Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-346q-mxg8-55g2

почти 4 года назад

Multiple buffer overflows in the IMAP service (imapd32.exe) in Ipswitch IMail Server 2006 before 2006.21 allow remote authenticated users to execute arbitrary code via the (1) Search or (2) Search Charset command.

EPSS: Высокий
github логотип

GHSA-346q-mh4q-v382

почти 4 года назад

Static code injection vulnerability in the translation module (translator.php) in SiteBar 3.3.8 allows remote authenticated users to execute arbitrary PHP code via the value parameter.

EPSS: Низкий
github логотип

GHSA-346q-388w-74cv

почти 4 года назад

The DCOM client in Windows 2000 before SP3 does not properly clear memory before sending an "alter context" request, which may allow remote attackers to obtain sensitive information by sniffing the session.

EPSS: Средний
github логотип

GHSA-346p-qx4x-g348

больше 3 лет назад

Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's initial server response was invalid. The connection was not properly closed, and the code could continue attempting to authenticate. This could result in authentication credentials being exposed on an unencrypted connection, or to a machine-in-the-middle.

EPSS: Низкий
github логотип

GHSA-346p-9xff-4p8r

больше 3 лет назад

In addBouquet in js/bqe.js in OpenWebif (aka e2openplugin-OpenWebif) through 1.4.7, inserting JavaScript into the Add Bouquet feature of the Bouquet Editor (i.e., bouqueteditor/api/addbouquet?name=) leads to Stored XSS.

EPSS: Низкий
github логотип

GHSA-346m-8hrr-v52g

10 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TotalSuite TotalContest Lite allows Reflected XSS. This issue affects TotalContest Lite: from n/a through 2.8.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-346m-8227-pf2q

9 месяцев назад

A vulnerability classified as critical was found in Campcodes Online Food Ordering System 1.0. This vulnerability affects unknown code of the file /routers/ticket-status.php. The manipulation of the argument ticket_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-346m-7r2c-vvh9

13 дней назад

A vulnerability was detected in D-Link DIR-615 up to 4.10. This impacts an unknown function of the file /wiz_policy_3_machine.php of the component Web Management Interface. Performing a manipulation of the argument ipaddr results in os command injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-346m-4qgc-hqv8

7 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: genirq/irq_sim: Initialize work context pointers properly Initialize `ops` member's pointers properly by using kzalloc() instead of kmalloc() when allocating the simulation work context. Otherwise the pointers contain random content leading to invalid dereferencing.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-346m-4mc4-jr67

больше 3 лет назад

AdPlug 2.3.1 has multiple heap-based buffer overflows in CmtkLoader::load() in mtk.cpp.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-346j-xhw2-f9xw

больше 3 лет назад

JMS Client in IBM MessageSight 1.1.x through 1.1.0.1, 1.2.x through 1.2.0.3, and 2.0.x through 2.0.0.0 allows remote authenticated users to obtain administrator privileges for executing arbitrary commands via unspecified vectors.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-346j-jpcf-2285

больше 3 лет назад

The Lucent/Ascend file parser in Wireshark 1.2.x before 1.2.18, 1.4.x through 1.4.7, and 1.6.0 allows remote attackers to cause a denial of service (infinite loop) via malformed packets.

EPSS: Низкий
github логотип

GHSA-346j-g3cg-vw5q

больше 3 лет назад

Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, tvOS 14.0, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, watchOS 7.0, iOS 14.0 and iPadOS 14.0. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-346j-7cvj-x28v

почти 4 года назад

Unrestricted file upload vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to upload and execute arbitrary PHP files in uploads/ via an Uploads action.

EPSS: Низкий
github логотип

GHSA-346h-rrp2-cwwg

больше 3 лет назад

Cross-Site Request Forgery (CSRF) (aka Session Riding) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers to perform unauthorized tasks such as retrieving internal system information or manipulating the database via specially crafted URLs.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-346h-r83r-9vqj

больше 3 лет назад

The nsCSPHostSrc::permits function in dom/security/nsCSPUtils.cpp in Mozilla Firefox before 40.0 does not implement the Content Security Policy Level 2 exceptions for the blob, data, and filesystem URL schemes during wildcard source-expression matching, which might make it easier for remote attackers to conduct cross-site scripting (XSS) attacks by leveraging unexpected policy-enforcement behavior.

EPSS: Низкий
github логотип

GHSA-346h-749j-r28w

почти 2 года назад

PHPECC vulnerable to multiple cryptographic side-channel attacks

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-346g-pfrw-wm3v

почти 2 года назад

There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions <= 11.2 that may allow a remote, authenticated attacker to provide input that is not sanitized properly and is rendered in error messages. The are no privileges required to execute this attack.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-346g-jrx9-jgf4

больше 3 лет назад

Jenkins 360 FireLine Plugin vulnerable to XML External Entity Reference

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-346g-3xvj-229v

почти 4 года назад

ghostscript before 5.10-16 allows local users to overwrite files of other users via a symlink attack.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-346q-mxg8-55g2

Multiple buffer overflows in the IMAP service (imapd32.exe) in Ipswitch IMail Server 2006 before 2006.21 allow remote authenticated users to execute arbitrary code via the (1) Search or (2) Search Charset command.

90%
Высокий
почти 4 года назад
github логотип
GHSA-346q-mh4q-v382

Static code injection vulnerability in the translation module (translator.php) in SiteBar 3.3.8 allows remote authenticated users to execute arbitrary PHP code via the value parameter.

2%
Низкий
почти 4 года назад
github логотип
GHSA-346q-388w-74cv

The DCOM client in Windows 2000 before SP3 does not properly clear memory before sending an "alter context" request, which may allow remote attackers to obtain sensitive information by sniffing the session.

23%
Средний
почти 4 года назад
github логотип
GHSA-346p-qx4x-g348

Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's initial server response was invalid. The connection was not properly closed, and the code could continue attempting to authenticate. This could result in authentication credentials being exposed on an unencrypted connection, or to a machine-in-the-middle.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-346p-9xff-4p8r

In addBouquet in js/bqe.js in OpenWebif (aka e2openplugin-OpenWebif) through 1.4.7, inserting JavaScript into the Add Bouquet feature of the Bouquet Editor (i.e., bouqueteditor/api/addbouquet?name=) leads to Stored XSS.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-346m-8hrr-v52g

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TotalSuite TotalContest Lite allows Reflected XSS. This issue affects TotalContest Lite: from n/a through 2.8.1.

CVSS3: 7.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-346m-8227-pf2q

A vulnerability classified as critical was found in Campcodes Online Food Ordering System 1.0. This vulnerability affects unknown code of the file /routers/ticket-status.php. The manipulation of the argument ticket_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-346m-7r2c-vvh9

A vulnerability was detected in D-Link DIR-615 up to 4.10. This impacts an unknown function of the file /wiz_policy_3_machine.php of the component Web Management Interface. Performing a manipulation of the argument ipaddr results in os command injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 7.2
0%
Низкий
13 дней назад
github логотип
GHSA-346m-4qgc-hqv8

In the Linux kernel, the following vulnerability has been resolved: genirq/irq_sim: Initialize work context pointers properly Initialize `ops` member's pointers properly by using kzalloc() instead of kmalloc() when allocating the simulation work context. Otherwise the pointers contain random content leading to invalid dereferencing.

CVSS3: 5.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-346m-4mc4-jr67

AdPlug 2.3.1 has multiple heap-based buffer overflows in CmtkLoader::load() in mtk.cpp.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-346j-xhw2-f9xw

JMS Client in IBM MessageSight 1.1.x through 1.1.0.1, 1.2.x through 1.2.0.3, and 2.0.x through 2.0.0.0 allows remote authenticated users to obtain administrator privileges for executing arbitrary commands via unspecified vectors.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-346j-jpcf-2285

The Lucent/Ascend file parser in Wireshark 1.2.x before 1.2.18, 1.4.x through 1.4.7, and 1.6.0 allows remote attackers to cause a denial of service (infinite loop) via malformed packets.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-346j-g3cg-vw5q

Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, tvOS 14.0, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, watchOS 7.0, iOS 14.0 and iPadOS 14.0. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-346j-7cvj-x28v

Unrestricted file upload vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to upload and execute arbitrary PHP files in uploads/ via an Uploads action.

6%
Низкий
почти 4 года назад
github логотип
GHSA-346h-rrp2-cwwg

Cross-Site Request Forgery (CSRF) (aka Session Riding) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers to perform unauthorized tasks such as retrieving internal system information or manipulating the database via specially crafted URLs.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-346h-r83r-9vqj

The nsCSPHostSrc::permits function in dom/security/nsCSPUtils.cpp in Mozilla Firefox before 40.0 does not implement the Content Security Policy Level 2 exceptions for the blob, data, and filesystem URL schemes during wildcard source-expression matching, which might make it easier for remote attackers to conduct cross-site scripting (XSS) attacks by leveraging unexpected policy-enforcement behavior.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-346h-749j-r28w

PHPECC vulnerable to multiple cryptographic side-channel attacks

CVSS3: 9.1
почти 2 года назад
github логотип
GHSA-346g-pfrw-wm3v

There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions <= 11.2 that may allow a remote, authenticated attacker to provide input that is not sanitized properly and is rendered in error messages. The are no privileges required to execute this attack.

CVSS3: 7.2
0%
Низкий
почти 2 года назад
github логотип
GHSA-346g-jrx9-jgf4

Jenkins 360 FireLine Plugin vulnerable to XML External Entity Reference

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-346g-3xvj-229v

ghostscript before 5.10-16 allows local users to overwrite files of other users via a symlink attack.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу