Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 289 803

Количество 289 803

github логотип

GHSA-xwmj-j245-94g9

больше 3 лет назад

The Quick Buttons feature in Konversation 0.15 allows remote attackers to execute certain IRC commands via a channel name containing "%" variables, which are recursively expanded by the Server::parseWildcards function when the Part Button is selected.

EPSS: Средний
github логотип

GHSA-xwmg-2g98-w7v9

около 1 месяца назад

Nimbus JOSE + JWT is vulnerable to DoS attacks when processing deeply nested JSON

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-xwmf-vq46-mhwp

больше 3 лет назад

Integer overflow in Adobe Shockwave Player before 11.5.7.609 might allow remote attackers to execute arbitrary code via a crafted .dir (aka Director) file.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-xwmc-cj49-wgpx

больше 3 лет назад

An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-8431.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xwm9-v4gv-cw38

больше 3 лет назад

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faulting Address controls Branch Selection starting at PDF!xmlParserInputRead+0x00000000001168a1."

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xwm9-c4jc-crcp

около 3 лет назад

A code execution vulnerability exists in the dwgCompressor::copyCompBytes21 functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dwg file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xwm9-3855-qxw3

больше 3 лет назад

Cross-Site Scripting (XSS) vulnerability has been identified in Micro Focus Operations Manager i, versions 10.60, 10.61, 10.62. The vulnerability could be remotely exploited to allow Cross-Site Scripting (XSS).

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xwm8-ff5h-57g6

больше 3 лет назад

Stack-based buffer overflow in the Core Foundation Library in Mac OS X 10.3.5 and 10.3.6, and possibly earlier versions, allows local users to execute arbitrary code via a long CF_CHARSET_PATH environment variable.

EPSS: Низкий
github логотип

GHSA-xwm8-c743-c377

больше 3 лет назад

SaltOS 3.1 r8126 allows action=login&querystring=&user=[SQL] SQL Injection.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xwm7-qf33-7c64

больше 3 лет назад

Xythos Enterprise Document Manager (XEDM), Digital Locker (XDL), and possibly WebFile Server before 6.0.46.1 allow remote authenticated users to associate arbitrary Content-Type HTTP headers with documents, which might facilitate malware distribution.

EPSS: Низкий
github логотип

GHSA-xwm7-6hf7-46pp

больше 3 лет назад

Buffer overflow in the legacy client support for AFP Server for Mac OS X 10.4.1 allows attackers to execute arbitrary code.

EPSS: Низкий
github логотип

GHSA-xwm6-w9x3-p4hx

больше 3 лет назад

Some Lenovo brand notebook systems do not have write protections properly configured in the system BIOS. This could enable an attacker with physical or administrative access to a system to be able to flash the BIOS with an arbitrary image and potentially run malicious BIOS code.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-xwm4-mmfg-2v6c

около 3 лет назад

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Windows DLL). The supported version that is affected is Java SE: 8u202. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. While the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/...

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-xwm4-79pm-f3fr

больше 3 лет назад

Integer overflow in Vertex4 SunAge 1.08.1 and earlier allows remote attackers to cause a denial of service (crash) via a crafted packet to UDP port 27960.

EPSS: Средний
github логотип

GHSA-xwm4-236h-gr55

10 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix command bitmask initialization Command bitmask have a dedicated bit for MANAGE_PAGES command, this bit isn't Initialize during command bitmask Initialization, only during MANAGE_PAGES. In addition, mlx5_cmd_trigger_completions() is trying to trigger completion for MANAGE_PAGES command as well. Hence, in case health error occurred before any MANAGE_PAGES command have been invoke (for example, during mlx5_enable_hca()), mlx5_cmd_trigger_completions() will try to trigger completion for MANAGE_PAGES command, which will result in null-ptr-deref error.[1] Fix it by Initialize command bitmask correctly. While at it, re-write the code for better understanding. [1] BUG: KASAN: null-ptr-deref in mlx5_cmd_trigger_completions+0x1db/0x600 [mlx5_core] Write of size 4 at addr 0000000000000214 by task kworker/u96:2/12078 CPU: 10 PID: 12078 Comm: kworker/u96:2 Not tainted 6.9.0-rc2_for_upstream_debug_2024_04_07_...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xwm2-hpp5-jvvm

около 2 лет назад

Cross Site Scripting vulnerability in taogogo taoCMS v.2.5 beta5.1 allows remote attacker to execute arbitrary code via the name field in admin.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xwjw-8w3g-468q

больше 3 лет назад

Unspecified vulnerability in the Widcomm Bluetooth stack allows remote attackers to gain administrative access (aka Remote Root) via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xwjw-8pxr-7xwf

почти 2 года назад

A cross-site scripting (XSS) vulnerability in /hoteldruid/clienti.php of Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the nometipotariffa1 parameter.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xwjw-7gc4-5h47

больше 3 лет назад

tog-pegasus in OpenGroup Pegasus 2.7.0 on Red Hat Enterprise Linux (RHEL) 5, Fedora 9, and Fedora 10 does not log failed authentication attempts to the OpenPegasus CIM server, which makes it easier for remote attackers to avoid detection of password guessing attacks.

EPSS: Низкий
github логотип

GHSA-xwjr-6fj7-fc6h

больше 4 лет назад

Local File Inclusion by unauthenticated users

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xwmj-j245-94g9

The Quick Buttons feature in Konversation 0.15 allows remote attackers to execute certain IRC commands via a channel name containing "%" variables, which are recursively expanded by the Server::parseWildcards function when the Part Button is selected.

15%
Средний
больше 3 лет назад
github логотип
GHSA-xwmg-2g98-w7v9

Nimbus JOSE + JWT is vulnerable to DoS attacks when processing deeply nested JSON

CVSS3: 5.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xwmf-vq46-mhwp

Integer overflow in Adobe Shockwave Player before 11.5.7.609 might allow remote attackers to execute arbitrary code via a crafted .dir (aka Director) file.

CVSS3: 8.8
12%
Средний
больше 3 лет назад
github логотип
GHSA-xwmc-cj49-wgpx

An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-8431.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xwm9-v4gv-cw38

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faulting Address controls Branch Selection starting at PDF!xmlParserInputRead+0x00000000001168a1."

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xwm9-c4jc-crcp

A code execution vulnerability exists in the dwgCompressor::copyCompBytes21 functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dwg file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

CVSS3: 8.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-xwm9-3855-qxw3

Cross-Site Scripting (XSS) vulnerability has been identified in Micro Focus Operations Manager i, versions 10.60, 10.61, 10.62. The vulnerability could be remotely exploited to allow Cross-Site Scripting (XSS).

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xwm8-ff5h-57g6

Stack-based buffer overflow in the Core Foundation Library in Mac OS X 10.3.5 and 10.3.6, and possibly earlier versions, allows local users to execute arbitrary code via a long CF_CHARSET_PATH environment variable.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xwm8-c743-c377

SaltOS 3.1 r8126 allows action=login&querystring=&user=[SQL] SQL Injection.

CVSS3: 9.8
4%
Низкий
больше 3 лет назад
github логотип
GHSA-xwm7-qf33-7c64

Xythos Enterprise Document Manager (XEDM), Digital Locker (XDL), and possibly WebFile Server before 6.0.46.1 allow remote authenticated users to associate arbitrary Content-Type HTTP headers with documents, which might facilitate malware distribution.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xwm7-6hf7-46pp

Buffer overflow in the legacy client support for AFP Server for Mac OS X 10.4.1 allows attackers to execute arbitrary code.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xwm6-w9x3-p4hx

Some Lenovo brand notebook systems do not have write protections properly configured in the system BIOS. This could enable an attacker with physical or administrative access to a system to be able to flash the BIOS with an arbitrary image and potentially run malicious BIOS code.

CVSS3: 6.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xwm4-mmfg-2v6c

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Windows DLL). The supported version that is affected is Java SE: 8u202. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. While the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/...

CVSS3: 9
1%
Низкий
около 3 лет назад
github логотип
GHSA-xwm4-79pm-f3fr

Integer overflow in Vertex4 SunAge 1.08.1 and earlier allows remote attackers to cause a denial of service (crash) via a crafted packet to UDP port 27960.

12%
Средний
больше 3 лет назад
github логотип
GHSA-xwm4-236h-gr55

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix command bitmask initialization Command bitmask have a dedicated bit for MANAGE_PAGES command, this bit isn't Initialize during command bitmask Initialization, only during MANAGE_PAGES. In addition, mlx5_cmd_trigger_completions() is trying to trigger completion for MANAGE_PAGES command as well. Hence, in case health error occurred before any MANAGE_PAGES command have been invoke (for example, during mlx5_enable_hca()), mlx5_cmd_trigger_completions() will try to trigger completion for MANAGE_PAGES command, which will result in null-ptr-deref error.[1] Fix it by Initialize command bitmask correctly. While at it, re-write the code for better understanding. [1] BUG: KASAN: null-ptr-deref in mlx5_cmd_trigger_completions+0x1db/0x600 [mlx5_core] Write of size 4 at addr 0000000000000214 by task kworker/u96:2/12078 CPU: 10 PID: 12078 Comm: kworker/u96:2 Not tainted 6.9.0-rc2_for_upstream_debug_2024_04_07_...

CVSS3: 5.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-xwm2-hpp5-jvvm

Cross Site Scripting vulnerability in taogogo taoCMS v.2.5 beta5.1 allows remote attacker to execute arbitrary code via the name field in admin.php.

CVSS3: 6.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-xwjw-8w3g-468q

Unspecified vulnerability in the Widcomm Bluetooth stack allows remote attackers to gain administrative access (aka Remote Root) via unspecified vectors.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xwjw-8pxr-7xwf

A cross-site scripting (XSS) vulnerability in /hoteldruid/clienti.php of Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the nometipotariffa1 parameter.

CVSS3: 5.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-xwjw-7gc4-5h47

tog-pegasus in OpenGroup Pegasus 2.7.0 on Red Hat Enterprise Linux (RHEL) 5, Fedora 9, and Fedora 10 does not log failed authentication attempts to the OpenPegasus CIM server, which makes it easier for remote attackers to avoid detection of password guessing attacks.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-xwjr-6fj7-fc6h

Local File Inclusion by unauthenticated users

CVSS3: 7.5
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу