Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-xvm9-hx6q-g9jq

больше 4 лет назад

On F5 BIG-IP 16.1.x versions prior to 16.1.2 and 15.1.x versions prior to 15.1.5.1, when the DNS resolver configuration is used, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xvm9-7c7q-qvh6

больше 4 лет назад

SQL Injection exists in the Saxum Numerology 3.0.4 component for Joomla! via the publicid parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xvm9-36wr-8w6j

10 месяцев назад

Protection mechanism failure for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an information disclosure. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable data exposure. This result may potentially occur via adjacent access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xvm8-45r5-rf28

5 месяцев назад

A vulnerability in the AdminServer component of OpenEdge on all supported platforms grants its authenticated users OS-level access to the server through the adopted authority of the AdminServer process itself.  The delegated authority of the AdminServer could allow its users the ability to read arbitrary files on the host system through the misuse of the setFile() and openFile() methods exposed through the RMI interface.  Misuse was limited only by OS-level authority of the AdminServer's elevated privileges granted and the user's access to these methods enabled through RMI.  The exploitable methods have been removed thus eliminating their access through RMI or downstream of the RMI registry.

EPSS: Низкий
github логотип

GHSA-xvm7-mqpx-hcpp

больше 4 лет назад

Dependency-Track before 3.5.1 allows XSS.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xvm7-hp96-mh3h

больше 2 лет назад

Foxit PDF Editor StrikeOut Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14355.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xvm7-544m-j5w9

больше 4 лет назад

Product: AndroidVersions: Android kernelAndroid ID: A-204956204References: N/A

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xvm6-65jm-mc4g

около 2 лет назад

An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow daemon (flowd) of Juniper Networks Junos OS on SRX4600 and SRX5000 Series allows an attacker to send TCP packets with SYN/FIN or SYN/RST flags, bypassing the expected blocking of these packets. A TCP packet with SYN/FIN or SYN/RST should be dropped in flowd. However, when no-syn-check and Express Path are enabled, these TCP packets are unexpectedly transferred to the downstream network. This issue affects Junos OS on SRX4600 and SRX5000 Series: * All versions before 21.2R3-S8, * from 21.4 before 21.4R3-S7, * from 22.1 before 22.1R3-S6, * from 22.2 before 22.2R3-S4, * from 22.3 before 22.3R3-S3, * from 22.4 before 22.4R3-S2, * from 23.2 before 23.2R2, * from 23.4 before 23.4R1-S1, 23.4R2.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-xvm6-4q8f-x3f5

больше 4 лет назад

TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) contains a null pointer dereference vulnerability, which may allow a remote attacker to stop the network functions of the products or execute a malicious program via a specially crafted packet.

EPSS: Низкий
github логотип

GHSA-xvm4-x6jf-7p35

почти 4 года назад

Dell Client BIOS Versions prior to the remediated version contain an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xvm4-qw2r-9jf6

почти 4 года назад

egg-compile.scm in CHICKEN 5.x before 5.3.1 allows arbitrary OS command execution during package installation via escape characters in a .egg file.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xvm4-hfq6-6r23

больше 3 лет назад

Information disclosure in Linux Networking Firmware due to unauthorized information leak during side channel analysis.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xvm4-2pvm-hp3g

около 4 лет назад

The MiCODUS MV720 GPS tracker API server has an authentication mechanism that allows devices to use a hard-coded master password. This may allow an attacker to send SMS commands directly to the GPS tracker as if they were coming from the GPS owner’s mobile number.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xvm3-w96c-9whc

больше 1 года назад

An issue was discovered in FlexRIC 2.0.0. It crashes during a Subscription Request denial-of-service (DoS) attack, triggered by an assertion error. An attacker must send a high number of E42 Subscription Requests to the Near-RT RIC component.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-xvm3-rxj9-vf93

больше 4 лет назад

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.2RX before 8.2R12.1, users using SAML authentication with the Reuse Existing NC (Pulse) Session option may see authentication leaks.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xvm2-9xvc-hx7f

больше 4 лет назад

Improper Restriction of XML External Entity Reference in com.monitorjbl:xlsx-streamer

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xvjx-r8gr-f7cg

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in Tickets/Submit in Kayako Fusion before 4.40.985 allows remote attackers to inject arbitrary web script or HTML via certain vectors, possibly a crafted ticket description.

EPSS: Низкий
github логотип

GHSA-xvjx-j3q9-j35p

больше 2 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xvjx-89jh-j37p

больше 4 лет назад

The Juniper SRX Series services gateways with Junos OS 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, and 12.3X48 before 12.3X48-D15 do not properly implement the "set system ports console insecure" feature, which allows physically proximate attackers to gain administrative privileges by leveraging access to the console port.

EPSS: Низкий
github логотип

GHSA-xvjw-m4jg-m2m4

3 месяца назад

Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise WebCenter Content: Imaging. Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xvm9-hx6q-g9jq

On F5 BIG-IP 16.1.x versions prior to 16.1.2 and 15.1.x versions prior to 15.1.5.1, when the DNS resolver configuration is used, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xvm9-7c7q-qvh6

SQL Injection exists in the Saxum Numerology 3.0.4 component for Joomla! via the publicid parameter.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-xvm9-36wr-8w6j

Protection mechanism failure for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an information disclosure. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable data exposure. This result may potentially occur via adjacent access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-xvm8-45r5-rf28

A vulnerability in the AdminServer component of OpenEdge on all supported platforms grants its authenticated users OS-level access to the server through the adopted authority of the AdminServer process itself.  The delegated authority of the AdminServer could allow its users the ability to read arbitrary files on the host system through the misuse of the setFile() and openFile() methods exposed through the RMI interface.  Misuse was limited only by OS-level authority of the AdminServer's elevated privileges granted and the user's access to these methods enabled through RMI.  The exploitable methods have been removed thus eliminating their access through RMI or downstream of the RMI registry.

0%
Низкий
5 месяцев назад
github логотип
GHSA-xvm7-mqpx-hcpp

Dependency-Track before 3.5.1 allows XSS.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xvm7-hp96-mh3h

Foxit PDF Editor StrikeOut Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14355.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xvm7-544m-j5w9

Product: AndroidVersions: Android kernelAndroid ID: A-204956204References: N/A

CVSS3: 9.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xvm6-65jm-mc4g

An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow daemon (flowd) of Juniper Networks Junos OS on SRX4600 and SRX5000 Series allows an attacker to send TCP packets with SYN/FIN or SYN/RST flags, bypassing the expected blocking of these packets. A TCP packet with SYN/FIN or SYN/RST should be dropped in flowd. However, when no-syn-check and Express Path are enabled, these TCP packets are unexpectedly transferred to the downstream network. This issue affects Junos OS on SRX4600 and SRX5000 Series: * All versions before 21.2R3-S8, * from 21.4 before 21.4R3-S7, * from 22.1 before 22.1R3-S6, * from 22.2 before 22.2R3-S4, * from 22.3 before 22.3R3-S3, * from 22.4 before 22.4R3-S2, * from 23.2 before 23.2R2, * from 23.4 before 23.4R1-S1, 23.4R2.

CVSS3: 5.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-xvm6-4q8f-x3f5

TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) contains a null pointer dereference vulnerability, which may allow a remote attacker to stop the network functions of the products or execute a malicious program via a specially crafted packet.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xvm4-x6jf-7p35

Dell Client BIOS Versions prior to the remediated version contain an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xvm4-qw2r-9jf6

egg-compile.scm in CHICKEN 5.x before 5.3.1 allows arbitrary OS command execution during package installation via escape characters in a .egg file.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-xvm4-hfq6-6r23

Information disclosure in Linux Networking Firmware due to unauthorized information leak during side channel analysis.

CVSS3: 7.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvm4-2pvm-hp3g

The MiCODUS MV720 GPS tracker API server has an authentication mechanism that allows devices to use a hard-coded master password. This may allow an attacker to send SMS commands directly to the GPS tracker as if they were coming from the GPS owner’s mobile number.

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xvm3-w96c-9whc

An issue was discovered in FlexRIC 2.0.0. It crashes during a Subscription Request denial-of-service (DoS) attack, triggered by an assertion error. An attacker must send a high number of E42 Subscription Requests to the Near-RT RIC component.

CVSS3: 5.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-xvm3-rxj9-vf93

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.2RX before 8.2R12.1, users using SAML authentication with the Reuse Existing NC (Pulse) Session option may see authentication leaks.

CVSS3: 7.5
4%
Низкий
больше 4 лет назад
github логотип
GHSA-xvm2-9xvc-hx7f

Improper Restriction of XML External Entity Reference in com.monitorjbl:xlsx-streamer

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xvjx-r8gr-f7cg

Cross-site scripting (XSS) vulnerability in Tickets/Submit in Kayako Fusion before 4.40.985 allows remote attackers to inject arbitrary web script or HTML via certain vectors, possibly a crafted ticket description.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xvjx-j3q9-j35p

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).

CVSS3: 5.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xvjx-89jh-j37p

The Juniper SRX Series services gateways with Junos OS 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, and 12.3X48 before 12.3X48-D15 do not properly implement the "set system ports console insecure" feature, which allows physically proximate attackers to gain administrative privileges by leveraging access to the console port.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xvjw-m4jg-m2m4

Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise WebCenter Content: Imaging. Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 9.8
0%
Низкий
3 месяца назад

Уязвимостей на страницу