Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 289 529

Количество 289 529

github логотип

GHSA-xx4c-jj58-r7x6

больше 3 лет назад

Inefficient Regular Expression Complexity in Validator.js

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xx49-hmrj-2wm5

почти 3 года назад

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, watchOS 9, macOS Monterey 12.6, tvOS 16. An app may be able to execute arbitrary code with kernel privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xx49-8f9w-5r74

больше 3 лет назад

Files created from interactive shell sessions in Cobalt RaQ microservers (e.g. .bash_history) are world readable, and thus are accessible from the web server.

EPSS: Низкий
github логотип

GHSA-xx49-72mm-f757

больше 3 лет назад

Windows NT 4.0 beta allows users to read and delete shares.

EPSS: Средний
github логотип

GHSA-xx48-fp29-wh9j

около 3 лет назад

In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-147882143References: M-ALPS04356754

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xx47-qq34-9xqq

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to insert arbitrary web script via the file parameter.

EPSS: Низкий
github логотип

GHSA-xx46-fhm6-qw2q

больше 3 лет назад

Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 3.2.24, 4.0.26, 4.1.34, 4.2.26, and 4.3.14 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-2487.

EPSS: Низкий
github логотип

GHSA-xx46-cq25-6hgf

около 3 лет назад

An issue was discovered in the Infosysta "In-App & Desktop Notifications" app before 1.6.14_J8 for Jira. It is possible to obtain a list of all Jira projects without authentication/authorization via the plugins/servlet/nfj/ProjectFilter?searchQuery= URI.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xx45-rh3m-ccvq

больше 3 лет назад

Buffer overflow in libstagefright in Mozilla Firefox before 36.0 allows remote attackers to execute arbitrary code via a crafted MP4 video that is improperly handled during playback.

EPSS: Низкий
github логотип

GHSA-xx45-f7pv-xj5x

больше 3 лет назад

SQL injection vulnerability in sign_in.aspx in Message Board / Threaded Discussion Forum Application Template allows remote attackers to execute arbitrary SQL commands via the Password parameter.

EPSS: Низкий
github логотип

GHSA-xx44-m54v-4pwc

около 3 лет назад

An exploitable local privilege elevation vulnerability exists in the file system permissions of Sytech XL Reporter v14.0.1 install directory. Depending on the vector chosen, an attacker can overwrite service executables and execute arbitrary code with privileges of user set to run the service or replace other files within the installation folder, which would allow for local privilege escalation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xx44-254w-m8vr

больше 3 лет назад

A malicious or compromised UApp or ABL may be used by an attacker to send a malformed system call to the bootloader, resulting in out-of-bounds memory accesses.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xx43-h94m-wj64

5 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpsoul Greenshift allows Stored XSS. This issue affects Greenshift: from n/a through 11.0.2.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xx42-xvv9-8p8p

больше 3 лет назад

The compositor in Google Chrome before 22.0.1229.92 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xx3v-pjx9-qmj7

больше 3 лет назад

Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The affected controllers utilize hard-coded credentials which may allow an attacker gain unauthorized access to the maintenance functions and obtain or modify information. This attack can be executed only during maintenance work.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xx3r-7m7h-68q2

больше 3 лет назад

Siemens SIMATIC S7-300 Profinet-enabled CPU devices with firmware before 3.2.12 and SIMATIC S7-300 Profinet-disabled CPU devices with firmware before 3.3.12 allow remote attackers to cause a denial of service (defect-mode transition) via crafted (1) ISO-TSAP or (2) Profibus packets.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xx3r-74m7-rjg4

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: md/dm-raid: don't call md_reap_sync_thread() directly Currently md_reap_sync_thread() is called from raid_message() directly without holding 'reconfig_mutex', this is definitely unsafe because md_reap_sync_thread() can change many fields that is protected by 'reconfig_mutex'. However, hold 'reconfig_mutex' here is still problematic because this will cause deadlock, for example, commit 130443d60b1b ("md: refactor idle/frozen_sync_thread() to fix deadlock"). Fix this problem by using stop_sync_thread() to unregister sync_thread, like md/raid did.

EPSS: Низкий
github логотип

GHSA-xx3q-mvc5-c52f

больше 3 лет назад

There is a NULL pointer dereference in the caseless_hash function in gxps-archive.c in libgxps 0.2.5. A crafted input will lead to a remote denial of service attack.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xx3p-ffq8-9pcp

больше 3 лет назад

Icinga Web 2 has XSS via the /icingaweb2/monitoring/list/services dir parameter, the /icingaweb2/user/list query string, the /icingaweb2/monitoring/timeline query string, or the /icingaweb2/setup query string.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xx3p-5m4j-rhw8

11 месяцев назад

A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from a USB device. This flaw may allow a malicious unprivileged guest user to crash the QEMU process on the host and cause a denial of service condition.

CVSS3: 4.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xx4c-jj58-r7x6

Inefficient Regular Expression Complexity in Validator.js

CVSS3: 5.3
больше 3 лет назад
github логотип
GHSA-xx49-hmrj-2wm5

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, watchOS 9, macOS Monterey 12.6, tvOS 16. An app may be able to execute arbitrary code with kernel privileges.

CVSS3: 7.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-xx49-8f9w-5r74

Files created from interactive shell sessions in Cobalt RaQ microservers (e.g. .bash_history) are world readable, and thus are accessible from the web server.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx49-72mm-f757

Windows NT 4.0 beta allows users to read and delete shares.

12%
Средний
больше 3 лет назад
github логотип
GHSA-xx48-fp29-wh9j

In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-147882143References: M-ALPS04356754

CVSS3: 7.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-xx47-qq34-9xqq

Cross-site scripting (XSS) vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to insert arbitrary web script via the file parameter.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xx46-fhm6-qw2q

Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 3.2.24, 4.0.26, 4.1.34, 4.2.26, and 4.3.14 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-2487.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx46-cq25-6hgf

An issue was discovered in the Infosysta "In-App & Desktop Notifications" app before 1.6.14_J8 for Jira. It is possible to obtain a list of all Jira projects without authentication/authorization via the plugins/servlet/nfj/ProjectFilter?searchQuery= URI.

CVSS3: 5.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-xx45-rh3m-ccvq

Buffer overflow in libstagefright in Mozilla Firefox before 36.0 allows remote attackers to execute arbitrary code via a crafted MP4 video that is improperly handled during playback.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-xx45-f7pv-xj5x

SQL injection vulnerability in sign_in.aspx in Message Board / Threaded Discussion Forum Application Template allows remote attackers to execute arbitrary SQL commands via the Password parameter.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xx44-m54v-4pwc

An exploitable local privilege elevation vulnerability exists in the file system permissions of Sytech XL Reporter v14.0.1 install directory. Depending on the vector chosen, an attacker can overwrite service executables and execute arbitrary code with privileges of user set to run the service or replace other files within the installation folder, which would allow for local privilege escalation.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-xx44-254w-m8vr

A malicious or compromised UApp or ABL may be used by an attacker to send a malformed system call to the bootloader, resulting in out-of-bounds memory accesses.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx43-h94m-wj64

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpsoul Greenshift allows Stored XSS. This issue affects Greenshift: from n/a through 11.0.2.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-xx42-xvv9-8p8p

The compositor in Google Chrome before 22.0.1229.92 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xx3v-pjx9-qmj7

Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The affected controllers utilize hard-coded credentials which may allow an attacker gain unauthorized access to the maintenance functions and obtain or modify information. This attack can be executed only during maintenance work.

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx3r-7m7h-68q2

Siemens SIMATIC S7-300 Profinet-enabled CPU devices with firmware before 3.2.12 and SIMATIC S7-300 Profinet-disabled CPU devices with firmware before 3.3.12 allow remote attackers to cause a denial of service (defect-mode transition) via crafted (1) ISO-TSAP or (2) Profibus packets.

CVSS3: 7.5
5%
Низкий
больше 3 лет назад
github логотип
GHSA-xx3r-74m7-rjg4

In the Linux kernel, the following vulnerability has been resolved: md/dm-raid: don't call md_reap_sync_thread() directly Currently md_reap_sync_thread() is called from raid_message() directly without holding 'reconfig_mutex', this is definitely unsafe because md_reap_sync_thread() can change many fields that is protected by 'reconfig_mutex'. However, hold 'reconfig_mutex' here is still problematic because this will cause deadlock, for example, commit 130443d60b1b ("md: refactor idle/frozen_sync_thread() to fix deadlock"). Fix this problem by using stop_sync_thread() to unregister sync_thread, like md/raid did.

0%
Низкий
около 1 года назад
github логотип
GHSA-xx3q-mvc5-c52f

There is a NULL pointer dereference in the caseless_hash function in gxps-archive.c in libgxps 0.2.5. A crafted input will lead to a remote denial of service attack.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xx3p-ffq8-9pcp

Icinga Web 2 has XSS via the /icingaweb2/monitoring/list/services dir parameter, the /icingaweb2/user/list query string, the /icingaweb2/monitoring/timeline query string, or the /icingaweb2/setup query string.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx3p-5m4j-rhw8

A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from a USB device. This flaw may allow a malicious unprivileged guest user to crash the QEMU process on the host and cause a denial of service condition.

CVSS3: 4.7
0%
Низкий
11 месяцев назад

Уязвимостей на страницу