unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
Live-Hack-CVE/CVE-2022-47927
An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. When installing with a pre-existing data directory that has weak permissions, the SQLite files are created with file mode 0644, i.e., world readable to local users. These files include credentials data. CVE project by @Sn0wAlice
Create: 2023-01-12 19:28:02 +0000 UTC Push: 2023-01-12 19:28:05 +0000 UTC |
Live-Hack-CVE/CVE-2023-23455
atm_tc_enqueue in net/sched/sch_atm.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather than valid classification results). CVE project by @Sn0wAlice
Create: 2023-01-12 19:27:57 +0000 UTC Push: 2023-01-12 19:28:01 +0000 UTC |
Live-Hack-CVE/CVE-2023-23454
cbq_classify in net/sched/sch_cbq.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service (slab-out-of-bounds read) because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather than valid classification results). CVE project by @Sn0wAlice
Create: 2023-01-12 19:27:53 +0000 UTC Push: 2023-01-12 19:27:56 +0000 UTC |
Live-Hack-CVE/CVE-2022-3715
A flaw was found in the bash package, where a heap-buffer overflow can occur in valid parameter_transform. This issue may lead to memory problems. CVE project by @Sn0wAlice
Create: 2023-01-12 15:05:59 +0000 UTC Push: 2023-01-12 15:06:02 +0000 UTC |
Live-Hack-CVE/CVE-2021-43797
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. Netty prior to version 4.1.71.Final skips control chars when they are present at the beginning / end of the header name. It should instead fail fast as these are not all CVE project by @Sn0wAlice
Create: 2023-01-12 15:05:53 +0000 UTC Push: 2023-01-12 15:05:56 +0000 UTC |
Live-Hack-CVE/CVE-2023-0042
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2. GitLab Pages allows redirection to arbitrary protocols. CVE project by @Sn0wAlice
Create: 2023-01-12 15:05:43 +0000 UTC Push: 2023-01-12 15:05:47 +0000 UTC |
Live-Hack-CVE/CVE-2022-4365
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A malicious Maintainer can leak the sentry token by changing the configured URL in the Sentry error tracking settings page. CVE project by @Sn0wAlice
Create: 2023-01-12 15:05:39 +0000 UTC Push: 2023-01-12 15:05:41 +0000 UTC |
Live-Hack-CVE/CVE-2022-4345
Infinite loops in the BPv6, OpenFlow, and Kafka protocol dissectors in Wireshark 4.0.0 to 4.0.1 and 3.6.0 to 3.6.9 allows denial of service via packet injection or crafted capture file CVE project by @Sn0wAlice
Create: 2023-01-12 15:05:34 +0000 UTC Push: 2023-01-12 15:05:37 +0000 UTC |
Live-Hack-CVE/CVE-2022-4342
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A malicious Maintainer can leak masked webhook secrets by changing target URL of the webhook. CVE project by @Sn0wAlice
Create: 2023-01-12 15:05:30 +0000 UTC Push: 2023-01-12 15:05:33 +0000 UTC |
Live-Hack-CVE/CVE-2022-4167
Incorrect Authorization check affecting all versions of GitLab EE from 13.11 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2 allows group access tokens to continue working even after the group owner loses the ability to revoke them. CVE project by @Sn0wAlice
Create: 2023-01-12 15:05:25 +0000 UTC Push: 2023-01-12 15:05:28 +0000 UTC |
Live-Hack-CVE/CVE-2022-4131
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.8 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. An attacker may cause Denial of Service on a GitLab instance by exploiting a regex issue in how the application parses user CVE project by @Sn0wAlice
Create: 2023-01-12 15:05:21 +0000 UTC Push: 2023-01-12 15:05:24 +0000 UTC |
Live-Hack-CVE/CVE-2022-4037
An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A race condition can lead to verified email forgery and takeover of third-party accounts when using GitLab as an OAuth provider. CVE project by @Sn0wAlice
Create: 2023-01-12 15:05:17 +0000 UTC Push: 2023-01-12 15:05:20 +0000 UTC |
Live-Hack-CVE/CVE-2022-3870
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. GitLab allows unauthenticated users to download user avatars using the victim's user ID, on private instances that restrict CVE project by @Sn0wAlice
Create: 2023-01-12 15:05:12 +0000 UTC Push: 2023-01-12 15:05:16 +0000 UTC |
Live-Hack-CVE/CVE-2022-3613
An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A crafted Prometheus Server query can cause high resource consumption and may lead to Denial of Service. CVE project by @Sn0wAlice
Create: 2023-01-12 15:05:08 +0000 UTC Push: 2023-01-12 15:05:11 +0000 UTC |
Live-Hack-CVE/CVE-2022-3573
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. Due to the improper filtering of query parameters in the wiki changes page, an attacker can execute arbitrary JavaScript on CVE project by @Sn0wAlice
Create: 2023-01-12 15:05:04 +0000 UTC Push: 2023-01-12 15:05:07 +0000 UTC |
Live-Hack-CVE/CVE-2022-3514
An issue has been discovered in GitLab CE/EE affecting all versions starting from 6.6 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. An attacker may cause Denial of Service on a GitLab instance by exploiting a regex issue in the submodule URL parser. CVE project by @Sn0wAlice
Create: 2023-01-12 15:04:59 +0000 UTC Push: 2023-01-12 15:05:02 +0000 UTC |
Live-Hack-CVE/CVE-2022-24913
Versions of the package com.fasterxml.util:java-merge-sort before 1.1.0 are vulnerable to Insecure Temporary File in the StdTempFileProvider() function in StdTempFileProvider.java, which uses the permissive File.createTempFile() function, exposing temporary file contents. CVE project by @Sn0wAlice
Create: 2023-01-12 15:04:55 +0000 UTC Push: 2023-01-12 15:04:58 +0000 UTC |
Live-Hack-CVE/CVE-2022-4344
Memory exhaustion in the Kafka protocol dissector in Wireshark 4.0.0 to 4.0.1 and 3.6.0 to 3.6.9 allows denial of service via packet injection or crafted capture file CVE project by @Sn0wAlice
Create: 2023-01-12 09:32:33 +0000 UTC Push: 2023-01-12 09:32:37 +0000 UTC |
Live-Hack-CVE/CVE-2017-14454
Multiple exploitable buffer overflow vulnerabilities exists in the PubNub message handler for the "control" channel of Insteon Hub running firmware version 1012. Specially crafted replies received from the PubNub service can cause buffer overflows on a global section overwriting arbitrary data. An attacker should imper CVE project by @Sn0wAlice
Create: 2023-01-12 09:32:29 +0000 UTC Push: 2023-01-12 09:32:32 +0000 UTC |
Live-Hack-CVE/CVE-2017-16309
Multiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. An attacker should send an authentica CVE project by @Sn0wAlice
Create: 2023-01-12 07:19:21 +0000 UTC Push: 2023-01-12 07:19:23 +0000 UTC |
Previous
724
725
726
727
728
729
730
731
Next