Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 354 924

Количество 354 924

github логотип

GHSA-xrvf-m29v-829x

около 3 лет назад

An Authorization Bypass vulnerability was found in MB Connect Lines mbCONNECT24, mymbCONNECT24 and Helmholz' myREX24 and myREX24.virtual version <= 2.13.3. An authenticated remote user with low privileges can change the password of any user in the same account. This allows to take over the admin user and therefore fully compromise the account.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xrvc-mqhc-wxg7

около 4 лет назад

The FTP server on Siemens SCALANCE X-300 switches with firmware before 4.0 and SCALANCE X 408 switches with firmware before 4.0 allows remote authenticated users to cause a denial of service (reboot) via crafted FTP packets.

EPSS: Низкий
github логотип

GHSA-xrvc-m3hh-hp9h

больше 4 лет назад

Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to execute arbitrary code.

EPSS: Средний
github логотип

GHSA-xrvc-5f74-4x4x

больше 4 лет назад

The CLUEVO LMS, E-Learning Platform WordPress plugin before 1.8.1 does not sanitise and escape Course's module, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

EPSS: Низкий
github логотип

GHSA-xrv9-h656-4rpq

около 2 лет назад

A vulnerability regarding buffer copy without checking the size of input ('Classic Buffer Overflow') has been found in the login component. This allows remote attackers to conduct denial-of-service attacks via unspecified vectors. This attack only affects the login service which will automatically restart. The following models with Synology Camera Firmware versions before 1.1.1-0383 may be affected: BC500 and TC500.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xrv8-2pf5-f3q7

8 месяцев назад

nitro-tpm-pcr-compute may allow kernel command line modification by an account operator

CVSS3: 6
EPSS: Низкий
github логотип

GHSA-xrv7-w6wq-5f4g

около 4 лет назад

The "http-client" egg always used a HTTP_PROXY environment variable to determine whether HTTP traffic should be routed via a proxy, even when running as a CGI process. Under several web servers this would mean a user-supplied "Proxy" header could allow an attacker to direct all HTTP requests through a proxy (also known as a "httpoxy" attack). This affects all versions of http-client before 0.10.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xrv7-5mq8-pxvp

около 3 лет назад

In Parse of simdata.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-263783565References: N/A

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-xrv6-3vg3-5pm7

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leetoo Toocheke Companion allows Stored XSS. This issue affects Toocheke Companion: from n/a through 1.166.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xrv5-vhqh-hwxh

больше 1 года назад

Cross Site Scripting vulnerability in PecanProject pecan v.1.7.2 allows a remote attacker to execute arbitrary code via the crafted payload to the hostname, sitegroupid, lat, lon and sitename parameters.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xrv5-2wwg-jp3r

около 1 года назад

A multi-vendor cache poisoning vulnerability named 'Rebirthday Attack' has been discovered in caching resolvers that support EDNS Client Subnet (ECS). Unbound is also vulnerable when compiled with ECS support, i.e., '--enable-subnet', AND configured to send ECS information along with queries to upstream name servers, i.e., at least one of the 'send-client-subnet', 'client-subnet-zone' or 'client-subnet-always-forward' options is used. Resolvers supporting ECS need to segregate outgoing queries to accommodate for different outgoing ECS information. This re-opens up resolvers to a birthday paradox attack (Rebirthday Attack) that tries to match the DNS transaction ID in order to cache non-ECS poisonous replies.

EPSS: Низкий
github логотип

GHSA-xrv4-xm8w-pm47

почти 3 года назад

An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to FoFiType1C::cvtGlyph function.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xrv4-rvr5-75gv

2 месяца назад

Use after free in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: Critical)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xrv3-jmcp-374j

около 2 лет назад

zerovec incorrectly uses `#[repr(packed)]`

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-xrv2-p88f-5qw2

около 4 лет назад

A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.5. A local user may be able to read kernel memory.

EPSS: Низкий
github логотип

GHSA-xrrx-xr48-h4jv

около 2 лет назад

A vulnerability, which was classified as critical, has been found in itsourcecode Online Laundry Management System 1.0. Affected by this issue is some unknown functionality of the file admin_class.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-268724.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xrrx-hrm6-mxr7

около 4 лет назад

An issue was discovered in GoAhead 4.x and 5.x before 5.1.5. In the file upload filter, user form variables can be passed to CGI scripts without being prefixed with the CGI prefix. This permits tunneling untrusted environment variables into vulnerable CGI scripts.

EPSS: Средний
github логотип

GHSA-xrrw-wm7v-5p7r

больше 4 лет назад

Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 stores an exception for a hostname when the user accepts an untrusted Exchange server certificate, which causes it to be accepted without prompting in future usage and allows remote Exchange servers to obtain sensitive information such as credentials.

EPSS: Низкий
github логотип

GHSA-xrrw-gmgc-3q22

больше 4 лет назад

dnstools.php for DNSTools 2.0 beta 4 and earlier allows remote attackers to bypass authentication and gain privileges by setting the user_logged_in or user_dnstools_administrator parameters.

EPSS: Средний
github логотип

GHSA-xrrw-9j78-hpf3

больше 2 лет назад

Jenkins HTML Publisher Plugin Stored XSS vulnerability

CVSS3: 8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xrvf-m29v-829x

An Authorization Bypass vulnerability was found in MB Connect Lines mbCONNECT24, mymbCONNECT24 and Helmholz' myREX24 and myREX24.virtual version <= 2.13.3. An authenticated remote user with low privileges can change the password of any user in the same account. This allows to take over the admin user and therefore fully compromise the account.

CVSS3: 8.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-xrvc-mqhc-wxg7

The FTP server on Siemens SCALANCE X-300 switches with firmware before 4.0 and SCALANCE X 408 switches with firmware before 4.0 allows remote authenticated users to cause a denial of service (reboot) via crafted FTP packets.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xrvc-m3hh-hp9h

Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to execute arbitrary code.

13%
Средний
больше 4 лет назад
github логотип
GHSA-xrvc-5f74-4x4x

The CLUEVO LMS, E-Learning Platform WordPress plugin before 1.8.1 does not sanitise and escape Course's module, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xrv9-h656-4rpq

A vulnerability regarding buffer copy without checking the size of input ('Classic Buffer Overflow') has been found in the login component. This allows remote attackers to conduct denial-of-service attacks via unspecified vectors. This attack only affects the login service which will automatically restart. The following models with Synology Camera Firmware versions before 1.1.1-0383 may be affected: BC500 and TC500.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-xrv8-2pf5-f3q7

nitro-tpm-pcr-compute may allow kernel command line modification by an account operator

CVSS3: 6
8 месяцев назад
github логотип
GHSA-xrv7-w6wq-5f4g

The "http-client" egg always used a HTTP_PROXY environment variable to determine whether HTTP traffic should be routed via a proxy, even when running as a CGI process. Under several web servers this would mean a user-supplied "Proxy" header could allow an attacker to direct all HTTP requests through a proxy (also known as a "httpoxy" attack). This affects all versions of http-client before 0.10.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xrv7-5mq8-pxvp

In Parse of simdata.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-263783565References: N/A

CVSS3: 6.7
0%
Низкий
около 3 лет назад
github логотип
GHSA-xrv6-3vg3-5pm7

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leetoo Toocheke Companion allows Stored XSS. This issue affects Toocheke Companion: from n/a through 1.166.

CVSS3: 5.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-xrv5-vhqh-hwxh

Cross Site Scripting vulnerability in PecanProject pecan v.1.7.2 allows a remote attacker to execute arbitrary code via the crafted payload to the hostname, sitegroupid, lat, lon and sitename parameters.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-xrv5-2wwg-jp3r

A multi-vendor cache poisoning vulnerability named 'Rebirthday Attack' has been discovered in caching resolvers that support EDNS Client Subnet (ECS). Unbound is also vulnerable when compiled with ECS support, i.e., '--enable-subnet', AND configured to send ECS information along with queries to upstream name servers, i.e., at least one of the 'send-client-subnet', 'client-subnet-zone' or 'client-subnet-always-forward' options is used. Resolvers supporting ECS need to segregate outgoing queries to accommodate for different outgoing ECS information. This re-opens up resolvers to a birthday paradox attack (Rebirthday Attack) that tries to match the DNS transaction ID in order to cache non-ECS poisonous replies.

0%
Низкий
около 1 года назад
github логотип
GHSA-xrv4-xm8w-pm47

An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to FoFiType1C::cvtGlyph function.

CVSS3: 6.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-xrv4-rvr5-75gv

Use after free in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: Critical)

CVSS3: 8.8
0%
Низкий
2 месяца назад
github логотип
GHSA-xrv3-jmcp-374j

zerovec incorrectly uses `#[repr(packed)]`

CVSS3: 6.2
около 2 лет назад
github логотип
GHSA-xrv2-p88f-5qw2

A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.5. A local user may be able to read kernel memory.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xrrx-xr48-h4jv

A vulnerability, which was classified as critical, has been found in itsourcecode Online Laundry Management System 1.0. Affected by this issue is some unknown functionality of the file admin_class.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-268724.

CVSS3: 6.3
1%
Низкий
около 2 лет назад
github логотип
GHSA-xrrx-hrm6-mxr7

An issue was discovered in GoAhead 4.x and 5.x before 5.1.5. In the file upload filter, user form variables can be passed to CGI scripts without being prefixed with the CGI prefix. This permits tunneling untrusted environment variables into vulnerable CGI scripts.

59%
Средний
около 4 лет назад
github логотип
GHSA-xrrw-wm7v-5p7r

Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 stores an exception for a hostname when the user accepts an untrusted Exchange server certificate, which causes it to be accepted without prompting in future usage and allows remote Exchange servers to obtain sensitive information such as credentials.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xrrw-gmgc-3q22

dnstools.php for DNSTools 2.0 beta 4 and earlier allows remote attackers to bypass authentication and gain privileges by setting the user_logged_in or user_dnstools_administrator parameters.

11%
Средний
больше 4 лет назад
github логотип
GHSA-xrrw-9j78-hpf3

Jenkins HTML Publisher Plugin Stored XSS vulnerability

CVSS3: 8
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу