Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 212

Количество 314 212

github логотип

GHSA-xx3c-ww24-2pgq

почти 4 года назад

Template injection (Improper Neutralization of Special Elements Used in a Template Engine) vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series versions prior to Ver.2.9.40, Ver.2.10.x series versions prior to Ver.2.10.44, Ver.2.11.x series versions prior to Ver.2.11.42, and Ver.3.0.x series versions prior to Ver.3.0.1 allows a remote authenticated attacker to obtain an arbitrary file on the server via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xx3c-6h6w-w5rg

больше 3 лет назад

JWT.php in F21 JWT before 2.0 allows remote attackers to bypass signature verification via crafted tokens.

EPSS: Низкий
github логотип

GHSA-xx3c-35rv-h773

больше 3 лет назад

The (1) udp_recvmsg and (2) udpv6_recvmsg functions in the Linux kernel before 4.0.6 do not properly consider yielding a processor, which allows remote attackers to cause a denial of service (system hang) via incorrect checksums within a UDP packet flood.

EPSS: Средний
github логотип

GHSA-xx38-qpxm-6j8x

почти 4 года назад

IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 on Linux, Solaris, and HP-UX, when a Local OS registry is used, does not properly validate user accounts, which allows remote attackers to bypass intended access restrictions via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xx38-8wp6-c2jw

больше 3 лет назад

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, Safari 13.0.5, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. Processing maliciously crafted web content may lead to arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-xx36-85fv-r3w7

почти 4 года назад

The dhcp.client program for QNX 4.25 vmware is setuid, possibly by default, which allows local users to modify the NIC configuration and conduct other attacks.

EPSS: Низкий
github логотип

GHSA-xx36-6rv4-gj8r

больше 3 лет назад

ecdsa-elixir fails to check signatures, vulnerable to message forging

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xx34-wh4m-w39f

почти 4 года назад

The AMaViS virus scanner 0.2.0-pre4 and earlier allows remote attackers to execute arbitrary commands as root via an infected mail message with shell metacharacters in the reply-to field.

EPSS: Низкий
github логотип

GHSA-xx34-qq6x-qvv2

больше 3 лет назад

IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158880.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xx33-j3mf-gffc

больше 2 лет назад

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function upgradeInfoRegister.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xx33-83f8-v2gp

больше 3 лет назад

The mintToken function of a smart contract implementation for loncoin (LON), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xx33-73cr-ffp7

больше 3 лет назад

vmware-mount in VMware Workstation 8.x and 9.x and VMware Player 4.x and 5.x, on systems based on Debian GNU/Linux, allows host OS users to gain host OS privileges via a crafted lsb_release binary in a directory in the PATH, related to use of the popen library function.

EPSS: Низкий
github логотип

GHSA-xx33-26x2-m77p

около 4 лет назад

In sourcecodetester Engineers Online Portal as of 10-21-21, an attacker can manipulate the Host header as seen by the web application and cause the application to behave in unexpected ways. Very often multiple websites are hosted on the same IP address. This is where the Host Header comes in. This header specifies which website should process the HTTP request. The web server uses the value of this header to dispatch the request to the specified website. Each website hosted on the same IP address is called a virtual host. And It's possible to send requests with arbitrary Host Headers to the first virtual host.

EPSS: Низкий
github логотип

GHSA-xx2w-rcmq-q3gc

около 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Ciprian Popescu Block for Font Awesome.This issue affects Block for Font Awesome: from n/a through 1.4.0.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xx2w-hg3f-6w9g

21 день назад

Xmind 2020 contains a cross-site scripting vulnerability that allows attackers to inject malicious payloads into mind mapping files or custom headers. Attackers can craft malicious files with embedded JavaScript that execute system commands when opened, enabling remote code execution through mouse interactions or file opening.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xx2v-j2rm-5c42

около 2 лет назад

TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanIp parameter’ of the setLanConfig interface of the cstecgi .cgi.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xx2r-xrgj-fm3f

около 2 лет назад

The vulnerability allows a remote attacker to inject arbitrary HTTP response headers or manipulate HTTP response bodies inside a victim’s session via a crafted URL or HTTP request.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xx2r-x7vm-xjjj

почти 4 года назад

A local authentication restriction bypass vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xx2r-f4xg-6rg7

почти 3 года назад

Malwarebytes AdwCleaner 8.4.0 runs as Administrator and performs an insecure file delete operation on C:\AdwCleaner\Logs\AdwCleaner_Debug.log in which the target location is user-controllable, allowing a non-admin user to escalate privileges to SYSTEM via a symbolic link.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xx2r-34w4-h84r

больше 3 лет назад

Microsoft Office 2013 and 2013 RT allows remote attackers to discover authentication tokens via a crafted response to a file-open request for an Office file on a web site, as exploited in the wild in 2013, aka "Token Hijacking Vulnerability."

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xx3c-ww24-2pgq

Template injection (Improper Neutralization of Special Elements Used in a Template Engine) vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series versions prior to Ver.2.9.40, Ver.2.10.x series versions prior to Ver.2.10.44, Ver.2.11.x series versions prior to Ver.2.11.42, and Ver.3.0.x series versions prior to Ver.3.0.1 allows a remote authenticated attacker to obtain an arbitrary file on the server via unspecified vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xx3c-6h6w-w5rg

JWT.php in F21 JWT before 2.0 allows remote attackers to bypass signature verification via crafted tokens.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-xx3c-35rv-h773

The (1) udp_recvmsg and (2) udpv6_recvmsg functions in the Linux kernel before 4.0.6 do not properly consider yielding a processor, which allows remote attackers to cause a denial of service (system hang) via incorrect checksums within a UDP packet flood.

21%
Средний
больше 3 лет назад
github логотип
GHSA-xx38-qpxm-6j8x

IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 on Linux, Solaris, and HP-UX, when a Local OS registry is used, does not properly validate user accounts, which allows remote attackers to bypass intended access restrictions via unspecified vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xx38-8wp6-c2jw

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, Safari 13.0.5, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. Processing maliciously crafted web content may lead to arbitrary code execution.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx36-85fv-r3w7

The dhcp.client program for QNX 4.25 vmware is setuid, possibly by default, which allows local users to modify the NIC configuration and conduct other attacks.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xx36-6rv4-gj8r

ecdsa-elixir fails to check signatures, vulnerable to message forging

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx34-wh4m-w39f

The AMaViS virus scanner 0.2.0-pre4 and earlier allows remote attackers to execute arbitrary commands as root via an infected mail message with shell metacharacters in the reply-to field.

3%
Низкий
почти 4 года назад
github логотип
GHSA-xx34-qq6x-qvv2

IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158880.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx33-j3mf-gffc

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function upgradeInfoRegister.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xx33-83f8-v2gp

The mintToken function of a smart contract implementation for loncoin (LON), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx33-73cr-ffp7

vmware-mount in VMware Workstation 8.x and 9.x and VMware Player 4.x and 5.x, on systems based on Debian GNU/Linux, allows host OS users to gain host OS privileges via a crafted lsb_release binary in a directory in the PATH, related to use of the popen library function.

6%
Низкий
больше 3 лет назад
github логотип
GHSA-xx33-26x2-m77p

In sourcecodetester Engineers Online Portal as of 10-21-21, an attacker can manipulate the Host header as seen by the web application and cause the application to behave in unexpected ways. Very often multiple websites are hosted on the same IP address. This is where the Host Header comes in. This header specifies which website should process the HTTP request. The web server uses the value of this header to dispatch the request to the specified website. Each website hosted on the same IP address is called a virtual host. And It's possible to send requests with arbitrary Host Headers to the first virtual host.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xx2w-rcmq-q3gc

Cross-Site Request Forgery (CSRF) vulnerability in Ciprian Popescu Block for Font Awesome.This issue affects Block for Font Awesome: from n/a through 1.4.0.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-xx2w-hg3f-6w9g

Xmind 2020 contains a cross-site scripting vulnerability that allows attackers to inject malicious payloads into mind mapping files or custom headers. Attackers can craft malicious files with embedded JavaScript that execute system commands when opened, enabling remote code execution through mouse interactions or file opening.

CVSS3: 6.1
0%
Низкий
21 день назад
github логотип
GHSA-xx2v-j2rm-5c42

TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanIp parameter’ of the setLanConfig interface of the cstecgi .cgi.

CVSS3: 9.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-xx2r-xrgj-fm3f

The vulnerability allows a remote attacker to inject arbitrary HTTP response headers or manipulate HTTP response bodies inside a victim’s session via a crafted URL or HTTP request.

CVSS3: 5.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-xx2r-x7vm-xjjj

A local authentication restriction bypass vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xx2r-f4xg-6rg7

Malwarebytes AdwCleaner 8.4.0 runs as Administrator and performs an insecure file delete operation on C:\AdwCleaner\Logs\AdwCleaner_Debug.log in which the target location is user-controllable, allowing a non-admin user to escalate privileges to SYSTEM via a symbolic link.

CVSS3: 7.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-xx2r-34w4-h84r

Microsoft Office 2013 and 2013 RT allows remote attackers to discover authentication tokens via a crafted response to a file-open request for an Office file on a web site, as exploited in the wild in 2013, aka "Token Hijacking Vulnerability."

11%
Средний
больше 3 лет назад

Уязвимостей на страницу