Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 375

Количество 314 375

github логотип

GHSA-xwff-jwf7-fmhq

8 месяцев назад

Bypass vulnerability in the device management channel Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xwfc-35wf-724m

больше 3 лет назад

Multiple CRLF injection vulnerabilities in the HTTP server in IBM Lotus Domino 8.5.x before 8.5.4 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input involving (1) Mozilla Firefox 3.0.9 and earlier or (2) unspecified browsers.

EPSS: Низкий
github логотип

GHSA-xwf9-ppp5-89qf

больше 3 лет назад

Configuration and database backup archives are not signed or validated in Trend Micro Deep Discovery Director 1.1.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xwf9-2w8q-559f

около 1 года назад

IrfanView CGM File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of CGM files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24866.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xwf7-ghx7-gwwp

около 4 лет назад

A Segmentation fault caused by null pointer dereference vulnerability eists in Gpac through 1.0.2 via the avc_parse_slice function in av_parsers.c when using mp4box, which causes a denial of service.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xwf7-9xfx-ghmm

больше 2 лет назад

Zoom clients prior to 5.13.5 contain an improper trust boundary implementation vulnerability. If a victim saves a local recording to an SMB location and later opens it using a link from Zoom’s web portal, an attacker positioned on an adjacent network to the victim client could set up a malicious SMB server to respond to client requests, causing the client to execute attacker controlled executables. This could result in an attacker gaining access to a user's device and data, and remote code execution.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xwf4-mvc8-9xvx

6 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in iThemes ServerBuddy by PluginBuddy.Com allows Object Injection.This issue affects ServerBuddy by PluginBuddy.Com: from n/a through 1.0.5.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xwf4-g3q4-g8hc

почти 4 года назад

Directory traversal vulnerability in index.php in xtcommerce allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter.

EPSS: Низкий
github логотип

GHSA-xwf4-fv46-xv49

больше 3 лет назад

Multiple stack-based buffer overflows in WebGate eDVR Manager allow remote attackers to execute arbitrary code via unspecified vectors to the (1) Connect, (2) ConnectEx, or (3) ConnectEx2 function in the WESPEvent.WESPEventCtrl.1 control; (4) AudioOnlySiteChannel function in the WESPPlayback.WESPPlaybackCtrl.1 control; (5) Connect or (6) ConnectEx function in the WESPPTZ.WESPPTZCtrl.1 control; (7) SiteChannel property in the WESPPlayback.WESPPlaybackCtrl.1 control; (8) SiteName property in the WESPPlayback.WESPPlaybackCtrl.1 control; or (9) OpenDVrSSite function in the WESPPTZ.WESPPTZCtrl.1 control.

EPSS: Средний
github логотип

GHSA-xwf4-c7mf-4rh5

почти 2 года назад

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/archives_do.php

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xwf4-88xr-hx2j

больше 3 лет назад

Cross site scripting in Apache Sling

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xwf4-4p9v-22fp

6 месяцев назад

in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-xwf4-4p3p-6p65

больше 3 лет назад

Cross-site scripting in handle.php in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "options[sysname]" parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xwf3-pcvx-xf5j

больше 3 лет назад

UNIVERGE Aspire series PBX (UNIVERGE Aspire WX from 1.00 to 3.51, UNIVERGE Aspire UX from 1.00 to 9.70, UNIVERGE SV9100 from 1.00 to 10.70, and SL2100 from 1.00 to 3.00) allows a remote authenticated attacker to cause system down and a denial of service (DoS) condition by sending a specially crafted command.

EPSS: Низкий
github логотип

GHSA-xwf3-c99h-p43f

больше 3 лет назад

Multiple vulnerabilities in the WebVPN service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the WebVPN portal of an affected device. The vulnerabilities exist because the software insufficiently validates user-supplied input on an affected device. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information. An attacker would need administrator privileges on the device to exploit these vulnerabilities.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xwf3-8452-8j2v

больше 3 лет назад

Possible out of bound access in WLAN handler when the received value of length in rx path is shorter than the expected value of country IE in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in IPQ8074, QCA8081, QCS605, SDA845, SDM670, SDM710, SDM845, SDM850, SM6150, SM7150, SM8150, SXR1130

EPSS: Низкий
github логотип

GHSA-xwf3-6rgv-939r

больше 3 лет назад

Flux CLI Workload Injection

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-xwf3-49mf-8pq7

около 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Marco Milesi Browser Theme Color.This issue affects Browser Theme Color: from n/a through 1.3.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xwf2-9m25-2hpf

больше 2 лет назад

OptiPNG v0.7.7 was discovered to contain a global buffer overflow via the 'buffer' variable at gifread.c.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xwf2-93hx-88xm

больше 3 лет назад

The Treck TCP/IP stack before 6.0.1.66 has Improper ICMPv4 Access Control.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xwff-jwf7-fmhq

Bypass vulnerability in the device management channel Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS3: 7.1
0%
Низкий
8 месяцев назад
github логотип
GHSA-xwfc-35wf-724m

Multiple CRLF injection vulnerabilities in the HTTP server in IBM Lotus Domino 8.5.x before 8.5.4 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input involving (1) Mozilla Firefox 3.0.9 and earlier or (2) unspecified browsers.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xwf9-ppp5-89qf

Configuration and database backup archives are not signed or validated in Trend Micro Deep Discovery Director 1.1.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xwf9-2w8q-559f

IrfanView CGM File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of CGM files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24866.

CVSS3: 7.8
1%
Низкий
около 1 года назад
github логотип
GHSA-xwf7-ghx7-gwwp

A Segmentation fault caused by null pointer dereference vulnerability eists in Gpac through 1.0.2 via the avc_parse_slice function in av_parsers.c when using mp4box, which causes a denial of service.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-xwf7-9xfx-ghmm

Zoom clients prior to 5.13.5 contain an improper trust boundary implementation vulnerability. If a victim saves a local recording to an SMB location and later opens it using a link from Zoom’s web portal, an attacker positioned on an adjacent network to the victim client could set up a malicious SMB server to respond to client requests, causing the client to execute attacker controlled executables. This could result in an attacker gaining access to a user's device and data, and remote code execution.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xwf4-mvc8-9xvx

Cross-Site Request Forgery (CSRF) vulnerability in iThemes ServerBuddy by PluginBuddy.Com allows Object Injection.This issue affects ServerBuddy by PluginBuddy.Com: from n/a through 1.0.5.

CVSS3: 8.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-xwf4-g3q4-g8hc

Directory traversal vulnerability in index.php in xtcommerce allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter.

7%
Низкий
почти 4 года назад
github логотип
GHSA-xwf4-fv46-xv49

Multiple stack-based buffer overflows in WebGate eDVR Manager allow remote attackers to execute arbitrary code via unspecified vectors to the (1) Connect, (2) ConnectEx, or (3) ConnectEx2 function in the WESPEvent.WESPEventCtrl.1 control; (4) AudioOnlySiteChannel function in the WESPPlayback.WESPPlaybackCtrl.1 control; (5) Connect or (6) ConnectEx function in the WESPPTZ.WESPPTZCtrl.1 control; (7) SiteChannel property in the WESPPlayback.WESPPlaybackCtrl.1 control; (8) SiteName property in the WESPPlayback.WESPPlaybackCtrl.1 control; or (9) OpenDVrSSite function in the WESPPTZ.WESPPTZCtrl.1 control.

42%
Средний
больше 3 лет назад
github логотип
GHSA-xwf4-c7mf-4rh5

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/archives_do.php

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-xwf4-88xr-hx2j

Cross site scripting in Apache Sling

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xwf4-4p9v-22fp

in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free.

CVSS3: 8.4
0%
Низкий
6 месяцев назад
github логотип
GHSA-xwf4-4p3p-6p65

Cross-site scripting in handle.php in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "options[sysname]" parameter.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xwf3-pcvx-xf5j

UNIVERGE Aspire series PBX (UNIVERGE Aspire WX from 1.00 to 3.51, UNIVERGE Aspire UX from 1.00 to 9.70, UNIVERGE SV9100 from 1.00 to 10.70, and SL2100 from 1.00 to 3.00) allows a remote authenticated attacker to cause system down and a denial of service (DoS) condition by sending a specially crafted command.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xwf3-c99h-p43f

Multiple vulnerabilities in the WebVPN service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the WebVPN portal of an affected device. The vulnerabilities exist because the software insufficiently validates user-supplied input on an affected device. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information. An attacker would need administrator privileges on the device to exploit these vulnerabilities.

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xwf3-8452-8j2v

Possible out of bound access in WLAN handler when the received value of length in rx path is shorter than the expected value of country IE in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in IPQ8074, QCA8081, QCS605, SDA845, SDM670, SDM710, SDM845, SDM850, SM6150, SM7150, SM8150, SXR1130

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xwf3-6rgv-939r

Flux CLI Workload Injection

CVSS3: 7.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xwf3-49mf-8pq7

Cross-Site Request Forgery (CSRF) vulnerability in Marco Milesi Browser Theme Color.This issue affects Browser Theme Color: from n/a through 1.3.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-xwf2-9m25-2hpf

OptiPNG v0.7.7 was discovered to contain a global buffer overflow via the 'buffer' variable at gifread.c.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xwf2-93hx-88xm

The Treck TCP/IP stack before 6.0.1.66 has Improper ICMPv4 Access Control.

3%
Низкий
больше 3 лет назад

Уязвимостей на страницу