Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 346 808

Количество 346 808

github логотип

GHSA-22gf-2q7p-998g

8 месяцев назад

An unauthenticated directory traversal vulnerability in cgi-bin/upload.cgi in SNMP Web Pro 1.1 allows a remote attacker to read arbitrary files. The CGI concatenates the user-supplied params directly onto the base path (/var/www/files/userScript/) using memcpy + strcat without validation or canonicalization, enabling ../ sequences to escape the intended directory. The download branch also echoes the unsanitized params into Content-Disposition, introducing header-injection risk.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-22g9-jc7j-7rgj

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix null pointer dereference in nouveau_connector_get_modes In nouveau_connector_get_modes(), the return value of drm_mode_duplicate() is assigned to mode, which will lead to a possible NULL pointer dereference on failure of drm_mode_duplicate(). Add a check to avoid npd.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-22g9-8497-wf8p

около 4 лет назад

masqmail before 0.2.18 allows local users to overwrite arbitrary files via a symlink attack on a log file.

EPSS: Низкий
github логотип

GHSA-22g9-2j29-w93q

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix uninitialized pointer free in add_inode_ref() The add_inode_ref() function does not initialize the "name" struct when it is declared. If any of the following calls to "read_one_inode() returns NULL, dir = read_one_inode(root, parent_objectid); if (!dir) { ret = -ENOENT; goto out; } inode = read_one_inode(root, inode_objectid); if (!inode) { ret = -EIO; goto out; } then "name.name" would be freed on "out" before being initialized. out: ... kfree(name.name); This issue was reported by Coverity with CID 1526744.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-22g8-9ph6-qpq3

около 4 лет назад

Lyris ListManager 8.95 allows remote authenticated users, who have administrative privileges for at least one list on the server, to add new administrators to any list via a modified MEMBERS_.List_ parameter.

EPSS: Низкий
github логотип

GHSA-22g8-52ww-hqgx

около 4 лет назад

Microsoft Windows 10 Gold and 1511 allows local users to bypass the Virtual Secure Mode Hypervisor Code Integrity (HVCI) protection mechanism and perform RWX markings of kernel-mode pages via a crafted application, aka "Hypervisor Code Integrity Security Feature Bypass."

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-22g7-wp2f-rmqf

больше 2 лет назад

Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in an email message or a mail-gateway REST API call.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-22g7-8p7v-6gr8

около 4 лет назад

In drivers/pci/hotplug/rpadlpar_sysfs.c in the Linux kernel through 5.11.8, the RPA PCI Hotplug driver has a user-tolerable buffer overflow when writing a new device name to the driver from userspace, allowing userspace to write data to the kernel stack frame directly. This occurs because add_slot_store and remove_slot_store mishandle drc_name '\0' termination, aka CID-cc7a0bb058b8.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-22g5-r2x5-97cx

24 дня назад

showdown contains a stored cross-site scripting vulnerability in the parseHeaders function of src/subParsers/makehtml/tables.js that fails to properly escape table header ID attributes. Attackers can inject arbitrary HTML and script-executing SVG elements through double-quote characters in markdown table headers, achieving stored XSS when untrusted markdown is rendered with the default github flavor configuration.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-22g4-7m96-g7pp

около 2 лет назад

A heap buffer overflow in the function cp_unfilter() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a Denial of Service (DoS) via a crafted PNG file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-22g4-6c36-68p9

около 4 лет назад

Cross-site scripting (XSS) vulnerability in Status.pm in Apache::Status and Apache2::Status in mod_perl1 and mod_perl2 for the Apache HTTP Server, when /perl-status is accessible, allows remote attackers to inject arbitrary web script or HTML via the URI.

EPSS: Средний
github логотип

GHSA-22g3-xr7w-8vqq

около 4 лет назад

A use-after-free vulnerability exists in the _3MF_Importer::_handle_end_model() functionality of Prusa Research PrusaSlicer 2.2.0 and Master (commit 4b040b856). A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-22g3-53pr-g6hg

больше 1 года назад

Incorrect Privilege Assignment vulnerability in Favethemes Homey allows Privilege Escalation.This issue affects Homey: from n/a through 2.4.1.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-22g2-gpw7-9pqh

около 4 лет назад

The update functionality of the Discover Media infotainment system in Volkswagen Polo 2019 vehicles allows physically proximate attackers to execute arbitrary code because some unsigned parts of a metainfo file are parsed, which can cause attacker-controlled files to be written to the infotainment system and executed as root.

EPSS: Низкий
github логотип

GHSA-22g2-cxxf-8f85

около 4 лет назад

Unknown vulnerability in Microsoft Jet DB engine (msjet40.dll) 4.00.8618.0, related to insufficient data validation, allows remote attackers to execute arbitrary code via a crafted mdb file.

EPSS: Средний
github логотип

GHSA-22fx-rv4f-228x

около 2 лет назад

Code-projects Budget Management 1.0 is vulnerable to Cross Site Scripting (XSS) via the budget parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-22fx-6r9m-r8h9

около 3 лет назад

libheif vulnerable to segmentation fault via floating point exception

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-22fw-9q6h-9hhc

почти 3 года назад

The WooCommerce PDF Invoice Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.90. This is due to missing or incorrect nonce validation on the Save function. This makes it possible for unauthenticated attackers to make changes to invoices via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-22fv-xwqp-5qhr

около 4 лет назад

rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function process_secondary_order() that results in a Denial of Service (segfault).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-22fv-h3f5-g95w

около 1 года назад

Improper authentication in Microsoft Defender for Identity allows an unauthorized attacker to perform spoofing over an adjacent network.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-22gf-2q7p-998g

An unauthenticated directory traversal vulnerability in cgi-bin/upload.cgi in SNMP Web Pro 1.1 allows a remote attacker to read arbitrary files. The CGI concatenates the user-supplied params directly onto the base path (/var/www/files/userScript/) using memcpy + strcat without validation or canonicalization, enabling ../ sequences to escape the intended directory. The download branch also echoes the unsanitized params into Content-Disposition, introducing header-injection risk.

CVSS3: 4.3
1%
Низкий
8 месяцев назад
github логотип
GHSA-22g9-jc7j-7rgj

In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix null pointer dereference in nouveau_connector_get_modes In nouveau_connector_get_modes(), the return value of drm_mode_duplicate() is assigned to mode, which will lead to a possible NULL pointer dereference on failure of drm_mode_duplicate(). Add a check to avoid npd.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-22g9-8497-wf8p

masqmail before 0.2.18 allows local users to overwrite arbitrary files via a symlink attack on a log file.

0%
Низкий
около 4 лет назад
github логотип
GHSA-22g9-2j29-w93q

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix uninitialized pointer free in add_inode_ref() The add_inode_ref() function does not initialize the "name" struct when it is declared. If any of the following calls to "read_one_inode() returns NULL, dir = read_one_inode(root, parent_objectid); if (!dir) { ret = -ENOENT; goto out; } inode = read_one_inode(root, inode_objectid); if (!inode) { ret = -EIO; goto out; } then "name.name" would be freed on "out" before being initialized. out: ... kfree(name.name); This issue was reported by Coverity with CID 1526744.

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-22g8-9ph6-qpq3

Lyris ListManager 8.95 allows remote authenticated users, who have administrative privileges for at least one list on the server, to add new administrators to any list via a modified MEMBERS_.List_ parameter.

1%
Низкий
около 4 лет назад
github логотип
GHSA-22g8-52ww-hqgx

Microsoft Windows 10 Gold and 1511 allows local users to bypass the Virtual Secure Mode Hypervisor Code Integrity (HVCI) protection mechanism and perform RWX markings of kernel-mode pages via a crafted application, aka "Hypervisor Code Integrity Security Feature Bypass."

CVSS3: 5.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-22g7-wp2f-rmqf

Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in an email message or a mail-gateway REST API call.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-22g7-8p7v-6gr8

In drivers/pci/hotplug/rpadlpar_sysfs.c in the Linux kernel through 5.11.8, the RPA PCI Hotplug driver has a user-tolerable buffer overflow when writing a new device name to the driver from userspace, allowing userspace to write data to the kernel stack frame directly. This occurs because add_slot_store and remove_slot_store mishandle drc_name '\0' termination, aka CID-cc7a0bb058b8.

CVSS3: 6.7
1%
Низкий
около 4 лет назад
github логотип
GHSA-22g5-r2x5-97cx

showdown contains a stored cross-site scripting vulnerability in the parseHeaders function of src/subParsers/makehtml/tables.js that fails to properly escape table header ID attributes. Attackers can inject arbitrary HTML and script-executing SVG elements through double-quote characters in markdown table headers, achieving stored XSS when untrusted markdown is rendered with the default github flavor configuration.

CVSS3: 6.1
0%
Низкий
24 дня назад
github логотип
GHSA-22g4-7m96-g7pp

A heap buffer overflow in the function cp_unfilter() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a Denial of Service (DoS) via a crafted PNG file.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-22g4-6c36-68p9

Cross-site scripting (XSS) vulnerability in Status.pm in Apache::Status and Apache2::Status in mod_perl1 and mod_perl2 for the Apache HTTP Server, when /perl-status is accessible, allows remote attackers to inject arbitrary web script or HTML via the URI.

30%
Средний
около 4 лет назад
github логотип
GHSA-22g3-xr7w-8vqq

A use-after-free vulnerability exists in the _3MF_Importer::_handle_end_model() functionality of Prusa Research PrusaSlicer 2.2.0 and Master (commit 4b040b856). A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-22g3-53pr-g6hg

Incorrect Privilege Assignment vulnerability in Favethemes Homey allows Privilege Escalation.This issue affects Homey: from n/a through 2.4.1.

CVSS3: 9.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-22g2-gpw7-9pqh

The update functionality of the Discover Media infotainment system in Volkswagen Polo 2019 vehicles allows physically proximate attackers to execute arbitrary code because some unsigned parts of a metainfo file are parsed, which can cause attacker-controlled files to be written to the infotainment system and executed as root.

0%
Низкий
около 4 лет назад
github логотип
GHSA-22g2-cxxf-8f85

Unknown vulnerability in Microsoft Jet DB engine (msjet40.dll) 4.00.8618.0, related to insufficient data validation, allows remote attackers to execute arbitrary code via a crafted mdb file.

34%
Средний
около 4 лет назад
github логотип
GHSA-22fx-rv4f-228x

Code-projects Budget Management 1.0 is vulnerable to Cross Site Scripting (XSS) via the budget parameter.

CVSS3: 6.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-22fx-6r9m-r8h9

libheif vulnerable to segmentation fault via floating point exception

CVSS3: 6.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-22fw-9q6h-9hhc

The WooCommerce PDF Invoice Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.90. This is due to missing or incorrect nonce validation on the Save function. This makes it possible for unauthenticated attackers to make changes to invoices via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-22fv-xwqp-5qhr

rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function process_secondary_order() that results in a Denial of Service (segfault).

CVSS3: 7.5
4%
Низкий
около 4 лет назад
github логотип
GHSA-22fv-h3f5-g95w

Improper authentication in Microsoft Defender for Identity allows an unauthorized attacker to perform spoofing over an adjacent network.

CVSS3: 6.5
1%
Низкий
около 1 года назад

Уязвимостей на страницу