Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3m25-4622-6q4x

больше 3 лет назад

An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) software. The InputMethod application can cause a system crash via a malformed serializable object in an Intent. The Samsung ID is SVE-2016-7123 (February 2017).

EPSS: Низкий
github логотип

GHSA-3m24-mjhw-3m4j

больше 3 лет назад

An issue was discovered in certain Apple products. The Apple Support app before 1.2 for iOS is affected. The issue involves the "Analytics" component. It allows remote attackers to obtain sensitive analytics information by leveraging its presence in a cleartext HTTP transmission to an Adobe Marketing Cloud server operated for Apple, as demonstrated by information about the installation date and time.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3m23-m58c-wrv4

почти 4 года назад

SQL injection vulnerability in tickets.php in cSupport 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the pg parameter.

EPSS: Низкий
github логотип

GHSA-3m23-jj5c-7p7p

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in phpgwapi/js/jscalendar/test.php in EGroupware Enterprise Line (EPL) before 11.1.20110804-1 and EGroupware Community Edition before 1.8.001.20110805 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.

EPSS: Низкий
github логотип

GHSA-3m23-cvmj-jrhp

больше 3 лет назад

The framework APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allow attackers to gain privileges via a crafted application, aka internal bug 30202481.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3m22-3wj5-cpwf

больше 3 лет назад

There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability).

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-3jxx-mhp5-7g48

почти 4 года назад

Multiple stack-based buffer overflows in the Online Media Technologies NCTSoft NCTAudioInformation2 ActiveX control in NCTAudioInformation2.dll, as used in (1) Power Audio CD Grabber 1.0, (2) Power Audio CD Burner 1.02, (3) CinematicMP3 1.4.0.0, (4) Alive MP3 WAV Converter 3.9.3.2, and possibly other products, allow remote attackers to execute arbitrary code via unspecified vectors.

EPSS: Средний
github логотип

GHSA-3jxx-m7vj-jgc2

3 месяца назад

Insufficient validation of untrusted input in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3jxw-m3h4-qfqj

3 месяца назад

InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3jxw-cv35-2mmv

почти 3 года назад

Apache DolphinScheduler's python gateway suffered from improper authentication

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3jxv-2g3q-q23g

больше 3 лет назад

Multiple heap-based buffer overflows in xine-lib 1.1.12, and other 1.1.15 and earlier versions, allow remote attackers to execute arbitrary code via vectors related to (1) a crafted EBML element length processed by the parse_block_group function in demux_matroska.c; (2) a certain combination of sps, w, and h values processed by the real_parse_audio_specific_data and demux_real_send_chunk functions in demux_real.c; and (3) an unspecified combination of three values processed by the open_ra_file function in demux_realaudio.c. NOTE: vector 2 reportedly exists because of an incomplete fix in 1.1.15.

EPSS: Низкий
github логотип

GHSA-3jxr-23ph-c89g

11 месяцев назад

Wildfly Elytron integration susceptible to brute force attacks via CLI

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3jxq-9m8c-3j55

больше 2 лет назад

Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin function 'sub_ADD50' contains a command execution vulnerability. In the "formSetIptv" function, obtaining the "list" and "vlanId" fields, unfiltered passing these two fields as parameters to the "sub_ADD50" function to execute commands.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3jxq-5xhh-9jr3

больше 1 года назад

Cross-Site Scripting (XSS) in TYPO3 component Backend

EPSS: Низкий
github логотип

GHSA-3jxq-45r5-2p48

больше 3 лет назад

In getPhoneAccountsForPackage of TelecomServiceImpl.java, there is a possible way to access a tracking identifier due to a missing permission check. This could lead to local information disclosure of the identifier, which could be used to track an account across devices, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10 Android-11Android ID: A-153995334

EPSS: Низкий
github логотип

GHSA-3jxp-72qc-76w7

больше 3 лет назад

The MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not properly restrict size addition, which allows remote attackers to execute arbitrary code or cause a denial of service (integer overflow and memory corruption) via a crafted MPEG-4 tx3g atom, aka internal bug 20923261.

EPSS: Средний
github логотип

GHSA-3jxm-cp2c-65rc

больше 3 лет назад

Open redirect vulnerability in Booked versions prior to 3.3 allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3jxm-9rgj-3r6j

11 месяцев назад

The SKU Generator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.6.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3jxj-c73c-7933

8 месяцев назад

IBM InfoSphere Information Server 11.7 stores credential information for database authentication in a cleartext parameter file that could be viewed by an authenticated user.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3jxj-2fmg-wg9x

9 месяцев назад

An Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to corrupt the memory of IO devices that use the library by sending a malicious RPC packet.

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3m25-4622-6q4x

An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) software. The InputMethod application can cause a system crash via a malformed serializable object in an Intent. The Samsung ID is SVE-2016-7123 (February 2017).

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3m24-mjhw-3m4j

An issue was discovered in certain Apple products. The Apple Support app before 1.2 for iOS is affected. The issue involves the "Analytics" component. It allows remote attackers to obtain sensitive analytics information by leveraging its presence in a cleartext HTTP transmission to an Adobe Marketing Cloud server operated for Apple, as demonstrated by information about the installation date and time.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3m23-m58c-wrv4

SQL injection vulnerability in tickets.php in cSupport 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the pg parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-3m23-jj5c-7p7p

Cross-site scripting (XSS) vulnerability in phpgwapi/js/jscalendar/test.php in EGroupware Enterprise Line (EPL) before 11.1.20110804-1 and EGroupware Community Edition before 1.8.001.20110805 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-3m23-cvmj-jrhp

The framework APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allow attackers to gain privileges via a crafted application, aka internal bug 30202481.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3m22-3wj5-cpwf

There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability).

CVSS3: 9.8
31%
Средний
больше 3 лет назад
github логотип
GHSA-3jxx-mhp5-7g48

Multiple stack-based buffer overflows in the Online Media Technologies NCTSoft NCTAudioInformation2 ActiveX control in NCTAudioInformation2.dll, as used in (1) Power Audio CD Grabber 1.0, (2) Power Audio CD Burner 1.02, (3) CinematicMP3 1.4.0.0, (4) Alive MP3 WAV Converter 3.9.3.2, and possibly other products, allow remote attackers to execute arbitrary code via unspecified vectors.

28%
Средний
почти 4 года назад
github логотип
GHSA-3jxx-m7vj-jgc2

Insufficient validation of untrusted input in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 5.4
0%
Низкий
3 месяца назад
github логотип
GHSA-3jxw-m3h4-qfqj

InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
3 месяца назад
github логотип
GHSA-3jxw-cv35-2mmv

Apache DolphinScheduler's python gateway suffered from improper authentication

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-3jxv-2g3q-q23g

Multiple heap-based buffer overflows in xine-lib 1.1.12, and other 1.1.15 and earlier versions, allow remote attackers to execute arbitrary code via vectors related to (1) a crafted EBML element length processed by the parse_block_group function in demux_matroska.c; (2) a certain combination of sps, w, and h values processed by the real_parse_audio_specific_data and demux_real_send_chunk functions in demux_real.c; and (3) an unspecified combination of three values processed by the open_ra_file function in demux_realaudio.c. NOTE: vector 2 reportedly exists because of an incomplete fix in 1.1.15.

4%
Низкий
больше 3 лет назад
github логотип
GHSA-3jxr-23ph-c89g

Wildfly Elytron integration susceptible to brute force attacks via CLI

CVSS3: 8.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-3jxq-9m8c-3j55

Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin function 'sub_ADD50' contains a command execution vulnerability. In the "formSetIptv" function, obtaining the "list" and "vlanId" fields, unfiltered passing these two fields as parameters to the "sub_ADD50" function to execute commands.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3jxq-5xhh-9jr3

Cross-Site Scripting (XSS) in TYPO3 component Backend

больше 1 года назад
github логотип
GHSA-3jxq-45r5-2p48

In getPhoneAccountsForPackage of TelecomServiceImpl.java, there is a possible way to access a tracking identifier due to a missing permission check. This could lead to local information disclosure of the identifier, which could be used to track an account across devices, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10 Android-11Android ID: A-153995334

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jxp-72qc-76w7

The MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not properly restrict size addition, which allows remote attackers to execute arbitrary code or cause a denial of service (integer overflow and memory corruption) via a crafted MPEG-4 tx3g atom, aka internal bug 20923261.

12%
Средний
больше 3 лет назад
github логотип
GHSA-3jxm-cp2c-65rc

Open redirect vulnerability in Booked versions prior to 3.3 allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3jxm-9rgj-3r6j

The SKU Generator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.6.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
1%
Низкий
11 месяцев назад
github логотип
GHSA-3jxj-c73c-7933

IBM InfoSphere Information Server 11.7 stores credential information for database authentication in a cleartext parameter file that could be viewed by an authenticated user.

CVSS3: 6.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-3jxj-2fmg-wg9x

An Heap-based Buffer Overflow in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to corrupt the memory of IO devices that use the library by sending a malicious RPC packet.

CVSS3: 4.8
0%
Низкий
9 месяцев назад

Уязвимостей на страницу