Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-xvhj-83gv-vjmg

больше 4 лет назад

Buffer overflow in L0pht AntiSniff allows remote attackers to execute arbitrary commands via a malformed DNS response packet.

EPSS: Низкий
github логотип

GHSA-xvhh-x8q7-xrxj

2 месяца назад

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Pluggable Auth). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server, MySQL Cluster accessible data. CVSS 3.1 Base Score 2.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).

CVSS3: 2.9
EPSS: Низкий
github логотип

GHSA-xvhg-w6qc-m3qq

около 3 лет назад

Yaklang Plugin's Fuzztag Component Allows Unauthorized Local File Reading

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xvhg-pwg9-qp4r

больше 4 лет назад

PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while reading a protocol message, which allows remote attackers to conduct SQL injection attacks via crafted binary data in a parameter and causing an error, which triggers the loss of synchronization and part of the protocol message to be treated as a new message, as demonstrated by causing a timeout or query cancellation.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xvhg-76qh-24v9

около 2 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: Fix null ptr deref in hci_abort_conn() hci_abort_conn() read hci_skb_event(hdev->sent_cmd) when a connection was pending, but hdev->sent_cmd can be NULL while req_status is still HCI_REQ_PEND, leading to a NULL pointer dereference and a general protection fault from the hci_rx_work() receive path. Instead of inspecting hdev->sent_cmd, track the in-flight create connection command with a new per-connection HCI_CONN_CREATE flag and route all cancellation through hci_cancel_connect_sync(), which dispatches to a dedicated per-type cancel function. The create command is in exactly one of two states: still queued, or in flight. The cancel function holds cmd_sync_work_lock across the whole decision: the worker takes this lock to dequeue every entry, so while it is held a queued command cannot start running and an in-flight command cannot complete and let the next command become pending. This keeps t...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xvhf-x56f-2hpp

7 месяцев назад

OpenClaw exec approvals: safeBins could bypass stdin-only constraints via shell expansion

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-xvhf-q744-5xm8

больше 4 лет назад

XXE vulnerability in NUnit Plugin

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-xvhf-gc4w-vcvc

4 дня назад

Memory Corruption when copying large input data exceeds normal allocation limits.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xvhf-cv8g-xhpr

8 дней назад

A vulnerability has been found in DataEase up to 2.10.25/2.10.26. Affected by this issue is the function buildTooltip of the file core/core-frontend/src/views/chart/components/js/panel/charts/map/symbolic-map.ts of the component Symbolic Map. Such manipulation of the argument canvasViewInfo[*].customAttr.tooltip.backgroundColor leads to cross site scripting. The attack may be performed from remote. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-xvhc-r5q4-hcgj

3 месяца назад

InCopy versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xvhc-jj62-7h84

около 1 года назад

The StrongDM Windows service incorrectly handled input validation. Authenticated attackers could potentially exploit this leading to privilege escalation.

EPSS: Низкий
github логотип

GHSA-xvhc-gm7j-mhmc

4 месяца назад

Shopware: Stored XSS via SVG file upload — no SVG sanitization

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-xvh9-mfm3-cvfq

больше 4 лет назад

wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to upgrade the application, and possibly cause a denial of service (application outage), via a direct request.

EPSS: Низкий
github логотип

GHSA-xvh9-jpfj-m9hg

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in classifieds/viewcat.cgi in KCScripts Classifieds, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter.

EPSS: Низкий
github логотип

GHSA-xvh8-gxxm-2h9g

больше 4 лет назад

SQL injection vulnerability in Webmatic before 2.8 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xvh8-g3fx-684w

больше 4 лет назад

D-Link DSR-250N devices with firmware 1.05B73_WW allow Persistent Root Access because of the admin password for the admin account.

EPSS: Низкий
github логотип

GHSA-xvh8-f5vg-49g2

около 1 года назад

A security flaw has been discovered in D-Link DIR-825 up to 2.10. Affected by this vulnerability is the function sub_4106d4 of the file apply.cgi. The manipulation of the argument countdown_time results in buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be exploited. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xvh8-9h96-57r8

8 месяцев назад

IDOR vulnerability has been found in Viafirma Inbox v4.5.13 that allows any authenticated user without privileges in the application to list all users, access and modify their data. This allows the user's email addresses to be modified and, subsequently, using the password recovery functionality to access the application by impersonating any user, including those with administrative permissions.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xvh8-95gq-687q

больше 4 лет назад

Huawei DP300, V500R002C00, RP200, V600R006C00, TE30, V100R001C10, V500R002C00,V600R006C00, TE40, V500R002C00, V600R006C00, TE50, V500R002C00,V600R006C00, TE60, V100R001C10, V500R002C00, V600R006C00, TX50,V500R002C00, V600R006C00 have a buffer overflow vulnerability. An attacker may send specially crafted HTTP messages to the affected products. Due insufficient input validation of three different parameters in the messages, successful exploit may cause some service abnormal.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xvh7-j354-hww5

больше 4 лет назад

An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vulnerability'.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xvhj-83gv-vjmg

Buffer overflow in L0pht AntiSniff allows remote attackers to execute arbitrary commands via a malformed DNS response packet.

8%
Низкий
больше 4 лет назад
github логотип
GHSA-xvhh-x8q7-xrxj

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Pluggable Auth). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server, MySQL Cluster accessible data. CVSS 3.1 Base Score 2.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).

CVSS3: 2.9
0%
Низкий
2 месяца назад
github логотип
GHSA-xvhg-w6qc-m3qq

Yaklang Plugin's Fuzztag Component Allows Unauthorized Local File Reading

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-xvhg-pwg9-qp4r

PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while reading a protocol message, which allows remote attackers to conduct SQL injection attacks via crafted binary data in a parameter and causing an error, which triggers the loss of synchronization and part of the protocol message to be treated as a new message, as demonstrated by causing a timeout or query cancellation.

CVSS3: 9.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-xvhg-76qh-24v9

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: Fix null ptr deref in hci_abort_conn() hci_abort_conn() read hci_skb_event(hdev->sent_cmd) when a connection was pending, but hdev->sent_cmd can be NULL while req_status is still HCI_REQ_PEND, leading to a NULL pointer dereference and a general protection fault from the hci_rx_work() receive path. Instead of inspecting hdev->sent_cmd, track the in-flight create connection command with a new per-connection HCI_CONN_CREATE flag and route all cancellation through hci_cancel_connect_sync(), which dispatches to a dedicated per-type cancel function. The create command is in exactly one of two states: still queued, or in flight. The cancel function holds cmd_sync_work_lock across the whole decision: the worker takes this lock to dequeue every entry, so while it is held a queued command cannot start running and an in-flight command cannot complete and let the next command become pending. This keeps t...

CVSS3: 5.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xvhf-x56f-2hpp

OpenClaw exec approvals: safeBins could bypass stdin-only constraints via shell expansion

CVSS3: 5.7
0%
Низкий
7 месяцев назад
github логотип
GHSA-xvhf-q744-5xm8

XXE vulnerability in NUnit Plugin

CVSS3: 7.6
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xvhf-gc4w-vcvc

Memory Corruption when copying large input data exceeds normal allocation limits.

CVSS3: 7.8
0%
Низкий
4 дня назад
github логотип
GHSA-xvhf-cv8g-xhpr

A vulnerability has been found in DataEase up to 2.10.25/2.10.26. Affected by this issue is the function buildTooltip of the file core/core-frontend/src/views/chart/components/js/panel/charts/map/symbolic-map.ts of the component Symbolic Map. Such manipulation of the argument canvasViewInfo[*].customAttr.tooltip.backgroundColor leads to cross site scripting. The attack may be performed from remote. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 3.5
0%
Низкий
8 дней назад
github логотип
GHSA-xvhc-r5q4-hcgj

InCopy versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
3 месяца назад
github логотип
GHSA-xvhc-jj62-7h84

The StrongDM Windows service incorrectly handled input validation. Authenticated attackers could potentially exploit this leading to privilege escalation.

0%
Низкий
около 1 года назад
github логотип
GHSA-xvhc-gm7j-mhmc

Shopware: Stored XSS via SVG file upload — no SVG sanitization

CVSS3: 4.9
0%
Низкий
4 месяца назад
github логотип
GHSA-xvh9-mfm3-cvfq

wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to upgrade the application, and possibly cause a denial of service (application outage), via a direct request.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-xvh9-jpfj-m9hg

Cross-site scripting (XSS) vulnerability in classifieds/viewcat.cgi in KCScripts Classifieds, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xvh8-gxxm-2h9g

SQL injection vulnerability in Webmatic before 2.8 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xvh8-g3fx-684w

D-Link DSR-250N devices with firmware 1.05B73_WW allow Persistent Root Access because of the admin password for the admin account.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xvh8-f5vg-49g2

A security flaw has been discovered in D-Link DIR-825 up to 2.10. Affected by this vulnerability is the function sub_4106d4 of the file apply.cgi. The manipulation of the argument countdown_time results in buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be exploited. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 8.8
3%
Низкий
около 1 года назад
github логотип
GHSA-xvh8-9h96-57r8

IDOR vulnerability has been found in Viafirma Inbox v4.5.13 that allows any authenticated user without privileges in the application to list all users, access and modify their data. This allows the user's email addresses to be modified and, subsequently, using the password recovery functionality to access the application by impersonating any user, including those with administrative permissions.

CVSS3: 8.1
0%
Низкий
8 месяцев назад
github логотип
GHSA-xvh8-95gq-687q

Huawei DP300, V500R002C00, RP200, V600R006C00, TE30, V100R001C10, V500R002C00,V600R006C00, TE40, V500R002C00, V600R006C00, TE50, V500R002C00,V600R006C00, TE60, V100R001C10, V500R002C00, V600R006C00, TX50,V500R002C00, V600R006C00 have a buffer overflow vulnerability. An attacker may send specially crafted HTTP messages to the affected products. Due insufficient input validation of three different parameters in the messages, successful exploit may cause some service abnormal.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xvh7-j354-hww5

An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vulnerability'.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу