Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-36fm-f9h6-j5xh

около 1 года назад

A vulnerability was found in Red Hat OpenShift Jenkins. The bearer token is not obfuscated in the logs and potentially carries a high risk if those logs are centralized when collected. The token is typically valid for one year. This flaw allows a malicious user to jeopardize the environment if they have access to sensitive information.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-36fh-g62v-wh23

24 дня назад

A NULL pointer dereference in the get_min_buffer_size function (/libswscale/slice.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-36fh-9j3c-fp3f

около 2 месяцев назад

Insufficient validation of untrusted input in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-36fh-84j7-cv5h

больше 3 лет назад

JSZip contains Path Traversal via loadAsync

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-36fh-2j8m-mpcw

больше 4 лет назад

Buffer overflow in MyWebServer 1.02 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.

EPSS: Низкий
github логотип

GHSA-36fg-whr2-g999

около 3 лет назад

Jenkins NodeJS Plugin improper credential masking vulnerability

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-36fg-v524-g4r4

около 1 года назад

A vulnerability was found in Mercusys MW301R 1.0.2 Build 190726 Rel.59423n. It has been rated as problematic. This issue affects some unknown processing of the component Login. The manipulation leads to improper restriction of excessive authentication attempts. The attack can only be initiated within the local network. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-36fg-r84v-4px6

около 1 года назад

A flaw has been found in Tenda M3 1.0.0.12. Affected is the function formQuickIndex of the file /goform/QuickIndex. Executing manipulation of the argument PPPOEPassword can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been published and may be used.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-36fg-pgp2-vmjr

больше 4 лет назад

Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

EPSS: Низкий
github логотип

GHSA-36fg-m6m3-3q45

больше 2 лет назад

Missing Authorization vulnerability in Undsgn Uncode Core.This issue affects Uncode Core: from n/a through 2.8.8.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-36fg-ffjj-h5p6

5 месяцев назад

An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.

CVSS3: 7.2
EPSS: Средний
github логотип

GHSA-36fg-92pv-q9h6

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the web framework in the Application Server in Cisco Unified MeetingPlace allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCui44681.

EPSS: Низкий
github логотип

GHSA-36fg-2x3m-m49m

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via a crafted pattern name that is included in an RPM info display.

EPSS: Низкий
github логотип

GHSA-36fg-2gj3-qpvv

больше 4 лет назад

Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm.

EPSS: Высокий
github логотип

GHSA-36ff-xw3f-vrx8

3 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.5 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an unauthenticated user to view confidential issue references on public projects due to improper authorization checks.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-36ff-j8p5-6r9r

больше 4 лет назад

Xpdf 2.00 allows a SIGSEGV in XRef::constructXRef in XRef.cc. NOTE: 2.00 is a version from November 2002.

EPSS: Низкий
github логотип

GHSA-36ff-9j7v-48h5

больше 4 лет назад

An elevation of privilege vulnerability exists when the Windows Work Folder Service improperly handles file operations, aka 'Windows Work Folder Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0777, CVE-2020-0797, CVE-2020-0864, CVE-2020-0865, CVE-2020-0866, CVE-2020-0897.

EPSS: Низкий
github логотип

GHSA-36ff-532g-qhp9

больше 4 лет назад

Unspecified vulnerability in the Application Express component in Oracle Database Server before 4.2.1 allows remote attackers to affect availability via unknown vectors.

EPSS: Низкий
github логотип

GHSA-36fc-7wjg-mfvj

4 месяца назад

Pimcore has Unsafe PHP Deserialization in Multiple Locations Without allowed_classes Restriction

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-36fc-7gp5-r893

больше 2 лет назад

In multiple locations, there is a possible cross-user read due to a confused deputy. This could lead to local information disclosure of photos or other images with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-36fm-f9h6-j5xh

A vulnerability was found in Red Hat OpenShift Jenkins. The bearer token is not obfuscated in the logs and potentially carries a high risk if those logs are centralized when collected. The token is typically valid for one year. This flaw allows a malicious user to jeopardize the environment if they have access to sensitive information.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-36fh-g62v-wh23

A NULL pointer dereference in the get_min_buffer_size function (/libswscale/slice.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file.

CVSS3: 7.5
0%
Низкий
24 дня назад
github логотип
GHSA-36fh-9j3c-fp3f

Insufficient validation of untrusted input in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-36fh-84j7-cv5h

JSZip contains Path Traversal via loadAsync

CVSS3: 7.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-36fh-2j8m-mpcw

Buffer overflow in MyWebServer 1.02 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-36fg-whr2-g999

Jenkins NodeJS Plugin improper credential masking vulnerability

CVSS3: 4.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-36fg-v524-g4r4

A vulnerability was found in Mercusys MW301R 1.0.2 Build 190726 Rel.59423n. It has been rated as problematic. This issue affects some unknown processing of the component Login. The manipulation leads to improper restriction of excessive authentication attempts. The attack can only be initiated within the local network. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.1
0%
Низкий
около 1 года назад
github логотип
GHSA-36fg-r84v-4px6

A flaw has been found in Tenda M3 1.0.0.12. Affected is the function formQuickIndex of the file /goform/QuickIndex. Executing manipulation of the argument PPPOEPassword can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been published and may be used.

CVSS3: 8.8
1%
Низкий
около 1 года назад
github логотип
GHSA-36fg-pgp2-vmjr

Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

4%
Низкий
больше 4 лет назад
github логотип
GHSA-36fg-m6m3-3q45

Missing Authorization vulnerability in Undsgn Uncode Core.This issue affects Uncode Core: from n/a through 2.8.8.

CVSS3: 7.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-36fg-ffjj-h5p6

An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.

CVSS3: 7.2
34%
Средний
5 месяцев назад
github логотип
GHSA-36fg-92pv-q9h6

Cross-site scripting (XSS) vulnerability in the web framework in the Application Server in Cisco Unified MeetingPlace allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCui44681.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-36fg-2x3m-m49m

Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via a crafted pattern name that is included in an RPM info display.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-36fg-2gj3-qpvv

Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm.

85%
Высокий
больше 4 лет назад
github логотип
GHSA-36ff-xw3f-vrx8

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.5 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an unauthenticated user to view confidential issue references on public projects due to improper authorization checks.

CVSS3: 5.3
0%
Низкий
3 месяца назад
github логотип
GHSA-36ff-j8p5-6r9r

Xpdf 2.00 allows a SIGSEGV in XRef::constructXRef in XRef.cc. NOTE: 2.00 is a version from November 2002.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-36ff-9j7v-48h5

An elevation of privilege vulnerability exists when the Windows Work Folder Service improperly handles file operations, aka 'Windows Work Folder Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0777, CVE-2020-0797, CVE-2020-0864, CVE-2020-0865, CVE-2020-0866, CVE-2020-0897.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-36ff-532g-qhp9

Unspecified vulnerability in the Application Express component in Oracle Database Server before 4.2.1 allows remote attackers to affect availability via unknown vectors.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-36fc-7wjg-mfvj

Pimcore has Unsafe PHP Deserialization in Multiple Locations Without allowed_classes Restriction

CVSS3: 8
1%
Низкий
4 месяца назад
github логотип
GHSA-36fc-7gp5-r893

In multiple locations, there is a possible cross-user read due to a confused deputy. This could lead to local information disclosure of photos or other images with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу