Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-29qx-v4hg-7755

около 4 лет назад

Check Point Endpoint Security Client for Windows, with Anti-Malware blade installed, before version E81.00, tries to load a non-existent DLL during an update initiated by the UI. An attacker with administrator privileges can leverage this to gain code execution within a Check Point Software Technologies signed binary, where under certain circumstances may cause the client to terminate.

EPSS: Низкий
github логотип

GHSA-29qx-j9r5-xp78

около 4 лет назад

The lock-counter implementation in utils/mount.ecryptfs_private.c in ecryptfs-utils before 90 allows local users to overwrite arbitrary files via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-29qx-4rqj-787m

почти 4 года назад

In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.5.0, excessive file permissions in F5OS allows an authenticated local attacker to execute limited set of commands in a container and impact the F5OS controller.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-29qx-3374-gqm9

около 4 лет назад

VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure vulnerability. This issue may allow plaintext credentials to be obtained when using the vCenter Server Appliance file-based backup feature.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-29qw-fxp9-wj84

около 2 лет назад

Inappropriate implementation in iframe in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-29qw-ccch-hcg3

7 месяцев назад

A vulnerability was detected in Tenda AC18 15.03.05.05. This affects the function sprintf of the file /goform/SetDlnaCfg of the component HTTP Request Handler. The manipulation of the argument scanList results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-29qw-9m44-pf9w

8 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress Sailing sailing allows PHP Local File Inclusion.This issue affects Sailing: from n/a through < 4.4.6.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-29qv-mf54-6cq7

17 дней назад

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-29qv-hhg4-6x96

почти 4 года назад

Unauthenticated Sensitive Information Disclosure vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-29qv-h4j6-wvj9

около 4 лет назад

Use-after-free vulnerability in WebKit before r65958, as used in Google Chrome before 6.0.472.59, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger use of document APIs such as document.close during parsing, as demonstrated by a Cascading Style Sheets (CSS) file referencing an invalid SVG font, aka rdar problem 8442098.

EPSS: Низкий
github логотип

GHSA-29qv-5fpp-cv72

около 4 лет назад

An information disclosure issue was discovered in GitLab CE/EE 8.14 and later, by using the move issue feature which could result in disclosure of the newly created issue ID.

EPSS: Низкий
github логотип

GHSA-29qv-4j9f-fjw5

4 месяца назад

Unsafe object property setter in mathjs

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-29qr-v4mc-jh54

около 4 лет назад

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-29qr-v2g8-fp8m

2 месяца назад

A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the accountstatus view userid parameter due to improper neutralization of special elements in a SQL UPDATE command allowing for reading the whole database and changing values in a non critical table. This can result in a total loss of confidentiality and some loss of integrity.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-29qr-jmq6-gcm6

больше 4 лет назад

A heap data infoleak in multiple locations including L2CAP_PARSE_CONF_RSP was found in the Linux kernel before 5.1-rc1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-29qq-gf32-fj2m

больше 1 года назад

When requesting an OpenPGP key from a WKD server, an incorrect padding size was used and a network observer could have learned the length of the requested email address. This vulnerability affects Thunderbird < 136 and Thunderbird < 128.8.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-29qq-5c29-c3wm

около 4 лет назад

The Restaurant Karaoke SHIDAX app 1.3.3 and earlier on Android does not verify SSL certificates, which allows remote attackers to obtain sensitive information via a man-in-the-middle attack.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-29qp-r356-cgp5

почти 2 года назад

A vulnerability has been found in itsourcecode Placement Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /resume_upload.php of the component Image Handler. The manipulation of the argument fileToUpload leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273541 was assigned to this vulnerability.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-29qp-crvh-w22m

больше 1 года назад

Withdrawn Advisory: github.com/hashicorp/yamux's DefaultConfig has dangerous defaults causing hung Read

EPSS: Низкий
github логотип

GHSA-29qm-pmxx-2p86

3 месяца назад

An improper authorization vulnerability in scoped user-to-server (ghu_) token authorization in GitHub Enterprise Server allows an authenticated attacker to access private repositories outside the intended installation scope, which can include write operations, via an authorization fallback that treated a revoked/deleted installation as a global installation context, which could be chained with token revocation timing and SSH push attribution to obtain and reuse a victim-scoped token. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.21 and was fixed in versions 3.20.1, 3.19.5, 3.18.8, 3.17.14, 3.16.17, 3.15.21, and 3.14.26. This vulnerability was reported via the GitHub Bug Bounty program.

CVSS3: 9.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-29qx-v4hg-7755

Check Point Endpoint Security Client for Windows, with Anti-Malware blade installed, before version E81.00, tries to load a non-existent DLL during an update initiated by the UI. An attacker with administrator privileges can leverage this to gain code execution within a Check Point Software Technologies signed binary, where under certain circumstances may cause the client to terminate.

1%
Низкий
около 4 лет назад
github логотип
GHSA-29qx-j9r5-xp78

The lock-counter implementation in utils/mount.ecryptfs_private.c in ecryptfs-utils before 90 allows local users to overwrite arbitrary files via unspecified vectors.

0%
Низкий
около 4 лет назад
github логотип
GHSA-29qx-4rqj-787m

In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.5.0, excessive file permissions in F5OS allows an authenticated local attacker to execute limited set of commands in a container and impact the F5OS controller.

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-29qx-3374-gqm9

VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure vulnerability. This issue may allow plaintext credentials to be obtained when using the vCenter Server Appliance file-based backup feature.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-29qw-fxp9-wj84

Inappropriate implementation in iframe in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 9.6
0%
Низкий
около 2 лет назад
github логотип
GHSA-29qw-ccch-hcg3

A vulnerability was detected in Tenda AC18 15.03.05.05. This affects the function sprintf of the file /goform/SetDlnaCfg of the component HTTP Request Handler. The manipulation of the argument scanList results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used.

CVSS3: 8.8
1%
Низкий
7 месяцев назад
github логотип
GHSA-29qw-9m44-pf9w

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress Sailing sailing allows PHP Local File Inclusion.This issue affects Sailing: from n/a through < 4.4.6.

CVSS3: 9.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-29qv-mf54-6cq7

Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
0%
Низкий
17 дней назад
github логотип
GHSA-29qv-hhg4-6x96

Unauthenticated Sensitive Information Disclosure vulnerability

CVSS3: 6.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-29qv-h4j6-wvj9

Use-after-free vulnerability in WebKit before r65958, as used in Google Chrome before 6.0.472.59, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger use of document APIs such as document.close during parsing, as demonstrated by a Cascading Style Sheets (CSS) file referencing an invalid SVG font, aka rdar problem 8442098.

3%
Низкий
около 4 лет назад
github логотип
GHSA-29qv-5fpp-cv72

An information disclosure issue was discovered in GitLab CE/EE 8.14 and later, by using the move issue feature which could result in disclosure of the newly created issue ID.

1%
Низкий
около 4 лет назад
github логотип
GHSA-29qv-4j9f-fjw5

Unsafe object property setter in mathjs

CVSS3: 8.8
1%
Низкий
4 месяца назад
github логотип
GHSA-29qr-v4mc-jh54

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-29qr-v2g8-fp8m

A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the accountstatus view userid parameter due to improper neutralization of special elements in a SQL UPDATE command allowing for reading the whole database and changing values in a non critical table. This can result in a total loss of confidentiality and some loss of integrity.

CVSS3: 5.5
0%
Низкий
2 месяца назад
github логотип
GHSA-29qr-jmq6-gcm6

A heap data infoleak in multiple locations including L2CAP_PARSE_CONF_RSP was found in the Linux kernel before 5.1-rc1.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-29qq-gf32-fj2m

When requesting an OpenPGP key from a WKD server, an incorrect padding size was used and a network observer could have learned the length of the requested email address. This vulnerability affects Thunderbird < 136 and Thunderbird < 128.8.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-29qq-5c29-c3wm

The Restaurant Karaoke SHIDAX app 1.3.3 and earlier on Android does not verify SSL certificates, which allows remote attackers to obtain sensitive information via a man-in-the-middle attack.

CVSS3: 5.9
1%
Низкий
около 4 лет назад
github логотип
GHSA-29qp-r356-cgp5

A vulnerability has been found in itsourcecode Placement Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /resume_upload.php of the component Image Handler. The manipulation of the argument fileToUpload leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273541 was assigned to this vulnerability.

CVSS3: 6.3
1%
Низкий
почти 2 года назад
github логотип
GHSA-29qp-crvh-w22m

Withdrawn Advisory: github.com/hashicorp/yamux's DefaultConfig has dangerous defaults causing hung Read

больше 1 года назад
github логотип
GHSA-29qm-pmxx-2p86

An improper authorization vulnerability in scoped user-to-server (ghu_) token authorization in GitHub Enterprise Server allows an authenticated attacker to access private repositories outside the intended installation scope, which can include write operations, via an authorization fallback that treated a revoked/deleted installation as a global installation context, which could be chained with token revocation timing and SSH push attribution to obtain and reuse a victim-scoped token. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.21 and was fixed in versions 3.20.1, 3.19.5, 3.18.8, 3.17.14, 3.16.17, 3.15.21, and 3.14.26. This vulnerability was reported via the GitHub Bug Bounty program.

CVSS3: 9.6
0%
Низкий
3 месяца назад

Уязвимостей на страницу