Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 714

Количество 353 714

github логотип

GHSA-2h6r-fv94-m5cr

больше 1 года назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-2h6r-fgmg-ppfq

9 месяцев назад

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in The Wikimedia Foundation Mediawiki Foundation - Springboard Extension allows Command Injection.This issue affects Mediawiki Foundation - Springboard Extension: master.

EPSS: Низкий
github логотип

GHSA-2h6p-mjgc-6qrf

11 месяцев назад

A denial-of-service issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26, iOS 18.7 and iPadOS 18.7. An app may be able to cause a denial-of-service.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2h6m-qr7j-x4hf

около 4 лет назад

Vulnerability in the Oracle Fusion Middleware component of Oracle Fusion Middleware (subcomponent: Oracle Notification Service). Supported versions that are affected are 12.2.1.2 and 12.2.1.3. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Fusion Middleware. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Fusion Middleware accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2h6j-mhcp-9j9h

4 месяца назад

GenieACS has an unauthenticated access vulnerability via the NBI API endpoint

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2h6j-3v9m-2v47

7 месяцев назад

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Scott Paterson Accept Donations with PayPal easy-paypal-donation allows Phishing.This issue affects Accept Donations with PayPal: from n/a through <= 1.5.1.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2h6h-vv39-q7cf

больше 4 лет назад

Out of bounds memory access in Blink Serial API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page and virtual serial port driver.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2h6h-vcrw-57ff

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix potential UAF in nfsd4_cb_getattr_release Once we drop the delegation reference, the fields embedded in it are no longer safe to access. Do that last.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2h6h-f2x3-xhhh

около 4 лет назад

Mozilla Firefox 33.0 and SeaMonkey before 2.31 include path strings in CSP violation reports, which allows remote attackers to obtain sensitive information via a web site that receives a report after a redirect.

EPSS: Низкий
github логотип

GHSA-2h6h-4q8g-8rmw

около 4 лет назад

The ReadDIBImage function in coders/dib.c in ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1 allows remote attackers to cause a denial of service (memory leak) via a crafted file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2h6g-jf6m-ch5q

3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_subset: Fix unbalanced refcnt in geth_free geth_alloc() increments the reference count, but geth_free() fails to decrement it. This prevents the configuration of attributes via configfs after unlinking the function. Decrement the reference count in geth_free() to ensure proper cleanup.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2h6g-8hmj-4mpg

около 4 лет назад

win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."

EPSS: Низкий
github логотип

GHSA-2h6g-3hxf-g52r

больше 4 лет назад

Bajie HTTP JServer 0.78, and other versions before 0.80, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP request for a CGI program that does not exist.

EPSS: Низкий
github логотип

GHSA-2h6f-r3qq-rcwx

около 4 лет назад

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1001, CVE-2019-1004, CVE-2019-1059.

EPSS: Низкий
github логотип

GHSA-2h6f-jv94-879x

около 4 лет назад

IBM BigFix Inventory v9 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2h6c-r45x-r8w4

около 4 лет назад

Microsoft Internet Explorer 6 SP1 and SP2, 7, and 8 allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."

EPSS: Средний
github логотип

GHSA-2h6c-m9mj-xfcf

больше 2 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

EPSS: Низкий
github логотип

GHSA-2h6c-j3gf-xp9r

больше 3 лет назад

IPFS go-bitfield vulnerable to DoS via malformed size arguments

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2h6c-9r57-fm42

больше 4 лет назад

Multiple SQL injection vulnerabilities in ASPMForum allow remote attackers to execute arbitrary SQL commands via the (1) harf parameter in kullanicilistesi.asp and (2) baslik parameter in forum.asp.

EPSS: Низкий
github логотип

GHSA-2h6c-6jr9-g2xg

около 1 года назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2h6r-fv94-m5cr

Rejected reason: Not used

больше 1 года назад
github логотип
GHSA-2h6r-fgmg-ppfq

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in The Wikimedia Foundation Mediawiki Foundation - Springboard Extension allows Command Injection.This issue affects Mediawiki Foundation - Springboard Extension: master.

1%
Низкий
9 месяцев назад
github логотип
GHSA-2h6p-mjgc-6qrf

A denial-of-service issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26, iOS 18.7 and iPadOS 18.7. An app may be able to cause a denial-of-service.

CVSS3: 5.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-2h6m-qr7j-x4hf

Vulnerability in the Oracle Fusion Middleware component of Oracle Fusion Middleware (subcomponent: Oracle Notification Service). Supported versions that are affected are 12.2.1.2 and 12.2.1.3. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Fusion Middleware. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Fusion Middleware accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 6.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-2h6j-mhcp-9j9h

GenieACS has an unauthenticated access vulnerability via the NBI API endpoint

CVSS3: 7.5
0%
Низкий
4 месяца назад
github логотип
GHSA-2h6j-3v9m-2v47

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Scott Paterson Accept Donations with PayPal easy-paypal-donation allows Phishing.This issue affects Accept Donations with PayPal: from n/a through <= 1.5.1.

CVSS3: 6.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-2h6h-vv39-q7cf

Out of bounds memory access in Blink Serial API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page and virtual serial port driver.

CVSS3: 8.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2h6h-vcrw-57ff

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix potential UAF in nfsd4_cb_getattr_release Once we drop the delegation reference, the fields embedded in it are no longer safe to access. Do that last.

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-2h6h-f2x3-xhhh

Mozilla Firefox 33.0 and SeaMonkey before 2.31 include path strings in CSP violation reports, which allows remote attackers to obtain sensitive information via a web site that receives a report after a redirect.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2h6h-4q8g-8rmw

The ReadDIBImage function in coders/dib.c in ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1 allows remote attackers to cause a denial of service (memory leak) via a crafted file.

CVSS3: 6.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-2h6g-jf6m-ch5q

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_subset: Fix unbalanced refcnt in geth_free geth_alloc() increments the reference count, but geth_free() fails to decrement it. This prevents the configuration of attributes via configfs after unlinking the function. Decrement the reference count in geth_free() to ensure proper cleanup.

CVSS3: 5.5
0%
Низкий
3 месяца назад
github логотип
GHSA-2h6g-8hmj-4mpg

win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."

3%
Низкий
около 4 лет назад
github логотип
GHSA-2h6g-3hxf-g52r

Bajie HTTP JServer 0.78, and other versions before 0.80, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP request for a CGI program that does not exist.

8%
Низкий
больше 4 лет назад
github логотип
GHSA-2h6f-r3qq-rcwx

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1001, CVE-2019-1004, CVE-2019-1059.

8%
Низкий
около 4 лет назад
github логотип
GHSA-2h6f-jv94-879x

IBM BigFix Inventory v9 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources.

CVSS3: 8.1
2%
Низкий
около 4 лет назад
github логотип
GHSA-2h6c-r45x-r8w4

Microsoft Internet Explorer 6 SP1 and SP2, 7, and 8 allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."

25%
Средний
около 4 лет назад
github логотип
GHSA-2h6c-m9mj-xfcf

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

больше 2 лет назад
github логотип
GHSA-2h6c-j3gf-xp9r

IPFS go-bitfield vulnerable to DoS via malformed size arguments

CVSS3: 5.9
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2h6c-9r57-fm42

Multiple SQL injection vulnerabilities in ASPMForum allow remote attackers to execute arbitrary SQL commands via the (1) harf parameter in kullanicilistesi.asp and (2) baslik parameter in forum.asp.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2h6c-6jr9-g2xg

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

около 1 года назад

Уязвимостей на страницу