Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 212

Количество 314 212

github логотип

GHSA-xx3r-7m7h-68q2

больше 3 лет назад

Siemens SIMATIC S7-300 Profinet-enabled CPU devices with firmware before 3.2.12 and SIMATIC S7-300 Profinet-disabled CPU devices with firmware before 3.3.12 allow remote attackers to cause a denial of service (defect-mode transition) via crafted (1) ISO-TSAP or (2) Profibus packets.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xx3r-74m7-rjg4

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: md/dm-raid: don't call md_reap_sync_thread() directly Currently md_reap_sync_thread() is called from raid_message() directly without holding 'reconfig_mutex', this is definitely unsafe because md_reap_sync_thread() can change many fields that is protected by 'reconfig_mutex'. However, hold 'reconfig_mutex' here is still problematic because this will cause deadlock, for example, commit 130443d60b1b ("md: refactor idle/frozen_sync_thread() to fix deadlock"). Fix this problem by using stop_sync_thread() to unregister sync_thread, like md/raid did.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xx3q-q45w-hjq8

6 месяцев назад

Group-Office versions prior to 6.8.119 and prior to 25.0.20 provided by Intermesh BV contain a path traversal vulnerability. If this vulnerability is exploited, information on the server hosting the product may be exposed.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xx3q-mvc5-c52f

больше 3 лет назад

There is a NULL pointer dereference in the caseless_hash function in gxps-archive.c in libgxps 0.2.5. A crafted input will lead to a remote denial of service attack.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xx3p-ffq8-9pcp

больше 3 лет назад

Icinga Web 2 has XSS via the /icingaweb2/monitoring/list/services dir parameter, the /icingaweb2/user/list query string, the /icingaweb2/monitoring/timeline query string, or the /icingaweb2/setup query string.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xx3p-5m4j-rhw8

больше 1 года назад

A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from a USB device. This flaw may allow a malicious unprivileged guest user to crash the QEMU process on the host and cause a denial of service condition.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-xx3m-p5mx-cgw5

около 4 лет назад

Grok 9.5.0 has a heap-based buffer overflow in openhtj2k::T1OpenHTJ2K::decompress (called from std::__1::__packaged_task_func<std::__1::__bind<grk::T1DecompressScheduler::deco and std::__1::packaged_task<int).

EPSS: Низкий
github логотип

GHSA-xx3m-g78m-fjqh

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in header.php in Ganglia Web 3.5.8 and 3.5.10 allows remote attackers to inject arbitrary web script or HTML via the host_regex parameter to the default URI, which is processed by get_context.php.

EPSS: Низкий
github логотип

GHSA-xx3m-f593-wg64

больше 3 лет назад

time.htm in the web interface on SerVision HVG Video Gateway devices with firmware through 2.2.26a100 allows remote authenticated users to gain privileges by leveraging a cookie received in an HTTP response, a different vulnerability than CVE-2015-0929 and CVE-2015-0930.

EPSS: Низкий
github логотип

GHSA-xx3m-cmqv-q6w6

больше 3 лет назад

An issue was discovered on Athom Homey and Homey Pro devices before 5.0.0. ZigBee hub devices should generate a unique Standard Network Key that is then exchanged with all enrolled devices so that all inter-device communication is encrypted. However, the cited Athom products use another widely known key that is designed for testing purposes: "01030507090b0d0f00020406080a0c0d" (the decimal equivalent of 1 3 5 7 9 11 13 15 0 2 4 6 8 10 12 13), which is human generated and static across all issued devices.

EPSS: Низкий
github логотип

GHSA-xx3m-8628-m9w5

больше 3 лет назад

In Poppler 0.59.0, a floating point exception occurs in the ImageStream class in Stream.cc, which may lead to a potential attack when handling malicious PDF files.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xx3m-2jcf-frfq

больше 2 лет назад

IBM Content Navigator 3.0.13 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 259247.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xx3j-5qgj-ppv5

больше 1 года назад

Memory corruption when allocating and accessing an entry in an SMEM partition.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xx3h-j3cx-8qfj

больше 6 лет назад

Insufficient Entropy in DotNetNuke

CVSS3: 7.5
EPSS: Высокий
github логотип

GHSA-xx3h-9xgv-2q4v

больше 3 лет назад

Directory traversal vulnerability in the modURL function in instance.c in Weborf before 0.12.3 allows remote attackers to read arbitrary files via ..%2f sequences in a URI.

EPSS: Низкий
github логотип

GHSA-xx3g-v5fx-v7w6

около 2 лет назад

launchAnyWhere vulnerability in the ActivityManagerService module. Successful exploitation of this vulnerability will affect availability.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xx3g-89q2-w8hh

почти 4 года назад

Cross-site scripting (XSS) vulnerability in the search functionality in Simon Brown Pebble 2.0.0 RC1 and RC2 allows remote attackers to inject arbitrary web script or HTML via the query string.

EPSS: Низкий
github логотип

GHSA-xx3f-8qwx-w9mh

больше 3 лет назад

The (1) av-centerd SOAP service and (2) backup command in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to execute arbitrary commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xx3f-44rh-4g76

больше 1 года назад

Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.13489 on Windows allows an attacker to load an arbitrary Windows library. The patch released in version 12.2.0.16909 to mitigate CVE-2024-7262 was not restrictive enough. Another hyperlink parameter was not properly sanitized which leads to the execution of an arbitrary Windows library.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xx3f-437p-fp69

около 1 месяца назад

A vulnerability was found in D-Link DI-7400G+ 19.12.25A1. This affects an unknown function of the file /msp_info.htm?flag=cmd. The manipulation of the argument cmd results in command injection. The attack can be launched remotely. The exploit has been made public and could be used.

CVSS3: 6.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xx3r-7m7h-68q2

Siemens SIMATIC S7-300 Profinet-enabled CPU devices with firmware before 3.2.12 and SIMATIC S7-300 Profinet-disabled CPU devices with firmware before 3.3.12 allow remote attackers to cause a denial of service (defect-mode transition) via crafted (1) ISO-TSAP or (2) Profibus packets.

CVSS3: 7.5
5%
Низкий
больше 3 лет назад
github логотип
GHSA-xx3r-74m7-rjg4

In the Linux kernel, the following vulnerability has been resolved: md/dm-raid: don't call md_reap_sync_thread() directly Currently md_reap_sync_thread() is called from raid_message() directly without holding 'reconfig_mutex', this is definitely unsafe because md_reap_sync_thread() can change many fields that is protected by 'reconfig_mutex'. However, hold 'reconfig_mutex' here is still problematic because this will cause deadlock, for example, commit 130443d60b1b ("md: refactor idle/frozen_sync_thread() to fix deadlock"). Fix this problem by using stop_sync_thread() to unregister sync_thread, like md/raid did.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xx3q-q45w-hjq8

Group-Office versions prior to 6.8.119 and prior to 25.0.20 provided by Intermesh BV contain a path traversal vulnerability. If this vulnerability is exploited, information on the server hosting the product may be exposed.

CVSS3: 4.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-xx3q-mvc5-c52f

There is a NULL pointer dereference in the caseless_hash function in gxps-archive.c in libgxps 0.2.5. A crafted input will lead to a remote denial of service attack.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xx3p-ffq8-9pcp

Icinga Web 2 has XSS via the /icingaweb2/monitoring/list/services dir parameter, the /icingaweb2/user/list query string, the /icingaweb2/monitoring/timeline query string, or the /icingaweb2/setup query string.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx3p-5m4j-rhw8

A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from a USB device. This flaw may allow a malicious unprivileged guest user to crash the QEMU process on the host and cause a denial of service condition.

CVSS3: 4.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-xx3m-p5mx-cgw5

Grok 9.5.0 has a heap-based buffer overflow in openhtj2k::T1OpenHTJ2K::decompress (called from std::__1::__packaged_task_func<std::__1::__bind<grk::T1DecompressScheduler::deco and std::__1::packaged_task<int).

0%
Низкий
около 4 лет назад
github логотип
GHSA-xx3m-g78m-fjqh

Cross-site scripting (XSS) vulnerability in header.php in Ganglia Web 3.5.8 and 3.5.10 allows remote attackers to inject arbitrary web script or HTML via the host_regex parameter to the default URI, which is processed by get_context.php.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xx3m-f593-wg64

time.htm in the web interface on SerVision HVG Video Gateway devices with firmware through 2.2.26a100 allows remote authenticated users to gain privileges by leveraging a cookie received in an HTTP response, a different vulnerability than CVE-2015-0929 and CVE-2015-0930.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx3m-cmqv-q6w6

An issue was discovered on Athom Homey and Homey Pro devices before 5.0.0. ZigBee hub devices should generate a unique Standard Network Key that is then exchanged with all enrolled devices so that all inter-device communication is encrypted. However, the cited Athom products use another widely known key that is designed for testing purposes: "01030507090b0d0f00020406080a0c0d" (the decimal equivalent of 1 3 5 7 9 11 13 15 0 2 4 6 8 10 12 13), which is human generated and static across all issued devices.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx3m-8628-m9w5

In Poppler 0.59.0, a floating point exception occurs in the ImageStream class in Stream.cc, which may lead to a potential attack when handling malicious PDF files.

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xx3m-2jcf-frfq

IBM Content Navigator 3.0.13 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 259247.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xx3j-5qgj-ppv5

Memory corruption when allocating and accessing an entry in an SMEM partition.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-xx3h-j3cx-8qfj

Insufficient Entropy in DotNetNuke

CVSS3: 7.5
77%
Высокий
больше 6 лет назад
github логотип
GHSA-xx3h-9xgv-2q4v

Directory traversal vulnerability in the modURL function in instance.c in Weborf before 0.12.3 allows remote attackers to read arbitrary files via ..%2f sequences in a URI.

6%
Низкий
больше 3 лет назад
github логотип
GHSA-xx3g-v5fx-v7w6

launchAnyWhere vulnerability in the ActivityManagerService module. Successful exploitation of this vulnerability will affect availability.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-xx3g-89q2-w8hh

Cross-site scripting (XSS) vulnerability in the search functionality in Simon Brown Pebble 2.0.0 RC1 and RC2 allows remote attackers to inject arbitrary web script or HTML via the query string.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xx3f-8qwx-w9mh

The (1) av-centerd SOAP service and (2) backup command in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to execute arbitrary commands via unspecified vectors.

5%
Низкий
больше 3 лет назад
github логотип
GHSA-xx3f-44rh-4g76

Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.13489 on Windows allows an attacker to load an arbitrary Windows library. The patch released in version 12.2.0.16909 to mitigate CVE-2024-7262 was not restrictive enough. Another hyperlink parameter was not properly sanitized which leads to the execution of an arbitrary Windows library.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-xx3f-437p-fp69

A vulnerability was found in D-Link DI-7400G+ 19.12.25A1. This affects an unknown function of the file /msp_info.htm?flag=cmd. The manipulation of the argument cmd results in command injection. The attack can be launched remotely. The exploit has been made public and could be used.

CVSS3: 6.3
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу