Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 315 500

Количество 315 500

github логотип

GHSA-37hr-3fmf-v449

11 месяцев назад

A vulnerability classified as critical was found in TOTOLINK A6000R 1.0.1-B20201211.2000. Affected by this vulnerability is the function apcli_cancel_wps of the file /usr/lib/lua/luci/controller/mtkwifi.lua. The manipulation leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-37hr-348p-rmf4

больше 3 лет назад

Improper handling of multiline messages in node-irc affects matrix-appservice-irc

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-37hq-frhq-c3c6

почти 4 года назад

index.php in FTP Admin 0.1.0 allows remote attackers to bypass authentication and obtain administrative access via a loggedin parameter with a value of true, as demonstrated by adding a user account.

EPSS: Низкий
github логотип

GHSA-37hq-32h5-h6mj

почти 4 года назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.0.80. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JT files. Crafted data in a JT file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15375.

EPSS: Низкий
github логотип

GHSA-37hp-xmxv-j842

больше 3 лет назад

Juniper Junos OS before 12.1X44-D60, 12.1X46 before 12.1X46-D40, 12.1X47 before 12.1X47-D30, 12.3 before 12.3R11, 12.3X48 before 12.3X48-D20, 13.2 before 13.2R9, 13.2X51 before 13.2X51-D39, 13.3 before 13.3R8, 14.1 before 14.1R6, 14.1X53 before 14.1X53-D30, 14.2 before 14.2R4-S1, 15.1 before 15.1R2, 15.1X49 before 15.1X49-D30, and 16.1 before 16.1R1 allow remote attackers to cause a denial of service (socket consumption) via crafted TCP timestamps.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-37hp-765x-j95x

около 7 лет назад

Django open redirect and possible XSS attack via user-supplied numeric redirect URLs

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-37hm-h4p2-3xrx

почти 4 года назад

Geert Moernaut LSrunasE allows local users to gain privileges by obtaining the encrypted password from a batch file, and constructing a modified batch file that specifies this password in the /password switch and specifies an arbitrary program in the /command switch.

EPSS: Низкий
github логотип

GHSA-37hm-8cwf-jp7f

больше 1 года назад

[A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-37hm-87pw-mw7f

почти 4 года назад

Clam AntiVirus (ClamAV) 0.88 and earlier allows remote attackers to cause a denial of service (crash) via a malformed base64-encoded MIME attachment that triggers a null pointer dereference.

EPSS: Низкий
github логотип

GHSA-37hm-7427-xp37

почти 4 года назад

Stack-based buffer overflow in Novell Client 4.91 SP4 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long username in the "forgotten password" dialog.

EPSS: Низкий
github логотип

GHSA-37hm-5m3h-f5px

почти 4 года назад

gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-37hj-qxxx-w7gw

больше 2 лет назад

An information leak in Daiky-value.Fukueten v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-37hj-7rj6-j3pq

около 2 лет назад

Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-37hg-4qwq-2g86

8 месяцев назад

A vulnerability was found in HobbesOSR Kitten up to c4f8b7c3158983d1020af432be1b417b28686736 and classified as critical. Affected by this issue is the function set_pte_at in the library /include/arch-arm64/pgtable.h. The manipulation leads to resource consumption. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-37hf-g994-5pq8

больше 3 лет назад

Cross Site Scriptiong vulnerabilityin Screenly screenly-ose all versions, including v1.8.2 (2019-09-25-Screenly-OSE-lite.img), in the 'Add Asset' page via manipulation of a 'URL' field, which could let a remote malicious user execute arbitrary code.

EPSS: Низкий
github логотип

GHSA-37hf-5fw9-j428

больше 3 лет назад

IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow an authenticated user to to obtain sensitive information from a specially crafted HTTP request. IBM X-Force ID: 212780.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-37hf-2v5g-2h92

почти 4 года назад

D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the MAC parameter in /goform/editassignment.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-37hc-xgcp-m6w2

почти 4 года назад

Directory traversal vulnerability in Abyss Web Server 1.0.3 allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in an HTTP GET request.

EPSS: Средний
github логотип

GHSA-37hc-x8xx-qcfp

7 месяцев назад

A vulnerability, which was classified as problematic, was found in Comodo Dragon up to 134.0.6998.179. This affects an unknown part of the component IP DNS Leakage Detector. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-37h9-9838-7j9c

больше 1 года назад

Longse NVR (Network Video Recorder) model NVR3608PGE2W, as well as products based on this device, are transmitting user's login and password to a remote control service without using any encryption. This enables an on-path attacker to eavesdrop the credentials and subsequently obtain access to the video stream.  The credentials are being sent when a user decides to change his password in router's portal.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-37hr-3fmf-v449

A vulnerability classified as critical was found in TOTOLINK A6000R 1.0.1-B20201211.2000. Affected by this vulnerability is the function apcli_cancel_wps of the file /usr/lib/lua/luci/controller/mtkwifi.lua. The manipulation leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
6%
Низкий
11 месяцев назад
github логотип
GHSA-37hr-348p-rmf4

Improper handling of multiline messages in node-irc affects matrix-appservice-irc

CVSS3: 8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-37hq-frhq-c3c6

index.php in FTP Admin 0.1.0 allows remote attackers to bypass authentication and obtain administrative access via a loggedin parameter with a value of true, as demonstrated by adding a user account.

4%
Низкий
почти 4 года назад
github логотип
GHSA-37hq-32h5-h6mj

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.0.80. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JT files. Crafted data in a JT file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15375.

1%
Низкий
почти 4 года назад
github логотип
GHSA-37hp-xmxv-j842

Juniper Junos OS before 12.1X44-D60, 12.1X46 before 12.1X46-D40, 12.1X47 before 12.1X47-D30, 12.3 before 12.3R11, 12.3X48 before 12.3X48-D20, 13.2 before 13.2R9, 13.2X51 before 13.2X51-D39, 13.3 before 13.3R8, 14.1 before 14.1R6, 14.1X53 before 14.1X53-D30, 14.2 before 14.2R4-S1, 15.1 before 15.1R2, 15.1X49 before 15.1X49-D30, and 16.1 before 16.1R1 allow remote attackers to cause a denial of service (socket consumption) via crafted TCP timestamps.

CVSS3: 7.5
3%
Низкий
больше 3 лет назад
github логотип
GHSA-37hp-765x-j95x

Django open redirect and possible XSS attack via user-supplied numeric redirect URLs

CVSS3: 6.1
1%
Низкий
около 7 лет назад
github логотип
GHSA-37hm-h4p2-3xrx

Geert Moernaut LSrunasE allows local users to gain privileges by obtaining the encrypted password from a batch file, and constructing a modified batch file that specifies this password in the /password switch and specifies an arbitrary program in the /command switch.

0%
Низкий
почти 4 года назад
github логотип
GHSA-37hm-8cwf-jp7f

[A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-37hm-87pw-mw7f

Clam AntiVirus (ClamAV) 0.88 and earlier allows remote attackers to cause a denial of service (crash) via a malformed base64-encoded MIME attachment that triggers a null pointer dereference.

1%
Низкий
почти 4 года назад
github логотип
GHSA-37hm-7427-xp37

Stack-based buffer overflow in Novell Client 4.91 SP4 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long username in the "forgotten password" dialog.

0%
Низкий
почти 4 года назад
github логотип
GHSA-37hm-5m3h-f5px

gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-37hj-qxxx-w7gw

An information leak in Daiky-value.Fukueten v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-37hj-7rj6-j3pq

Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-37hg-4qwq-2g86

A vulnerability was found in HobbesOSR Kitten up to c4f8b7c3158983d1020af432be1b417b28686736 and classified as critical. Affected by this issue is the function set_pte_at in the library /include/arch-arm64/pgtable.h. The manipulation leads to resource consumption. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.

CVSS3: 5.7
0%
Низкий
8 месяцев назад
github логотип
GHSA-37hf-g994-5pq8

Cross Site Scriptiong vulnerabilityin Screenly screenly-ose all versions, including v1.8.2 (2019-09-25-Screenly-OSE-lite.img), in the 'Add Asset' page via manipulation of a 'URL' field, which could let a remote malicious user execute arbitrary code.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-37hf-5fw9-j428

IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow an authenticated user to to obtain sensitive information from a specially crafted HTTP request. IBM X-Force ID: 212780.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-37hf-2v5g-2h92

D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the MAC parameter in /goform/editassignment.

CVSS3: 9.8
2%
Низкий
почти 4 года назад
github логотип
GHSA-37hc-xgcp-m6w2

Directory traversal vulnerability in Abyss Web Server 1.0.3 allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in an HTTP GET request.

13%
Средний
почти 4 года назад
github логотип
GHSA-37hc-x8xx-qcfp

A vulnerability, which was classified as problematic, was found in Comodo Dragon up to 134.0.6998.179. This affects an unknown part of the component IP DNS Leakage Detector. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-37h9-9838-7j9c

Longse NVR (Network Video Recorder) model NVR3608PGE2W, as well as products based on this device, are transmitting user's login and password to a remote control service without using any encryption. This enables an on-path attacker to eavesdrop the credentials and subsequently obtain access to the video stream.  The credentials are being sent when a user decides to change his password in router's portal.

0%
Низкий
больше 1 года назад

Уязвимостей на страницу