Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 234

Количество 358 234

github логотип

GHSA-xj8f-g7hp-3hcv

больше 4 лет назад

Adobe Premiere Pro version 15.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xj8c-vcc9-5mfq

больше 2 лет назад

NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause stack memory corruption by sending a specially crafted network packet. A successful exploit of this vulnerability may lead to arbitrary code execution, denial of service, information disclosure, and data tampering.

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-xj8c-f7qf-ch6p

больше 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NinjaTeam Database for Contact Form 7 allows Stored XSS.This issue affects Database for Contact Form 7: from n/a through 3.0.6.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xj8c-4hpj-pm7v

12 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: vfio/pds: Fix missing detach_ioas op When CONFIG_IOMMUFD is enabled and a device is bound to the pds_vfio_pci driver, the following WARN_ON() trace is seen and probe fails: WARNING: CPU: 0 PID: 5040 at drivers/vfio/vfio_main.c:317 __vfio_register_dev+0x130/0x140 [vfio] <...> pds_vfio_pci 0000:08:00.1: probe with driver pds_vfio_pci failed with error -22 This is because the driver's vfio_device_ops.detach_ioas isn't set. Fix this by using the generic vfio_iommufd_physical_detach_ioas function.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xj8c-32pp-9795

12 месяцев назад

In rfc_check_send_cmd of rfc_utils.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xj89-wxvh-5m7p

около 4 лет назад

Integer signedness error in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to cause a denial of service via a crafted packet that triggers a heap-based buffer overflow.

EPSS: Низкий
github логотип

GHSA-xj89-pr57-g8p3

больше 4 лет назад

In Tidy 5.7.0, the prvTidyTidyMetaCharset function in clean.c allows attackers to cause a denial of service (Segmentation Fault), because the currentNode variable in the "children of the head" processing feature is modified in the loop without validating the new value.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xj89-hjg5-97v6

больше 3 лет назад

A vulnerability was found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. It has been rated as critical. Affected by this issue is some unknown functionality of the component Web Management Interface. The manipulation of the argument suffix-rate-up leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-227654 is the identifier assigned to this vulnerability.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xj89-3jjf-34h5

около 4 лет назад

Skyworth Digital Technology RN510 V.3.1.0.4 RN510 V.3.1.0.4 contains a buffer overflow vulnerability in /cgi-bin/app-staticIP.asp. An authenticated attacker can send a specially crafted request to endpoint which can lead to a denial of service (DoS) or possible code execution on the device.

EPSS: Низкий
github логотип

GHSA-xj88-rf28-xgv9

около 4 лет назад

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.5, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.3.1, iOS 15.4.1 and iPadOS 15.4.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-xj88-q9xm-8q7v

больше 4 лет назад

Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.

EPSS: Низкий
github логотип

GHSA-xj87-w94c-qmj7

больше 4 лет назад

The Apple Security Update 2007-004 uses an incorrect configuration file for FTPServer in Apple Mac OS X Server 10.4.9, which might allow remote authenticated users to access additional directories.

EPSS: Низкий
github логотип

GHSA-xj87-rp3c-q5f4

около 4 лет назад

Improper input validation vulnerability in AR Emoji Editor prior to version 4.4.03.5 in Android Q(10.0) and above allows untrusted applications to access arbitrary files with an escalated privilege.

EPSS: Низкий
github логотип

GHSA-xj87-rmh4-792j

около 3 лет назад

Out-of-bounds Write vulnerability in SSHDCPAPP TA prior to &quot;SAMSUNG ELECTONICS, CO, LTD. - System Hardware Update - 7/13/2023&quot; in Windows Update for Galaxy book Go, Galaxy book Go 5G, Galaxy book2 Go and Galaxy book2 Pro 360 allows local attacker to execute arbitrary code.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-xj87-q393-fjr7

больше 4 лет назад

SQL injection vulnerability in Php/Functions/log_function.php in phpTrafficA 2.3 and earlier allows remote attackers to execute arbitrary SQL commands via a User-Agent HTTP header.

EPSS: Низкий
github логотип

GHSA-xj87-mqvh-88w2

около 2 лет назад

fish-shop/syntax-check Improper Neutralization of Delimiters

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xj87-j62f-mmxj

больше 4 лет назад

Buffer overflow in the libauth library in Solaris allows local users to gain additional privileges, possibly root access.

EPSS: Низкий
github логотип

GHSA-xj85-gxf6-hq98

больше 4 лет назад

The cfg80211_wext_giwessid function in net/wireless/wext-compat.c in the Linux kernel before 2.6.36-rc3-next-20100831 does not properly initialize certain structure members, which allows local users to leverage an off-by-one error in the ioctl_standard_iw_point function in net/wireless/wext-core.c, and obtain potentially sensitive information from kernel heap memory, via vectors involving an SIOCGIWESSID ioctl call that specifies a large buffer size.

EPSS: Низкий
github логотип

GHSA-xj84-whq8-hph6

больше 3 лет назад

Remote Procedure Call Runtime Remote Code Execution Vulnerability

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xj84-6q8f-qg2r

больше 4 лет назад

TYPO3 Reveals Sensitive Information via Direct Request to `misc/phpcheck/`

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xj8f-g7hp-3hcv

Adobe Premiere Pro version 15.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

CVSS3: 7.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xj8c-vcc9-5mfq

NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause stack memory corruption by sending a specially crafted network packet. A successful exploit of this vulnerability may lead to arbitrary code execution, denial of service, information disclosure, and data tampering.

CVSS3: 9
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xj8c-f7qf-ch6p

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NinjaTeam Database for Contact Form 7 allows Stored XSS.This issue affects Database for Contact Form 7: from n/a through 3.0.6.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xj8c-4hpj-pm7v

In the Linux kernel, the following vulnerability has been resolved: vfio/pds: Fix missing detach_ioas op When CONFIG_IOMMUFD is enabled and a device is bound to the pds_vfio_pci driver, the following WARN_ON() trace is seen and probe fails: WARNING: CPU: 0 PID: 5040 at drivers/vfio/vfio_main.c:317 __vfio_register_dev+0x130/0x140 [vfio] <...> pds_vfio_pci 0000:08:00.1: probe with driver pds_vfio_pci failed with error -22 This is because the driver's vfio_device_ops.detach_ioas isn't set. Fix this by using the generic vfio_iommufd_physical_detach_ioas function.

CVSS3: 5.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-xj8c-32pp-9795

In rfc_check_send_cmd of rfc_utils.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 9.8
0%
Низкий
12 месяцев назад
github логотип
GHSA-xj89-wxvh-5m7p

Integer signedness error in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to cause a denial of service via a crafted packet that triggers a heap-based buffer overflow.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xj89-pr57-g8p3

In Tidy 5.7.0, the prvTidyTidyMetaCharset function in clean.c allows attackers to cause a denial of service (Segmentation Fault), because the currentNode variable in the "children of the head" processing feature is modified in the loop without validating the new value.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xj89-hjg5-97v6

A vulnerability was found in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. It has been rated as critical. Affected by this issue is some unknown functionality of the component Web Management Interface. The manipulation of the argument suffix-rate-up leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-227654 is the identifier assigned to this vulnerability.

CVSS3: 6.3
8%
Низкий
больше 3 лет назад
github логотип
GHSA-xj89-3jjf-34h5

Skyworth Digital Technology RN510 V.3.1.0.4 RN510 V.3.1.0.4 contains a buffer overflow vulnerability in /cgi-bin/app-staticIP.asp. An authenticated attacker can send a specially crafted request to endpoint which can lead to a denial of service (DoS) or possible code execution on the device.

4%
Низкий
около 4 лет назад
github логотип
GHSA-xj88-rf28-xgv9

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.5, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.3.1, iOS 15.4.1 and iPadOS 15.4.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..

CVSS3: 7.8
12%
Средний
около 4 лет назад
github логотип
GHSA-xj88-q9xm-8q7v

Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-xj87-w94c-qmj7

The Apple Security Update 2007-004 uses an incorrect configuration file for FTPServer in Apple Mac OS X Server 10.4.9, which might allow remote authenticated users to access additional directories.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xj87-rp3c-q5f4

Improper input validation vulnerability in AR Emoji Editor prior to version 4.4.03.5 in Android Q(10.0) and above allows untrusted applications to access arbitrary files with an escalated privilege.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xj87-rmh4-792j

Out-of-bounds Write vulnerability in SSHDCPAPP TA prior to &quot;SAMSUNG ELECTONICS, CO, LTD. - System Hardware Update - 7/13/2023&quot; in Windows Update for Galaxy book Go, Galaxy book Go 5G, Galaxy book2 Go and Galaxy book2 Pro 360 allows local attacker to execute arbitrary code.

CVSS3: 6.7
0%
Низкий
около 3 лет назад
github логотип
GHSA-xj87-q393-fjr7

SQL injection vulnerability in Php/Functions/log_function.php in phpTrafficA 2.3 and earlier allows remote attackers to execute arbitrary SQL commands via a User-Agent HTTP header.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xj87-mqvh-88w2

fish-shop/syntax-check Improper Neutralization of Delimiters

CVSS3: 4.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-xj87-j62f-mmxj

Buffer overflow in the libauth library in Solaris allows local users to gain additional privileges, possibly root access.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xj85-gxf6-hq98

The cfg80211_wext_giwessid function in net/wireless/wext-compat.c in the Linux kernel before 2.6.36-rc3-next-20100831 does not properly initialize certain structure members, which allows local users to leverage an off-by-one error in the ioctl_standard_iw_point function in net/wireless/wext-core.c, and obtain potentially sensitive information from kernel heap memory, via vectors involving an SIOCGIWESSID ioctl call that specifies a large buffer size.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xj84-whq8-hph6

Remote Procedure Call Runtime Remote Code Execution Vulnerability

CVSS3: 8.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xj84-6q8f-qg2r

TYPO3 Reveals Sensitive Information via Direct Request to `misc/phpcheck/`

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу