Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 290

Количество 353 290

github логотип

GHSA-22w8-2mrr-vh7h

5 месяцев назад

A security vulnerability has been detected in OWASP DefectDojo up to 2.55.4. This vulnerability affects the function input_zip.read of the file parser.py of the component SonarQubeParser/MSDefenderParser. The manipulation leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 2.56.0 is able to resolve this issue. The identifier of the patch is e8f1e5131535b8fd80a7b1b3085d676295fdcd41. Upgrading the affected component is recommended.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-22w8-27w2-f55c

около 4 лет назад

Heap-based buffer overflow in the EscapeParenthesis function in GraphicsMagick before 1.3.25 allows remote attackers to have unspecified impact via unknown vectors.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-22w7-m5f8-87vh

около 3 лет назад

Liferay Portal and Liferay DXP Vulnerable to Open Redirect via the Layout Module

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-22w7-gmrw-m5qp

около 4 лет назад

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. A malicious application may be able to elevate privileges.

EPSS: Низкий
github логотип

GHSA-22w7-7694-298f

около 4 лет назад

A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to disclose sensitive informatoin on affected installations.

CVSS3: 7.5
EPSS: Высокий
github логотип

GHSA-22w6-gp78-84rc

около 4 лет назад

The Red Hat mkdumprd script for kexec-tools, as distributed in the kexec-tools 1.x before 1.102pre-154 and 2.x before 2.0.0-209 packages in Red Hat Enterprise Linux, includes all of root's SSH private keys within a vmcore file, which allows context-dependent attackers to obtain sensitive information by inspecting the file content.

EPSS: Низкий
github логотип

GHSA-22w6-c8h9-6mx7

4 месяца назад

NVIDIA Jetson Linux has a vulnerability in initrd, where the nvluks trusted application is not disabled. A successful exploit of this vulnerability might lead to information disclosure.

CVSS3: 5.2
EPSS: Низкий
github логотип

GHSA-22w5-vw2x-wqp3

около 4 лет назад

Cross-site scripting (XSS) vulnerability in index.php in the PhotoSmash plugin 1.0.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the action parameter.

EPSS: Низкий
github логотип

GHSA-22w4-vm3c-6x82

около 4 лет назад

DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_pic_view.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.

EPSS: Низкий
github логотип

GHSA-22w3-693w-x895

3 месяца назад

webauthn-rs-core/webauthn-authenticator-rs: Origin validation mismatch possible when subdomains are allowed

EPSS: Низкий
github логотип

GHSA-22w2-qhqg-5898

около 4 лет назад

Multiple unspecified vulnerabilities in Google Chrome before 44.0.2403.89 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

EPSS: Низкий
github логотип

GHSA-22vx-vmhj-v8m6

больше 3 лет назад

Windows SmartScreen Security Feature Bypass Vulnerability.

CVSS3: 5.4
EPSS: Высокий
github логотип

GHSA-22vx-j9g4-5q8f

около 4 лет назад

It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-22vx-6323-v265

больше 4 лет назад

In apusys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS05672003.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-22vx-583j-gv96

больше 4 лет назад

The Remote Desktop client in Windows XP sends the most recent user account name in cleartext, which could allow remote attackers to obtain terminal server user account names via sniffing.

EPSS: Средний
github логотип

GHSA-22vx-3c5q-pcwr

почти 3 года назад

xunruicms <=4.5.1 is vulnerable to Remote Code Execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-22vx-2x23-98w6

3 месяца назад

OpenSearch vulnerable to improper authorization for Rollover Requests

CVSS3: 2.2
EPSS: Низкий
github логотип

GHSA-22vw-7ch9-23fx

около 2 месяцев назад

In handleBondStateChanged of AdapterService.java, there is a possible sensitive information disclosure due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-22vw-27vp-9fr9

больше 4 лет назад

WinGate 5.2.3 build 901 and 6.0 beta 2 build 942, and other versions such as 5.0.5, allows remote attackers to read arbitrary files via leading slash (//) characters in a URL request to the wingate-internal directory.

EPSS: Низкий
github логотип

GHSA-22vv-j8jc-mq9p

около 4 лет назад

ADSP can be compromised since it`s a general-purpose CPU processing untrusted data in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in IPQ4019, IPQ8064, IPQ8074, MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS405, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-22w8-2mrr-vh7h

A security vulnerability has been detected in OWASP DefectDojo up to 2.55.4. This vulnerability affects the function input_zip.read of the file parser.py of the component SonarQubeParser/MSDefenderParser. The manipulation leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 2.56.0 is able to resolve this issue. The identifier of the patch is e8f1e5131535b8fd80a7b1b3085d676295fdcd41. Upgrading the affected component is recommended.

CVSS3: 4.3
1%
Низкий
5 месяцев назад
github логотип
GHSA-22w8-27w2-f55c

Heap-based buffer overflow in the EscapeParenthesis function in GraphicsMagick before 1.3.25 allows remote attackers to have unspecified impact via unknown vectors.

CVSS3: 9.8
4%
Низкий
около 4 лет назад
github логотип
GHSA-22w7-m5f8-87vh

Liferay Portal and Liferay DXP Vulnerable to Open Redirect via the Layout Module

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-22w7-gmrw-m5qp

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. A malicious application may be able to elevate privileges.

1%
Низкий
около 4 лет назад
github логотип
GHSA-22w7-7694-298f

A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to disclose sensitive informatoin on affected installations.

CVSS3: 7.5
90%
Высокий
около 4 лет назад
github логотип
GHSA-22w6-gp78-84rc

The Red Hat mkdumprd script for kexec-tools, as distributed in the kexec-tools 1.x before 1.102pre-154 and 2.x before 2.0.0-209 packages in Red Hat Enterprise Linux, includes all of root's SSH private keys within a vmcore file, which allows context-dependent attackers to obtain sensitive information by inspecting the file content.

1%
Низкий
около 4 лет назад
github логотип
GHSA-22w6-c8h9-6mx7

NVIDIA Jetson Linux has a vulnerability in initrd, where the nvluks trusted application is not disabled. A successful exploit of this vulnerability might lead to information disclosure.

CVSS3: 5.2
0%
Низкий
4 месяца назад
github логотип
GHSA-22w5-vw2x-wqp3

Cross-site scripting (XSS) vulnerability in index.php in the PhotoSmash plugin 1.0.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the action parameter.

2%
Низкий
около 4 лет назад
github логотип
GHSA-22w4-vm3c-6x82

DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_pic_view.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.

1%
Низкий
около 4 лет назад
github логотип
GHSA-22w3-693w-x895

webauthn-rs-core/webauthn-authenticator-rs: Origin validation mismatch possible when subdomains are allowed

3 месяца назад
github логотип
GHSA-22w2-qhqg-5898

Multiple unspecified vulnerabilities in Google Chrome before 44.0.2403.89 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-22vx-vmhj-v8m6

Windows SmartScreen Security Feature Bypass Vulnerability.

CVSS3: 5.4
76%
Высокий
больше 3 лет назад
github логотип
GHSA-22vx-j9g4-5q8f

It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.

CVSS3: 5.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-22vx-6323-v265

In apusys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05672107; Issue ID: ALPS05672003.

CVSS3: 6.7
0%
Низкий
больше 4 лет назад
github логотип
GHSA-22vx-583j-gv96

The Remote Desktop client in Windows XP sends the most recent user account name in cleartext, which could allow remote attackers to obtain terminal server user account names via sniffing.

13%
Средний
больше 4 лет назад
github логотип
GHSA-22vx-3c5q-pcwr

xunruicms <=4.5.1 is vulnerable to Remote Code Execution.

CVSS3: 9.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-22vx-2x23-98w6

OpenSearch vulnerable to improper authorization for Rollover Requests

CVSS3: 2.2
3 месяца назад
github логотип
GHSA-22vw-7ch9-23fx

In handleBondStateChanged of AdapterService.java, there is a possible sensitive information disclosure due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 3.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-22vw-27vp-9fr9

WinGate 5.2.3 build 901 and 6.0 beta 2 build 942, and other versions such as 5.0.5, allows remote attackers to read arbitrary files via leading slash (//) characters in a URL request to the wingate-internal directory.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-22vv-j8jc-mq9p

ADSP can be compromised since it`s a general-purpose CPU processing untrusted data in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in IPQ4019, IPQ8064, IPQ8074, MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS405, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24

0%
Низкий
около 4 лет назад

Уязвимостей на страницу