Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-2c9q-p5rf-5vp8

около 4 лет назад

The JSON_parser function (ext/json/JSON_parser.c) in PHP 5.2.x before 5.2.9 allows remote attackers to cause a denial of service (segmentation fault) via a malformed string to the json_decode API function.

EPSS: Низкий
github логотип

GHSA-2c9q-jgx6-2qx7

больше 2 лет назад

QuickJS before c4cdd61 has a build_for_in_iterator NULL pointer dereference because of an erroneous lexical scope of "this" with eval.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2c9q-7wm6-r5xc

около 3 лет назад

Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm-core prior to 8.3.0.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-2c9q-4475-49j3

больше 3 лет назад

Control By Web X-400 devices are vulnerable to a cross-site scripting attack, which could result in private and session information being transferred to the attacker.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2c9p-4x2v-863c

больше 4 лет назад

An interaction between the Perl MD5 module (perl-Digest-MD5) and Perl could produce incorrect MD5 checksums for UTF-8 data, which could prevent a system from properly verifying the integrity of the data.

EPSS: Низкий
github логотип

GHSA-2c9m-w3h6-q5pr

больше 2 лет назад

Dell Pair Installer version prior to 1.2.1 contains an elevation of privilege vulnerability. A low privilege user with local access to the system could potentially exploit this vulnerability to delete arbitrary files and result in Denial of Service.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-2c9m-w27f-53rm

больше 3 лет назад

Apache Tomcat vulnerable to Unprotected Transport of Credentials

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2c9m-q8q2-rjjx

3 месяца назад

Premiere Pro versions 26.0.2, 25.6.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2c9m-9m4q-pf59

около 4 лет назад

Heap-based buffer overflow in the xioscan_readline function in xio-readline.c in socat 1.4.0.0 through 1.7.2.0 and 2.0.0-b1 through 2.0.0-b4 allows local users to execute arbitrary code via the READLINE address.

EPSS: Низкий
github логотип

GHSA-2c9h-c498-472c

около 4 лет назад

The Manager in Eye-Fi 1.1.2 generates predictable snonce values based on the time of day, which allows remote attackers to bypass authentication and upload arbitrary images by guessing the snonce.

EPSS: Низкий
github логотип

GHSA-2c9g-xf8g-mf89

больше 1 года назад

InDesign Desktop versions ID19.5, ID18.5.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2c9f-m8c9-p33j

почти 4 года назад

Online Pet Shop We App v1.0 by oretnom23 is vulnerable to SQL injection via /pet_shop/classes/Master.php?f=delete_order,id.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2c9f-95gh-crpj

около 4 лет назад

Brocade SANnav before Brocade SANvav v. 2.2.0.2 and Brocade SANanv v.2.1.1.8 logs the Brocade Fabric OS switch password in plain text in asyncjobscheduler-manager.log

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2c9f-7jg2-vp9c

около 2 лет назад

Inadequate input validation leads to XSS vulnerabilities in the accessiblemedia field.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2c9f-5m92-rwqm

около 4 лет назад

cPanel before 68.0.15 allows use of an unreserved e-mail address in DNS zone SOA records (SEC-306).

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-2c9f-4h7m-wqr9

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: EDAC/igen6: Avoid segmentation fault on module unload The segmentation fault happens because: During modprobe: 1. In igen6_probe(), igen6_pvt will be allocated with kzalloc() 2. In igen6_register_mci(), mci->pvt_info will point to &igen6_pvt->imc[mc] During rmmod: 1. In mci_release() in edac_mc.c, it will kfree(mci->pvt_info) 2. In igen6_remove(), it will kfree(igen6_pvt); Fix this issue by setting mci->pvt_info to NULL to avoid the double kfree.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2c9f-3x4j-7qjc

около 4 лет назад

PHP remote file inclusion vulnerability in admin/configset.php in Sphider 1.3 and earlier, when register_globals is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the settings_dir parameter.

EPSS: Низкий
github логотип

GHSA-2c9c-945f-4jg3

около 4 лет назад

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/cells/view_cell.php:4

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2c9c-5m3c-vxqg

около 4 лет назад

SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation in nonstandard conditions. ConnectSecure on Windows is affected.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-2c99-hrrc-j3vh

больше 1 года назад

Floating point exception in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via get_slope function.

CVSS3: 6.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2c9q-p5rf-5vp8

The JSON_parser function (ext/json/JSON_parser.c) in PHP 5.2.x before 5.2.9 allows remote attackers to cause a denial of service (segmentation fault) via a malformed string to the json_decode API function.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2c9q-jgx6-2qx7

QuickJS before c4cdd61 has a build_for_in_iterator NULL pointer dereference because of an erroneous lexical scope of "this" with eval.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2c9q-7wm6-r5xc

Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm-core prior to 8.3.0.

CVSS3: 7.6
1%
Низкий
около 3 лет назад
github логотип
GHSA-2c9q-4475-49j3

Control By Web X-400 devices are vulnerable to a cross-site scripting attack, which could result in private and session information being transferred to the attacker.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2c9p-4x2v-863c

An interaction between the Perl MD5 module (perl-Digest-MD5) and Perl could produce incorrect MD5 checksums for UTF-8 data, which could prevent a system from properly verifying the integrity of the data.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2c9m-w3h6-q5pr

Dell Pair Installer version prior to 1.2.1 contains an elevation of privilege vulnerability. A low privilege user with local access to the system could potentially exploit this vulnerability to delete arbitrary files and result in Denial of Service.

CVSS3: 6.6
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2c9m-w27f-53rm

Apache Tomcat vulnerable to Unprotected Transport of Credentials

CVSS3: 4.3
2%
Низкий
больше 3 лет назад
github логотип
GHSA-2c9m-q8q2-rjjx

Premiere Pro versions 26.0.2, 25.6.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
3 месяца назад
github логотип
GHSA-2c9m-9m4q-pf59

Heap-based buffer overflow in the xioscan_readline function in xio-readline.c in socat 1.4.0.0 through 1.7.2.0 and 2.0.0-b1 through 2.0.0-b4 allows local users to execute arbitrary code via the READLINE address.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2c9h-c498-472c

The Manager in Eye-Fi 1.1.2 generates predictable snonce values based on the time of day, which allows remote attackers to bypass authentication and upload arbitrary images by guessing the snonce.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2c9g-xf8g-mf89

InDesign Desktop versions ID19.5, ID18.5.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2c9f-m8c9-p33j

Online Pet Shop We App v1.0 by oretnom23 is vulnerable to SQL injection via /pet_shop/classes/Master.php?f=delete_order,id.

CVSS3: 7.2
1%
Низкий
почти 4 года назад
github логотип
GHSA-2c9f-95gh-crpj

Brocade SANnav before Brocade SANvav v. 2.2.0.2 and Brocade SANanv v.2.1.1.8 logs the Brocade Fabric OS switch password in plain text in asyncjobscheduler-manager.log

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2c9f-7jg2-vp9c

Inadequate input validation leads to XSS vulnerabilities in the accessiblemedia field.

CVSS3: 6.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-2c9f-5m92-rwqm

cPanel before 68.0.15 allows use of an unreserved e-mail address in DNS zone SOA records (SEC-306).

CVSS3: 2.7
1%
Низкий
около 4 лет назад
github логотип
GHSA-2c9f-4h7m-wqr9

In the Linux kernel, the following vulnerability has been resolved: EDAC/igen6: Avoid segmentation fault on module unload The segmentation fault happens because: During modprobe: 1. In igen6_probe(), igen6_pvt will be allocated with kzalloc() 2. In igen6_register_mci(), mci->pvt_info will point to &igen6_pvt->imc[mc] During rmmod: 1. In mci_release() in edac_mc.c, it will kfree(mci->pvt_info) 2. In igen6_remove(), it will kfree(igen6_pvt); Fix this issue by setting mci->pvt_info to NULL to avoid the double kfree.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2c9f-3x4j-7qjc

PHP remote file inclusion vulnerability in admin/configset.php in Sphider 1.3 and earlier, when register_globals is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the settings_dir parameter.

8%
Низкий
около 4 лет назад
github логотип
GHSA-2c9c-945f-4jg3

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/cells/view_cell.php:4

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2c9c-5m3c-vxqg

SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation in nonstandard conditions. ConnectSecure on Windows is affected.

CVSS3: 7
0%
Низкий
около 4 лет назад
github логотип
GHSA-2c99-hrrc-j3vh

Floating point exception in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via get_slope function.

CVSS3: 6.6
0%
Низкий
больше 1 года назад

Уязвимостей на страницу