Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 326 121

Количество 326 121

github логотип

GHSA-xp42-838x-6m32

около 1 года назад

During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that could lead to an incorrect user privilege level in the VAPIX service account D-Bus API.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xp42-65qj-mvgv

почти 4 года назад

expect before 5.32 searches for its libraries in /var/tmp before other directories, which could allow local users to gain root privileges via a Trojan horse library that is accessed by mkpasswd.

EPSS: Низкий
github логотип

GHSA-xp3x-85w4-72px

почти 4 года назад

Parallel::ForkManager module before 1.0.0 for Perl does not properly handle temporary files.

EPSS: Низкий
github логотип

GHSA-xp3x-5m3g-5cqj

9 месяцев назад

IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to a stack-based buffer overflow in db2fm, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xp3x-24fv-qfpm

почти 4 года назад

The resolver in dnscache in Daniel J. Bernstein djbdns 1.05 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack.

EPSS: Низкий
github логотип

GHSA-xp3w-m47v-rv5p

почти 4 года назад

A certain ActiveX control in NCTWavChunksEditor2.dll 2.6.1.148 in NCTAudioStudio (NCTAudioStudio2) 2.7, as used by Sienzo DMM and probably other products, allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the CreateFile method, a different product than CVE-2007-3400.

EPSS: Средний
github логотип

GHSA-xp3v-xrxh-vpv7

почти 4 года назад

Open redirect vulnerability in GroupSession version 4.7.0 and earlier allows an attacker to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xp3r-qr68-xr3w

около 2 месяцев назад

The Worry Proof Backup plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.2.4 via the backup upload functionality. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload a malicious ZIP archive with path traversal sequences to write arbitrary files anywhere on the server, including executable PHP files. This can lead to remote code execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xp3r-c9h3-vjc7

больше 4 лет назад

Incorrect default permissions in the installer for the Intel(R) oneAPI Rendering Toolkit before version 2021.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

EPSS: Низкий
github логотип

GHSA-xp3r-9wx8-q2mm

больше 3 лет назад

Agent-to-controller security bypass vulnerabilities in Jenkins Compuware Topaz for Total Test Plugin

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xp3q-55jv-wpp2

почти 4 года назад

Dell Inspiron 7352 BIOS versions prior to A12 contain a UEFI BIOS Boot Services overwrite vulnerability. A local attacker with access to system memory may exploit this vulnerability by overwriting the EFI_BOOT_SERVICES structure to execute arbitrary code in System Management Mode (SMM).

EPSS: Низкий
github логотип

GHSA-xp3p-hpx6-m9q4

около 1 года назад

: Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Lexmark International CX, XC, CS, et. Al. (Postscript interpreter modules) allows Resource Injection.This issue affects CX, XC, CS, et. Al.: from 001.001:0 through 081.231, from *.*.P001 through *.*.P233, from *.*.P001 through *.*.P759, from *.*.P001 through *.*.P836.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xp3p-gg4w-cp3f

почти 4 года назад

SQL injection vulnerability in podcast.php in Loudblog before 0.42 allows remote attackers to execute arbitrary SQL commands via the id parameter.

EPSS: Низкий
github логотип

GHSA-xp3m-hmgx-49jg

почти 4 года назад

In Android before 2018-04-05 or earlier security patch level on Qualcomm Small Cell SoC, Snapdragon Mobile, and Snapdragon Wear FSM9055, IPQ4019, IPQ8064, MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, MSM8909W, QCA4531, QCA9980, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 835, and SDX20, information exposure vulnerability when logging debug statement due to %p usage.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xp3h-r7xh-px7p

около 3 лет назад

The framework service handles pendingIntent incorrectly, allowing a malicious application with certain privileges to perform privileged actions.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xp3h-fh9q-xm26

почти 4 года назад

Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xp3h-ccqh-r6p9

почти 4 года назад

Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Print Server). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle One-to-One Fulfillment. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle One-to-One Fulfillment, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle One-to-One Fulfillment accessible data as well as unauthorized update, insert or delete access to some of Oracle One-to-One Fulfillment accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).

EPSS: Низкий
github логотип

GHSA-xp3g-x2j2-g2m4

около 1 месяца назад

An issue in DJI Mavic Mini, Spark, Mavic Air, Mini, Mini SE 0.1.00.0500 and below allows a remote attacker to cause a denial of service via the DJI Enhanced-WiFi transmission subsystem

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xp3g-h23f-cgpc

9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: drop fragments with multicast or broadcast RA IEEE 802.11 fragmentation can only be applied to unicast frames. Therefore, drop fragments with multicast or broadcast RA. This patch addresses vulnerabilities such as CVE-2020-26145.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xp3g-cfwm-4q5h

около 2 месяцев назад

Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'name', in 'a3factura-app.wolterskluwer.es/#/incomes/representatives-management' endpoint, which could allow an attacker to execute arbitrary code in the victim's browser.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xp42-838x-6m32

During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that could lead to an incorrect user privilege level in the VAPIX service account D-Bus API.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-xp42-65qj-mvgv

expect before 5.32 searches for its libraries in /var/tmp before other directories, which could allow local users to gain root privileges via a Trojan horse library that is accessed by mkpasswd.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xp3x-85w4-72px

Parallel::ForkManager module before 1.0.0 for Perl does not properly handle temporary files.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xp3x-5m3g-5cqj

IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to a stack-based buffer overflow in db2fm, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.

CVSS3: 7.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-xp3x-24fv-qfpm

The resolver in dnscache in Daniel J. Bernstein djbdns 1.05 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xp3w-m47v-rv5p

A certain ActiveX control in NCTWavChunksEditor2.dll 2.6.1.148 in NCTAudioStudio (NCTAudioStudio2) 2.7, as used by Sienzo DMM and probably other products, allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the CreateFile method, a different product than CVE-2007-3400.

45%
Средний
почти 4 года назад
github логотип
GHSA-xp3v-xrxh-vpv7

Open redirect vulnerability in GroupSession version 4.7.0 and earlier allows an attacker to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-xp3r-qr68-xr3w

The Worry Proof Backup plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.2.4 via the backup upload functionality. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload a malicious ZIP archive with path traversal sequences to write arbitrary files anywhere on the server, including executable PHP files. This can lead to remote code execution.

CVSS3: 8.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xp3r-c9h3-vjc7

Incorrect default permissions in the installer for the Intel(R) oneAPI Rendering Toolkit before version 2021.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xp3r-9wx8-q2mm

Agent-to-controller security bypass vulnerabilities in Jenkins Compuware Topaz for Total Test Plugin

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xp3q-55jv-wpp2

Dell Inspiron 7352 BIOS versions prior to A12 contain a UEFI BIOS Boot Services overwrite vulnerability. A local attacker with access to system memory may exploit this vulnerability by overwriting the EFI_BOOT_SERVICES structure to execute arbitrary code in System Management Mode (SMM).

0%
Низкий
почти 4 года назад
github логотип
GHSA-xp3p-hpx6-m9q4

: Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Lexmark International CX, XC, CS, et. Al. (Postscript interpreter modules) allows Resource Injection.This issue affects CX, XC, CS, et. Al.: from 001.001:0 through 081.231, from *.*.P001 through *.*.P233, from *.*.P001 through *.*.P759, from *.*.P001 through *.*.P836.

CVSS3: 7.3
0%
Низкий
около 1 года назад
github логотип
GHSA-xp3p-gg4w-cp3f

SQL injection vulnerability in podcast.php in Loudblog before 0.42 allows remote attackers to execute arbitrary SQL commands via the id parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xp3m-hmgx-49jg

In Android before 2018-04-05 or earlier security patch level on Qualcomm Small Cell SoC, Snapdragon Mobile, and Snapdragon Wear FSM9055, IPQ4019, IPQ8064, MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, MSM8909W, QCA4531, QCA9980, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 835, and SDX20, information exposure vulnerability when logging debug statement due to %p usage.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xp3h-r7xh-px7p

The framework service handles pendingIntent incorrectly, allowing a malicious application with certain privileges to perform privileged actions.

CVSS3: 9.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-xp3h-fh9q-xm26

Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 5.5
7%
Низкий
почти 4 года назад
github логотип
GHSA-xp3h-ccqh-r6p9

Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Print Server). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle One-to-One Fulfillment. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle One-to-One Fulfillment, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle One-to-One Fulfillment accessible data as well as unauthorized update, insert or delete access to some of Oracle One-to-One Fulfillment accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).

1%
Низкий
почти 4 года назад
github логотип
GHSA-xp3g-x2j2-g2m4

An issue in DJI Mavic Mini, Spark, Mavic Air, Mini, Mini SE 0.1.00.0500 and below allows a remote attacker to cause a denial of service via the DJI Enhanced-WiFi transmission subsystem

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xp3g-h23f-cgpc

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: drop fragments with multicast or broadcast RA IEEE 802.11 fragmentation can only be applied to unicast frames. Therefore, drop fragments with multicast or broadcast RA. This patch addresses vulnerabilities such as CVE-2020-26145.

CVSS3: 5.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-xp3g-cfwm-4q5h

Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'name', in 'a3factura-app.wolterskluwer.es/#/incomes/representatives-management' endpoint, which could allow an attacker to execute arbitrary code in the victim's browser.

CVSS3: 6.1
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу