Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 727

Количество 375 727

github логотип

GHSA-3mpp-xh9p-vf59

больше 4 лет назад

Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via a long user name.

EPSS: Низкий
github логотип

GHSA-3mpp-xfvh-qh37

больше 4 лет назад

node-ipc behavior change

EPSS: Низкий
github логотип

GHSA-3mpm-jx38-9m8w

12 месяцев назад

sassdoc-extras vulnerable to prototype pollution

EPSS: Низкий
github логотип

GHSA-3mpm-5q2w-wr7w

почти 3 года назад

HCL Commerce Remote Store server could allow a remote attacker, using a specially-crafted URL, to read arbitrary files on the system.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-3mpj-wgvw-fw9v

больше 2 лет назад

SQL Injection vulnerability in HiPresta "Gift Wrapping Pro" (hiadvancedgiftwrapping) module for PrestaShop before version 1.4.1, allows remote attackers to escalate privileges and obtain sensitive information via the HiAdvancedGiftWrappingGiftWrappingModuleFrontController::addGiftWrappingCartValue() method.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3mpj-h64q-x7gf

больше 4 лет назад

In CODESYS EtherNetIP before 4.1.0.0, specific EtherNet/IP requests may cause a null pointer dereference in the downloaded vulnerable EtherNet/IP stack that is executed by the CODESYS Control runtime system.

EPSS: Низкий
github логотип

GHSA-3mpj-g9cw-f3hj

около 4 лет назад

A null pointer dereference issue was discovered in fs/io_uring.c in the Linux kernel before 5.15.62. A local user could use this flaw to crash the system or potentially cause a denial of service.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3mpj-92q9-pvw2

больше 4 лет назад

Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used.

EPSS: Низкий
github логотип

GHSA-3mpj-8j86-c69j

больше 4 лет назад

The Google Email application 4.2.2.0200 for Android allows remote attackers to cause a denial of service (persistent application crash) via a "Content-Disposition: ;" header in an e-mail message.

EPSS: Низкий
github логотип

GHSA-3mpj-29mm-p7wr

8 дней назад

Description The worker's Netty message decoder is installed ahead of the SASL authentication handlers in the pipeline and acts on frames before any authentication has taken place. It allocated buffers sized from a length field carried in the frame, so a single frame from an unauthenticated peer able to reach a worker slot port could drive a large allocation. `storm.messaging.netty.authentication` defaults to false, and the decoder runs before the handler that enforces it in any case, so no credentials are required. The attacker needs only TCP reachability to a worker port. The effect of a single frame at the default 768 MB worker heap has not been measured to distinguish sustained worker loss from transient garbage-collection pressure. The severity assigned to this advisory reflects the more conservative reading; consumers who require a precise figure should test against their own worker heap configuration. Mitigation Upgrade to 3.1.0, where frames are decoded only after the ha...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3mph-xfrg-5928

11 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: block: Fix the maximum minor value is blk_alloc_ext_minor() ida_alloc_range(..., min, max, ...) returns values from min to max, inclusive. So, NR_EXT_DEVT is a valid idx returned by blk_alloc_ext_minor(). This is an issue because in device_add_disk(), this value is used in: ddev->devt = MKDEV(disk->major, disk->first_minor); and NR_EXT_DEVT is '(1 << MINORBITS)'. So, should 'disk->first_minor' be NR_EXT_DEVT, it would overflow.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3mph-v6cr-ghhj

около 1 года назад

Improper authorization in accessing saved Wi-Fi password for Galaxy Tablet prior to SMR Jul-2025 Release 1 allows secondary users to access owner's saved Wi-Fi password.

CVSS3: 4.1
EPSS: Низкий
github логотип

GHSA-3mph-m2wr-4wh3

11 дней назад

The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not check the capability of the user making the request, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-3mph-2jfm-48f3

больше 4 лет назад

The mintToken function of a smart contract implementation for BitcoinAgileToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3mpg-q26j-83j5

больше 3 лет назад

Command injection in yiisoft/yii2-gii

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3mpf-rq8q-xcv5

больше 4 лет назад

The debugging interfaces in the kernel in Apple OS X before 10.11 allow local users to obtain sensitive memory-layout information via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3mpf-rcc7-5347

больше 2 лет назад

Hono vulnerable to Restricted Directory Traversal in serveStatic with deno

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3mpf-fhf9-62mx

около 1 года назад

An low privileged remote attacker in possession of the second factor for another user can login as that user without knowledge of the other user`s password.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3mpf-9cvv-qh7g

больше 4 лет назад

The Windows Installation component of TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition, TIBCO ActiveSpaces - Developer Edition, and TIBCO ActiveSpaces - Enterprise Edition contains a vulnerability that theoretically allows a low privileged attacker with local access on some versions of the Windows operating system to insert malicious software. The affected component can be abused to execute the malicious software inserted by the attacker with the elevated privileges of the component. This vulnerability results from a lack of access restrictions on certain files and/or folders in the installation. Affected releases are TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition: versions 4.5.0 and below, TIBCO ActiveSpaces - Developer Edition: versions 4.5.0 and below, and TIBCO ActiveSpaces - Enterprise Edition: versions 4.5.0 and below.

EPSS: Низкий
github логотип

GHSA-3mpf-56v2-rjgc

8 месяцев назад

A directory traversal (Zip Slip) vulnerability exists in the “Static Sites” feature of 66biolinks v44.0.0 by AltumCode. Uploaded ZIP archives are automatically extracted without validating or sanitizing file paths. An attacker can include traversal sequences (e.g., ../) in ZIP entries to write files outside the intended extraction directory. This allows static files (html, js, css, images) file write to unintended locations, or overwriting existing HTML files, potentially leading to content defacement and, in certain deployments, further impact if sensitive files are overwritten.

CVSS3: 5.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3mpp-xh9p-vf59

Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via a long user name.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3mpp-xfvh-qh37

node-ipc behavior change

больше 4 лет назад
github логотип
GHSA-3mpm-jx38-9m8w

sassdoc-extras vulnerable to prototype pollution

0%
Низкий
12 месяцев назад
github логотип
GHSA-3mpm-5q2w-wr7w

HCL Commerce Remote Store server could allow a remote attacker, using a specially-crafted URL, to read arbitrary files on the system.

CVSS3: 5.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-3mpj-wgvw-fw9v

SQL Injection vulnerability in HiPresta "Gift Wrapping Pro" (hiadvancedgiftwrapping) module for PrestaShop before version 1.4.1, allows remote attackers to escalate privileges and obtain sensitive information via the HiAdvancedGiftWrappingGiftWrappingModuleFrontController::addGiftWrappingCartValue() method.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3mpj-h64q-x7gf

In CODESYS EtherNetIP before 4.1.0.0, specific EtherNet/IP requests may cause a null pointer dereference in the downloaded vulnerable EtherNet/IP stack that is executed by the CODESYS Control runtime system.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mpj-g9cw-f3hj

A null pointer dereference issue was discovered in fs/io_uring.c in the Linux kernel before 5.15.62. A local user could use this flaw to crash the system or potentially cause a denial of service.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-3mpj-92q9-pvw2

Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3mpj-8j86-c69j

The Google Email application 4.2.2.0200 for Android allows remote attackers to cause a denial of service (persistent application crash) via a "Content-Disposition: ;" header in an e-mail message.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3mpj-29mm-p7wr

Description The worker's Netty message decoder is installed ahead of the SASL authentication handlers in the pipeline and acts on frames before any authentication has taken place. It allocated buffers sized from a length field carried in the frame, so a single frame from an unauthenticated peer able to reach a worker slot port could drive a large allocation. `storm.messaging.netty.authentication` defaults to false, and the decoder runs before the handler that enforces it in any case, so no credentials are required. The attacker needs only TCP reachability to a worker port. The effect of a single frame at the default 768 MB worker heap has not been measured to distinguish sustained worker loss from transient garbage-collection pressure. The severity assigned to this advisory reflects the more conservative reading; consumers who require a precise figure should test against their own worker heap configuration. Mitigation Upgrade to 3.1.0, where frames are decoded only after the ha...

CVSS3: 9.8
1%
Низкий
8 дней назад
github логотип
GHSA-3mph-xfrg-5928

In the Linux kernel, the following vulnerability has been resolved: block: Fix the maximum minor value is blk_alloc_ext_minor() ida_alloc_range(..., min, max, ...) returns values from min to max, inclusive. So, NR_EXT_DEVT is a valid idx returned by blk_alloc_ext_minor(). This is an issue because in device_add_disk(), this value is used in: ddev->devt = MKDEV(disk->major, disk->first_minor); and NR_EXT_DEVT is '(1 << MINORBITS)'. So, should 'disk->first_minor' be NR_EXT_DEVT, it would overflow.

CVSS3: 5.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-3mph-v6cr-ghhj

Improper authorization in accessing saved Wi-Fi password for Galaxy Tablet prior to SMR Jul-2025 Release 1 allows secondary users to access owner's saved Wi-Fi password.

CVSS3: 4.1
0%
Низкий
около 1 года назад
github логотип
GHSA-3mph-m2wr-4wh3

The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not check the capability of the user making the request, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.

CVSS3: 9.6
0%
Низкий
11 дней назад
github логотип
GHSA-3mph-2jfm-48f3

The mintToken function of a smart contract implementation for BitcoinAgileToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mpg-q26j-83j5

Command injection in yiisoft/yii2-gii

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3mpf-rq8q-xcv5

The debugging interfaces in the kernel in Apple OS X before 10.11 allow local users to obtain sensitive memory-layout information via unspecified vectors.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3mpf-rcc7-5347

Hono vulnerable to Restricted Directory Traversal in serveStatic with deno

CVSS3: 5.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3mpf-fhf9-62mx

An low privileged remote attacker in possession of the second factor for another user can login as that user without knowledge of the other user`s password.

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-3mpf-9cvv-qh7g

The Windows Installation component of TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition, TIBCO ActiveSpaces - Developer Edition, and TIBCO ActiveSpaces - Enterprise Edition contains a vulnerability that theoretically allows a low privileged attacker with local access on some versions of the Windows operating system to insert malicious software. The affected component can be abused to execute the malicious software inserted by the attacker with the elevated privileges of the component. This vulnerability results from a lack of access restrictions on certain files and/or folders in the installation. Affected releases are TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition: versions 4.5.0 and below, TIBCO ActiveSpaces - Developer Edition: versions 4.5.0 and below, and TIBCO ActiveSpaces - Enterprise Edition: versions 4.5.0 and below.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3mpf-56v2-rjgc

A directory traversal (Zip Slip) vulnerability exists in the “Static Sites” feature of 66biolinks v44.0.0 by AltumCode. Uploaded ZIP archives are automatically extracted without validating or sanitizing file paths. An attacker can include traversal sequences (e.g., ../) in ZIP entries to write files outside the intended extraction directory. This allows static files (html, js, css, images) file write to unintended locations, or overwriting existing HTML files, potentially leading to content defacement and, in certain deployments, further impact if sensitive files are overwritten.

CVSS3: 5.1
1%
Низкий
8 месяцев назад

Уязвимостей на страницу