Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-38hj-4492-g88q

больше 3 лет назад

INFOR EAM V11.0 Build 201410 has SQL injection via search fields, related to the filtervalue parameter.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-38hh-r6wr-38f6

почти 4 года назад

yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allows remote attackers to cause a denial of service (crash) via a Hello packet containing a large size value, which triggers a buffer over-read in the HASHwithTransform::Update function in hash.cpp.

EPSS: Низкий
github логотип

GHSA-38hh-g82x-9mpc

больше 3 лет назад

Windows Media Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-38hg-q2gf-cgvf

больше 2 лет назад

Vulnerability of failures to capture exceptions in the communication framework. Successful exploitation of this vulnerability may cause features to perform abnormally.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-38hg-hvc8-v572

больше 1 года назад

Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/NatStaticSetting.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-38hg-hfvc-c347

2 дня назад

A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file FinalStatusImportService.php of the component Final Status Import. Executing a manipulation of the argument school_id can lead to improper authorization. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-38hg-9xjj-pc2r

больше 2 лет назад

A vulnerability in the Tomcat implementation for Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to cause a web cache poisoning attack on an affected device. This vulnerability is due to improper input validation of HTTP requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to a specific API endpoint on the Unified CCX Finesse Portal. A successful exploit could allow the attacker to cause the internal WebProxy to redirect users to an attacker-controlled host.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-38hg-964r-m8jj

почти 3 года назад

IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS could allow an authenticated attacker with authorization to craft messages to cause a denial of service. IBM X-Force ID: 241354.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-38hg-868p-r35x

больше 3 лет назад

Inappropriate implementation in Omnibox in Google Chrome prior to 59.0.3071.92 for Android allowed a remote attacker to perform domain spoofing with RTL characters via a crafted URL page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-38hf-xjmx-jrh8

больше 3 лет назад

Cross-site Scripting in Graylog Server

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-38hf-j8cf-rw67

почти 2 года назад

LG Simple Editor createThumbnailByMovie Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the createThumbnailByMovie method. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-19978.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-38hf-f26w-w4j3

почти 4 года назад

Buffer overflow in the FTP service on the Tandberg MXP F7.0 allows remote attackers to cause a denial of service (process crash or device reboot) or possibly execute arbitrary code via a long USER command, as demonstrated by a command ending with many space characters.

EPSS: Средний
github логотип

GHSA-38hf-c37x-32hv

больше 3 лет назад

LIEF vulnerable to denial of service through segmentation fault

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-38hf-3vg9-9h45

больше 3 лет назад

The Pods – Custom Content Types and Fields WordPress plugin before 2.7.27 was vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) security vulnerability within the 'Menu Label' field parameter.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-38hc-j6w3-jg6w

больше 3 лет назад

The Bundle copy module 7.x-1.x before 7.x-1.1 for Drupal does not check for the "use PHP for settings" permission while importing settings, which allows remote authenticated users with certain permissions to execute arbitrary PHP code via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-38h9-vhv3-fwgh

больше 3 лет назад

The Portfolium (aka com.wPortfolium) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-38h9-g2p9-689w

около 1 года назад

A vulnerability classified as critical has been found in JFinalCMS 1.0. This affects the function findPage of the file src\main\java\com\cms\entity\ContentModel.java of the component File Content Handler. The manipulation of the argument name leads to sql injection. It is possible to initiate the attack remotely.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-38h9-5963-2wq2

больше 3 лет назад

An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GPMF_Next, related to certain checks for GPMF_KEY_END and nest_level (conditional on a buffer_size_longs check).

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-38h8-x697-gh8q

около 7 лет назад

Tmp files readable by other users in sync-exec

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-38h8-4x5x-cvpr

почти 4 года назад

SQL injection vulnerability in module/down.inc.php in jportal 2.3.1 allows remote attackers to execute arbitrary SQL commands via the search field to download.php.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-38hj-4492-g88q

INFOR EAM V11.0 Build 201410 has SQL injection via search fields, related to the filtervalue parameter.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-38hh-r6wr-38f6

yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allows remote attackers to cause a denial of service (crash) via a Hello packet containing a large size value, which triggers a buffer over-read in the HASHwithTransform::Update function in hash.cpp.

7%
Низкий
почти 4 года назад
github логотип
GHSA-38hh-g82x-9mpc

Windows Media Remote Code Execution Vulnerability

CVSS3: 7.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-38hg-q2gf-cgvf

Vulnerability of failures to capture exceptions in the communication framework. Successful exploitation of this vulnerability may cause features to perform abnormally.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-38hg-hvc8-v572

Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/NatStaticSetting.

CVSS3: 9.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-38hg-hfvc-c347

A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file FinalStatusImportService.php of the component Final Status Import. Executing a manipulation of the argument school_id can lead to improper authorization. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
0%
Низкий
2 дня назад
github логотип
GHSA-38hg-9xjj-pc2r

A vulnerability in the Tomcat implementation for Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to cause a web cache poisoning attack on an affected device. This vulnerability is due to improper input validation of HTTP requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to a specific API endpoint on the Unified CCX Finesse Portal. A successful exploit could allow the attacker to cause the internal WebProxy to redirect users to an attacker-controlled host.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-38hg-964r-m8jj

IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS could allow an authenticated attacker with authorization to craft messages to cause a denial of service. IBM X-Force ID: 241354.

CVSS3: 5.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-38hg-868p-r35x

Inappropriate implementation in Omnibox in Google Chrome prior to 59.0.3071.92 for Android allowed a remote attacker to perform domain spoofing with RTL characters via a crafted URL page.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-38hf-xjmx-jrh8

Cross-site Scripting in Graylog Server

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-38hf-j8cf-rw67

LG Simple Editor createThumbnailByMovie Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the createThumbnailByMovie method. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-19978.

CVSS3: 9.8
2%
Низкий
почти 2 года назад
github логотип
GHSA-38hf-f26w-w4j3

Buffer overflow in the FTP service on the Tandberg MXP F7.0 allows remote attackers to cause a denial of service (process crash or device reboot) or possibly execute arbitrary code via a long USER command, as demonstrated by a command ending with many space characters.

17%
Средний
почти 4 года назад
github логотип
GHSA-38hf-c37x-32hv

LIEF vulnerable to denial of service through segmentation fault

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-38hf-3vg9-9h45

The Pods – Custom Content Types and Fields WordPress plugin before 2.7.27 was vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) security vulnerability within the 'Menu Label' field parameter.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-38hc-j6w3-jg6w

The Bundle copy module 7.x-1.x before 7.x-1.1 for Drupal does not check for the "use PHP for settings" permission while importing settings, which allows remote authenticated users with certain permissions to execute arbitrary PHP code via unspecified vectors.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-38h9-vhv3-fwgh

The Portfolium (aka com.wPortfolium) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-38h9-g2p9-689w

A vulnerability classified as critical has been found in JFinalCMS 1.0. This affects the function findPage of the file src\main\java\com\cms\entity\ContentModel.java of the component File Content Handler. The manipulation of the argument name leads to sql injection. It is possible to initiate the attack remotely.

CVSS3: 6.3
0%
Низкий
около 1 года назад
github логотип
GHSA-38h9-5963-2wq2

An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GPMF_Next, related to certain checks for GPMF_KEY_END and nest_level (conditional on a buffer_size_longs check).

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-38h8-x697-gh8q

Tmp files readable by other users in sync-exec

CVSS3: 6.5
0%
Низкий
около 7 лет назад
github логотип
GHSA-38h8-4x5x-cvpr

SQL injection vulnerability in module/down.inc.php in jportal 2.3.1 allows remote attackers to execute arbitrary SQL commands via the search field to download.php.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу