Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-4325-8w9c-7p9p

больше 3 лет назад

NVIDIA GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which an operation is performed which may lead to denial of service or escalation of privileges.

EPSS: Низкий
github логотип

GHSA-4324-m828-225f

почти 4 года назад

Buffer overflow in the HTTP redirection capability in conn.c for Axel before 1.0b may allow remote attackers to execute arbitrary code.

EPSS: Низкий
github логотип

GHSA-4324-64fx-mx9p

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in the Futon UI in Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the browser-based test suite.

EPSS: Низкий
github логотип

GHSA-4324-6326-x24p

больше 3 лет назад

When logging in to a VBASE runtime project via Web-Remote, the product uses XOR with a static initial key to obfuscate login messages. An unauthenticated remote attacker with the ability to capture a login session can obtain the login credentials.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4324-5wfm-45rh

больше 3 лет назад

OTFCC v0.10.4 was discovered to contain a segmentation violation via /release-x64/otfccdump+0x5266a8.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4323-f82v-f6jr

больше 1 года назад

Magento Open Source Cross-Site Request Forgery (CSRF) vulnerability

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4323-cfj5-98mh

больше 3 лет назад

Dolibarr ERP and CRM contain XSS Vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4322-j82q-j25q

почти 2 года назад

D-Link DAP-2622 DDP User Verification Auth Username Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the DDP service. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-20052.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4322-9574-7cv6

больше 2 лет назад

In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an authenticated remote attacker with admin privileges could upload a crafted XML file which causes a denial-of-service.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-42xx-v9rj-x9mp

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the newpassword2 parameter.

EPSS: Низкий
github логотип

GHSA-42xx-38jq-4844

почти 2 года назад

Kofax Power PDF PCX File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PCX files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-20389.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-42xw-p62x-hwcf

больше 3 лет назад

Improper Access Control in Apache Derby

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-42xw-2xvc-qx8m

больше 6 лет назад

Denial of Service in axios

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-42xw-2v8p-rrf7

больше 3 лет назад

An issue was discovered in Open XDMoD through 7.5.0. An authentication bypass (account takeover) exists due to a weak password reset mechanism. A brute-force attack against an MD5 rid value requires only 600 guesses in the plausible situation where the attacker knows that the victim has started a password-reset process (pass_reset.php, password_reset.php, XDUser.php) in the past few minutes.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-42xv-889g-w333

около 1 года назад

In m3326_gps_write and m3326_gps_read of gps.s, there is a possible Out Of Bounds Read due to a missing bounds check. This could lead to a local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-42xr-w96f-53vq

больше 3 лет назад

Information disclosure of .esp source code on the Cohu 3960 allows an attacker to view sensitive information such as application logic with a simple web browser.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-42xr-jggh-w47m

больше 3 лет назад

Cisco Wireless LAN Controller (WLC) devices 7.2 before 7.2.115.2, 7.3, and 7.4 before 7.4.110.0 allow remote attackers to cause a denial of service (device restart) via a crafted 802.11 Ethernet frame, aka Bug ID CSCue87929.

EPSS: Низкий
github логотип

GHSA-42xr-fff6-m3hh

больше 3 лет назад

The nsHtml5TreeBuilder::resetTheInsertionMode function in the HTML5 Tree Builder in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 does not properly maintain the state of the insertion-mode stack for template elements, which allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer over-read) by triggering use of this stack in its empty state.

EPSS: Низкий
github логотип

GHSA-42xr-3hw9-x5g4

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management Reference Data Management (RDM) Hub 10.1 and 11.0 before 11.0.0.0-MDM-IF008 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

EPSS: Низкий
github логотип

GHSA-42xq-j3ww-cxh9

около 4 лет назад

On BIG-IP ASM & Advanced WAF version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x and 12.1.x, an authenticated user with low privileges, such as a guest, can upload data using an undisclosed REST endpoint causing an increase in disk resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4325-8w9c-7p9p

NVIDIA GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which an operation is performed which may lead to denial of service or escalation of privileges.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-4324-m828-225f

Buffer overflow in the HTTP redirection capability in conn.c for Axel before 1.0b may allow remote attackers to execute arbitrary code.

4%
Низкий
почти 4 года назад
github логотип
GHSA-4324-64fx-mx9p

Cross-site scripting (XSS) vulnerability in the Futon UI in Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the browser-based test suite.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-4324-6326-x24p

When logging in to a VBASE runtime project via Web-Remote, the product uses XOR with a static initial key to obfuscate login messages. An unauthenticated remote attacker with the ability to capture a login session can obtain the login credentials.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4324-5wfm-45rh

OTFCC v0.10.4 was discovered to contain a segmentation violation via /release-x64/otfccdump+0x5266a8.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4323-f82v-f6jr

Magento Open Source Cross-Site Request Forgery (CSRF) vulnerability

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-4323-cfj5-98mh

Dolibarr ERP and CRM contain XSS Vulnerability

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4322-j82q-j25q

D-Link DAP-2622 DDP User Verification Auth Username Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the DDP service. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-20052.

CVSS3: 8.8
2%
Низкий
почти 2 года назад
github логотип
GHSA-4322-9574-7cv6

In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an authenticated remote attacker with admin privileges could upload a crafted XML file which causes a denial-of-service.

CVSS3: 4.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-42xx-v9rj-x9mp

Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the newpassword2 parameter.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-42xx-38jq-4844

Kofax Power PDF PCX File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PCX files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-20389.

CVSS3: 7.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-42xw-p62x-hwcf

Improper Access Control in Apache Derby

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-42xw-2xvc-qx8m

Denial of Service in axios

CVSS3: 7.5
14%
Средний
больше 6 лет назад
github логотип
GHSA-42xw-2v8p-rrf7

An issue was discovered in Open XDMoD through 7.5.0. An authentication bypass (account takeover) exists due to a weak password reset mechanism. A brute-force attack against an MD5 rid value requires only 600 guesses in the plausible situation where the attacker knows that the victim has started a password-reset process (pass_reset.php, password_reset.php, XDUser.php) in the past few minutes.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-42xv-889g-w333

In m3326_gps_write and m3326_gps_read of gps.s, there is a possible Out Of Bounds Read due to a missing bounds check. This could lead to a local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-42xr-w96f-53vq

Information disclosure of .esp source code on the Cohu 3960 allows an attacker to view sensitive information such as application logic with a simple web browser.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-42xr-jggh-w47m

Cisco Wireless LAN Controller (WLC) devices 7.2 before 7.2.115.2, 7.3, and 7.4 before 7.4.110.0 allow remote attackers to cause a denial of service (device restart) via a crafted 802.11 Ethernet frame, aka Bug ID CSCue87929.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-42xr-fff6-m3hh

The nsHtml5TreeBuilder::resetTheInsertionMode function in the HTML5 Tree Builder in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 does not properly maintain the state of the insertion-mode stack for template elements, which allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer over-read) by triggering use of this stack in its empty state.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-42xr-3hw9-x5g4

Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management Reference Data Management (RDM) Hub 10.1 and 11.0 before 11.0.0.0-MDM-IF008 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-42xq-j3ww-cxh9

On BIG-IP ASM & Advanced WAF version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x and 12.1.x, an authenticated user with low privileges, such as a guest, can upload data using an undisclosed REST endpoint causing an increase in disk resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

0%
Низкий
около 4 лет назад

Уязвимостей на страницу