Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 704

Количество 355 704

github логотип

GHSA-xq4r-4xfh-vch8

больше 2 лет назад

Liferay Portal and Liferay DXP vulnerable to theft of hashed password

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xq4q-93xc-52g2

22 дня назад

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: add wcid publish check in mt76_sta_add Since mt7925_mac_sta_add publishes wcid, add publish check in mt76_sta_add to avoid reinitializing the wcid->poll_list. Found dev->sta_poll_list corruption when using mt7925 and 7.1-rc4. According to the corruption information, prev->next was changed to itself. wlan0: disconnect from AP 90:fb:5d:94:8b:e3 for new auth to 90:fb:5d:94:8b:e2 wlan0: authenticate with 90:fb:5d:94:8b:e2 (local address=84:9e:56:9c:7e:6b) wlan0: send auth to 90:fb:5d:94:8b:e2 (try 1/3) slab kmalloc-8k start ffff8c80958a6000 pointer offset 4160 size 8192 list_add corruption. prev->next should be next (ffff8c808a7488f8), but was ffff8c80958a7040. (prev=ffff8c80958a7040). mt76_wcid_add_poll+0x95/0xd0 [mt76] mt7925_mac_add_txs.part.0+0xa5/0xe0 [mt7925_common] mt7925_rx_check+0xa7/0xc0 [mt7925_common] mt76_dma_rx_poll+0x50d/0x790 [mt76] mt792x_poll_rx+0x52/0xe0 [mt792x_lib]

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xq4q-2rxg-mhwp

больше 4 лет назад

Cross-site scripting vulnerability in index.php in raSMP 2.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the $_SERVER[HTTP_USER_AGENT] variable (User-Agent header).

EPSS: Низкий
github логотип

GHSA-xq4p-wwvx-xw44

больше 3 лет назад

In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xq4p-gp5c-c5rw

около 4 лет назад

Session fixation vulnerability in Fujitsu e-Pares V01 L01, L03, L10, L20, L30 allows remote attackers to hijack web sessions via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xq4p-6j59-jfv4

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: usb: typec: altmodes/displayport: create sysfs nodes as driver's default device attribute group The DisplayPort driver's sysfs nodes may be present to the userspace before typec_altmode_set_drvdata() completes in dp_altmode_probe. This means that a sysfs read can trigger a NULL pointer error by deferencing dp->hpd in hpd_show or dp->lock in pin_assignment_show, as dev_get_drvdata() returns NULL in those cases. Remove manual sysfs node creation in favor of adding attribute group as default for devices bound to the driver. The ATTRIBUTE_GROUPS() macro is not used here otherwise the path to the sysfs nodes is no longer compliant with the ABI.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xq4m-w85j-23vg

12 месяцев назад

The The Soledad theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.6.7. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xq4m-r2r3-54jq

около 4 лет назад

acp/core/files.browser.php in flatCore 1.4.7 allows file deletion via directory traversal in the delete parameter to acp/acp.php. The risk might be limited to requests submitted through CSRF.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xq4m-mc3c-vvg3

8 месяцев назад

Claude Code Command Validation Bypass Allows Arbitrary Code Execution

EPSS: Низкий
github логотип

GHSA-xq4m-hfgr-r2x5

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix potential bug in end_buffer_async_write According to a syzbot report, end_buffer_async_write(), which handles the completion of block device writes, may detect abnormal condition of the buffer async_write flag and cause a BUG_ON failure when using nilfs2. Nilfs2 itself does not use end_buffer_async_write(). But, the async_write flag is now used as a marker by commit 7f42ec394156 ("nilfs2: fix issue with race condition of competition between segments for dirty blocks") as a means of resolving double list insertion of dirty blocks in nilfs_lookup_dirty_data_buffers() and nilfs_lookup_node_buffers() and the resulting crash. This modification is safe as long as it is used for file data and b-tree node blocks where the page caches are independent. However, it was irrelevant and redundant to also introduce async_write for segment summary and super root blocks that share buffers with the backing device. ...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xq4m-cj98-7hg9

около 4 лет назад

Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality, integrity, and availability via vectors related to IPS transfer module, a different vulnerability than CVE-2014-4280.

EPSS: Низкий
github логотип

GHSA-xq4j-x39q-xhqm

6 месяцев назад

A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended extraction directory. This vulnerability appears to be susceptible on Windows OS only.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-xq4j-rv6r-ch63

около 2 лет назад

Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the 'view' parameter in '/student/index.php'.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xq4j-j5qp-3mfq

больше 3 лет назад

Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to an escalation of privileges.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xq4j-g85q-wf97

4 месяца назад

REDAXO has reflected XSS backend packages API via function parameter (CSRF token required)

EPSS: Низкий
github логотип

GHSA-xq4h-wqm2-668w

9 месяцев назад

Babylon's BIP322 signature implementation is not fully compliant to the spec

EPSS: Низкий
github логотип

GHSA-xq4h-hmq6-ghrv

около 4 лет назад

Mozilla Firefox 38.0 and Firefox ESR 38.0 allow user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges via a crafted web site that is accessed with unspecified mouse and keyboard actions. NOTE: this vulnerability exists because of a CVE-2015-0821 regression.

EPSS: Низкий
github логотип

GHSA-xq4h-8qpv-793q

больше 1 года назад

in OpenHarmony v4.1.1 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xq4h-4mpj-q5jr

около 2 лет назад

Transient DOS while processing TID-to-link mapping IE elements.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xq4g-vf85-h54p

около 4 лет назад

EspoCRM version 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the api/v1/Document functionality for storing documents in the account tab. An attacker can upload a crafted file that contains JavaScript code in its name. This code will be executed when a user opens a page of any profile with this.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xq4r-4xfh-vch8

Liferay Portal and Liferay DXP vulnerable to theft of hashed password

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xq4q-93xc-52g2

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: add wcid publish check in mt76_sta_add Since mt7925_mac_sta_add publishes wcid, add publish check in mt76_sta_add to avoid reinitializing the wcid->poll_list. Found dev->sta_poll_list corruption when using mt7925 and 7.1-rc4. According to the corruption information, prev->next was changed to itself. wlan0: disconnect from AP 90:fb:5d:94:8b:e3 for new auth to 90:fb:5d:94:8b:e2 wlan0: authenticate with 90:fb:5d:94:8b:e2 (local address=84:9e:56:9c:7e:6b) wlan0: send auth to 90:fb:5d:94:8b:e2 (try 1/3) slab kmalloc-8k start ffff8c80958a6000 pointer offset 4160 size 8192 list_add corruption. prev->next should be next (ffff8c808a7488f8), but was ffff8c80958a7040. (prev=ffff8c80958a7040). mt76_wcid_add_poll+0x95/0xd0 [mt76] mt7925_mac_add_txs.part.0+0xa5/0xe0 [mt7925_common] mt7925_rx_check+0xa7/0xc0 [mt7925_common] mt76_dma_rx_poll+0x50d/0x790 [mt76] mt792x_poll_rx+0x52/0xe0 [mt792x_lib]

CVSS3: 8.8
0%
Низкий
22 дня назад
github логотип
GHSA-xq4q-2rxg-mhwp

Cross-site scripting vulnerability in index.php in raSMP 2.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the $_SERVER[HTTP_USER_AGENT] variable (User-Agent header).

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xq4p-wwvx-xw44

In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xq4p-gp5c-c5rw

Session fixation vulnerability in Fujitsu e-Pares V01 L01, L03, L10, L20, L30 allows remote attackers to hijack web sessions via unspecified vectors.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xq4p-6j59-jfv4

In the Linux kernel, the following vulnerability has been resolved: usb: typec: altmodes/displayport: create sysfs nodes as driver's default device attribute group The DisplayPort driver's sysfs nodes may be present to the userspace before typec_altmode_set_drvdata() completes in dp_altmode_probe. This means that a sysfs read can trigger a NULL pointer error by deferencing dp->hpd in hpd_show or dp->lock in pin_assignment_show, as dev_get_drvdata() returns NULL in those cases. Remove manual sysfs node creation in favor of adding attribute group as default for devices bound to the driver. The ATTRIBUTE_GROUPS() macro is not used here otherwise the path to the sysfs nodes is no longer compliant with the ABI.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-xq4m-w85j-23vg

The The Soledad theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.6.7. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

CVSS3: 7.3
0%
Низкий
12 месяцев назад
github логотип
GHSA-xq4m-r2r3-54jq

acp/core/files.browser.php in flatCore 1.4.7 allows file deletion via directory traversal in the delete parameter to acp/acp.php. The risk might be limited to requests submitted through CSRF.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-xq4m-mc3c-vvg3

Claude Code Command Validation Bypass Allows Arbitrary Code Execution

1%
Низкий
8 месяцев назад
github логотип
GHSA-xq4m-hfgr-r2x5

In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix potential bug in end_buffer_async_write According to a syzbot report, end_buffer_async_write(), which handles the completion of block device writes, may detect abnormal condition of the buffer async_write flag and cause a BUG_ON failure when using nilfs2. Nilfs2 itself does not use end_buffer_async_write(). But, the async_write flag is now used as a marker by commit 7f42ec394156 ("nilfs2: fix issue with race condition of competition between segments for dirty blocks") as a means of resolving double list insertion of dirty blocks in nilfs_lookup_dirty_data_buffers() and nilfs_lookup_node_buffers() and the resulting crash. This modification is safe as long as it is used for file data and b-tree node blocks where the page caches are independent. However, it was irrelevant and redundant to also introduce async_write for segment summary and super root blocks that share buffers with the backing device. ...

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xq4m-cj98-7hg9

Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality, integrity, and availability via vectors related to IPS transfer module, a different vulnerability than CVE-2014-4280.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xq4j-x39q-xhqm

A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended extraction directory. This vulnerability appears to be susceptible on Windows OS only.

CVSS3: 8.2
0%
Низкий
6 месяцев назад
github логотип
GHSA-xq4j-rv6r-ch63

Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the 'view' parameter in '/student/index.php'.

CVSS3: 7.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-xq4j-j5qp-3mfq

Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to an escalation of privileges.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xq4j-g85q-wf97

REDAXO has reflected XSS backend packages API via function parameter (CSRF token required)

4 месяца назад
github логотип
GHSA-xq4h-wqm2-668w

Babylon's BIP322 signature implementation is not fully compliant to the spec

9 месяцев назад
github логотип
GHSA-xq4h-hmq6-ghrv

Mozilla Firefox 38.0 and Firefox ESR 38.0 allow user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges via a crafted web site that is accessed with unspecified mouse and keyboard actions. NOTE: this vulnerability exists because of a CVE-2015-0821 regression.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xq4h-8qpv-793q

in OpenHarmony v4.1.1 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xq4h-4mpj-q5jr

Transient DOS while processing TID-to-link mapping IE elements.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-xq4g-vf85-h54p

EspoCRM version 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the api/v1/Document functionality for storing documents in the account tab. An attacker can upload a crafted file that contains JavaScript code in its name. This code will be executed when a user opens a page of any profile with this.

CVSS3: 6.1
1%
Низкий
около 4 лет назад

Уязвимостей на страницу