Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 289 803

Количество 289 803

github логотип

GHSA-2c62-8p8p-hh5w

больше 3 лет назад

Libgcrypt before 1.6.5 does not properly perform elliptic-point curve multiplication during decryption, which makes it easier for physically proximate attackers to extract ECDH keys by measuring electromagnetic emanations.

CVSS3: 2
EPSS: Низкий
github логотип

GHSA-2c5w-43q3-9h56

больше 1 года назад

D-Link D-View coreservice_action_script Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link D-View. Authentication is not required to exploit this vulnerability. The specific flaw exists within the coreservice_action_script action. The issue results from the exposure of a dangerous function. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-19573.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2c5v-4pcw-67jx

больше 3 лет назад

Format string vulnerability in Lithium II mod 1.24 for Quake 2 allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via format string specifiers in the nickname.

EPSS: Низкий
github логотип

GHSA-2c5r-8h52-phwr

около 2 лет назад

Zoom for Windows clients prior to 5.13.5 contain an improper verification of cryptographic signature vulnerability. A malicious user may potentially downgrade Zoom Client components to previous versions.

CVSS3: 2.8
EPSS: Низкий
github логотип

GHSA-2c5p-v6r6-q8xj

9 месяцев назад

In wlan driver, there is a possible out of bound read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998291; Issue ID: MSV-1604.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2c5p-55qj-5p58

больше 3 лет назад

A CWE-614 Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain an unauthorized access over a hijacked session to the charger station web server even after the legitimate user account holder has changed his password. Affected Products: EVlink City EVC1S22P4 / EVC1S7P4 (All versions prior to R8 V3.4.0.2 ), EVlink Parking EVW2 / EVF2 / EVP2PE (All versions prior to R8 V3.4.0.2), and EVlink Smart Wallbox EVB1A (All versions prior to R8 V3.4.0.2)

EPSS: Низкий
github логотип

GHSA-2c5p-3g7v-4hc2

больше 3 лет назад

Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, and 7u67, and Java SE Embedded 7u60, allows remote attackers to affect confidentiality via unknown vectors related to Hotspot.

EPSS: Низкий
github логотип

GHSA-2c5m-w65p-6fhv

больше 3 лет назад

** DISPUTED ** PHP remote file inclusion vulnerability in logic/controller.class.php in clearBudget 0.9.8 allows remote attackers to execute arbitrary PHP code via a URL in the actionPath parameter. NOTE: this issue has been disputed by a reliable third party.

EPSS: Низкий
github логотип

GHSA-2c5m-jj29-px47

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in help.php in Moodle before 1.3 allows remote attackers to inject arbitrary HTML and web script via the text parameter.

EPSS: Низкий
github логотип

GHSA-2c5j-c3wx-m67f

больше 3 лет назад

Cloud Foundry Garden-Linux versions prior to v0.333.0 and Elastic Runtime 1.6.x version prior to 1.6.17 contain a flaw in managing container files during Docker image preparation that could be used to delete, corrupt or overwrite host files and directories, including other container filesystems on the host.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2c5j-72v9-m25f

больше 3 лет назад

STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "User Mode Write AV starting at STDUJBIG2File!DllUnregisterServer+0x000000000000566e."

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2c5h-8vr9-5p47

больше 2 лет назад

A vulnerability was found in FeiFeiCMS 2.7.130201. It has been classified as problematic. This affects an unknown part of the file \Public\system\slide_add.html of the component Extension Tool. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-223557 was assigned to this vulnerability.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2c5h-464h-7qrx

2 месяца назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BZOTheme Fitrush allows PHP Local File Inclusion. This issue affects Fitrush: from n/a through 1.3.4.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2c5g-wfw7-9g8c

больше 3 лет назад

The Standard Collector Service in Windows Diagnostics Hub in Microsoft Windows 10 Gold, 1511, and 1607 mishandles library loading, which allows local users to gain privileges via a crafted application, aka "Windows Diagnostics Hub Elevation of Privilege Vulnerability."

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2c5g-m2mc-9rp3

больше 3 лет назад

Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Products 8.52 allows remote attackers to affect integrity, related to PIA Core Technology.

EPSS: Низкий
github логотип

GHSA-2c5g-cwp8-gxcg

около 3 лет назад

ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read at MagickCore/threshold.c in AdaptiveThresholdImage because a width of zero is mishandled.

EPSS: Низкий
github логотип

GHSA-2c5f-68qc-5vrp

больше 3 лет назад

An Information Disclosure vulnerability exists in Netgear WNDR4700 running firmware 1.0.0.34 in the management web interface, which discloses the PSK of the wireless LAN.

EPSS: Низкий
github логотип

GHSA-2c5f-4533-6cw9

больше 3 лет назад

Unspecified vulnerability in the Oracle Customer Intelligence component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2016-0545, CVE-2016-0551, CVE-2016-0552, and CVE-2016-0559.

EPSS: Низкий
github логотип

GHSA-2c5f-4477-2248

около 3 лет назад

XSS in signup form in Project Worlds Online Examination System 1.0 allows remote attacker to inject arbitrary code via the name field

EPSS: Низкий
github логотип

GHSA-2c5c-fhr8-pwh9

больше 2 лет назад

Jenkins AppSpider Plugin missing permission check

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2c62-8p8p-hh5w

Libgcrypt before 1.6.5 does not properly perform elliptic-point curve multiplication during decryption, which makes it easier for physically proximate attackers to extract ECDH keys by measuring electromagnetic emanations.

CVSS3: 2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2c5w-43q3-9h56

D-Link D-View coreservice_action_script Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link D-View. Authentication is not required to exploit this vulnerability. The specific flaw exists within the coreservice_action_script action. The issue results from the exposure of a dangerous function. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-19573.

CVSS3: 9.8
4%
Низкий
больше 1 года назад
github логотип
GHSA-2c5v-4pcw-67jx

Format string vulnerability in Lithium II mod 1.24 for Quake 2 allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via format string specifiers in the nickname.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-2c5r-8h52-phwr

Zoom for Windows clients prior to 5.13.5 contain an improper verification of cryptographic signature vulnerability. A malicious user may potentially downgrade Zoom Client components to previous versions.

CVSS3: 2.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-2c5p-v6r6-q8xj

In wlan driver, there is a possible out of bound read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998291; Issue ID: MSV-1604.

CVSS3: 7.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-2c5p-55qj-5p58

A CWE-614 Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain an unauthorized access over a hijacked session to the charger station web server even after the legitimate user account holder has changed his password. Affected Products: EVlink City EVC1S22P4 / EVC1S7P4 (All versions prior to R8 V3.4.0.2 ), EVlink Parking EVW2 / EVF2 / EVP2PE (All versions prior to R8 V3.4.0.2), and EVlink Smart Wallbox EVB1A (All versions prior to R8 V3.4.0.2)

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2c5p-3g7v-4hc2

Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, and 7u67, and Java SE Embedded 7u60, allows remote attackers to affect confidentiality via unknown vectors related to Hotspot.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-2c5m-w65p-6fhv

** DISPUTED ** PHP remote file inclusion vulnerability in logic/controller.class.php in clearBudget 0.9.8 allows remote attackers to execute arbitrary PHP code via a URL in the actionPath parameter. NOTE: this issue has been disputed by a reliable third party.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2c5m-jj29-px47

Cross-site scripting (XSS) vulnerability in help.php in Moodle before 1.3 allows remote attackers to inject arbitrary HTML and web script via the text parameter.

4%
Низкий
больше 3 лет назад
github логотип
GHSA-2c5j-c3wx-m67f

Cloud Foundry Garden-Linux versions prior to v0.333.0 and Elastic Runtime 1.6.x version prior to 1.6.17 contain a flaw in managing container files during Docker image preparation that could be used to delete, corrupt or overwrite host files and directories, including other container filesystems on the host.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2c5j-72v9-m25f

STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "User Mode Write AV starting at STDUJBIG2File!DllUnregisterServer+0x000000000000566e."

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2c5h-8vr9-5p47

A vulnerability was found in FeiFeiCMS 2.7.130201. It has been classified as problematic. This affects an unknown part of the file \Public\system\slide_add.html of the component Extension Tool. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-223557 was assigned to this vulnerability.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2c5h-464h-7qrx

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BZOTheme Fitrush allows PHP Local File Inclusion. This issue affects Fitrush: from n/a through 1.3.4.

CVSS3: 8.1
0%
Низкий
2 месяца назад
github логотип
GHSA-2c5g-wfw7-9g8c

The Standard Collector Service in Windows Diagnostics Hub in Microsoft Windows 10 Gold, 1511, and 1607 mishandles library loading, which allows local users to gain privileges via a crafted application, aka "Windows Diagnostics Hub Elevation of Privilege Vulnerability."

CVSS3: 7.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-2c5g-m2mc-9rp3

Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Products 8.52 allows remote attackers to affect integrity, related to PIA Core Technology.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2c5g-cwp8-gxcg

ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read at MagickCore/threshold.c in AdaptiveThresholdImage because a width of zero is mishandled.

0%
Низкий
около 3 лет назад
github логотип
GHSA-2c5f-68qc-5vrp

An Information Disclosure vulnerability exists in Netgear WNDR4700 running firmware 1.0.0.34 in the management web interface, which discloses the PSK of the wireless LAN.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-2c5f-4533-6cw9

Unspecified vulnerability in the Oracle Customer Intelligence component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2016-0545, CVE-2016-0551, CVE-2016-0552, and CVE-2016-0559.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2c5f-4477-2248

XSS in signup form in Project Worlds Online Examination System 1.0 allows remote attacker to inject arbitrary code via the name field

0%
Низкий
около 3 лет назад
github логотип
GHSA-2c5c-fhr8-pwh9

Jenkins AppSpider Plugin missing permission check

CVSS3: 4.3
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу