Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-2fwq-2wwr-qrww

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: phy: qcom: qmp-usb: fix NULL-deref on runtime suspend Commit 413db06c05e7 ("phy: qcom-qmp-usb: clean up probe initialisation") removed most users of the platform device driver data, but mistakenly also removed the initialisation despite the data still being used in the runtime PM callbacks. Restore the driver data initialisation at probe to avoid a NULL-pointer dereference on runtime suspend. Apparently no one uses runtime PM, which currently needs to be enabled manually through sysfs, with this driver.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2fwp-8972-4pv4

около 4 лет назад

Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by a Use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2fwm-m84p-x5qh

около 4 лет назад

The view review history resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the invited reviewers for a review.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2fwm-fp55-mv7p

больше 3 лет назад

Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS. A successful exploit could allow an authenticated attacker to retrieve files from the local system or cause the application to consume system resources, resulting in a denial of service condition.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2fwg-qpp6-4fv9

около 4 лет назад

Under certain conditions a malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, via IGS Chart service.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2fwg-qc8c-frhr

около 4 лет назад

Trend Micro InterScan Web Security Virtual Appliance version 6.5 was found to have a reflected cross-site scripting (XSS) vulnerability in the product's Captive Portal.

EPSS: Низкий
github логотип

GHSA-2fwf-wj2x-3f3q

5 месяцев назад

In pcie, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10315038 / ALPS10340155; Issue ID: MSV-5155.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2fwf-jc53-g325

около 4 лет назад

Certain NETGEAR devices are affected by password reset by an unauthenticated attacker. This affects RBK852 before 3.2.10.11, RBK853 before 3.2.10.11, RBR854 before 3.2.10.11, RBR850 before 3.2.10.11, RBS850 before 3.2.10.11, CBR40 before 2.5.0.10, R7000 before 1.0.11.116, R6900P before 1.3.2.126, R7900 before 1.0.4.38, R7960P before 1.4.1.66, R8000 before 1.0.4.66, R7900P before 1.4.1.66, R8000P before 1.4.1.66, RAX75 before 1.0.3.102, RAX80 before 1.0.3.102, and R7000P before 1.3.2.126.

EPSS: Низкий
github логотип

GHSA-2fwf-gr55-x95r

около 4 лет назад

The automatic screen lock functionality in GNOME Shell (aka gnome-shell) before 3.10 does not prevent access to the "Enter a Command" dialog, which allows physically proximate attackers to execute arbitrary commands by leveraging an unattended workstation.

EPSS: Низкий
github логотип

GHSA-2fwf-5jpg-282p

больше 2 лет назад

Rejected reason: This CVE ID was unused by the CNA.

EPSS: Низкий
github логотип

GHSA-2fw9-cxch-qx5h

4 месяца назад

Race in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2fw9-5c4f-hmp4

около 4 лет назад

Insufficient data validation in Extensions API in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2fw8-6c95-mmp8

около 4 лет назад

Uninitialized data in endianness conversion in the XEvent handling of the X.Org X Server before 2017-06-19 allowed authenticated malicious users to access potentially privileged data from the X server.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2fw7-qxr6-mwq7

5 месяцев назад

RustFly 2.0.0 contains a command injection vulnerability in its remote UI control mechanism that accepts hex-encoded instructions over UDP port 5005 without proper sanitization. Attackers can send crafted hex-encoded payloads containing system commands to execute arbitrary operations on the target system, including reverse shell establishment and command execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2fw7-6f7r-fx94

6 месяцев назад

Permissive Cross-domain Security Policy with Untrusted Domains vulnerability in Drupal Next.Js allows Cross-Site Scripting (XSS).This issue affects Next.Js: from 0.0.0 before 1.6.4, from 2.0.0 before 2.0.1.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2fw6-rcj8-hfw7

8 месяцев назад

A potential DLL hijacking vulnerability was reported in Lenovo One Client during an internal security assessment that could allow a local authenticated user to execute code with elevated privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2fw5-rvf2-jq56

почти 8 лет назад

Apache Camel's XSLT component allows remote attackers to read arbitrary files

EPSS: Средний
github логотип

GHSA-2fw5-hcch-p3cj

больше 1 года назад

A vulnerability has been found in Zorlan SkyCaiji 2.9 and classified as critical. This vulnerability affects the function fileAction of the file vendor/skycaiji/app/admin/controller/Tool.php. The manipulation of the argument save_data leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2fw4-mgq9-39cx

больше 5 лет назад

Code Injection in oauth2-server

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2fw3-wc2h-wv2q

около 4 лет назад

PHP remote file inclusion vulnerability in news_show.php in Newanz NewsOffice 1.0 and 1.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the newsoffice_directory parameter.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2fwq-2wwr-qrww

In the Linux kernel, the following vulnerability has been resolved: phy: qcom: qmp-usb: fix NULL-deref on runtime suspend Commit 413db06c05e7 ("phy: qcom-qmp-usb: clean up probe initialisation") removed most users of the platform device driver data, but mistakenly also removed the initialisation despite the data still being used in the runtime PM callbacks. Restore the driver data initialisation at probe to avoid a NULL-pointer dereference on runtime suspend. Apparently no one uses runtime PM, which currently needs to be enabled manually through sysfs, with this driver.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2fwp-8972-4pv4

Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by a Use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-2fwm-m84p-x5qh

The view review history resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the invited reviewers for a review.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-2fwm-fp55-mv7p

Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS. A successful exploit could allow an authenticated attacker to retrieve files from the local system or cause the application to consume system resources, resulting in a denial of service condition.

CVSS3: 5.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2fwg-qpp6-4fv9

Under certain conditions a malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, via IGS Chart service.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2fwg-qc8c-frhr

Trend Micro InterScan Web Security Virtual Appliance version 6.5 was found to have a reflected cross-site scripting (XSS) vulnerability in the product's Captive Portal.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2fwf-wj2x-3f3q

In pcie, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10315038 / ALPS10340155; Issue ID: MSV-5155.

CVSS3: 7.2
0%
Низкий
5 месяцев назад
github логотип
GHSA-2fwf-jc53-g325

Certain NETGEAR devices are affected by password reset by an unauthenticated attacker. This affects RBK852 before 3.2.10.11, RBK853 before 3.2.10.11, RBR854 before 3.2.10.11, RBR850 before 3.2.10.11, RBS850 before 3.2.10.11, CBR40 before 2.5.0.10, R7000 before 1.0.11.116, R6900P before 1.3.2.126, R7900 before 1.0.4.38, R7960P before 1.4.1.66, R8000 before 1.0.4.66, R7900P before 1.4.1.66, R8000P before 1.4.1.66, RAX75 before 1.0.3.102, RAX80 before 1.0.3.102, and R7000P before 1.3.2.126.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2fwf-gr55-x95r

The automatic screen lock functionality in GNOME Shell (aka gnome-shell) before 3.10 does not prevent access to the "Enter a Command" dialog, which allows physically proximate attackers to execute arbitrary commands by leveraging an unattended workstation.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2fwf-5jpg-282p

Rejected reason: This CVE ID was unused by the CNA.

больше 2 лет назад
github логотип
GHSA-2fw9-cxch-qx5h

Race in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 5.3
0%
Низкий
4 месяца назад
github логотип
GHSA-2fw9-5c4f-hmp4

Insufficient data validation in Extensions API in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.

CVSS3: 6.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-2fw8-6c95-mmp8

Uninitialized data in endianness conversion in the XEvent handling of the X.Org X Server before 2017-06-19 allowed authenticated malicious users to access potentially privileged data from the X server.

CVSS3: 6.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-2fw7-qxr6-mwq7

RustFly 2.0.0 contains a command injection vulnerability in its remote UI control mechanism that accepts hex-encoded instructions over UDP port 5005 without proper sanitization. Attackers can send crafted hex-encoded payloads containing system commands to execute arbitrary operations on the target system, including reverse shell establishment and command execution.

CVSS3: 9.8
3%
Низкий
5 месяцев назад
github логотип
GHSA-2fw7-6f7r-fx94

Permissive Cross-domain Security Policy with Untrusted Domains vulnerability in Drupal Next.Js allows Cross-Site Scripting (XSS).This issue affects Next.Js: from 0.0.0 before 1.6.4, from 2.0.0 before 2.0.1.

CVSS3: 6.1
0%
Низкий
6 месяцев назад
github логотип
GHSA-2fw6-rcj8-hfw7

A potential DLL hijacking vulnerability was reported in Lenovo One Client during an internal security assessment that could allow a local authenticated user to execute code with elevated privileges.

CVSS3: 7.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-2fw5-rvf2-jq56

Apache Camel's XSLT component allows remote attackers to read arbitrary files

33%
Средний
почти 8 лет назад
github логотип
GHSA-2fw5-hcch-p3cj

A vulnerability has been found in Zorlan SkyCaiji 2.9 and classified as critical. This vulnerability affects the function fileAction of the file vendor/skycaiji/app/admin/controller/Tool.php. The manipulation of the argument save_data leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2fw4-mgq9-39cx

Code Injection in oauth2-server

CVSS3: 7.5
2%
Низкий
больше 5 лет назад
github логотип
GHSA-2fw3-wc2h-wv2q

PHP remote file inclusion vulnerability in news_show.php in Newanz NewsOffice 1.0 and 1.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the newsoffice_directory parameter.

39%
Средний
около 4 лет назад

Уязвимостей на страницу