Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 453

Количество 375 453

github логотип

GHSA-xvch-q88g-j649

больше 4 лет назад

The Cut the Rope: Time Travel (aka com.zeptolab.timetravel.free.google) application 1.3.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-xvch-pp92-23j8

около 3 лет назад

Windows Installer Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xvch-fv6q-gx5m

больше 4 лет назад

Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.7.32 and prior and 8.0.22 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Client. CVSS 3.1 Base Score 5.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xvch-5gv4-984h

больше 4 лет назад

Prototype Pollution in minimist

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xvcg-x6pj-6267

больше 4 лет назад

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/manage-tickets.php by adding a question mark (?) followed by the payload.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xvcg-hv6h-729g

больше 4 лет назад

PackLinuxElf64::unpack in p_lx_elf.cpp in UPX 3.95 allows remote attackers to cause a denial of service (double free), limit the ability of a malware scanner to operate on the entire original data, or possibly have unspecified other impact via a crafted file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xvcg-ff9f-p7x7

больше 4 лет назад

SQL injection vulnerability in home.html in Xpoze Pro 4.10 allows remote attackers to execute arbitrary SQL commands via the menu parameter.

EPSS: Низкий
github логотип

GHSA-xvcg-crx7-qcjv

почти 2 года назад

Weaver Ecology v9* was discovered to contain a SQL injection vulnerability.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xvcg-2q82-r87j

больше 4 лет назад

Panic mishandled in libpulse-binding

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xvcc-h99r-vm8p

больше 4 лет назад

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.

EPSS: Низкий
github логотип

GHSA-xvcc-fffc-h2p4

больше 4 лет назад

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xvcc-cxhc-j68h

3 месяца назад

Wondershare PDFelement 5.2.9 contains a privilege escalation vulnerability due to an unquoted service path in the WsAppService Windows service. Local attackers can place a malicious executable in the service path and execute code with LocalSystem privileges upon service restart or system reboot.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xvc9-xwgj-4cq9

больше 4 лет назад

Duplicate Advisory: Integer Overflow in HeaderMap::reserve() can cause Denial of Service

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xvc9-v5hw-8v8j

почти 2 года назад

An information disclosure issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 18.1 and iPadOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, macOS Ventura 13.7.1, macOS Sonoma 14.7.1, watchOS 11.1, visionOS 2.1. A sandboxed app may be able to access sensitive user data in system logs.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xvc8-c6gw-4q63

10 дней назад

An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the setup routine that regenerates credentials will expose that component's administrative interface to anyone aware of the default value.

EPSS: Низкий
github логотип

GHSA-xvc7-7qxh-qw3m

8 месяцев назад

A stack overflow in the mk_http_index_lookup function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xvc5-jg6r-264j

около 2 лет назад

Azure Network Watcher VM Agent Elevation of Privilege Vulnerability

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xvc4-xc7h-xwp4

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the Rules Link module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer rules links" permission to inject arbitrary web script or HTML via unspecified vectors, which are not properly handled in the (1) question and (2) description strings in a confirmation form for a triggering Rules link.

EPSS: Низкий
github логотип

GHSA-xvc4-r5fw-47j4

больше 4 лет назад

The connection_edge_process_relay_cell function in or/relay.c in Tor before 0.2.3.25 maintains circuits even if an unexpected SENDME cell arrives, which might allow remote attackers to cause a denial of service (memory consumption or excessive cell reception rate) or bypass intended flow-control restrictions via a RELAY_COMMAND_SENDME command.

EPSS: Низкий
github логотип

GHSA-xvc4-h3h9-rjwx

около 2 лет назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Noor-E-Alam Amazing Hover Effects allows Stored XSS.This issue affects Amazing Hover Effects: from n/a through 2.4.9.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xvch-q88g-j649

The Cut the Rope: Time Travel (aka com.zeptolab.timetravel.free.google) application 1.3.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xvch-pp92-23j8

Windows Installer Elevation of Privilege Vulnerability

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-xvch-fv6q-gx5m

Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.7.32 and prior and 8.0.22 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Client. CVSS 3.1 Base Score 5.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 5.9
3%
Низкий
больше 4 лет назад
github логотип
GHSA-xvch-5gv4-984h

Prototype Pollution in minimist

CVSS3: 9.8
5%
Низкий
больше 4 лет назад
github логотип
GHSA-xvcg-x6pj-6267

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/manage-tickets.php by adding a question mark (?) followed by the payload.

CVSS3: 4.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xvcg-hv6h-729g

PackLinuxElf64::unpack in p_lx_elf.cpp in UPX 3.95 allows remote attackers to cause a denial of service (double free), limit the ability of a malware scanner to operate on the entire original data, or possibly have unspecified other impact via a crafted file.

CVSS3: 7.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xvcg-ff9f-p7x7

SQL injection vulnerability in home.html in Xpoze Pro 4.10 allows remote attackers to execute arbitrary SQL commands via the menu parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xvcg-crx7-qcjv

Weaver Ecology v9* was discovered to contain a SQL injection vulnerability.

CVSS3: 9.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-xvcg-2q82-r87j

Panic mishandled in libpulse-binding

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xvcc-h99r-vm8p

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xvcc-fffc-h2p4

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVSS3: 8.8
6%
Низкий
больше 4 лет назад
github логотип
GHSA-xvcc-cxhc-j68h

Wondershare PDFelement 5.2.9 contains a privilege escalation vulnerability due to an unquoted service path in the WsAppService Windows service. Local attackers can place a malicious executable in the service path and execute code with LocalSystem privileges upon service restart or system reboot.

CVSS3: 7.8
0%
Низкий
3 месяца назад
github логотип
GHSA-xvc9-xwgj-4cq9

Duplicate Advisory: Integer Overflow in HeaderMap::reserve() can cause Denial of Service

CVSS3: 7.5
больше 4 лет назад
github логотип
GHSA-xvc9-v5hw-8v8j

An information disclosure issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 18.1 and iPadOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, macOS Ventura 13.7.1, macOS Sonoma 14.7.1, watchOS 11.1, visionOS 2.1. A sandboxed app may be able to access sensitive user data in system logs.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-xvc8-c6gw-4q63

An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the setup routine that regenerates credentials will expose that component's administrative interface to anyone aware of the default value.

0%
Низкий
10 дней назад
github логотип
GHSA-xvc7-7qxh-qw3m

A stack overflow in the mk_http_index_lookup function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.

CVSS3: 7.5
1%
Низкий
8 месяцев назад
github логотип
GHSA-xvc5-jg6r-264j

Azure Network Watcher VM Agent Elevation of Privilege Vulnerability

CVSS3: 7.1
1%
Низкий
около 2 лет назад
github логотип
GHSA-xvc4-xc7h-xwp4

Cross-site scripting (XSS) vulnerability in the Rules Link module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer rules links" permission to inject arbitrary web script or HTML via unspecified vectors, which are not properly handled in the (1) question and (2) description strings in a confirmation form for a triggering Rules link.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xvc4-r5fw-47j4

The connection_edge_process_relay_cell function in or/relay.c in Tor before 0.2.3.25 maintains circuits even if an unexpected SENDME cell arrives, which might allow remote attackers to cause a denial of service (memory consumption or excessive cell reception rate) or bypass intended flow-control restrictions via a RELAY_COMMAND_SENDME command.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xvc4-h3h9-rjwx

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Noor-E-Alam Amazing Hover Effects allows Stored XSS.This issue affects Amazing Hover Effects: from n/a through 2.4.9.

CVSS3: 6.5
0%
Низкий
около 2 лет назад

Уязвимостей на страницу