Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 714

Количество 353 714

github логотип

GHSA-2h5h-59f5-c5x9

около 3 лет назад

Rekor's compressed archives can result in OOM conditions

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2h5h-2fc6-g2qv

4 дня назад

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, watchOS 26.6. An app may be able to access sensitive user data.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2h5g-87fc-mwp6

около 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Archer GRC 5.x before 5.5.3 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2h5f-jcgv-ffv5

около 4 лет назад

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 175066.

EPSS: Низкий
github логотип

GHSA-2h5c-f427-3wjr

около 1 месяца назад

Argument Injection in TortoiseGitBlame via Malicious Git History Filenames Leads to Arbitrary File Write in TortoiseGit

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2h5c-85wg-jwx8

около 4 лет назад

Apple Safari 4.0.5 on Windows sends the "Authorization: Basic" header appropriate for one web site to a different web site named in a Location header received from the first site, which allows remote web servers to obtain sensitive information by logging HTTP requests. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-2h59-fjvh-cg52

больше 1 года назад

Silicon Labs Gecko OS DNS Response Processing Infinite Loop Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of DNS responses. The issue results from a logic error that can lead to an infinite loop. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-23392.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2h59-fhpr-vfx4

почти 3 года назад

A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackers to execute arbitrary code via crafted XML-RPC requests.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-2h58-x23m-3288

около 4 лет назад

IBM Sterling B2B Integrator Standard Edition 5.2 allows a user to view sensitive information that belongs to another user. IBM X-Force ID: 128619.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2h57-wv8w-2wmj

больше 2 лет назад

Adobe Substance 3D Designer versions 13.0.0 (and earlier) and 13.1.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2h57-5ppx-7x34

4 месяца назад

Use after free in Windows Speech Brokered Api allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2h57-3xqf-9v5f

около 4 лет назад

SQL injection vulnerability in default.asp in ASP Product Catalog allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2007-5220.

EPSS: Низкий
github логотип

GHSA-2h56-v244-fqpv

около 4 лет назад

Calsos CSDJ (CSDJ-B 01.08.00 and earlier, CSDJ-H 01.08.00 and earlier, CSDJ-D 01.08.00 and earlier, and CSDJ-A 03.08.00 and earlier) allows remote attackers to bypass access restriction and to obtain unauthorized historical data without access privileges via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2h56-q6pr-f3f8

около 4 лет назад

Unspecified vulnerability in ptrace in NetBSD-current before 20061027, NetBSD 3.0 and 3.0.1 before 20061027, and NetBSD 2.x before 20061119 allows local users to read kernel memory and obtain sensitive information via certain manipulations of a PT_LWPINFO request, which leads to a memory leak and information leak.

EPSS: Низкий
github логотип

GHSA-2h56-96mx-jvrh

около 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Google Analyticator plugin before 6.4.9.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) ga_adsense, (2) ga_admin_disable_DimentionIndex, (3) ga_downloads_prefix, (4) ga_downloads, or (5) ga_outbound_prefix parameter in the google-analyticator page to wp-admin/admin.php.

EPSS: Низкий
github логотип

GHSA-2h56-2mqr-w44f

3 месяца назад

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.7, macOS Tahoe 26.5. A remote attacker may be able to cause unexpected system termination.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2h55-w7q6-9v78

около 4 лет назад

IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive information. IBM X-Force ID: 148870.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2h55-hc4f-7vj2

около 4 лет назад

A heap-based buffer over-read exists in libopencad 0.2.0 in the ReadCHAR function in lib/dwg/io.cpp, resulting in an application crash.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2h54-g4cf-fg9x

около 4 лет назад

In setIPv6AddrGenMode of NetworkManagementService.java, there is a possible bypass of networking permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-141920289

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2h54-c9vf-47rr

около 4 лет назад

Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 59.0.3071.86 for Windows and Mac allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2h5h-59f5-c5x9

Rekor's compressed archives can result in OOM conditions

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-2h5h-2fc6-g2qv

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, watchOS 26.6. An app may be able to access sensitive user data.

CVSS3: 5.5
0%
Низкий
4 дня назад
github логотип
GHSA-2h5g-87fc-mwp6

Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Archer GRC 5.x before 5.5.3 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2h5f-jcgv-ffv5

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 175066.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2h5c-f427-3wjr

Argument Injection in TortoiseGitBlame via Malicious Git History Filenames Leads to Arbitrary File Write in TortoiseGit

CVSS3: 5.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-2h5c-85wg-jwx8

Apple Safari 4.0.5 on Windows sends the "Authorization: Basic" header appropriate for one web site to a different web site named in a Location header received from the first site, which allows remote web servers to obtain sensitive information by logging HTTP requests. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2h59-fjvh-cg52

Silicon Labs Gecko OS DNS Response Processing Infinite Loop Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of DNS responses. The issue results from a logic error that can lead to an infinite loop. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-23392.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2h59-fhpr-vfx4

A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackers to execute arbitrary code via crafted XML-RPC requests.

CVSS3: 9.8
45%
Средний
почти 3 года назад
github логотип
GHSA-2h58-x23m-3288

IBM Sterling B2B Integrator Standard Edition 5.2 allows a user to view sensitive information that belongs to another user. IBM X-Force ID: 128619.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-2h57-wv8w-2wmj

Adobe Substance 3D Designer versions 13.0.0 (and earlier) and 13.1.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2h57-5ppx-7x34

Use after free in Windows Speech Brokered Api allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
4 месяца назад
github логотип
GHSA-2h57-3xqf-9v5f

SQL injection vulnerability in default.asp in ASP Product Catalog allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2007-5220.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2h56-v244-fqpv

Calsos CSDJ (CSDJ-B 01.08.00 and earlier, CSDJ-H 01.08.00 and earlier, CSDJ-D 01.08.00 and earlier, and CSDJ-A 03.08.00 and earlier) allows remote attackers to bypass access restriction and to obtain unauthorized historical data without access privileges via unspecified vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2h56-q6pr-f3f8

Unspecified vulnerability in ptrace in NetBSD-current before 20061027, NetBSD 3.0 and 3.0.1 before 20061027, and NetBSD 2.x before 20061119 allows local users to read kernel memory and obtain sensitive information via certain manipulations of a PT_LWPINFO request, which leads to a memory leak and information leak.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2h56-96mx-jvrh

Multiple cross-site scripting (XSS) vulnerabilities in the Google Analyticator plugin before 6.4.9.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) ga_adsense, (2) ga_admin_disable_DimentionIndex, (3) ga_downloads_prefix, (4) ga_downloads, or (5) ga_outbound_prefix parameter in the google-analyticator page to wp-admin/admin.php.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2h56-2mqr-w44f

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.7, macOS Tahoe 26.5. A remote attacker may be able to cause unexpected system termination.

CVSS3: 7.5
1%
Низкий
3 месяца назад
github логотип
GHSA-2h55-w7q6-9v78

IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive information. IBM X-Force ID: 148870.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2h55-hc4f-7vj2

A heap-based buffer over-read exists in libopencad 0.2.0 in the ReadCHAR function in lib/dwg/io.cpp, resulting in an application crash.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2h54-g4cf-fg9x

In setIPv6AddrGenMode of NetworkManagementService.java, there is a possible bypass of networking permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-141920289

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-2h54-c9vf-47rr

Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 59.0.3071.86 for Windows and Mac allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.

CVSS3: 6.5
1%
Низкий
около 4 лет назад

Уязвимостей на страницу