Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-34g7-g5m3-mfmr

больше 3 лет назад

The slick-popup plugin before 1.7.2 for WordPress has a hardcoded OmakPass13# password for the slickpopupteam account, after a Subscriber calls a certain AJAX action.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-34g6-xv7x-r7fm

больше 3 лет назад

Multiple vulnerabilities in Cisco Intersight Virtual Appliance could allow an unauthenticated, adjacent attacker to access sensitive internal services from an external interface. These vulnerabilities are due to insufficient restrictions for IPv4 or IPv6 packets that are received on the external management interface. An attacker could exploit these vulnerabilities by sending specific traffic to this interface on an affected device. A successful exploit could allow the attacker to access sensitive internal services and make configuration changes on the affected device.

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-34g6-cvrg-j3q3

около 1 года назад

Improper access control in Media Controller prior to version 1.0.24.5282 allows local attacker to launch activities in MediaController's privilege.

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-34g5-7wwm-mgrr

больше 3 лет назад

The SSH implementation on D-Link Japan DES-3810 devices with firmware before R2.20.011 allows remote authenticated users to cause a denial of service (device hang) by leveraging login access.

EPSS: Низкий
github логотип

GHSA-34g5-52c8-jghg

больше 3 лет назад

Untrusted search path vulnerability in Hamster Free ZIP Archiver 2.0.1.7 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the current working directory.

EPSS: Низкий
github логотип

GHSA-34g4-wcj4-64vj

больше 3 лет назад

panel/login in Kirby v2.5.12 allows Host header injection via the "forget password" feature.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-34g4-3jrw-9qgp

почти 2 года назад

lunasvg v2.3.9 was discovered to contain an FPE (Floating Point Exception) at blend_transformed_tiled_argb.isra.0.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-34g3-9529-6r2w

17 дней назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in matiskiba Ravpage ravpage allows Reflected XSS.This issue affects Ravpage: from n/a through <= 2.33.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-34g2-p88j-292j

больше 3 лет назад

Directory traversal vulnerability in the Arcade Games (com_arcadegames) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

EPSS: Низкий
github логотип

GHSA-34g2-8x4r-2hc9

почти 4 года назад

Unspecified vulnerability in the Query Optimizer component of Oracle Database server 9.0.1.5, 9.2.0.7, and 10.1.0.5 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB19.

EPSS: Низкий
github логотип

GHSA-34fx-r4jh-7jxc

больше 3 лет назад

The pam_sm_close_session function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not properly handle a failure to determine a certain target uid, which might allow local users to delete unintended files by executing a program that relies on the pam_xauth PAM check.

EPSS: Низкий
github логотип

GHSA-34fw-v4pg-vc94

почти 4 года назад

Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to insufficient access control for standard JavaScript prototypes in other domains.

EPSS: Низкий
github логотип

GHSA-34fw-m7m3-5c57

больше 3 лет назад

EMC RSA BSAFE Crypto-J versions prior to 6.2.2 has a PKCS#12 Timing Attack Vulnerability. A possible timing attack could be carried out by modifying a PKCS#12 file that has an integrity MAC for which the password is not known. An attacker could then feed the modified PKCS#12 file to the toolkit and guess the current MAC one byte at a time. This is possible because Crypto-J uses a non-constant-time method to compare the stored MAC with the calculated MAC. This vulnerability is similar to the issue described in CVE-2015-2601.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-34fw-7qxm-rh77

около 1 года назад

Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-34fv-975p-jxfc

больше 3 лет назад

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Heap Overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-34fr-fhqr-7235

больше 4 лет назад

Information Disclosure in User Authentication

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-34fq-w3c7-7c97

больше 3 лет назад

Skia, as used in Google Chrome before 18.0.1025.151, does not properly perform clipping, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-34fq-m8qx-w3x4

больше 3 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to HotSpot. NOTE: the previous information was obtained from the February 2011 CPU. Oracle has not commented on claims from a downstream vendor that this issue is heap corruption related to the Verifier and "backward jsrs."

EPSS: Низкий
github логотип

GHSA-34fq-7fhg-4q58

больше 3 лет назад

Vulnerability in the Oracle Email Center product of Oracle E-Business Suite (component: Message Display). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Email Center. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Email Center, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Email Center accessible data as well as unauthorized update, insert or delete access to some of Oracle Email Center accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).

EPSS: Низкий
github логотип

GHSA-34fq-364c-3w2g

около 1 года назад

Open62541 v1.4.6 is has an assertion failure in fuzz_binary_decode, which leads to a crash.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-34g7-g5m3-mfmr

The slick-popup plugin before 1.7.2 for WordPress has a hardcoded OmakPass13# password for the slickpopupteam account, after a Subscriber calls a certain AJAX action.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-34g6-xv7x-r7fm

Multiple vulnerabilities in Cisco Intersight Virtual Appliance could allow an unauthenticated, adjacent attacker to access sensitive internal services from an external interface. These vulnerabilities are due to insufficient restrictions for IPv4 or IPv6 packets that are received on the external management interface. An attacker could exploit these vulnerabilities by sending specific traffic to this interface on an affected device. A successful exploit could allow the attacker to access sensitive internal services and make configuration changes on the affected device.

CVSS3: 8.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-34g6-cvrg-j3q3

Improper access control in Media Controller prior to version 1.0.24.5282 allows local attacker to launch activities in MediaController's privilege.

CVSS3: 5.1
0%
Низкий
около 1 года назад
github логотип
GHSA-34g5-7wwm-mgrr

The SSH implementation on D-Link Japan DES-3810 devices with firmware before R2.20.011 allows remote authenticated users to cause a denial of service (device hang) by leveraging login access.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-34g5-52c8-jghg

Untrusted search path vulnerability in Hamster Free ZIP Archiver 2.0.1.7 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the current working directory.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-34g4-wcj4-64vj

panel/login in Kirby v2.5.12 allows Host header injection via the "forget password" feature.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-34g4-3jrw-9qgp

lunasvg v2.3.9 was discovered to contain an FPE (Floating Point Exception) at blend_transformed_tiled_argb.isra.0.

CVSS3: 5.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-34g3-9529-6r2w

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in matiskiba Ravpage ravpage allows Reflected XSS.This issue affects Ravpage: from n/a through <= 2.33.

CVSS3: 7.1
0%
Низкий
17 дней назад
github логотип
GHSA-34g2-p88j-292j

Directory traversal vulnerability in the Arcade Games (com_arcadegames) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

5%
Низкий
больше 3 лет назад
github логотип
GHSA-34g2-8x4r-2hc9

Unspecified vulnerability in the Query Optimizer component of Oracle Database server 9.0.1.5, 9.2.0.7, and 10.1.0.5 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB19.

1%
Низкий
почти 4 года назад
github логотип
GHSA-34fx-r4jh-7jxc

The pam_sm_close_session function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not properly handle a failure to determine a certain target uid, which might allow local users to delete unintended files by executing a program that relies on the pam_xauth PAM check.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-34fw-v4pg-vc94

Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to insufficient access control for standard JavaScript prototypes in other domains.

1%
Низкий
почти 4 года назад
github логотип
GHSA-34fw-m7m3-5c57

EMC RSA BSAFE Crypto-J versions prior to 6.2.2 has a PKCS#12 Timing Attack Vulnerability. A possible timing attack could be carried out by modifying a PKCS#12 file that has an integrity MAC for which the password is not known. An attacker could then feed the modified PKCS#12 file to the toolkit and guess the current MAC one byte at a time. This is possible because Crypto-J uses a non-constant-time method to compare the stored MAC with the calculated MAC. This vulnerability is similar to the issue described in CVE-2015-2601.

CVSS3: 3.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-34fw-7qxm-rh77

Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
около 1 года назад
github логотип
GHSA-34fv-975p-jxfc

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Heap Overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

CVSS3: 9.8
24%
Средний
больше 3 лет назад
github логотип
GHSA-34fr-fhqr-7235

Information Disclosure in User Authentication

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
github логотип
GHSA-34fq-w3c7-7c97

Skia, as used in Google Chrome before 18.0.1025.151, does not properly perform clipping, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-34fq-m8qx-w3x4

Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to HotSpot. NOTE: the previous information was obtained from the February 2011 CPU. Oracle has not commented on claims from a downstream vendor that this issue is heap corruption related to the Verifier and "backward jsrs."

4%
Низкий
больше 3 лет назад
github логотип
GHSA-34fq-7fhg-4q58

Vulnerability in the Oracle Email Center product of Oracle E-Business Suite (component: Message Display). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Email Center. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Email Center, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Email Center accessible data as well as unauthorized update, insert or delete access to some of Oracle Email Center accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).

2%
Низкий
больше 3 лет назад
github логотип
GHSA-34fq-364c-3w2g

Open62541 v1.4.6 is has an assertion failure in fuzz_binary_decode, which leads to a crash.

CVSS3: 7.5
0%
Низкий
около 1 года назад

Уязвимостей на страницу