Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 373 528

Количество 373 528

github логотип

GHSA-xxq9-94ff-354x

больше 2 лет назад

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_subscribe_get_nl_params(), there is no input validation check on hal_req->num_intf_addr_present coming from userspace, which can lead to a heap overwrite.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-xxq8-w68p-wqxp

больше 4 лет назад

Improper exception handling in Samsung Pass prior to version 3.7.07.5 allows physical attacker to view the screen that is previously running without authentication

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xxq8-5mc3-63xg

почти 4 года назад

IBM CICS TX 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. X-Force ID: 229449.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-xxq8-555q-w627

больше 4 лет назад

Unspecified "absolute path vulnerability" in umountall in IBM AIX 5.1 through 5.3 allows local users to cause unknown impact via unknown vectors.

EPSS: Низкий
github логотип

GHSA-xxq7-hjr2-f27f

больше 4 лет назад

Verizon 4G LTE Network Extender GA4.38 - V0.4.038.2131 utilizes a weak default admin password generation algorithm which generates passwords that are accessible to unauthenticated attackers via the webUI login page.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxq5-xj37-9fx7

больше 4 лет назад

It was discovered that the fix for CVE-2017-12163 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxq5-c27j-953j

почти 3 года назад

Microsoft Outlook for Mac Spoofing Vulnerability

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xxq4-jv5p-cfwc

больше 4 лет назад

In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any other users.

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-xxq4-9c68-6533

около 2 лет назад

Windows Authentication Information Disclosure Vulnerability

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxq4-3742-3h28

больше 4 лет назад

Generation of Error Message Containing Sensitive Information in microweber

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xxq3-gj76-wh9v

больше 4 лет назад

PHP remote file inclusion vulnerability in core/videodb.class.xml.php in the VideoDB component for Mambo 0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

EPSS: Низкий
github логотип

GHSA-xxq3-764r-q6rm

больше 4 лет назад

AdPlug 2.3.1 has a heap-based buffer overflow in CmkjPlayer::load() in mkj.cpp.

EPSS: Низкий
github логотип

GHSA-xxq2-fm9w-xjv8

8 месяцев назад

The Relevanssi WordPress plugin before 4.26.0, Relevanssi Premium WordPress plugin before 2.29.0 do not sanitize and escape a parameter before using it in a SQL statement, allowing contributor and above roles to perform SQL injection attacks

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-xxq2-97gh-5p37

около 1 месяца назад

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel memory access and in certain cases cause GPU UAF of arbitrary pages. Incorrect validation of array index can lead to OOB read and potentially to GPU UAF of arbitrary pages.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xxq2-74hw-vg6m

больше 3 лет назад

Jenkins WSO2 Oauth Plugin Session Fixation vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xxq2-62cv-vmcw

больше 3 лет назад

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in psicosi448 wp2syslog plugin <= 1.0.5 versions.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xxpx-w698-q23j

около 4 лет назад

When a user opens manipulated JPEG 2000 (.jp2, jp2k.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application. The file format details along with their CVE relevant information can be found below

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxpx-f58m-683f

больше 1 года назад

Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insufficient Resource Pool vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xxpx-f366-4xpq

около 1 месяца назад

Craft CMS: Authorization bypass: view-only Categories user can modify category structure via structures/move-element

EPSS: Низкий
github логотип

GHSA-xxpw-3xg9-qwph

около 1 месяца назад

The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access of protected files due to insufficient token validation in the `get_advance_file_by_url()` method in all versions up to, and including, 2.8.8.8 The method uses a SQL `LIKE` operator for token lookup without escaping wildcard characters via `$wpdb->esc_like()`. This makes it possible for unauthenticated attackers to bypass the private token requirement by supplying SQL wildcard characters (such as `%`) as the token value, matching any record in the plugin's file table and downloading any protected file.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xxq9-94ff-354x

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_subscribe_get_nl_params(), there is no input validation check on hal_req->num_intf_addr_present coming from userspace, which can lead to a heap overwrite.

CVSS3: 6.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xxq8-w68p-wqxp

Improper exception handling in Samsung Pass prior to version 3.7.07.5 allows physical attacker to view the screen that is previously running without authentication

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xxq8-5mc3-63xg

IBM CICS TX 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. X-Force ID: 229449.

CVSS3: 3.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-xxq8-555q-w627

Unspecified "absolute path vulnerability" in umountall in IBM AIX 5.1 through 5.3 allows local users to cause unknown impact via unknown vectors.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xxq7-hjr2-f27f

Verizon 4G LTE Network Extender GA4.38 - V0.4.038.2131 utilizes a weak default admin password generation algorithm which generates passwords that are accessible to unauthenticated attackers via the webUI login page.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xxq5-xj37-9fx7

It was discovered that the fix for CVE-2017-12163 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xxq5-c27j-953j

Microsoft Outlook for Mac Spoofing Vulnerability

CVSS3: 5.3
1%
Низкий
почти 3 года назад
github логотип
GHSA-xxq4-jv5p-cfwc

In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any other users.

CVSS3: 3.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xxq4-9c68-6533

Windows Authentication Information Disclosure Vulnerability

CVSS3: 5.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-xxq4-3742-3h28

Generation of Error Message Containing Sensitive Information in microweber

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xxq3-gj76-wh9v

PHP remote file inclusion vulnerability in core/videodb.class.xml.php in the VideoDB component for Mambo 0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xxq3-764r-q6rm

AdPlug 2.3.1 has a heap-based buffer overflow in CmkjPlayer::load() in mkj.cpp.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xxq2-fm9w-xjv8

The Relevanssi WordPress plugin before 4.26.0, Relevanssi Premium WordPress plugin before 2.29.0 do not sanitize and escape a parameter before using it in a SQL statement, allowing contributor and above roles to perform SQL injection attacks

CVSS3: 4.9
0%
Низкий
8 месяцев назад
github логотип
GHSA-xxq2-97gh-5p37

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel memory access and in certain cases cause GPU UAF of arbitrary pages. Incorrect validation of array index can lead to OOB read and potentially to GPU UAF of arbitrary pages.

CVSS3: 7.1
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xxq2-74hw-vg6m

Jenkins WSO2 Oauth Plugin Session Fixation vulnerability

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xxq2-62cv-vmcw

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in psicosi448 wp2syslog plugin <= 1.0.5 versions.

CVSS3: 5.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xxpx-w698-q23j

When a user opens manipulated JPEG 2000 (.jp2, jp2k.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application. The file format details along with their CVE relevant information can be found below

CVSS3: 5.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xxpx-f58m-683f

Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insufficient Resource Pool vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-xxpx-f366-4xpq

Craft CMS: Authorization bypass: view-only Categories user can modify category structure via structures/move-element

0%
Низкий
около 1 месяца назад
github логотип
GHSA-xxpw-3xg9-qwph

The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access of protected files due to insufficient token validation in the `get_advance_file_by_url()` method in all versions up to, and including, 2.8.8.8 The method uses a SQL `LIKE` operator for token lookup without escaping wildcard characters via `$wpdb->esc_like()`. This makes it possible for unauthenticated attackers to bypass the private token requirement by supplying SQL wildcard characters (such as `%`) as the token value, matching any record in the plugin's file table and downloading any protected file.

CVSS3: 5.3
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу