Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 354 500

Количество 354 500

github логотип

GHSA-xvcw-fcfv-34gg

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in core.input.php in ExpressionEngine 1.4.1 allows remote attackers to inject arbitrary web script or HTML via HTTP_REFERER (referer).

EPSS: Низкий
github логотип

GHSA-xvcw-f78r-rfc5

больше 4 лет назад

WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly handle changes to keyboard focus that occur during processing of key press events, which allows remote attackers to force arbitrary key presses via a crafted HTML document.

EPSS: Низкий
github логотип

GHSA-xvcw-3rfr-7w27

около 4 лет назад

The gdImageRotateInterpolated function in ext/gd/libgd/gd_interpolation.c in PHP before 5.5.31, 5.6.x before 5.6.17, and 7.x before 7.0.2 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a large bgd_color argument to the imagerotate function.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xvcw-283x-r7pw

больше 4 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the DataProvider class. The issue results from the lack of proper validation of a user-supplied string before executing it as JavaScript code. An attacker can leverage this vulnerability to escape the JavaScript sandbox and execute Java code in the context of NETWORK SERVICE. Was ZDI-CAN-13755.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xvcv-9c64-gw2j

3 месяца назад

Allok soft WMV to AVI MPEG DVD WMV Converter 4.6.1217 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized string in the License Name field. Attackers can craft a malicious input containing shellcode with structured exception handler (SEH) overwrite to bypass protections and execute code with application privileges.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-xvcv-5fpw-x4r5

3 месяца назад

Illustrator versions 29.8.6, 30.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xvcr-mm2p-vgrf

больше 3 лет назад

The Spacer WordPress plugin before 3.0.7 does not sanitize and escapes some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xvcr-5pxv-hxgc

около 4 лет назад

An error within the "parse_sinar_ia()" function (internal/dcraw_common.cpp) within LibRaw versions prior to 0.19.1 can be exploited to exhaust available CPU resources.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xvcr-4h4q-m7m8

около 4 лет назад

An issue was discovered in Cloud Foundry Foundation cf-release v255 and Staticfile buildpack versions v1.4.0 - v1.4.3. A regression introduced in the Static file build pack causes the Staticfile.auth configuration to be ignored when the Static file file is not present in the application root. Applications containing a Staticfile.auth file but not a Static file had their basic auth turned off when an operator upgraded the Static file build pack in the foundation to one of the vulnerable versions. Note that Static file applications without a Static file are technically misconfigured, and will not successfully detect unless the Static file build pack is explicitly specified.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xvcq-gm57-37c5

около 2 лет назад

LB-LINK BL-W1210M v2.0 was discovered to contain a clickjacking vulnerability via the Administrator login page. Attackers can cause victim users to perform arbitrary operations via interaction with crafted elements on the web page.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xvcp-f5rw-f54w

почти 3 года назад

A?CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')?vulnerability exists?that could cause?a path traversal issue?when?using the File Command. 

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xvcp-85rr-xfr8

около 4 лет назад

A remote command injection vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

EPSS: Низкий
github логотип

GHSA-xvcp-33rc-j8gq

около 2 лет назад

Insecure Unserialize in TYPO3 Import/Export

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xvcm-6775-5m9r

16 дней назад

Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set

EPSS: Низкий
github логотип

GHSA-xvcm-5qj2-5972

почти 2 года назад

The Embed PDF Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' and 'width' parameters in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-xvcj-qw55-xx42

около 2 лет назад

EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Zero due to a UNIT32 overflow via local access. A successful exploit of this vulnerability may lead to a loss of Availability.

CVSS3: 6
EPSS: Низкий
github логотип

GHSA-xvcj-9449-w85c

больше 1 года назад

The Maintenance & Coming Soon Redirect Animation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wploti_add_whitelisted_roles_option', 'wploti_remove_whitelisted_roles_option', 'wploti_add_whitelisted_users_option', 'wploti_remove_whitelisted_users_option', and 'wploti_uploaded_animation_save_option' functions in all versions up to, and including, 2.1.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify certain plugin settings.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xvcj-65f9-8jg3

2 месяца назад

IBM Guardium Data Protection 12.2.1, and 12.2.2 's add-on feature of Guardium Data Protection named "Long Term Retention" (LTR) can expose sensitive credentials in debug mode.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xvch-r4wf-h8w9

больше 7 лет назад

Improper Certificate Validation in proton-j

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-xvch-q88g-j649

около 4 лет назад

The Cut the Rope: Time Travel (aka com.zeptolab.timetravel.free.google) application 1.3.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xvcw-fcfv-34gg

Cross-site scripting (XSS) vulnerability in core.input.php in ExpressionEngine 1.4.1 allows remote attackers to inject arbitrary web script or HTML via HTTP_REFERER (referer).

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xvcw-f78r-rfc5

WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly handle changes to keyboard focus that occur during processing of key press events, which allows remote attackers to force arbitrary key presses via a crafted HTML document.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xvcw-3rfr-7w27

The gdImageRotateInterpolated function in ext/gd/libgd/gd_interpolation.c in PHP before 5.5.31, 5.6.x before 5.6.17, and 7.x before 7.0.2 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a large bgd_color argument to the imagerotate function.

CVSS3: 9.1
8%
Низкий
около 4 лет назад
github логотип
GHSA-xvcw-283x-r7pw

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the DataProvider class. The issue results from the lack of proper validation of a user-supplied string before executing it as JavaScript code. An attacker can leverage this vulnerability to escape the JavaScript sandbox and execute Java code in the context of NETWORK SERVICE. Was ZDI-CAN-13755.

CVSS3: 8.8
6%
Низкий
больше 4 лет назад
github логотип
GHSA-xvcv-9c64-gw2j

Allok soft WMV to AVI MPEG DVD WMV Converter 4.6.1217 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized string in the License Name field. Attackers can craft a malicious input containing shellcode with structured exception handler (SEH) overwrite to bypass protections and execute code with application privileges.

CVSS3: 8.4
0%
Низкий
3 месяца назад
github логотип
GHSA-xvcv-5fpw-x4r5

Illustrator versions 29.8.6, 30.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
0%
Низкий
3 месяца назад
github логотип
GHSA-xvcr-mm2p-vgrf

The Spacer WordPress plugin before 3.0.7 does not sanitize and escapes some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvcr-5pxv-hxgc

An error within the "parse_sinar_ia()" function (internal/dcraw_common.cpp) within LibRaw versions prior to 0.19.1 can be exploited to exhaust available CPU resources.

CVSS3: 7.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-xvcr-4h4q-m7m8

An issue was discovered in Cloud Foundry Foundation cf-release v255 and Staticfile buildpack versions v1.4.0 - v1.4.3. A regression introduced in the Static file build pack causes the Staticfile.auth configuration to be ignored when the Static file file is not present in the application root. Applications containing a Staticfile.auth file but not a Static file had their basic auth turned off when an operator upgraded the Static file build pack in the foundation to one of the vulnerable versions. Note that Static file applications without a Static file are technically misconfigured, and will not successfully detect unless the Static file build pack is explicitly specified.

CVSS3: 5.9
1%
Низкий
около 4 лет назад
github логотип
GHSA-xvcq-gm57-37c5

LB-LINK BL-W1210M v2.0 was discovered to contain a clickjacking vulnerability via the Administrator login page. Attackers can cause victim users to perform arbitrary operations via interaction with crafted elements on the web page.

CVSS3: 8.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-xvcp-f5rw-f54w

A?CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')?vulnerability exists?that could cause?a path traversal issue?when?using the File Command. 

CVSS3: 9.8
39%
Средний
почти 3 года назад
github логотип
GHSA-xvcp-85rr-xfr8

A remote command injection vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

4%
Низкий
около 4 лет назад
github логотип
GHSA-xvcp-33rc-j8gq

Insecure Unserialize in TYPO3 Import/Export

CVSS3: 6.3
около 2 лет назад
github логотип
GHSA-xvcm-6775-5m9r

Immutabl: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set

0%
Низкий
16 дней назад
github логотип
GHSA-xvcm-5qj2-5972

The Embed PDF Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' and 'width' parameters in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-xvcj-qw55-xx42

EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Zero due to a UNIT32 overflow via local access. A successful exploit of this vulnerability may lead to a loss of Availability.

CVSS3: 6
0%
Низкий
около 2 лет назад
github логотип
GHSA-xvcj-9449-w85c

The Maintenance & Coming Soon Redirect Animation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wploti_add_whitelisted_roles_option', 'wploti_remove_whitelisted_roles_option', 'wploti_add_whitelisted_users_option', 'wploti_remove_whitelisted_users_option', and 'wploti_uploaded_animation_save_option' functions in all versions up to, and including, 2.1.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify certain plugin settings.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-xvcj-65f9-8jg3

IBM Guardium Data Protection 12.2.1, and 12.2.2 's add-on feature of Guardium Data Protection named "Long Term Retention" (LTR) can expose sensitive credentials in debug mode.

CVSS3: 6.5
0%
Низкий
2 месяца назад
github логотип
GHSA-xvch-r4wf-h8w9

Improper Certificate Validation in proton-j

CVSS3: 7.4
3%
Низкий
больше 7 лет назад
github логотип
GHSA-xvch-q88g-j649

The Cut the Rope: Time Travel (aka com.zeptolab.timetravel.free.google) application 1.3.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
около 4 лет назад

Уязвимостей на страницу