Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 154

Количество 359 154

github логотип

GHSA-xhr8-9mw2-3mf4

4 месяца назад

Memory safety bugs present in Firefox ESR 115.35.0, Firefox ESR 140.10.0, Thunderbird ESR 140.10.0, Firefox 150.0.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, and Firefox ESR 115.35.1.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xhr7-hgf3-h7pr

около 4 лет назад

fmwlan.c on D-Link DIR-615Jx10 devices has a stack-based buffer overflow via the formWlanSetup_Wizard webpage parameter when f_radius_ip1 is malformed.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xhr7-9ww7-w3xg

больше 4 лет назад

index.php for TorrentFlux 2.2 allows remote attackers to delete files by specifying the target filename in the delfile parameter.

EPSS: Низкий
github логотип

GHSA-xhr7-3gcx-q3wq

около 4 лет назад

The Multimedia Messaging Centre (MMSC) in NowSMS Now SMS & MMS Gateway 2013.09.26 allows remote attackers to cause a denial of service via a malformed message to a MM4 connection.

EPSS: Низкий
github логотип

GHSA-xhr6-v9pv-82wv

около 4 лет назад

The installer for Metasploit Framework 3.5.1, when running on Windows, uses weak inherited permissions for the Metasploit installation directory, which allows local users to gain privileges by replacing critical files with a Trojan horse.

EPSS: Низкий
github логотип

GHSA-xhr6-cwm7-hfr4

около 4 лет назад

A UNIX Symbolic Link (Symlink) Following vulnerability in the mysql-systemd-helper of the mariadb packaging of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allows local attackers to change the permissions of arbitrary files to 0640. This issue affects: SUSE Linux Enterprise Server 12 mariadb versions prior to 10.2.31-3.25.1. SUSE Linux Enterprise Server 15 mariadb versions prior to 10.2.31-3.26.1.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xhr6-7rpm-rmv3

9 месяцев назад

An issue was discovered in Ruoyi 4.8.1 allowing attackers to gain escalated privileges due to the owning department having higher rights than the active user.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xhr5-q8cq-g8ch

почти 2 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Sale php scripts Web Directory Free allows Reflected XSS.This issue affects Web Directory Free: from n/a through 1.7.3.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xhr5-7w4q-jwjc

больше 2 лет назад

A vulnerability, which was classified as critical, was found in Kashipara Food Management System up to 1.0. Affected is an unknown function of the file item_list_edit.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-249834 is the identifier assigned to this vulnerability.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xhr4-mxhh-ffmg

около 4 лет назад

zzcms version 8.3 and earlier is affected by: File Delete to Code Execution. The impact is: zzcms File Delete to Code Execution. The component is: user/licence_save.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xhr4-jrvp-2fpc

почти 3 года назад

Improper Neutralization of Formula Elements in a CSV File vulnerability in WPOmnia KB Support.This issue affects KB Support: from n/a through 1.5.84.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xhr4-fjfq-6r46

почти 3 года назад

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1969.

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-xhr4-9hhj-4j2m

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in index.php in dl Download Ticket Service before 0.7 allows remote attackers to inject arbitrary web script or HTML via the t parameter, related to an invalid ticket ID. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-xhr4-2jjv-2g88

около 4 лет назад

SQL injection vulnerability in spywall/includes/deptUploads_data.php in Symantec Web Gateway 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via the groupid parameter.

EPSS: Низкий
github логотип

GHSA-xhr3-wf7j-h255

почти 2 года назад

Infinite loop in github.com/gomarkdown/markdown

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-xhr3-rxgw-89r7

больше 4 лет назад

The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2 do not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Win32k User Input Validation Vulnerability."

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-xhr2-vhcg-3g56

больше 4 лет назад

Remote Desktop Session Host (RDSH) in Remote Desktop Protocol (RDP) through 8.1 in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly verify certificates, which allows man-in-the-middle attackers to spoof clients via a crafted certificate with valid Issuer and Serial Number fields, aka "Remote Desktop Session Host Spoofing Vulnerability."

EPSS: Низкий
github логотип

GHSA-xhr2-j67f-5vh2

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the Relay Diagnostic page in IBM Tivoli Endpoint Manager 9.1 before 9.1.1229 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xhr2-gj6g-mm67

около 4 лет назад

The issue was addressed with additional user controls. This issue is fixed in macOS Big Sur 11.0.1. Users may be unable to remove metadata indicating where files were downloaded from.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xhqx-mgh3-3h7q

около 2 месяцев назад

Incus: CreateCustomVolumeFromBackup nil-pointer dereference on volume_snapshots[*].expires_at (sibling-field variant of GHSA-r7w7)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xhr8-9mw2-3mf4

Memory safety bugs present in Firefox ESR 115.35.0, Firefox ESR 140.10.0, Thunderbird ESR 140.10.0, Firefox 150.0.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, and Firefox ESR 115.35.1.

CVSS3: 7.3
0%
Низкий
4 месяца назад
github логотип
GHSA-xhr7-hgf3-h7pr

fmwlan.c on D-Link DIR-615Jx10 devices has a stack-based buffer overflow via the formWlanSetup_Wizard webpage parameter when f_radius_ip1 is malformed.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-xhr7-9ww7-w3xg

index.php for TorrentFlux 2.2 allows remote attackers to delete files by specifying the target filename in the delfile parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xhr7-3gcx-q3wq

The Multimedia Messaging Centre (MMSC) in NowSMS Now SMS & MMS Gateway 2013.09.26 allows remote attackers to cause a denial of service via a malformed message to a MM4 connection.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xhr6-v9pv-82wv

The installer for Metasploit Framework 3.5.1, when running on Windows, uses weak inherited permissions for the Metasploit installation directory, which allows local users to gain privileges by replacing critical files with a Trojan horse.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xhr6-cwm7-hfr4

A UNIX Symbolic Link (Symlink) Following vulnerability in the mysql-systemd-helper of the mariadb packaging of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allows local attackers to change the permissions of arbitrary files to 0640. This issue affects: SUSE Linux Enterprise Server 12 mariadb versions prior to 10.2.31-3.25.1. SUSE Linux Enterprise Server 15 mariadb versions prior to 10.2.31-3.26.1.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-xhr6-7rpm-rmv3

An issue was discovered in Ruoyi 4.8.1 allowing attackers to gain escalated privileges due to the owning department having higher rights than the active user.

CVSS3: 8.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-xhr5-q8cq-g8ch

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Sale php scripts Web Directory Free allows Reflected XSS.This issue affects Web Directory Free: from n/a through 1.7.3.

CVSS3: 7.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-xhr5-7w4q-jwjc

A vulnerability, which was classified as critical, was found in Kashipara Food Management System up to 1.0. Affected is an unknown function of the file item_list_edit.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-249834 is the identifier assigned to this vulnerability.

CVSS3: 6.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xhr4-mxhh-ffmg

zzcms version 8.3 and earlier is affected by: File Delete to Code Execution. The impact is: zzcms File Delete to Code Execution. The component is: user/licence_save.php.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-xhr4-jrvp-2fpc

Improper Neutralization of Formula Elements in a CSV File vulnerability in WPOmnia KB Support.This issue affects KB Support: from n/a through 1.5.84.

CVSS3: 8.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-xhr4-fjfq-6r46

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1969.

CVSS3: 4
1%
Низкий
почти 3 года назад
github логотип
GHSA-xhr4-9hhj-4j2m

Cross-site scripting (XSS) vulnerability in index.php in dl Download Ticket Service before 0.7 allows remote attackers to inject arbitrary web script or HTML via the t parameter, related to an invalid ticket ID. NOTE: some of these details are obtained from third party information.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xhr4-2jjv-2g88

SQL injection vulnerability in spywall/includes/deptUploads_data.php in Symantec Web Gateway 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via the groupid parameter.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xhr3-wf7j-h255

Infinite loop in github.com/gomarkdown/markdown

CVSS3: 5.1
1%
Низкий
почти 2 года назад
github логотип
GHSA-xhr3-rxgw-89r7

The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2 do not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Win32k User Input Validation Vulnerability."

CVSS3: 8.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xhr2-vhcg-3g56

Remote Desktop Session Host (RDSH) in Remote Desktop Protocol (RDP) through 8.1 in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly verify certificates, which allows man-in-the-middle attackers to spoof clients via a crafted certificate with valid Issuer and Serial Number fields, aka "Remote Desktop Session Host Spoofing Vulnerability."

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xhr2-j67f-5vh2

Cross-site scripting (XSS) vulnerability in the Relay Diagnostic page in IBM Tivoli Endpoint Manager 9.1 before 9.1.1229 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xhr2-gj6g-mm67

The issue was addressed with additional user controls. This issue is fixed in macOS Big Sur 11.0.1. Users may be unable to remove metadata indicating where files were downloaded from.

CVSS3: 5.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xhqx-mgh3-3h7q

Incus: CreateCustomVolumeFromBackup nil-pointer dereference on volume_snapshots[*].expires_at (sibling-field variant of GHSA-r7w7)

около 2 месяцев назад

Уязвимостей на страницу