Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 290

Количество 353 290

github логотип

GHSA-278x-6vg6-6g42

около 4 лет назад

src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3.34 versions, does not validate string length fields in SDP packets, which allows remote SDP servers to cause a denial of service or possibly have unspecified other impact via a crafted length field that triggers excessive memory allocation or a buffer over-read.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-278v-j3cr-jv2x

около 4 лет назад

Jenkins Kanboard Plugin vulnerable to Server-side request forgery (SSRF)

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-278v-98mp-vjv7

около 4 лет назад

Cross-site scripting (XSS) vulnerability in Domino Blogsphere 3.01 Beta 7 allows remote attackers to inject arbitrary web script or HTML via the name field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-278v-8427-jw24

больше 4 лет назад

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. GetMask param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-278v-44j3-pqxv

около 4 лет назад

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 13.3, watchOS 6.1.1, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. Processing maliciously crafted web content may lead to arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-278r-xxvf-49rm

больше 2 лет назад

An issue was discovered in Zammad before 6.2.0. Due to lack of rate limiting in the "email address verification" feature, an attacker could send many requests for a known address to cause Denial Of Service (generation of many emails, which would also spam the victim).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-278r-549p-g687

больше 3 лет назад

An Out-of-bounds read vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This is similar to, but not the same as CVE-2022-44648.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-278q-x23r-mw73

около 4 лет назад

Use-after-free vulnerability in Google Chrome before 23.0.1271.97 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to visibility events.

EPSS: Низкий
github логотип

GHSA-278p-xrjq-m6gf

5 месяцев назад

HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have weak entropy for authentication cookies, allowing an attacker with a stolen session cookie to find the user password by brute-forcing an encryption parameter.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-278p-2ghg-cvch

около 4 лет назад

A denial of service vulnerability exists in the IOCTL handling functionality of Kaspersky Internet Security KL1 driver. A specially crafted IOCTL signal can cause an access violation in KL1 kernel driver resulting in local system denial of service. An attacker can run a program from user-mode to trigger this vulnerability.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-278m-rc9v-hf3c

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Advanced Flamingo.This issue affects Advanced Flamingo: from n/a through 1.0.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-278j-w8wp-h5g9

больше 1 года назад

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00400889; Issue ID: MSV-2491.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-278j-379h-8hqx

около 4 лет назад

Memory corruption in PAN-OS 7.1.24 and earlier, PAN-OS 8.0.19 and earlier, PAN-OS 8.1.9 and earlier, and PAN-OS 9.0.3 and earlier will allow a remote, unauthenticated user to craft a message to Secure Shell Daemon (SSHD) and corrupt arbitrary memory.

EPSS: Низкий
github логотип

GHSA-278j-256r-v8r4

больше 1 года назад

Multiple Cisco products are affected by a vulnerability in the Ethernet Frame Decoder of the Snort detection engine that could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper handling of error conditions when processing Ethernet frames. An attacker could exploit this vulnerability by sending malicious Ethernet frames through an affected device. A successful exploit could allow the attacker to exhaust disk space on the affected device, which could result in administrators being unable to log in to the device or the device being unable to boot up correctly.Note: Manual intervention is required to recover from this situation. Customers are advised to contact the Cisco Technical Assistance Center (TAC) to help recover a device in this condition.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-278h-mv4v-wq6r

больше 2 лет назад

Rejected reason: This is unused.

EPSS: Низкий
github логотип

GHSA-278h-99f9-m238

больше 2 лет назад

cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_SetValuestring at cJSON.c.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-278g-rq84-9hmg

почти 5 лет назад

`CHECK`-fail in `MapStage`

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-278f-86wj-28mf

около 4 лет назад

An undocumented (hidden) capability for switching the web interface in Hanwha Techwin Smartcams

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-278c-qcm2-c4mv

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Takashi Matsuyama Posts Filter allows Stored XSS.This issue affects Posts Filter: from n/a through 1.3.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2789-v55f-r7v6

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad4851: fix ad4858 chan pointer handling The pointer returned from ad4851_parse_channels_common() is incremented internally as each channel is populated. In ad4858_parse_channels(), the same pointer was further incremented while setting ext_scan_type fields for each channel. This resulted in indio_dev->channels being set to a pointer past the end of the allocated array, potentially causing memory corruption or undefined behavior. Fix this by iterating over the channels using an explicit index instead of incrementing the pointer. This preserves the original base pointer and ensures all channel metadata is set correctly.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-278x-6vg6-6g42

src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3.34 versions, does not validate string length fields in SDP packets, which allows remote SDP servers to cause a denial of service or possibly have unspecified other impact via a crafted length field that triggers excessive memory allocation or a buffer over-read.

CVSS3: 9.8
4%
Низкий
около 4 лет назад
github логотип
GHSA-278v-j3cr-jv2x

Jenkins Kanboard Plugin vulnerable to Server-side request forgery (SSRF)

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-278v-98mp-vjv7

Cross-site scripting (XSS) vulnerability in Domino Blogsphere 3.01 Beta 7 allows remote attackers to inject arbitrary web script or HTML via the name field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

1%
Низкий
около 4 лет назад
github логотип
GHSA-278v-8427-jw24

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. GetMask param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-278v-44j3-pqxv

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 13.3, watchOS 6.1.1, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. Processing maliciously crafted web content may lead to arbitrary code execution.

2%
Низкий
около 4 лет назад
github логотип
GHSA-278r-xxvf-49rm

An issue was discovered in Zammad before 6.2.0. Due to lack of rate limiting in the "email address verification" feature, an attacker could send many requests for a known address to cause Denial Of Service (generation of many emails, which would also spam the victim).

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-278r-549p-g687

An Out-of-bounds read vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This is similar to, but not the same as CVE-2022-44648.

CVSS3: 5.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-278q-x23r-mw73

Use-after-free vulnerability in Google Chrome before 23.0.1271.97 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to visibility events.

2%
Низкий
около 4 лет назад
github логотип
GHSA-278p-xrjq-m6gf

HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have weak entropy for authentication cookies, allowing an attacker with a stolen session cookie to find the user password by brute-forcing an encryption parameter.

CVSS3: 9.1
0%
Низкий
5 месяцев назад
github логотип
GHSA-278p-2ghg-cvch

A denial of service vulnerability exists in the IOCTL handling functionality of Kaspersky Internet Security KL1 driver. A specially crafted IOCTL signal can cause an access violation in KL1 kernel driver resulting in local system denial of service. An attacker can run a program from user-mode to trigger this vulnerability.

CVSS3: 5.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-278m-rc9v-hf3c

Cross-Site Request Forgery (CSRF) vulnerability in Advanced Flamingo.This issue affects Advanced Flamingo: from n/a through 1.0.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-278j-w8wp-h5g9

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00400889; Issue ID: MSV-2491.

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-278j-379h-8hqx

Memory corruption in PAN-OS 7.1.24 and earlier, PAN-OS 8.0.19 and earlier, PAN-OS 8.1.9 and earlier, and PAN-OS 9.0.3 and earlier will allow a remote, unauthenticated user to craft a message to Secure Shell Daemon (SSHD) and corrupt arbitrary memory.

3%
Низкий
около 4 лет назад
github логотип
GHSA-278j-256r-v8r4

Multiple Cisco products are affected by a vulnerability in the Ethernet Frame Decoder of the Snort detection engine that could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper handling of error conditions when processing Ethernet frames. An attacker could exploit this vulnerability by sending malicious Ethernet frames through an affected device. A successful exploit could allow the attacker to exhaust disk space on the affected device, which could result in administrators being unable to log in to the device or the device being unable to boot up correctly.Note: Manual intervention is required to recover from this situation. Customers are advised to contact the Cisco Technical Assistance Center (TAC) to help recover a device in this condition.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

CVSS3: 7.4
3%
Низкий
больше 1 года назад
github логотип
GHSA-278h-mv4v-wq6r

Rejected reason: This is unused.

больше 2 лет назад
github логотип
GHSA-278h-99f9-m238

cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_SetValuestring at cJSON.c.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-278g-rq84-9hmg

`CHECK`-fail in `MapStage`

CVSS3: 5.5
0%
Низкий
почти 5 лет назад
github логотип
GHSA-278f-86wj-28mf

An undocumented (hidden) capability for switching the web interface in Hanwha Techwin Smartcams

CVSS3: 5.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-278c-qcm2-c4mv

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Takashi Matsuyama Posts Filter allows Stored XSS.This issue affects Posts Filter: from n/a through 1.3.1.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2789-v55f-r7v6

In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad4851: fix ad4858 chan pointer handling The pointer returned from ad4851_parse_channels_common() is incremented internally as each channel is populated. In ad4858_parse_channels(), the same pointer was further incremented while setting ext_scan_type fields for each channel. This resulted in indio_dev->channels being set to a pointer past the end of the allocated array, potentially causing memory corruption or undefined behavior. Fix this by iterating over the channels using an explicit index instead of incrementing the pointer. This preserves the original base pointer and ensures all channel metadata is set correctly.

CVSS3: 7.8
0%
Низкий
около 1 года назад

Уязвимостей на страницу