Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 373 892

Количество 373 892

github логотип

GHSA-xxf6-r989-348x

больше 4 лет назад

The default configuration of FLEXlm license manager 6.0d, and possibly other versions, allows remote attackers to shut down the server via the lmdown command.

EPSS: Низкий
github логотип

GHSA-xxf6-pvjr-qhj4

2 месяца назад

In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level When recovering hugepages in the shadow MMU, verify that the base gfn of the shadow page is actually contained within the target memslot, *before* querying the max mapping level given the shadow page's gfn. Failure to pre-check the validity of the gfn can lead to an out-of-bounds access to the slot's lpage_info (which typically manifests as a host #PF because the lpage_info is vmalloc'd) if the guest creates a hugepage mapping (in its PTEs) that extends "below" the bounds of a memslot. When faulting in memory for a guest, and the size of the guest mapping is greater than KVM's (current) max mapping, then KVM will create a "direct" shadow page (direct in that there are no gPTEs to shadow, and so the target gfn is a direct calculation given the base gfn of the shadow page). The hugepage recovery flow looks for such direct shadow pages, ...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xxf6-mj48-xcg3

почти 4 года назад

An integer overflow in the VNC module in VideoLAN VLC Media Player through 3.0.17.4 allows attackers, by tricking a user into opening a crafted playlist or connecting to a rogue VNC server, to crash VLC or execute code under some conditions.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xxf6-hq9q-9r8q

больше 4 лет назад

NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.4.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxf6-4hxv-4m3v

больше 3 лет назад

A vulnerability, which was classified as problematic, has been found in MuYuCMS 2.2. This issue affects some unknown processing of the file index.php. The manipulation of the argument file_path leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-221735.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xxf4-wg2g-58ch

почти 3 года назад

An issue was discovered in Zammad before 6.2.0. In several subsystems, SSL/TLS was used to establish connections to external services without proper validation of hostname and certificate authority. This is exploitable by man-in-the-middle attackers.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xxf4-w2wr-j4h9

больше 4 лет назад

The kernel video driver in Android before 2016-07-05 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 28447556.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xxf4-cqmv-x4mh

больше 4 лет назад

A null pointer dereference vulnerability exists in gpac 1.1.0 in the gf_isom_parse_movie_boxes_internal function, which causes a segmentation fault and application crash.

EPSS: Низкий
github логотип

GHSA-xxf4-9wwx-fqpj

больше 4 лет назад

The Alfa-Bank (aka ru.alfabank.mobile.android) application 5.5.1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-xxf3-pv4f-cxx4

больше 2 лет назад

The Team Circle Image Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or incorrect nonce validation on the circle_thumbnail_slider_with_lightbox_image_management_func() function. This makes it possible for unauthenticated attackers to edit image data which can be used to inject malicious JavaScript, along with deleting images, and uploading malicious files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xxf3-jj8v-mccf

больше 4 лет назад

In taocms 3.0.1 after logging in to the background, there is an Arbitrary file download vulnerability at the File Management column.

EPSS: Низкий
github логотип

GHSA-xxf2-xrv7-r2gj

больше 2 лет назад

A vulnerability has been identified in Simcenter Nastran 2306 (All versions), Simcenter Nastran 2312 (All versions), Simcenter Nastran 2406 (All versions < V2406.90). The affected applications contain a stack overflow vulnerability while parsing specially strings as argument for one of the application binaries. This could allow an attacker to execute code in the context of the current process.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xxf2-c69q-g3w9

почти 3 года назад

Client side permission bypass in Devolutions Remote Desktop Manager 2023.3.4.0 and earlier on iOS allows an attacker that has access to the application to execute entries in a SQL data source without restriction.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xxf2-85hh-x424

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the Search Site in CMScout 2.09, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the search parameter. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-xxcx-x7hr-wg4h

больше 4 лет назад

paxtest handles temporary files insecurely

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxcx-v673-pwpr

около 1 месяца назад

A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs. Software customers upgrade to resolved maintenance release. Update Command Center.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xxcx-3jxf-738h

больше 4 лет назад

A privilege escalation vulnerability exists in Dream Report 5 R20-2. In the default configuration, the Syncfusion Dashboard Service service binary can be replaced by attackers to escalate privileges to NT SYSTEM. An attacker can provide a malicious file to trigger this vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xxcr-5qmm-8wfp

больше 1 года назад

This issue was addressed through improved state management. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to access arbitrary files.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xxcq-q4px-9ggw

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: slub/kunit: fix a WARNING due to unwrapped __kmalloc_cache_noprof 'modprobe slub_kunit' will have a warning as shown below. The root cause is that __kmalloc_cache_noprof was directly used, which resulted in no alloc_tag being allocated. This caused current->alloc_tag to be null, leading to a warning in alloc_tag_add_check. Let's add an alloc_hook layer to __kmalloc_cache_noprof specifically within lib/slub_kunit.c, which is the only user of this internal slub function outside kmalloc implementation itself. [58162.947016] WARNING: CPU: 2 PID: 6210 at ./include/linux/alloc_tag.h:125 alloc_tagging_slab_alloc_hook+0x268/0x27c [58162.957721] Call trace: [58162.957919] alloc_tagging_slab_alloc_hook+0x268/0x27c [58162.958286] __kmalloc_cache_noprof+0x14c/0x344 [58162.958615] test_kmalloc_redzone_access+0x50/0x10c [slub_kunit] [58162.959045] kunit_try_run_case+0x74/0x184 [kunit] [58162.959401] kunit_generic_run_thr...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxcq-phq6-gfr3

больше 3 лет назад

In messaging service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xxf6-r989-348x

The default configuration of FLEXlm license manager 6.0d, and possibly other versions, allows remote attackers to shut down the server via the lmdown command.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xxf6-pvjr-qhj4

In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level When recovering hugepages in the shadow MMU, verify that the base gfn of the shadow page is actually contained within the target memslot, *before* querying the max mapping level given the shadow page's gfn. Failure to pre-check the validity of the gfn can lead to an out-of-bounds access to the slot's lpage_info (which typically manifests as a host #PF because the lpage_info is vmalloc'd) if the guest creates a hugepage mapping (in its PTEs) that extends "below" the bounds of a memslot. When faulting in memory for a guest, and the size of the guest mapping is greater than KVM's (current) max mapping, then KVM will create a "direct" shadow page (direct in that there are no gPTEs to shadow, and so the target gfn is a direct calculation given the base gfn of the shadow page). The hugepage recovery flow looks for such direct shadow pages, ...

CVSS3: 8.8
0%
Низкий
2 месяца назад
github логотип
GHSA-xxf6-mj48-xcg3

An integer overflow in the VNC module in VideoLAN VLC Media Player through 3.0.17.4 allows attackers, by tricking a user into opening a crafted playlist or connecting to a rogue VNC server, to crash VLC or execute code under some conditions.

CVSS3: 7.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-xxf6-hq9q-9r8q

NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.4.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xxf6-4hxv-4m3v

A vulnerability, which was classified as problematic, has been found in MuYuCMS 2.2. This issue affects some unknown processing of the file index.php. The manipulation of the argument file_path leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-221735.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xxf4-wg2g-58ch

An issue was discovered in Zammad before 6.2.0. In several subsystems, SSL/TLS was used to establish connections to external services without proper validation of hostname and certificate authority. This is exploitable by man-in-the-middle attackers.

CVSS3: 5.9
0%
Низкий
почти 3 года назад
github логотип
GHSA-xxf4-w2wr-j4h9

The kernel video driver in Android before 2016-07-05 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 28447556.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xxf4-cqmv-x4mh

A null pointer dereference vulnerability exists in gpac 1.1.0 in the gf_isom_parse_movie_boxes_internal function, which causes a segmentation fault and application crash.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xxf4-9wwx-fqpj

The Alfa-Bank (aka ru.alfabank.mobile.android) application 5.5.1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xxf3-pv4f-cxx4

The Team Circle Image Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or incorrect nonce validation on the circle_thumbnail_slider_with_lightbox_image_management_func() function. This makes it possible for unauthenticated attackers to edit image data which can be used to inject malicious JavaScript, along with deleting images, and uploading malicious files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xxf3-jj8v-mccf

In taocms 3.0.1 after logging in to the background, there is an Arbitrary file download vulnerability at the File Management column.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xxf2-xrv7-r2gj

A vulnerability has been identified in Simcenter Nastran 2306 (All versions), Simcenter Nastran 2312 (All versions), Simcenter Nastran 2406 (All versions < V2406.90). The affected applications contain a stack overflow vulnerability while parsing specially strings as argument for one of the application binaries. This could allow an attacker to execute code in the context of the current process.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xxf2-c69q-g3w9

Client side permission bypass in Devolutions Remote Desktop Manager 2023.3.4.0 and earlier on iOS allows an attacker that has access to the application to execute entries in a SQL data source without restriction.

CVSS3: 9.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-xxf2-85hh-x424

Cross-site scripting (XSS) vulnerability in the Search Site in CMScout 2.09, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the search parameter. NOTE: some of these details are obtained from third party information.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xxcx-x7hr-wg4h

paxtest handles temporary files insecurely

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xxcx-v673-pwpr

A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs. Software customers upgrade to resolved maintenance release. Update Command Center.

CVSS3: 9.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xxcx-3jxf-738h

A privilege escalation vulnerability exists in Dream Report 5 R20-2. In the default configuration, the Syncfusion Dashboard Service service binary can be replaced by attackers to escalate privileges to NT SYSTEM. An attacker can provide a malicious file to trigger this vulnerability.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xxcr-5qmm-8wfp

This issue was addressed through improved state management. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to access arbitrary files.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-xxcq-q4px-9ggw

In the Linux kernel, the following vulnerability has been resolved: slub/kunit: fix a WARNING due to unwrapped __kmalloc_cache_noprof 'modprobe slub_kunit' will have a warning as shown below. The root cause is that __kmalloc_cache_noprof was directly used, which resulted in no alloc_tag being allocated. This caused current->alloc_tag to be null, leading to a warning in alloc_tag_add_check. Let's add an alloc_hook layer to __kmalloc_cache_noprof specifically within lib/slub_kunit.c, which is the only user of this internal slub function outside kmalloc implementation itself. [58162.947016] WARNING: CPU: 2 PID: 6210 at ./include/linux/alloc_tag.h:125 alloc_tagging_slab_alloc_hook+0x268/0x27c [58162.957721] Call trace: [58162.957919] alloc_tagging_slab_alloc_hook+0x268/0x27c [58162.958286] __kmalloc_cache_noprof+0x14c/0x344 [58162.958615] test_kmalloc_redzone_access+0x50/0x10c [slub_kunit] [58162.959045] kunit_try_run_case+0x74/0x184 [kunit] [58162.959401] kunit_generic_run_thr...

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-xxcq-phq6-gfr3

In messaging service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу