Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 326 109

Количество 326 109

github логотип

GHSA-xpcp-ch6h-733h

почти 4 года назад

Buffer overflow in Change passwd 3.1 (chpasswd) SquirrelMail plugin allows local users to execute arbitrary code via long command line arguments.

EPSS: Низкий
github логотип

GHSA-xpcp-c53g-wp4q

почти 4 года назад

Buffer overflow in the vorbis_stream_info function in input/vorbis/vorbis_engine.c (aka the vorbis input plugin) in AlsaPlayer before 0.99.80-rc3 allows remote attackers to execute arbitrary code via a .OGG file with long comments.

EPSS: Средний
github логотип

GHSA-xpcp-7r7v-4mfm

3 месяца назад

An allocation of resources without limits or throttling vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the vulnerability in the following versions: QTS 5.2.6.3195 build 20250715 and later QuTS hero h5.2.6.3195 build 20250715 and later

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xpcm-qv2j-fxfr

почти 4 года назад

FreeBSD kernel 4.6 and earlier closes the file descriptors 0, 1, and 2 after they have already been assigned to /dev/null when the descriptors reference procfs or linprocfs, which could allow local users to reuse the file descriptors in a setuid or setgid program to modify critical data and gain privileges.

EPSS: Низкий
github логотип

GHSA-xpcm-7rjr-9h29

почти 4 года назад

A command injection vulnerability in Avaya Session Border Controller for Enterprise could allow an authenticated, remote attacker to send specially crafted messages and execute arbitrary commands with the affected system privileges. Affected versions of Avaya Session Border Controller for Enterprise include 7.x, 8.0 through 8.1.1.x

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xpcm-5q5j-h76x

почти 4 года назад

The x86 emulator in KVM 83, when a guest is configured for Symmetric Multiprocessing (SMP), does not use the Current Privilege Level (CPL) and I/O Privilege Level (IOPL) to restrict instruction execution, which allows guest OS users to cause a denial of service (guest OS crash) or gain privileges on the guest OS by leveraging access to a (1) IO port or (2) MMIO region, and replacing an instruction in between emulator entry and instruction fetch, a related issue to CVE-2010-0298.

EPSS: Низкий
github логотип

GHSA-xpch-qhw2-xgh6

около 1 года назад

A vulnerability classified as critical has been found in Tenda AC15 15.13.07.13. This affects the function formSetDevNetName of the file /goform/SetDevNetName. The manipulation of the argument mac leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-xpch-hm7m-8vm4

почти 3 года назад

NTFS Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xpch-9h27-3hpf

около 1 года назад

An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiOS versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, versions 7.0.0 through 7.0.15, and versions 6.4.0 through 6.4.15 may allow an unauthenticated remote user to consume all system memory via multiple large file uploads.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xpcg-rh9r-mm78

7 месяцев назад

A vulnerability was identified in fuyang_lipengjun platform 1.0.0. This issue affects the function AdController of the file /ad/queryAll. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xpcg-cr9r-gv9r

почти 3 года назад

Improper input validation in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable information disclosure via local access.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xpcf-pg52-r92g

4 дня назад

Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addresses

EPSS: Низкий
github логотип

GHSA-xpcf-78h5-6vc8

почти 4 года назад

The Sunday Indian Oriya (aka com.magzter.thesundayindianoriya) application 3.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-xpcc-f29m-w2xx

больше 1 года назад

Windows Storage Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xpcc-cjr7-mgvm

почти 4 года назад

Improper access control in the subsystem for Intel(R) Smart Sound Technology may allow an authenticated user to potentially enable escalation of privilege via local access. This affects Intel® Smart Sound Technology before versions: 10th Generation Intel® Core™ i7 Processors, version 3431 and 8th Generation Intel® Core™ Processors, version 3349.

EPSS: Низкий
github логотип

GHSA-xpcc-5cmh-qxxp

больше 1 года назад

Dell iDRAC Service Module version 5.3.0.0 and prior, contain an Out of bound Read Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xpc9-45pr-rh5m

около 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Quantum Cloud Slider Hero allows Stored XSS.This issue affects Slider Hero: from n/a through 8.6.1.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xpc8-wjfc-3cf6

почти 2 года назад

The WP Stacker WordPress plugin through 1.8.5 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xpc8-q78m-cqrv

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in Calendarix 0.7.20070307, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) year and (2) month parameters to calendar.php, and the (3) leftfooter parameter to cal_footer.inc.php. NOTE: the ycyear parameter to yearcal.php is already covered by CVE-2006-1835.

EPSS: Средний
github логотип

GHSA-xpc7-m273-pggq

почти 4 года назад

Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrator session when the guest user enters the administrator username, with an arbitrary incorrect password, in an mc/ login attempt within a different browser tab.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xpcp-ch6h-733h

Buffer overflow in Change passwd 3.1 (chpasswd) SquirrelMail plugin allows local users to execute arbitrary code via long command line arguments.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xpcp-c53g-wp4q

Buffer overflow in the vorbis_stream_info function in input/vorbis/vorbis_engine.c (aka the vorbis input plugin) in AlsaPlayer before 0.99.80-rc3 allows remote attackers to execute arbitrary code via a .OGG file with long comments.

43%
Средний
почти 4 года назад
github логотип
GHSA-xpcp-7r7v-4mfm

An allocation of resources without limits or throttling vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the vulnerability in the following versions: QTS 5.2.6.3195 build 20250715 and later QuTS hero h5.2.6.3195 build 20250715 and later

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-xpcm-qv2j-fxfr

FreeBSD kernel 4.6 and earlier closes the file descriptors 0, 1, and 2 after they have already been assigned to /dev/null when the descriptors reference procfs or linprocfs, which could allow local users to reuse the file descriptors in a setuid or setgid program to modify critical data and gain privileges.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xpcm-7rjr-9h29

A command injection vulnerability in Avaya Session Border Controller for Enterprise could allow an authenticated, remote attacker to send specially crafted messages and execute arbitrary commands with the affected system privileges. Affected versions of Avaya Session Border Controller for Enterprise include 7.x, 8.0 through 8.1.1.x

CVSS3: 8.8
3%
Низкий
почти 4 года назад
github логотип
GHSA-xpcm-5q5j-h76x

The x86 emulator in KVM 83, when a guest is configured for Symmetric Multiprocessing (SMP), does not use the Current Privilege Level (CPL) and I/O Privilege Level (IOPL) to restrict instruction execution, which allows guest OS users to cause a denial of service (guest OS crash) or gain privileges on the guest OS by leveraging access to a (1) IO port or (2) MMIO region, and replacing an instruction in between emulator entry and instruction fetch, a related issue to CVE-2010-0298.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xpch-qhw2-xgh6

A vulnerability classified as critical has been found in Tenda AC15 15.13.07.13. This affects the function formSetDevNetName of the file /goform/SetDevNetName. The manipulation of the argument mac leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
10%
Средний
около 1 года назад
github логотип
GHSA-xpch-hm7m-8vm4

NTFS Elevation of Privilege Vulnerability

CVSS3: 7.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-xpch-9h27-3hpf

An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiOS versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, versions 7.0.0 through 7.0.15, and versions 6.4.0 through 6.4.15 may allow an unauthenticated remote user to consume all system memory via multiple large file uploads.

CVSS3: 7.5
2%
Низкий
около 1 года назад
github логотип
GHSA-xpcg-rh9r-mm78

A vulnerability was identified in fuyang_lipengjun platform 1.0.0. This issue affects the function AdController of the file /ad/queryAll. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.

CVSS3: 4.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-xpcg-cr9r-gv9r

Improper input validation in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable information disclosure via local access.

CVSS3: 6.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-xpcf-pg52-r92g

Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addresses

0%
Низкий
4 дня назад
github логотип
GHSA-xpcf-78h5-6vc8

The Sunday Indian Oriya (aka com.magzter.thesundayindianoriya) application 3.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xpcc-f29m-w2xx

Windows Storage Elevation of Privilege Vulnerability

CVSS3: 7.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-xpcc-cjr7-mgvm

Improper access control in the subsystem for Intel(R) Smart Sound Technology may allow an authenticated user to potentially enable escalation of privilege via local access. This affects Intel® Smart Sound Technology before versions: 10th Generation Intel® Core™ i7 Processors, version 3431 and 8th Generation Intel® Core™ Processors, version 3349.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xpcc-5cmh-qxxp

Dell iDRAC Service Module version 5.3.0.0 and prior, contain an Out of bound Read Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event.

CVSS3: 4.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-xpc9-45pr-rh5m

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Quantum Cloud Slider Hero allows Stored XSS.This issue affects Slider Hero: from n/a through 8.6.1.

CVSS3: 5.9
0%
Низкий
около 2 лет назад
github логотип
GHSA-xpc8-wjfc-3cf6

The WP Stacker WordPress plugin through 1.8.5 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVSS3: 5.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-xpc8-q78m-cqrv

Multiple cross-site scripting (XSS) vulnerabilities in Calendarix 0.7.20070307, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) year and (2) month parameters to calendar.php, and the (3) leftfooter parameter to cal_footer.inc.php. NOTE: the ycyear parameter to yearcal.php is already covered by CVE-2006-1835.

11%
Средний
почти 4 года назад
github логотип
GHSA-xpc7-m273-pggq

Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrator session when the guest user enters the administrator username, with an arbitrary incorrect password, in an mc/ login attempt within a different browser tab.

CVSS3: 8.8
9%
Низкий
почти 4 года назад

Уязвимостей на страницу