Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 325 903

Количество 325 903

github логотип

GHSA-xpm3-hxcq-hjv4

почти 4 года назад

Unspecified vulnerability in the Oracle MapViewer component in Oracle Fusion Middleware 10.1.3.1, 11.1.1.5, and 11.1.1.6 allows remote attackers to affect integrity via unknown vectors related to Install.

EPSS: Низкий
github логотип

GHSA-xpm3-5wvv-pxfh

около 1 года назад

A vulnerability classified as critical was found in ywoa up to 2024.07.03. This vulnerability affects the function listNameBySql of the file com/cloudweb/oa/mapper/xml/UserMapper.xml. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2024.07.04 is able to address this issue. It is recommended to upgrade the affected component.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xpm2-jxrf-prmx

почти 4 года назад

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvar_s function

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xpm2-f32f-q35f

больше 1 года назад

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_regulated_pure_pursuit_controller.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xpjw-vcgc-qx6p

почти 4 года назад

A elevation of privilege vulnerability in the Upstream kernel skcipher. Product: Android. Versions: Android kernel. Android ID: A-64386293. References: Upstream kernel.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xpjw-f7rh-9w56

почти 4 года назад

An issue was discovered in EMC ScaleIO 2.0.1.x. In a Linux environment, one of the support scripts saves the credentials of the ScaleIO MDM user who executed the script in clear text in temporary log files. The temporary files may potentially be read by an unprivileged user with access to the server where the script was executed to recover exposed credentials.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-xpjw-95g4-7q57

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: eeprom: ee1004: limit i2c reads to I2C_SMBUS_BLOCK_MAX Commit effa453168a7 ("i2c: i801: Don't silently correct invalid transfer size") revealed that ee1004_eeprom_read() did not properly limit how many bytes to read at once. In particular, i2c_smbus_read_i2c_block_data_or_emulated() takes the length to read as an u8. If count == 256 after taking into account the offset and page boundary, the cast to u8 overflows. And this is common when user space tries to read the entire EEPROM at once. To fix it, limit each read to I2C_SMBUS_BLOCK_MAX (32) bytes, already the maximum length i2c_smbus_read_i2c_block_data_or_emulated() allows.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xpjq-rwvv-6r33

почти 4 года назад

An information disclosure vulnerability exists in the Thermal Driver, where a missing bounds checking in the thermal driver could allow a read from an arbitrary kernel address. This issue is rated as moderate. Product: Pixel. Versions: N/A. Android ID: A-34702397. References: N-CVE-2017-6275.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xpjq-43c4-m796

9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: rtsn: Fix a null pointer dereference in rtsn_probe() Add check for the return value of rcar_gen4_ptp_alloc() to prevent potential null pointer dereference.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xpjm-p24r-pm4q

почти 4 года назад

Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0951 and CVE-2016-0952.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xpjm-f7mq-g7wr

10 месяцев назад

Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have cleartext storage of code.

CVSS3: 2
EPSS: Низкий
github логотип

GHSA-xpjm-7phh-w9j8

почти 4 года назад

RTI Connext DDS Professional and Connext DDS Secure Versions 4.2.x to 6.1.0 are vulnerable to a stack-based buffer overflow, which may allow a local attacker to execute arbitrary code.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xpjh-vmfm-8qmf

около 1 года назад

An authentication issue was addressed with improved state management. This issue is fixed in Safari 18.2, macOS Sequoia 15.2, watchOS 11.2, iOS 18.2 and iPadOS 18.2. Private Browsing tabs may be accessed without authentication.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xpjh-pqrp-82w9

около 1 года назад

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the Navigator/Index function.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xpjg-jjvj-hqh2

около 4 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JT files. Crafted data in a JT file can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14885.

EPSS: Низкий
github логотип

GHSA-xpjg-7hx7-wgcx

около 2 лет назад

Liferay Portal and Liferay DXP vulnerable to Cross-site Scripting

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-xpjg-4p4f-hgxc

3 месяца назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-xpjf-7q8c-6jfc

почти 4 года назад

WordPress before 3.5.2 allows remote attackers to read arbitrary files via an oEmbed XML provider response containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

EPSS: Низкий
github логотип

GHSA-xpjc-q6jh-h98h

больше 4 лет назад

A Pointer Dereference Vulnerability exists in GPAC 1.0.1 via the Media_IsSelfContained function, which could cause a Denial of Service. .

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xpjc-h3w5-8x3f

почти 4 года назад

Nightfall Personal Diary 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for users-zza21.mdb.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xpm3-hxcq-hjv4

Unspecified vulnerability in the Oracle MapViewer component in Oracle Fusion Middleware 10.1.3.1, 11.1.1.5, and 11.1.1.6 allows remote attackers to affect integrity via unknown vectors related to Install.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xpm3-5wvv-pxfh

A vulnerability classified as critical was found in ywoa up to 2024.07.03. This vulnerability affects the function listNameBySql of the file com/cloudweb/oa/mapper/xml/UserMapper.xml. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2024.07.04 is able to address this issue. It is recommended to upgrade the affected component.

CVSS3: 6.3
0%
Низкий
около 1 года назад
github логотип
GHSA-xpm2-jxrf-prmx

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvar_s function

CVSS3: 7.2
0%
Низкий
почти 4 года назад
github логотип
GHSA-xpm2-f32f-q35f

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_regulated_pure_pursuit_controller.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-xpjw-vcgc-qx6p

A elevation of privilege vulnerability in the Upstream kernel skcipher. Product: Android. Versions: Android kernel. Android ID: A-64386293. References: Upstream kernel.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xpjw-f7rh-9w56

An issue was discovered in EMC ScaleIO 2.0.1.x. In a Linux environment, one of the support scripts saves the credentials of the ScaleIO MDM user who executed the script in clear text in temporary log files. The temporary files may potentially be read by an unprivileged user with access to the server where the script was executed to recover exposed credentials.

CVSS3: 8.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-xpjw-95g4-7q57

In the Linux kernel, the following vulnerability has been resolved: eeprom: ee1004: limit i2c reads to I2C_SMBUS_BLOCK_MAX Commit effa453168a7 ("i2c: i801: Don't silently correct invalid transfer size") revealed that ee1004_eeprom_read() did not properly limit how many bytes to read at once. In particular, i2c_smbus_read_i2c_block_data_or_emulated() takes the length to read as an u8. If count == 256 after taking into account the offset and page boundary, the cast to u8 overflows. And this is common when user space tries to read the entire EEPROM at once. To fix it, limit each read to I2C_SMBUS_BLOCK_MAX (32) bytes, already the maximum length i2c_smbus_read_i2c_block_data_or_emulated() allows.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xpjq-rwvv-6r33

An information disclosure vulnerability exists in the Thermal Driver, where a missing bounds checking in the thermal driver could allow a read from an arbitrary kernel address. This issue is rated as moderate. Product: Pixel. Versions: N/A. Android ID: A-34702397. References: N-CVE-2017-6275.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xpjq-43c4-m796

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: rtsn: Fix a null pointer dereference in rtsn_probe() Add check for the return value of rcar_gen4_ptp_alloc() to prevent potential null pointer dereference.

CVSS3: 5.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-xpjm-p24r-pm4q

Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0951 and CVE-2016-0952.

CVSS3: 9.8
18%
Средний
почти 4 года назад
github логотип
GHSA-xpjm-f7mq-g7wr

Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have cleartext storage of code.

CVSS3: 2
0%
Низкий
10 месяцев назад
github логотип
GHSA-xpjm-7phh-w9j8

RTI Connext DDS Professional and Connext DDS Secure Versions 4.2.x to 6.1.0 are vulnerable to a stack-based buffer overflow, which may allow a local attacker to execute arbitrary code.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xpjh-vmfm-8qmf

An authentication issue was addressed with improved state management. This issue is fixed in Safari 18.2, macOS Sequoia 15.2, watchOS 11.2, iOS 18.2 and iPadOS 18.2. Private Browsing tabs may be accessed without authentication.

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-xpjh-pqrp-82w9

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the Navigator/Index function.

CVSS3: 7.5
1%
Низкий
около 1 года назад
github логотип
GHSA-xpjg-jjvj-hqh2

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JT files. Crafted data in a JT file can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14885.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xpjg-7hx7-wgcx

Liferay Portal and Liferay DXP vulnerable to Cross-site Scripting

CVSS3: 9.6
0%
Низкий
около 2 лет назад
github логотип
GHSA-xpjg-4p4f-hgxc

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

3 месяца назад
github логотип
GHSA-xpjf-7q8c-6jfc

WordPress before 3.5.2 allows remote attackers to read arbitrary files via an oEmbed XML provider response containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xpjc-q6jh-h98h

A Pointer Dereference Vulnerability exists in GPAC 1.0.1 via the Media_IsSelfContained function, which could cause a Denial of Service. .

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xpjc-h3w5-8x3f

Nightfall Personal Diary 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for users-zza21.mdb.

6%
Низкий
почти 4 года назад

Уязвимостей на страницу