Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-xwv6-v7qx-f5jc

больше 4 лет назад

Code injection in ezsystems/ezpublish-kernel

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xwv5-74wf-vr6h

около 1 года назад

There is an out of bounds write vulnerability due to improper bounds checking resulting in an invalid address when parsing a DSB file with Digilent DASYLab. This vulnerability may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted DSB file. The vulnerability affects all versions of DASYLab.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xwv4-vj99-cxxj

11 месяцев назад

M365 Copilot Spoofing Vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xwv4-ppgv-h9j7

больше 4 лет назад

Symantec IT Analytics, prior to 2.9.1, may be susceptible to a cross-site scripting (XSS) exploit, which is a type of issue that can potentially enable attackers to inject client-side scripts into web pages viewed by other users.

EPSS: Низкий
github логотип

GHSA-xwv4-jx2p-x8xw

3 месяца назад

The CodePeople Post Map for Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cpm_point' Post Meta in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-xwv4-cq25-qmfg

больше 4 лет назад

Liblouis 3.5.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xwv4-chgp-x89p

почти 2 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hyumika OSM – OpenStreetMap allows Stored XSS.This issue affects OSM – OpenStreetMap: from n/a through 6.1.2.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xwv3-xrx8-63rf

больше 4 лет назад

A missing bounds check in WhatsApp for Android prior to v2.21.1.13 and WhatsApp Business for Android prior to v2.21.1.13 could have allowed out-of-bounds read and write if a user applied specific image filters to a specially crafted image and sent the resulting image.

EPSS: Низкий
github логотип

GHSA-xwv3-34j2-7jgx

почти 2 года назад

Integer overflow in Skia in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xwv2-xfhg-6wqw

больше 4 лет назад

PHP remote file inclusion vulnerability in language/1/splash.lang.php in Beacon 0.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the languagePath parameter.

EPSS: Низкий
github логотип

GHSA-xwv2-6j43-gjcx

больше 4 лет назад

Privoxy before 3.0.21 does not properly handle Proxy-Authenticate and Proxy-Authorization headers in the client-server data stream, which makes it easier for remote HTTP servers to spoof the intended proxy service via a 407 (aka Proxy Authentication Required) HTTP status code.

EPSS: Низкий
github логотип

GHSA-xwv2-23r9-3p5j

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in ESCON SupportPortal Professional Edition 3.0 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with (1) a SCRIPT element, (2) a crafted SRC attribute of an IFRAME element, (3) a crafted CONTENT attribute of an HTTP-EQUIV="Set-Cookie" META element, or (4) an innerHTML attribute within an XML document.

EPSS: Низкий
github логотип

GHSA-xwrx-f4gw-ff4g

12 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: iommufd: Fix unpinning of pages when an access is present syzkaller found that the calculation of batch_last_index should use 'start_index' since at input to this function the batch is either empty or it has already been adjusted to cross any accesses so it will start at the point we are unmapping from. Getting this wrong causes the unmap to run over the end of the pages which corrupts pages that were never mapped. In most cases this triggers the num pinned debugging: WARNING: CPU: 0 PID: 557 at drivers/iommu/iommufd/pages.c:294 __iopt_area_unfill_domain+0x152/0x560 Modules linked in: CPU: 0 PID: 557 Comm: repro Not tainted 6.3.0-rc2-eeac8ede1755 #1 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014 RIP: 0010:__iopt_area_unfill_domain+0x152/0x560 Code: d2 0f ff 44 8b 64 24 54 48 8b 44 24 48 31 ff 44 89 e6 48 89 44 24 38 e8 fc d3 0f ff 4...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xwrx-9qxp-9w34

больше 4 лет назад

Format string vulnerability in pam-pgsql 0.5.2 and earlier allows remote attackers to execute arbitrary code via the username that isp rovided during authentication, which is not properly handled when recording a log message.

EPSS: Низкий
github логотип

GHSA-xwrx-6pgq-qmcj

около 2 лет назад

SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'id' in '/AttendanceMonitoring/department/index.php' parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xwrw-m7f6-fqjx

больше 4 лет назад

Buffer overflow in War FTPd 1.6x allows users to cause a denial of service via long MKD and CWD commands.

EPSS: Низкий
github логотип

GHSA-xwrw-9qxw-gm75

больше 1 года назад

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ownekey parameter in the web_rmon_alarm_post_rmon_alarm function.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xwrw-2crp-46q4

9 месяцев назад

NUT-14 allows cashu tokens to be created with a preimage hash. However, nutshell (cashubtc/nuts) before 0.18.0 do not validate the size of preimage when the token is spent. The preimage is stored by the mint and attacker can exploit this vulnerability to fill the mint's db nd disk with arbitrary data.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xwrv-8p5w-52hj

больше 1 года назад

A vulnerability in Vtiger CRM Open Source Edition v8.3.0 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the ZIP import functionality in the Module Import feature.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xwrr-w87j-j7m5

больше 4 лет назад

Multiple SQL injection vulnerabilities in TekRADIUS 3.0 allow context-dependent attackers to execute arbitrary SQL commands via (1) the GUI client, as demonstrated by input to the Browse Users text box in the Users tab; or (2) the command-line client, as demonstrated by a certain trcli -r command.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xwv6-v7qx-f5jc

Code injection in ezsystems/ezpublish-kernel

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xwv5-74wf-vr6h

There is an out of bounds write vulnerability due to improper bounds checking resulting in an invalid address when parsing a DSB file with Digilent DASYLab. This vulnerability may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted DSB file. The vulnerability affects all versions of DASYLab.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-xwv4-vj99-cxxj

M365 Copilot Spoofing Vulnerability

CVSS3: 6.5
1%
Низкий
11 месяцев назад
github логотип
GHSA-xwv4-ppgv-h9j7

Symantec IT Analytics, prior to 2.9.1, may be susceptible to a cross-site scripting (XSS) exploit, which is a type of issue that can potentially enable attackers to inject client-side scripts into web pages viewed by other users.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xwv4-jx2p-x8xw

The CodePeople Post Map for Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cpm_point' Post Meta in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
3 месяца назад
github логотип
GHSA-xwv4-cq25-qmfg

Liblouis 3.5.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c.

CVSS3: 8.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-xwv4-chgp-x89p

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hyumika OSM – OpenStreetMap allows Stored XSS.This issue affects OSM – OpenStreetMap: from n/a through 6.1.2.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-xwv3-xrx8-63rf

A missing bounds check in WhatsApp for Android prior to v2.21.1.13 and WhatsApp Business for Android prior to v2.21.1.13 could have allowed out-of-bounds read and write if a user applied specific image filters to a specially crafted image and sent the resulting image.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-xwv3-34j2-7jgx

Integer overflow in Skia in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)

CVSS3: 7.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-xwv2-xfhg-6wqw

PHP remote file inclusion vulnerability in language/1/splash.lang.php in Beacon 0.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the languagePath parameter.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xwv2-6j43-gjcx

Privoxy before 3.0.21 does not properly handle Proxy-Authenticate and Proxy-Authorization headers in the client-server data stream, which makes it easier for remote HTTP servers to spoof the intended proxy service via a 407 (aka Proxy Authentication Required) HTTP status code.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-xwv2-23r9-3p5j

Multiple cross-site scripting (XSS) vulnerabilities in ESCON SupportPortal Professional Edition 3.0 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with (1) a SCRIPT element, (2) a crafted SRC attribute of an IFRAME element, (3) a crafted CONTENT attribute of an HTTP-EQUIV="Set-Cookie" META element, or (4) an innerHTML attribute within an XML document.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xwrx-f4gw-ff4g

In the Linux kernel, the following vulnerability has been resolved: iommufd: Fix unpinning of pages when an access is present syzkaller found that the calculation of batch_last_index should use 'start_index' since at input to this function the batch is either empty or it has already been adjusted to cross any accesses so it will start at the point we are unmapping from. Getting this wrong causes the unmap to run over the end of the pages which corrupts pages that were never mapped. In most cases this triggers the num pinned debugging: WARNING: CPU: 0 PID: 557 at drivers/iommu/iommufd/pages.c:294 __iopt_area_unfill_domain+0x152/0x560 Modules linked in: CPU: 0 PID: 557 Comm: repro Not tainted 6.3.0-rc2-eeac8ede1755 #1 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014 RIP: 0010:__iopt_area_unfill_domain+0x152/0x560 Code: d2 0f ff 44 8b 64 24 54 48 8b 44 24 48 31 ff 44 89 e6 48 89 44 24 38 e8 fc d3 0f ff 4...

CVSS3: 5.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-xwrx-9qxp-9w34

Format string vulnerability in pam-pgsql 0.5.2 and earlier allows remote attackers to execute arbitrary code via the username that isp rovided during authentication, which is not properly handled when recording a log message.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xwrx-6pgq-qmcj

SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'id' in '/AttendanceMonitoring/department/index.php' parameter.

CVSS3: 9.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-xwrw-m7f6-fqjx

Buffer overflow in War FTPd 1.6x allows users to cause a denial of service via long MKD and CWD commands.

8%
Низкий
больше 4 лет назад
github логотип
GHSA-xwrw-9qxw-gm75

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ownekey parameter in the web_rmon_alarm_post_rmon_alarm function.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xwrw-2crp-46q4

NUT-14 allows cashu tokens to be created with a preimage hash. However, nutshell (cashubtc/nuts) before 0.18.0 do not validate the size of preimage when the token is spent. The preimage is stored by the mint and attacker can exploit this vulnerability to fill the mint's db nd disk with arbitrary data.

CVSS3: 9.1
0%
Низкий
9 месяцев назад
github логотип
GHSA-xwrv-8p5w-52hj

A vulnerability in Vtiger CRM Open Source Edition v8.3.0 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the ZIP import functionality in the Module Import feature.

CVSS3: 7.2
0%
Низкий
больше 1 года назад
github логотип
GHSA-xwrr-w87j-j7m5

Multiple SQL injection vulnerabilities in TekRADIUS 3.0 allow context-dependent attackers to execute arbitrary SQL commands via (1) the GUI client, as demonstrated by input to the Browse Users text box in the Users tab; or (2) the command-line client, as demonstrated by a certain trcli -r command.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу