Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 269

Количество 353 269

github логотип

GHSA-282x-mj8h-7q8w

около 4 лет назад

A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could use this flaw to intercept the request to the KDC and replace the user name (principal) in the request with any desired user name (principal) that exists in the KDC effectively obtaining a ticket for that principal.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-282w-q25g-979q

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: drm/meson: encoder_hdmi: Fix refcount leak in meson_encoder_hdmi_init of_graph_get_remote_node() returns remote device nodepointer with refcount incremented, we should use of_node_put() on it when done. Add missing of_node_put() to avoid refcount leak.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-282w-5q6m-5xx6

около 4 лет назад

Heap-based buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-0604.

EPSS: Низкий
github логотип

GHSA-282v-8gf3-6m78

около 4 лет назад

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.7.0 allows remote attackers to perform unauthorized actions as a logged-in user via a link or IMG tag to server_privileges.php, as demonstrated using the dbname and checkprivs parameters. NOTE: the provenance of this issue is unknown, although third parties imply that it is related to the disclosure of CVE-2005-4349, which was labeled as SQL injection but disputed.

EPSS: Низкий
github логотип

GHSA-282v-666c-3fvg

около 3 лет назад

transformers has Insecure Temporary File

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-282v-3f28-8726

около 4 лет назад

Incorrect access control in the /drobopix/api/drobo.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve sensitive system information.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-282r-w9m2-4r2w

около 1 года назад

Path Traversal vulnerability in Mikado-Themes Grill and Chow allows PHP Local File Inclusion. This issue affects Grill and Chow: from n/a through 1.6.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-282q-x2f9-j9j7

около 4 лет назад

An issue was discovered in Bitdefender BOX firmware versions before 2.1.37.37-34 that affects the general reliability of the product. Specially crafted packets sent to the miniupnpd implementation in result in the device allocating memory without freeing it later. This behavior can cause the miniupnpd component to crash or to trigger a device reboot.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-282p-qvpm-4cp8

почти 2 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Phi Phan Meta Field Block allows Stored XSS.This issue affects Meta Field Block: from n/a through 1.2.13.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-282p-pqm6-5xv5

10 месяцев назад

Missing Authorization vulnerability in gutentor Gutentor allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Gutentor: from n/a through 3.5.2.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-282p-p74m-mx9r

8 месяцев назад

Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of this vulnerability may affect availability.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-282p-5qxv-x526

около 4 лет назад

An issue was discovered in Clementine Music Player 1.3.1. Clementine.exe is vulnerable to a user mode write access violation due to a NULL pointer dereference in the Init call in the MoodbarPipeline::NewPadCallback function in moodbar/moodbarpipeline.cpp. The vulnerability is triggered when the user opens a malformed mp3 file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-282m-cc46-hh73

больше 4 лет назад

An unauthenticated command injection vulnerability exists in the parameters of operation 10 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on the device by sending a specially crafted malicious packet to the controller_server service on port 9999.

EPSS: Низкий
github логотип

GHSA-282m-667p-q2wq

около 2 лет назад

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-282j-9h8p-xf7h

больше 3 лет назад

Microsoft Exchange Server Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2023-21763.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-282h-xw4x-7x34

около 4 лет назад

A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. A malicious application may be able to gain root privileges.

EPSS: Низкий
github логотип

GHSA-282h-wh7g-68c6

около 4 лет назад

Cross-site request forgery (CSRF) vulnerability in ajax.php in Cerb before 7.0.4 allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via a saveWorkerPeek action.

EPSS: Низкий
github логотип

GHSA-282h-vfc3-82h7

30 дней назад

Use after free in QUIC in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: High)

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-282h-pgm7-6q2g

около 4 лет назад

Adobe Photoshop versions 21.2.6 (and earlier) and 22.3 (and earlier) are affected by a Buffer Overflow vulnerability when parsing a specially crafted JSX file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

EPSS: Низкий
github логотип

GHSA-282h-4pvx-ffwg

около 4 лет назад

An attacker with local network access can obtain a fixed cryptography key which may allow for further compromise of Reolink P2P cameras outside of local network access

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-282x-mj8h-7q8w

A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could use this flaw to intercept the request to the KDC and replace the user name (principal) in the request with any desired user name (principal) that exists in the KDC effectively obtaining a ticket for that principal.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-282w-q25g-979q

In the Linux kernel, the following vulnerability has been resolved: drm/meson: encoder_hdmi: Fix refcount leak in meson_encoder_hdmi_init of_graph_get_remote_node() returns remote device nodepointer with refcount incremented, we should use of_node_put() on it when done. Add missing of_node_put() to avoid refcount leak.

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-282w-5q6m-5xx6

Heap-based buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-0604.

8%
Низкий
около 4 лет назад
github логотип
GHSA-282v-8gf3-6m78

Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.7.0 allows remote attackers to perform unauthorized actions as a logged-in user via a link or IMG tag to server_privileges.php, as demonstrated using the dbname and checkprivs parameters. NOTE: the provenance of this issue is unknown, although third parties imply that it is related to the disclosure of CVE-2005-4349, which was labeled as SQL injection but disputed.

1%
Низкий
около 4 лет назад
github логотип
GHSA-282v-666c-3fvg

transformers has Insecure Temporary File

CVSS3: 4.7
0%
Низкий
около 3 лет назад
github логотип
GHSA-282v-3f28-8726

Incorrect access control in the /drobopix/api/drobo.php endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve sensitive system information.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-282r-w9m2-4r2w

Path Traversal vulnerability in Mikado-Themes Grill and Chow allows PHP Local File Inclusion. This issue affects Grill and Chow: from n/a through 1.6.

CVSS3: 8.1
1%
Низкий
около 1 года назад
github логотип
GHSA-282q-x2f9-j9j7

An issue was discovered in Bitdefender BOX firmware versions before 2.1.37.37-34 that affects the general reliability of the product. Specially crafted packets sent to the miniupnpd implementation in result in the device allocating memory without freeing it later. This behavior can cause the miniupnpd component to crash or to trigger a device reboot.

CVSS3: 4.4
0%
Низкий
около 4 лет назад
github логотип
GHSA-282p-qvpm-4cp8

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Phi Phan Meta Field Block allows Stored XSS.This issue affects Meta Field Block: from n/a through 1.2.13.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-282p-pqm6-5xv5

Missing Authorization vulnerability in gutentor Gutentor allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Gutentor: from n/a through 3.5.2.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-282p-p74m-mx9r

Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of this vulnerability may affect availability.

CVSS3: 3.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-282p-5qxv-x526

An issue was discovered in Clementine Music Player 1.3.1. Clementine.exe is vulnerable to a user mode write access violation due to a NULL pointer dereference in the Init call in the MoodbarPipeline::NewPadCallback function in moodbar/moodbarpipeline.cpp. The vulnerability is triggered when the user opens a malformed mp3 file.

CVSS3: 5.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-282m-cc46-hh73

An unauthenticated command injection vulnerability exists in the parameters of operation 10 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on the device by sending a specially crafted malicious packet to the controller_server service on port 9999.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-282m-667p-q2wq

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

CVSS3: 6.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-282j-9h8p-xf7h

Microsoft Exchange Server Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2023-21763.

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-282h-xw4x-7x34

A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. A malicious application may be able to gain root privileges.

1%
Низкий
около 4 лет назад
github логотип
GHSA-282h-wh7g-68c6

Cross-site request forgery (CSRF) vulnerability in ajax.php in Cerb before 7.0.4 allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via a saveWorkerPeek action.

3%
Низкий
около 4 лет назад
github логотип
GHSA-282h-vfc3-82h7

Use after free in QUIC in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: High)

CVSS3: 8.1
0%
Низкий
30 дней назад
github логотип
GHSA-282h-pgm7-6q2g

Adobe Photoshop versions 21.2.6 (and earlier) and 22.3 (and earlier) are affected by a Buffer Overflow vulnerability when parsing a specially crafted JSX file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

7%
Низкий
около 4 лет назад
github логотип
GHSA-282h-4pvx-ffwg

An attacker with local network access can obtain a fixed cryptography key which may allow for further compromise of Reolink P2P cameras outside of local network access

0%
Низкий
около 4 лет назад

Уязвимостей на страницу