Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-36m7-j2mr-5864

больше 4 лет назад

scp.c in Dropbear before 2020.79 mishandles the filename of . or an empty filename, a related issue to CVE-2018-20685.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-36m7-hm82-xm8q

больше 4 лет назад

htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack.

EPSS: Низкий
github логотип

GHSA-36m7-65w5-jm6c

23 дня назад

Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run specific commands can execute denied programs by calling execveat directly or through fexecve, bypassing policy enforcement and logging.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-36m7-49vh-x3qh

6 месяцев назад

ByteDance Deer-Flow versions prior to commit 5dbb362 contain a stored cross-site scripting vulnerability in the artifacts API that allows attackers to execute arbitrary scripts by uploading malicious HTML or script content as artifacts. Attackers can store malicious content that executes in the browser context when users view artifacts, leading to session compromise, credential theft, and arbitrary script execution.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-36m6-mcp9-gvc5

больше 1 года назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in g5theme Essential Real Estate allows PHP Local File Inclusion. This issue affects Essential Real Estate: from n/a through 5.2.1.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-36m6-588r-vqcw

3 месяца назад

AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checks

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-36m6-3822-4m7c

около 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Cristiano Zanca WooCommerce Booking Bundle Hours allows Stored XSS. This issue affects WooCommerce Booking Bundle Hours: from n/a through 0.7.4.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-36m5-4hhc-2hxj

9 месяцев назад

PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the episode title field accessible through the episodes upload interface (episodes_upload.php). Malicious JavaScript payloads injected into episode titles execute when administrators view the episodes list page (episodes_list.php).

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-36m5-2rw3-hr39

больше 4 лет назад

An improper caller check logic of SMC call in TEEGRIS secure OS prior to SMR Oct-2021 Release 1 can be used to compromise TEE.

CVSS3: 7.9
EPSS: Низкий
github логотип

GHSA-36m4-pcqv-xcxp

11 месяцев назад

The device is running an outdated operating system, which may be susceptible to known vulnerabilities.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-36m4-mv4f-9c4q

больше 1 года назад

Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) are susceptible to an assertion-based crash when an oversized NAS packet is received. An attacker may leverage this behavior to repeatedly crash the MME via either a compromised base station or via an unauthenticated cellphone within range of a base station managed by the MME, causing a denial of service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-36m4-6v6m-4vpr

больше 7 лет назад

Cross-site Scripting in remarkable

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-36m3-jv8v-27f2

2 месяца назад

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-36m3-c68m-7673

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: USB: gadget: pxa25x_udc: fix memory leak with using debugfs_lookup() When calling debugfs_lookup() the result must have dput() called on it, otherwise the memory will leak over time. To make things simpler, just call debugfs_lookup_and_remove() instead which handles all of the logic at once.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-36m3-3x88-3x7w

6 месяцев назад

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in yoyofr modizer (libs/libopenmpt/openmpt-trunk/include/premake/contrib/curl/lib modules). This vulnerability is associated with program files imap.C‎. This issue affects modizer: before v4.3.

EPSS: Низкий
github логотип

GHSA-36m3-3rr8-qrqf

больше 3 лет назад

Dell PowerScale OneFS 9.0.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in cloudpool. A low privileged local attacker could potentially exploit this vulnerability, leading to sensitive information disclosure.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-36m2-vv3g-rf4q

больше 4 лет назад

Vulnerability in the Oracle Loans product of Oracle E-Business Suite (component: Loan Details, Loan Accounting Events). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Loans. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Loans accessible data as well as unauthorized access to critical data or complete access to all Oracle Loans accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

EPSS: Низкий
github логотип

GHSA-36m2-mxfm-7fx8

больше 4 лет назад

Apple Safari 3.1.1 allows remote attackers to spoof the address bar by placing many "invisible" characters in the userinfo subcomponent of the authority component of the URL (aka the user field), as demonstrated by %E3%80%80 sequences.

EPSS: Низкий
github логотип

GHSA-36m2-fp76-fx6w

больше 2 лет назад

An issue in PX4 Autopilot v.1.14.0 allows an attacker to manipulate the flight path allowing for crashes of the drone via the home point location of the mission_block.cpp component.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-36m2-8rhx-f36j

больше 4 лет назад

Sandbox bypass in Latte templates

CVSS3: 8.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-36m7-j2mr-5864

scp.c in Dropbear before 2020.79 mishandles the filename of . or an empty filename, a related issue to CVE-2018-20685.

CVSS3: 8.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-36m7-hm82-xm8q

htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-36m7-65w5-jm6c

Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run specific commands can execute denied programs by calling execveat directly or through fexecve, bypassing policy enforcement and logging.

CVSS3: 7.8
0%
Низкий
23 дня назад
github логотип
GHSA-36m7-49vh-x3qh

ByteDance Deer-Flow versions prior to commit 5dbb362 contain a stored cross-site scripting vulnerability in the artifacts API that allows attackers to execute arbitrary scripts by uploading malicious HTML or script content as artifacts. Attackers can store malicious content that executes in the browser context when users view artifacts, leading to session compromise, credential theft, and arbitrary script execution.

CVSS3: 5.4
0%
Низкий
6 месяцев назад
github логотип
GHSA-36m6-mcp9-gvc5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in g5theme Essential Real Estate allows PHP Local File Inclusion. This issue affects Essential Real Estate: from n/a through 5.2.1.

CVSS3: 8.1
1%
Низкий
больше 1 года назад
github логотип
GHSA-36m6-588r-vqcw

AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checks

CVSS3: 6.8
1%
Низкий
3 месяца назад
github логотип
GHSA-36m6-3822-4m7c

Cross-Site Request Forgery (CSRF) vulnerability in Cristiano Zanca WooCommerce Booking Bundle Hours allows Stored XSS. This issue affects WooCommerce Booking Bundle Hours: from n/a through 0.7.4.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-36m5-4hhc-2hxj

PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the episode title field accessible through the episodes upload interface (episodes_upload.php). Malicious JavaScript payloads injected into episode titles execute when administrators view the episodes list page (episodes_list.php).

CVSS3: 5.4
0%
Низкий
9 месяцев назад
github логотип
GHSA-36m5-2rw3-hr39

An improper caller check logic of SMC call in TEEGRIS secure OS prior to SMR Oct-2021 Release 1 can be used to compromise TEE.

CVSS3: 7.9
0%
Низкий
больше 4 лет назад
github логотип
GHSA-36m4-pcqv-xcxp

The device is running an outdated operating system, which may be susceptible to known vulnerabilities.

CVSS3: 9.3
11 месяцев назад
github логотип
GHSA-36m4-mv4f-9c4q

Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) are susceptible to an assertion-based crash when an oversized NAS packet is received. An attacker may leverage this behavior to repeatedly crash the MME via either a compromised base station or via an unauthenticated cellphone within range of a base station managed by the MME, causing a denial of service.

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-36m4-6v6m-4vpr

Cross-site Scripting in remarkable

CVSS3: 6.1
1%
Низкий
больше 7 лет назад
github логотип
GHSA-36m3-jv8v-27f2

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).

CVSS3: 8.8
0%
Низкий
2 месяца назад
github логотип
GHSA-36m3-c68m-7673

In the Linux kernel, the following vulnerability has been resolved: USB: gadget: pxa25x_udc: fix memory leak with using debugfs_lookup() When calling debugfs_lookup() the result must have dput() called on it, otherwise the memory will leak over time. To make things simpler, just call debugfs_lookup_and_remove() instead which handles all of the logic at once.

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-36m3-3x88-3x7w

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in yoyofr modizer (libs/libopenmpt/openmpt-trunk/include/premake/contrib/curl/lib modules). This vulnerability is associated with program files imap.C‎. This issue affects modizer: before v4.3.

0%
Низкий
6 месяцев назад
github логотип
GHSA-36m3-3rr8-qrqf

Dell PowerScale OneFS 9.0.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in cloudpool. A low privileged local attacker could potentially exploit this vulnerability, leading to sensitive information disclosure.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-36m2-vv3g-rf4q

Vulnerability in the Oracle Loans product of Oracle E-Business Suite (component: Loan Details, Loan Accounting Events). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Loans. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Loans accessible data as well as unauthorized access to critical data or complete access to all Oracle Loans accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

1%
Низкий
больше 4 лет назад
github логотип
GHSA-36m2-mxfm-7fx8

Apple Safari 3.1.1 allows remote attackers to spoof the address bar by placing many "invisible" characters in the userinfo subcomponent of the authority component of the URL (aka the user field), as demonstrated by %E3%80%80 sequences.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-36m2-fp76-fx6w

An issue in PX4 Autopilot v.1.14.0 allows an attacker to manipulate the flight path allowing for crashes of the drone via the home point location of the mission_block.cpp component.

CVSS3: 6.6
0%
Низкий
больше 2 лет назад
github логотип
GHSA-36m2-8rhx-f36j

Sandbox bypass in Latte templates

CVSS3: 8.2
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу