Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 269

Количество 353 269

github логотип

GHSA-2489-gxhv-vf7c

3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Fix SError in ufshcd_rtc_work() during UFS suspend In __ufshcd_wl_suspend(), cancel_delayed_work_sync() is called to cancel the UFS RTC work, but it is placed after ufshcd_vops_suspend(hba, pm_op, POST_CHANGE). This creates a race condition where ufshcd_rtc_work() can still be running while ufshcd_vops_suspend() is executing. When UFSHCD_CAP_CLK_GATING is not supported, the condition !hba->clk_gating.active_reqs is always true, causing ufshcd_update_rtc() to be executed. Since ufshcd_vops_suspend() typically performs clock gating operations, executing ufshcd_update_rtc() at that moment triggers an SError. The kernel panic trace is as follows: Kernel panic - not syncing: Asynchronous SError Interrupt Call trace: dump_backtrace+0xec/0x128 show_stack+0x18/0x28 dump_stack_lvl+0x40/0xa0 dump_stack+0x18/0x24 panic+0x148/0x374 nmi_panic+0x3c/0x8c arm64_serror_panic+0x64/0x8c do_serror+0xc4/0xc8 ...

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-2489-fj5v-q8w2

около 4 лет назад

A configuration issue was addressed with additional restrictions. This issue affected versions prior to macOS Mojave 10.14.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2488-w585-72ch

10 месяцев назад

counterpart vulnerable to prototype pollution

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2488-pfc2-g3x9

около 4 лет назад

The sell function of a smart contract implementation for ETHEREUMBLACK (ETCBK), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2488-c4gj-6g77

8 месяцев назад

Nagios XI versions prior to 2026R1.1 are vulnerable to local privilege escalation due to an unsafe interaction between sudo permissions and application file permissions. A user‑accessible maintenance script may be executed as root via sudo and includes an application file that is writable by a lower‑privileged user. A local attacker with access to the application account can modify this file to introduce malicious code, which is then executed with elevated privileges when the script is run. Successful exploitation results in arbitrary code execution as the root user.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2488-7mjj-wx6f

около 4 лет назад

Stack-based buffer overflow in the reply_netbios_packet function in nmbd/nmbd_packets.c in nmbd in Samba 3.0.0 through 3.0.26a, when operating as a WINS server, allows remote attackers to execute arbitrary code via crafted WINS Name Registration requests followed by a WINS Name Query request.

EPSS: Средний
github логотип

GHSA-2487-c6w9-prxm

4 месяца назад

A vulnerability has been found in Nothings stb up to 2.30. This issue affects the function stbi__gif_load_next in the library stb_image.h of the component GIF Decoder. Such manipulation leads to denial of service. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2487-9f55-2vg9

около 1 года назад

OZI-Project/ozi-publish Code Injection vulnerability

EPSS: Низкий
github логотип

GHSA-2486-f4hq-9m5c

около 4 лет назад

The Hide-Thread-Content plugin through 2021-01-27 for MyBB allows remote attackers to bypass intended content-reading restrictions by clicking on reply or quote in the postbit.

EPSS: Средний
github логотип

GHSA-2486-25fw-2vf4

около 4 лет назад

Intesync Solismed 3.3sp allows Insecure File Upload.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2484-xfxv-q77x

почти 2 года назад

The Product Filter by WooBeWoo plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 1.4.9 due to missing authorization checks on various functions. This makes it possible for unauthenticated attackers to perform unauthorized actions such as creating new filters and injecting malicious javascript into a vulnerable site. This was actively exploited at the time of discovery.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2482-hx3h-75g4

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: io_uring: Fix a null-ptr-deref in io_tctx_exit_cb() Syzkaller reports a NULL deref bug as follows: BUG: KASAN: null-ptr-deref in io_tctx_exit_cb+0x53/0xd3 Read of size 4 at addr 0000000000000138 by task file1/1955 CPU: 1 PID: 1955 Comm: file1 Not tainted 6.1.0-rc7-00103-gef4d3ea40565 #75 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.11.0-2.el7 04/01/2014 Call Trace: <TASK> dump_stack_lvl+0xcd/0x134 ? io_tctx_exit_cb+0x53/0xd3 kasan_report+0xbb/0x1f0 ? io_tctx_exit_cb+0x53/0xd3 kasan_check_range+0x140/0x190 io_tctx_exit_cb+0x53/0xd3 task_work_run+0x164/0x250 ? task_work_cancel+0x30/0x30 get_signal+0x1c3/0x2440 ? lock_downgrade+0x6e0/0x6e0 ? lock_downgrade+0x6e0/0x6e0 ? exit_signals+0x8b0/0x8b0 ? do_raw_read_unlock+0x3b/0x70 ? do_raw_spin_unlock+0x50/0x230 arch_do_signal_or_restart+0x82/0x2470 ? kmem_cache_free+0x260/0x4b0 ? putname+0xfe/0x140 ? get_sigfra...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2482-gr3v-f3f3

больше 3 лет назад

Jenkins Fogbugz Plugin has missing permissions check

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-247x-w9wc-8gvv

около 4 лет назад

An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. The default management application is delivered over cleartext HTTP with Basic Authentication, as demonstrated by the /admin/index.html URI.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-247x-jv5h-grf9

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Luzuk Luzuk Testimonials allows Stored XSS.This issue affects Luzuk Testimonials: from n/a through 0.0.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-247x-7qw8-fp98

4 месяца назад

Mattermost doesn't rate limit login requests, allowing DoS

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-247x-4435-qv9r

больше 4 лет назад

An issue in the component Item_subselect::init_expr_cache_tracker of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-247x-2f9f-5wp7

больше 4 лет назад

Stack overflow in TensorFlow

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-247w-9prv-x7gm

около 4 лет назад

Cross-site scripting (XSS) vulnerability in php/edit_photos.php in Zoph (aka Zoph Organizes Photos) 0.9.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) photographer_id or (2) _crumb parameter.

EPSS: Низкий
github логотип

GHSA-247w-3m4x-wg95

около 4 лет назад

Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.3.0 through 5.3.4, 6.0.1, and 6.2.0 allows remote authenticated users to affect integrity via unknown vectors related to Core-Base.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2489-gxhv-vf7c

In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Fix SError in ufshcd_rtc_work() during UFS suspend In __ufshcd_wl_suspend(), cancel_delayed_work_sync() is called to cancel the UFS RTC work, but it is placed after ufshcd_vops_suspend(hba, pm_op, POST_CHANGE). This creates a race condition where ufshcd_rtc_work() can still be running while ufshcd_vops_suspend() is executing. When UFSHCD_CAP_CLK_GATING is not supported, the condition !hba->clk_gating.active_reqs is always true, causing ufshcd_update_rtc() to be executed. Since ufshcd_vops_suspend() typically performs clock gating operations, executing ufshcd_update_rtc() at that moment triggers an SError. The kernel panic trace is as follows: Kernel panic - not syncing: Asynchronous SError Interrupt Call trace: dump_backtrace+0xec/0x128 show_stack+0x18/0x28 dump_stack_lvl+0x40/0xa0 dump_stack+0x18/0x24 panic+0x148/0x374 nmi_panic+0x3c/0x8c arm64_serror_panic+0x64/0x8c do_serror+0xc4/0xc8 ...

CVSS3: 4.7
0%
Низкий
3 месяца назад
github логотип
GHSA-2489-fj5v-q8w2

A configuration issue was addressed with additional restrictions. This issue affected versions prior to macOS Mojave 10.14.

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2488-w585-72ch

counterpart vulnerable to prototype pollution

CVSS3: 6.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-2488-pfc2-g3x9

The sell function of a smart contract implementation for ETHEREUMBLACK (ETCBK), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2488-c4gj-6g77

Nagios XI versions prior to 2026R1.1 are vulnerable to local privilege escalation due to an unsafe interaction between sudo permissions and application file permissions. A user‑accessible maintenance script may be executed as root via sudo and includes an application file that is writable by a lower‑privileged user. A local attacker with access to the application account can modify this file to introduce malicious code, which is then executed with elevated privileges when the script is run. Successful exploitation results in arbitrary code execution as the root user.

CVSS3: 6.7
2%
Низкий
8 месяцев назад
github логотип
GHSA-2488-7mjj-wx6f

Stack-based buffer overflow in the reply_netbios_packet function in nmbd/nmbd_packets.c in nmbd in Samba 3.0.0 through 3.0.26a, when operating as a WINS server, allows remote attackers to execute arbitrary code via crafted WINS Name Registration requests followed by a WINS Name Query request.

11%
Средний
около 4 лет назад
github логотип
GHSA-2487-c6w9-prxm

A vulnerability has been found in Nothings stb up to 2.30. This issue affects the function stbi__gif_load_next in the library stb_image.h of the component GIF Decoder. Such manipulation leads to denial of service. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
0%
Низкий
4 месяца назад
github логотип
GHSA-2487-9f55-2vg9

OZI-Project/ozi-publish Code Injection vulnerability

0%
Низкий
около 1 года назад
github логотип
GHSA-2486-f4hq-9m5c

The Hide-Thread-Content plugin through 2021-01-27 for MyBB allows remote attackers to bypass intended content-reading restrictions by clicking on reply or quote in the postbit.

11%
Средний
около 4 лет назад
github логотип
GHSA-2486-25fw-2vf4

Intesync Solismed 3.3sp allows Insecure File Upload.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2484-xfxv-q77x

The Product Filter by WooBeWoo plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 1.4.9 due to missing authorization checks on various functions. This makes it possible for unauthenticated attackers to perform unauthorized actions such as creating new filters and injecting malicious javascript into a vulnerable site. This was actively exploited at the time of discovery.

CVSS3: 7.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-2482-hx3h-75g4

In the Linux kernel, the following vulnerability has been resolved: io_uring: Fix a null-ptr-deref in io_tctx_exit_cb() Syzkaller reports a NULL deref bug as follows: BUG: KASAN: null-ptr-deref in io_tctx_exit_cb+0x53/0xd3 Read of size 4 at addr 0000000000000138 by task file1/1955 CPU: 1 PID: 1955 Comm: file1 Not tainted 6.1.0-rc7-00103-gef4d3ea40565 #75 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.11.0-2.el7 04/01/2014 Call Trace: <TASK> dump_stack_lvl+0xcd/0x134 ? io_tctx_exit_cb+0x53/0xd3 kasan_report+0xbb/0x1f0 ? io_tctx_exit_cb+0x53/0xd3 kasan_check_range+0x140/0x190 io_tctx_exit_cb+0x53/0xd3 task_work_run+0x164/0x250 ? task_work_cancel+0x30/0x30 get_signal+0x1c3/0x2440 ? lock_downgrade+0x6e0/0x6e0 ? lock_downgrade+0x6e0/0x6e0 ? exit_signals+0x8b0/0x8b0 ? do_raw_read_unlock+0x3b/0x70 ? do_raw_spin_unlock+0x50/0x230 arch_do_signal_or_restart+0x82/0x2470 ? kmem_cache_free+0x260/0x4b0 ? putname+0xfe/0x140 ? get_sigfra...

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-2482-gr3v-f3f3

Jenkins Fogbugz Plugin has missing permissions check

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-247x-w9wc-8gvv

An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. The default management application is delivered over cleartext HTTP with Basic Authentication, as demonstrated by the /admin/index.html URI.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-247x-jv5h-grf9

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Luzuk Luzuk Testimonials allows Stored XSS.This issue affects Luzuk Testimonials: from n/a through 0.0.1.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-247x-7qw8-fp98

Mattermost doesn't rate limit login requests, allowing DoS

CVSS3: 4.3
0%
Низкий
4 месяца назад
github логотип
GHSA-247x-4435-qv9r

An issue in the component Item_subselect::init_expr_cache_tracker of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-247x-2f9f-5wp7

Stack overflow in TensorFlow

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-247w-9prv-x7gm

Cross-site scripting (XSS) vulnerability in php/edit_photos.php in Zoph (aka Zoph Organizes Photos) 0.9.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) photographer_id or (2) _crumb parameter.

3%
Низкий
около 4 лет назад
github логотип
GHSA-247w-3m4x-wg95

Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.3.0 through 5.3.4, 6.0.1, and 6.2.0 allows remote authenticated users to affect integrity via unknown vectors related to Core-Base.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу