsing to use amdgpu_ib_get_value() which handles the bounds checks.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2hxw-2gfv-p3w2

около 2 лет назад

The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2hxv-mx8x-mcj9

почти 8 лет назад

Spina gem vulnerable to Cross-site request forgery (CSRF) vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2hxv-mq53-vg5m

9 месяцев назад

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26.1 and iPadOS 26.1, tvOS 26.1, visionOS 26.1, macOS Sequoia 15.7.2. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2hxv-86mh-6c78

2 месяца назад

A flaw has been found in Shibby Tomato 1.28. The affected element is the function send of the file usr/sbin/miniupnpd of the component SUBSCRIBE Call Handler. This manipulation causes server-side request forgery. The attack may be initiated remotely. This project is superseded by FreshTomato. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2hxr-f3r4-c6v6

около 4 лет назад

A crafted NTFS image can cause an out-of-bounds access in ntfs_inode_sync_standard_information in NTFS-3G < 2021.8.22.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2hxr-89p3-mvg2

около 4 лет назад

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2hxq-j7vv-gr4m

около 4 лет назад

There is a stack overflow vulnerability in the goform/fast_setting_wifi_set function in the httpd service of Tenda ac9 15.03.2.21_cn router. An attacker can obtain a stable shell through a carefully constructed payload

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2hxq-hqp9-w42p

больше 4 лет назад

The use of a hard-coded cryptographic key significantly increases the possibility encrypted data may be recovered from the Patient Information Center iX (PIC iX) Versions B.02, C.02, and C.03.

EPSS: Низкий
github логотип

GHSA-2hxh-f4xp-4wcj

больше 1 года назад

Under specific circumstances, insecure permissions in Ivanti Performance Manager before version 2024.3 HF1, 2024.1 HF1, or 2023.3 HF1 allows a local authenticated attacker to achieve local privilege escalation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2hxg-rh2v-hj3h

около 4 лет назад

In callUnchecked of DocumentsProvider.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege allowing a caller to copy, move, or delete files accessible to DocumentsProvider with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157320716

EPSS: Низкий
github логотип

GHSA-2hxg-84pv-j2pg

около 1 года назад

A vulnerability was found in FLIR AX8 up to 1.46. It has been declared as critical. This vulnerability affects unknown code of the file /upload.php. The manipulation of the argument File leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2hxf-vvc6-4wwp

около 4 лет назад

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for control calls where the software reads or writes to a buffer by using an index or pointer that references a memory location after the end of the buffer, which may lead to data tampering or denial of service.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2hxf-jmpm-jxjc

около 2 лет назад

Server-Side Request Forgery (SSRF) vulnerability in Seraphinite Solutions Seraphinite Post .DOCX Source.This issue affects Seraphinite Post .DOCX Source: from n/a through 2.16.9.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2hxf-gmcq-wh7p

больше 4 лет назад

Auction Weaver 1.0 through 1.04 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the username or bidfile form fields.

EPSS: Низкий
github логотип

GHSA-2hxf-733f-2428

5 месяцев назад

In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10320471; Issue ID: MSV-5535.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-2hxf-5ppp-g398

9 месяцев назад

A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Revive Adserver version 5.5.2. An attacker could trick a user with access to the user interface of a Revive Adserver instance into clicking on a specifically crafted URL and execute injected JavaScript code in the context of the victim's browser. The session cookie cannot be accessed, but a number of other operations could be performed. The vulnerability is present in the admin-search.php file and can be exploited via the compact parameter.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2hxc-x8ph-68p8

около 4 лет назад

Unspecified vulnerability in the domain alias management in Virtual Hosting Control System (VHCS) 2.4.6.2, related to "creating and deleting forwards for domain aliases," allows users to hijack the forwardings of other users.

EPSS: Низкий
github логотип

GHSA-2hxc-g3vg-5jpj

около 4 лет назад

A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Security Feature Bypass Vulnerability'.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2hxx-r3w3-pc94

An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2019-0549, CVE-2019-0554, CVE-2019-0569.

CVSS3: 5.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-2hxx-m8v6-fcm5

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn4: Prevent OOB reads when parsing IB Rewrite the IB parsing to use amdgpu_ib_get_value() which handles the bounds checks.

CVSS3: 7.1
0%
Низкий
2 месяца назад
github логотип
GHSA-2hxw-2gfv-p3w2

The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVSS3: 8.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-2hxv-mx8x-mcj9

Spina gem vulnerable to Cross-site request forgery (CSRF) vulnerability

CVSS3: 8.8
1%
Низкий
почти 8 лет назад
github логотип
GHSA-2hxv-mq53-vg5m

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26.1 and iPadOS 26.1, tvOS 26.1, visionOS 26.1, macOS Sequoia 15.7.2. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.

CVSS3: 7.5
1%
Низкий
9 месяцев назад
github логотип
GHSA-2hxv-86mh-6c78

A flaw has been found in Shibby Tomato 1.28. The affected element is the function send of the file usr/sbin/miniupnpd of the component SUBSCRIBE Call Handler. This manipulation causes server-side request forgery. The attack may be initiated remotely. This project is superseded by FreshTomato. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 7.3
0%
Низкий
2 месяца назад
github логотип
GHSA-2hxr-f3r4-c6v6

A crafted NTFS image can cause an out-of-bounds access in ntfs_inode_sync_standard_information in NTFS-3G < 2021.8.22.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-2hxr-89p3-mvg2

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

CVSS3: 8.8
9%
Низкий
около 4 лет назад
github логотип
GHSA-2hxq-j7vv-gr4m

There is a stack overflow vulnerability in the goform/fast_setting_wifi_set function in the httpd service of Tenda ac9 15.03.2.21_cn router. An attacker can obtain a stable shell through a carefully constructed payload

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2hxq-hqp9-w42p

The use of a hard-coded cryptographic key significantly increases the possibility encrypted data may be recovered from the Patient Information Center iX (PIC iX) Versions B.02, C.02, and C.03.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-2hxh-f4xp-4wcj

Under specific circumstances, insecure permissions in Ivanti Performance Manager before version 2024.3 HF1, 2024.1 HF1, or 2023.3 HF1 allows a local authenticated attacker to achieve local privilege escalation.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2hxg-rh2v-hj3h

In callUnchecked of DocumentsProvider.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege allowing a caller to copy, move, or delete files accessible to DocumentsProvider with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157320716

0%
Низкий
около 4 лет назад
github логотип
GHSA-2hxg-84pv-j2pg

A vulnerability was found in FLIR AX8 up to 1.46. It has been declared as critical. This vulnerability affects unknown code of the file /upload.php. The manipulation of the argument File leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
0%
Низкий
около 1 года назад
github логотип
GHSA-2hxf-vvc6-4wwp

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for control calls where the software reads or writes to a buffer by using an index or pointer that references a memory location after the end of the buffer, which may lead to data tampering or denial of service.

CVSS3: 7.1
0%
Низкий
около 4 лет назад
github логотип
GHSA-2hxf-jmpm-jxjc

Server-Side Request Forgery (SSRF) vulnerability in Seraphinite Solutions Seraphinite Post .DOCX Source.This issue affects Seraphinite Post .DOCX Source: from n/a through 2.16.9.

CVSS3: 7.2
0%
Низкий
около 2 лет назад
github логотип
GHSA-2hxf-gmcq-wh7p

Auction Weaver 1.0 through 1.04 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the username or bidfile form fields.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2hxf-733f-2428

In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10320471; Issue ID: MSV-5535.

CVSS3: 4.4
0%
Низкий
5 месяцев назад
github логотип
GHSA-2hxf-5ppp-g398

A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Revive Adserver version 5.5.2. An attacker could trick a user with access to the user interface of a Revive Adserver instance into clicking on a specifically crafted URL and execute injected JavaScript code in the context of the victim's browser. The session cookie cannot be accessed, but a number of other operations could be performed. The vulnerability is present in the admin-search.php file and can be exploited via the compact parameter.

CVSS3: 6.3
1%
Низкий
9 месяцев назад
github логотип
GHSA-2hxc-x8ph-68p8

Unspecified vulnerability in the domain alias management in Virtual Hosting Control System (VHCS) 2.4.6.2, related to "creating and deleting forwards for domain aliases," allows users to hijack the forwardings of other users.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2hxc-g3vg-5jpj

A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Security Feature Bypass Vulnerability'.

CVSS3: 7.8
4%
Низкий
около 4 лет назад

Уязвимостей на страницу