Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 365 060

Количество 365 060

github логотип

GHSA-xxw3-cmrq-w3vh

больше 4 лет назад

An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-8149, CVE-2018-8156, CVE-2018-8168.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xxw3-765m-f37p

больше 4 лет назад

SaltStack Salt Improper Authentication vulnerability

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-xxw3-74wh-vcjp

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in detail.php in WEBBDOMAIN Multi Languages WebShop Online 1.02 allows remote attackers to inject arbitrary web script or HTML via the name parameter.

EPSS: Низкий
github логотип

GHSA-xxw2-vx44-7cv6

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: x86/mm: Eliminate window where TLB flushes may be inadvertently skipped tl;dr: There is a window in the mm switching code where the new CR3 is set and the CPU should be getting TLB flushes for the new mm. But should_flush_tlb() has a bug and suppresses the flush. Fix it by widening the window where should_flush_tlb() sends an IPI. Long Version: === History === There were a few things leading up to this. First, updating mm_cpumask() was observed to be too expensive, so it was made lazier. But being lazy caused too many unnecessary IPIs to CPUs due to the now-lazy mm_cpumask(). So code was added to cull mm_cpumask() periodically[2]. But that culling was a bit too aggressive and skipped sending TLB flushes to CPUs that need them. So here we are again. === Problem === The too-aggressive code in should_flush_tlb() strikes in this window: // Turn on IPIs for this CPU/mm combination, but only // if should_...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxw2-f852-rrc4

больше 4 лет назад

Use after free in Omnibox in Google Chrome prior to 97.0.4692.99 allowed an attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via a crafted HTML page.

EPSS: Низкий
github логотип

GHSA-xxw2-9c45-r2hr

6 месяцев назад

Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows unauthenticated users to enumerate existing hosts by observing different HTTP response codes in deploy_agent endpoint, which could lead to information disclosure.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xxvx-4jh7-w294

2 месяца назад

HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP address details within its generated server responses, which could allow a remote attacker to gather sensitive network topology information and use it to map the internal infrastructure for further targeted attacks.

CVSS3: 2.6
EPSS: Низкий
github логотип

GHSA-xxvw-xxhw-vp79

12 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: LoongArch: mm: Add p?d_leaf() definitions When I do LTP test, LTP test case ksm06 caused panic at break_ksm_pmd_entry -> pmd_leaf (Huge page table but False) -> pte_present (panic) The reason is pmd_leaf() is not defined, So like commit 501b81046701 ("mips: mm: add p?d_leaf() definitions") add p?d_leaf() definition for LoongArch.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxvw-mmrh-6cr5

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Add job to pending list if the reset was skipped When a CL/CSD job times out, we check if the GPU has made any progress since the last timeout. If so, instead of resetting the hardware, we skip the reset and let the timer get rearmed. This gives long-running jobs a chance to complete. However, when `timedout_job()` is called, the job in question is removed from the pending list, which means it won't be automatically freed through `free_job()`. Consequently, when we skip the reset and keep the job running, the job won't be freed when it finally completes. This situation leads to a memory leak, as exposed in [1] and [2]. Similarly to commit 704d3d60fec4 ("drm/etnaviv: don't block scheduler when GPU is still active"), this patch ensures the job is put back on the pending list when extending the timeout.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxvw-6qqh-qrjj

больше 1 года назад

Tenda W18E v2.0 v16.01.0.11 was discovered to contain a stack overflow in the wifiSSID parameter at /goform/setModules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xxvw-45rp-3mj2

почти 9 лет назад

Deserialization Code Execution in js-yaml

EPSS: Средний
github логотип

GHSA-xxvv-rw24-p2j6

больше 1 года назад

In JetBrains Toolbox App before 2.6 command injection in SSH plugin was possible

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-xxvr-rjcx-vqw8

2 месяца назад

Use after free in Ozone in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxvq-wr93-6r58

почти 3 года назад

Buffer overflow in some Intel(R) QAT drivers for Windows - HW Version 1.0 before version 1.10 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 7.9
EPSS: Низкий
github логотип

GHSA-xxvq-27rc-4q93

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users to gain elevated project privileges by requesting access to projects where role modifications during the approval process resulted in unintended permission grants.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-xxvp-3855-w9fv

больше 4 лет назад

Watchguard Firebox II allows remote attackers to cause a denial of service by establishing multiple connections and sending malformed PPTP packets.

EPSS: Низкий
github логотип

GHSA-xxvm-h45q-hvv9

больше 4 лет назад

CGI::Session 4.03-1 allows local users to overwrite arbitrary files via a symlink attack on temporary files used by (1) Driver::File, (2) Driver::db_file, and possibly (3) Driver::sqlite.

EPSS: Низкий
github логотип

GHSA-xxvm-h2mx-9mwj

почти 3 года назад

Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Title parameter in the Manage Shortcuts component.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xxvm-gxxx-r9pg

около 1 года назад

A vulnerability, which was classified as problematic, has been found in Open5GS up to 2.7.5. This issue affects the function amf_state_operational of the file src/amf/amf-sm.c of the component AMF Service. The manipulation leads to reachable assertion. It is possible to launch the attack on the local host. The identifier of the patch is 53e9e059ed96b940f7ddcd9a2b68cb512524d5db. It is recommended to apply a patch to fix this issue.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-xxvj-8g5m-4qgw

больше 4 лет назад

SaltStack Salt Directory traversal vulnerability in minion id validation

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xxw3-cmrq-w3vh

An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-8149, CVE-2018-8156, CVE-2018-8168.

CVSS3: 5.4
3%
Низкий
больше 4 лет назад
github логотип
GHSA-xxw3-765m-f37p

SaltStack Salt Improper Authentication vulnerability

CVSS3: 9.8
73%
Высокий
больше 4 лет назад
github логотип
GHSA-xxw3-74wh-vcjp

Cross-site scripting (XSS) vulnerability in detail.php in WEBBDOMAIN Multi Languages WebShop Online 1.02 allows remote attackers to inject arbitrary web script or HTML via the name parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xxw2-vx44-7cv6

In the Linux kernel, the following vulnerability has been resolved: x86/mm: Eliminate window where TLB flushes may be inadvertently skipped tl;dr: There is a window in the mm switching code where the new CR3 is set and the CPU should be getting TLB flushes for the new mm. But should_flush_tlb() has a bug and suppresses the flush. Fix it by widening the window where should_flush_tlb() sends an IPI. Long Version: === History === There were a few things leading up to this. First, updating mm_cpumask() was observed to be too expensive, so it was made lazier. But being lazy caused too many unnecessary IPIs to CPUs due to the now-lazy mm_cpumask(). So code was added to cull mm_cpumask() periodically[2]. But that culling was a bit too aggressive and skipped sending TLB flushes to CPUs that need them. So here we are again. === Problem === The too-aggressive code in should_flush_tlb() strikes in this window: // Turn on IPIs for this CPU/mm combination, but only // if should_...

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xxw2-f852-rrc4

Use after free in Omnibox in Google Chrome prior to 97.0.4692.99 allowed an attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via a crafted HTML page.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xxw2-9c45-r2hr

Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows unauthenticated users to enumerate existing hosts by observing different HTTP response codes in deploy_agent endpoint, which could lead to information disclosure.

CVSS3: 4.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-xxvx-4jh7-w294

HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP address details within its generated server responses, which could allow a remote attacker to gather sensitive network topology information and use it to map the internal infrastructure for further targeted attacks.

CVSS3: 2.6
0%
Низкий
2 месяца назад
github логотип
GHSA-xxvw-xxhw-vp79

In the Linux kernel, the following vulnerability has been resolved: LoongArch: mm: Add p?d_leaf() definitions When I do LTP test, LTP test case ksm06 caused panic at break_ksm_pmd_entry -> pmd_leaf (Huge page table but False) -> pte_present (panic) The reason is pmd_leaf() is not defined, So like commit 501b81046701 ("mips: mm: add p?d_leaf() definitions") add p?d_leaf() definition for LoongArch.

CVSS3: 5.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-xxvw-mmrh-6cr5

In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Add job to pending list if the reset was skipped When a CL/CSD job times out, we check if the GPU has made any progress since the last timeout. If so, instead of resetting the hardware, we skip the reset and let the timer get rearmed. This gives long-running jobs a chance to complete. However, when `timedout_job()` is called, the job in question is removed from the pending list, which means it won't be automatically freed through `free_job()`. Consequently, when we skip the reset and keep the job running, the job won't be freed when it finally completes. This situation leads to a memory leak, as exposed in [1] and [2]. Similarly to commit 704d3d60fec4 ("drm/etnaviv: don't block scheduler when GPU is still active"), this patch ensures the job is put back on the pending list when extending the timeout.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xxvw-6qqh-qrjj

Tenda W18E v2.0 v16.01.0.11 was discovered to contain a stack overflow in the wifiSSID parameter at /goform/setModules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xxvw-45rp-3mj2

Deserialization Code Execution in js-yaml

17%
Средний
почти 9 лет назад
github логотип
GHSA-xxvv-rw24-p2j6

In JetBrains Toolbox App before 2.6 command injection in SSH plugin was possible

CVSS3: 8.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-xxvr-rjcx-vqw8

Use after free in Ozone in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

CVSS3: 7.5
0%
Низкий
2 месяца назад
github логотип
GHSA-xxvq-wr93-6r58

Buffer overflow in some Intel(R) QAT drivers for Windows - HW Version 1.0 before version 1.10 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 7.9
0%
Низкий
почти 3 года назад
github логотип
GHSA-xxvq-27rc-4q93

An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users to gain elevated project privileges by requesting access to projects where role modifications during the approval process resulted in unintended permission grants.

CVSS3: 3.1
0%
Низкий
около 1 года назад
github логотип
GHSA-xxvp-3855-w9fv

Watchguard Firebox II allows remote attackers to cause a denial of service by establishing multiple connections and sending malformed PPTP packets.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xxvm-h45q-hvv9

CGI::Session 4.03-1 allows local users to overwrite arbitrary files via a symlink attack on temporary files used by (1) Driver::File, (2) Driver::db_file, and possibly (3) Driver::sqlite.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xxvm-h2mx-9mwj

Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Title parameter in the Manage Shortcuts component.

CVSS3: 5.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-xxvm-gxxx-r9pg

A vulnerability, which was classified as problematic, has been found in Open5GS up to 2.7.5. This issue affects the function amf_state_operational of the file src/amf/amf-sm.c of the component AMF Service. The manipulation leads to reachable assertion. It is possible to launch the attack on the local host. The identifier of the patch is 53e9e059ed96b940f7ddcd9a2b68cb512524d5db. It is recommended to apply a patch to fix this issue.

CVSS3: 3.3
0%
Низкий
около 1 года назад
github логотип
GHSA-xxvj-8g5m-4qgw

SaltStack Salt Directory traversal vulnerability in minion id validation

CVSS3: 9.8
5%
Низкий
больше 4 лет назад

Уязвимостей на страницу