Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 360 872

Количество 360 872

github логотип

GHSA-xg8p-34w2-j49j

почти 4 года назад

linked_list_allocator vulnerable to out-of-bound writes on `Heap` initialization and `Heap::extend`

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-xg8m-gfp3-4fv6

около 4 лет назад

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Wiki was vulnerable to a parser attack that prohibits anyone from accessing the Wiki functionality through the user interface.

EPSS: Низкий
github логотип

GHSA-xg8m-cjfg-g3jw

12 месяцев назад

Missing Authorization vulnerability in ThemeArile Consultstreet allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Consultstreet: from n/a through 3.0.0.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xg8m-56gm-9394

6 дней назад

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-xg8m-4qxg-vm4m

больше 3 лет назад

An issue has been discovered in GitLab affecting versions starting from 15.1 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. A maintainer could modify a webhook URL to leak masked webhook secrets by adding a new parameter to the url. This addresses an incomplete fix for CVE-2022-4342.

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-xg8m-385j-rc99

больше 4 лет назад

In HID_DevAddRecord of hidd_api.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege in the Bluetooth service with User execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-79946737.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xg8j-j6vp-6h5w

около 1 года назад

Apache Zeppelin: Missing Origin Validation in WebSockets vulnerability

EPSS: Низкий
github логотип

GHSA-xg8j-6m35-m6wr

около 1 месяца назад

Grav before 2.0.2 contains a Twig sandbox bypass that allows a page author (any admin.pages user, or anyone able to write to user/pages) to exfiltrate configuration secrets. Although the sandbox replaces the 'config' variable with a redacted facade and strips Config::get/toArray from the method allowlist, the raw container remains accessible via the allow-listed grav.offsetGet('config'), which returns the real Config object. Allow-listed object-dumping filters (json_encode, print_r, yaml_encode) then serialize that object at the PHP level without invoking the sandbox method gate, exposing the full config tree including plugin secrets such as SMTP credentials, API keys, and plugin DB credentials. This is an incomplete fix for GHSA-j274-39qw-32c9.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xg8h-q2h5-gj77

около 4 лет назад

Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Labor Distribution. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Labor Distribution accessible data as well as unauthorized access to critical data or complete access to all Oracle Labor Distribution accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

EPSS: Низкий
github логотип

GHSA-xg8h-j46f-w952

около 1 года назад

Pillow vulnerability can cause write buffer overflow on BCn encoding

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xg8h-h4cf-qvvx

около 4 лет назад

HomeAutomation 3.3.2 suffers from an authentication bypass vulnerability when spoofing client IP address using the X-Forwarded-For header with the local (loopback) IP address value allowing remote control of the smart home solution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xg8h-3f53-j5px

около 4 лет назад

The NAAS 3.x before 3.10.0 API keys were generated using an insecure pseudo-random string and hashing algorithm which could lead to predictable keys.

EPSS: Низкий
github логотип

GHSA-xg8h-3f4m-39v6

около 1 месяца назад

A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by these packages execute files marked as executable when the mailcap package is installed. A compromised or malicious sandboxed application with access to the OpenURI portal via xdg-desktop-portal-gtk can write a malicious .jar file to the host file system, set its executable bit, and trigger the handler to execute arbitrary code outside of the sandbox environment.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xg8h-2cqp-4x5f

около 4 лет назад

The function AdminGetFirstFileContentByFilePath in MIK.starlight 7.9.5.24363 allows (by design) an authenticated attacker to read arbitrary files from the filesystem by specifying the file path.

EPSS: Низкий
github логотип

GHSA-xg8f-g55r-6q3h

10 месяцев назад

Deserialization of Untrusted Data vulnerability in VictorThemes Seil seil allows Object Injection.This issue affects Seil: from n/a through <= 1.7.1.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xg8c-mw7j-wcv9

около 4 лет назад

On version 16.0.x before 16.0.1.2, insufficient permission checks may allow authenticated users with guest privileges to perform Server-Side Request Forgery (SSRF) attacks through F5 Advanced Web Application Firewall (WAF) and the BIG-IP ASM Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

EPSS: Низкий
github логотип

GHSA-xg8c-hf2j-jjw5

3 месяца назад

A weakness has been identified in Open5GS up to 2.7.7. Impacted is the function ogs_nnrf_nfm_handle_nf_profile of the file lib/sbi/nnrf-handler.c of the component NRF. This manipulation causes denial of service. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The pull request to fix this issue awaits acceptance.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xg8c-2xjc-w37r

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the Administrative Console in CA Arcot WebFort Versatile Authentication Server (VAS) before 6.2.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xg89-vvwp-9c27

больше 3 лет назад

Exposure of Sensitive Information in OpenGoofy Hippo4j

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xg89-j94m-h233

больше 4 лет назад

The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 sets the Cache-Control header to cache session cookies when a user is autocreated, which allows remote attackers to authenticate as the created user.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xg8p-34w2-j49j

linked_list_allocator vulnerable to out-of-bound writes on `Heap` initialization and `Heap::extend`

CVSS3: 8.4
1%
Низкий
почти 4 года назад
github логотип
GHSA-xg8m-gfp3-4fv6

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Wiki was vulnerable to a parser attack that prohibits anyone from accessing the Wiki functionality through the user interface.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xg8m-cjfg-g3jw

Missing Authorization vulnerability in ThemeArile Consultstreet allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Consultstreet: from n/a through 3.0.0.

CVSS3: 4.3
0%
Низкий
12 месяцев назад
github логотип
GHSA-xg8m-56gm-9394

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.

CVSS3: 8.6
0%
Низкий
6 дней назад
github логотип
GHSA-xg8m-4qxg-vm4m

An issue has been discovered in GitLab affecting versions starting from 15.1 before 15.8.5, 15.9 before 15.9.4, and 15.10 before 15.10.1. A maintainer could modify a webhook URL to leak masked webhook secrets by adding a new parameter to the url. This addresses an incomplete fix for CVE-2022-4342.

CVSS3: 3.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xg8m-385j-rc99

In HID_DevAddRecord of hidd_api.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege in the Bluetooth service with User execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-79946737.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xg8j-j6vp-6h5w

Apache Zeppelin: Missing Origin Validation in WebSockets vulnerability

0%
Низкий
около 1 года назад
github логотип
GHSA-xg8j-6m35-m6wr

Grav before 2.0.2 contains a Twig sandbox bypass that allows a page author (any admin.pages user, or anyone able to write to user/pages) to exfiltrate configuration secrets. Although the sandbox replaces the 'config' variable with a redacted facade and strips Config::get/toArray from the method allowlist, the raw container remains accessible via the allow-listed grav.offsetGet('config'), which returns the real Config object. Allow-listed object-dumping filters (json_encode, print_r, yaml_encode) then serialize that object at the PHP level without invoking the sandbox method gate, exposing the full config tree including plugin secrets such as SMTP credentials, API keys, and plugin DB credentials. This is an incomplete fix for GHSA-j274-39qw-32c9.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xg8h-q2h5-gj77

Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Labor Distribution. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Labor Distribution accessible data as well as unauthorized access to critical data or complete access to all Oracle Labor Distribution accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

1%
Низкий
около 4 лет назад
github логотип
GHSA-xg8h-j46f-w952

Pillow vulnerability can cause write buffer overflow on BCn encoding

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-xg8h-h4cf-qvvx

HomeAutomation 3.3.2 suffers from an authentication bypass vulnerability when spoofing client IP address using the X-Forwarded-For header with the local (loopback) IP address value allowing remote control of the smart home solution.

CVSS3: 9.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-xg8h-3f53-j5px

The NAAS 3.x before 3.10.0 API keys were generated using an insecure pseudo-random string and hashing algorithm which could lead to predictable keys.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xg8h-3f4m-39v6

A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by these packages execute files marked as executable when the mailcap package is installed. A compromised or malicious sandboxed application with access to the OpenURI portal via xdg-desktop-portal-gtk can write a malicious .jar file to the host file system, set its executable bit, and trigger the handler to execute arbitrary code outside of the sandbox environment.

CVSS3: 8.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xg8h-2cqp-4x5f

The function AdminGetFirstFileContentByFilePath in MIK.starlight 7.9.5.24363 allows (by design) an authenticated attacker to read arbitrary files from the filesystem by specifying the file path.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xg8f-g55r-6q3h

Deserialization of Untrusted Data vulnerability in VictorThemes Seil seil allows Object Injection.This issue affects Seil: from n/a through <= 1.7.1.

CVSS3: 9.8
0%
Низкий
10 месяцев назад
github логотип
GHSA-xg8c-mw7j-wcv9

On version 16.0.x before 16.0.1.2, insufficient permission checks may allow authenticated users with guest privileges to perform Server-Side Request Forgery (SSRF) attacks through F5 Advanced Web Application Firewall (WAF) and the BIG-IP ASM Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xg8c-hf2j-jjw5

A weakness has been identified in Open5GS up to 2.7.7. Impacted is the function ogs_nnrf_nfm_handle_nf_profile of the file lib/sbi/nnrf-handler.c of the component NRF. This manipulation causes denial of service. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The pull request to fix this issue awaits acceptance.

CVSS3: 4.3
0%
Низкий
3 месяца назад
github логотип
GHSA-xg8c-2xjc-w37r

Multiple cross-site scripting (XSS) vulnerabilities in the Administrative Console in CA Arcot WebFort Versatile Authentication Server (VAS) before 6.2.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xg89-vvwp-9c27

Exposure of Sensitive Information in OpenGoofy Hippo4j

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xg89-j94m-h233

The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 sets the Cache-Control header to cache session cookies when a user is autocreated, which allows remote attackers to authenticate as the created user.

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу