Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 323 279

Количество 323 279

github логотип

GHSA-xx44-254w-m8vr

почти 4 года назад

A malicious or compromised UApp or ABL may be used by an attacker to send a malformed system call to the bootloader, resulting in out-of-bounds memory accesses.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xx43-h94m-wj64

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpsoul Greenshift allows Stored XSS. This issue affects Greenshift: from n/a through 11.0.2.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xx43-6j8m-vx2f

5 месяцев назад

Quipux 4.0.1 through e1774ac allows enumeration of usernames, and accessing the Ecuadorean identification number for all registered users via the Administracion/usuarios/cambiar_password_olvido_validar.php txt_login parameter.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xx42-xvv9-8p8p

почти 4 года назад

The compositor in Google Chrome before 22.0.1229.92 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xx3v-pjx9-qmj7

почти 4 года назад

Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The affected controllers utilize hard-coded credentials which may allow an attacker gain unauthorized access to the maintenance functions and obtain or modify information. This attack can be executed only during maintenance work.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xx3r-7m7h-68q2

почти 4 года назад

Siemens SIMATIC S7-300 Profinet-enabled CPU devices with firmware before 3.2.12 and SIMATIC S7-300 Profinet-disabled CPU devices with firmware before 3.3.12 allow remote attackers to cause a denial of service (defect-mode transition) via crafted (1) ISO-TSAP or (2) Profibus packets.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xx3r-74m7-rjg4

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: md/dm-raid: don't call md_reap_sync_thread() directly Currently md_reap_sync_thread() is called from raid_message() directly without holding 'reconfig_mutex', this is definitely unsafe because md_reap_sync_thread() can change many fields that is protected by 'reconfig_mutex'. However, hold 'reconfig_mutex' here is still problematic because this will cause deadlock, for example, commit 130443d60b1b ("md: refactor idle/frozen_sync_thread() to fix deadlock"). Fix this problem by using stop_sync_thread() to unregister sync_thread, like md/raid did.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xx3q-q45w-hjq8

7 месяцев назад

Group-Office versions prior to 6.8.119 and prior to 25.0.20 provided by Intermesh BV contain a path traversal vulnerability. If this vulnerability is exploited, information on the server hosting the product may be exposed.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xx3q-mvc5-c52f

почти 4 года назад

There is a NULL pointer dereference in the caseless_hash function in gxps-archive.c in libgxps 0.2.5. A crafted input will lead to a remote denial of service attack.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xx3p-ffq8-9pcp

почти 4 года назад

Icinga Web 2 has XSS via the /icingaweb2/monitoring/list/services dir parameter, the /icingaweb2/user/list query string, the /icingaweb2/monitoring/timeline query string, or the /icingaweb2/setup query string.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xx3p-5m4j-rhw8

больше 1 года назад

A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from a USB device. This flaw may allow a malicious unprivileged guest user to crash the QEMU process on the host and cause a denial of service condition.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-xx3m-p5mx-cgw5

около 4 лет назад

Grok 9.5.0 has a heap-based buffer overflow in openhtj2k::T1OpenHTJ2K::decompress (called from std::__1::__packaged_task_func<std::__1::__bind<grk::T1DecompressScheduler::deco and std::__1::packaged_task<int).

EPSS: Низкий
github логотип

GHSA-xx3m-g78m-fjqh

почти 4 года назад

Cross-site scripting (XSS) vulnerability in header.php in Ganglia Web 3.5.8 and 3.5.10 allows remote attackers to inject arbitrary web script or HTML via the host_regex parameter to the default URI, which is processed by get_context.php.

EPSS: Низкий
github логотип

GHSA-xx3m-f593-wg64

почти 4 года назад

time.htm in the web interface on SerVision HVG Video Gateway devices with firmware through 2.2.26a100 allows remote authenticated users to gain privileges by leveraging a cookie received in an HTTP response, a different vulnerability than CVE-2015-0929 and CVE-2015-0930.

EPSS: Низкий
github логотип

GHSA-xx3m-cmqv-q6w6

почти 4 года назад

An issue was discovered on Athom Homey and Homey Pro devices before 5.0.0. ZigBee hub devices should generate a unique Standard Network Key that is then exchanged with all enrolled devices so that all inter-device communication is encrypted. However, the cited Athom products use another widely known key that is designed for testing purposes: "01030507090b0d0f00020406080a0c0d" (the decimal equivalent of 1 3 5 7 9 11 13 15 0 2 4 6 8 10 12 13), which is human generated and static across all issued devices.

EPSS: Низкий
github логотип

GHSA-xx3m-8628-m9w5

почти 4 года назад

In Poppler 0.59.0, a floating point exception occurs in the ImageStream class in Stream.cc, which may lead to a potential attack when handling malicious PDF files.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xx3m-2jcf-frfq

больше 2 лет назад

IBM Content Navigator 3.0.13 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 259247.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xx3j-5qgj-ppv5

больше 1 года назад

Memory corruption when allocating and accessing an entry in an SMEM partition.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xx3h-j3cx-8qfj

больше 6 лет назад

Insufficient Entropy in DotNetNuke

CVSS3: 7.5
EPSS: Высокий
github логотип

GHSA-xx3h-9xgv-2q4v

почти 4 года назад

Directory traversal vulnerability in the modURL function in instance.c in Weborf before 0.12.3 allows remote attackers to read arbitrary files via ..%2f sequences in a URI.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xx44-254w-m8vr

A malicious or compromised UApp or ABL may be used by an attacker to send a malformed system call to the bootloader, resulting in out-of-bounds memory accesses.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xx43-h94m-wj64

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpsoul Greenshift allows Stored XSS. This issue affects Greenshift: from n/a through 11.0.2.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-xx43-6j8m-vx2f

Quipux 4.0.1 through e1774ac allows enumeration of usernames, and accessing the Ecuadorean identification number for all registered users via the Administracion/usuarios/cambiar_password_olvido_validar.php txt_login parameter.

CVSS3: 5.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-xx42-xvv9-8p8p

The compositor in Google Chrome before 22.0.1229.92 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xx3v-pjx9-qmj7

Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The affected controllers utilize hard-coded credentials which may allow an attacker gain unauthorized access to the maintenance functions and obtain or modify information. This attack can be executed only during maintenance work.

CVSS3: 8.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-xx3r-7m7h-68q2

Siemens SIMATIC S7-300 Profinet-enabled CPU devices with firmware before 3.2.12 and SIMATIC S7-300 Profinet-disabled CPU devices with firmware before 3.3.12 allow remote attackers to cause a denial of service (defect-mode transition) via crafted (1) ISO-TSAP or (2) Profibus packets.

CVSS3: 7.5
5%
Низкий
почти 4 года назад
github логотип
GHSA-xx3r-74m7-rjg4

In the Linux kernel, the following vulnerability has been resolved: md/dm-raid: don't call md_reap_sync_thread() directly Currently md_reap_sync_thread() is called from raid_message() directly without holding 'reconfig_mutex', this is definitely unsafe because md_reap_sync_thread() can change many fields that is protected by 'reconfig_mutex'. However, hold 'reconfig_mutex' here is still problematic because this will cause deadlock, for example, commit 130443d60b1b ("md: refactor idle/frozen_sync_thread() to fix deadlock"). Fix this problem by using stop_sync_thread() to unregister sync_thread, like md/raid did.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-xx3q-q45w-hjq8

Group-Office versions prior to 6.8.119 and prior to 25.0.20 provided by Intermesh BV contain a path traversal vulnerability. If this vulnerability is exploited, information on the server hosting the product may be exposed.

CVSS3: 4.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-xx3q-mvc5-c52f

There is a NULL pointer dereference in the caseless_hash function in gxps-archive.c in libgxps 0.2.5. A crafted input will lead to a remote denial of service attack.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-xx3p-ffq8-9pcp

Icinga Web 2 has XSS via the /icingaweb2/monitoring/list/services dir parameter, the /icingaweb2/user/list query string, the /icingaweb2/monitoring/timeline query string, or the /icingaweb2/setup query string.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-xx3p-5m4j-rhw8

A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from a USB device. This flaw may allow a malicious unprivileged guest user to crash the QEMU process on the host and cause a denial of service condition.

CVSS3: 4.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-xx3m-p5mx-cgw5

Grok 9.5.0 has a heap-based buffer overflow in openhtj2k::T1OpenHTJ2K::decompress (called from std::__1::__packaged_task_func<std::__1::__bind<grk::T1DecompressScheduler::deco and std::__1::packaged_task<int).

0%
Низкий
около 4 лет назад
github логотип
GHSA-xx3m-g78m-fjqh

Cross-site scripting (XSS) vulnerability in header.php in Ganglia Web 3.5.8 and 3.5.10 allows remote attackers to inject arbitrary web script or HTML via the host_regex parameter to the default URI, which is processed by get_context.php.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xx3m-f593-wg64

time.htm in the web interface on SerVision HVG Video Gateway devices with firmware through 2.2.26a100 allows remote authenticated users to gain privileges by leveraging a cookie received in an HTTP response, a different vulnerability than CVE-2015-0929 and CVE-2015-0930.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xx3m-cmqv-q6w6

An issue was discovered on Athom Homey and Homey Pro devices before 5.0.0. ZigBee hub devices should generate a unique Standard Network Key that is then exchanged with all enrolled devices so that all inter-device communication is encrypted. However, the cited Athom products use another widely known key that is designed for testing purposes: "01030507090b0d0f00020406080a0c0d" (the decimal equivalent of 1 3 5 7 9 11 13 15 0 2 4 6 8 10 12 13), which is human generated and static across all issued devices.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xx3m-8628-m9w5

In Poppler 0.59.0, a floating point exception occurs in the ImageStream class in Stream.cc, which may lead to a potential attack when handling malicious PDF files.

CVSS3: 7.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-xx3m-2jcf-frfq

IBM Content Navigator 3.0.13 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 259247.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xx3j-5qgj-ppv5

Memory corruption when allocating and accessing an entry in an SMEM partition.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-xx3h-j3cx-8qfj

Insufficient Entropy in DotNetNuke

CVSS3: 7.5
77%
Высокий
больше 6 лет назад
github логотип
GHSA-xx3h-9xgv-2q4v

Directory traversal vulnerability in the modURL function in instance.c in Weborf before 0.12.3 allows remote attackers to read arbitrary files via ..%2f sequences in a URI.

6%
Низкий
почти 4 года назад

Уязвимостей на страницу