Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 727

Количество 375 727

github логотип

GHSA-3mjv-8f83-6r45

6 месяцев назад

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access sensitive user data.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3mjv-89c5-xc65

почти 3 года назад

In jpg driver, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with System execution privileges needed

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-3mjv-375j-6h92

4 месяца назад

AVideo: Authenticated Arbitrary File Read in view/update.php

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-3mjr-8v4p-9qf4

около 2 лет назад

A code execution vulnerability exists in the Xiaomi App market product. The vulnerability is caused by unsafe configuration and can be exploited by attackers to execute arbitrary code.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-3mjr-5fr9-2r8m

больше 4 лет назад

The setup_cifs_sb function in fs/cifs/connect.c in the Linux kernel before 2.6.39 does not properly handle DFS referrals, which allows remote CIFS servers to cause a denial of service (system crash) by placing a referral at the root of a share.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3mjq-qmqc-xrrv

больше 4 лет назад

Microsoft Windows Media Player 7 executes scripts in custom skin (.WMS) files, which could allow remote attackers to gain privileges via a skin that contains a malicious script, aka the ".WMS Script Execution" vulnerability.

EPSS: Средний
github логотип

GHSA-3mjq-gr7r-h6x3

почти 2 года назад

An XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldServer v11.8.2 to access sensitive information and execute arbitrary commands via supplying a crafted .tmx file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3mjq-8c52-rc5f

около 2 лет назад

A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been declared as problematic. Affected by this vulnerability is the function update_settings_info of the file /classes/SystemSettings.php?f=update_settings. The manipulation of the argument contact/address leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-3mjp-p938-4329

больше 4 лет назад

Apache Tomcat vulnerable to SecurityManager bypass

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3mjp-86xg-ff9v

около 4 лет назад

Improper Restriction of XML External Entity Reference vulnerability in DLP Endpoint for Windows prior to 11.9.100 and 11.6.600 allows a remote attacker to cause the DLP Agent to access a local service that the attacker wouldn't usually have access to via a carefully constructed XML file, which the DLP Agent doesn't parse correctly.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3mjm-x6gw-2x42

6 месяцев назад

@grackle-ai/server has Missing Content-Security-Policy and X-Frame-Options Headers

EPSS: Низкий
github логотип

GHSA-3mjj-mr4f-qxmx

больше 4 лет назад

Mercurial mishandles integer addition and subtraction

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3mjj-j5cv-mf5p

больше 4 лет назад

Cross-site request forgery (CSRF) vulnerability in admin/conf_users_edit.php in PHP Link Directory (phpLD) 4.1.0 allows remote attackers to hijack the authentication of administrators for requests that add an administrator via the N action.

EPSS: Низкий
github логотип

GHSA-3mjj-g5w8-p3gp

около 1 месяца назад

In the Linux kernel, the following vulnerability has been resolved: xsk: require at least 16 bytes of TX metadata AF_XDP accepts a TX metadata length as small as eight bytes, but every supported request needs the flags plus at least one eight-byte request field. Such short metadata also lets the kernel read beyond the registered area. Require 16 bytes rather than sizeof(struct xsk_tx_metadata) to preserve compatibility with applications that do not use launch-time metadata.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3mjj-cjvr-532f

больше 4 лет назад

Unspecified vulnerability in Reservation.class.php for phpScheduleIt 1.01 and earlier allows attackers to modify or delete reservations.

EPSS: Низкий
github логотип

GHSA-3mjj-7mcj-gxwq

3 месяца назад

Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3mjh-xq7h-qg2x

11 дней назад

The SureRank SEO WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the structured data it outputs on public pages by default, allowing unauthenticated visitors to obtain the email address of any user who has published content.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3mjh-87v6-2677

больше 4 лет назад

Unspecified vulnerability in McAfee Encrypted USB Manager 3.1.0.0, when the Re-use Threshold for passwords is nonzero, allows remote attackers to conduct offline brute force attacks via unknown vectors.

EPSS: Низкий
github логотип

GHSA-3mjh-34gx-h2r7

больше 4 лет назад

Symantec Endpoint Protection Manager, prior to 14.3, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.

EPSS: Низкий
github логотип

GHSA-3mjg-gvfx-f783

больше 4 лет назад

Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 allow remote attackers to execute arbitrary code by changing an element's style from position:relative to position:static, which causes Gecko to operate on freed memory.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3mjv-8f83-6r45

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access sensitive user data.

CVSS3: 5.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-3mjv-89c5-xc65

In jpg driver, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with System execution privileges needed

CVSS3: 4.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-3mjv-375j-6h92

AVideo: Authenticated Arbitrary File Read in view/update.php

CVSS3: 4.9
0%
Низкий
4 месяца назад
github логотип
GHSA-3mjr-8v4p-9qf4

A code execution vulnerability exists in the Xiaomi App market product. The vulnerability is caused by unsafe configuration and can be exploited by attackers to execute arbitrary code.

CVSS3: 7.6
1%
Низкий
около 2 лет назад
github логотип
GHSA-3mjr-5fr9-2r8m

The setup_cifs_sb function in fs/cifs/connect.c in the Linux kernel before 2.6.39 does not properly handle DFS referrals, which allows remote CIFS servers to cause a denial of service (system crash) by placing a referral at the root of a share.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mjq-qmqc-xrrv

Microsoft Windows Media Player 7 executes scripts in custom skin (.WMS) files, which could allow remote attackers to gain privileges via a skin that contains a malicious script, aka the ".WMS Script Execution" vulnerability.

14%
Средний
больше 4 лет назад
github логотип
GHSA-3mjq-gr7r-h6x3

An XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldServer v11.8.2 to access sensitive information and execute arbitrary commands via supplying a crafted .tmx file.

CVSS3: 6.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-3mjq-8c52-rc5f

A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been declared as problematic. Affected by this vulnerability is the function update_settings_info of the file /classes/SystemSettings.php?f=update_settings. The manipulation of the argument contact/address leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 3.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-3mjp-p938-4329

Apache Tomcat vulnerable to SecurityManager bypass

CVSS3: 7.5
8%
Низкий
больше 4 лет назад
github логотип
GHSA-3mjp-86xg-ff9v

Improper Restriction of XML External Entity Reference vulnerability in DLP Endpoint for Windows prior to 11.9.100 and 11.6.600 allows a remote attacker to cause the DLP Agent to access a local service that the attacker wouldn't usually have access to via a carefully constructed XML file, which the DLP Agent doesn't parse correctly.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-3mjm-x6gw-2x42

@grackle-ai/server has Missing Content-Security-Policy and X-Frame-Options Headers

6 месяцев назад
github логотип
GHSA-3mjj-mr4f-qxmx

Mercurial mishandles integer addition and subtraction

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3mjj-j5cv-mf5p

Cross-site request forgery (CSRF) vulnerability in admin/conf_users_edit.php in PHP Link Directory (phpLD) 4.1.0 allows remote attackers to hijack the authentication of administrators for requests that add an administrator via the N action.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mjj-g5w8-p3gp

In the Linux kernel, the following vulnerability has been resolved: xsk: require at least 16 bytes of TX metadata AF_XDP accepts a TX metadata length as small as eight bytes, but every supported request needs the flags plus at least one eight-byte request field. Such short metadata also lets the kernel read beyond the registered area. Require 16 bytes rather than sizeof(struct xsk_tx_metadata) to preserve compatibility with applications that do not use launch-time metadata.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3mjj-cjvr-532f

Unspecified vulnerability in Reservation.class.php for phpScheduleIt 1.01 and earlier allows attackers to modify or delete reservations.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mjj-7mcj-gxwq

Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-3mjh-xq7h-qg2x

The SureRank SEO WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the structured data it outputs on public pages by default, allowing unauthenticated visitors to obtain the email address of any user who has published content.

CVSS3: 5.3
0%
Низкий
11 дней назад
github логотип
GHSA-3mjh-87v6-2677

Unspecified vulnerability in McAfee Encrypted USB Manager 3.1.0.0, when the Re-use Threshold for passwords is nonzero, allows remote attackers to conduct offline brute force attacks via unknown vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mjh-34gx-h2r7

Symantec Endpoint Protection Manager, prior to 14.3, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3mjg-gvfx-f783

Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 allow remote attackers to execute arbitrary code by changing an element's style from position:relative to position:static, which causes Gecko to operate on freed memory.

5%
Низкий
больше 4 лет назад

Уязвимостей на страницу