Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 360 872

Количество 360 872

github логотип

GHSA-xgf9-9fpj-mv3c

больше 4 лет назад

Heap-based buffer overflow in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xgf9-7jgm-fgxp

8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: usb: typec: altmodes/displayport: fix pin_assignment_show This patch fixes negative indexing of buf array in pin_assignment_show when get_current_pin_assignments returns 0 i.e. no compatible pin assignments are found. BUG: KASAN: use-after-free in pin_assignment_show+0x26c/0x33c ... Call trace: dump_backtrace+0x110/0x204 dump_stack_lvl+0x84/0xbc print_report+0x358/0x974 kasan_report+0x9c/0xfc __do_kernel_fault+0xd4/0x2d4 do_bad_area+0x48/0x168 do_tag_check_fault+0x24/0x38 do_mem_abort+0x6c/0x14c el1_abort+0x44/0x68 el1h_64_sync_handler+0x64/0xa4 el1h_64_sync+0x78/0x7c pin_assignment_show+0x26c/0x33c dev_attr_show+0x50/0xc0

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xgf9-6xh9-8mvh

больше 4 лет назад

Array index error in Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via crafted Shockwave content on a web site. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-xgf9-6mx9-6fv3

около 4 лет назад

IBM QRadar SIEM 7.3 and 7.4 when configured to use Active Directory Authentication may be susceptible to spoofing attacks. IBM X-Force ID: 165877.

EPSS: Низкий
github логотип

GHSA-xgf9-46hc-5c98

19 дней назад

The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX action that adds subscribers to the site owner's configured email service mailing lists, allowing unauthenticated attackers to enrol arbitrary email addresses into those lists using the owner's stored API credentials.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xgf8-98pj-cm5c

около 4 лет назад

An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValue call.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xgf8-6gvg-9rvw

больше 4 лет назад

A vulnerability in synotheme_upload.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to upload arbitrary files without authentication via the logo_upload action.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xgf8-49jx-rh6m

больше 4 лет назад

iMessage (Messages app) iOS 12.4 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xgf6-69f9-3847

больше 3 лет назад

Nokia OneNDS 17r2 has Insecure Permissions vulnerability that allows for privilege escalation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xgf6-3v64-jvfv

больше 4 лет назад

Vulnerability in the Oracle One-to-One Fulfillment component of Oracle E-Business Suite (subcomponent: Print Server). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle One-to-One Fulfillment. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle One-to-One Fulfillment, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle One-to-One Fulfillment accessible data as well as unauthorized update, insert or delete access to some of Oracle One-to-One Fulfillment accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xgf5-5gjr-4hjq

почти 6 лет назад

Directory Traversal in zjjserver

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xgf4-vh79-4g7j

почти 3 года назад

IBM Security Verify Privilege On-Premises 11.5 does not validate, or incorrectly validates, a certificate which could disclose sensitive information which could aid further attacks against the system. IBM X-Force ID: 240455.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-xgf4-g8fr-fcv9

7 месяцев назад

Authorization Bypass Through User-Controlled Key vulnerability in Wptexture Image Slider Slideshow allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Slider Slideshow: from n/a through 1.8.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xgf4-6mjg-7hqq

больше 3 лет назад

Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xgf3-qx4m-5q5j

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-topology: Fix input format query of process modules without base extension If a process module does not have base config extension then the same format applies to all of it's inputs and the process->base_config_ext is NULL, causing NULL dereference when specifically crafted topology and sequences used.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xgf3-6w37-8rhc

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.0 through 6.1.0.6 CF27, 6.1.5.0 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF28, and 8.0.0 before 8.0.0.1 CF12 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

EPSS: Низкий
github логотип

GHSA-xgf3-3873-jq4x

около 4 лет назад

The zoho-salesiq plugin before 1.0.9 for WordPress has CSRF.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xgf2-vxv2-rrmg

6 месяцев назад

OpenClaw's shell startup env injection bypasses system.run allowlist intent (RCE class)

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xgf2-5w76-r5jg

около 3 лет назад

Missing access permissions checks in M-Files Client before 23.5.12598.0 allows elevation of privilege via UI extension applications

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xgcx-vvr8-486q

больше 4 лет назад

In Joomla! 3.5.0 through 3.8.5, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the User Notes list view.

CVSS3: 8.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xgf9-9fpj-mv3c

Heap-based buffer overflow in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors.

CVSS3: 9.8
35%
Средний
больше 4 лет назад
github логотип
GHSA-xgf9-7jgm-fgxp

In the Linux kernel, the following vulnerability has been resolved: usb: typec: altmodes/displayport: fix pin_assignment_show This patch fixes negative indexing of buf array in pin_assignment_show when get_current_pin_assignments returns 0 i.e. no compatible pin assignments are found. BUG: KASAN: use-after-free in pin_assignment_show+0x26c/0x33c ... Call trace: dump_backtrace+0x110/0x204 dump_stack_lvl+0x84/0xbc print_report+0x358/0x974 kasan_report+0x9c/0xfc __do_kernel_fault+0xd4/0x2d4 do_bad_area+0x48/0x168 do_tag_check_fault+0x24/0x38 do_mem_abort+0x6c/0x14c el1_abort+0x44/0x68 el1h_64_sync_handler+0x64/0xa4 el1h_64_sync+0x78/0x7c pin_assignment_show+0x26c/0x33c dev_attr_show+0x50/0xc0

CVSS3: 7.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-xgf9-6xh9-8mvh

Array index error in Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via crafted Shockwave content on a web site. NOTE: some of these details are obtained from third party information.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-xgf9-6mx9-6fv3

IBM QRadar SIEM 7.3 and 7.4 when configured to use Active Directory Authentication may be susceptible to spoofing attacks. IBM X-Force ID: 165877.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xgf9-46hc-5c98

The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX action that adds subscribers to the site owner's configured email service mailing lists, allowing unauthenticated attackers to enrol arbitrary email addresses into those lists using the owner's stored API credentials.

CVSS3: 6.5
0%
Низкий
19 дней назад
github логотип
GHSA-xgf8-98pj-cm5c

An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValue call.

CVSS3: 9.1
2%
Низкий
около 4 лет назад
github логотип
GHSA-xgf8-6gvg-9rvw

A vulnerability in synotheme_upload.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to upload arbitrary files without authentication via the logo_upload action.

CVSS3: 9.8
16%
Средний
больше 4 лет назад
github логотип
GHSA-xgf8-49jx-rh6m

iMessage (Messages app) iOS 12.4 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xgf6-69f9-3847

Nokia OneNDS 17r2 has Insecure Permissions vulnerability that allows for privilege escalation.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xgf6-3v64-jvfv

Vulnerability in the Oracle One-to-One Fulfillment component of Oracle E-Business Suite (subcomponent: Print Server). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle One-to-One Fulfillment. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle One-to-One Fulfillment, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle One-to-One Fulfillment accessible data as well as unauthorized update, insert or delete access to some of Oracle One-to-One Fulfillment accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).

CVSS3: 7.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xgf5-5gjr-4hjq

Directory Traversal in zjjserver

CVSS3: 7.5
2%
Низкий
почти 6 лет назад
github логотип
GHSA-xgf4-vh79-4g7j

IBM Security Verify Privilege On-Premises 11.5 does not validate, or incorrectly validates, a certificate which could disclose sensitive information which could aid further attacks against the system. IBM X-Force ID: 240455.

CVSS3: 3.7
0%
Низкий
почти 3 года назад
github логотип
GHSA-xgf4-g8fr-fcv9

Authorization Bypass Through User-Controlled Key vulnerability in Wptexture Image Slider Slideshow allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Slider Slideshow: from n/a through 1.8.

CVSS3: 4.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-xgf4-6mjg-7hqq

Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xgf3-qx4m-5q5j

In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-topology: Fix input format query of process modules without base extension If a process module does not have base config extension then the same format applies to all of it's inputs and the process->base_config_ext is NULL, causing NULL dereference when specifically crafted topology and sequences used.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-xgf3-6w37-8rhc

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.0 through 6.1.0.6 CF27, 6.1.5.0 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF28, and 8.0.0 before 8.0.0.1 CF12 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xgf3-3873-jq4x

The zoho-salesiq plugin before 1.0.9 for WordPress has CSRF.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xgf2-vxv2-rrmg

OpenClaw's shell startup env injection bypasses system.run allowlist intent (RCE class)

CVSS3: 7.5
1%
Низкий
6 месяцев назад
github логотип
GHSA-xgf2-5w76-r5jg

Missing access permissions checks in M-Files Client before 23.5.12598.0 allows elevation of privilege via UI extension applications

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-xgcx-vvr8-486q

In Joomla! 3.5.0 through 3.8.5, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the User Notes list view.

CVSS3: 8.8
29%
Средний
больше 4 лет назад

Уязвимостей на страницу