Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 313 368

Количество 313 368

github логотип

GHSA-xx2q-9cgc-6xvc

больше 3 лет назад

The (1) v9fs_create and (2) v9fs_lcreate functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow local guest OS privileged users to cause a denial of service (file descriptor or memory consumption) via vectors related to an already in-use fid.

CVSS3: 6
EPSS: Низкий
github логотип

GHSA-xx2q-52g7-vmx5

почти 4 года назад

Cross-site scripting vulnerability in addevent.php in myEvent 1.x allows remote attackers to inject arbitrary web script or HTML via the event_desc parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-xx2p-7x2v-j239

больше 3 лет назад

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, tvOS 12.3, watchOS 5.2.1. A remote attacker may be able to cause arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-xx2p-5w38-cw49

почти 4 года назад

The scm_send function in the scm layer for Linux kernel 2.4.x up to 2.4.28, and 2.6.x up to 2.6.9, allows local users to cause a denial of service (system hang) via crafted auxiliary messages that are passed to the sendmsg function, which causes a deadlock condition.

EPSS: Низкий
github логотип

GHSA-xx2p-3xq8-p2xm

почти 4 года назад

The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file that triggers a free of invalid data.

EPSS: Низкий
github логотип

GHSA-xx2h-vg66-mpr3

больше 3 лет назад

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0890, CVE-2019-0891, CVE-2019-0893, CVE-2019-0894, CVE-2019-0895, CVE-2019-0896, CVE-2019-0897, CVE-2019-0898, CVE-2019-0899, CVE-2019-0900, CVE-2019-0901, CVE-2019-0902.

EPSS: Средний
github логотип

GHSA-xx2h-qwcv-vv5w

9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: arm64/crc-t10dif: fix use of out-of-scope array in crc_t10dif_arch() Fix a silly bug where an array was used outside of its scope.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xx2h-39g7-5x2c

почти 4 года назад

Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the "URL Decoding Zone Spoofing Vulnerability."

EPSS: Средний
github логотип

GHSA-xx2h-2hf5-v7vv

больше 3 лет назад

Liferay Portal and Liferay DXP May Reveal S3 Store's Proxy Password

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xx2g-w5xg-2w3f

больше 3 лет назад

ServiceNow through San Diego Patch 4b and Patch 6 allows reflected XSS in the logout functionality.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-xx2g-p975-mwgc

14 дней назад

In the Linux kernel, the following vulnerability has been resolved: gpio: mpsse: ensure worker is torn down When an IRQ worker is running, unplugging the device would cause a crash. The sealevel hardware this driver was written for was not hotpluggable, so I never realized it. This change uses a spinlock to protect a list of workers, which it tears down on disconnect.

EPSS: Низкий
github логотип

GHSA-xx2f-m35m-cqwx

больше 3 лет назад

In start of WelcomeActivity.java, there is a possible residual profile due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-9Android ID: A-172322502

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xx29-p5f4-mwr8

больше 3 лет назад

D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_save configBackup or downloadServerip parameter.

CVSS3: 7.8
EPSS: Критический
github логотип

GHSA-xx29-5p54-f7qq

больше 3 лет назад

In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112892194

EPSS: Низкий
github логотип

GHSA-xx28-hqvc-mm7j

около 1 года назад

Cross Site Scripting vulnerability in Cyber Cafe Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted script to the adminname parameter.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xx28-7x9q-6ch2

почти 4 года назад

index.php in myBloggie 2.1.1 allows remote attackers to obtain sensitive information via an invalid post_id parameter, which reveals the path in an error message.

EPSS: Низкий
github логотип

GHSA-xx27-x5jh-mcrm

больше 3 лет назад

In resolv_cache_lookup of res_cache.cpp, there is a possible side channel information disclosure. This could lead to local information disclosure of accessed web resources with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-150371903

EPSS: Низкий
github логотип

GHSA-xx27-vcf5-wm84

больше 3 лет назад

Wrong public key usage from existing oem_keystore for hash generation in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, MDM9206, MDM9207C, MDM9607, MDM9650, MSM8905, MSM8909W, MSM8917, MSM8953, MSM8996AU, QM215, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDX20

EPSS: Низкий
github логотип

GHSA-xx25-w9gj-928r

почти 4 года назад

A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the updateVersion function in /cgi-bin/luci/api/wireless.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-xx24-r484-7p82

около 1 года назад

There is an out-of-bound read and write vulnerability in Huawei smartphone. A module dose not verify the input sufficiently. Attackers can exploit this vulnerability by modifying some configuration to cause out-of-bound read and write, causing denial of service. (Vulnerability ID: HWPSIRT-2020-05103) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9211.

CVSS3: 6.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xx2q-9cgc-6xvc

The (1) v9fs_create and (2) v9fs_lcreate functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow local guest OS privileged users to cause a denial of service (file descriptor or memory consumption) via vectors related to an already in-use fid.

CVSS3: 6
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx2q-52g7-vmx5

Cross-site scripting vulnerability in addevent.php in myEvent 1.x allows remote attackers to inject arbitrary web script or HTML via the event_desc parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xx2p-7x2v-j239

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, tvOS 12.3, watchOS 5.2.1. A remote attacker may be able to cause arbitrary code execution.

4%
Низкий
больше 3 лет назад
github логотип
GHSA-xx2p-5w38-cw49

The scm_send function in the scm layer for Linux kernel 2.4.x up to 2.4.28, and 2.6.x up to 2.6.9, allows local users to cause a denial of service (system hang) via crafted auxiliary messages that are passed to the sendmsg function, which causes a deadlock condition.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xx2p-3xq8-p2xm

The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file that triggers a free of invalid data.

5%
Низкий
почти 4 года назад
github логотип
GHSA-xx2h-vg66-mpr3

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0890, CVE-2019-0891, CVE-2019-0893, CVE-2019-0894, CVE-2019-0895, CVE-2019-0896, CVE-2019-0897, CVE-2019-0898, CVE-2019-0899, CVE-2019-0900, CVE-2019-0901, CVE-2019-0902.

28%
Средний
больше 3 лет назад
github логотип
GHSA-xx2h-qwcv-vv5w

In the Linux kernel, the following vulnerability has been resolved: arm64/crc-t10dif: fix use of out-of-scope array in crc_t10dif_arch() Fix a silly bug where an array was used outside of its scope.

CVSS3: 5.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-xx2h-39g7-5x2c

Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the "URL Decoding Zone Spoofing Vulnerability."

35%
Средний
почти 4 года назад
github логотип
GHSA-xx2h-2hf5-v7vv

Liferay Portal and Liferay DXP May Reveal S3 Store's Proxy Password

CVSS3: 5.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx2g-w5xg-2w3f

ServiceNow through San Diego Patch 4b and Patch 6 allows reflected XSS in the logout functionality.

CVSS3: 6.1
29%
Средний
больше 3 лет назад
github логотип
GHSA-xx2g-p975-mwgc

In the Linux kernel, the following vulnerability has been resolved: gpio: mpsse: ensure worker is torn down When an IRQ worker is running, unplugging the device would cause a crash. The sealevel hardware this driver was written for was not hotpluggable, so I never realized it. This change uses a spinlock to protect a list of workers, which it tears down on disconnect.

0%
Низкий
14 дней назад
github логотип
GHSA-xx2f-m35m-cqwx

In start of WelcomeActivity.java, there is a possible residual profile due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-9Android ID: A-172322502

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx29-p5f4-mwr8

D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_save configBackup or downloadServerip parameter.

CVSS3: 7.8
92%
Критический
больше 3 лет назад
github логотип
GHSA-xx29-5p54-f7qq

In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112892194

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx28-hqvc-mm7j

Cross Site Scripting vulnerability in Cyber Cafe Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted script to the adminname parameter.

CVSS3: 4.8
0%
Низкий
около 1 года назад
github логотип
GHSA-xx28-7x9q-6ch2

index.php in myBloggie 2.1.1 allows remote attackers to obtain sensitive information via an invalid post_id parameter, which reveals the path in an error message.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xx27-x5jh-mcrm

In resolv_cache_lookup of res_cache.cpp, there is a possible side channel information disclosure. This could lead to local information disclosure of accessed web resources with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-150371903

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx27-vcf5-wm84

Wrong public key usage from existing oem_keystore for hash generation in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, MDM9206, MDM9207C, MDM9607, MDM9650, MSM8905, MSM8909W, MSM8917, MSM8953, MSM8996AU, QM215, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDX20

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx25-w9gj-928r

A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the updateVersion function in /cgi-bin/luci/api/wireless.

CVSS3: 8.8
26%
Средний
почти 4 года назад
github логотип
GHSA-xx24-r484-7p82

There is an out-of-bound read and write vulnerability in Huawei smartphone. A module dose not verify the input sufficiently. Attackers can exploit this vulnerability by modifying some configuration to cause out-of-bound read and write, causing denial of service. (Vulnerability ID: HWPSIRT-2020-05103) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9211.

CVSS3: 6.4
0%
Низкий
около 1 года назад

Уязвимостей на страницу