Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-3242-g4f6-mjm3

почти 4 года назад

Oracle 10g Database Server stores the password for the SYSMAN account in cleartext in the world-readable emoms.properties file, which could allow local users to gain DBA privileges.

EPSS: Низкий
github логотип

GHSA-323x-wpgh-r8q4

больше 2 лет назад

A broken authentication mechanism in the endpoint excel.php of POS Codekop v2.0 allows unauthenticated attackers to download selling data.

CVSS3: 7.5
EPSS: Высокий
github логотип

GHSA-323x-vj5p-jwh3

5 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: jfs: upper bound check of tree index in dbAllocAG When computing the tree index in dbAllocAG, we never check if we are out of bounds realative to the size of the stree. This could happen in a scenario where the filesystem metadata are corrupted.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-323x-m6wx-9h98

больше 3 лет назад

Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect integrity via unknown vectors related to Solaris Management Console.

EPSS: Низкий
github логотип

GHSA-323w-xf3r-4754

больше 3 лет назад

Buffer overflow in phrelay in BlackBerry QNX Neutrino RTOS through 6.5.0 SP1 in the QNX Software Development Platform allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted packets to TCP port 4868 that leverage improper handling of the /dev/photon device file.

EPSS: Низкий
github логотип

GHSA-323w-vcff-w7mp

больше 3 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of script within a Keystroke action of a listbox field. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-9081.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-323w-6p85-26fr

11 месяцев назад

Duplicate Advisory: Plenti - Code Injection - Denial of Services

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-323v-h623-mm25

больше 3 лет назад

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Merge). Supported versions that are affected are 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.0 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-323v-6736-wj2p

больше 3 лет назад

Windows 10 Update Assistant Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-323q-hgv4-565g

больше 3 лет назад

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5. A remote attacker may be able to modify the file system.

EPSS: Низкий
github логотип

GHSA-323q-9369-p5wm

почти 4 года назад

PHP remote file inclusion vulnerability in genpage-cgi.php in Brian Fraval hitweb 4.2 and possibly earlier versions allows remote attackers to execute arbitrary PHP code via the REP_INC parameter.

EPSS: Средний
github логотип

GHSA-323q-3h7w-jpg8

около 3 лет назад

IBM CICS TX 11.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 229461.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-323p-wcmw-r7c5

больше 2 лет назад

Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list at /goform/SetNetControlList.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-323p-r9jj-62gh

больше 3 лет назад

Use-after-free vulnerability in the shmem_remount_fs function in mm/shmem.c in the Linux kernel before 3.7.10 allows local users to gain privileges or cause a denial of service (system crash) by remounting a tmpfs filesystem without specifying a required mpol (aka mempolicy) mount option.

EPSS: Низкий
github логотип

GHSA-323p-966c-ffpv

почти 4 года назад

Buffer overflow in the JavaScript engine in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, might allow remote attackers to execute arbitrary code via vectors involving exception timing and a large number of string values, aka an "atom map" issue.

EPSS: Низкий
github логотип

GHSA-323p-4v5q-w32p

почти 4 года назад

SQL injection vulnerability in the JBudgetsMagic (com_jbudgetsmagic) component 0.3.2 through 0.4.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the bid parameter in a mybudget action to index.php.

EPSS: Низкий
github логотип

GHSA-323p-2gfm-rcr4

почти 4 года назад

The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to cause a denial of service (crash) via an HTTP request without a Content-Length parameter.

EPSS: Низкий
github логотип

GHSA-323m-j8jx-g8pq

больше 2 лет назад

Ericsson Network Manager (ENM), versions prior to 22.2, contains a vulnerability in the REST endpoint “editprofile” where Open Redirect HTTP Header Injection can lead to redirection of the submitted request to domain out of control of ENM deployment. The attacker would need admin/elevated access to exploit the vulnerability

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-323m-cw2j-43x4

больше 3 лет назад

XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=file&targetObjId=fileFolder-2&targetObjIdChild=[XSS] attack.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-323h-xxg4-72gc

26 дней назад

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVSS3: 8.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3242-g4f6-mjm3

Oracle 10g Database Server stores the password for the SYSMAN account in cleartext in the world-readable emoms.properties file, which could allow local users to gain DBA privileges.

0%
Низкий
почти 4 года назад
github логотип
GHSA-323x-wpgh-r8q4

A broken authentication mechanism in the endpoint excel.php of POS Codekop v2.0 allows unauthenticated attackers to download selling data.

CVSS3: 7.5
83%
Высокий
больше 2 лет назад
github логотип
GHSA-323x-vj5p-jwh3

In the Linux kernel, the following vulnerability has been resolved: jfs: upper bound check of tree index in dbAllocAG When computing the tree index in dbAllocAG, we never check if we are out of bounds realative to the size of the stree. This could happen in a scenario where the filesystem metadata are corrupted.

CVSS3: 7.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-323x-m6wx-9h98

Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect integrity via unknown vectors related to Solaris Management Console.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-323w-xf3r-4754

Buffer overflow in phrelay in BlackBerry QNX Neutrino RTOS through 6.5.0 SP1 in the QNX Software Development Platform allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted packets to TCP port 4868 that leverage improper handling of the /dev/photon device file.

4%
Низкий
больше 3 лет назад
github логотип
GHSA-323w-vcff-w7mp

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of script within a Keystroke action of a listbox field. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-9081.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-323w-6p85-26fr

Duplicate Advisory: Plenti - Code Injection - Denial of Services

CVSS3: 6.5
11 месяцев назад
github логотип
GHSA-323v-h623-mm25

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Merge). Supported versions that are affected are 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.0 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-323v-6736-wj2p

Windows 10 Update Assistant Elevation of Privilege Vulnerability

CVSS3: 7.8
5%
Низкий
больше 3 лет назад
github логотип
GHSA-323q-hgv4-565g

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5. A remote attacker may be able to modify the file system.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-323q-9369-p5wm

PHP remote file inclusion vulnerability in genpage-cgi.php in Brian Fraval hitweb 4.2 and possibly earlier versions allows remote attackers to execute arbitrary PHP code via the REP_INC parameter.

13%
Средний
почти 4 года назад
github логотип
GHSA-323q-3h7w-jpg8

IBM CICS TX 11.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 229461.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-323p-wcmw-r7c5

Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list at /goform/SetNetControlList.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-323p-r9jj-62gh

Use-after-free vulnerability in the shmem_remount_fs function in mm/shmem.c in the Linux kernel before 3.7.10 allows local users to gain privileges or cause a denial of service (system crash) by remounting a tmpfs filesystem without specifying a required mpol (aka mempolicy) mount option.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-323p-966c-ffpv

Buffer overflow in the JavaScript engine in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, might allow remote attackers to execute arbitrary code via vectors involving exception timing and a large number of string values, aka an "atom map" issue.

9%
Низкий
почти 4 года назад
github логотип
GHSA-323p-4v5q-w32p

SQL injection vulnerability in the JBudgetsMagic (com_jbudgetsmagic) component 0.3.2 through 0.4.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the bid parameter in a mybudget action to index.php.

0%
Низкий
почти 4 года назад
github логотип
GHSA-323p-2gfm-rcr4

The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to cause a denial of service (crash) via an HTTP request without a Content-Length parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-323m-j8jx-g8pq

Ericsson Network Manager (ENM), versions prior to 22.2, contains a vulnerability in the REST endpoint “editprofile” where Open Redirect HTTP Header Injection can lead to redirection of the submitted request to domain out of control of ENM deployment. The attacker would need admin/elevated access to exploit the vulnerability

CVSS3: 4.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-323m-cw2j-43x4

XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=file&targetObjId=fileFolder-2&targetObjIdChild=[XSS] attack.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-323h-xxg4-72gc

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVSS3: 8.4
0%
Низкий
26 дней назад

Уязвимостей на страницу