Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-2g54-42rw-p43x

около 4 лет назад

The specific function in ASUS BMC’s firmware Web management page (Modify user’s information function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

EPSS: Низкий
github логотип

GHSA-2g53-pmw3-ccp9

около 4 лет назад

CheckSec Canopy 3.x before 3.0.7 has stored XSS via the Login Page Disclaimer, allowing attacks by low-privileged users against higher-privileged users.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2g53-8j24-x4mg

около 2 месяцев назад

A vulnerability was determined in theonedev onedev up to 15.0.5. This affects an unknown part of the file /repositories/{projectId}/default-branch of the component REST API. This manipulation of the argument project.defaultBranch causes improper authorization. It is possible to initiate the attack remotely. Upgrading to version 15.0.6 is able to mitigate this issue. Upgrading the affected component is advised.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2g53-3pj8-qvxv

около 4 лет назад

Use-after-free vulnerability in the path_openat function in fs/namei.c in the Linux kernel 3.x and 4.x before 4.0.4 allows local users to cause a denial of service or possibly have unspecified other impact via O_TMPFILE filesystem operations that leverage a duplicate cleanup operation.

EPSS: Низкий
github логотип

GHSA-2g52-w93h-w9v5

2 дня назад

An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a crafted hostname. This allows arbitrary file and directory creation, potentially leading to a denial of service.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2g52-qw8q-wfr9

больше 1 года назад

Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed. This vulnerability affects Firefox < 134.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-2g52-f4rf-8vm9

5 месяцев назад

A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf() function, where a task object is freed multiple times in certain error-handling paths. This redundant memory deallocation can lead to a double-free condition, potentially causing FFmpeg or any application using it to crash when processing TensorFlow-based DNN models. This results in a denial-of-service scenario but does not allow arbitrary code execution under normal conditions.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-2g4x-xxrm-h5mw

около 4 лет назад

Dell Encryption (formerly Dell Data Protection | Encryption) v10.1.0 and earlier contain an information disclosure vulnerability. A malicious user with physical access to the machine could potentially exploit this vulnerability to access the unencrypted RegBack folder that contains back-ups of sensitive system files.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2g4x-p9qv-phcg

около 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Gallery 3 before 3.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) movie title to modules/gallery/controllers/movies.php or (2) key variable to modules/gallery/views/error_admin.html.php.

EPSS: Низкий
github логотип

GHSA-2g4x-fv7q-8jrf

около 4 лет назад

Insufficient data validation in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.

EPSS: Низкий
github логотип

GHSA-2g4x-fq3j-cgq4

3 месяца назад

Dalfox has an Unauthenticated Remote DoS via Closed-Channel Write in `ParameterAnalysis` (server mode)

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2g4x-3mj5-gvj6

около 4 лет назад

Multiple buffer overflows in the Broderbund Expressit 3DGreetings Player ActiveX control could allow remote attackers to execute arbitrary code via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2g4w-xqhx-j2x8

около 4 лет назад

OpenSource Moddable v10.5.0 was discovered to contain a stack overflow via the component /moddable/xs/sources/xsScript.c.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2g4w-jfv5-fgmr

8 месяцев назад

Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms FreshDesk Plugin gf-freshdesk allows Object Injection.This issue affects WP Gravity Forms FreshDesk Plugin: from n/a through <= 1.3.5.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2g4w-fv9w-h3mm

около 4 лет назад

SQL injection vulnerability in ArrayOS before AG 9.4.0.135, when the portal bookmark function is enabled, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2g4w-cqhh-m9w9

больше 2 лет назад

VMware SD-WAN Edge contains a missing authentication and protection mechanism vulnerability. A malicious actor with physical access to the SD-WAN Edge appliance during activation can potentially exploit this vulnerability to access the BIOS configuration. In addition, the malicious actor may be able to exploit the default boot priority configured.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2g4w-262r-45rr

около 4 лет назад

In openlibrary versions deploy-2016-07-0 through deploy-2021-12-22 are vulnerable to Stored XSS.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2g4v-qc3v-672p

больше 4 лет назад

Buffer overflow in ByteCatcher FTP client 1.04b allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP server banner.

EPSS: Низкий
github логотип

GHSA-2g4v-8vvw-r8m9

около 2 лет назад

An issue discovered in skycaiji 2.8 allows attackers to run arbitrary code via crafted POST request to /index.php?s=/admin/develop/editor_save.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2g4r-w789-9wg5

около 4 лет назад

In macOS High Sierra before 10.13.4, there was an issue with the handling of smartcard PINs. This issue was addressed with additional logic.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2g54-42rw-p43x

The specific function in ASUS BMC’s firmware Web management page (Modify user’s information function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2g53-pmw3-ccp9

CheckSec Canopy 3.x before 3.0.7 has stored XSS via the Login Page Disclaimer, allowing attacks by low-privileged users against higher-privileged users.

CVSS3: 4.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2g53-8j24-x4mg

A vulnerability was determined in theonedev onedev up to 15.0.5. This affects an unknown part of the file /repositories/{projectId}/default-branch of the component REST API. This manipulation of the argument project.defaultBranch causes improper authorization. It is possible to initiate the attack remotely. Upgrading to version 15.0.6 is able to mitigate this issue. Upgrading the affected component is advised.

CVSS3: 6.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2g53-3pj8-qvxv

Use-after-free vulnerability in the path_openat function in fs/namei.c in the Linux kernel 3.x and 4.x before 4.0.4 allows local users to cause a denial of service or possibly have unspecified other impact via O_TMPFILE filesystem operations that leverage a duplicate cleanup operation.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2g52-w93h-w9v5

An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a crafted hostname. This allows arbitrary file and directory creation, potentially leading to a denial of service.

CVSS3: 5.3
0%
Низкий
2 дня назад
github логотип
GHSA-2g52-qw8q-wfr9

Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed. This vulnerability affects Firefox < 134.

CVSS3: 3.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2g52-f4rf-8vm9

A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf() function, where a task object is freed multiple times in certain error-handling paths. This redundant memory deallocation can lead to a double-free condition, potentially causing FFmpeg or any application using it to crash when processing TensorFlow-based DNN models. This results in a denial-of-service scenario but does not allow arbitrary code execution under normal conditions.

CVSS3: 3.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-2g4x-xxrm-h5mw

Dell Encryption (formerly Dell Data Protection | Encryption) v10.1.0 and earlier contain an information disclosure vulnerability. A malicious user with physical access to the machine could potentially exploit this vulnerability to access the unencrypted RegBack folder that contains back-ups of sensitive system files.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-2g4x-p9qv-phcg

Multiple cross-site scripting (XSS) vulnerabilities in Gallery 3 before 3.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) movie title to modules/gallery/controllers/movies.php or (2) key variable to modules/gallery/views/error_admin.html.php.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2g4x-fv7q-8jrf

Insufficient data validation in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page.

10%
Низкий
около 4 лет назад
github логотип
GHSA-2g4x-fq3j-cgq4

Dalfox has an Unauthenticated Remote DoS via Closed-Channel Write in `ParameterAnalysis` (server mode)

CVSS3: 7.5
0%
Низкий
3 месяца назад
github логотип
GHSA-2g4x-3mj5-gvj6

Multiple buffer overflows in the Broderbund Expressit 3DGreetings Player ActiveX control could allow remote attackers to execute arbitrary code via unspecified vectors.

7%
Низкий
около 4 лет назад
github логотип
GHSA-2g4w-xqhx-j2x8

OpenSource Moddable v10.5.0 was discovered to contain a stack overflow via the component /moddable/xs/sources/xsScript.c.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2g4w-jfv5-fgmr

Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms FreshDesk Plugin gf-freshdesk allows Object Injection.This issue affects WP Gravity Forms FreshDesk Plugin: from n/a through <= 1.3.5.

CVSS3: 9.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-2g4w-fv9w-h3mm

SQL injection vulnerability in ArrayOS before AG 9.4.0.135, when the portal bookmark function is enabled, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2g4w-cqhh-m9w9

VMware SD-WAN Edge contains a missing authentication and protection mechanism vulnerability. A malicious actor with physical access to the SD-WAN Edge appliance during activation can potentially exploit this vulnerability to access the BIOS configuration. In addition, the malicious actor may be able to exploit the default boot priority configured.

CVSS3: 4.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2g4w-262r-45rr

In openlibrary versions deploy-2016-07-0 through deploy-2021-12-22 are vulnerable to Stored XSS.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-2g4v-qc3v-672p

Buffer overflow in ByteCatcher FTP client 1.04b allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP server banner.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-2g4v-8vvw-r8m9

An issue discovered in skycaiji 2.8 allows attackers to run arbitrary code via crafted POST request to /index.php?s=/admin/develop/editor_save.

CVSS3: 9.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-2g4r-w789-9wg5

In macOS High Sierra before 10.13.4, there was an issue with the handling of smartcard PINs. This issue was addressed with additional logic.

CVSS3: 5.5
0%
Низкий
около 4 лет назад

Уязвимостей на страницу