Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-34h9-hw7w-7v67

больше 3 лет назад

An issue was discovered in Couchbase Server 7.x before 7.0.4. Field names are not redacted in logged validation messages for Analytics Service. An Unauthorized Actor may be able to obtain Sensitive Information.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-34h8-mfmv-f2g5

больше 3 лет назад

A vulnerability has been identified in Simcenter Femap 2020.2 (All versions < V2020.2.MP3), Simcenter Femap 2021.1 (All versions < V2021.1.MP3). The femap.exe application lacks proper validation of user-supplied data when parsing FEMAP files. This could result in an out of bounds write past the end of an allocated structure, a different vulnerability than CVE-2021-27399. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-12819)

EPSS: Низкий
github логотип

GHSA-34h8-39qg-fg5m

больше 2 лет назад

In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-34h5-p5c9-pjw6

почти 4 года назад

libxml2 2.7.0 and 2.7.1 does not properly handle "predefined entities definitions" in entities, which allows context-dependent attackers to cause a denial of service (memory consumption and application crash), as demonstrated by use of xmllint on a certain XML document, a different vulnerability than CVE-2003-1564 and CVE-2008-3281.

EPSS: Средний
github логотип

GHSA-34h5-8gf3-x5q5

больше 3 лет назад

LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Write vulnerability in Patient file letter functions that can result in Write files with malicious content and may lead to remote code execution. This attack appear to be exploitable via User controlled parameters.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-34h5-5rm5-5r55

больше 3 лет назад

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.

EPSS: Низкий
github логотип

GHSA-34h5-53fh-qqxm

почти 2 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Evergreen Content Poster allows Reflected XSS.This issue affects Evergreen Content Poster: from n/a through 1.4.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-34h4-h6v3-w52h

больше 3 лет назад

Huawei smart phones Emily-L29C with versions of 8.1.0.132a(C432), 8.1.0.135(C782), 8.1.0.154(C10), 8.1.0.154(C461), 8.1.0.154(C635), 8.1.0.156(C185), 8.1.0.156(C605), 8.1.0.159(C636) have a double free vulnerability. An attacker can trick a user to click a URL to exploit this vulnerability. Successful exploitation may cause the affected phone abnormal.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-34h4-6895-w557

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Product Attachment for WooCommerce plugin <= 2.1.8 versions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-34h3-8mw4-qw57

почти 2 года назад

@electron/packager's build process memory potentially leaked into final executable

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-34h3-77mg-mfgh

больше 1 года назад

Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-34gx-cxph-hgc9

больше 3 лет назад

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Security Bypass vulnerability. Successful exploitation could lead to privilege escalation.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-34gx-cprw-qgmf

больше 3 лет назад

Huawei smartphone Lion-AL00C with versions earlier than 10.0.0.205(C00E202R7P2) have a denial of service vulnerability. An attacker crafted specially file to the affected device. Due to insufficient input validation of the value when executing the file, successful exploit may cause device abnormal.

EPSS: Низкий
github логотип

GHSA-34gx-7858-4cgx

почти 4 года назад

Directory traversal vulnerability in template.php in in phpFaber TopSites 3 allows remote attackers to read arbitrary files via a .. (dot dot) in the modify parameter in a template action to admin/index.php.

EPSS: Низкий
github логотип

GHSA-34gw-w8q4-67cj

больше 3 лет назад

A memory corruption issue was addressed with improved input validation. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4, macOS Big Sur 11.6.6. A malicious application may be able to execute arbitrary code with kernel privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-34gw-qv43-p592

больше 3 лет назад

Unspecified vulnerability in HP HP-UX Whitelisting (aka WLI) before A.01.02.02 on HP-UX B.11.31 allows local users to bypass intended access restrictions via unknown vectors.

EPSS: Низкий
github логотип

GHSA-34gw-343r-pm56

больше 3 лет назад

IBM Tivoli Event Pump 4.2.2, when the LOG_REQUESTS and VALIDATE_SOAP_USERS options are enabled, places credentials into the AOPSCLOG (aka AOPLOG) data set, which allows local users to obtain sensitive information by reading the data.

EPSS: Низкий
github логотип

GHSA-34gv-wgxf-mrpx

около 4 лет назад

The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the gf_list_del function in list.c, which allows attackers to cause a denial of service.

EPSS: Низкий
github логотип

GHSA-34gv-vxwq-v84r

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in misc.php in Image Hosting Script DPI 1.0, 1.3, and earlier allows remote attackers to inject arbitrary web script or HTML via the showseries parameter.

EPSS: Низкий
github логотип

GHSA-34gv-g2q3-w3f7

почти 4 года назад

Multiple SQL injection vulnerabilities in (1) addcustomer.asp, (2) addprod.asp, and (3) process.asp in a.shopKart 2.0.3 allow remote attackers to execute arbitrary SQL and obtain sensitive information via the zip, state, country, phone, and fax parameters.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-34h9-hw7w-7v67

An issue was discovered in Couchbase Server 7.x before 7.0.4. Field names are not redacted in logged validation messages for Analytics Service. An Unauthorized Actor may be able to obtain Sensitive Information.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-34h8-mfmv-f2g5

A vulnerability has been identified in Simcenter Femap 2020.2 (All versions < V2020.2.MP3), Simcenter Femap 2021.1 (All versions < V2021.1.MP3). The femap.exe application lacks proper validation of user-supplied data when parsing FEMAP files. This could result in an out of bounds write past the end of an allocated structure, a different vulnerability than CVE-2021-27399. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-12819)

0%
Низкий
больше 3 лет назад
github логотип
GHSA-34h8-39qg-fg5m

In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-34h5-p5c9-pjw6

libxml2 2.7.0 and 2.7.1 does not properly handle "predefined entities definitions" in entities, which allows context-dependent attackers to cause a denial of service (memory consumption and application crash), as demonstrated by use of xmllint on a certain XML document, a different vulnerability than CVE-2003-1564 and CVE-2008-3281.

11%
Средний
почти 4 года назад
github логотип
GHSA-34h5-8gf3-x5q5

LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Write vulnerability in Patient file letter functions that can result in Write files with malicious content and may lead to remote code execution. This attack appear to be exploitable via User controlled parameters.

CVSS3: 8.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-34h5-5rm5-5r55

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-34h5-53fh-qqxm

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Evergreen Content Poster allows Reflected XSS.This issue affects Evergreen Content Poster: from n/a through 1.4.1.

CVSS3: 7.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-34h4-h6v3-w52h

Huawei smart phones Emily-L29C with versions of 8.1.0.132a(C432), 8.1.0.135(C782), 8.1.0.154(C10), 8.1.0.154(C461), 8.1.0.154(C635), 8.1.0.156(C185), 8.1.0.156(C605), 8.1.0.159(C636) have a double free vulnerability. An attacker can trick a user to click a URL to exploit this vulnerability. Successful exploitation may cause the affected phone abnormal.

CVSS3: 6.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-34h4-6895-w557

Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Product Attachment for WooCommerce plugin <= 2.1.8 versions.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-34h3-8mw4-qw57

@electron/packager's build process memory potentially leaked into final executable

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-34h3-77mg-mfgh

Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-34gx-cxph-hgc9

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Security Bypass vulnerability. Successful exploitation could lead to privilege escalation.

CVSS3: 9.8
8%
Низкий
больше 3 лет назад
github логотип
GHSA-34gx-cprw-qgmf

Huawei smartphone Lion-AL00C with versions earlier than 10.0.0.205(C00E202R7P2) have a denial of service vulnerability. An attacker crafted specially file to the affected device. Due to insufficient input validation of the value when executing the file, successful exploit may cause device abnormal.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-34gx-7858-4cgx

Directory traversal vulnerability in template.php in in phpFaber TopSites 3 allows remote attackers to read arbitrary files via a .. (dot dot) in the modify parameter in a template action to admin/index.php.

4%
Низкий
почти 4 года назад
github логотип
GHSA-34gw-w8q4-67cj

A memory corruption issue was addressed with improved input validation. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4, macOS Big Sur 11.6.6. A malicious application may be able to execute arbitrary code with kernel privileges.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-34gw-qv43-p592

Unspecified vulnerability in HP HP-UX Whitelisting (aka WLI) before A.01.02.02 on HP-UX B.11.31 allows local users to bypass intended access restrictions via unknown vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-34gw-343r-pm56

IBM Tivoli Event Pump 4.2.2, when the LOG_REQUESTS and VALIDATE_SOAP_USERS options are enabled, places credentials into the AOPSCLOG (aka AOPLOG) data set, which allows local users to obtain sensitive information by reading the data.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-34gv-wgxf-mrpx

The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the gf_list_del function in list.c, which allows attackers to cause a denial of service.

0%
Низкий
около 4 лет назад
github логотип
GHSA-34gv-vxwq-v84r

Cross-site scripting (XSS) vulnerability in misc.php in Image Hosting Script DPI 1.0, 1.3, and earlier allows remote attackers to inject arbitrary web script or HTML via the showseries parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-34gv-g2q3-w3f7

Multiple SQL injection vulnerabilities in (1) addcustomer.asp, (2) addprod.asp, and (3) process.asp in a.shopKart 2.0.3 allow remote attackers to execute arbitrary SQL and obtain sensitive information via the zip, state, country, phone, and fax parameters.

1%
Низкий
почти 4 года назад

Уязвимостей на страницу