Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-xw9c-qm7m-c9wc

больше 4 лет назад

libvirt 1.1.0 and 1.1.1 allows local users to cause a denial of service (memory consumption) via a large number of domain migrate parameters in certain RPC calls in (1) daemon/remote.c and (2) remote/remote_driver.c.

EPSS: Низкий
github логотип

GHSA-xw9c-j6h9-9vjc

больше 4 лет назад

Foundation in Apple Mac OS X 10.4.11 might allow context-dependent attackers to execute arbitrary code via a malformed selector name to the NSSelectorFromString API, which causes an "unexpected selector" to be used.

EPSS: Низкий
github логотип

GHSA-xw9c-79j7-p3p6

больше 4 лет назад

In FusionPBX up to v4.5.7, the file app\conferences_active\conference_interactive.php uses an unsanitized "c" variable coming from the URL, which is reflected in HTML, leading to XSS.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xw9c-4vrc-64gr

8 месяцев назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-xw99-vmpf-qpg4

больше 4 лет назад

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1024, CVE-2020-1102.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xw99-jr69-5j43

больше 4 лет назад

Multiple SQL injection vulnerabilities in MyioSoft EasyBookMarker 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) delete_folder and (2) delete_link parameters to unspecified vectors, possibly to (a) plugins/bookmarker/bookmarker_backend.php or (b) ajaxp.php, different vectors than CVE-2008-5654. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-xw99-fqpg-v257

больше 2 лет назад

Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.5.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xw98-vm6c-57r4

больше 4 лет назад

Unknown vulnerability in IBM Parallel Environment (PE) 3.2 and 4.1 allows attackers to execute arbitrary commands as root via unknown vectors in the sample code.

EPSS: Низкий
github логотип

GHSA-xw98-8fcm-j8x7

около 1 месяца назад

A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in zip files during scanning. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate as a result of a memory double-free, resulting in a DoS condition on the affected software.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xw98-6cfw-p3wh

больше 4 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NEC ESMPRO Manager 6.42. Authentication is not required to exploit this vulnerability. The specific flaw exists within the RMI service. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-10007.

EPSS: Низкий
github логотип

GHSA-xw98-5q62-jx94

7 месяцев назад

Traefik: tcp router clears read deadlines before tls forwarding, enabling stalled handshakes (Slowloris DOS)

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xw98-5fp3-v7vg

около 2 месяцев назад

The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV import, allowing a user holding only the user-creation capability to create an administrator account and to overwrite an existing administrator's password or email.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xw97-pjh6-x5h5

больше 4 лет назад

Media Player Classic (MPC) allows user-assisted remote attackers to cause a denial of service (application crash) via a malformed .au file that triggers a divide-by-zero error.

EPSS: Низкий
github логотип

GHSA-xw97-mfvw-wc3w

больше 2 лет назад

In multiple locations, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xw97-6734-68pm

больше 4 лет назад

IOGraphicsFamily in Apple OS X before 10.9.4 allows local users to bypass the ASLR protection mechanism by leveraging read access to a kernel pointer in an IOKit object.

EPSS: Низкий
github логотип

GHSA-xw96-xcrg-p8w2

больше 4 лет назад

Incorrect security UI in popup blocker in Google Chrome on iOS prior to 75.0.3770.80 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xw96-874r-24gc

почти 4 года назад

The Goolytics WordPress plugin before 1.1.2 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xw96-5rq6-6334

больше 4 лет назад

A wgagent stack-based buffer overflow in WatchGuard Firebox and XTM appliances allows an authenticated remote attacker to potentially execute arbitrary code by initiating a firmware update with a malicious upgrade image. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xw96-38mm-h5jg

больше 1 года назад

Deserialization of Untrusted Data vulnerability in flexmls Flexmls® IDX allows Object Injection. This issue affects Flexmls® IDX: from n/a through 3.14.27.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xw95-hgq7-7c3x

около 3 лет назад

A reflected cross-site scripting (XSS) vulnerability in the component /ui/diagnostics/log/core/ of OPNsense before 23.7 allows attackers to inject arbitrary JavaScript via the URL path.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xw9c-qm7m-c9wc

libvirt 1.1.0 and 1.1.1 allows local users to cause a denial of service (memory consumption) via a large number of domain migrate parameters in certain RPC calls in (1) daemon/remote.c and (2) remote/remote_driver.c.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xw9c-j6h9-9vjc

Foundation in Apple Mac OS X 10.4.11 might allow context-dependent attackers to execute arbitrary code via a malformed selector name to the NSSelectorFromString API, which causes an "unexpected selector" to be used.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-xw9c-79j7-p3p6

In FusionPBX up to v4.5.7, the file app\conferences_active\conference_interactive.php uses an unsanitized "c" variable coming from the URL, which is reflected in HTML, leading to XSS.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xw9c-4vrc-64gr

Rejected reason: Not used

8 месяцев назад
github логотип
GHSA-xw99-vmpf-qpg4

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1024, CVE-2020-1102.

CVSS3: 8.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-xw99-jr69-5j43

Multiple SQL injection vulnerabilities in MyioSoft EasyBookMarker 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) delete_folder and (2) delete_link parameters to unspecified vectors, possibly to (a) plugins/bookmarker/bookmarker_backend.php or (b) ajaxp.php, different vectors than CVE-2008-5654. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xw99-fqpg-v257

Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.5.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xw98-vm6c-57r4

Unknown vulnerability in IBM Parallel Environment (PE) 3.2 and 4.1 allows attackers to execute arbitrary commands as root via unknown vectors in the sample code.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xw98-8fcm-j8x7

A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in zip files during scanning. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate as a result of a memory double-free, resulting in a DoS condition on the affected software.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xw98-6cfw-p3wh

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NEC ESMPRO Manager 6.42. Authentication is not required to exploit this vulnerability. The specific flaw exists within the RMI service. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-10007.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-xw98-5q62-jx94

Traefik: tcp router clears read deadlines before tls forwarding, enabling stalled handshakes (Slowloris DOS)

CVSS3: 7.5
1%
Низкий
7 месяцев назад
github логотип
GHSA-xw98-5fp3-v7vg

The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV import, allowing a user holding only the user-creation capability to create an administrator account and to overwrite an existing administrator's password or email.

CVSS3: 9.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xw97-pjh6-x5h5

Media Player Classic (MPC) allows user-assisted remote attackers to cause a denial of service (application crash) via a malformed .au file that triggers a divide-by-zero error.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xw97-mfvw-wc3w

In multiple locations, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xw97-6734-68pm

IOGraphicsFamily in Apple OS X before 10.9.4 allows local users to bypass the ASLR protection mechanism by leveraging read access to a kernel pointer in an IOKit object.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xw96-xcrg-p8w2

Incorrect security UI in popup blocker in Google Chrome on iOS prior to 75.0.3770.80 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xw96-874r-24gc

The Goolytics WordPress plugin before 1.1.2 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVSS3: 4.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-xw96-5rq6-6334

A wgagent stack-based buffer overflow in WatchGuard Firebox and XTM appliances allows an authenticated remote attacker to potentially execute arbitrary code by initiating a firmware update with a malicious upgrade image. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xw96-38mm-h5jg

Deserialization of Untrusted Data vulnerability in flexmls Flexmls® IDX allows Object Injection. This issue affects Flexmls® IDX: from n/a through 3.14.27.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-xw95-hgq7-7c3x

A reflected cross-site scripting (XSS) vulnerability in the component /ui/diagnostics/log/core/ of OPNsense before 23.7 allows attackers to inject arbitrary JavaScript via the URL path.

CVSS3: 6.1
1%
Низкий
около 3 лет назад

Уязвимостей на страницу