Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 453

Количество 375 453

github логотип

GHSA-xrxh-g8jf-mf2m

больше 4 лет назад

Suricata version 4.0.4 incorrectly handles the parsing of the SSH banner. A malformed SSH banner can cause the parsing code to read beyond the allocated data because SSHParseBanner in app-layer-ssh.c lacks a length check.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xrxh-9m4x-58jr

больше 4 лет назад

In parsePrimaryFieldFirstUidAnnotation of LogEvent.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174485572

EPSS: Низкий
github логотип

GHSA-xrxg-rjqm-5pr4

около 1 месяца назад

In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus/core) honor vrm_version in pmbus_data2reg_vid() pmbus_data2reg_vid() hardcoded the VR11 encoding regardless of the vrm_version configured by the driver, while pmbus_reg2data_vid() already switched on it. Any driver that selects a non-VR11 VID mode and exposes a regulator (or hwmon vout setter) sent dangerously wrong codes to PMBUS_VOUT_COMMAND -- e.g. an nvidia195mv part asked for 200 mV got the VR11 clamp to 500 mV encoded as 0xB2, which the chip interprets as 1080 mV. Mirror pmbus_reg2data_vid() so writes round-trip with reads.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xrxg-jchm-2wr7

больше 4 лет назад

imlib2 before 1.4.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted PNM file.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xrxf-jgv3-qmrm

5 месяцев назад

OpenAI Codex CLI enables code execution through malicious MCP (Model Context Protocol) configuration files

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xrxf-9763-8vpj

больше 4 лет назад

There is an escalation of privilege vulnerability in the Intel Solid State Drive Toolbox versions before 3.4.5 which allow a local administrative attacker to load and execute arbitrary code.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-xrxc-cv69-f3fp

почти 3 года назад

Arbitrary file upload to web root in the IDAttend’s IDWeb application 3.1.013 allows authenticated attackers to upload dangerous files to web root such as ASP or ASPX, gaining command execution on the affected server.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xrxc-57v3-82rr

больше 4 лет назад

Cisco IOS 15.2(04)M and 15.4(03)M lets physical-interface ACLs supersede virtual PPP interface ACLs, which allows remote authenticated users to bypass intended network-traffic restrictions in opportunistic circumstances by using PPP, aka Bug ID CSCur61303.

EPSS: Низкий
github логотип

GHSA-xrx9-j5xj-gqmh

больше 1 года назад

A vulnerability classified as critical has been found in code-projects Payroll Management System 1.0. This affects an unknown part of the file /add_overtime.php. The manipulation of the argument rate leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xrx9-gj26-5wx9

почти 4 года назад

v8n vulnerable to Inefficient Regular Expression Complexity

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xrx8-f378-fwph

около 2 лет назад

Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xrx7-h3p9-h3r6

почти 2 года назад

Missing Authorization vulnerability in СleanTalk - Anti-Spam Protection Spam protection, AntiSpam, FireWall by CleanTalk allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spam protection, AntiSpam, FireWall by CleanTalk: from n/a through 6.10.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xrx7-7p6r-q95g

12 месяцев назад

The LatePoint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1.94. This is due to missing nonce validation on the change_password() function of its customer_cabinet__change_password AJAX route. The plugin hooks this endpoint via wp_ajax and wp_ajax_nopriv but does not verify a nonce or user capability before resetting the user’s password. This makes it possible for unauthenticated attackers who trick a logged-in customer (or, with “WP users as customers” enabled, an administrator) into visiting a malicious link to take over their account.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xrx6-ghw2-jgjm

больше 4 лет назад

Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant. An authenticated attacker with privileges to write to the Kibana index could insert data that would cause Kibana to execute arbitrary code. This could possibly lead to an attacker executing code with the permissions of the Kibana process on the host system.

EPSS: Средний
github логотип

GHSA-xrx6-fmxq-rjj2

больше 5 лет назад

Timing attacks in python-rsa

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xrx5-vc96-3g46

больше 4 лет назад

Firefox before 1.0 allows the user to store a (1) javascript: or (2) data: URLs as a Livefeed bookmark, then executes it in the security context of the currently loaded page when the user later accesses the bookmark, which could allow remote attackers to execute arbitrary code.

EPSS: Низкий
github логотип

GHSA-xrx5-jvp4-rqmj

19 дней назад

CAT uses Java String.hashCode as the sole integrity check for session cookies without server-side keying, allowing attackers to forge valid checksums offline. Attackers can set the x-forwarded-for header to bypass IP binding validation and create admin sessions with full configuration access.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xrx4-x2w9-xf6v

почти 3 года назад

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in MD Jakir Hosen Tiger Forms – Drag and Drop Form Builder plugin <= 2.0.0 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xrx4-vq84-23w6

больше 4 лет назад

Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code. This issue affects: Checkbox Survey versions prior to 7.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xrx4-hm38-w6hm

больше 4 лет назад

Etomite Content Management System 0.6, and possibly earlier versions, when downloaded from the web site in January 2006 after January 10, contains a back door in manager/includes/todo.inc.php, which allows remote attackers to execute arbitrary commands via the "cij" parameter.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xrxh-g8jf-mf2m

Suricata version 4.0.4 incorrectly handles the parsing of the SSH banner. A malformed SSH banner can cause the parsing code to read beyond the allocated data because SSHParseBanner in app-layer-ssh.c lacks a length check.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xrxh-9m4x-58jr

In parsePrimaryFieldFirstUidAnnotation of LogEvent.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174485572

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xrxg-rjqm-5pr4

In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus/core) honor vrm_version in pmbus_data2reg_vid() pmbus_data2reg_vid() hardcoded the VR11 encoding regardless of the vrm_version configured by the driver, while pmbus_reg2data_vid() already switched on it. Any driver that selects a non-VR11 VID mode and exposes a regulator (or hwmon vout setter) sent dangerously wrong codes to PMBUS_VOUT_COMMAND -- e.g. an nvidia195mv part asked for 200 mV got the VR11 clamp to 500 mV encoded as 0xB2, which the chip interprets as 1080 mV. Mirror pmbus_reg2data_vid() so writes round-trip with reads.

CVSS3: 7.1
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xrxg-jchm-2wr7

imlib2 before 1.4.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted PNM file.

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-xrxf-jgv3-qmrm

OpenAI Codex CLI enables code execution through malicious MCP (Model Context Protocol) configuration files

CVSS3: 9.8
7%
Низкий
5 месяцев назад
github логотип
GHSA-xrxf-9763-8vpj

There is an escalation of privilege vulnerability in the Intel Solid State Drive Toolbox versions before 3.4.5 which allow a local administrative attacker to load and execute arbitrary code.

CVSS3: 6.7
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xrxc-cv69-f3fp

Arbitrary file upload to web root in the IDAttend’s IDWeb application 3.1.013 allows authenticated attackers to upload dangerous files to web root such as ASP or ASPX, gaining command execution on the affected server.

CVSS3: 8.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-xrxc-57v3-82rr

Cisco IOS 15.2(04)M and 15.4(03)M lets physical-interface ACLs supersede virtual PPP interface ACLs, which allows remote authenticated users to bypass intended network-traffic restrictions in opportunistic circumstances by using PPP, aka Bug ID CSCur61303.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xrx9-j5xj-gqmh

A vulnerability classified as critical has been found in code-projects Payroll Management System 1.0. This affects an unknown part of the file /add_overtime.php. The manipulation of the argument rate leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-xrx9-gj26-5wx9

v8n vulnerable to Inefficient Regular Expression Complexity

CVSS3: 7.5
2%
Низкий
почти 4 года назад
github логотип
GHSA-xrx8-f378-fwph

Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 8.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-xrx7-h3p9-h3r6

Missing Authorization vulnerability in СleanTalk - Anti-Spam Protection Spam protection, AntiSpam, FireWall by CleanTalk allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spam protection, AntiSpam, FireWall by CleanTalk: from n/a through 6.10.

CVSS3: 8.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-xrx7-7p6r-q95g

The LatePoint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1.94. This is due to missing nonce validation on the change_password() function of its customer_cabinet__change_password AJAX route. The plugin hooks this endpoint via wp_ajax and wp_ajax_nopriv but does not verify a nonce or user capability before resetting the user’s password. This makes it possible for unauthenticated attackers who trick a logged-in customer (or, with “WP users as customers” enabled, an administrator) into visiting a malicious link to take over their account.

CVSS3: 8.8
0%
Низкий
12 месяцев назад
github логотип
GHSA-xrx6-ghw2-jgjm

Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant. An authenticated attacker with privileges to write to the Kibana index could insert data that would cause Kibana to execute arbitrary code. This could possibly lead to an attacker executing code with the permissions of the Kibana process on the host system.

18%
Средний
больше 4 лет назад
github логотип
GHSA-xrx6-fmxq-rjj2

Timing attacks in python-rsa

CVSS3: 5.9
2%
Низкий
больше 5 лет назад
github логотип
GHSA-xrx5-vc96-3g46

Firefox before 1.0 allows the user to store a (1) javascript: or (2) data: URLs as a Livefeed bookmark, then executes it in the security context of the currently loaded page when the user later accesses the bookmark, which could allow remote attackers to execute arbitrary code.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xrx5-jvp4-rqmj

CAT uses Java String.hashCode as the sole integrity check for session cookies without server-side keying, allowing attackers to forge valid checksums offline. Attackers can set the x-forwarded-for header to bypass IP binding validation and create admin sessions with full configuration access.

CVSS3: 9.8
0%
Низкий
19 дней назад
github логотип
GHSA-xrx4-x2w9-xf6v

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in MD Jakir Hosen Tiger Forms – Drag and Drop Form Builder plugin <= 2.0.0 versions.

CVSS3: 7.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-xrx4-vq84-23w6

Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code. This issue affects: Checkbox Survey versions prior to 7.

CVSS3: 9.8
32%
Средний
больше 4 лет назад
github логотип
GHSA-xrx4-hm38-w6hm

Etomite Content Management System 0.6, and possibly earlier versions, when downloaded from the web site in January 2006 after January 10, contains a back door in manager/includes/todo.inc.php, which allows remote attackers to execute arbitrary commands via the "cij" parameter.

3%
Низкий
больше 4 лет назад

Уязвимостей на страницу