Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 628

Количество 355 628

github логотип

GHSA-xq97-24qj-jwq2

около 4 лет назад

A vulnerability in BIOS authentication management of Cisco 5000 Series Enterprise Network Compute System and Cisco Unified Computing (UCS) E-Series Servers could allow an unauthenticated, local attacker to bypass the BIOS authentication and execute actions as an unprivileged user. The vulnerability is due to improper security restrictions that are imposed by the affected system. An attacker could exploit this vulnerability by submitting an empty password value to an affected device's BIOS authentication prompt. An exploit could allow the attacker to have access to a restricted set of user-level BIOS commands. Cisco Bug IDs: CSCvh83260.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xq96-f7x8-gfx3

около 1 месяца назад

A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent processing of another archive entry can trigger a second free of the same memory region, resulting in a double-free condition. Successful exploitation may cause applications using the vulnerable libarchive API to terminate unexpectedly, leading to a denial of service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xq95-8x62-4j38

почти 2 года назад

An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. By default, the device comes (and functions) without a password. The user is at no point prompted to set up a password on the device (leaving a number of devices without a password). In this case, anyone connecting to the web admin panel is capable of becoming admin without using any credentials.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xq95-4rwq-mppc

больше 4 лет назад

The (1) gendef.sh, (2) doc/fixinfo.sh, and (3) contrib/gdiffmk/tests/runtests.in scripts in GNU troff (aka groff) 1.21 and earlier allow local users to overwrite arbitrary files via a symlink attack on a gro#####.tmp or /tmp/##### temporary file.

EPSS: Низкий
github логотип

GHSA-xq94-r468-qwgj

4 месяца назад

OpenClaw: Browser SSRF hostname validation could be bypassed by DNS rebinding

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xq94-mvh2-x3r2

около 4 лет назад

ClickDesk version 4.3 and below has persistent cross site scripting

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xq94-j9xm-j8mp

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix NULL pointer dereference in svm_migrate_to_ram() ./drivers/gpu/drm/amd/amdkfd/kfd_migrate.c:985:58-62: ERROR: p is NULL but dereferenced.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xq93-xr8g-2h7w

10 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix smbdirect_recv_io leak in smbd_negotiate() error path During tests of another unrelated patch I was able to trigger this error: Objects remaining on __kmem_cache_shutdown()

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xq93-2hg3-rpjx

9 месяцев назад

Zohocorp ManageEngine Exchange Reporter Plus through 5721 are vulnerable to ReDOS vulnerability in the search module.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xq8x-w75x-jmpc

12 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix use-after-free in amdgpu_userq_suspend+0x51a/0x5a0 [ +0.000020] BUG: KASAN: slab-use-after-free in amdgpu_userq_suspend+0x51a/0x5a0 [amdgpu] [ +0.000817] Read of size 8 at addr ffff88812eec8c58 by task amd_pci_unplug/1733 [ +0.000027] CPU: 10 UID: 0 PID: 1733 Comm: amd_pci_unplug Tainted: G W 6.14.0+ #2 [ +0.000009] Tainted: [W]=WARN [ +0.000003] Hardware name: ASUS System Product Name/ROG STRIX B550-F GAMING (WI-FI), BIOS 1401 12/03/2020 [ +0.000004] Call Trace: [ +0.000004] <TASK> [ +0.000003] dump_stack_lvl+0x76/0xa0 [ +0.000011] print_report+0xce/0x600 [ +0.000009] ? srso_return_thunk+0x5/0x5f [ +0.000006] ? kasan_complete_mode_report_info+0x76/0x200 [ +0.000007] ? kasan_addr_to_slab+0xd/0xb0 [ +0.000006] ? amdgpu_userq_suspend+0x51a/0x5a0 [amdgpu] [ +0.000707] kasan_report+0xbe/0x110 [ +0.000006] ? amdgpu_userq_suspend+0x51a/0x5a0 [amdgpu] [ +0.000541]...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xq8w-9jvx-gm3v

2 месяца назад

hermes-agent has an Injection issue

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xq8w-42gv-82j4

больше 4 лет назад

Buffer overflow in QuickDraw Manager for Apple OS X 10.3.9 and 10.4.2, as used by applications such as Safari, Mail, and Finder, allows remote attackers to execute arbitrary code via a crafted PICT file.

EPSS: Низкий
github логотип

GHSA-xq8v-w479-r24f

больше 3 лет назад

Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xq8v-3x6g-9vpm

больше 4 лет назад

PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and 2.6.4-pl1 allows remote attackers to include local files via the $__redirect parameter, possibly involving the subform array.

EPSS: Средний
github логотип

GHSA-xq8r-r72r-pqwm

почти 6 лет назад

Downloads Resources over HTTP in roslib-socketio

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xq8r-c6vq-9553

больше 4 лет назад

The _dl_unsetenv function in loader.c in the ELF ld.so in OpenBSD 3.9 and 4.0 does not properly remove duplicate environment variables, which allows local users to pass dangerous variables such as LD_PRELOAD to loading processes, which might be leveraged to gain privileges.

EPSS: Низкий
github логотип

GHSA-xq8r-6v6q-5jcf

около 4 лет назад

Check Point SmartConsole before R80.20 Build 119, R80.30 before Build 94, R80.40 before Build 415, and R81 before Build 548 were vulnerable to a possible local privilege escalation due to running executables from a directory with write access to all authenticated users.

EPSS: Низкий
github логотип

GHSA-xq8m-m27q-hg69

почти 3 года назад

SQL Injection vulnerability in oretnom23 School Faculty Scheduling System version 1.0, allows remote attacker to execute arbitrary code, escalate privilieges, and gain sensitive information via crafted payload to id parameter in manage_user.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xq8m-cj64-vrmm

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound UniTimetable allows Stored XSS. This issue affects UniTimetable: from n/a through 1.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xq8m-cc84-8x5q

около 4 лет назад

SAP NetWeaver Portal, WebDynpro Java, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xq97-24qj-jwq2

A vulnerability in BIOS authentication management of Cisco 5000 Series Enterprise Network Compute System and Cisco Unified Computing (UCS) E-Series Servers could allow an unauthenticated, local attacker to bypass the BIOS authentication and execute actions as an unprivileged user. The vulnerability is due to improper security restrictions that are imposed by the affected system. An attacker could exploit this vulnerability by submitting an empty password value to an affected device's BIOS authentication prompt. An exploit could allow the attacker to have access to a restricted set of user-level BIOS commands. Cisco Bug IDs: CSCvh83260.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-xq96-f7x8-gfx3

A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent processing of another archive entry can trigger a second free of the same memory region, resulting in a double-free condition. Successful exploitation may cause applications using the vulnerable libarchive API to terminate unexpectedly, leading to a denial of service.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xq95-8x62-4j38

An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. By default, the device comes (and functions) without a password. The user is at no point prompted to set up a password on the device (leaving a number of devices without a password). In this case, anyone connecting to the web admin panel is capable of becoming admin without using any credentials.

CVSS3: 8.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-xq95-4rwq-mppc

The (1) gendef.sh, (2) doc/fixinfo.sh, and (3) contrib/gdiffmk/tests/runtests.in scripts in GNU troff (aka groff) 1.21 and earlier allow local users to overwrite arbitrary files via a symlink attack on a gro#####.tmp or /tmp/##### temporary file.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xq94-r468-qwgj

OpenClaw: Browser SSRF hostname validation could be bypassed by DNS rebinding

CVSS3: 6.3
0%
Низкий
4 месяца назад
github логотип
GHSA-xq94-mvh2-x3r2

ClickDesk version 4.3 and below has persistent cross site scripting

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-xq94-j9xm-j8mp

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix NULL pointer dereference in svm_migrate_to_ram() ./drivers/gpu/drm/amd/amdkfd/kfd_migrate.c:985:58-62: ERROR: p is NULL but dereferenced.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xq93-xr8g-2h7w

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix smbdirect_recv_io leak in smbd_negotiate() error path During tests of another unrelated patch I was able to trigger this error: Objects remaining on __kmem_cache_shutdown()

CVSS3: 5.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-xq93-2hg3-rpjx

Zohocorp ManageEngine Exchange Reporter Plus through 5721 are vulnerable to ReDOS vulnerability in the search module.

CVSS3: 4.3
1%
Низкий
9 месяцев назад
github логотип
GHSA-xq8x-w75x-jmpc

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix use-after-free in amdgpu_userq_suspend+0x51a/0x5a0 [ +0.000020] BUG: KASAN: slab-use-after-free in amdgpu_userq_suspend+0x51a/0x5a0 [amdgpu] [ +0.000817] Read of size 8 at addr ffff88812eec8c58 by task amd_pci_unplug/1733 [ +0.000027] CPU: 10 UID: 0 PID: 1733 Comm: amd_pci_unplug Tainted: G W 6.14.0+ #2 [ +0.000009] Tainted: [W]=WARN [ +0.000003] Hardware name: ASUS System Product Name/ROG STRIX B550-F GAMING (WI-FI), BIOS 1401 12/03/2020 [ +0.000004] Call Trace: [ +0.000004] <TASK> [ +0.000003] dump_stack_lvl+0x76/0xa0 [ +0.000011] print_report+0xce/0x600 [ +0.000009] ? srso_return_thunk+0x5/0x5f [ +0.000006] ? kasan_complete_mode_report_info+0x76/0x200 [ +0.000007] ? kasan_addr_to_slab+0xd/0xb0 [ +0.000006] ? amdgpu_userq_suspend+0x51a/0x5a0 [amdgpu] [ +0.000707] kasan_report+0xbe/0x110 [ +0.000006] ? amdgpu_userq_suspend+0x51a/0x5a0 [amdgpu] [ +0.000541]...

CVSS3: 7.8
0%
Низкий
12 месяцев назад
github логотип
GHSA-xq8w-9jvx-gm3v

hermes-agent has an Injection issue

CVSS3: 7.3
0%
Низкий
2 месяца назад
github логотип
GHSA-xq8w-42gv-82j4

Buffer overflow in QuickDraw Manager for Apple OS X 10.3.9 and 10.4.2, as used by applications such as Safari, Mail, and Finder, allows remote attackers to execute arbitrary code via a crafted PICT file.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-xq8v-w479-r24f

Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xq8v-3x6g-9vpm

PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and 2.6.4-pl1 allows remote attackers to include local files via the $__redirect parameter, possibly involving the subform array.

16%
Средний
больше 4 лет назад
github логотип
GHSA-xq8r-r72r-pqwm

Downloads Resources over HTTP in roslib-socketio

CVSS3: 8.1
2%
Низкий
почти 6 лет назад
github логотип
GHSA-xq8r-c6vq-9553

The _dl_unsetenv function in loader.c in the ELF ld.so in OpenBSD 3.9 and 4.0 does not properly remove duplicate environment variables, which allows local users to pass dangerous variables such as LD_PRELOAD to loading processes, which might be leveraged to gain privileges.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xq8r-6v6q-5jcf

Check Point SmartConsole before R80.20 Build 119, R80.30 before Build 94, R80.40 before Build 415, and R81 before Build 548 were vulnerable to a possible local privilege escalation due to running executables from a directory with write access to all authenticated users.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xq8m-m27q-hg69

SQL Injection vulnerability in oretnom23 School Faculty Scheduling System version 1.0, allows remote attacker to execute arbitrary code, escalate privilieges, and gain sensitive information via crafted payload to id parameter in manage_user.php.

CVSS3: 9.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-xq8m-cj64-vrmm

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound UniTimetable allows Stored XSS. This issue affects UniTimetable: from n/a through 1.1.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xq8m-cc84-8x5q

SAP NetWeaver Portal, WebDynpro Java, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

CVSS3: 6.1
1%
Низкий
около 4 лет назад

Уязвимостей на страницу