Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 234

Количество 358 234

github логотип

GHSA-xj6j-6m68-mr7h

больше 3 лет назад

Libde265 v1.0.11 was discovered to contain a segmentation violation via the function decoder_context::process_slice_segment_header at decctx.cc.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xj6h-r3q8-7cmf

около 4 лет назад

Nagios XI 5.7.5 and earlier allows authenticated admins to upload arbitrary files due to improper validation of the rename functionality in custom-includes component, which leads to remote code execution by uploading php files.

EPSS: Средний
github логотип

GHSA-xj6h-22hm-62qq

около 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Pligg CMS before 1.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) user or (2) page parameter to (a) admin/admin_comments.php or (b) admin/admin_links.php; or list parameter in a (3) move or (4) minimize action to (c) admin/admin_index.php.

EPSS: Низкий
github логотип

GHSA-xj6g-jqvr-8wx7

больше 4 лет назад

A use after free in Blink in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xj6g-crgg-j3cm

больше 4 лет назад

An issue was discovered in ZoneMinder v1.32.3. Reflected XSS exists in web/skins/classic/views/plugin.php via the zm/index.php?view=plugin pl parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xj6g-c6gv-vmjp

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix netfs_page_mkwrite() to check folio->mapping is valid Fix netfs_page_mkwrite() to check that folio->mapping is valid once it has taken the folio lock (as filemap_page_mkwrite() does). Without this, generic/247 occasionally oopses with something like the following: BUG: kernel NULL pointer dereference, address: 0000000000000000 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page RIP: 0010:trace_event_raw_event_netfs_folio+0x61/0xc0 ... Call Trace: <TASK> ? __die_body+0x1a/0x60 ? page_fault_oops+0x6e/0xa0 ? exc_page_fault+0xc2/0xe0 ? asm_exc_page_fault+0x22/0x30 ? trace_event_raw_event_netfs_folio+0x61/0xc0 trace_netfs_folio+0x39/0x40 netfs_page_mkwrite+0x14c/0x1d0 do_page_mkwrite+0x50/0x90 do_pte_missing+0x184/0x200 __handle_mm_fault+0x42d/0x500 handle_mm_fault+0x121/0x1f0 do_user...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xj6g-7vq6-3mcm

около 4 лет назад

An issue was discovered in HCC Embedded InterNiche NicheStack through 4.3. The tfshnd():tftpsrv.c TFTP packet processing function doesn't ensure that a filename is adequately '\0' terminated; therefore, a subsequent call to strlen for the filename might read out of bounds of the protocol packet buffer (if no '\0' byte exists within a reasonable range).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xj6g-6cpf-m82c

8 месяцев назад

A weakness has been identified in code-projects Computer Book Store 1.0. Affected is an unknown function of the file /admin_delete.php. This manipulation of the argument bookisbn causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xj6f-x7jm-85ff

больше 7 лет назад

openframe-ascii-image downloads Resources over HTTP

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xj6f-mr2f-7c6m

почти 3 года назад

Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-xj6f-hh7p-x6vm

около 4 лет назад

The Yahoo! Japan Box (aka jp.co.yahoo.android.ybox) application 1.5.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-xj6f-gh33-gmgg

около 1 года назад

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radIpkey parameter in the web_radiusSrv_post function.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xj6f-7cvw-xj6h

больше 4 лет назад

WebKit, as used in Apple iOS before 8.1.3; Apple Safari before 6.2.3, 7.x before 7.1.3, and 8.x before 8.0.3; and Apple TV before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-4476 and CVE-2014-4477.

EPSS: Низкий
github логотип

GHSA-xj6f-4x9j-9mx2

около 2 лет назад

Memory corruption when more scan frequency list or channels are sent from the user space.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-xj6c-4x5p-6pj3

больше 4 лет назад

net/packet/af_packet.c in the Linux kernel before 2.6.39.3 does not properly restrict user-space access to certain packet data structures associated with VLAN Tag Control Information, which allows local users to obtain potentially sensitive information via a crafted application.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xj69-m9qq-8m94

5 месяцев назад

Quill has unbounded memory allocation via unvalidated size fields in Mach-O binary parsing

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xj69-cqwc-2w67

19 дней назад

Improper validation of symbolic links in the Pack Git import feature in Cribl Stream before 4.18.2 allows a remote authenticated attacker with Pack import and pipeline preview permissions to execute arbitrary code as the Cribl server process via a crafted Git repository containing a symbolic link in the pack's functions directory.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xj67-986p-6xph

больше 4 лет назад

EMU Webmail allows local users to execute arbitrary programs via a .. (dot dot) in the HTTP Host header that points to a Trojan horse configuration file that contains a pageroot specifier that contains shell metacharacters.

EPSS: Низкий
github логотип

GHSA-xj67-863c-2vj3

больше 4 лет назад

Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, and (4) pdftohtml, (5) KOffice KWord, (6) CUPS, and (7) libextractor allows remote attackers to execute arbitrary code via a PDF file with an out-of-range numComps (number of components) field.

EPSS: Низкий
github логотип

GHSA-xj67-5prp-p33j

больше 4 лет назад

Memory leak in ypdb_open in yp_db.c for ypserv before 2.5 in the NIS package 3.9 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of requests for a map that does not exist.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xj6j-6m68-mr7h

Libde265 v1.0.11 was discovered to contain a segmentation violation via the function decoder_context::process_slice_segment_header at decctx.cc.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xj6h-r3q8-7cmf

Nagios XI 5.7.5 and earlier allows authenticated admins to upload arbitrary files due to improper validation of the rename functionality in custom-includes component, which leads to remote code execution by uploading php files.

55%
Средний
около 4 лет назад
github логотип
GHSA-xj6h-22hm-62qq

Multiple cross-site scripting (XSS) vulnerabilities in Pligg CMS before 1.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) user or (2) page parameter to (a) admin/admin_comments.php or (b) admin/admin_links.php; or list parameter in a (3) move or (4) minimize action to (c) admin/admin_index.php.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xj6g-jqvr-8wx7

A use after free in Blink in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xj6g-crgg-j3cm

An issue was discovered in ZoneMinder v1.32.3. Reflected XSS exists in web/skins/classic/views/plugin.php via the zm/index.php?view=plugin pl parameter.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xj6g-c6gv-vmjp

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix netfs_page_mkwrite() to check folio->mapping is valid Fix netfs_page_mkwrite() to check that folio->mapping is valid once it has taken the folio lock (as filemap_page_mkwrite() does). Without this, generic/247 occasionally oopses with something like the following: BUG: kernel NULL pointer dereference, address: 0000000000000000 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page RIP: 0010:trace_event_raw_event_netfs_folio+0x61/0xc0 ... Call Trace: <TASK> ? __die_body+0x1a/0x60 ? page_fault_oops+0x6e/0xa0 ? exc_page_fault+0xc2/0xe0 ? asm_exc_page_fault+0x22/0x30 ? trace_event_raw_event_netfs_folio+0x61/0xc0 trace_netfs_folio+0x39/0x40 netfs_page_mkwrite+0x14c/0x1d0 do_page_mkwrite+0x50/0x90 do_pte_missing+0x184/0x200 __handle_mm_fault+0x42d/0x500 handle_mm_fault+0x121/0x1f0 do_user...

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-xj6g-7vq6-3mcm

An issue was discovered in HCC Embedded InterNiche NicheStack through 4.3. The tfshnd():tftpsrv.c TFTP packet processing function doesn't ensure that a filename is adequately '\0' terminated; therefore, a subsequent call to strlen for the filename might read out of bounds of the protocol packet buffer (if no '\0' byte exists within a reasonable range).

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-xj6g-6cpf-m82c

A weakness has been identified in code-projects Computer Book Store 1.0. Affected is an unknown function of the file /admin_delete.php. This manipulation of the argument bookisbn causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited.

CVSS3: 7.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-xj6f-x7jm-85ff

openframe-ascii-image downloads Resources over HTTP

CVSS3: 8.1
2%
Низкий
больше 7 лет назад
github логотип
GHSA-xj6f-mr2f-7c6m

Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value.

CVSS3: 8.2
0%
Низкий
почти 3 года назад
github логотип
GHSA-xj6f-hh7p-x6vm

The Yahoo! Japan Box (aka jp.co.yahoo.android.ybox) application 1.5.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xj6f-gh33-gmgg

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radIpkey parameter in the web_radiusSrv_post function.

CVSS3: 9.8
0%
Низкий
около 1 года назад
github логотип
GHSA-xj6f-7cvw-xj6h

WebKit, as used in Apple iOS before 8.1.3; Apple Safari before 6.2.3, 7.x before 7.1.3, and 8.x before 8.0.3; and Apple TV before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-4476 and CVE-2014-4477.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xj6f-4x9j-9mx2

Memory corruption when more scan frequency list or channels are sent from the user space.

CVSS3: 6.7
0%
Низкий
около 2 лет назад
github логотип
GHSA-xj6c-4x5p-6pj3

net/packet/af_packet.c in the Linux kernel before 2.6.39.3 does not properly restrict user-space access to certain packet data structures associated with VLAN Tag Control Information, which allows local users to obtain potentially sensitive information via a crafted application.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xj69-m9qq-8m94

Quill has unbounded memory allocation via unvalidated size fields in Mach-O binary parsing

CVSS3: 5.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-xj69-cqwc-2w67

Improper validation of symbolic links in the Pack Git import feature in Cribl Stream before 4.18.2 allows a remote authenticated attacker with Pack import and pipeline preview permissions to execute arbitrary code as the Cribl server process via a crafted Git repository containing a symbolic link in the pack's functions directory.

CVSS3: 8.8
1%
Низкий
19 дней назад
github логотип
GHSA-xj67-986p-6xph

EMU Webmail allows local users to execute arbitrary programs via a .. (dot dot) in the HTTP Host header that points to a Trojan horse configuration file that contains a pageroot specifier that contains shell metacharacters.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xj67-863c-2vj3

Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, and (4) pdftohtml, (5) KOffice KWord, (6) CUPS, and (7) libextractor allows remote attackers to execute arbitrary code via a PDF file with an out-of-range numComps (number of components) field.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-xj67-5prp-p33j

Memory leak in ypdb_open in yp_db.c for ypserv before 2.5 in the NIS package 3.9 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of requests for a map that does not exist.

3%
Низкий
больше 4 лет назад

Уязвимостей на страницу