Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 972

Количество 353 972

github логотип

GHSA-xwhx-h3gq-62jp

больше 4 лет назад

Stack-based buffer overflow in the pam_micasa PAM authentication module in CASA on Novell Linux Desktop 9 and Open Enterprise Server 1 allows remote attackers to execute arbitrary code via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xwhx-6g69-79wc

больше 4 лет назад

The IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x server connection to an IBM Spectrum Protect Plus workload agent is subject to a man-in-the-middle attack due to improper certificate validation. IBM X-Force ID: 182046.

EPSS: Низкий
github логотип

GHSA-xwhx-3qqx-64m9

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: wifi: mac8021: fix possible oob access in ieee80211_get_rate_duration Fix possible out-of-bound access in ieee80211_get_rate_duration routine as reported by the following UBSAN report: UBSAN: array-index-out-of-bounds in net/mac80211/airtime.c:455:47 index 15 is out of range for type 'u16 [12]' CPU: 2 PID: 217 Comm: kworker/u32:10 Not tainted 6.1.0-060100rc3-generic Hardware name: Acer Aspire TC-281/Aspire TC-281, BIOS R01-A2 07/18/2017 Workqueue: mt76 mt76u_tx_status_data [mt76_usb] Call Trace: <TASK> show_stack+0x4e/0x61 dump_stack_lvl+0x4a/0x6f dump_stack+0x10/0x18 ubsan_epilogue+0x9/0x43 __ubsan_handle_out_of_bounds.cold+0x42/0x47 ieee80211_get_rate_duration.constprop.0+0x22f/0x2a0 [mac80211] ? ieee80211_tx_status_ext+0x32e/0x640 [mac80211] ieee80211_calc_rx_airtime+0xda/0x120 [mac80211] ieee80211_calc_tx_airtime+0xb4/0x100 [mac80211] mt76x02_send_tx_status+0x266/0x480 [mt76x02_lib] mt76x02_tx_stat...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xwhw-jwh4-hh9v

около 4 лет назад

In Poppler 0.59.0, a NULL Pointer Dereference exists in the XRef::parseEntry() function in XRef.cc via a crafted PDF document.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xwhw-cvrw-c9g5

6 месяцев назад

Victor CMS version 1.0 contains a SQL injection vulnerability in the 'post' parameter on post.php that allows remote attackers to manipulate database queries. Attackers can exploit this vulnerability by sending crafted UNION SELECT payloads to extract database information through boolean-based, error-based, and time-based injection techniques.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-xwhw-9p7r-3vq8

почти 4 года назад

Xpdf prior to 4.04 lacked an integer overflow check in JPXStream.cc.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xwhw-83c9-38cf

почти 2 года назад

The TrueBooker WordPress plugin before 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xwhw-2q44-qw48

около 4 лет назад

OX App Suite through 7.10.4 allows SSRF via a URL with an @ character in an appsuite/api/oauth/proxy PUT request.

EPSS: Низкий
github логотип

GHSA-xwhv-5h8x-ff8f

около 4 лет назад

The E-book viewer in calibre before 2.75 allows remote attackers to read arbitrary files via a crafted epub file with JavaScript.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xwhr-x5p4-2h82

около 4 лет назад

The Symphony G100 Android device with a build fingerprint of Symphony/G100/G100:8.1.0/O11019/1530618779:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.

EPSS: Низкий
github логотип

GHSA-xwhr-hxqf-pv44

5 месяцев назад

Xmind Attachment Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Xmind. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of attachments. When opening an attachment, the user interface fails to warn the user of unsafe actions. An attacker can leverage this vulnerability to execute code in the context of current user. Was ZDI-CAN-26034.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xwhq-77cp-j75x

около 4 лет назад

The web management interface in 3Com Wireless 8760 Dual Radio 11a/b/g PoE Access Point allows remote attackers to cause a denial of service (device crash) via a malformed HTTP POST request.

EPSS: Низкий
github логотип

GHSA-xwhp-9m57-54vw

около 2 лет назад

Authentication Bypass by Spoofing vulnerability in WP Maintenance allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Maintenance: from n/a through 6.1.3.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-xwhm-gpc5-8rh4

больше 4 лет назад

Recourse ManTrap 1.6 modifies the kernel so that ".." does not appear in the /proc listing, which allows attackers to determine that they are in a honeypot system.

EPSS: Низкий
github логотип

GHSA-xwhj-x2g6-527m

больше 3 лет назад

An information disclosure vulnerability exists in the IFFOutput channel interleaving functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to leaked heap data. An attacker can provide malicious input to trigger this vulnerability.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xwhj-pqcg-8rcr

больше 3 лет назад

CakePHP vulnerable to Cross-site Scripting in some development error pages

EPSS: Низкий
github логотип

GHSA-xwhh-qff2-j7fx

7 месяцев назад

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and later QuTS hero h5.2.7.3256 build 20250913 and later QuTS hero h5.3.1.3250 build 20250912 and later

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-xwhg-vr3r-8xvq

около 4 лет назад

A NULL pointer dereference flaw was found in the Linux kernel’s KVM module, which can lead to a denial of service in the x86_emulate_insn in arch/x86/kvm/emulate.c. This flaw occurs while executing an illegal instruction in guest in the Intel CPU.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xwhg-hhp3-v8r3

больше 4 лет назад

Directory traversal vulnerability in index.php in PHP Directory Lister (dirLIST) before 0.1.1 allows remote attackers to list the contents of a parent directory via a .. (dot dot) in the folder parameter.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xwhf-r489-w73v

больше 3 лет назад

An issue was discovered in TigerGraph Enterprise Free Edition 3.x. Data loading jobs in gsql_server, created by any user with designer permissions, can read sensitive data from arbitrary locations.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xwhx-h3gq-62jp

Stack-based buffer overflow in the pam_micasa PAM authentication module in CASA on Novell Linux Desktop 9 and Open Enterprise Server 1 allows remote attackers to execute arbitrary code via unspecified vectors.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-xwhx-6g69-79wc

The IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x server connection to an IBM Spectrum Protect Plus workload agent is subject to a man-in-the-middle attack due to improper certificate validation. IBM X-Force ID: 182046.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xwhx-3qqx-64m9

In the Linux kernel, the following vulnerability has been resolved: wifi: mac8021: fix possible oob access in ieee80211_get_rate_duration Fix possible out-of-bound access in ieee80211_get_rate_duration routine as reported by the following UBSAN report: UBSAN: array-index-out-of-bounds in net/mac80211/airtime.c:455:47 index 15 is out of range for type 'u16 [12]' CPU: 2 PID: 217 Comm: kworker/u32:10 Not tainted 6.1.0-060100rc3-generic Hardware name: Acer Aspire TC-281/Aspire TC-281, BIOS R01-A2 07/18/2017 Workqueue: mt76 mt76u_tx_status_data [mt76_usb] Call Trace: <TASK> show_stack+0x4e/0x61 dump_stack_lvl+0x4a/0x6f dump_stack+0x10/0x18 ubsan_epilogue+0x9/0x43 __ubsan_handle_out_of_bounds.cold+0x42/0x47 ieee80211_get_rate_duration.constprop.0+0x22f/0x2a0 [mac80211] ? ieee80211_tx_status_ext+0x32e/0x640 [mac80211] ieee80211_calc_rx_airtime+0xda/0x120 [mac80211] ieee80211_calc_tx_airtime+0xb4/0x100 [mac80211] mt76x02_send_tx_status+0x266/0x480 [mt76x02_lib] mt76x02_tx_stat...

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-xwhw-jwh4-hh9v

In Poppler 0.59.0, a NULL Pointer Dereference exists in the XRef::parseEntry() function in XRef.cc via a crafted PDF document.

CVSS3: 5.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xwhw-cvrw-c9g5

Victor CMS version 1.0 contains a SQL injection vulnerability in the 'post' parameter on post.php that allows remote attackers to manipulate database queries. Attackers can exploit this vulnerability by sending crafted UNION SELECT payloads to extract database information through boolean-based, error-based, and time-based injection techniques.

CVSS3: 8.2
0%
Низкий
6 месяцев назад
github логотип
GHSA-xwhw-9p7r-3vq8

Xpdf prior to 4.04 lacked an integer overflow check in JPXStream.cc.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xwhw-83c9-38cf

The TrueBooker WordPress plugin before 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVSS3: 9.8
3%
Низкий
почти 2 года назад
github логотип
GHSA-xwhw-2q44-qw48

OX App Suite through 7.10.4 allows SSRF via a URL with an @ character in an appsuite/api/oauth/proxy PUT request.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xwhv-5h8x-ff8f

The E-book viewer in calibre before 2.75 allows remote attackers to read arbitrary files via a crafted epub file with JavaScript.

CVSS3: 5.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-xwhr-x5p4-2h82

The Symphony G100 Android device with a build fingerprint of Symphony/G100/G100:8.1.0/O11019/1530618779:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xwhr-hxqf-pv44

Xmind Attachment Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Xmind. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of attachments. When opening an attachment, the user interface fails to warn the user of unsafe actions. An attacker can leverage this vulnerability to execute code in the context of current user. Was ZDI-CAN-26034.

CVSS3: 7.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-xwhq-77cp-j75x

The web management interface in 3Com Wireless 8760 Dual Radio 11a/b/g PoE Access Point allows remote attackers to cause a denial of service (device crash) via a malformed HTTP POST request.

3%
Низкий
около 4 лет назад
github логотип
GHSA-xwhp-9m57-54vw

Authentication Bypass by Spoofing vulnerability in WP Maintenance allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Maintenance: from n/a through 6.1.3.

CVSS3: 3.7
0%
Низкий
около 2 лет назад
github логотип
GHSA-xwhm-gpc5-8rh4

Recourse ManTrap 1.6 modifies the kernel so that ".." does not appear in the /proc listing, which allows attackers to determine that they are in a honeypot system.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xwhj-x2g6-527m

An information disclosure vulnerability exists in the IFFOutput channel interleaving functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially crafted ImageOutput Object can lead to leaked heap data. An attacker can provide malicious input to trigger this vulnerability.

CVSS3: 5.9
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xwhj-pqcg-8rcr

CakePHP vulnerable to Cross-site Scripting in some development error pages

больше 3 лет назад
github логотип
GHSA-xwhh-qff2-j7fx

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.7.3256 build 20250913 and later QuTS hero h5.2.7.3256 build 20250913 and later QuTS hero h5.3.1.3250 build 20250912 and later

CVSS3: 4.9
0%
Низкий
7 месяцев назад
github логотип
GHSA-xwhg-vr3r-8xvq

A NULL pointer dereference flaw was found in the Linux kernel’s KVM module, which can lead to a denial of service in the x86_emulate_insn in arch/x86/kvm/emulate.c. This flaw occurs while executing an illegal instruction in guest in the Intel CPU.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-xwhg-hhp3-v8r3

Directory traversal vulnerability in index.php in PHP Directory Lister (dirLIST) before 0.1.1 allows remote attackers to list the contents of a parent directory via a .. (dot dot) in the folder parameter.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xwhf-r489-w73v

An issue was discovered in TigerGraph Enterprise Free Edition 3.x. Data loading jobs in gsql_server, created by any user with designer permissions, can read sensitive data from arbitrary locations.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу