Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 288 388

Количество 288 388

github логотип

GHSA-253r-m962-f83q

около 3 лет назад

Buffer Overflow in httpd in EpiCentro E_7.3.2+ allows attackers to cause a denial of service attack remotely via a specially crafted GET request with a leading "/" in the URL.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-253r-3vgg-gj92

около 3 лет назад

In versions 16.0.0-16.0.0.1 and 15.1.0-15.1.1, on specific BIG-IP platforms, attackers may be able to obtain TCP sequence numbers from the BIG-IP system that can be reused in future connections with the same source and destination port and IP numbers. Only these platforms are affected: BIG-IP 2000 series (C112), BIG-IP 4000 series (C113), BIG-IP i2000 series (C117), BIG-IP i4000 series (C115), BIG-IP Virtual Edition (VE).

EPSS: Низкий
github логотип

GHSA-253q-prr2-4prx

12 месяцев назад

Exposure of Sensitive Information to an Unauthorized Actor, Missing Authorization vulnerability in ThemeSphere SmartMag allows Excavation, Accessing Functionality Not Properly Constrained by ACLs.This issue affects SmartMag: from n/a through 9.3.0.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-253q-85fr-vjfv

около 3 лет назад

Cross-site scripting (XSS) vulnerability in cgiemail and cgiecho allows remote attackers to inject arbitrary web script or HTML via the addendum parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-253p-g49j-p89x

около 3 лет назад

Cross-site scripting (XSS) vulnerability in the googleSearch (CSE) (com_googlesearch_cse) component 3.0.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the q parameter to index.php.

EPSS: Низкий
github логотип

GHSA-253p-896q-pwmq

около 3 лет назад

IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 203440.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-253m-678w-hcj3

около 3 лет назад

IBM Emptoris Sourcing 9.5 - 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128172.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-253m-4wjm-2prr

больше 3 лет назад

Multiple unknown vulnerabilities in Real Estate Management Software 1.0 have unknown impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-253j-mgc4-hp35

около 3 лет назад

Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-253h-63vc-5w2v

около 3 лет назад

XBMC 13.0 uses world-readable permissions for .xbmc/userdata/sources.xml, which allows local users to obtain user names and passwords by reading this file.

EPSS: Низкий
github логотип

GHSA-253g-w96v-v3cj

больше 3 лет назад

IcedTea 1.7 before 1.7.8, 1.8 before 1.8.5, and 1.9 before 1.9.5 does not properly verify signatures for JAR files that (1) are "partially signed" or (2) signed by multiple entities, which allows remote attackers to trick users into executing code that appears to come from a trusted source.

EPSS: Низкий
github логотип

GHSA-253g-rphr-6h5j

10 месяцев назад

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the web-based management interface does not validate user input adequately. An attacker could exploit this vulnerability by authenticating to the application as an Administrator and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to obtain unauthorized data from the database and make changes to the system. To exploit this vulnerability, an attacker would need Administrator-level privileges.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-253g-g2mf-qcvg

около 3 лет назад

IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 uses weak permissions for unspecified resources, which allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-253g-4jm3-6p9v

около 3 лет назад

Huawei Honor Magic2 mobile phones with versions earlier than 10.0.0.175(C00E59R2P11) have an information leak vulnerability. Due to a module using weak encryption tool, an attacker with the root permission may exploit the vulnerability to obtain some information.

EPSS: Низкий
github логотип

GHSA-253f-6wj2-m9j2

больше 3 лет назад

Cisco ONS15454 and ONS15327 running ONS before 3.4 stores usernames and passwords in cleartext in the image database for the TCC, TCC+ or XTC, which could allow attackers to gain privileges by obtaining the passwords from the image database or a backup.

EPSS: Низкий
github логотип

GHSA-253c-qwpg-75w9

больше 3 лет назад

Buffer overflow in PPP on Apple Mac OS X 10.4.x up to 10.4.8 and 10.3.x up to 10.3.9, when PPPoE is enabled, allows remote attackers to execute arbitrary code via unspecified vectors.

EPSS: Средний
github логотип

GHSA-253c-crvf-xgfx

около 3 лет назад

IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to hijack sessions, and consequently read records, modify records, or conduct transactions, via an unspecified link injection.

EPSS: Низкий
github логотип

GHSA-253c-2jpf-7jp9

больше 2 лет назад

Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2539-c345-jfjh

больше 1 года назад

A stored cross-site scripting (XSS) vulnerability in EyouCMS v1.6.4-UTF8-SP1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Field Title field at /login.php?m=admin&c=Field&a=arctype_add&_ajax=1&lang=cn.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2539-86p5-f4xj

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Web Inspector in WebKit in Apple Safari before 4.0 allows user-assisted remote attackers to inject arbitrary web script or HTML, and read local files, via vectors related to script execution with incorrect privileges.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-253r-m962-f83q

Buffer Overflow in httpd in EpiCentro E_7.3.2+ allows attackers to cause a denial of service attack remotely via a specially crafted GET request with a leading "/" in the URL.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-253r-3vgg-gj92

In versions 16.0.0-16.0.0.1 and 15.1.0-15.1.1, on specific BIG-IP platforms, attackers may be able to obtain TCP sequence numbers from the BIG-IP system that can be reused in future connections with the same source and destination port and IP numbers. Only these platforms are affected: BIG-IP 2000 series (C112), BIG-IP 4000 series (C113), BIG-IP i2000 series (C117), BIG-IP i4000 series (C115), BIG-IP Virtual Edition (VE).

0%
Низкий
около 3 лет назад
github логотип
GHSA-253q-prr2-4prx

Exposure of Sensitive Information to an Unauthorized Actor, Missing Authorization vulnerability in ThemeSphere SmartMag allows Excavation, Accessing Functionality Not Properly Constrained by ACLs.This issue affects SmartMag: from n/a through 9.3.0.

CVSS3: 5.3
0%
Низкий
12 месяцев назад
github логотип
GHSA-253q-85fr-vjfv

Cross-site scripting (XSS) vulnerability in cgiemail and cgiecho allows remote attackers to inject arbitrary web script or HTML via the addendum parameter.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-253p-g49j-p89x

Cross-site scripting (XSS) vulnerability in the googleSearch (CSE) (com_googlesearch_cse) component 3.0.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the q parameter to index.php.

0%
Низкий
около 3 лет назад
github логотип
GHSA-253p-896q-pwmq

IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 203440.

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-253m-678w-hcj3

IBM Emptoris Sourcing 9.5 - 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128172.

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-253m-4wjm-2prr

Multiple unknown vulnerabilities in Real Estate Management Software 1.0 have unknown impact and attack vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-253j-mgc4-hp35

Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

CVSS3: 6.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-253h-63vc-5w2v

XBMC 13.0 uses world-readable permissions for .xbmc/userdata/sources.xml, which allows local users to obtain user names and passwords by reading this file.

0%
Низкий
около 3 лет назад
github логотип
GHSA-253g-w96v-v3cj

IcedTea 1.7 before 1.7.8, 1.8 before 1.8.5, and 1.9 before 1.9.5 does not properly verify signatures for JAR files that (1) are "partially signed" or (2) signed by multiple entities, which allows remote attackers to trick users into executing code that appears to come from a trusted source.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-253g-rphr-6h5j

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the web-based management interface does not validate user input adequately. An attacker could exploit this vulnerability by authenticating to the application as an Administrator and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to obtain unauthorized data from the database and make changes to the system. To exploit this vulnerability, an attacker would need Administrator-level privileges.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-253g-g2mf-qcvg

IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 uses weak permissions for unspecified resources, which allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.

CVSS3: 6.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-253g-4jm3-6p9v

Huawei Honor Magic2 mobile phones with versions earlier than 10.0.0.175(C00E59R2P11) have an information leak vulnerability. Due to a module using weak encryption tool, an attacker with the root permission may exploit the vulnerability to obtain some information.

0%
Низкий
около 3 лет назад
github логотип
GHSA-253f-6wj2-m9j2

Cisco ONS15454 and ONS15327 running ONS before 3.4 stores usernames and passwords in cleartext in the image database for the TCC, TCC+ or XTC, which could allow attackers to gain privileges by obtaining the passwords from the image database or a backup.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-253c-qwpg-75w9

Buffer overflow in PPP on Apple Mac OS X 10.4.x up to 10.4.8 and 10.3.x up to 10.3.9, when PPPoE is enabled, allows remote attackers to execute arbitrary code via unspecified vectors.

21%
Средний
больше 3 лет назад
github логотип
GHSA-253c-crvf-xgfx

IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to hijack sessions, and consequently read records, modify records, or conduct transactions, via an unspecified link injection.

0%
Низкий
около 3 лет назад
github логотип
GHSA-253c-2jpf-7jp9

Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2539-c345-jfjh

A stored cross-site scripting (XSS) vulnerability in EyouCMS v1.6.4-UTF8-SP1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Field Title field at /login.php?m=admin&c=Field&a=arctype_add&_ajax=1&lang=cn.

CVSS3: 4.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2539-86p5-f4xj

Cross-site scripting (XSS) vulnerability in Web Inspector in WebKit in Apple Safari before 4.0 allows user-assisted remote attackers to inject arbitrary web script or HTML, and read local files, via vectors related to script execution with incorrect privileges.

2%
Низкий
больше 3 лет назад

Уязвимостей на страницу