Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 453

Количество 375 453

github логотип

GHSA-3mv6-r7mf-4mmv

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the web framework in Cisco Content Security Management on Security Management Appliance (SMA) devices allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCuh24749.

EPSS: Низкий
github логотип

GHSA-3mv5-rjm2-qwx6

больше 4 лет назад

An information disclosure vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow unauthenticated access to some configuration files which may contain usernames, license keys, IP addresses, and encrypted password hashes.

EPSS: Низкий
github логотип

GHSA-3mv5-343c-w2qg

почти 3 года назад

Ref methods into_ref, into_mut, into_slice, and into_slice_mut are unsound when used with cell::Ref or cell::RefMut

EPSS: Низкий
github логотип

GHSA-3mv4-jjf4-j7wj

около 3 лет назад

Adobe InDesign versions ID18.3 (and earlier) and ID17.4.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3mv4-77hr-gc5g

больше 4 лет назад

Launch Services in Apple Mac OS X 10.5.8 does not properly recognize an unsafe Uniform Type Identifier (UTI) in an exported document type in a downloaded application, which allows remote attackers to trigger the automatic opening of a file, and execute arbitrary code, via a crafted web site.

EPSS: Низкий
github логотип

GHSA-3mv4-6x34-qw3c

около 4 лет назад

A floating point exception (divide-by-zero) issue was discovered in SoX in functon read_samples() of voc.c file. An attacker with a crafted file, could cause an application to crash.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3mv4-59rc-qvqm

больше 4 лет назад

WordPress before 5.2.3 allows XSS in post previews by authenticated users.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3mv3-hfpq-vvw5

7 дней назад

In IP Multimedia Subsystem, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3mv3-2f4g-87xm

больше 3 лет назад

Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes are defined for this purpose. Links can be activated by clicks, or by automatic document events. The execution of such links must be subject to user approval. In the affected versions of OpenOffice, approval for certain links is not requested; when activated, such links could therefore result in arbitrary script execution.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3mv2-vmwh-rwfx

4 месяца назад

AVideo: 2FA toggle endpoint has no CSRF protection, letting an attacker page silently disable a logged-in victim's 2FA

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-3mv2-86j6-x44q

4 месяца назад

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-3mrx-hx45-5865

почти 2 года назад

Windows USB Video Class System Driver Elevation of Privilege Vulnerability

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-3mrx-5p8g-6q5j

больше 4 лет назад

PHPMemcachedAdmin 1.2.2 and earlier allows remote attackers to execute arbitrary PHP code via vectors related "serialized data and the last part of the concatenated filename," which creates a file in webroot.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-3mrx-4wfm-g48p

больше 3 лет назад

An issue discovered in Obsidian Canvas 1.1.9 allows remote attackers to send desktop notifications, record user audio and other unspecified impacts via embedded website on the canvas page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3mrw-xf65-fqjh

2 месяца назад

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix busy dentry used after unmounting Since commit 340cea84f691c ("cifs: open files should not hold ref on superblock"), cifs file only holds the dentry ref_cnt, the cifs file close work(cfile->deferred) could be executed after unmounting, which will trigger a warning in generic_shutdown_super: BUG: Dentry 00000000a14a6845{i=c,n=file} still in use (1) [unmount of cifs cifs] The detailed processs is: process A process B kworker fd = open(PATH) vfs_open file->__f_path = *path // dentry->d_lockref.count = 1 cifs_open cifs_new_fileinfo cfile->dentry = dget(dentry) // dentry->d_lockref.count = 2 close(fd) __fput cifs_close queue_delayed_work(deferredclose_wq, cfile->deferred) dput(dentry) // dentry->d_lockref.count = 1 smb2_deferred_work_close _cifsFileInfo_put list_del(&cifs_file->flist) umount cl...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3mrv-v95f-r4rx

почти 5 лет назад

AOM v2.0.1 was discovered to contain a NULL pointer dereference via the component rate_hist.c.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3mrv-rm2p-hfgx

7 дней назад

Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 156.

EPSS: Низкий
github логотип

GHSA-3mrv-3jj9-w487

около 4 лет назад

The Allow SVG Files WordPress plugin through 1.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3mrr-qqw5-mqj9

больше 4 лет назад

The School Manage System, developed by ALLE INFORMATION CO., LTD., contains a vulnerability of Path Traversal, allowing attackers to access arbitrary files.

EPSS: Низкий
github логотип

GHSA-3mrr-pqw6-73rq

больше 4 лет назад

Multiple SQL injection vulnerabilities in Zoph (aka Zoph Organizes Photos) 0.9.1 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) _action parameter to group.php or (2) user.php or the (3) location_id parameter to photos.php in php/.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3mv6-r7mf-4mmv

Cross-site scripting (XSS) vulnerability in the web framework in Cisco Content Security Management on Security Management Appliance (SMA) devices allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCuh24749.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mv5-rjm2-qwx6

An information disclosure vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow unauthenticated access to some configuration files which may contain usernames, license keys, IP addresses, and encrypted password hashes.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mv5-343c-w2qg

Ref methods into_ref, into_mut, into_slice, and into_slice_mut are unsound when used with cell::Ref or cell::RefMut

почти 3 года назад
github логотип
GHSA-3mv4-jjf4-j7wj

Adobe InDesign versions ID18.3 (and earlier) and ID17.4.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-3mv4-77hr-gc5g

Launch Services in Apple Mac OS X 10.5.8 does not properly recognize an unsafe Uniform Type Identifier (UTI) in an exported document type in a downloaded application, which allows remote attackers to trigger the automatic opening of a file, and execute arbitrary code, via a crafted web site.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3mv4-6x34-qw3c

A floating point exception (divide-by-zero) issue was discovered in SoX in functon read_samples() of voc.c file. An attacker with a crafted file, could cause an application to crash.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-3mv4-59rc-qvqm

WordPress before 5.2.3 allows XSS in post previews by authenticated users.

CVSS3: 5.4
5%
Низкий
больше 4 лет назад
github логотип
GHSA-3mv3-hfpq-vvw5

In IP Multimedia Subsystem, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 8.8
0%
Низкий
7 дней назад
github логотип
GHSA-3mv3-2f4g-87xm

Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes are defined for this purpose. Links can be activated by clicks, or by automatic document events. The execution of such links must be subject to user approval. In the affected versions of OpenOffice, approval for certain links is not requested; when activated, such links could therefore result in arbitrary script execution.

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3mv2-vmwh-rwfx

AVideo: 2FA toggle endpoint has no CSRF protection, letting an attacker page silently disable a logged-in victim's 2FA

CVSS3: 5.7
0%
Низкий
4 месяца назад
github логотип
GHSA-3mv2-86j6-x44q

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
4 месяца назад
github логотип
GHSA-3mrx-hx45-5865

Windows USB Video Class System Driver Elevation of Privilege Vulnerability

CVSS3: 6.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-3mrx-5p8g-6q5j

PHPMemcachedAdmin 1.2.2 and earlier allows remote attackers to execute arbitrary PHP code via vectors related "serialized data and the last part of the concatenated filename," which creates a file in webroot.

CVSS3: 9.8
12%
Средний
больше 4 лет назад
github логотип
GHSA-3mrx-4wfm-g48p

An issue discovered in Obsidian Canvas 1.1.9 allows remote attackers to send desktop notifications, record user audio and other unspecified impacts via embedded website on the canvas page.

CVSS3: 6.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-3mrw-xf65-fqjh

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix busy dentry used after unmounting Since commit 340cea84f691c ("cifs: open files should not hold ref on superblock"), cifs file only holds the dentry ref_cnt, the cifs file close work(cfile->deferred) could be executed after unmounting, which will trigger a warning in generic_shutdown_super: BUG: Dentry 00000000a14a6845{i=c,n=file} still in use (1) [unmount of cifs cifs] The detailed processs is: process A process B kworker fd = open(PATH) vfs_open file->__f_path = *path // dentry->d_lockref.count = 1 cifs_open cifs_new_fileinfo cfile->dentry = dget(dentry) // dentry->d_lockref.count = 2 close(fd) __fput cifs_close queue_delayed_work(deferredclose_wq, cfile->deferred) dput(dentry) // dentry->d_lockref.count = 1 smb2_deferred_work_close _cifsFileInfo_put list_del(&cifs_file->flist) umount cl...

CVSS3: 7.8
0%
Низкий
2 месяца назад
github логотип
GHSA-3mrv-v95f-r4rx

AOM v2.0.1 was discovered to contain a NULL pointer dereference via the component rate_hist.c.

CVSS3: 6.5
1%
Низкий
почти 5 лет назад
github логотип
GHSA-3mrv-rm2p-hfgx

Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 156.

0%
Низкий
7 дней назад
github логотип
GHSA-3mrv-3jj9-w487

The Allow SVG Files WordPress plugin through 1.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-3mrr-qqw5-mqj9

The School Manage System, developed by ALLE INFORMATION CO., LTD., contains a vulnerability of Path Traversal, allowing attackers to access arbitrary files.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mrr-pqw6-73rq

Multiple SQL injection vulnerabilities in Zoph (aka Zoph Organizes Photos) 0.9.1 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) _action parameter to group.php or (2) user.php or the (3) location_id parameter to photos.php in php/.

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу