Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 289 610

Количество 289 610

github логотип

GHSA-2859-fc3x-94xw

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in HP Systems Insight Manager (SIM) before 6.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2859-f9hx-gvcp

больше 3 лет назад

SQL injection vulnerability in matchdetail.php in Powie's PHP MatchMaker 4.05 and earlier allows remote attackers to execute arbitrary SQL commands via the edit parameter.

EPSS: Низкий
github логотип

GHSA-2859-5gr5-x7f5

больше 3 лет назад

Springboard in Apple iOS before 7.1 allows physically proximate attackers to bypass intended access restrictions and read the home screen by leveraging an application crash during activation of an unactivated device.

EPSS: Низкий
github логотип

GHSA-2859-3xrw-r77c

около 1 года назад

D-Link DIR-605L v2.13B01 was discovered to contain a hardcoded password vulnerability in /etc/passwd, which allows attackers to log in as root.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2859-2jv7-892h

больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in the web interface in Cisco Prime Infrastructure allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCue84676.

EPSS: Низкий
github логотип

GHSA-2859-2hr6-f86v

около 3 лет назад

In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages.

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-2858-jrxx-h689

больше 3 лет назад

SQL injection vulnerability in page.php in Pre Studio Business Cards Designer allows remote attackers to execute arbitrary SQL commands via the id parameter.

EPSS: Низкий
github логотип

GHSA-2858-8cfx-69m9

больше 1 года назад

XWiki Platform: Remote code execution as guest via DatabaseSearch

CVSS3: 10
EPSS: Критический
github логотип

GHSA-2856-c9gx-h7rp

больше 3 лет назад

Alibaba HTTP server allows remote attackers to read files via a .. (dot dot) attack.

EPSS: Низкий
github логотип

GHSA-2856-5p3x-qmfp

больше 3 лет назад

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, and CVE-2015-8650.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-2856-2658-h48j

около 3 лет назад

A stack-based buffer over-read exists in PostScriptFunction::transform in Function.cc in Xpdf 4.01.01 because GfxSeparationColorSpace and GfxDeviceNColorSpace mishandle tint transform functions. It can, for example, be triggered by sending a crafted PDF document to the pdftops tool. It might allow an attacker to cause Denial of Service or leak memory data.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2854-jq38-8grq

около 3 лет назад

Incorrect Access Control in Tranquil WAPT Enterprise - before 1.8.2.7373 and before 2.0.0.9450 allows guest OS users to escalate privileges via WAPT Agent.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2853-hf2g-9843

больше 3 лет назад

PHPOffice Common Improper Restriction of XML External Entity Reference

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2853-84mf-g278

12 месяцев назад

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.8.2823 build 20240712 and later QuTS hero h5.1.8.2823 build 20240712 and later

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-284w-4f63-96hj

больше 3 лет назад

Buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 before LD SP32 EP10 and T28 before T28.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted WRF file, aka Bug ID CSCua61331.

EPSS: Низкий
github логотип

GHSA-284v-wmgp-rgxg

больше 3 лет назад

mountall 1.54, as used in Ubuntu 14.10, does not properly handle the umask when using the mount utility, which allows local users to bypass intended access restrictions via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-284r-hjcq-566x

около 3 лет назад

In AOSP Email, there is a possible information disclosure due to a confused deputy. This could lead to local disclosure of the Email app's protected files with User execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-37637796

EPSS: Низкий
github логотип

GHSA-284r-cvrc-f2f2

больше 3 лет назад

Buffer overflow in the SQLVDIRLib.SQLVDirControl ActiveX control in Tools\Binn\sqlvdir.dll in Microsoft SQL Server 2000 (aka SQL Server 8.0) allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a long URL in the second argument to the Connect method. NOTE: this issue is not a vulnerability in many environments, since the control is not marked as safe for scripting and would not execute with default Internet Explorer settings.

EPSS: Средний
github логотип

GHSA-284q-vmqr-cv75

около 3 лет назад

Oryx Embedded CycloneTCP 1.7.6 to 2.0.0, fixed in 2.0.2, is affected by incorrect input validation, which may cause a denial of service (DoS). To exploit the vulnerability, an attacker needs to have TCP connectivity to the target system. Receiving a maliciously crafted TCP packet from an unauthenticated endpoint is sufficient to trigger the bug.

EPSS: Низкий
github логотип

GHSA-284p-mmr3-vvxf

больше 3 лет назад

Summary:Product: AndroidVersions: Android SoCAndroid ID: A-204686438

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2859-fc3x-94xw

Cross-site scripting (XSS) vulnerability in HP Systems Insight Manager (SIM) before 6.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2859-f9hx-gvcp

SQL injection vulnerability in matchdetail.php in Powie's PHP MatchMaker 4.05 and earlier allows remote attackers to execute arbitrary SQL commands via the edit parameter.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2859-5gr5-x7f5

Springboard in Apple iOS before 7.1 allows physically proximate attackers to bypass intended access restrictions and read the home screen by leveraging an application crash during activation of an unactivated device.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2859-3xrw-r77c

D-Link DIR-605L v2.13B01 was discovered to contain a hardcoded password vulnerability in /etc/passwd, which allows attackers to log in as root.

CVSS3: 8.8
0%
Низкий
около 1 года назад
github логотип
GHSA-2859-2jv7-892h

Cross-site request forgery (CSRF) vulnerability in the web interface in Cisco Prime Infrastructure allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCue84676.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2859-2hr6-f86v

In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages.

CVSS3: 9.8
94%
Критический
около 3 лет назад
github логотип
GHSA-2858-jrxx-h689

SQL injection vulnerability in page.php in Pre Studio Business Cards Designer allows remote attackers to execute arbitrary SQL commands via the id parameter.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2858-8cfx-69m9

XWiki Platform: Remote code execution as guest via DatabaseSearch

CVSS3: 10
94%
Критический
больше 1 года назад
github логотип
GHSA-2856-c9gx-h7rp

Alibaba HTTP server allows remote attackers to read files via a .. (dot dot) attack.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-2856-5p3x-qmfp

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8634, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, and CVE-2015-8650.

CVSS3: 8.8
49%
Средний
больше 3 лет назад
github логотип
GHSA-2856-2658-h48j

A stack-based buffer over-read exists in PostScriptFunction::transform in Function.cc in Xpdf 4.01.01 because GfxSeparationColorSpace and GfxDeviceNColorSpace mishandle tint transform functions. It can, for example, be triggered by sending a crafted PDF document to the pdftops tool. It might allow an attacker to cause Denial of Service or leak memory data.

CVSS3: 7.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-2854-jq38-8grq

Incorrect Access Control in Tranquil WAPT Enterprise - before 1.8.2.7373 and before 2.0.0.9450 allows guest OS users to escalate privileges via WAPT Agent.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-2853-hf2g-9843

PHPOffice Common Improper Restriction of XML External Entity Reference

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2853-84mf-g278

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.8.2823 build 20240712 and later QuTS hero h5.1.8.2823 build 20240712 and later

CVSS3: 4.7
1%
Низкий
12 месяцев назад
github логотип
GHSA-284w-4f63-96hj

Buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 before LD SP32 EP10 and T28 before T28.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted WRF file, aka Bug ID CSCua61331.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-284v-wmgp-rgxg

mountall 1.54, as used in Ubuntu 14.10, does not properly handle the umask when using the mount utility, which allows local users to bypass intended access restrictions via unspecified vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-284r-hjcq-566x

In AOSP Email, there is a possible information disclosure due to a confused deputy. This could lead to local disclosure of the Email app's protected files with User execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-37637796

0%
Низкий
около 3 лет назад
github логотип
GHSA-284r-cvrc-f2f2

Buffer overflow in the SQLVDIRLib.SQLVDirControl ActiveX control in Tools\Binn\sqlvdir.dll in Microsoft SQL Server 2000 (aka SQL Server 8.0) allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a long URL in the second argument to the Connect method. NOTE: this issue is not a vulnerability in many environments, since the control is not marked as safe for scripting and would not execute with default Internet Explorer settings.

38%
Средний
больше 3 лет назад
github логотип
GHSA-284q-vmqr-cv75

Oryx Embedded CycloneTCP 1.7.6 to 2.0.0, fixed in 2.0.2, is affected by incorrect input validation, which may cause a denial of service (DoS). To exploit the vulnerability, an attacker needs to have TCP connectivity to the target system. Receiving a maliciously crafted TCP packet from an unauthenticated endpoint is sufficient to trigger the bug.

0%
Низкий
около 3 лет назад
github логотип
GHSA-284p-mmr3-vvxf

Summary:Product: AndroidVersions: Android SoCAndroid ID: A-204686438

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу