Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 301 694

Количество 301 694

github логотип

GHSA-28f5-mg2c-r34c

больше 3 лет назад

Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScript API execution via unspecified vectors, a different vulnerability than CVE-2015-3060, CVE-2015-3061, CVE-2015-3062, CVE-2015-3063, CVE-2015-3064, CVE-2015-3065, CVE-2015-3066, CVE-2015-3067, CVE-2015-3068, CVE-2015-3069, CVE-2015-3071, CVE-2015-3072, and CVE-2015-3074.

EPSS: Средний
github логотип

GHSA-28f5-7mw6-mfmc

больше 3 лет назад

In AccountManager, there is a possible bypass of a permissions check due to a confused deputy. This could lead to local information disclosure, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-123700107

EPSS: Низкий
github логотип

GHSA-28f5-7fwx-xrf3

больше 3 лет назад

When SWFTools 0.9.2 processes a crafted file in png2swf, it can lead to a Segmentation Violation in the png_load() function in lib/png.c.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-28f5-3rf2-gpm8

больше 3 лет назад

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.

EPSS: Низкий
github логотип

GHSA-28f4-mjfq-qrvf

около 5 лет назад

Malicious Package in buffes-xor

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-28f4-f5wq-36wr

больше 1 года назад

The WooCommerce POS plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 1.4.11. This is due to the plugin not properly verifying the authentication and authorization of the current user This makes it possible for authenticated attackers, with customer-level access and above, to view potentially sensitive information about other users by leveraging their order id

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-28f4-9qfp-6f7v

больше 3 лет назад

An issue was discovered in Xpdf 4.01.01. There is an FPE in the function ImageStream::ImageStream at Stream.cc for nBits.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-28f3-rf96-2vvg

почти 2 года назад

Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'txtPass' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-28f3-c95g-f4g3

больше 3 лет назад

In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the IxVeriWave file parser could crash. This was addressed in wiretap/vwr.c by correcting the signature timestamp bounds checks.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-28f2-gw74-5cpj

больше 3 лет назад

The setpermissions function in the auto-updater in Arq before 5.9.7 for Mac allows local users to gain root privileges via a symlink attack on the updater binary itself.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-28cx-j4v5-m5fv

около 1 года назад

Pluck CMS 4.7.18 does not restrict failed login attempts, allowing attackers to execute a brute force attack.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-28cx-hxv4-g5q7

больше 3 лет назад

Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/vehicles/manage_vehicle.php?id=.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-28cx-5f85-hrh4

больше 1 года назад

FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/edit/10.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-28cw-rx3r-6f3c

больше 3 лет назад

Palo Alto Networks Traps ESM Console before 3.4.4 allows attackers to cause a denial of service by leveraging improper validation of requests to revoke a Traps agent license.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-28cw-qr46-rx46

больше 3 лет назад

The php_zip_make_relative_path function in php_zip.c in PHP 5.2.x before 5.2.9 allows context-dependent attackers to cause a denial of service (crash) via a ZIP file that contains filenames with relative paths, which is not properly handled during extraction.

EPSS: Низкий
github логотип

GHSA-28cw-qjjv-g5g8

почти 3 года назад

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to a Log Injection attack by constructing URLs from user-controlled data. This could enable attackers to make arbitrary requests to the internal network or to the local file system. IBM X-Force ID: 240266.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-28cw-3j6f-3fv3

больше 3 лет назад

A vulnerability exists that could allow the execution of operating system commands on systems running MiPlatform 2019.05.16 and earlier. An attacker could execute arbitrary remote command by sending parameters to WinExec function in ExtCommandApi.dll module of MiPlatform.

EPSS: Низкий
github логотип

GHSA-28cv-g234-w9cx

больше 2 лет назад

A vulnerability has been identified in Polarion ALM (All versions < V2304.0). The application contains a XML External Entity Injection (XXE) vulnerability. This could allow an attacker to view files on the application server filesystem.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-28cv-7xwr-65c6

около 1 месяца назад

VitaraCharts 5.3.5 is vulnerable to Server-Side Request Forgery in fileLoader.jsp.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-28cv-45w7-c3g7

больше 1 года назад

Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-28f5-mg2c-r34c

Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScript API execution via unspecified vectors, a different vulnerability than CVE-2015-3060, CVE-2015-3061, CVE-2015-3062, CVE-2015-3063, CVE-2015-3064, CVE-2015-3065, CVE-2015-3066, CVE-2015-3067, CVE-2015-3068, CVE-2015-3069, CVE-2015-3071, CVE-2015-3072, and CVE-2015-3074.

31%
Средний
больше 3 лет назад
github логотип
GHSA-28f5-7mw6-mfmc

In AccountManager, there is a possible bypass of a permissions check due to a confused deputy. This could lead to local information disclosure, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-123700107

0%
Низкий
больше 3 лет назад
github логотип
GHSA-28f5-7fwx-xrf3

When SWFTools 0.9.2 processes a crafted file in png2swf, it can lead to a Segmentation Violation in the png_load() function in lib/png.c.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-28f5-3rf2-gpm8

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-28f4-mjfq-qrvf

Malicious Package in buffes-xor

CVSS3: 9.8
около 5 лет назад
github логотип
GHSA-28f4-f5wq-36wr

The WooCommerce POS plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 1.4.11. This is due to the plugin not properly verifying the authentication and authorization of the current user This makes it possible for authenticated attackers, with customer-level access and above, to view potentially sensitive information about other users by leveraging their order id

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-28f4-9qfp-6f7v

An issue was discovered in Xpdf 4.01.01. There is an FPE in the function ImageStream::ImageStream at Stream.cc for nBits.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-28f3-rf96-2vvg

Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'txtPass' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
почти 2 года назад
github логотип
GHSA-28f3-c95g-f4g3

In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the IxVeriWave file parser could crash. This was addressed in wiretap/vwr.c by correcting the signature timestamp bounds checks.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-28f2-gw74-5cpj

The setpermissions function in the auto-updater in Arq before 5.9.7 for Mac allows local users to gain root privileges via a symlink attack on the updater binary itself.

CVSS3: 7.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-28cx-j4v5-m5fv

Pluck CMS 4.7.18 does not restrict failed login attempts, allowing attackers to execute a brute force attack.

CVSS3: 9.8
0%
Низкий
около 1 года назад
github логотип
GHSA-28cx-hxv4-g5q7

Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/vehicles/manage_vehicle.php?id=.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-28cx-5f85-hrh4

FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/edit/10.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-28cw-rx3r-6f3c

Palo Alto Networks Traps ESM Console before 3.4.4 allows attackers to cause a denial of service by leveraging improper validation of requests to revoke a Traps agent license.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-28cw-qr46-rx46

The php_zip_make_relative_path function in php_zip.c in PHP 5.2.x before 5.2.9 allows context-dependent attackers to cause a denial of service (crash) via a ZIP file that contains filenames with relative paths, which is not properly handled during extraction.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-28cw-qjjv-g5g8

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to a Log Injection attack by constructing URLs from user-controlled data. This could enable attackers to make arbitrary requests to the internal network or to the local file system. IBM X-Force ID: 240266.

CVSS3: 7.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-28cw-3j6f-3fv3

A vulnerability exists that could allow the execution of operating system commands on systems running MiPlatform 2019.05.16 and earlier. An attacker could execute arbitrary remote command by sending parameters to WinExec function in ExtCommandApi.dll module of MiPlatform.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-28cv-g234-w9cx

A vulnerability has been identified in Polarion ALM (All versions < V2304.0). The application contains a XML External Entity Injection (XXE) vulnerability. This could allow an attacker to view files on the application server filesystem.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-28cv-7xwr-65c6

VitaraCharts 5.3.5 is vulnerable to Server-Side Request Forgery in fileLoader.jsp.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-28cv-45w7-c3g7

Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

CVSS3: 8.8
1%
Низкий
больше 1 года назад

Уязвимостей на страницу