Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 453

Количество 375 453

github логотип

GHSA-xv5g-jfvh-hgph

больше 2 лет назад

Inappropriate pointer order of map_sub_ and map_free(map_) (amcl_node.cpp) in Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions leads to a use-after-free.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xv5g-h355-j9v9

больше 4 лет назад

Structured reply is a feature of the newstyle NBD protocol allowing the server to send a reply in chunks. A bounds check which was supposed to test for chunk offsets smaller than the beginning of the request did not work because of signed/unsigned confusion. If one of these chunks contains a negative offset then data under control of the server is written to memory before the read buffer supplied by the client. If the read buffer is located on the stack then this allows the stack return address from nbd_pread() to be trivially modified, allowing arbitrary code execution under the control of the server. If the buffer is located on the heap then other memory objects before the buffer can be overwritten, which again would usually lead to arbitrary code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xv5g-cq95-4rcm

почти 3 года назад

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xv5g-36c6-hqwj

около 1 года назад

Deserialization of Untrusted Data vulnerability in jetmonsters JetFormBuilder allows Object Injection. This issue affects JetFormBuilder: from n/a through 3.5.1.2.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xv5f-2997-qhrq

больше 4 лет назад

Craft CMS XSS Vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xv5c-vg59-hj7x

больше 1 года назад

There is a "Use After Free" vulnerability in Qt's QHttp2ProtocolHandler in the QtNetwork module. This only affects HTTP/2 handling, HTTP handling is not affected by this at all. This happens due to a race condition between how QHttp2Stream uploads the body of a POST request and the simultaneous handling of HTTP error responses. This issue only affects Qt 6.9.0 and has been fixed for Qt 6.9.1.

EPSS: Низкий
github логотип

GHSA-xv59-gc3r-rf92

около 4 лет назад

Insufficient Session Expiration in Nakama

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xv59-967r-8726

5 месяцев назад

rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding

EPSS: Низкий
github логотип

GHSA-xv59-3gpf-c92h

больше 4 лет назад

There is a Factory Reset Protection (FRP) bypass vulnerability on several smartphones. The system does not sufficiently verify the permission, an attacker could do a certain operation on certain step of setup wizard. Successful exploit could allow the attacker bypass the FRP protection. Affected products: Mate 20 X, versions earlier than Ever-AL00B 9.0.0.200(C00E200R2P1); Mate 20, versions earlier than Hima-AL00B/Hima-TL00B 9.0.0.200(C00E200R2P1); Honor Magic 2, versions earlier than Tony-AL00B/Tony-TL00B 9.0.0.182(C00E180R2P2).

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-xv58-xpg4-8jv9

больше 3 лет назад

** UNSUPPORTED WHEN ASSIGNED ** Reflected cross-site scripting vulnerability in Wired/Wireless LAN Pan/Tilt Network Camera CS-WMV02G all versions allows a remote unauthenticated attacker to inject arbitrary script to inject an arbitrary script. NOTE: This vulnerability only affects products that are no longer supported by the developer.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xv58-gp43-6m76

больше 4 лет назад

Credentials stored in plain text by Zephyr Enterprise Test Management Plugin

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-xv58-2569-gmpq

больше 4 лет назад

Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

EPSS: Высокий
github логотип

GHSA-xv57-4mr9-wg8v

около 1 года назад

Next.js Content Injection Vulnerability for Image Optimization

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xv56-v69h-6cw4

больше 4 лет назад

AnyDesk before 6.1.0 on Windows, when run in portable mode on a system where the attacker has write access to the application directory, allows this attacker to compromise a local user account via a read-only setting for a Trojan horse gcapi.dll file.

EPSS: Низкий
github логотип

GHSA-xv56-c9px-vg88

почти 3 года назад

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability, which allows attackers to inject JS via the "title" parameter, in the "/admin/admin-menu/add-submit" endpoint, which can lead to unauthorized execution of scripts in a user's web browser.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xv56-7cfh-4v8j

больше 4 лет назад

Group.pm in Metadot Portal Server 6.4.4 and earlier does not properly reset the $IS_OWNER, $IS_ADMIN, and $IS_MANAGER global variables when performing checks for special privileges, which allows users to gain administrator privileges by adding themselves to the SITE_MGR group.

EPSS: Низкий
github логотип

GHSA-xv56-54j2-wf98

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in apps/zxtm/locallog.cgi in Riverbed Stingray (aka SteelApp) Traffic Manager Virtual Appliance 9.6 patchlevel 9620140312 allows remote attackers to inject arbitrary web script or HTML via the logfile parameter.

EPSS: Низкий
github логотип

GHSA-xv56-4f6g-pxh9

больше 4 лет назад

Microsoft Internet Explorer 10 and 11 allows local users to bypass the Protected Mode protection mechanism, and consequently gain privileges, by leveraging the ability to execute sandboxed code, aka "Internet Explorer Elevation of Privilege Vulnerability."

EPSS: Средний
github логотип

GHSA-xv56-3wq5-9997

8 месяцев назад

Renovate vulnerable to arbitrary command injection via kustomize manager and malicious helm repository

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-xv54-r3hg-rvqj

около 2 месяцев назад

The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks.

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xv5g-jfvh-hgph

Inappropriate pointer order of map_sub_ and map_free(map_) (amcl_node.cpp) in Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions leads to a use-after-free.

CVSS3: 8.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xv5g-h355-j9v9

Structured reply is a feature of the newstyle NBD protocol allowing the server to send a reply in chunks. A bounds check which was supposed to test for chunk offsets smaller than the beginning of the request did not work because of signed/unsigned confusion. If one of these chunks contains a negative offset then data under control of the server is written to memory before the read buffer supplied by the client. If the read buffer is located on the stack then this allows the stack return address from nbd_pread() to be trivially modified, allowing arbitrary code execution under the control of the server. If the buffer is located on the heap then other memory objects before the buffer can be overwritten, which again would usually lead to arbitrary code execution.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xv5g-cq95-4rcm

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS).

CVSS3: 7.5
4%
Низкий
почти 3 года назад
github логотип
GHSA-xv5g-36c6-hqwj

Deserialization of Untrusted Data vulnerability in jetmonsters JetFormBuilder allows Object Injection. This issue affects JetFormBuilder: from n/a through 3.5.1.2.

CVSS3: 7.2
0%
Низкий
около 1 года назад
github логотип
GHSA-xv5f-2997-qhrq

Craft CMS XSS Vulnerability

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xv5c-vg59-hj7x

There is a "Use After Free" vulnerability in Qt's QHttp2ProtocolHandler in the QtNetwork module. This only affects HTTP/2 handling, HTTP handling is not affected by this at all. This happens due to a race condition between how QHttp2Stream uploads the body of a POST request and the simultaneous handling of HTTP error responses. This issue only affects Qt 6.9.0 and has been fixed for Qt 6.9.1.

0%
Низкий
больше 1 года назад
github логотип
GHSA-xv59-gc3r-rf92

Insufficient Session Expiration in Nakama

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xv59-967r-8726

rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding

0%
Низкий
5 месяцев назад
github логотип
GHSA-xv59-3gpf-c92h

There is a Factory Reset Protection (FRP) bypass vulnerability on several smartphones. The system does not sufficiently verify the permission, an attacker could do a certain operation on certain step of setup wizard. Successful exploit could allow the attacker bypass the FRP protection. Affected products: Mate 20 X, versions earlier than Ever-AL00B 9.0.0.200(C00E200R2P1); Mate 20, versions earlier than Hima-AL00B/Hima-TL00B 9.0.0.200(C00E200R2P1); Honor Magic 2, versions earlier than Tony-AL00B/Tony-TL00B 9.0.0.182(C00E180R2P2).

CVSS3: 4.6
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xv58-xpg4-8jv9

** UNSUPPORTED WHEN ASSIGNED ** Reflected cross-site scripting vulnerability in Wired/Wireless LAN Pan/Tilt Network Camera CS-WMV02G all versions allows a remote unauthenticated attacker to inject arbitrary script to inject an arbitrary script. NOTE: This vulnerability only affects products that are no longer supported by the developer.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xv58-gp43-6m76

Credentials stored in plain text by Zephyr Enterprise Test Management Plugin

CVSS3: 3.3
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xv58-2569-gmpq

Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

83%
Высокий
больше 4 лет назад
github логотип
GHSA-xv57-4mr9-wg8v

Next.js Content Injection Vulnerability for Image Optimization

CVSS3: 4.3
1%
Низкий
около 1 года назад
github логотип
GHSA-xv56-v69h-6cw4

AnyDesk before 6.1.0 on Windows, when run in portable mode on a system where the attacker has write access to the application directory, allows this attacker to compromise a local user account via a read-only setting for a Trojan horse gcapi.dll file.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xv56-c9px-vg88

Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability, which allows attackers to inject JS via the "title" parameter, in the "/admin/admin-menu/add-submit" endpoint, which can lead to unauthorized execution of scripts in a user's web browser.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-xv56-7cfh-4v8j

Group.pm in Metadot Portal Server 6.4.4 and earlier does not properly reset the $IS_OWNER, $IS_ADMIN, and $IS_MANAGER global variables when performing checks for special privileges, which allows users to gain administrator privileges by adding themselves to the SITE_MGR group.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xv56-54j2-wf98

Cross-site scripting (XSS) vulnerability in apps/zxtm/locallog.cgi in Riverbed Stingray (aka SteelApp) Traffic Manager Virtual Appliance 9.6 patchlevel 9620140312 allows remote attackers to inject arbitrary web script or HTML via the logfile parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xv56-4f6g-pxh9

Microsoft Internet Explorer 10 and 11 allows local users to bypass the Protected Mode protection mechanism, and consequently gain privileges, by leveraging the ability to execute sandboxed code, aka "Internet Explorer Elevation of Privilege Vulnerability."

17%
Средний
больше 4 лет назад
github логотип
GHSA-xv56-3wq5-9997

Renovate vulnerable to arbitrary command injection via kustomize manager and malicious helm repository

CVSS3: 6.7
8 месяцев назад
github логотип
GHSA-xv54-r3hg-rvqj

The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks.

CVSS3: 9.1
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу