Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 364 867

Количество 364 867

github логотип

GHSA-24j9-242h-cf9v

2 месяца назад

Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Weblogic). Supported versions that are affected are 8.61 and 8.62. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT PeopleTools. While the vulnerability is in PeopleSoft Enterprise PT PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PT PeopleTools accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise PT PeopleTools accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-24j8-j3f5-wfw6

больше 4 лет назад

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0. Processing maliciously crafted web content may lead to arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-24j6-cgww-3pm6

больше 4 лет назад

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Format events. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-6355.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-24j6-88m8-2wx3

11 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: coresight: cti: Fix hang in cti_disable_hw() cti_enable_hw() and cti_disable_hw() are called from an atomic context so shouldn't use runtime PM because it can result in a sleep when communicating with firmware. Since commit 3c6656337852 ("Revert "firmware: arm_scmi: Add clock management to the SCMI power domain""), this causes a hang on Juno when running the Perf Coresight tests or running this command: perf record -e cs_etm//u -- ls This was also missed until the revert commit because pm_runtime_put() was called with the wrong device until commit 692c9a499b28 ("coresight: cti: Correct the parameter for pm_runtime_put") With lock and scheduler debugging enabled the following is output: coresight cti_sys0: cti_enable_hw -- dev:cti_sys0 parent: 20020000.cti BUG: sleeping function called from invalid context at drivers/base/power/runtime.c:1151 in_atomic(): 1, irqs_disabled(): 128, non_block: 0, pid:...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-24j5-267c-mjxv

почти 4 года назад

Cross-Site Request Forgery (CSRF) vulnerability in CodeAndMore WP Page Widget plugin <= 3.9 on WordPress leading to plugin settings change.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-24j4-xmfv-849m

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Adrian Moreno WP Lyrics allows Stored XSS.This issue affects WP Lyrics: from n/a through 0.4.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-24j3-w3xq-4r3w

больше 1 года назад

An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Add Mycode function.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-24j2-jggq-gp96

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thiudis Custom Menu allows Stored XSS. This issue affects Custom Menu: from n/a through 1.8.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-24j2-327w-xq74

больше 3 лет назад

Product: AndroidVersions: Android kernelAndroid ID: A-235292841References: N/A

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-24hw-jxqf-4vc6

больше 4 лет назад

Multiple SQL injection vulnerabilities in Portale e-commerce Creasito (aka creasito e-commerce content manager) 1.3.16, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the username parameter to (1) admin/checkuser.php and (2) checkuser.php.

EPSS: Низкий
github логотип

GHSA-24hr-cpfg-6gx9

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: mfd: max77620: Fix refcount leak in max77620_initialise_fps of_get_child_by_name() returns a node pointer with refcount incremented, we should use of_node_put() on it when not need anymore. Add missing of_node_put() to avoid refcount leak.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-24hp-jpqm-m2j2

больше 4 лет назад

An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. A local attacker may be able to elevate their privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-24hp-h6f6-wg59

больше 4 лет назад

oggenc/oggenc.c in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted raw file.

EPSS: Низкий
github логотип

GHSA-24hp-h53g-7w7v

больше 4 лет назад

IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 214534.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-24hp-84jp-8wgm

почти 4 года назад

Cross-Site Request Forgery in Jenkins Cluster Statistics Plugin

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-24hm-wm2h-h8w7

9 месяцев назад

Peppol-py is vulnerable to XXE attacks due to Saxon configuration

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-24hm-fc95-562h

около 2 месяцев назад

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-24hm-687f-7ggw

около 2 месяцев назад

Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-24hj-mv6m-7hw4

больше 4 лет назад

ZoneAlarm and ZoneAlarm Pro allows a local attacker to cause a denial of service by running a trojan to initialize a ZoneAlarm mutex object which prevents ZoneAlarm from starting.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-24hj-cmm2-v789

больше 4 лет назад

Read access violation in the III_dequantize_sample function in mpglibDBL/layer3.c in mp3gain through 1.5.2-r2 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact, a different vulnerability than CVE-2017-9872 and CVE-2017-14409.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-24j9-242h-cf9v

Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Weblogic). Supported versions that are affected are 8.61 and 8.62. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT PeopleTools. While the vulnerability is in PeopleSoft Enterprise PT PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PT PeopleTools accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise PT PeopleTools accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).

CVSS3: 8.7
0%
Низкий
2 месяца назад
github логотип
GHSA-24j8-j3f5-wfw6

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0. Processing maliciously crafted web content may lead to arbitrary code execution.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-24j6-cgww-3pm6

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Format events. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-6355.

CVSS3: 8.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-24j6-88m8-2wx3

In the Linux kernel, the following vulnerability has been resolved: coresight: cti: Fix hang in cti_disable_hw() cti_enable_hw() and cti_disable_hw() are called from an atomic context so shouldn't use runtime PM because it can result in a sleep when communicating with firmware. Since commit 3c6656337852 ("Revert "firmware: arm_scmi: Add clock management to the SCMI power domain""), this causes a hang on Juno when running the Perf Coresight tests or running this command: perf record -e cs_etm//u -- ls This was also missed until the revert commit because pm_runtime_put() was called with the wrong device until commit 692c9a499b28 ("coresight: cti: Correct the parameter for pm_runtime_put") With lock and scheduler debugging enabled the following is output: coresight cti_sys0: cti_enable_hw -- dev:cti_sys0 parent: 20020000.cti BUG: sleeping function called from invalid context at drivers/base/power/runtime.c:1151 in_atomic(): 1, irqs_disabled(): 128, non_block: 0, pid:...

CVSS3: 5.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-24j5-267c-mjxv

Cross-Site Request Forgery (CSRF) vulnerability in CodeAndMore WP Page Widget plugin <= 3.9 on WordPress leading to plugin settings change.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-24j4-xmfv-849m

Cross-Site Request Forgery (CSRF) vulnerability in Adrian Moreno WP Lyrics allows Stored XSS.This issue affects WP Lyrics: from n/a through 0.4.1.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-24j3-w3xq-4r3w

An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Add Mycode function.

CVSS3: 7.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-24j2-jggq-gp96

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thiudis Custom Menu allows Stored XSS. This issue affects Custom Menu: from n/a through 1.8.

CVSS3: 6.5
1%
Низкий
около 1 года назад
github логотип
GHSA-24j2-327w-xq74

Product: AndroidVersions: Android kernelAndroid ID: A-235292841References: N/A

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-24hw-jxqf-4vc6

Multiple SQL injection vulnerabilities in Portale e-commerce Creasito (aka creasito e-commerce content manager) 1.3.16, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the username parameter to (1) admin/checkuser.php and (2) checkuser.php.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-24hr-cpfg-6gx9

In the Linux kernel, the following vulnerability has been resolved: mfd: max77620: Fix refcount leak in max77620_initialise_fps of_get_child_by_name() returns a node pointer with refcount incremented, we should use of_node_put() on it when not need anymore. Add missing of_node_put() to avoid refcount leak.

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-24hp-jpqm-m2j2

An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. A local attacker may be able to elevate their privileges.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-24hp-h6f6-wg59

oggenc/oggenc.c in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted raw file.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-24hp-h53g-7w7v

IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 214534.

CVSS3: 5.4
0%
Низкий
больше 4 лет назад
github логотип
GHSA-24hp-84jp-8wgm

Cross-Site Request Forgery in Jenkins Cluster Statistics Plugin

CVSS3: 4.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-24hm-wm2h-h8w7

Peppol-py is vulnerable to XXE attacks due to Saxon configuration

CVSS3: 5
0%
Низкий
9 месяцев назад
github логотип
GHSA-24hm-fc95-562h

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction.

CVSS3: 5.9
1%
Низкий
около 2 месяцев назад
github логотип
GHSA-24hm-687f-7ggw

Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally.

CVSS3: 4.7
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-24hj-mv6m-7hw4

ZoneAlarm and ZoneAlarm Pro allows a local attacker to cause a denial of service by running a trojan to initialize a ZoneAlarm mutex object which prevents ZoneAlarm from starting.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-24hj-cmm2-v789

Read access violation in the III_dequantize_sample function in mpglibDBL/layer3.c in mp3gain through 1.5.2-r2 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact, a different vulnerability than CVE-2017-9872 and CVE-2017-14409.

CVSS3: 7.8
2%
Низкий
больше 4 лет назад

Уязвимостей на страницу