Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-2578-mq3j-6qq4

больше 4 лет назад

An elevation of privilege vulnerability in Binder could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as Moderate because it first requires compromising a privileged process and is mitigated by current platform configurations. Product: Android. Versions: Kernel-3.18. Android ID: A-32394425.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-2577-j9hh-f6g7

11 месяцев назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and 9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-2576-m45c-p3gg

больше 4 лет назад

The administration interface in the Planet VC-200M VDSL2 router allows remote attackers to cause a denial of service (administration interface outage) via an HTTP request without a Host header.

EPSS: Низкий
github логотип

GHSA-2575-pghm-6qqx

больше 4 лет назад

Kubernetes Unsafe Cacheing

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-2575-mf38-hvqq

больше 4 лет назад

Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Approval Framework). Supported versions that are affected are 9.1 and 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CC Common Application Objects. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise CC Common Application Objects accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2575-c77r-rr97

больше 4 лет назад

gzip before 1.3 in Solaris 8, when called with the -f or -force flags, will change the permissions of files that are hard linked to the target files, which allows local users to view or modify these files.

EPSS: Низкий
github логотип

GHSA-2575-3228-j966

10 месяцев назад

Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2574-fqfw-fxcc

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the DocumentLoader::maybeCreateArchive function in core/loader/DocumentLoader.cpp in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to inject arbitrary web script or HTML via crafted MHTML content, aka "Universal XSS (UXSS)."

EPSS: Низкий
github логотип

GHSA-2574-cw53-m29g

больше 3 лет назад

PublicCMS <=V4.0.202302 is vulnerable to Insecure Permissions.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2573-wq7r-2x2r

больше 4 лет назад

Heap buffer overflow in TabStrip in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2573-rpmq-pq99

больше 4 лет назад

A null pointer dereference was addressed with improved validation. This issue is fixed in macOS High Sierra 10.13, iCloud for Windows 7.0, watchOS 4, iOS 11, iTunes 12.7 for Windows. Processing maliciously crafted XML may lead to an unexpected application termination or arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-2572-4xw7-mcfc

больше 2 лет назад

An issue was discovered in ksmbd in the Linux kernel before 6.6.10. smb2_get_data_area_len in fs/smb/server/smb2misc.c can cause an smb_strndup_from_utf16 out-of-bounds access because the relationship between Name data and CreateContexts data is mishandled.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-256x-7q8g-xjmc

15 дней назад

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of credentials.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-256w-3jc2-hh38

больше 4 лет назад

Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project files lacking proper validation of user supplied data may cause a stack-based buffer overflow, which may allow remote code execution, disclosure/modification of information, or cause the application to crash.

EPSS: Низкий
github логотип

GHSA-256v-mmj4-qqjc

3 месяца назад

Denial of service via malformed HTTP/2 requests in NetScaler ADC and NetScaler Gateway if HTTP/2 is enabled in HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-256v-c957-m9f7

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in msg.php in FoeCMS allow remote attackers to inject arbitrary web script or HTML via the (1) e or (2) r parameter.

EPSS: Низкий
github логотип

GHSA-256q-r8jw-w2f7

больше 4 лет назад

PHP remote file inclusion vulnerability in include/prodler.class.php in ProdLer 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the sPath parameter.

EPSS: Низкий
github логотип

GHSA-256q-hx8w-xcqx

больше 1 года назад

Silverstripe Framework user enumeration via timing attack on login and password reset forms

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-256q-5j64-52vj

больше 4 лет назад

The ieee_archive_p function in bfd/ieee.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, might allow remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution. NOTE: this may be related to a compiler bug.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-256p-jvfp-85c5

больше 4 лет назад

The User Profile & Membership plugin before 2.0.7 for WordPress has no mitigations implemented against cross site request forgery attacks. This is a structural finding throughout the entire plugin.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2578-mq3j-6qq4

An elevation of privilege vulnerability in Binder could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as Moderate because it first requires compromising a privileged process and is mitigated by current platform configurations. Product: Android. Versions: Kernel-3.18. Android ID: A-32394425.

CVSS3: 7
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2577-j9hh-f6g7

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and 9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
1%
Низкий
11 месяцев назад
github логотип
GHSA-2576-m45c-p3gg

The administration interface in the Planet VC-200M VDSL2 router allows remote attackers to cause a denial of service (administration interface outage) via an HTTP request without a Host header.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2575-pghm-6qqx

Kubernetes Unsafe Cacheing

CVSS3: 5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-2575-mf38-hvqq

Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Approval Framework). Supported versions that are affected are 9.1 and 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CC Common Application Objects. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise CC Common Application Objects accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2575-c77r-rr97

gzip before 1.3 in Solaris 8, when called with the -f or -force flags, will change the permissions of files that are hard linked to the target files, which allows local users to view or modify these files.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2575-3228-j966

Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally.

CVSS3: 7.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-2574-fqfw-fxcc

Cross-site scripting (XSS) vulnerability in the DocumentLoader::maybeCreateArchive function in core/loader/DocumentLoader.cpp in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to inject arbitrary web script or HTML via crafted MHTML content, aka "Universal XSS (UXSS)."

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2574-cw53-m29g

PublicCMS <=V4.0.202302 is vulnerable to Insecure Permissions.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2573-wq7r-2x2r

Heap buffer overflow in TabStrip in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-2573-rpmq-pq99

A null pointer dereference was addressed with improved validation. This issue is fixed in macOS High Sierra 10.13, iCloud for Windows 7.0, watchOS 4, iOS 11, iTunes 12.7 for Windows. Processing maliciously crafted XML may lead to an unexpected application termination or arbitrary code execution.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2572-4xw7-mcfc

An issue was discovered in ksmbd in the Linux kernel before 6.6.10. smb2_get_data_area_len in fs/smb/server/smb2misc.c can cause an smb_strndup_from_utf16 out-of-bounds access because the relationship between Name data and CreateContexts data is mishandled.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-256x-7q8g-xjmc

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of credentials.

CVSS3: 6.2
0%
Низкий
15 дней назад
github логотип
GHSA-256w-3jc2-hh38

Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project files lacking proper validation of user supplied data may cause a stack-based buffer overflow, which may allow remote code execution, disclosure/modification of information, or cause the application to crash.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-256v-mmj4-qqjc

Denial of service via malformed HTTP/2 requests in NetScaler ADC and NetScaler Gateway if HTTP/2 is enabled in HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler

CVSS3: 7.5
1%
Низкий
3 месяца назад
github логотип
GHSA-256v-c957-m9f7

Multiple cross-site scripting (XSS) vulnerabilities in msg.php in FoeCMS allow remote attackers to inject arbitrary web script or HTML via the (1) e or (2) r parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-256q-r8jw-w2f7

PHP remote file inclusion vulnerability in include/prodler.class.php in ProdLer 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the sPath parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-256q-hx8w-xcqx

Silverstripe Framework user enumeration via timing attack on login and password reset forms

CVSS3: 5.3
больше 1 года назад
github логотип
GHSA-256q-5j64-52vj

The ieee_archive_p function in bfd/ieee.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, might allow remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution. NOTE: this may be related to a compiler bug.

CVSS3: 7.8
8%
Низкий
больше 4 лет назад
github логотип
GHSA-256p-jvfp-85c5

The User Profile & Membership plugin before 2.0.7 for WordPress has no mitigations implemented against cross site request forgery attacks. This is a structural finding throughout the entire plugin.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу