Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-xxp5-f86m-3v5v

почти 4 года назад

Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxp5-8cpw-353h

около 4 лет назад

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. Processing a maliciously crafted audio file may lead to arbitrary code execution.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xxp5-838q-65wj

больше 4 лет назад

cda in xmcd 3.0.2 and 2.6 in SuSE Linux allows local users to overwrite arbitrary files via a symlink attack.

EPSS: Низкий
github логотип

GHSA-xxp5-7q7f-j96c

около 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in add_url.php in CloudNine Interactive Links Manager 2006-06-12 allow remote attackers to inject arbitrary web script or HTML via the (1) title, (2) description, or (3) keywords parameters.

EPSS: Низкий
github логотип

GHSA-xxp4-q5hx-j33x

около 4 лет назад

WebKit, as used in Apple iOS before 8.3 and Apple TV before 7.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-04-08-3 and APPLE-SA-2015-04-08-4.

EPSS: Низкий
github логотип

GHSA-xxp4-mf4h-6cwm

около 3 лет назад

Moodle vulnerable to Server Side Request Forgery

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxp4-hw2v-2vcr

около 4 лет назад

In Eclipse Kura versions up to 4.0.0, the Web UI package and component services, the Artemis simple Mqtt component and the emulator position service (not part of the device distribution) could potentially be target of XXE attack due to an improper factory and parser initialisation.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxp3-mm76-hhf2

около 4 лет назад

EgavilanMedia User Registration & Login System 1.0 is affected by SQL injection to the admin panel, which may allow arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-xxp3-fcv5-mx3m

около 4 лет назад

JerryScript 2.2.0 allows attackers to cause a denial of service (assertion failure) because a property key query for a Proxy object returns unintended data.

EPSS: Низкий
github логотип

GHSA-xxp2-xgc8-48h8

4 месяца назад

Missing Authorization vulnerability in Glowlogix WP Frontend Profile wp-front-end-profile allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Frontend Profile: from n/a through <= 1.3.9.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xxp2-cp36-7xm7

около 4 лет назад

Cross-site scripting (XSS) vulnerability in Feng Office allows remote attackers to inject arbitrary web script or HTML via a client Name field.

EPSS: Низкий
github логотип

GHSA-xxp2-9c9g-7wmj

больше 2 лет назад

XWiki Platform: Remote code execution from edit in multilingual wikis via translations

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-xxmw-m6v2-9h47

больше 2 лет назад

A reliance on untrusted inputs in a security decision could be exploited by a privileged user to configure the Gallagher Command Centre Diagnostics Service to use less secure communication protocols. This issue affects: Gallagher Diagnostics Service prior to v1.3.0 (distributed in 9.00.1507(MR1)).

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxmv-v72m-r6w4

больше 4 лет назад

The sysgen service in Aptis Totalbill does not perform authentication, which allows remote attackers to gain root privileges by connecting to the service and specifying the commands to be executed.

EPSS: Низкий
github логотип

GHSA-xxmv-mjx9-wg53

около 4 лет назад

Users can lock their notes with a password in Memono version 3.8. Thus, users needs to know a password to read notes. However, these notes are stored in a database without encryption and an attacker can read the password-protected notes without having the password. Notes are stored in the ZENTITY table in the memono.sqlite database.

EPSS: Низкий
github логотип

GHSA-xxmr-5pw7-p42v

около 4 лет назад

Unspecified vulnerability in IBM WebSphere Business Modeler Basic and Advanced 6.0.2.1 before Interim Fix 11 allows remote authenticated users to bypass intended access restrictions and delete unspecified repository resources via unknown vectors, even when they are not administrators or members of the repository's owning group.

EPSS: Низкий
github логотип

GHSA-xxmr-593v-8f45

больше 3 лет назад

In JetBrains Hub before 2022.3.15573, 2022.2.15572, 2022.1.15583 reflected XSS in dashboards was possible

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xxmr-226v-fr48

10 месяцев назад

Missing Authorization vulnerability in Codexpert, Inc CF7 Submissions allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CF7 Submissions: from n/a through 0.26.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xxmq-q3f3-wvpg

около 4 лет назад

A CWE-426: Untrusted Search Path vulnerability exists in SoMachine HVAC v2.4.1 and earlier versions, which could cause arbitrary code execution on the system running SoMachine HVAC when a malicious DLL library is loaded by the product.

EPSS: Низкий
github логотип

GHSA-xxmq-pq4f-q6mv

около 4 лет назад

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within download.jsp. The issue results from the lack of proper validation of a user-supplied string before using it to download a file. An attacker can leverage this vulnerability to expose sensitive information. Was ZDI-CAN-4750.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xxp5-f86m-3v5v

Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xxp5-8cpw-353h

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. Processing a maliciously crafted audio file may lead to arbitrary code execution.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xxp5-838q-65wj

cda in xmcd 3.0.2 and 2.6 in SuSE Linux allows local users to overwrite arbitrary files via a symlink attack.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xxp5-7q7f-j96c

Multiple cross-site scripting (XSS) vulnerabilities in add_url.php in CloudNine Interactive Links Manager 2006-06-12 allow remote attackers to inject arbitrary web script or HTML via the (1) title, (2) description, or (3) keywords parameters.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xxp4-q5hx-j33x

WebKit, as used in Apple iOS before 8.3 and Apple TV before 7.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-04-08-3 and APPLE-SA-2015-04-08-4.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xxp4-mf4h-6cwm

Moodle vulnerable to Server Side Request Forgery

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-xxp4-hw2v-2vcr

In Eclipse Kura versions up to 4.0.0, the Web UI package and component services, the Artemis simple Mqtt component and the emulator position service (not part of the device distribution) could potentially be target of XXE attack due to an improper factory and parser initialisation.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-xxp3-mm76-hhf2

EgavilanMedia User Registration & Login System 1.0 is affected by SQL injection to the admin panel, which may allow arbitrary code execution.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xxp3-fcv5-mx3m

JerryScript 2.2.0 allows attackers to cause a denial of service (assertion failure) because a property key query for a Proxy object returns unintended data.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xxp2-xgc8-48h8

Missing Authorization vulnerability in Glowlogix WP Frontend Profile wp-front-end-profile allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Frontend Profile: from n/a through <= 1.3.9.

CVSS3: 5.3
0%
Низкий
4 месяца назад
github логотип
GHSA-xxp2-cp36-7xm7

Cross-site scripting (XSS) vulnerability in Feng Office allows remote attackers to inject arbitrary web script or HTML via a client Name field.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xxp2-9c9g-7wmj

XWiki Platform: Remote code execution from edit in multilingual wikis via translations

CVSS3: 9.9
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xxmw-m6v2-9h47

A reliance on untrusted inputs in a security decision could be exploited by a privileged user to configure the Gallagher Command Centre Diagnostics Service to use less secure communication protocols. This issue affects: Gallagher Diagnostics Service prior to v1.3.0 (distributed in 9.00.1507(MR1)).

CVSS3: 5.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xxmv-v72m-r6w4

The sysgen service in Aptis Totalbill does not perform authentication, which allows remote attackers to gain root privileges by connecting to the service and specifying the commands to be executed.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-xxmv-mjx9-wg53

Users can lock their notes with a password in Memono version 3.8. Thus, users needs to know a password to read notes. However, these notes are stored in a database without encryption and an attacker can read the password-protected notes without having the password. Notes are stored in the ZENTITY table in the memono.sqlite database.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xxmr-5pw7-p42v

Unspecified vulnerability in IBM WebSphere Business Modeler Basic and Advanced 6.0.2.1 before Interim Fix 11 allows remote authenticated users to bypass intended access restrictions and delete unspecified repository resources via unknown vectors, even when they are not administrators or members of the repository's owning group.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xxmr-593v-8f45

In JetBrains Hub before 2022.3.15573, 2022.2.15572, 2022.1.15583 reflected XSS in dashboards was possible

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xxmr-226v-fr48

Missing Authorization vulnerability in Codexpert, Inc CF7 Submissions allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CF7 Submissions: from n/a through 0.26.

CVSS3: 4.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-xxmq-q3f3-wvpg

A CWE-426: Untrusted Search Path vulnerability exists in SoMachine HVAC v2.4.1 and earlier versions, which could cause arbitrary code execution on the system running SoMachine HVAC when a malicious DLL library is loaded by the product.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xxmq-pq4f-q6mv

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within download.jsp. The issue results from the lack of proper validation of a user-supplied string before using it to download a file. An attacker can leverage this vulnerability to expose sensitive information. Was ZDI-CAN-4750.

CVSS3: 7.5
3%
Низкий
около 4 лет назад

Уязвимостей на страницу