Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-xw3h-25x4-6r6q

больше 4 лет назад

IBM Sametime Media Services 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 113899.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xw3h-25p9-q9gp

около 4 лет назад

A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant and in certain WithSecure products whereby the scanning the aeheur.dll component can crash the scanning engine. The exploit can be triggered remotely by an attacker.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xw3g-x45j-xxhh

больше 2 лет назад

A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer dereference in the NVMe driver, causing kernel panic and a denial of service.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xw3g-f28m-3q7j

больше 1 года назад

An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Travel Ideas" function.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xw3g-88p6-48wm

больше 4 лет назад

FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (core dump) via malformed USR vendor-specific attributes (VSA) that cause a memcpy operation with a -1 argument.

EPSS: Низкий
github логотип

GHSA-xw3f-9qfw-v43f

больше 4 лет назад

It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to ceph cluster network who is able to sniff packets on network can use this vulnerability to authenticate with ceph service and perform actions allowed by ceph service. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xw3c-vh4p-m7j2

3 месяца назад

The Naxclow platform exposes a registration endpoint that accepts signed requests containing a batch prefix and an arbitrary caller-supplied account identifier, without validating any ownership relationship. Each call mints a new sequential device identifier and returns the current high-water counter value for the batch, allowing callers to measure and enumerate the active device space. The endpoint’s behavior enables precise fleet enumeration.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xw39-vx24-m6fx

больше 4 лет назад

The Flood-It (aka com.appspot.eoltek.flood) application 4.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-xw39-q6xj-4gq5

больше 4 лет назад

participants-database.php in the Participants Database plugin 1.9.5.5 and previous versions for WordPress has a time-based SQL injection vulnerability via the ascdesc, list_filter_count, or sortBy parameters. It is possible to exfiltrate data and potentially execute code (if certain conditions are met).

EPSS: Низкий
github логотип

GHSA-xw39-p8g9-hq9j

больше 4 лет назад

An exploitable information disclosure vulnerability exists in the Server Agent functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted TCP packet can cause information disclosure. An attacker can send a crafted TCP packet to trigger this vulnerability.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-xw39-hrhx-6f53

около 3 лет назад

In on_remove_iso_data_path of btm_iso_impl.h, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-236688764

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xw39-hmhj-f95j

больше 4 лет назад

Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows context-dependent attackers to cause a denial of service (device restart and BGP routing table rebuild) via certain regular expressions in a "show ip bgp regexp" command. NOTE: unauthenticated remote attacks are possible in environments with anonymous telnet and Looking Glass access.

EPSS: Средний
github логотип

GHSA-xw39-fhvp-3jj6

больше 4 лет назад

The BigFix Client installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying vulnerability fixed.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xw39-57rx-4hr5

больше 2 лет назад

It is possible to download the configuration backup without authorization and decrypt included passwords using hardcoded static key.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xw38-r5v4-92p9

больше 4 лет назад

Unspecified vulnerability in Adaptive Micro Systems ALPHA Ethernet Adapter II Web-Manager 3.40.2 allows remote attackers to bypass authentication and read or write configuration files via unknown vectors.

EPSS: Низкий
github логотип

GHSA-xw37-xfrp-pmwc

больше 2 лет назад

Missing Authorization vulnerability in ThemeBoy SportsPress – Sports Club & League Manager.This issue affects SportsPress – Sports Club & League Manager: from n/a through 2.7.20.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xw37-57qp-9mm4

около 5 лет назад

Consensus flaw during block processing in github.com/ethereum/go-ethereum

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xw36-67f8-339x

6 месяцев назад

SimpleJWT has an Unauthenticated Denial of Service via JWE header tampering

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xw36-22jx-j7vq

больше 4 лет назад

An uncontrolled resource consumption vulnerability in Juniper Networks Junos OS on QFX5000 Series and EX4600 Series switches allows an attacker sending large amounts of legitimate traffic destined to the device to cause Interchassis Control Protocol (ICCP) interruptions, leading to an unstable control connection between the Multi-Chassis Link Aggregation Group (MC-LAG) nodes which can in turn lead to traffic loss. Continued receipt of this amount of traffic will create a sustained Denial of Service (DoS) condition. An indication that the system could be impacted by this issue is the following log message: "DDOS_PROTOCOL_VIOLATION_SET: Warning: Host-bound traffic for protocol/exception LOCALNH:aggregate exceeded its allowed bandwidth at fpc <fpc number> for <n> times, started at <timestamp>" This issue affects Juniper Networks Junos OS on QFX5000 Series and EX4600 Series: 15.1 versions prior to 15.1R7-S9; 17.3 versions prior to 17.3R3-S11; 17.4 versions prior to 17.4R2-S13, 17.4R3-S5...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xw35-x29w-q9gx

больше 4 лет назад

Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the Adobe Texture Format (ATF) module. Successful exploitation could lead to arbitrary code execution.

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xw3h-25x4-6r6q

IBM Sametime Media Services 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 113899.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xw3h-25p9-q9gp

A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant and in certain WithSecure products whereby the scanning the aeheur.dll component can crash the scanning engine. The exploit can be triggered remotely by an attacker.

CVSS3: 7.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-xw3g-x45j-xxhh

A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer dereference in the NVMe driver, causing kernel panic and a denial of service.

CVSS3: 6.5
2%
Низкий
больше 2 лет назад
github логотип
GHSA-xw3g-f28m-3q7j

An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Travel Ideas" function.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xw3g-88p6-48wm

FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (core dump) via malformed USR vendor-specific attributes (VSA) that cause a memcpy operation with a -1 argument.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xw3f-9qfw-v43f

It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to ceph cluster network who is able to sniff packets on network can use this vulnerability to authenticate with ceph service and perform actions allowed by ceph service. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xw3c-vh4p-m7j2

The Naxclow platform exposes a registration endpoint that accepts signed requests containing a batch prefix and an arbitrary caller-supplied account identifier, without validating any ownership relationship. Each call mints a new sequential device identifier and returns the current high-water counter value for the batch, allowing callers to measure and enumerate the active device space. The endpoint’s behavior enables precise fleet enumeration.

CVSS3: 5.3
0%
Низкий
3 месяца назад
github логотип
GHSA-xw39-vx24-m6fx

The Flood-It (aka com.appspot.eoltek.flood) application 4.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xw39-q6xj-4gq5

participants-database.php in the Participants Database plugin 1.9.5.5 and previous versions for WordPress has a time-based SQL injection vulnerability via the ascdesc, list_filter_count, or sortBy parameters. It is possible to exfiltrate data and potentially execute code (if certain conditions are met).

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xw39-p8g9-hq9j

An exploitable information disclosure vulnerability exists in the Server Agent functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted TCP packet can cause information disclosure. An attacker can send a crafted TCP packet to trigger this vulnerability.

CVSS3: 7.5
43%
Средний
больше 4 лет назад
github логотип
GHSA-xw39-hrhx-6f53

In on_remove_iso_data_path of btm_iso_impl.h, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-236688764

CVSS3: 5.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-xw39-hmhj-f95j

Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows context-dependent attackers to cause a denial of service (device restart and BGP routing table rebuild) via certain regular expressions in a "show ip bgp regexp" command. NOTE: unauthenticated remote attacks are possible in environments with anonymous telnet and Looking Glass access.

13%
Средний
больше 4 лет назад
github логотип
GHSA-xw39-fhvp-3jj6

The BigFix Client installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying vulnerability fixed.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xw39-57rx-4hr5

It is possible to download the configuration backup without authorization and decrypt included passwords using hardcoded static key.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xw38-r5v4-92p9

Unspecified vulnerability in Adaptive Micro Systems ALPHA Ethernet Adapter II Web-Manager 3.40.2 allows remote attackers to bypass authentication and read or write configuration files via unknown vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xw37-xfrp-pmwc

Missing Authorization vulnerability in ThemeBoy SportsPress – Sports Club & League Manager.This issue affects SportsPress – Sports Club & League Manager: from n/a through 2.7.20.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xw37-57qp-9mm4

Consensus flaw during block processing in github.com/ethereum/go-ethereum

CVSS3: 5.3
1%
Низкий
около 5 лет назад
github логотип
GHSA-xw36-67f8-339x

SimpleJWT has an Unauthenticated Denial of Service via JWE header tampering

CVSS3: 7.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-xw36-22jx-j7vq

An uncontrolled resource consumption vulnerability in Juniper Networks Junos OS on QFX5000 Series and EX4600 Series switches allows an attacker sending large amounts of legitimate traffic destined to the device to cause Interchassis Control Protocol (ICCP) interruptions, leading to an unstable control connection between the Multi-Chassis Link Aggregation Group (MC-LAG) nodes which can in turn lead to traffic loss. Continued receipt of this amount of traffic will create a sustained Denial of Service (DoS) condition. An indication that the system could be impacted by this issue is the following log message: "DDOS_PROTOCOL_VIOLATION_SET: Warning: Host-bound traffic for protocol/exception LOCALNH:aggregate exceeded its allowed bandwidth at fpc <fpc number> for <n> times, started at <timestamp>" This issue affects Juniper Networks Junos OS on QFX5000 Series and EX4600 Series: 15.1 versions prior to 15.1R7-S9; 17.3 versions prior to 17.3R3-S11; 17.4 versions prior to 17.4R2-S13, 17.4R3-S5...

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xw35-x29w-q9gx

Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the Adobe Texture Format (ATF) module. Successful exploitation could lead to arbitrary code execution.

CVSS3: 9.8
31%
Средний
больше 4 лет назад

Уязвимостей на страницу