Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 714

Количество 353 714

github логотип

GHSA-xxfq-8cc9-rwx9

около 2 лет назад

Inappropriate implementation in Skia in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-xxfp-pgx8-h38x

около 4 лет назад

Vulnerability in Fidelis Network and Deception CommandPost enables SQL injection through the web interface by an attacker with user level access. The vulnerability is present in Fidelis Network and Deception versions prior to 9.4.5. Patches and updates are available to address this vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xxfm-x6r9-cf2j

больше 4 лет назад

Buffer overflow in mIRC 6.0.2 and earlier allows remote attackers to execute arbitrary code via a long $asctime value.

EPSS: Средний
github логотип

GHSA-xxfm-vmcf-g33f

около 2 лет назад

Improper Handling of Insufficient Permissions in `wagtail.contrib.settings`

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxfm-q6cq-gcwc

больше 4 лет назад

Buffer overflow in O'Reilly WebSite Professional web server 2.4 and earlier allows remote attackers to execute arbitrary commands via a long GET request or Referrer header.

EPSS: Низкий
github логотип

GHSA-xxfj-rx7f-qq9c

10 месяцев назад

A vulnerability was identified in Campcodes Society Membership Information System 1.0. This issue affects some unknown processing of the file /check_student.php. Such manipulation of the argument student_id leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xxfj-h999-8mjj

около 4 лет назад

In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxfh-x98p-j8fr

больше 4 лет назад

Remote code injection in Log4j (through pax-logging-log4j2)

EPSS: Низкий
github логотип

GHSA-xxfh-4hh8-prf8

около 4 лет назад

The Web Proxy Auto Discovery (WPAD) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mishandles proxy discovery, which allows remote attackers to redirect network traffic via unspecified vectors, aka "Windows WPAD Proxy Discovery Elevation of Privilege Vulnerability."

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-xxfg-vcwf-78fg

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add NULL check for 'afb' before dereferencing in amdgpu_dm_plane_handle_cursor_update This commit adds a null check for the 'afb' variable in the amdgpu_dm_plane_handle_cursor_update function. Previously, 'afb' was assumed to be null, but was used later in the code without a null check. This could potentially lead to a null pointer dereference. Fixes the below: drivers/gpu/drm/amd/amdgpu/../display/amdgpu_dm/amdgpu_dm_plane.c:1298 amdgpu_dm_plane_handle_cursor_update() error: we previously assumed 'afb' could be null (see line 1252)

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxfg-v7qr-vxwh

больше 4 лет назад

Heap-based buffer overflow in the demux_open_bmp function in demux_bmp.c for Unix MPlayer 1.0pre5 allows remote attackers to execute arbitrary code via a bitmap (BMP) file containing a large biClrUsed field.

EPSS: Низкий
github логотип

GHSA-xxfg-pm66-vc8j

больше 3 лет назад

Pi-Star_DV_Dash (for Pi-Star DV) before 5aa194d mishandles the module parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xxfg-fm6v-83pq

около 4 лет назад

Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/ProcessingInstruction.cpp in the DOM implementation in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

EPSS: Низкий
github логотип

GHSA-xxfg-35q3-39r8

больше 4 лет назад

Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formSetFirewallCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via the firewallEn parameter.

EPSS: Низкий
github логотип

GHSA-xxff-6r9x-wwjh

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Casey Johnson Loan Calculator allows Stored XSS. This issue affects Loan Calculator: from n/a through 1.3.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xxfc-3cx8-mjp2

больше 4 лет назад

SQL injection vulnerability in index.php in vwdev allows remote attackers to execute arbitrary SQL commands via the UID parameter in the definition Page.

EPSS: Низкий
github логотип

GHSA-xxf9-rgcc-942c

больше 4 лет назад

prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prevents the variables (1) $l_statsblock in prefs.php or (2) $l_privnotify in auth.php from being properly initialized, which can be modified by the user and later used in an eval statement.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xxf9-g9h4-3pmj

больше 4 лет назад

Directory traversal vulnerability in region.php in KML share 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the layer parameter.

EPSS: Низкий
github логотип

GHSA-xxf9-fpw2-6hgc

11 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: ppp: fix race conditions in ppp_fill_forward_path ppp_fill_forward_path() has two race conditions: 1. The ppp->channels list can change between list_empty() and list_first_entry(), as ppp_lock() is not held. If the only channel is deleted in ppp_disconnect_channel(), list_first_entry() may access an empty head or a freed entry, and trigger a panic. 2. pch->chan can be NULL. When ppp_unregister_channel() is called, pch->chan is set to NULL before pch is removed from ppp->channels. Fix these by using a lockless RCU approach: - Use list_first_or_null_rcu() to safely test and access the first list entry. - Convert list modifications on ppp->channels to their RCU variants and add synchronize_net() after removal. - Check for a NULL pch->chan before dereferencing it.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-xxf9-f548-r28c

больше 4 лет назад

Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allow remote attackers to execute arbitrary code via certain WAV file header fields.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xxfq-8cc9-rwx9

Inappropriate implementation in Skia in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS3: 9.6
0%
Низкий
около 2 лет назад
github логотип
GHSA-xxfp-pgx8-h38x

Vulnerability in Fidelis Network and Deception CommandPost enables SQL injection through the web interface by an attacker with user level access. The vulnerability is present in Fidelis Network and Deception versions prior to 9.4.5. Patches and updates are available to address this vulnerability.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xxfm-x6r9-cf2j

Buffer overflow in mIRC 6.0.2 and earlier allows remote attackers to execute arbitrary code via a long $asctime value.

12%
Средний
больше 4 лет назад
github логотип
GHSA-xxfm-vmcf-g33f

Improper Handling of Insufficient Permissions in `wagtail.contrib.settings`

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-xxfm-q6cq-gcwc

Buffer overflow in O'Reilly WebSite Professional web server 2.4 and earlier allows remote attackers to execute arbitrary commands via a long GET request or Referrer header.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-xxfj-rx7f-qq9c

A vulnerability was identified in Campcodes Society Membership Information System 1.0. This issue affects some unknown processing of the file /check_student.php. Such manipulation of the argument student_id leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.

CVSS3: 6.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-xxfj-h999-8mjj

In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server.

CVSS3: 7.5
4%
Низкий
около 4 лет назад
github логотип
GHSA-xxfh-x98p-j8fr

Remote code injection in Log4j (through pax-logging-log4j2)

больше 4 лет назад
github логотип
GHSA-xxfh-4hh8-prf8

The Web Proxy Auto Discovery (WPAD) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mishandles proxy discovery, which allows remote attackers to redirect network traffic via unspecified vectors, aka "Windows WPAD Proxy Discovery Elevation of Privilege Vulnerability."

CVSS3: 9.8
78%
Высокий
около 4 лет назад
github логотип
GHSA-xxfg-vcwf-78fg

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add NULL check for 'afb' before dereferencing in amdgpu_dm_plane_handle_cursor_update This commit adds a null check for the 'afb' variable in the amdgpu_dm_plane_handle_cursor_update function. Previously, 'afb' was assumed to be null, but was used later in the code without a null check. This could potentially lead to a null pointer dereference. Fixes the below: drivers/gpu/drm/amd/amdgpu/../display/amdgpu_dm/amdgpu_dm_plane.c:1298 amdgpu_dm_plane_handle_cursor_update() error: we previously assumed 'afb' could be null (see line 1252)

CVSS3: 5.5
почти 2 года назад
github логотип
GHSA-xxfg-v7qr-vxwh

Heap-based buffer overflow in the demux_open_bmp function in demux_bmp.c for Unix MPlayer 1.0pre5 allows remote attackers to execute arbitrary code via a bitmap (BMP) file containing a large biClrUsed field.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-xxfg-pm66-vc8j

Pi-Star_DV_Dash (for Pi-Star DV) before 5aa194d mishandles the module parameter.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xxfg-fm6v-83pq

Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/ProcessingInstruction.cpp in the DOM implementation in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xxfg-35q3-39r8

Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formSetFirewallCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via the firewallEn parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xxff-6r9x-wwjh

Cross-Site Request Forgery (CSRF) vulnerability in Casey Johnson Loan Calculator allows Stored XSS. This issue affects Loan Calculator: from n/a through 1.3.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-xxfc-3cx8-mjp2

SQL injection vulnerability in index.php in vwdev allows remote attackers to execute arbitrary SQL commands via the UID parameter in the definition Page.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xxf9-rgcc-942c

prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid language value, which prevents the variables (1) $l_statsblock in prefs.php or (2) $l_privnotify in auth.php from being properly initialized, which can be modified by the user and later used in an eval statement.

CVSS3: 8.8
8%
Низкий
больше 4 лет назад
github логотип
GHSA-xxf9-g9h4-3pmj

Directory traversal vulnerability in region.php in KML share 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the layer parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xxf9-fpw2-6hgc

In the Linux kernel, the following vulnerability has been resolved: ppp: fix race conditions in ppp_fill_forward_path ppp_fill_forward_path() has two race conditions: 1. The ppp->channels list can change between list_empty() and list_first_entry(), as ppp_lock() is not held. If the only channel is deleted in ppp_disconnect_channel(), list_first_entry() may access an empty head or a freed entry, and trigger a panic. 2. pch->chan can be NULL. When ppp_unregister_channel() is called, pch->chan is set to NULL before pch is removed from ppp->channels. Fix these by using a lockless RCU approach: - Use list_first_or_null_rcu() to safely test and access the first list entry. - Convert list modifications on ppp->channels to their RCU variants and add synchronize_net() after removal. - Check for a NULL pch->chan before dereferencing it.

CVSS3: 4.7
0%
Низкий
11 месяцев назад
github логотип
GHSA-xxf9-f548-r28c

Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allow remote attackers to execute arbitrary code via certain WAV file header fields.

25%
Средний
больше 4 лет назад

Уязвимостей на страницу