Github Exploits

488 exploits tracked across all sources.

Sort: Activity Stars
CVE-2017-16939 GITHUB HIGH c
Linux kernel <4.13.11 - Privilege Escalation/DoS
The XFRM dump policy implementation in net/xfrm/xfrm_user.c in the Linux kernel before 4.13.11 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted SO_RCVBUF setsockopt system call in conjunction with XFRM_MSG_GETPOLICY Netlink messages.
by TamiiLambrado
3 stars
CVSS 7.8
CVE-2017-0576 GITHUB HIGH c
Linux Kernel - Integer Overflow in Qualcomm Crypto Engine Driver
An elevation of privilege vulnerability in the Qualcomm crypto engine driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33544431. References: QC-CR#1103089.
by derrekr
87 stars
CVSS 7.0
CVE-2017-0531 GITHUB MEDIUM c
Linux Kernel 3.10-3.18 - Information Disclosure via Qualcomm Wi-Fi Driver
An information disclosure vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32877245. References: QC-CR#1087469.
by derrekr
87 stars
CVSS 4.7
CVE-2017-0521 GITHUB HIGH c
Linux Kernel - Integer Overflow in Qualcomm Camera Driver
An elevation of privilege vulnerability in the Qualcomm camera driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32919951. References: QC-CR#1097709.
by derrekr
87 stars
CVSS 7.0
CVE-2017-0392 GITHUB MEDIUM c
Android 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1 - Denial of Service in VBRISeeker.cpp
A denial of service vulnerability in VBRISeeker.cpp in libstagefright in Mediaserver could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32577290.
by derrekr
87 stars
CVSS 5.5
CVE-2016-8477 GITHUB MEDIUM c
Android Kernel 3.10/3.18 - Info Disclosure
An information disclosure vulnerability in the Qualcomm camera driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32720522. References: QC-CR#1090007.
by derrekr
87 stars
CVSS 4.7
CVE-2016-8413 GITHUB MEDIUM c
Android Kernel 3.10/3.18 - Info Disclosure
An information disclosure vulnerability in the Qualcomm camera driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32709702. References: QC-CR#518731.
by derrekr
87 stars
CVSS 4.7
CVE-2015-7214 GITHUB c
Opensuse Leap < 42.0 - Information Disclosure
Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allow remote attackers to bypass the Same Origin Policy via data: and view-source: URIs.
by OpenSISE
31 stars
CVE-2012-1876 GITHUB c
Microsoft Internet Explorer 6-9 and 10 Consumer Preview - Remote Code Execution via Col Element Handling
Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by attempting to access a nonexistent object, leading to a heap-based buffer overflow, aka "Col Element Remote Code Execution Vulnerability," as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012.
by OpenSISE
31 stars
CVE-2015-6086 GITHUB c
Microsoft Internet Explorer <11 - Info Disclosure
Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."
by OpenSISE
31 stars
CVE-2012-4792 GITHUB HIGH c
Microsoft Internet Explorer <9 - Use After Free
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object, and exploited in the wild in December 2012.
by OpenSISE
31 stars
CVSS 8.8
CVE-2015-5119 GITHUB CRITICAL c
Adobe Flash Player ByteArray Use After Free
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.
by OpenSISE
31 stars
CVSS 9.8
CVE-2015-7547 GITHUB HIGH c
GNU C Library <2.23 - Buffer Overflow
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the getaddrinfo function with the AF_UNSPEC or AF_INET6 address family, related to performing "dual A/AAAA DNS queries" and the libnss_dns.so.2 NSS module.
by OpenSISE
31 stars
CVSS 8.1
CVE-2015-1701 GITHUB HIGH c
Microsoft Win32k - Privilege Escalation
Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in April 2015, aka "Win32k Elevation of Privilege Vulnerability."
by OpenSISE
31 stars
CVSS 7.8
CVE-2014-0038 GITHUB c
Linux Kernel recvmmsg Privilege Escalation
The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allows local users to gain privileges via a recvmmsg system call with a crafted timeout pointer parameter.
by OpenSISE
31 stars
CVE-2015-3636 GITHUB c
Linux kernel <4.0.3 - Use After Free
The ping_unhash function in net/ipv4/ping.c in the Linux kernel before 4.0.3 does not initialize a certain list data structure during an unhash operation, which allows local users to gain privileges or cause a denial of service (use-after-free and system crash) by leveraging the ability to make a SOCK_DGRAM socket system call for the IPPROTO_ICMP or IPPROTO_ICMPV6 protocol, and then making a connect system call after a disconnect.
by OpenSISE
31 stars
CVE-2016-5173 GITHUB HIGH c
Google Chrome < 53.0.2785.101 - Same Origin Policy Bypass via Object.prototype Access
The extensions subsystem in Google Chrome before 53.0.2785.113 does not properly restrict access to Object.prototype, which allows remote attackers to load unintended resources, and consequently trigger unintended JavaScript function calls and bypass the Same Origin Policy via an indirect interception attack.
by OpenSISE
31 stars
CVSS 7.1
CVE-2016-5160 GITHUB MEDIUM c
Opensuse Leap < 52.0.2743.116 - Security Feature Bypass
The AllowCrossRendererResourceLoad function in extensions/browser/url_request_util.cc in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly use an extension's manifest.json web_accessible_resources field for restrictions on IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks, and trick users into changing extension settings, via a crafted web site, a different vulnerability than CVE-2016-5162.
by OpenSISE
31 stars
CVSS 6.5
CVE-2016-5135 GITHUB MEDIUM c
Google Chrome < 51.0.2704.106 - Content Security Policy Bypass via Referrer Policy Mismatch
WebKit/Source/core/html/parser/HTMLPreloadScanner.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not consider referrer-policy information inside an HTML document during a preload request, which allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via a crafted web site, as demonstrated by a "Content-Security-Policy: referrer origin-when-cross-origin" header that overrides a "<META name='referrer' content='no-referrer'>" element.
by OpenSISE
31 stars
CVSS 6.5
CVE-2016-1701 GITHUB HIGH c
Google Chrome <51.0.2704.79 - Use After Free
The Autofill implementation in Google Chrome before 51.0.2704.79 mishandles the interaction between field updates and JavaScript code that triggers a frame deletion, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site, a different vulnerability than CVE-2016-1690.
by OpenSISE
31 stars
CVSS 8.8
CVE-2016-1700 GITHUB HIGH c
Google Chrome <51.0.2704.79 - Use After Free
extensions/renderer/runtime_custom_bindings.cc in Google Chrome before 51.0.2704.79 does not consider side effects during creation of an array of extension views, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors related to extensions.
by OpenSISE
31 stars
CVSS 7.5
CVE-2016-1699 GITHUB MEDIUM c
WebKit/Source/devtools/front_end/devtools.js - Info Disclosure
WebKit/Source/devtools/front_end/devtools.js in the Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 51.0.2704.79, does not ensure that the remoteFrontendUrl parameter is associated with a chrome-devtools-frontend.appspot.com URL, which allows remote attackers to bypass intended access restrictions via a crafted URL.
by OpenSISE
31 stars
CVSS 6.5
CVE-2016-1698 GITHUB MEDIUM c
Google Chrome <51.0.2704.79 - Code Injection
The createCustomType function in extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.79 does not validate module types, which might allow attackers to load arbitrary modules or obtain sensitive information by leveraging a poisoned definition.
by OpenSISE
31 stars
CVSS 6.5
CVE-2016-1697 GITHUB HIGH c
Google Chrome < 51.0.2704.79 - Same Origin Policy Bypass via Frame Navigation
The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 51.0.2704.79, does not prevent frame navigations during DocumentLoader detach operations, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.
by OpenSISE
31 stars
CVSS 8.8
CVE-2016-1691 GITHUB HIGH c
Skia <51.0.2704.63 - DoS
Skia, as used in Google Chrome before 51.0.2704.63, mishandles coincidence runs, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted curves, related to SkOpCoincidence.cpp and SkPathOpsCommon.cpp.
by OpenSISE
31 stars
CVSS 7.5