Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 325 903

Количество 325 903

github логотип

GHSA-xpqx-4wj8-ww45

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mkkmail Aparat Responsive allows DOM-Based XSS. This issue affects Aparat Responsive: from n/a through 1.3.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xpqw-fqpw-35fc

больше 5 лет назад

Directory Traversal in wangguojing123

EPSS: Низкий
github логотип

GHSA-xpqw-6gx7-v673

около 1 месяца назад

SVGO DoS through entity expansion in DOCTYPE (Billion Laughs)

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xpqw-3mmq-rpcv

почти 4 года назад

Multiple cross-site request forgery (CSRF) vulnerabilities in unspecified administrative modules in Proofpoint Messaging Security Gateway 6.2.0.263:6.2.0.237 and earlier in Proofpoint Protection Server 5.5.3, 5.5.4, 5.5.5, 6.0.2, 6.1.1, and 6.2.0 allow remote attackers to hijack the authentication of administrators via unknown vectors.

EPSS: Низкий
github логотип

GHSA-xpqv-f82r-327v

почти 2 года назад

Improper Privilege Management vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Build App Online: from n/a through 1.0.19.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xpqv-37cp-9vj2

почти 4 года назад

Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by triggering a null dereference.

EPSS: Низкий
github логотип

GHSA-xpqq-583w-8g73

почти 3 года назад

VMware Workstation (17.x) and VMware Fusion (13.x) contain a stack-based buffer-overflow vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-xpqq-5557-v5jm

больше 1 года назад

Credentials to access device configuration were transmitted using an unencrypted protocol. These credentials would allow read-only access to network configuration information and terminal configuration data.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xpqm-wm3m-f34h

2 месяца назад

pnpm scoped bin name Path Traversal allows arbitrary file creation outside node_modules/.bin

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xpqm-h22m-6vxm

почти 4 года назад

Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability in the processing of the AcroForm deleteItemAt action that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

EPSS: Средний
github логотип

GHSA-xpqm-g5q7-2r7x

12 месяцев назад

TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setWebWlanIdx function through the webWlanIdx parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xpqm-66vq-xgp8

почти 2 года назад

Maxon Cinema 4D SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Maxon Cinema 4D. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SKP files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-21437.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xpqj-27x8-277f

почти 4 года назад

NETGEAR JNR1010 devices before 1.0.0.32 have Incorrect Access Control because the ok value of the auth cookie is a special case.

EPSS: Низкий
github логотип

GHSA-xpqh-grpw-4xmg

7 дней назад

Roundcube Webmail: Insufficient CSS sanitization in HTML e-mail messages

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xpqh-2w77-cvcv

12 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: ASoC: imx-card: Add NULL check in imx_card_probe() devm_kasprintf() returns NULL when memory allocation fails. Currently, imx_card_probe() does not check for this case, which results in a NULL pointer dereference. Add NULL check after devm_kasprintf() to prevent this issue.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xpqf-h5q4-9r99

больше 3 лет назад

VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability. A malicious actor with administrator and network access can trigger a remote code execution.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xpqc-2xj6-mrm4

около 3 лет назад

Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xpq9-m45f-g29q

почти 4 года назад

In versions of mruby up to and including 1.4.0, a use-after-free vulnerability exists in src/io.c::File#initilialize_copy(). An attacker that can cause Ruby code to be run can possibly use this to execute arbitrary code.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xpq9-hr2h-w5cj

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: Fix the use of GFP_KERNEL in atomic context on rt The commit 4af1b64f80fb ("octeontx2-pf: Fix lmtst ID used in aura free") uses the get/put_cpu() to protect the usage of percpu pointer in ->aura_freeptr() callback, but it also unnecessarily disable the preemption for the blockable memory allocation. The commit 87b93b678e95 ("octeontx2-pf: Avoid use of GFP_KERNEL in atomic context") tried to fix these sleep inside atomic warnings. But it only fix the one for the non-rt kernel. For the rt kernel, we still get the similar warnings like below. BUG: sleeping function called from invalid context at kernel/locking/spinlock_rt.c:46 in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 1, name: swapper/0 preempt_count: 1, expected: 0 RCU nest depth: 0, expected: 0 3 locks held by swapper/0/1: #0: ffff800009fc5fe8 (rtnl_mutex){+.+.}-{3:3}, at: rtnl_lock+0x24/0x30 #1: ffff000100c276c0 (&mbox->l...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xpq8-mc3r-r862

почти 2 года назад

In onCreate of WifiDialogActivity.java, there is a possible way to bypass the DISALLOW_ADD_WIFI_CONFIG restriction due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xpqx-4wj8-ww45

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mkkmail Aparat Responsive allows DOM-Based XSS. This issue affects Aparat Responsive: from n/a through 1.3.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-xpqw-fqpw-35fc

Directory Traversal in wangguojing123

1%
Низкий
больше 5 лет назад
github логотип
GHSA-xpqw-6gx7-v673

SVGO DoS through entity expansion in DOCTYPE (Billion Laughs)

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xpqw-3mmq-rpcv

Multiple cross-site request forgery (CSRF) vulnerabilities in unspecified administrative modules in Proofpoint Messaging Security Gateway 6.2.0.263:6.2.0.237 and earlier in Proofpoint Protection Server 5.5.3, 5.5.4, 5.5.5, 6.0.2, 6.1.1, and 6.2.0 allow remote attackers to hijack the authentication of administrators via unknown vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xpqv-f82r-327v

Improper Privilege Management vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Build App Online: from n/a through 1.0.19.

CVSS3: 8.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-xpqv-37cp-9vj2

Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by triggering a null dereference.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xpqq-583w-8g73

VMware Workstation (17.x) and VMware Fusion (13.x) contain a stack-based buffer-overflow vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine.

CVSS3: 8.2
2%
Низкий
почти 3 года назад
github логотип
GHSA-xpqq-5557-v5jm

Credentials to access device configuration were transmitted using an unencrypted protocol. These credentials would allow read-only access to network configuration information and terminal configuration data.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xpqm-wm3m-f34h

pnpm scoped bin name Path Traversal allows arbitrary file creation outside node_modules/.bin

CVSS3: 6.5
0%
Низкий
2 месяца назад
github логотип
GHSA-xpqm-h22m-6vxm

Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability in the processing of the AcroForm deleteItemAt action that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

51%
Средний
почти 4 года назад
github логотип
GHSA-xpqm-g5q7-2r7x

TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setWebWlanIdx function through the webWlanIdx parameter.

CVSS3: 9.8
8%
Низкий
12 месяцев назад
github логотип
GHSA-xpqm-66vq-xgp8

Maxon Cinema 4D SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Maxon Cinema 4D. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SKP files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-21437.

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-xpqj-27x8-277f

NETGEAR JNR1010 devices before 1.0.0.32 have Incorrect Access Control because the ok value of the auth cookie is a special case.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xpqh-grpw-4xmg

Roundcube Webmail: Insufficient CSS sanitization in HTML e-mail messages

CVSS3: 5.3
0%
Низкий
7 дней назад
github логотип
GHSA-xpqh-2w77-cvcv

In the Linux kernel, the following vulnerability has been resolved: ASoC: imx-card: Add NULL check in imx_card_probe() devm_kasprintf() returns NULL when memory allocation fails. Currently, imx_card_probe() does not check for this case, which results in a NULL pointer dereference. Add NULL check after devm_kasprintf() to prevent this issue.

CVSS3: 5.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-xpqf-h5q4-9r99

VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability. A malicious actor with administrator and network access can trigger a remote code execution.

CVSS3: 7.2
2%
Низкий
больше 3 лет назад
github логотип
GHSA-xpqc-2xj6-mrm4

Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-xpq9-m45f-g29q

In versions of mruby up to and including 1.4.0, a use-after-free vulnerability exists in src/io.c::File#initilialize_copy(). An attacker that can cause Ruby code to be run can possibly use this to execute arbitrary code.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-xpq9-hr2h-w5cj

In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: Fix the use of GFP_KERNEL in atomic context on rt The commit 4af1b64f80fb ("octeontx2-pf: Fix lmtst ID used in aura free") uses the get/put_cpu() to protect the usage of percpu pointer in ->aura_freeptr() callback, but it also unnecessarily disable the preemption for the blockable memory allocation. The commit 87b93b678e95 ("octeontx2-pf: Avoid use of GFP_KERNEL in atomic context") tried to fix these sleep inside atomic warnings. But it only fix the one for the non-rt kernel. For the rt kernel, we still get the similar warnings like below. BUG: sleeping function called from invalid context at kernel/locking/spinlock_rt.c:46 in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 1, name: swapper/0 preempt_count: 1, expected: 0 RCU nest depth: 0, expected: 0 3 locks held by swapper/0/1: #0: ffff800009fc5fe8 (rtnl_mutex){+.+.}-{3:3}, at: rtnl_lock+0x24/0x30 #1: ffff000100c276c0 (&mbox->l...

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-xpq8-mc3r-r862

In onCreate of WifiDialogActivity.java, there is a possible way to bypass the DISALLOW_ADD_WIFI_CONFIG restriction due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7
0%
Низкий
почти 2 года назад

Уязвимостей на страницу