Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 354 924

Количество 354 924

github логотип

GHSA-xv49-34rf-rqv4

6 месяцев назад

A flaw was found in libsoup, an HTTP client/server library. This HTTP Request Smuggling vulnerability arises from non-RFC-compliant parsing in the soup_filter_input_stream_read_line() logic, where libsoup accepts malformed chunk headers, such as lone line feed (LF) characters instead of the required carriage return and line feed (CRLF). A remote attacker can exploit this without authentication or user interaction by sending specially crafted chunked requests. This allows libsoup to parse and process multiple HTTP requests from a single network message, potentially leading to information disclosure.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xv49-2wgv-qvc2

около 4 лет назад

Cross-site scripting (XSS) vulnerability in index.php in the hosted_signup module in NetArt Media iBoutique.MALL 1.2 allows remote attackers to inject arbitrary web script or HTML via the tmpl parameter. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-xv48-qfxm-rc53

7 месяцев назад

An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500. A race condition in the issimian device driver results in an out-of-bounds access, leading to a denial of service.

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-xv46-hhwp-vf34

около 4 лет назад

A vulnerability in the internal Kubernetes agent api in GitLab CE/EE version 13.3 and above allows unauthorized access to private projects. Affected versions are: >=13.4, <13.4.5,>=13.3, <13.3.9,>=13.5, <13.5.2.

EPSS: Низкий
github логотип

GHSA-xv46-47mw-9vxc

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: add RCU protection to mld_newpack() mld_newpack() can be called without RTNL or RCU being held. Note that we no longer can use sock_alloc_send_skb() because ipv6.igmp_sk uses GFP_KERNEL allocations which can sleep. Instead use alloc_skb() and charge the net->ipv6.igmp_sk socket under RCU protection.

CVSS3: 5.5
EPSS: Средний
github логотип

GHSA-xv45-rrwp-wgf4

около 4 лет назад

The official rabbitmq docker images before 3.7.13-beta.1-management-alpine (Alpine specific) contain a blank password for a root user. System using the rabbitmq docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.

EPSS: Низкий
github логотип

GHSA-xv45-qm36-h77q

около 3 лет назад

ToolboxST prior to version 7.10 is affected by a deserialization vulnerability. An attacker with local access to an HMI or who has conducted a social engineering attack on an authorized operator could execute code in a Toolbox user's context through the deserialization of an untrusted configuration file. Two CVSS scores have been provided to capture the differences between the two aforementioned attack vectors.  Customers are advised to update to ToolboxST 7.10 which can be found in ControlST 7.10. If unable to update at this time customers should ensure they are following the guidance laid out in GE Gas Power's Secure Deployment Guide (GEH-6839). Customers should ensure they are not running ToolboxST as an Administrative user. 

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xv45-9768-g2mm

около 4 лет назад

The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xv44-pg58-qmq3

12 месяцев назад

A vulnerability was identified in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown processing of the file /admin/page-login.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xv44-cpqx-3w77

больше 4 лет назад

AlstraSoft Forum Pay Per Post Exchange 2.0 stores passwords in cleartext, which makes it easier for attackers to access user accounts.

EPSS: Низкий
github логотип

GHSA-xv44-4p65-mmrx

почти 3 года назад

Maid Hiring Management System v1.0 was discovered to contain a SQL injection vulnerability in the Search Maid page.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xv3x-x36v-w2jp

больше 4 лет назад

Directory traversal vulnerability in EMotion MediaPartner Web Server 5.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

EPSS: Низкий
github логотип

GHSA-xv3x-4h27-q4j5

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in FluentSMTP & WPManageNinja Team FluentSMTP allows Cross Site Request Forgery. This issue affects FluentSMTP: from n/a through 2.2.80.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xv3w-jq9v-7wvx

больше 4 лет назад

Oracle Internet Directory Server 2.1.1.x and 3.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via invalid encodings of BER OBJECT-IDENTIFIER values, as demonstrated by the PROTOS LDAPv3 test suite.

EPSS: Низкий
github логотип

GHSA-xv3v-mrcp-v5qc

больше 3 лет назад

Microsoft ODBC Driver Remote Code Execution Vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xv3r-wcc2-gmq8

больше 4 лет назад

Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 permit cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote attackers to obtain sensitive information via a crafted document.

EPSS: Низкий
github логотип

GHSA-xv3r-vr59-95rg

4 месяца назад

CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE

EPSS: Низкий
github логотип

GHSA-xv3q-rp6x-hwhw

около 4 лет назад

An issue was discovered in channels/chan_sip.c in Sangoma Asterisk 13.x, 16.x, and 17.x, and Certified Asterisk 13.21, because of an incomplete fix for CVE-2019-18351. A SIP request can be sent to Asterisk that can change a SIP peer's IP address. A REGISTER does not need to occur, and calls can be hijacked as a result. The only thing that needs to be known is the peer's name; authentication details such as passwords do not need to be known. This vulnerability is only exploitable when the nat option is set to the default, or auto_force_rport.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xv3q-r363-84pg

около 4 лет назад

A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions). The control logic (CL) the LOGO! 8 executes could be manipulated in a way that could cause the device executing the CL to improperly handle the manipulation and crash. After successful execution of the attack, the device needs to be manually reset.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xv3q-jrmm-4fxv

больше 3 лет назад

Authentication Bypass in @strapi/plugin-users-permissions

CVSS3: 8.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xv49-34rf-rqv4

A flaw was found in libsoup, an HTTP client/server library. This HTTP Request Smuggling vulnerability arises from non-RFC-compliant parsing in the soup_filter_input_stream_read_line() logic, where libsoup accepts malformed chunk headers, such as lone line feed (LF) characters instead of the required carriage return and line feed (CRLF). A remote attacker can exploit this without authentication or user interaction by sending specially crafted chunked requests. This allows libsoup to parse and process multiple HTTP requests from a single network message, potentially leading to information disclosure.

CVSS3: 5.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-xv49-2wgv-qvc2

Cross-site scripting (XSS) vulnerability in index.php in the hosted_signup module in NetArt Media iBoutique.MALL 1.2 allows remote attackers to inject arbitrary web script or HTML via the tmpl parameter. NOTE: some of these details are obtained from third party information.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xv48-qfxm-rc53

An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500. A race condition in the issimian device driver results in an out-of-bounds access, leading to a denial of service.

CVSS3: 5.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-xv46-hhwp-vf34

A vulnerability in the internal Kubernetes agent api in GitLab CE/EE version 13.3 and above allows unauthorized access to private projects. Affected versions are: >=13.4, <13.4.5,>=13.3, <13.3.9,>=13.5, <13.5.2.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xv46-47mw-9vxc

In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: add RCU protection to mld_newpack() mld_newpack() can be called without RTNL or RCU being held. Note that we no longer can use sock_alloc_send_skb() because ipv6.igmp_sk uses GFP_KERNEL allocations which can sleep. Instead use alloc_skb() and charge the net->ipv6.igmp_sk socket under RCU protection.

CVSS3: 5.5
14%
Средний
больше 1 года назад
github логотип
GHSA-xv45-rrwp-wgf4

The official rabbitmq docker images before 3.7.13-beta.1-management-alpine (Alpine specific) contain a blank password for a root user. System using the rabbitmq docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xv45-qm36-h77q

ToolboxST prior to version 7.10 is affected by a deserialization vulnerability. An attacker with local access to an HMI or who has conducted a social engineering attack on an authorized operator could execute code in a Toolbox user's context through the deserialization of an untrusted configuration file. Two CVSS scores have been provided to capture the differences between the two aforementioned attack vectors.  Customers are advised to update to ToolboxST 7.10 which can be found in ControlST 7.10. If unable to update at this time customers should ensure they are following the guidance laid out in GE Gas Power's Secure Deployment Guide (GEH-6839). Customers should ensure they are not running ToolboxST as an Administrative user. 

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-xv45-9768-g2mm

The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.

CVSS3: 5.9
4%
Низкий
около 4 лет назад
github логотип
GHSA-xv44-pg58-qmq3

A vulnerability was identified in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown processing of the file /admin/page-login.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
12 месяцев назад
github логотип
GHSA-xv44-cpqx-3w77

AlstraSoft Forum Pay Per Post Exchange 2.0 stores passwords in cleartext, which makes it easier for attackers to access user accounts.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xv44-4p65-mmrx

Maid Hiring Management System v1.0 was discovered to contain a SQL injection vulnerability in the Search Maid page.

CVSS3: 4.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-xv3x-x36v-w2jp

Directory traversal vulnerability in EMotion MediaPartner Web Server 5.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xv3x-4h27-q4j5

Cross-Site Request Forgery (CSRF) vulnerability in FluentSMTP & WPManageNinja Team FluentSMTP allows Cross Site Request Forgery. This issue affects FluentSMTP: from n/a through 2.2.80.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-xv3w-jq9v-7wvx

Oracle Internet Directory Server 2.1.1.x and 3.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via invalid encodings of BER OBJECT-IDENTIFIER values, as demonstrated by the PROTOS LDAPv3 test suite.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-xv3v-mrcp-v5qc

Microsoft ODBC Driver Remote Code Execution Vulnerability

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xv3r-wcc2-gmq8

Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 permit cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote attackers to obtain sensitive information via a crafted document.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xv3r-vr59-95rg

CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE

0%
Низкий
4 месяца назад
github логотип
GHSA-xv3q-rp6x-hwhw

An issue was discovered in channels/chan_sip.c in Sangoma Asterisk 13.x, 16.x, and 17.x, and Certified Asterisk 13.21, because of an incomplete fix for CVE-2019-18351. A SIP request can be sent to Asterisk that can change a SIP peer's IP address. A REGISTER does not need to occur, and calls can be hijacked as a result. The only thing that needs to be known is the peer's name; authentication details such as passwords do not need to be known. This vulnerability is only exploitable when the nat option is set to the default, or auto_force_rport.

CVSS3: 6.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-xv3q-r363-84pg

A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions). The control logic (CL) the LOGO! 8 executes could be manipulated in a way that could cause the device executing the CL to improperly handle the manipulation and crash. After successful execution of the attack, the device needs to be manually reset.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-xv3q-jrmm-4fxv

Authentication Bypass in @strapi/plugin-users-permissions

CVSS3: 8.2
больше 3 лет назад

Уязвимостей на страницу