Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 364 543

Количество 364 543

github логотип

GHSA-23x2-f488-jm35

больше 4 лет назад

Samsung Gallery on the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-23x2-c6m6-m9c7

больше 4 лет назад

Vulnerability in ppl in HP-UX 10.x and earlier allows local users to gain root privileges by forcing ppl to core dump.

EPSS: Низкий
github логотип

GHSA-23wx-cgxq-vpwx

больше 4 лет назад

Prototype Pollution in dset

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-23wx-6wm2-v53g

больше 4 лет назад

SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-23ww-hxf9-47fc

около 1 года назад

A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011 and classified as problematic. This issue affects some unknown processing of the file /boafrm/formPortFw of the component Virtual Server Page. The manipulation of the argument service_type leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-23ww-2jh7-98f9

больше 4 лет назад

search.dll Sambar ISAPI Search utility in Sambar Server 4.4 Beta 3 allows remote attackers to read arbitrary directories by specifying the directory in the query parameter.

EPSS: Низкий
github логотип

GHSA-23wv-w3v2-hcrj

почти 2 года назад

Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the docname parameter in /admin/add-doctor.php and /admin/edit-doctor.php

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-23wv-q9m5-hq8q

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: aspeed: Add NULL pointer check in ast_vhub_init_dev() The variable d->name, returned by devm_kasprintf(), could be NULL. A pointer check is added to prevent potential NULL pointer dereference. This is similar to the fix in commit 3027e7b15b02 ("ice: Fix some null pointer dereference issues in ice_ptp.c"). This issue is found by our static analysis tool

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-23wv-pq77-4gp7

почти 3 года назад

SiberianCMS - CWE-284 Improper Access Control Authorized user may disable a security feature over the network

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-23wv-2qr9-wf5v

10 дней назад

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could perform Remote Code Execution (RCE) by uploading a malicious knowledge bundle and causing it to be used by distributed search, which can allow for access to all relevant data and affect system integrity and availability. The vulnerability is possible because the Representational State Transfer (REST) API endpoint for knowledge bundle upload does not require the high-privilege capability edit_dist_peer, and distributed search accepts caller-supplied knowledge bundle selections from users who do not hold that capability. For more information see What search heads send to search peers (https://help.splunk.com/en/splunk-enterprise/administer/distributed-search/9.2/knowledge-bundle-replication/what-search-heads-send-to-search-peers), About configuring role-based user access (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-secu...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-23wr-h929-wh3j

больше 4 лет назад

Out-of-bounds read in some Intel(R) Core(TM) processors with Radeon(TM) RX Vega M GL integrated graphics before version 21.10 may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-23wq-qm4c-6497

около 2 лет назад

A cross-site scripting (XSS) vulnerability in skycaiji v2.8 allows attackers to execute arbitrary web scripts or HTML via a crafted payload using eval(String.fromCharCode()).

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-23wq-9cpv-vp32

12 дней назад

Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 14.0.0 - Regular Labs Sourcerer before 14.0.0 processes {source} blocks found in Joomla’s final rendered HTML without reliably determining where that code originated.

EPSS: Низкий
github логотип

GHSA-23wp-rxm7-f6f3

больше 4 лет назад

Biometric Shift Employee Management System has XSS via the Last_Name parameter in an index.php?user=ajax request.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-23wp-pqh4-8w8f

больше 4 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of script within a Calculate action of a text field. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-9044.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-23wj-wvvj-vgcc

больше 4 лет назад

Multiple SQL injection vulnerabilities in admin/login_submit.php in Whole Hog Password Protect: Enhanced 1.x allow remote attackers to execute arbitrary SQL commands via (1) the uid parameter (aka Username field) or (2) the pwd parameter (aka Password field). NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-23wj-r557-8c5p

больше 4 лет назад

tinyexr 0.9.5 has an assertion failure in DecodePixelData in tinyexr.h.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-23wj-h8fm-chf2

больше 4 лет назад

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9650, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, and SD 850, a buffer over-read can occur in a DRM API.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-23wj-fq4f-57vr

больше 4 лет назад

An issue was discovered in MiniCMS 1.10. There is a post.php?date= XSS vulnerability.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-23wh-q78v-xxm4

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: tracing: kprobe: Fix potential null-ptr-deref on trace_event_file in kprobe_event_gen_test_exit() When trace_get_event_file() failed, gen_kretprobe_test will be assigned as the error code. If module kprobe_event_gen_test is removed now, the null pointer dereference will happen in kprobe_event_gen_test_exit(). Check if gen_kprobe_test or gen_kretprobe_test is error code or NULL before dereference them. BUG: kernel NULL pointer dereference, address: 0000000000000012 PGD 0 P4D 0 Oops: 0000 [#1] SMP PTI CPU: 3 PID: 2210 Comm: modprobe Not tainted 6.1.0-rc1-00171-g2159299a3b74-dirty #217 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.15.0-0-g2dd4b9b3f840-prebuilt.qemu.org 04/01/2014 RIP: 0010:kprobe_event_gen_test_exit+0x1c/0xb5 [kprobe_event_gen_test] Code: Unable to access opcode bytes at 0xffffffff9ffffff2. RSP: 0018:ffffc900015bfeb8 EFLAGS: 00010246 RAX: ffffffffffffffea RBX: ffffffffa0002080 RC...

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-23x2-f488-jm35

Samsung Gallery on the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-23x2-c6m6-m9c7

Vulnerability in ppl in HP-UX 10.x and earlier allows local users to gain root privileges by forcing ppl to core dump.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-23wx-cgxq-vpwx

Prototype Pollution in dset

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-23wx-6wm2-v53g

SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php.

CVSS3: 9.8
5%
Низкий
больше 4 лет назад
github логотип
GHSA-23ww-hxf9-47fc

A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011 and classified as problematic. This issue affects some unknown processing of the file /boafrm/formPortFw of the component Virtual Server Page. The manipulation of the argument service_type leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 2.4
0%
Низкий
около 1 года назад
github логотип
GHSA-23ww-2jh7-98f9

search.dll Sambar ISAPI Search utility in Sambar Server 4.4 Beta 3 allows remote attackers to read arbitrary directories by specifying the directory in the query parameter.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-23wv-w3v2-hcrj

Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the docname parameter in /admin/add-doctor.php and /admin/edit-doctor.php

CVSS3: 5.9
0%
Низкий
почти 2 года назад
github логотип
GHSA-23wv-q9m5-hq8q

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: aspeed: Add NULL pointer check in ast_vhub_init_dev() The variable d->name, returned by devm_kasprintf(), could be NULL. A pointer check is added to prevent potential NULL pointer dereference. This is similar to the fix in commit 3027e7b15b02 ("ice: Fix some null pointer dereference issues in ice_ptp.c"). This issue is found by our static analysis tool

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-23wv-pq77-4gp7

SiberianCMS - CWE-284 Improper Access Control Authorized user may disable a security feature over the network

CVSS3: 6.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-23wv-2qr9-wf5v

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could perform Remote Code Execution (RCE) by uploading a malicious knowledge bundle and causing it to be used by distributed search, which can allow for access to all relevant data and affect system integrity and availability. The vulnerability is possible because the Representational State Transfer (REST) API endpoint for knowledge bundle upload does not require the high-privilege capability edit_dist_peer, and distributed search accepts caller-supplied knowledge bundle selections from users who do not hold that capability. For more information see What search heads send to search peers (https://help.splunk.com/en/splunk-enterprise/administer/distributed-search/9.2/knowledge-bundle-replication/what-search-heads-send-to-search-peers), About configuring role-based user access (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-secu...

CVSS3: 8.8
0%
Низкий
10 дней назад
github логотип
GHSA-23wr-h929-wh3j

Out-of-bounds read in some Intel(R) Core(TM) processors with Radeon(TM) RX Vega M GL integrated graphics before version 21.10 may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-23wq-qm4c-6497

A cross-site scripting (XSS) vulnerability in skycaiji v2.8 allows attackers to execute arbitrary web scripts or HTML via a crafted payload using eval(String.fromCharCode()).

CVSS3: 6.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-23wq-9cpv-vp32

Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 14.0.0 - Regular Labs Sourcerer before 14.0.0 processes {source} blocks found in Joomla’s final rendered HTML without reliably determining where that code originated.

0%
Низкий
12 дней назад
github логотип
GHSA-23wp-rxm7-f6f3

Biometric Shift Employee Management System has XSS via the Last_Name parameter in an index.php?user=ajax request.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-23wp-pqh4-8w8f

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of script within a Calculate action of a text field. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-9044.

CVSS3: 8.8
5%
Низкий
больше 4 лет назад
github логотип
GHSA-23wj-wvvj-vgcc

Multiple SQL injection vulnerabilities in admin/login_submit.php in Whole Hog Password Protect: Enhanced 1.x allow remote attackers to execute arbitrary SQL commands via (1) the uid parameter (aka Username field) or (2) the pwd parameter (aka Password field). NOTE: some of these details are obtained from third party information.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-23wj-r557-8c5p

tinyexr 0.9.5 has an assertion failure in DecodePixelData in tinyexr.h.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-23wj-h8fm-chf2

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9650, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, and SD 850, a buffer over-read can occur in a DRM API.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-23wj-fq4f-57vr

An issue was discovered in MiniCMS 1.10. There is a post.php?date= XSS vulnerability.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-23wh-q78v-xxm4

In the Linux kernel, the following vulnerability has been resolved: tracing: kprobe: Fix potential null-ptr-deref on trace_event_file in kprobe_event_gen_test_exit() When trace_get_event_file() failed, gen_kretprobe_test will be assigned as the error code. If module kprobe_event_gen_test is removed now, the null pointer dereference will happen in kprobe_event_gen_test_exit(). Check if gen_kprobe_test or gen_kretprobe_test is error code or NULL before dereference them. BUG: kernel NULL pointer dereference, address: 0000000000000012 PGD 0 P4D 0 Oops: 0000 [#1] SMP PTI CPU: 3 PID: 2210 Comm: modprobe Not tainted 6.1.0-rc1-00171-g2159299a3b74-dirty #217 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.15.0-0-g2dd4b9b3f840-prebuilt.qemu.org 04/01/2014 RIP: 0010:kprobe_event_gen_test_exit+0x1c/0xb5 [kprobe_event_gen_test] Code: Unable to access opcode bytes at 0xffffffff9ffffff2. RSP: 0018:ffffc900015bfeb8 EFLAGS: 00010246 RAX: ffffffffffffffea RBX: ffffffffa0002080 RC...

CVSS3: 5.5
0%
Низкий
больше 1 года назад

Уязвимостей на страницу