Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 356 366

Количество 356 366

github логотип

GHSA-xpjw-95g4-7q57

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: eeprom: ee1004: limit i2c reads to I2C_SMBUS_BLOCK_MAX Commit effa453168a7 ("i2c: i801: Don't silently correct invalid transfer size") revealed that ee1004_eeprom_read() did not properly limit how many bytes to read at once. In particular, i2c_smbus_read_i2c_block_data_or_emulated() takes the length to read as an u8. If count == 256 after taking into account the offset and page boundary, the cast to u8 overflows. And this is common when user space tries to read the entire EEPROM at once. To fix it, limit each read to I2C_SMBUS_BLOCK_MAX (32) bytes, already the maximum length i2c_smbus_read_i2c_block_data_or_emulated() allows.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xpjq-rwvv-6r33

около 4 лет назад

An information disclosure vulnerability exists in the Thermal Driver, where a missing bounds checking in the thermal driver could allow a read from an arbitrary kernel address. This issue is rated as moderate. Product: Pixel. Versions: N/A. Android ID: A-34702397. References: N-CVE-2017-6275.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xpjq-43c4-m796

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: rtsn: Fix a null pointer dereference in rtsn_probe() Add check for the return value of rcar_gen4_ptp_alloc() to prevent potential null pointer dereference.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xpjm-p24r-pm4q

около 4 лет назад

Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0951 and CVE-2016-0952.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xpjm-f7mq-g7wr

около 1 года назад

Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have cleartext storage of code.

CVSS3: 2
EPSS: Низкий
github логотип

GHSA-xpjm-7phh-w9j8

больше 4 лет назад

RTI Connext DDS Professional and Connext DDS Secure Versions 4.2.x to 6.1.0 are vulnerable to a stack-based buffer overflow, which may allow a local attacker to execute arbitrary code.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xpjj-rh44-8gf9

около 13 часов назад

SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a specially crafted spreadsheet file containing malicious external references. When the file is processed as a data source, the affected component resolves these references and exposes the contents of sensitive server-side files within the resulting report. This results in a high impact on confidentiality, with no impact on integrity and availability.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xpjh-vmfm-8qmf

больше 1 года назад

An authentication issue was addressed with improved state management. This issue is fixed in Safari 18.2, macOS Sequoia 15.2, watchOS 11.2, iOS 18.2 and iPadOS 18.2. Private Browsing tabs may be accessed without authentication.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xpjh-pqrp-82w9

больше 1 года назад

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the Navigator/Index function.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xpjh-7q9g-cgj5

около 2 месяцев назад

A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an out-of-bounds heap read of approximately 40,728 bytes when computing a layer context array index. An attacker who can influence SVC encoder parameters in a network-facing service could exploit this for information disclosure (heap content leak) or denial of service (segmentation fault from hitting unmapped memory).

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xpjg-jjvj-hqh2

больше 4 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JT files. Crafted data in a JT file can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14885.

EPSS: Низкий
github логотип

GHSA-xpjg-7hx7-wgcx

больше 2 лет назад

Liferay Portal and Liferay DXP vulnerable to Cross-site Scripting

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-xpjg-4p4f-hgxc

7 месяцев назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-xpjf-7q8c-6jfc

около 4 лет назад

WordPress before 3.5.2 allows remote attackers to read arbitrary files via an oEmbed XML provider response containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

EPSS: Низкий
github логотип

GHSA-xpjc-q6jh-h98h

больше 4 лет назад

A Pointer Dereference Vulnerability exists in GPAC 1.0.1 via the Media_IsSelfContained function, which could cause a Denial of Service. .

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xpjc-h3w5-8x3f

около 4 лет назад

Nightfall Personal Diary 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for users-zza21.mdb.

EPSS: Низкий
github логотип

GHSA-xpjc-cq5g-ggfp

больше 4 лет назад

Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 does not properly protect the install directory, which might allow local users to gain privileges by replacing an application component with a Trojan horse.

EPSS: Низкий
github логотип

GHSA-xpj9-xffp-cqj7

около 4 лет назад

Improper Neutralization of Formula Elements in a CSV File in GitHub repository kromitgmbh/titra prior to 0.77.0.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-xpj9-9pj3-2qjv

больше 2 лет назад

PDF-XChange Editor JPG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JPG files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-19948.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xpj8-v2g3-x4r2

2 месяца назад

A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V4.0). The affected applications stores sensitive information in the browser cache when an authenticated user modify specific configurations. This could allow an authenticated attacker to access sensitive data stored in the browser.

CVSS3: 5.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xpjw-95g4-7q57

In the Linux kernel, the following vulnerability has been resolved: eeprom: ee1004: limit i2c reads to I2C_SMBUS_BLOCK_MAX Commit effa453168a7 ("i2c: i801: Don't silently correct invalid transfer size") revealed that ee1004_eeprom_read() did not properly limit how many bytes to read at once. In particular, i2c_smbus_read_i2c_block_data_or_emulated() takes the length to read as an u8. If count == 256 after taking into account the offset and page boundary, the cast to u8 overflows. And this is common when user space tries to read the entire EEPROM at once. To fix it, limit each read to I2C_SMBUS_BLOCK_MAX (32) bytes, already the maximum length i2c_smbus_read_i2c_block_data_or_emulated() allows.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-xpjq-rwvv-6r33

An information disclosure vulnerability exists in the Thermal Driver, where a missing bounds checking in the thermal driver could allow a read from an arbitrary kernel address. This issue is rated as moderate. Product: Pixel. Versions: N/A. Android ID: A-34702397. References: N-CVE-2017-6275.

CVSS3: 7.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-xpjq-43c4-m796

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: rtsn: Fix a null pointer dereference in rtsn_probe() Add check for the return value of rcar_gen4_ptp_alloc() to prevent potential null pointer dereference.

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-xpjm-p24r-pm4q

Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0951 and CVE-2016-0952.

CVSS3: 9.8
21%
Средний
около 4 лет назад
github логотип
GHSA-xpjm-f7mq-g7wr

Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have cleartext storage of code.

CVSS3: 2
0%
Низкий
около 1 года назад
github логотип
GHSA-xpjm-7phh-w9j8

RTI Connext DDS Professional and Connext DDS Secure Versions 4.2.x to 6.1.0 are vulnerable to a stack-based buffer overflow, which may allow a local attacker to execute arbitrary code.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xpjj-rh44-8gf9

SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a specially crafted spreadsheet file containing malicious external references. When the file is processed as a data source, the affected component resolves these references and exposes the contents of sensitive server-side files within the resulting report. This results in a high impact on confidentiality, with no impact on integrity and availability.

CVSS3: 6.5
около 13 часов назад
github логотип
GHSA-xpjh-vmfm-8qmf

An authentication issue was addressed with improved state management. This issue is fixed in Safari 18.2, macOS Sequoia 15.2, watchOS 11.2, iOS 18.2 and iPadOS 18.2. Private Browsing tabs may be accessed without authentication.

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-xpjh-pqrp-82w9

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the Navigator/Index function.

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-xpjh-7q9g-cgj5

A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an out-of-bounds heap read of approximately 40,728 bytes when computing a layer context array index. An attacker who can influence SVC encoder parameters in a network-facing service could exploit this for information disclosure (heap content leak) or denial of service (segmentation fault from hitting unmapped memory).

CVSS3: 7.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xpjg-jjvj-hqh2

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JT files. Crafted data in a JT file can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14885.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xpjg-7hx7-wgcx

Liferay Portal and Liferay DXP vulnerable to Cross-site Scripting

CVSS3: 9.6
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xpjg-4p4f-hgxc

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

7 месяцев назад
github логотип
GHSA-xpjf-7q8c-6jfc

WordPress before 3.5.2 allows remote attackers to read arbitrary files via an oEmbed XML provider response containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xpjc-q6jh-h98h

A Pointer Dereference Vulnerability exists in GPAC 1.0.1 via the Media_IsSelfContained function, which could cause a Denial of Service. .

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xpjc-h3w5-8x3f

Nightfall Personal Diary 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for users-zza21.mdb.

3%
Низкий
около 4 лет назад
github логотип
GHSA-xpjc-cq5g-ggfp

Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 does not properly protect the install directory, which might allow local users to gain privileges by replacing an application component with a Trojan horse.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xpj9-xffp-cqj7

Improper Neutralization of Formula Elements in a CSV File in GitHub repository kromitgmbh/titra prior to 0.77.0.

CVSS3: 8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xpj9-9pj3-2qjv

PDF-XChange Editor JPG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JPG files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-19948.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xpj8-v2g3-x4r2

A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V4.0). The affected applications stores sensitive information in the browser cache when an authenticated user modify specific configurations. This could allow an authenticated attacker to access sensitive data stored in the browser.

CVSS3: 5.7
0%
Низкий
2 месяца назад

Уязвимостей на страницу