Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-2cfv-x53x-xfw3

больше 4 лет назад

Unknown vulnerability in the Linux kernel before 2.4.23, on the AMD AMD64 and Intel EM64T architectures, associated with "setting up TSS limits," allows local users to cause a denial of service (crash) and possibly execute arbitrary code.

EPSS: Низкий
github логотип

GHSA-2cfv-m46w-52hh

около 4 лет назад

CipherTrust IronMail 5.0.1, when "Denial of Service Protection" is enabled, allows remote attackers to cause a denial of service (possibly CPU consumption) via a SYN flood with malformed TCP packets from multiple connections.

EPSS: Низкий
github логотип

GHSA-2cfq-jpg3-8hhw

11 месяцев назад

A vulnerability in the REST API endpoints of Cisco Nexus Dashboard and Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote attacker to view sensitive information or upload and modify files on an affected device. This vulnerability exists because of missing authorization controls on some REST API endpoints. An attacker could exploit th vulnerability by sending crafted API requests to an affected endpoint. A successful exploit could allow the attacker to perform limited Administrator functions, such as accessing sensitive information regarding HTTP Proxy and NTP configurations, uploading images, and damaging image files on an affected device.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2cfq-hfxh-5h78

больше 3 лет назад

RushBet version 2022.23.1-b490616d allows a remote attacker to steal customer accounts via use of a malicious application. This is possible because the application exposes an activity and does not properly validate the data it receives.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2cfq-h45g-8h84

около 4 лет назад

An insecure client auto update feature in C-CURE 9000 can allow remote execution of lower privileged Windows programs.

EPSS: Низкий
github логотип

GHSA-2cfp-xqff-2fgj

около 4 лет назад

Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-3695, CVE-2015-3696, CVE-2015-3697, CVE-2015-3698, CVE-2015-3699, CVE-2015-3700, and CVE-2015-3701.

EPSS: Низкий
github логотип

GHSA-2cfp-qxgv-mqcq

больше 4 лет назад

A reflected cross-site scripting (XSS) vulnerability in PHP-Fusion 7.02.07 allows remote attackers to inject arbitrary web script or HTML via the status parameter in the CMS admin panel.

EPSS: Низкий
github логотип

GHSA-2cfp-q4hx-m356

около 4 лет назад

The freelist-randomization feature in mm/slab.c in the Linux kernel 4.8.x and 4.9.x before 4.9.5 allows local users to cause a denial of service (duplicate freelist entries and system crash) or possibly have unspecified other impact in opportunistic circumstances by leveraging the selection of a large value for a random number.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2cfp-2pmr-56x9

больше 1 года назад

Missing Authorization vulnerability in mikemmx Super Block Slider allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Super Block Slider: from n/a through 2.7.9.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2cfm-pf58-8m3h

7 месяцев назад

Cobian Backup 11 Gravity 11.2.0.582 contains a denial of service vulnerability in the FTP password input field that allows attackers to crash the application. Attackers can generate a specially crafted 800-byte buffer and paste it into the password field to trigger an application crash.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-2cfj-r94q-xgfj

больше 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AAM Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More allows Stored XSS.This issue affects Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More: from n/a through 6.9.15.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2cfj-f596-h4fr

около 3 лет назад

Improper access control for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable denial of service via local access.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-2cfj-58rp-82cv

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: pause TCM when the firmware is stopped Not doing so will make us send a host command to the transport while the firmware is not alive, which will trigger a WARNING. bad state = 0 WARNING: CPU: 2 PID: 17434 at drivers/net/wireless/intel/iwlwifi/iwl-trans.c:115 iwl_trans_send_cmd+0x1cb/0x1e0 [iwlwifi] RIP: 0010:iwl_trans_send_cmd+0x1cb/0x1e0 [iwlwifi] Call Trace: <TASK> iwl_mvm_send_cmd+0x40/0xc0 [iwlmvm] iwl_mvm_config_scan+0x198/0x260 [iwlmvm] iwl_mvm_recalc_tcm+0x730/0x11d0 [iwlmvm] iwl_mvm_tcm_work+0x1d/0x30 [iwlmvm] process_one_work+0x29e/0x640 worker_thread+0x2df/0x690 ? rescuer_thread+0x540/0x540 kthread+0x192/0x1e0 ? set_kthread_struct+0x90/0x90 ret_from_fork+0x22/0x30

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2cfh-cfhm-pm58

около 4 лет назад

** DISPUTED ** Monstra CMS 3.0.4 allows an attacker, who already has administrative access to modify .chunk.php files on the Edit Chunk screen, to execute arbitrary OS commands via the Theme Module by visiting the admin/index.php?id=themes&action=edit_chunk URI. NOTE: there is no indication that the Edit Chunk feature was intended to prevent an administrator from using PHP's exec feature.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2cfh-53w7-wvx4

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: habanalabs: fix possible memory leak in MMU DR fini This patch fixes what seems to be copy paste error. We will have a memory leak if the host-resident shadow is NULL (which will likely happen as the DR and HR are not dependent).

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2cfg-h7c9-q2qm

около 4 лет назад

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iCloud for Windows 11.0. Processing maliciously crafted web content may lead to arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-2cff-8v78-vq77

около 4 лет назад

Unspecified vulnerability in DomainPOP in Alt-N Technologies MDaemon before 9.61 allows remote attackers to cause a denial of service (crash) via malformed messages.

EPSS: Низкий
github логотип

GHSA-2cff-2pfq-x5v9

около 4 лет назад

poppler 0.54.0, as used in Evince and other products, has a NULL pointer dereference in the JPXStream::readUByte function in JPXStream.cc. For example, the perf_test utility will crash (segmentation fault) when parsing an invalid PDF file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2cfc-cqv5-w2wq

около 2 месяцев назад

Integer overflow in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a malicious file. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2cfc-865j-gm4w

больше 4 лет назад

XML External Entity Reference in detekt

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2cfv-x53x-xfw3

Unknown vulnerability in the Linux kernel before 2.4.23, on the AMD AMD64 and Intel EM64T architectures, associated with "setting up TSS limits," allows local users to cause a denial of service (crash) and possibly execute arbitrary code.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-2cfv-m46w-52hh

CipherTrust IronMail 5.0.1, when "Denial of Service Protection" is enabled, allows remote attackers to cause a denial of service (possibly CPU consumption) via a SYN flood with malformed TCP packets from multiple connections.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2cfq-jpg3-8hhw

A vulnerability in the REST API endpoints of Cisco Nexus Dashboard and Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote attacker to view sensitive information or upload and modify files on an affected device. This vulnerability exists because of missing authorization controls on some REST API endpoints. An attacker could exploit th vulnerability by sending crafted API requests to an affected endpoint. A successful exploit could allow the attacker to perform limited Administrator functions, such as accessing sensitive information regarding HTTP Proxy and NTP configurations, uploading images, and damaging image files on an affected device.

CVSS3: 5.4
0%
Низкий
11 месяцев назад
github логотип
GHSA-2cfq-hfxh-5h78

RushBet version 2022.23.1-b490616d allows a remote attacker to steal customer accounts via use of a malicious application. This is possible because the application exposes an activity and does not properly validate the data it receives.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2cfq-h45g-8h84

An insecure client auto update feature in C-CURE 9000 can allow remote execution of lower privileged Windows programs.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2cfp-xqff-2fgj

Buffer overflow in the Intel Graphics Driver in Apple OS X before 10.10.4 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-3695, CVE-2015-3696, CVE-2015-3697, CVE-2015-3698, CVE-2015-3699, CVE-2015-3700, and CVE-2015-3701.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2cfp-qxgv-mqcq

A reflected cross-site scripting (XSS) vulnerability in PHP-Fusion 7.02.07 allows remote attackers to inject arbitrary web script or HTML via the status parameter in the CMS admin panel.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2cfp-q4hx-m356

The freelist-randomization feature in mm/slab.c in the Linux kernel 4.8.x and 4.9.x before 4.9.5 allows local users to cause a denial of service (duplicate freelist entries and system crash) or possibly have unspecified other impact in opportunistic circumstances by leveraging the selection of a large value for a random number.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-2cfp-2pmr-56x9

Missing Authorization vulnerability in mikemmx Super Block Slider allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Super Block Slider: from n/a through 2.7.9.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2cfm-pf58-8m3h

Cobian Backup 11 Gravity 11.2.0.582 contains a denial of service vulnerability in the FTP password input field that allows attackers to crash the application. Attackers can generate a specially crafted 800-byte buffer and paste it into the password field to trigger an application crash.

CVSS3: 6.2
0%
Низкий
7 месяцев назад
github логотип
GHSA-2cfj-r94q-xgfj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AAM Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More allows Stored XSS.This issue affects Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More: from n/a through 6.9.15.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2cfj-f596-h4fr

Improper access control for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable denial of service via local access.

CVSS3: 5.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-2cfj-58rp-82cv

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: pause TCM when the firmware is stopped Not doing so will make us send a host command to the transport while the firmware is not alive, which will trigger a WARNING. bad state = 0 WARNING: CPU: 2 PID: 17434 at drivers/net/wireless/intel/iwlwifi/iwl-trans.c:115 iwl_trans_send_cmd+0x1cb/0x1e0 [iwlwifi] RIP: 0010:iwl_trans_send_cmd+0x1cb/0x1e0 [iwlwifi] Call Trace: <TASK> iwl_mvm_send_cmd+0x40/0xc0 [iwlmvm] iwl_mvm_config_scan+0x198/0x260 [iwlmvm] iwl_mvm_recalc_tcm+0x730/0x11d0 [iwlmvm] iwl_mvm_tcm_work+0x1d/0x30 [iwlmvm] process_one_work+0x29e/0x640 worker_thread+0x2df/0x690 ? rescuer_thread+0x540/0x540 kthread+0x192/0x1e0 ? set_kthread_struct+0x90/0x90 ret_from_fork+0x22/0x30

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-2cfh-cfhm-pm58

** DISPUTED ** Monstra CMS 3.0.4 allows an attacker, who already has administrative access to modify .chunk.php files on the Edit Chunk screen, to execute arbitrary OS commands via the Theme Module by visiting the admin/index.php?id=themes&action=edit_chunk URI. NOTE: there is no indication that the Edit Chunk feature was intended to prevent an administrator from using PHP's exec feature.

CVSS3: 7.2
1%
Низкий
около 4 лет назад
github логотип
GHSA-2cfh-53w7-wvx4

In the Linux kernel, the following vulnerability has been resolved: habanalabs: fix possible memory leak in MMU DR fini This patch fixes what seems to be copy paste error. We will have a memory leak if the host-resident shadow is NULL (which will likely happen as the DR and HR are not dependent).

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2cfg-h7c9-q2qm

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iCloud for Windows 11.0. Processing maliciously crafted web content may lead to arbitrary code execution.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2cff-8v78-vq77

Unspecified vulnerability in DomainPOP in Alt-N Technologies MDaemon before 9.61 allows remote attackers to cause a denial of service (crash) via malformed messages.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2cff-2pfq-x5v9

poppler 0.54.0, as used in Evince and other products, has a NULL pointer dereference in the JPXStream::readUByte function in JPXStream.cc. For example, the perf_test utility will crash (segmentation fault) when parsing an invalid PDF file.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2cfc-cqv5-w2wq

Integer overflow in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a malicious file. (Chromium security severity: High)

CVSS3: 8.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2cfc-865j-gm4w

XML External Entity Reference in detekt

CVSS3: 7.3
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу