Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-2p25-c5jm-68vm

около 3 лет назад

In MISP 2.4.167, app/Controller/Component/ACLComponent.php has incorrect access control for the decaying import function.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2p25-8rrm-x7f7

больше 3 лет назад

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3 and iPadOS 13.3, watchOS 6.1.1, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, tvOS 13.3. An application may be able to execute arbitrary code with kernel privileges.

EPSS: Низкий
github логотип

GHSA-2p25-55c9-h58q

около 4 лет назад

Overflow/crash in `tf.tile` when tiling tensor is large

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2p24-r54g-2p7g

почти 4 года назад

SQL injection vulnerability in comment.php in PHP Knowledge Base (PHPKB) 1.5 and 2.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.

EPSS: Низкий
github логотип

GHSA-2p24-q7p2-7pg5

больше 3 лет назад

A new account can be inserted into simContacts service using Android command line tool in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in MDM9206, MDM9607, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SD 845.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2p24-ppfc-qr69

больше 3 лет назад

MIRACASE MHUB500 USB splitters through 2021-08-09, in certain specific use cases in which the device supplies power to audio-output equipment, allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a "Glowworm" attack. We assume that the USB splitter supplies power to some speakers. The power indicator LED of the USB splitter is connected directly to the power line, as a result, the intensity of the USB splitter's power indicator LED is correlative to its power consumption. The sound played by the connected speakers affects the USB splitter's power consumption and as a result is also correlative to the light intensity of the LED. By analyzing measurements obtained from an electro-optical sensor directed at the power indicator LED of the USB splitter, we can recover the sound played by the connected speakers.

EPSS: Низкий
github логотип

GHSA-2p24-c5hx-j864

больше 3 лет назад

The CFNetwork HTTPProtocol component in Apple iOS before 9 allows remote attackers to bypass the HSTS protection mechanism, and consequently obtain sensitive information, via a crafted URL.

EPSS: Низкий
github логотип

GHSA-2p22-jp73-7gf2

больше 3 лет назад

Buffer Overflow in Tenda G1 and G3 routers with firmware version V15.11.0.17(9502)_CN allows remote attackers to execute arbitrary code via a crafted action/"IPMacBindIndex "request. This occurs because the "formIPMacBindDel" function directly passes the parameter "IPMacBindIndex" to strcpy without limit.

EPSS: Низкий
github логотип

GHSA-2mxv-g6h6-532m

почти 4 года назад

NTRtScan.exe in Trend Micro OfficeScan Client 8.0 SP1 and 8.0 SP1 Patch 1 allows local users to cause a denial of service (application crash) via directories with long pathnames. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-2mxv-c4j5-3h58

почти 4 года назад

iCal before 1.5.4 on Mac OS X 10.2.3, and other later versions, does not alert the user when handling calendars that use alarms, which allows attackers to execute programs and send e-mail via alarms.

EPSS: Низкий
github логотип

GHSA-2mxv-7pp5-pw9f

больше 3 лет назад

CFNetwork in Apple Mac OS X before 10.9 does not properly support Safari's deletion of session cookies in response to a reset operation, which makes it easier for remote web servers to track users via Set-Cookie HTTP headers.

EPSS: Низкий
github логотип

GHSA-2mxr-rc97-xrj2

2 месяца назад

Robocode has an insecure temporary file creation vulnerability in the AutoExtract component

EPSS: Низкий
github логотип

GHSA-2mxr-89gf-rc4v

почти 6 лет назад

Read permissions not enforced for client provided filter expressions in Elide.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-2mxq-q8p2-g2c8

больше 2 лет назад

The SALESmanago plugin for WordPress is vulnerable to Log Injection in versions up to, and including, 3.2.4. This is due to the use of a weak authentication token for the /wp-json/salesmanago/v1/callbackApiV3 API endpoint which is simply a SHA1 hash of the site URL and client ID found in the page source of the website. This makes it possible for unauthenticated attackers to inject arbitrary content into the log files, and when combined with another vulnerability this could have significant consequences.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2mxq-9vvh-j4jv

около 1 года назад

Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2mxp-xv42-39jh

больше 3 лет назад

The MeiPai (aka com.meitu.meipaimv) application 1.2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-2mxp-83cx-hqmp

больше 3 лет назад

The SCP and SFTP modules in Cisco IOS XR 5.0.0 through 5.2.5 on Network Convergence System 6000 devices use weak permissions for system files, which allows remote authenticated users to cause a denial of service (overwrite) via unspecified vectors, aka Bug ID CSCuw75848.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2mxm-mhxp-766x

больше 3 лет назад

Adobe Experience Manager versions 6.5, 6.4 and 6.3 have a cross site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2mxm-4g25-p6w9

почти 4 года назад

Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Talent Acquisition Management.

EPSS: Низкий
github логотип

GHSA-2mxm-3cxj-6cmp

11 месяцев назад

Insufficiently Protected Credentials vulnerability in OpenText Identity Manager Advanced Edition on Windows, Linux, 64 bit allows Privilege Abuse. This vulnerability could allow an authenticated user to obtain higher privileged user’s sensitive information via crafted payload. This issue affects Identity Manager Advanced Edition: from 4.8.0.0 through 4.8.7.0102, 4.9.0.0.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2p25-c5jm-68vm

In MISP 2.4.167, app/Controller/Component/ACLComponent.php has incorrect access control for the decaying import function.

CVSS3: 9.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-2p25-8rrm-x7f7

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3 and iPadOS 13.3, watchOS 6.1.1, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, tvOS 13.3. An application may be able to execute arbitrary code with kernel privileges.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2p25-55c9-h58q

Overflow/crash in `tf.tile` when tiling tensor is large

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-2p24-r54g-2p7g

SQL injection vulnerability in comment.php in PHP Knowledge Base (PHPKB) 1.5 and 2.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.

1%
Низкий
почти 4 года назад
github логотип
GHSA-2p24-q7p2-7pg5

A new account can be inserted into simContacts service using Android command line tool in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in MDM9206, MDM9607, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SD 845.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2p24-ppfc-qr69

MIRACASE MHUB500 USB splitters through 2021-08-09, in certain specific use cases in which the device supplies power to audio-output equipment, allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a "Glowworm" attack. We assume that the USB splitter supplies power to some speakers. The power indicator LED of the USB splitter is connected directly to the power line, as a result, the intensity of the USB splitter's power indicator LED is correlative to its power consumption. The sound played by the connected speakers affects the USB splitter's power consumption and as a result is also correlative to the light intensity of the LED. By analyzing measurements obtained from an electro-optical sensor directed at the power indicator LED of the USB splitter, we can recover the sound played by the connected speakers.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2p24-c5hx-j864

The CFNetwork HTTPProtocol component in Apple iOS before 9 allows remote attackers to bypass the HSTS protection mechanism, and consequently obtain sensitive information, via a crafted URL.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2p22-jp73-7gf2

Buffer Overflow in Tenda G1 and G3 routers with firmware version V15.11.0.17(9502)_CN allows remote attackers to execute arbitrary code via a crafted action/"IPMacBindIndex "request. This occurs because the "formIPMacBindDel" function directly passes the parameter "IPMacBindIndex" to strcpy without limit.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-2mxv-g6h6-532m

NTRtScan.exe in Trend Micro OfficeScan Client 8.0 SP1 and 8.0 SP1 Patch 1 allows local users to cause a denial of service (application crash) via directories with long pathnames. NOTE: some of these details are obtained from third party information.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2mxv-c4j5-3h58

iCal before 1.5.4 on Mac OS X 10.2.3, and other later versions, does not alert the user when handling calendars that use alarms, which allows attackers to execute programs and send e-mail via alarms.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2mxv-7pp5-pw9f

CFNetwork in Apple Mac OS X before 10.9 does not properly support Safari's deletion of session cookies in response to a reset operation, which makes it easier for remote web servers to track users via Set-Cookie HTTP headers.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2mxr-rc97-xrj2

Robocode has an insecure temporary file creation vulnerability in the AutoExtract component

0%
Низкий
2 месяца назад
github логотип
GHSA-2mxr-89gf-rc4v

Read permissions not enforced for client provided filter expressions in Elide.

CVSS3: 6.8
0%
Низкий
почти 6 лет назад
github логотип
GHSA-2mxq-q8p2-g2c8

The SALESmanago plugin for WordPress is vulnerable to Log Injection in versions up to, and including, 3.2.4. This is due to the use of a weak authentication token for the /wp-json/salesmanago/v1/callbackApiV3 API endpoint which is simply a SHA1 hash of the site URL and client ID found in the page source of the website. This makes it possible for unauthenticated attackers to inject arbitrary content into the log files, and when combined with another vulnerability this could have significant consequences.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2mxq-9vvh-j4jv

Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function.

CVSS3: 6.3
1%
Низкий
около 1 года назад
github логотип
GHSA-2mxp-xv42-39jh

The MeiPai (aka com.meitu.meipaimv) application 1.2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2mxp-83cx-hqmp

The SCP and SFTP modules in Cisco IOS XR 5.0.0 through 5.2.5 on Network Convergence System 6000 devices use weak permissions for system files, which allows remote authenticated users to cause a denial of service (overwrite) via unspecified vectors, aka Bug ID CSCuw75848.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2mxm-mhxp-766x

Adobe Experience Manager versions 6.5, 6.4 and 6.3 have a cross site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.

CVSS3: 6.1
2%
Низкий
больше 3 лет назад
github логотип
GHSA-2mxm-4g25-p6w9

Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Talent Acquisition Management.

0%
Низкий
почти 4 года назад
github логотип
GHSA-2mxm-3cxj-6cmp

Insufficiently Protected Credentials vulnerability in OpenText Identity Manager Advanced Edition on Windows, Linux, 64 bit allows Privilege Abuse. This vulnerability could allow an authenticated user to obtain higher privileged user’s sensitive information via crafted payload. This issue affects Identity Manager Advanced Edition: from 4.8.0.0 through 4.8.7.0102, 4.9.0.0.

0%
Низкий
11 месяцев назад

Уязвимостей на страницу