Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2wph-5668-pjw8

больше 2 лет назад

Buffer overflow in CPCA Resource Download process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series firmware Ver.11.04 and earlier sold in Japan. Color imageCLASS LBP660C Series/LBP 620C Series/X LBP1127C/MF740C Series/MF640C Series/X MF1127C firmware Ver.11.04 and earlier sold in US. i-SENSYS LBP660C Series/LBP620C Series/MF740C Series/MF640C Series, C1127P, C1127iF, C1127i firmware Ver.11.04 and earlier sold in Europe.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2wph-4xpg-r884

около 2 лет назад

A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) (All versions < V19). An information disclosure vulnerability could allow a local attacker to gain access to the access level password of the SIMATIC S7-1200 and S7-1500 CPUs, when entered by a legitimate user in the hardware configuration of the affected application.

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-2wpc-xq3c-4c33

больше 3 лет назад

A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_revhistory ../../src/decode.c:3051.

EPSS: Низкий
github логотип

GHSA-2wpc-x967-v5qq

2 месяца назад

NMIS/BioDose software V22.02 and previous versions contain executable binaries with plain text hard-coded passwords. These hard-coded passwords could allow unauthorized access to both the application and database.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2wpc-c59v-c6xv

около 1 года назад

Substance3D - Modeler versions 1.14.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2wpc-7vw8-rm2x

больше 3 лет назад

Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 allows remote attackers to execute arbitrary code via vectors involving attachment of an XMLHttpRequest object to a dedicated worker.

EPSS: Низкий
github логотип

GHSA-2wpc-6fxg-xpcf

больше 1 года назад

Cross Site Scripting vulnerability in CodeAstro Membership Management System 1.0 allows attackers to run malicious JavaScript via the membership_type field in the edit-type.php component.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2wp8-f786-g8mx

4 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mithra62 WP-Click-Tracker wp-click-track allows Reflected XSS.This issue affects WP-Click-Tracker: from n/a through <= 0.7.3.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2wp8-8f56-4p9g

больше 3 лет назад

Cisco IOS XE 2.x before 2.4.3 and 2.5.x before 2.5.1 on ASR 1000 devices allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted series of fragmented (1) IPv4 or (2) IPv6 packets, aka Bug ID CSCtd72617.

EPSS: Низкий
github логотип

GHSA-2wp7-xr55-frhh

больше 3 лет назад

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-2wp7-73q4-52p8

почти 4 года назад

IBM QRadar 7.3, 7.4, and 7.5 could allow a malicious actor to impersonate an actor due to key exchange without entity authentication. IBM X-Force ID: 208756.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2wp7-476w-v7fh

больше 3 лет назад

Some Huawei home routers have an input validation vulnerability. Due to input parameter is not correctly verified, an attacker can exploit this vulnerability by sending special constructed packets to obtain files in the device and upload files to some directories.

EPSS: Низкий
github логотип

GHSA-2wp6-3qrw-p6q9

больше 3 лет назад

SQL injection vulnerability in modules/patient/mycare2x_pat_info.php in myCare2x allows remote attackers to execute arbitrary SQL commands via the lang parameter.

EPSS: Низкий
github логотип

GHSA-2wp5-cxv2-6684

около 3 лет назад

Dell PowerScale OneFS 8.2.x, 9.0.0.x - 9.4.0.x, contain an insufficient resource pool vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2wp5-2f53-g5f3

больше 3 лет назад

There is an Integer Overflow Vulnerability in Huawei Smartphone. Successful exploitation of these vulnerabilities may escalate the permission to that of the root user.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2wp4-vwq7-x2x6

больше 3 лет назад

A use after free issue has been identified in the way ISPSoft(v3.12 and prior) processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-2wp4-rcrr-hrvg

больше 3 лет назад

The wp-all-import plugin before 3.4.7 for WordPress has XSS.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2wp4-jvcq-g9p9

почти 4 года назад

Unspecified vulnerability in Wireshark 0.99.6 through 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted Tektronix .rf5 file.

EPSS: Низкий
github логотип

GHSA-2wp4-95hr-rx8x

больше 3 лет назад

Microsoft Office Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-31175, CVE-2021-31177, CVE-2021-31179.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2wp3-vrhh-pccj

больше 3 лет назад

Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) 15.7 before 15.7 SP50 or 15.7 SP100 allows remote attackers to cause a denial of service via unspecified vectors.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2wph-5668-pjw8

Buffer overflow in CPCA Resource Download process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series firmware Ver.11.04 and earlier sold in Japan. Color imageCLASS LBP660C Series/LBP 620C Series/X LBP1127C/MF740C Series/MF640C Series/X MF1127C firmware Ver.11.04 and earlier sold in US. i-SENSYS LBP660C Series/LBP620C Series/MF740C Series/MF640C Series, C1127P, C1127iF, C1127i firmware Ver.11.04 and earlier sold in Europe.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2wph-4xpg-r884

A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) (All versions < V19). An information disclosure vulnerability could allow a local attacker to gain access to the access level password of the SIMATIC S7-1200 and S7-1500 CPUs, when entered by a legitimate user in the hardware configuration of the affected application.

CVSS3: 4.2
0%
Низкий
около 2 лет назад
github логотип
GHSA-2wpc-xq3c-4c33

A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_revhistory ../../src/decode.c:3051.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2wpc-x967-v5qq

NMIS/BioDose software V22.02 and previous versions contain executable binaries with plain text hard-coded passwords. These hard-coded passwords could allow unauthorized access to both the application and database.

CVSS3: 7.3
0%
Низкий
2 месяца назад
github логотип
GHSA-2wpc-c59v-c6xv

Substance3D - Modeler versions 1.14.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-2wpc-7vw8-rm2x

Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 allows remote attackers to execute arbitrary code via vectors involving attachment of an XMLHttpRequest object to a dedicated worker.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-2wpc-6fxg-xpcf

Cross Site Scripting vulnerability in CodeAstro Membership Management System 1.0 allows attackers to run malicious JavaScript via the membership_type field in the edit-type.php component.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-2wp8-f786-g8mx

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mithra62 WP-Click-Tracker wp-click-track allows Reflected XSS.This issue affects WP-Click-Tracker: from n/a through <= 0.7.3.

CVSS3: 7.1
0%
Низкий
4 месяца назад
github логотип
GHSA-2wp8-8f56-4p9g

Cisco IOS XE 2.x before 2.4.3 and 2.5.x before 2.5.1 on ASR 1000 devices allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted series of fragmented (1) IPv4 or (2) IPv6 packets, aka Bug ID CSCtd72617.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2wp7-xr55-frhh

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

CVSS3: 8.8
16%
Средний
больше 3 лет назад
github логотип
GHSA-2wp7-73q4-52p8

IBM QRadar 7.3, 7.4, and 7.5 could allow a malicious actor to impersonate an actor due to key exchange without entity authentication. IBM X-Force ID: 208756.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-2wp7-476w-v7fh

Some Huawei home routers have an input validation vulnerability. Due to input parameter is not correctly verified, an attacker can exploit this vulnerability by sending special constructed packets to obtain files in the device and upload files to some directories.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2wp6-3qrw-p6q9

SQL injection vulnerability in modules/patient/mycare2x_pat_info.php in myCare2x allows remote attackers to execute arbitrary SQL commands via the lang parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2wp5-cxv2-6684

Dell PowerScale OneFS 8.2.x, 9.0.0.x - 9.4.0.x, contain an insufficient resource pool vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-2wp5-2f53-g5f3

There is an Integer Overflow Vulnerability in Huawei Smartphone. Successful exploitation of these vulnerabilities may escalate the permission to that of the root user.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2wp4-vwq7-x2x6

A use after free issue has been identified in the way ISPSoft(v3.12 and prior) processes project files, allowing an attacker to craft a special project file that may allow arbitrary code execution.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2wp4-rcrr-hrvg

The wp-all-import plugin before 3.4.7 for WordPress has XSS.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2wp4-jvcq-g9p9

Unspecified vulnerability in Wireshark 0.99.6 through 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted Tektronix .rf5 file.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2wp4-95hr-rx8x

Microsoft Office Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-31175, CVE-2021-31177, CVE-2021-31179.

CVSS3: 7.8
6%
Низкий
больше 3 лет назад
github логотип
GHSA-2wp3-vrhh-pccj

Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) 15.7 before 15.7 SP50 or 15.7 SP100 allows remote attackers to cause a denial of service via unspecified vectors.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу