Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 354 500

Количество 354 500

github логотип

GHSA-xvm7-hp96-mh3h

около 2 лет назад

Foxit PDF Editor StrikeOut Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14355.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xvm7-544m-j5w9

около 4 лет назад

Product: AndroidVersions: Android kernelAndroid ID: A-204956204References: N/A

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xvm6-65jm-mc4g

около 2 лет назад

An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow daemon (flowd) of Juniper Networks Junos OS on SRX4600 and SRX5000 Series allows an attacker to send TCP packets with SYN/FIN or SYN/RST flags, bypassing the expected blocking of these packets. A TCP packet with SYN/FIN or SYN/RST should be dropped in flowd. However, when no-syn-check and Express Path are enabled, these TCP packets are unexpectedly transferred to the downstream network. This issue affects Junos OS on SRX4600 and SRX5000 Series: * All versions before 21.2R3-S8, * from 21.4 before 21.4R3-S7, * from 22.1 before 22.1R3-S6, * from 22.2 before 22.2R3-S4, * from 22.3 before 22.3R3-S3, * from 22.4 before 22.4R3-S2, * from 23.2 before 23.2R2, * from 23.4 before 23.4R1-S1, 23.4R2.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-xvm6-4q8f-x3f5

около 4 лет назад

TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) contains a null pointer dereference vulnerability, which may allow a remote attacker to stop the network functions of the products or execute a malicious program via a specially crafted packet.

EPSS: Низкий
github логотип

GHSA-xvm4-x6jf-7p35

почти 4 года назад

Dell Client BIOS Versions prior to the remediated version contain an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xvm4-qw2r-9jf6

больше 3 лет назад

egg-compile.scm in CHICKEN 5.x before 5.3.1 allows arbitrary OS command execution during package installation via escape characters in a .egg file.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xvm4-hfq6-6r23

около 3 лет назад

Information disclosure in Linux Networking Firmware due to unauthorized information leak during side channel analysis.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xvm4-2pvm-hp3g

около 4 лет назад

The MiCODUS MV720 GPS tracker API server has an authentication mechanism that allows devices to use a hard-coded master password. This may allow an attacker to send SMS commands directly to the GPS tracker as if they were coming from the GPS owner’s mobile number.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xvm3-w96c-9whc

больше 1 года назад

An issue was discovered in FlexRIC 2.0.0. It crashes during a Subscription Request denial-of-service (DoS) attack, triggered by an assertion error. An attacker must send a high number of E42 Subscription Requests to the Near-RT RIC component.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-xvm3-rxj9-vf93

около 4 лет назад

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.2RX before 8.2R12.1, users using SAML authentication with the Reuse Existing NC (Pulse) Session option may see authentication leaks.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xvm2-9xvc-hx7f

больше 4 лет назад

Improper Restriction of XML External Entity Reference in com.monitorjbl:xlsx-streamer

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xvjx-r8gr-f7cg

около 4 лет назад

Cross-site scripting (XSS) vulnerability in Tickets/Submit in Kayako Fusion before 4.40.985 allows remote attackers to inject arbitrary web script or HTML via certain vectors, possibly a crafted ticket description.

EPSS: Низкий
github логотип

GHSA-xvjx-j3q9-j35p

больше 2 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xvjx-89jh-j37p

около 4 лет назад

The Juniper SRX Series services gateways with Junos OS 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, and 12.3X48 before 12.3X48-D15 do not properly implement the "set system ports console insecure" feature, which allows physically proximate attackers to gain administrative privileges by leveraging access to the console port.

EPSS: Низкий
github логотип

GHSA-xvjw-m4jg-m2m4

около 2 месяцев назад

Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise WebCenter Content: Imaging. Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xvjw-g673-q26h

около 4 лет назад

The QuickType feature in the Keyboards subsystem in Apple iOS before 8.3 allows physically proximate attackers to discover passcodes by reading the lock screen during use of a Bluetooth keyboard.

EPSS: Низкий
github логотип

GHSA-xvjq-vrrj-vrmg

около 4 лет назад

Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects WAC505 before 8.0.6.4 and WAC510 before 8.0.6.4.

EPSS: Низкий
github логотип

GHSA-xvjp-9xvp-rjm8

около 4 лет назад

Cross-site request forgery (CSRF) vulnerability in Cisco TelePresence Video Communication Server (VCS) X8.5.1 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuv72412.

EPSS: Низкий
github логотип

GHSA-xvjp-7j8r-cgj2

около 4 лет назад

A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 11, Internet Explorer 10.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xvjp-783h-vvhp

4 месяца назад

Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

CVSS3: 5.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xvm7-hp96-mh3h

Foxit PDF Editor StrikeOut Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14355.

CVSS3: 7.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-xvm7-544m-j5w9

Product: AndroidVersions: Android kernelAndroid ID: A-204956204References: N/A

CVSS3: 9.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-xvm6-65jm-mc4g

An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow daemon (flowd) of Juniper Networks Junos OS on SRX4600 and SRX5000 Series allows an attacker to send TCP packets with SYN/FIN or SYN/RST flags, bypassing the expected blocking of these packets. A TCP packet with SYN/FIN or SYN/RST should be dropped in flowd. However, when no-syn-check and Express Path are enabled, these TCP packets are unexpectedly transferred to the downstream network. This issue affects Junos OS on SRX4600 and SRX5000 Series: * All versions before 21.2R3-S8, * from 21.4 before 21.4R3-S7, * from 22.1 before 22.1R3-S6, * from 22.2 before 22.2R3-S4, * from 22.3 before 22.3R3-S3, * from 22.4 before 22.4R3-S2, * from 23.2 before 23.2R2, * from 23.4 before 23.4R1-S1, 23.4R2.

CVSS3: 5.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-xvm6-4q8f-x3f5

TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) contains a null pointer dereference vulnerability, which may allow a remote attacker to stop the network functions of the products or execute a malicious program via a specially crafted packet.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xvm4-x6jf-7p35

Dell Client BIOS Versions prior to the remediated version contain an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xvm4-qw2r-9jf6

egg-compile.scm in CHICKEN 5.x before 5.3.1 allows arbitrary OS command execution during package installation via escape characters in a .egg file.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xvm4-hfq6-6r23

Information disclosure in Linux Networking Firmware due to unauthorized information leak during side channel analysis.

CVSS3: 7.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-xvm4-2pvm-hp3g

The MiCODUS MV720 GPS tracker API server has an authentication mechanism that allows devices to use a hard-coded master password. This may allow an attacker to send SMS commands directly to the GPS tracker as if they were coming from the GPS owner’s mobile number.

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xvm3-w96c-9whc

An issue was discovered in FlexRIC 2.0.0. It crashes during a Subscription Request denial-of-service (DoS) attack, triggered by an assertion error. An attacker must send a high number of E42 Subscription Requests to the Near-RT RIC component.

CVSS3: 5.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-xvm3-rxj9-vf93

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.2RX before 8.2R12.1, users using SAML authentication with the Reuse Existing NC (Pulse) Session option may see authentication leaks.

CVSS3: 7.5
4%
Низкий
около 4 лет назад
github логотип
GHSA-xvm2-9xvc-hx7f

Improper Restriction of XML External Entity Reference in com.monitorjbl:xlsx-streamer

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xvjx-r8gr-f7cg

Cross-site scripting (XSS) vulnerability in Tickets/Submit in Kayako Fusion before 4.40.985 allows remote attackers to inject arbitrary web script or HTML via certain vectors, possibly a crafted ticket description.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xvjx-j3q9-j35p

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).

CVSS3: 5.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xvjx-89jh-j37p

The Juniper SRX Series services gateways with Junos OS 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, and 12.3X48 before 12.3X48-D15 do not properly implement the "set system ports console insecure" feature, which allows physically proximate attackers to gain administrative privileges by leveraging access to the console port.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xvjw-m4jg-m2m4

Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise WebCenter Content: Imaging. Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 9.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xvjw-g673-q26h

The QuickType feature in the Keyboards subsystem in Apple iOS before 8.3 allows physically proximate attackers to discover passcodes by reading the lock screen during use of a Bluetooth keyboard.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xvjq-vrrj-vrmg

Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects WAC505 before 8.0.6.4 and WAC510 before 8.0.6.4.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xvjp-9xvp-rjm8

Cross-site request forgery (CSRF) vulnerability in Cisco TelePresence Video Communication Server (VCS) X8.5.1 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuv72412.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xvjp-7j8r-cgj2

A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 11, Internet Explorer 10.

CVSS3: 7.5
10%
Низкий
около 4 лет назад
github логотип
GHSA-xvjp-783h-vvhp

Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

CVSS3: 5.1
0%
Низкий
4 месяца назад

Уязвимостей на страницу