Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 269

Количество 353 269

github логотип

GHSA-24m4-jmrh-xh5r

больше 1 года назад

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-24m4-fmx6-c2q6

около 4 лет назад

tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that potentially causes a heap-based buffer overflow via a crafted RGBA image, related to a "Negative-size-param" condition.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-24m4-9q2q-2374

больше 2 лет назад

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Yakir Sitbon, Ariel Klikstein Linker plugin <= 1.2.1 versions.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-24m4-6q78-mqxw

около 4 лет назад

AppleGraphicsPowerManagement in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-24m3-w8g9-jwpq

больше 6 лет назад

Information disclosure of source code in SimpleSAMLphp

CVSS3: 3
EPSS: Низкий
github логотип

GHSA-24m3-rcq7-76r2

почти 3 года назад

TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command injection vulnerability. This vulnerability stems from inadequate input validation in the certificate management function, which could potentially allow malicious users to execute remote code on affected devices.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-24m2-vhhc-392c

около 4 лет назад

Buffer overflow vulnerability in fcovatti libiec_iccp_mod v1.5, allows attackers to cause a denail of service when trying to calloc an unexpectiedly large space.

EPSS: Низкий
github логотип

GHSA-24m2-rchh-h2mx

около 2 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Reject empty multisync extension to prevent infinite loop v3d_get_extensions() walks a userspace-provided singly-linked list of ioctl extensions without any bound on the chain length. A local user can craft a self-referential extension (ext->next == &ext) with zero in_sync_count and out_sync_count, which bypasses the existing duplicate- extension guard: if (se->in_sync_count || se->out_sync_count) return -EINVAL; The guard never fires because v3d_get_multisync_post_deps() returns immediately when count is zero, leaving both fields at zero on every iteration. The result is an infinite loop in kernel context, blocking the calling thread and pegging a CPU core indefinitely. Fix this by rejecting a multisync extension where both in_sync_count and out_sync_count are zero in v3d_get_multisync_submit_deps(). An empty multisync carries no synchronization information and serves no useful purpose...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-24jx-rfj6-x4mp

почти 4 года назад

An XSS exists in automation controller UI where the project name is susceptible to XSS injection

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-24jx-jxxh-qrw7

около 4 лет назад

The Neon app 1.6.14 iOS does not verify X.509 certificates from SSL servers, which allows remote attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-24jx-cr55-jpm5

5 месяцев назад

Credentials are not deleted from Acronis Agent after plan revocation. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 41124.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-24jw-rphj-mqwg

около 4 лет назад

IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) could allow an authenticated user to obtain sensitive information from a specially crafted HTTP request that could be used to aid future attacks. IBM X-Force ID: 129970.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-24jw-qhh7-33q6

около 4 лет назад

Western Digital SanDisk SanDisk X300, X300s, X400, and X600 devices: The firmware update authentication method relies on a symmetric HMAC digest. The key used to validate this digest is present in a protected area of the device, and if extracted could be used to install arbitrary firmware to other devices.

EPSS: Низкий
github логотип

GHSA-24jw-cfv8-4gp7

около 4 лет назад

A remote code execution vulnerability exists when Windows does not properly handle specially crafted image files, aka "Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-24jw-8jpm-q7p5

около 4 лет назад

In check_user_token in util.c in the Yubico PAM module (aka pam_yubico) 2.18 through 2.25, successful logins can leak file descriptors to the auth mapping file, which can lead to information disclosure (serial number of a device) and/or DoS (reaching the maximum number of file descriptors).

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-24jw-4h76-4686

около 4 лет назад

Cleartext transmission of sensitive information vulnerability in DDNS in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to eavesdrop authentication information of DNSExit via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-24jv-p3jm-jjh3

около 4 лет назад

The AP4_AvccAtom::InspectFields function in Core/Ap4AvccAtom.cpp in Bento4 mp4dump before 1.5.0-616 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted mp4 file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-24jv-f75q-ghpw

около 1 года назад

A vulnerability classified as critical has been found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the file /panel/edit-tax.php. The manipulation of the argument editid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-24jv-89r5-6fvm

около 4 лет назад

An exploitable out-of-bounds write vulnerability exists in the uncompress_scan_line function of the igcore19d.dll library of Accusoft ImageGear, version 19.5.0. A specially crafted PCX file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-24jr-8pxp-69pm

около 4 лет назад

klaussilveira GitList version <= 0.6 contains a Passing incorrectly sanitized input to system function vulnerability in `searchTree` function that can result in Execute any code as PHP user. This attack appear to be exploitable via Send POST request using search form. This vulnerability appears to have been fixed in 0.7 after commit 87b8c26b023c3fc37f0796b14bb13710f397b322.

CVSS3: 9.8
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-24m4-jmrh-xh5r

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

CVSS3: 6.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-24m4-fmx6-c2q6

tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that potentially causes a heap-based buffer overflow via a crafted RGBA image, related to a "Negative-size-param" condition.

CVSS3: 8.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-24m4-9q2q-2374

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Yakir Sitbon, Ariel Klikstein Linker plugin <= 1.2.1 versions.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-24m4-6q78-mqxw

AppleGraphicsPowerManagement in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-24m3-w8g9-jwpq

Information disclosure of source code in SimpleSAMLphp

CVSS3: 3
1%
Низкий
больше 6 лет назад
github логотип
GHSA-24m3-rcq7-76r2

TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command injection vulnerability. This vulnerability stems from inadequate input validation in the certificate management function, which could potentially allow malicious users to execute remote code on affected devices.

CVSS3: 7.2
1%
Низкий
почти 3 года назад
github логотип
GHSA-24m2-vhhc-392c

Buffer overflow vulnerability in fcovatti libiec_iccp_mod v1.5, allows attackers to cause a denail of service when trying to calloc an unexpectiedly large space.

1%
Низкий
около 4 лет назад
github логотип
GHSA-24m2-rchh-h2mx

In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Reject empty multisync extension to prevent infinite loop v3d_get_extensions() walks a userspace-provided singly-linked list of ioctl extensions without any bound on the chain length. A local user can craft a self-referential extension (ext->next == &ext) with zero in_sync_count and out_sync_count, which bypasses the existing duplicate- extension guard: if (se->in_sync_count || se->out_sync_count) return -EINVAL; The guard never fires because v3d_get_multisync_post_deps() returns immediately when count is zero, leaving both fields at zero on every iteration. The result is an infinite loop in kernel context, blocking the calling thread and pegging a CPU core indefinitely. Fix this by rejecting a multisync extension where both in_sync_count and out_sync_count are zero in v3d_get_multisync_submit_deps(). An empty multisync carries no synchronization information and serves no useful purpose...

CVSS3: 5.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-24jx-rfj6-x4mp

An XSS exists in automation controller UI where the project name is susceptible to XSS injection

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-24jx-jxxh-qrw7

The Neon app 1.6.14 iOS does not verify X.509 certificates from SSL servers, which allows remote attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVSS3: 5.9
1%
Низкий
около 4 лет назад
github логотип
GHSA-24jx-cr55-jpm5

Credentials are not deleted from Acronis Agent after plan revocation. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 41124.

CVSS3: 4.4
0%
Низкий
5 месяцев назад
github логотип
GHSA-24jw-rphj-mqwg

IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) could allow an authenticated user to obtain sensitive information from a specially crafted HTTP request that could be used to aid future attacks. IBM X-Force ID: 129970.

CVSS3: 4.3
2%
Низкий
около 4 лет назад
github логотип
GHSA-24jw-qhh7-33q6

Western Digital SanDisk SanDisk X300, X300s, X400, and X600 devices: The firmware update authentication method relies on a symmetric HMAC digest. The key used to validate this digest is present in a protected area of the device, and if extracted could be used to install arbitrary firmware to other devices.

0%
Низкий
около 4 лет назад
github логотип
GHSA-24jw-cfv8-4gp7

A remote code execution vulnerability exists when Windows does not properly handle specially crafted image files, aka "Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

CVSS3: 8.8
15%
Средний
около 4 лет назад
github логотип
GHSA-24jw-8jpm-q7p5

In check_user_token in util.c in the Yubico PAM module (aka pam_yubico) 2.18 through 2.25, successful logins can leak file descriptors to the auth mapping file, which can lead to information disclosure (serial number of a device) and/or DoS (reaching the maximum number of file descriptors).

CVSS3: 8.2
1%
Низкий
около 4 лет назад
github логотип
GHSA-24jw-4h76-4686

Cleartext transmission of sensitive information vulnerability in DDNS in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to eavesdrop authentication information of DNSExit via unspecified vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-24jv-p3jm-jjh3

The AP4_AvccAtom::InspectFields function in Core/Ap4AvccAtom.cpp in Bento4 mp4dump before 1.5.0-616 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted mp4 file.

CVSS3: 5.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-24jv-f75q-ghpw

A vulnerability classified as critical has been found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the file /panel/edit-tax.php. The manipulation of the argument editid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
около 1 года назад
github логотип
GHSA-24jv-89r5-6fvm

An exploitable out-of-bounds write vulnerability exists in the uncompress_scan_line function of the igcore19d.dll library of Accusoft ImageGear, version 19.5.0. A specially crafted PCX file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.

CVSS3: 8.8
4%
Низкий
около 4 лет назад
github логотип
GHSA-24jr-8pxp-69pm

klaussilveira GitList version <= 0.6 contains a Passing incorrectly sanitized input to system function vulnerability in `searchTree` function that can result in Execute any code as PHP user. This attack appear to be exploitable via Send POST request using search form. This vulnerability appears to have been fixed in 0.7 after commit 87b8c26b023c3fc37f0796b14bb13710f397b322.

CVSS3: 9.8
73%
Высокий
около 4 лет назад

Уязвимостей на страницу