Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-2666-8p4f-7r6x

около 1 месяца назад

In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios __folio_split() keeps dereferencing the mapping after the split: shmem_uncharge(mapping->host) and remap_page() while the folios are still frozen/locked, and i_mmap_unlock_read(mapping) at the very end, after the after-split folios have been unlocked and freed. Nothing holds an inode reference across that. The split relies on @folio -- which the beyond-EOF drop loop never removes, as it starts at folio_next(folio) -- staying locked and in the page cache to hold off eviction. But the unlock loop unlocks @folio before i_mmap_unlock_read() runs. If the caller's @lock_at is a tail beyond EOF, as memory_failure() passes when splitting a poisoned tail of a shmem THP that reaches past i_size during truncation, it too is gone from the page cache; so once @folio is unlocked no locked, in-cache folio pins the inode, and a concurrent final iput() can...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2665-m8rg-c7xp

7 месяцев назад

A security vulnerability has been detected in Tenda HG9 300001138. Affected by this issue is some unknown functionality of the file /boaform/formLoopBack of the component Loopback Detection Configuration Endpoint. Such manipulation of the argument Ethtype leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2665-5qhw-p224

больше 1 года назад

A Reflected Cross-Site Scripting (XSS) vulnerability has been discovered in FAST LTA Silent Brick WebUI, allowing attackers to inject malicious JavaScript code into web pages viewed by users. This issue arises when user-supplied input is improperly handled and reflected directly in the output of a web page without proper sanitization or encoding. Exploiting this vulnerability, an attacker can execute arbitrary JavaScript in the context of the victim's browser, potentially leading to session hijacking, data theft, and other malicious actions. Affected WebUI parameters are "h", "hd", "p", "pi", "s", "t", "x", "y".

EPSS: Низкий
github логотип

GHSA-2664-hr5v-554w

около 1 месяца назад

n8n is a workflow automation platform. In versions prior to 1.123.69, 2.33.4, and 2.34.1, the JavaScript Code node's VM sandbox did not freeze the sandbox's Function.prototype, allowing an authenticated user with the ability to create and execute workflows to pollute it from within a Code node execution and recover a reference to the host's globalThis, resulting in a sandbox escape. The full exploit chain additionally depends on specific modules being available as allowlisted imports in the deployment's configuration. The issue is fixed in versions 1.123.69, 2.33.4, and 2.34.1.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2663-pr32-5j3w

больше 4 лет назад

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper buffer length calculation in wma_roam_scan_filter() leads to buffer overflow.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2663-jm96-pp8f

почти 2 года назад

IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, 9.4 CD, IBM MQ Appliance 9.3 LTS, 9.3 CD, 9.4 LTS, and IBM MQ for HPE NonStop 8.1.0 through 8.1.0.25 could allow an authenticated user to cause a denial-of-service due to messages with improperly set values.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2662-x873-f333

больше 4 лет назад

A malicious authenticated user may be able to delete a device from the Junos Space database without the necessary privileges through crafted Ajax interactions obtained from another legitimate delete action performed by another administrative user. Affected releases are Juniper Networks Junos Space versions prior to 18.3R1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-265x-jgfx-f3g8

больше 4 лет назад

A vulnerability(improper input validation) in the ExECM CoreB2B solution allows an unauthenticated attacker to download and execute an arbitrary file via httpDownload function. A successful exploit could allow the attacker to hijack vulnerable system.

EPSS: Низкий
github логотип

GHSA-265x-fx7c-234x

больше 4 лет назад

Privileges manipulation in Micro Focus Data Protector, versions 10.00, 10.01, 10.02, 10.03, 10.04, 10.10, 10.20, 10.30, 10.40. This vulnerability could be exploited by a low-privileged user to execute a custom binary with higher privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-265x-5fh2-vqf4

больше 4 лет назад

In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x002220e0.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-265x-54h3-3643

больше 4 лет назад

Unspecified vulnerability in the font parsing implementation in Sun JDK and JRE 5.0 Update 9 and earlier, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to perform unauthorized actions via an applet that grants certain privileges to itself.

EPSS: Низкий
github логотип

GHSA-265x-3mxm-gj2j

почти 2 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ehues Gboy Custom Google Map allows Blind SQL Injection.This issue affects Gboy Custom Google Map: from n/a through 1.2.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-265w-rf2w-cjh4

5 месяцев назад

Paperclip: Privilege Escalation via Agent-Controlled workspaceStrategy.provisionCommand Leading to OS Command Execution

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-265v-54qj-mvh8

около 3 лет назад

The Gravity Forms WordPress plugin before 2.7.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high-privileged users such as admin.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-265r-pp83-gww7

больше 4 лет назад

Cross-site Scripting in Apache Struts

EPSS: Низкий
github логотип

GHSA-265r-mxr6-rf33

около 1 месяца назад

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-265r-hfxg-fhmg

больше 1 года назад

containerd has an integer overflow in User ID handling

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-265q-28rp-chq5

больше 6 лет назад

Insecure Entropy Source - Math.random() in node-uuid

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-265q-222x-52m6

больше 2 лет назад

silverstripe/framework has potential SQL Injection vulnerability in PostgreSQL database connector

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-265p-mprc-6xmw

больше 4 лет назад

Windows Print Spooler Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-26878.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2666-8p4f-7r6x

In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios __folio_split() keeps dereferencing the mapping after the split: shmem_uncharge(mapping->host) and remap_page() while the folios are still frozen/locked, and i_mmap_unlock_read(mapping) at the very end, after the after-split folios have been unlocked and freed. Nothing holds an inode reference across that. The split relies on @folio -- which the beyond-EOF drop loop never removes, as it starts at folio_next(folio) -- staying locked and in the page cache to hold off eviction. But the unlock loop unlocks @folio before i_mmap_unlock_read() runs. If the caller's @lock_at is a tail beyond EOF, as memory_failure() passes when splitting a poisoned tail of a shmem THP that reaches past i_size during truncation, it too is gone from the page cache; so once @folio is unlocked no locked, in-cache folio pins the inode, and a concurrent final iput() can...

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-2665-m8rg-c7xp

A security vulnerability has been detected in Tenda HG9 300001138. Affected by this issue is some unknown functionality of the file /boaform/formLoopBack of the component Loopback Detection Configuration Endpoint. Such manipulation of the argument Ethtype leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

CVSS3: 8.8
1%
Низкий
7 месяцев назад
github логотип
GHSA-2665-5qhw-p224

A Reflected Cross-Site Scripting (XSS) vulnerability has been discovered in FAST LTA Silent Brick WebUI, allowing attackers to inject malicious JavaScript code into web pages viewed by users. This issue arises when user-supplied input is improperly handled and reflected directly in the output of a web page without proper sanitization or encoding. Exploiting this vulnerability, an attacker can execute arbitrary JavaScript in the context of the victim's browser, potentially leading to session hijacking, data theft, and other malicious actions. Affected WebUI parameters are "h", "hd", "p", "pi", "s", "t", "x", "y".

0%
Низкий
больше 1 года назад
github логотип
GHSA-2664-hr5v-554w

n8n is a workflow automation platform. In versions prior to 1.123.69, 2.33.4, and 2.34.1, the JavaScript Code node's VM sandbox did not freeze the sandbox's Function.prototype, allowing an authenticated user with the ability to create and execute workflows to pollute it from within a Code node execution and recover a reference to the host's globalThis, resulting in a sandbox escape. The full exploit chain additionally depends on specific modules being available as allowlisted imports in the deployment's configuration. The issue is fixed in versions 1.123.69, 2.33.4, and 2.34.1.

CVSS3: 5.9
0%
Низкий
около 1 месяца назад
github логотип
GHSA-2663-pr32-5j3w

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper buffer length calculation in wma_roam_scan_filter() leads to buffer overflow.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-2663-jm96-pp8f

IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, 9.4 CD, IBM MQ Appliance 9.3 LTS, 9.3 CD, 9.4 LTS, and IBM MQ for HPE NonStop 8.1.0 through 8.1.0.25 could allow an authenticated user to cause a denial-of-service due to messages with improperly set values.

CVSS3: 6.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-2662-x873-f333

A malicious authenticated user may be able to delete a device from the Junos Space database without the necessary privileges through crafted Ajax interactions obtained from another legitimate delete action performed by another administrative user. Affected releases are Juniper Networks Junos Space versions prior to 18.3R1.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-265x-jgfx-f3g8

A vulnerability(improper input validation) in the ExECM CoreB2B solution allows an unauthenticated attacker to download and execute an arbitrary file via httpDownload function. A successful exploit could allow the attacker to hijack vulnerable system.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-265x-fx7c-234x

Privileges manipulation in Micro Focus Data Protector, versions 10.00, 10.01, 10.02, 10.03, 10.04, 10.10, 10.20, 10.30, 10.40. This vulnerability could be exploited by a low-privileged user to execute a custom binary with higher privileges.

CVSS3: 7.8
8%
Низкий
больше 4 лет назад
github логотип
GHSA-265x-5fh2-vqf4

In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x002220e0.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-265x-54h3-3643

Unspecified vulnerability in the font parsing implementation in Sun JDK and JRE 5.0 Update 9 and earlier, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to perform unauthorized actions via an applet that grants certain privileges to itself.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-265x-3mxm-gj2j

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ehues Gboy Custom Google Map allows Blind SQL Injection.This issue affects Gboy Custom Google Map: from n/a through 1.2.

CVSS3: 8.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-265w-rf2w-cjh4

Paperclip: Privilege Escalation via Agent-Controlled workspaceStrategy.provisionCommand Leading to OS Command Execution

CVSS3: 8.8
1%
Низкий
5 месяцев назад
github логотип
GHSA-265v-54qj-mvh8

The Gravity Forms WordPress plugin before 2.7.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high-privileged users such as admin.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-265r-pp83-gww7

Cross-site Scripting in Apache Struts

6%
Низкий
больше 4 лет назад
github логотип
GHSA-265r-mxr6-rf33

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information or cause a denial of service due to an out-of-bounds read.

CVSS3: 5.4
0%
Низкий
около 1 месяца назад
github логотип
GHSA-265r-hfxg-fhmg

containerd has an integer overflow in User ID handling

CVSS3: 4.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-265q-28rp-chq5

Insecure Entropy Source - Math.random() in node-uuid

CVSS3: 7.5
2%
Низкий
больше 6 лет назад
github логотип
GHSA-265q-222x-52m6

silverstripe/framework has potential SQL Injection vulnerability in PostgreSQL database connector

CVSS3: 8.8
больше 2 лет назад
github логотип
GHSA-265p-mprc-6xmw

Windows Print Spooler Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-26878.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу