unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
Live-Hack-CVE/CVE-2020-10056
A vulnerability has been identified in License Management Utility (LMU) (All versions < V2.4). The lmgrd service of the affected application is executed with local SYSTEM privileges on the server while its configuration can be modified by local users. The vulnerability could allow a local authenticated attacker to exec CVE project by @Sn0wAlice
Create: 2023-01-24 14:41:01 +0000 UTC Push: 2023-01-24 14:41:04 +0000 UTC |
Live-Hack-CVE/CVE-2013-0898
Use-after-free vulnerability in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a URL. CVE project by @Sn0wAlice
Create: 2023-01-24 14:40:56 +0000 UTC Push: 2023-01-24 14:41:00 +0000 UTC |
Live-Hack-CVE/CVE-2013-0880
Use-after-free vulnerability in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to databases. CVE project by @Sn0wAlice
Create: 2023-01-24 14:40:53 +0000 UTC Push: 2023-01-24 14:40:55 +0000 UTC |
Live-Hack-CVE/CVE-2020-5395
FontForge 20190801 has a use-after-free in SFD_GetFontMetaData in sfd.c. CVE project by @Sn0wAlice
Create: 2023-01-24 14:40:49 +0000 UTC Push: 2023-01-24 14:40:51 +0000 UTC |
Live-Hack-CVE/CVE-2020-5496
FontForge 20190801 has a heap-based buffer overflow in the Type2NotDefSplines() function in splinesave.c. CVE project by @Sn0wAlice
Create: 2023-01-24 14:40:46 +0000 UTC Push: 2023-01-24 14:40:48 +0000 UTC |
Live-Hack-CVE/CVE-2020-5497
The OpenID Connect reference implementation for MITREid Connect through 1.3.3 allows XSS due to userInfoJson being included in the page unsanitized. This is related to header.tag. The issue can be exploited to execute arbitrary JavaScript. CVE project by @Sn0wAlice
Create: 2023-01-24 14:40:42 +0000 UTC Push: 2023-01-24 14:40:44 +0000 UTC |
Live-Hack-CVE/CVE-2019-25044
The block subsystem in the Linux kernel before 5.2 has a use-after-free that can lead to arbitrary code execution in the kernel context and privilege escalation, aka CID-c3e2219216c9. This is related to blk_mq_free_rqs and blk_cleanup_queue. CVE project by @Sn0wAlice
Create: 2023-01-24 14:40:38 +0000 UTC Push: 2023-01-24 14:40:41 +0000 UTC |
Live-Hack-CVE/CVE-2013-7490
An issue was discovered in the DBI module before 1.632 for Perl. Using many arguments to methods for Callbacks may lead to memory corruption. CVE project by @Sn0wAlice
Create: 2023-01-24 14:40:35 +0000 UTC Push: 2023-01-24 14:40:37 +0000 UTC |
Live-Hack-CVE/CVE-2020-15094
In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on the HttpCache class to handle requests. HttpCache uses internal headers like X-Body-Eval and X-Body-File to control the restoration of cached responses. The class was initially written with surrogate CVE project by @Sn0wAlice
Create: 2023-01-24 14:40:31 +0000 UTC Push: 2023-01-24 14:40:33 +0000 UTC |
Live-Hack-CVE/CVE-2020-25269
An issue was discovered in InspIRCd 2 before 2.0.29 and 3 before 3.6.0. The pgsql module contains a use after free vulnerability. When combined with the sqlauth or sqloper modules, this vulnerability can be used for remote crashing of an InspIRCd server by any user able to connect to a server. CVE project by @Sn0wAlice
Create: 2023-01-24 14:40:28 +0000 UTC Push: 2023-01-24 14:40:30 +0000 UTC |
Live-Hack-CVE/CVE-2019-20382
QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a VNC disconnect operation because libz is misused, resulting in a situation where memory allocated in deflateInit2 is not freed in deflateEnd. CVE project by @Sn0wAlice
Create: 2023-01-24 14:40:24 +0000 UTC Push: 2023-01-24 14:40:26 +0000 UTC |
Live-Hack-CVE/CVE-2019-18860
Squid before 4.9, when certain web browsers are used, mishandles HTML in the host (aka hostname) parameter to cachemgr.cgi. CVE project by @Sn0wAlice
Create: 2023-01-24 14:40:20 +0000 UTC Push: 2023-01-24 14:40:23 +0000 UTC |
Live-Hack-CVE/CVE-2021-29024
In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing an attacker to directory traversal and download files suppose to be private without authentication. CVE project by @Sn0wAlice
Create: 2023-01-24 14:40:17 +0000 UTC Push: 2023-01-24 14:40:19 +0000 UTC |
Live-Hack-CVE/CVE-2022-45639
OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter. CVE project by @Sn0wAlice
Create: 2023-01-24 14:40:13 +0000 UTC Push: 2023-01-24 14:40:16 +0000 UTC |
Live-Hack-CVE/CVE-2020-24370
ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by getlocal(3,2^31). CVE project by @Sn0wAlice
Create: 2023-01-24 14:40:10 +0000 UTC Push: 2023-01-24 14:40:12 +0000 UTC |
Live-Hack-CVE/CVE-2020-14349
It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to CVE-2018-1058, in order to execute arbitrary SQL command in the context of the user used for replica CVE project by @Sn0wAlice
Create: 2023-01-24 14:40:06 +0000 UTC Push: 2023-01-24 14:40:08 +0000 UTC |
Live-Hack-CVE/CVE-2020-14350
It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privileges could use this flaw to trick an administrator into executing a specially crafted script, during the installation or update of such extension. This affects PostgreSQL versions CVE project by @Sn0wAlice
Create: 2023-01-24 14:40:02 +0000 UTC Push: 2023-01-24 14:40:05 +0000 UTC |
Live-Hack-CVE/CVE-2020-17353
scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and embedded-svg, as demonstrated by including dangerous PostScript code. CVE project by @Sn0wAlice
Create: 2023-01-24 14:39:59 +0000 UTC Push: 2023-01-24 14:40:01 +0000 UTC |
Live-Hack-CVE/CVE-2020-15701
An unhandled exception in check_ignored() in apport/report.py can be exploited by a local attacker to cause a denial of service. If the mtime attribute is a string value in apport-ignore.xml, it will trigger an unhandled exception, resulting in a crash. Fixed in 2.20.1-0ubuntu2.24, 2.20.9-0ubuntu7.16, 2.20.11-0ubuntu27 CVE project by @Sn0wAlice
Create: 2023-01-24 14:39:56 +0000 UTC Push: 2023-01-24 14:39:58 +0000 UTC |
Live-Hack-CVE/CVE-2020-17505
Artica Web Proxy 4.30.000000 allows an authenticated remote attacker to inject commands via the service-cmds parameter in cyrus.php. These commands are executed with root privileges via service_cmds_peform. CVE project by @Sn0wAlice
Create: 2023-01-24 14:39:52 +0000 UTC Push: 2023-01-24 14:39:54 +0000 UTC |
Previous
678
679
680
681
682
683
684
685
Next