Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 458

Количество 314 458

github логотип

GHSA-2g3x-jgf5-xm96

больше 1 года назад

The swctrl service is used to detect and remotely manage PLANET Technology devices. Certain switch models have a Denial-of-Service vulnerability in the swctrl service, allowing unauthenticated remote attackers to send crafted packets that can crash the service.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2g3x-26wj-3wgm

больше 3 лет назад

Stack-based buffer overflow in the MailCheck821Address function in nnotes.dll in the nrouter.exe service in the server in IBM Lotus Domino 8.0.x before 8.0.2 FP5 and 8.5.x before 8.5.1 FP2 allows remote attackers to execute arbitrary code via a long e-mail address in an ORGANIZER:mailto header in an iCalendar calendar-invitation e-mail message, aka SPR NRBY7ZPJ9V.

EPSS: Высокий
github логотип

GHSA-2g3v-rq5j-m37f

4 месяца назад

Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-2g3v-5cpr-rx7q

почти 4 года назад

A potential vulnerability in LenovoVariable SMI Handler due to insufficient validation in some Lenovo Notebook models BIOS may allow an attacker with local access and elevated privileges to execute arbitrary code.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2g3q-pfmx-p47f

больше 3 лет назад

A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiSandbox before 3.0 may allow an attacker to execute unauthorized code or commands via the back_url parameter in the file scan component.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2g3q-f6jj-72f9

почти 4 года назад

MashZone NextGen through 10.7 GA allows a remote authenticated user, with access to the admin console, to upload a new JDBC driver that can execute arbitrary commands on the underlying host. This occurs in com.idsscheer.ppmmashup.business.jdbc.DriverUploadController.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2g3q-9hvf-4qgx

6 месяцев назад

An Information Exposure vulnerability has been identified in OpenText Enterprise Security Manager. The vulnerability could be remotely exploited.

EPSS: Низкий
github логотип

GHSA-2g3m-fq88-fm9q

почти 4 года назад

The Microsoft Java implementation, as used in Internet Explorer, can provide HTML object references to applets via Javascript, which allows remote attackers to cause a denial of service (crash due to illegal memory accesses) and possibly conduct other unauthorized activities via an applet that uses those references to access proprietary Microsoft methods.

EPSS: Низкий
github логотип

GHSA-2g3j-pp7m-869h

больше 3 лет назад

ELOG 3.1.4-57bea22 and below can be used as an HTTP GET request proxy when unauthenticated remote attackers send crafted HTTP POST requests.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2g3j-6hrf-vjp9

почти 4 года назад

Buffer overflow in A1 HTTP server 1.0a allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP request.

EPSS: Низкий
github логотип

GHSA-2g3h-rvgj-6gh5

почти 4 года назад

Buffer overflow in DHTRoutingTableDeserializer.cc in aria2 0.15.3, 1.2.0, and other versions allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.

EPSS: Низкий
github логотип

GHSA-2g3h-mh2w-wpjr

почти 3 года назад

In avdt_scb_hdl_pkt_no_frag of avdt_scb_act.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-225879503

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2g3g-vvgw-mw65

больше 2 лет назад

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function loginRegister.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2g3g-3px6-gf3h

больше 1 года назад

A cross-site scripting (XSS) vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a network. We have already fixed the vulnerability in the following version: Helpdesk 3.3.1 and later

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-2g3f-rmh8-cj3f

больше 1 года назад

phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/tools/request-ip/index.php.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2g3f-73vr-7c76

почти 2 года назад

Dell Grab for Windows, versions 5.0.4 and below, contains an improper file permissions vulnerability. A locally authenticated attacker could potentially exploit this vulnerability, leading to the information disclosure of certain system information.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2g3c-rmmx-7hq8

больше 3 лет назад

There is an invalid free in the Action::TaskFactory::cleanup function of actions.cpp in Exiv2 0.26. A crafted input will lead to a remote denial of service attack.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2g3c-qcgf-24jv

больше 3 лет назад

The WP Fusion Lite WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the startdate parameter found in the ~/includes/admin/logging/class-log-table-list.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.37.18.

EPSS: Низкий
github логотип

GHSA-2g3c-3p8m-g2p4

больше 3 лет назад

The escapeshellarg function in ext/standard/exec.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 on Windows allows remote attackers to execute arbitrary OS commands via a crafted string to an application that accepts command-line arguments for a call to the PHP system function.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2g39-vw48-vrxc

почти 4 года назад

PHP remote file inclusion vulnerability in configure.php in Vu Le An Virtual Path (VirtualPath) 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2g3x-jgf5-xm96

The swctrl service is used to detect and remotely manage PLANET Technology devices. Certain switch models have a Denial-of-Service vulnerability in the swctrl service, allowing unauthenticated remote attackers to send crafted packets that can crash the service.

CVSS3: 5.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-2g3x-26wj-3wgm

Stack-based buffer overflow in the MailCheck821Address function in nnotes.dll in the nrouter.exe service in the server in IBM Lotus Domino 8.0.x before 8.0.2 FP5 and 8.5.x before 8.5.1 FP2 allows remote attackers to execute arbitrary code via a long e-mail address in an ORGANIZER:mailto header in an iCalendar calendar-invitation e-mail message, aka SPR NRBY7ZPJ9V.

78%
Высокий
больше 3 лет назад
github логотип
GHSA-2g3v-rq5j-m37f

Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally.

CVSS3: 7
0%
Низкий
4 месяца назад
github логотип
GHSA-2g3v-5cpr-rx7q

A potential vulnerability in LenovoVariable SMI Handler due to insufficient validation in some Lenovo Notebook models BIOS may allow an attacker with local access and elevated privileges to execute arbitrary code.

CVSS3: 6.7
0%
Низкий
почти 4 года назад
github логотип
GHSA-2g3q-pfmx-p47f

A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiSandbox before 3.0 may allow an attacker to execute unauthorized code or commands via the back_url parameter in the file scan component.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2g3q-f6jj-72f9

MashZone NextGen through 10.7 GA allows a remote authenticated user, with access to the admin console, to upload a new JDBC driver that can execute arbitrary commands on the underlying host. This occurs in com.idsscheer.ppmmashup.business.jdbc.DriverUploadController.

CVSS3: 7.2
1%
Низкий
почти 4 года назад
github логотип
GHSA-2g3q-9hvf-4qgx

An Information Exposure vulnerability has been identified in OpenText Enterprise Security Manager. The vulnerability could be remotely exploited.

0%
Низкий
6 месяцев назад
github логотип
GHSA-2g3m-fq88-fm9q

The Microsoft Java implementation, as used in Internet Explorer, can provide HTML object references to applets via Javascript, which allows remote attackers to cause a denial of service (crash due to illegal memory accesses) and possibly conduct other unauthorized activities via an applet that uses those references to access proprietary Microsoft methods.

6%
Низкий
почти 4 года назад
github логотип
GHSA-2g3j-pp7m-869h

ELOG 3.1.4-57bea22 and below can be used as an HTTP GET request proxy when unauthenticated remote attackers send crafted HTTP POST requests.

CVSS3: 6.5
4%
Низкий
больше 3 лет назад
github логотип
GHSA-2g3j-6hrf-vjp9

Buffer overflow in A1 HTTP server 1.0a allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP request.

3%
Низкий
почти 4 года назад
github логотип
GHSA-2g3h-rvgj-6gh5

Buffer overflow in DHTRoutingTableDeserializer.cc in aria2 0.15.3, 1.2.0, and other versions allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.

3%
Низкий
почти 4 года назад
github логотип
GHSA-2g3h-mh2w-wpjr

In avdt_scb_hdl_pkt_no_frag of avdt_scb_act.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-225879503

CVSS3: 7.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-2g3g-vvgw-mw65

TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function loginRegister.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2g3g-3px6-gf3h

A cross-site scripting (XSS) vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a network. We have already fixed the vulnerability in the following version: Helpdesk 3.3.1 and later

CVSS3: 3.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-2g3f-rmh8-cj3f

phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/tools/request-ip/index.php.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2g3f-73vr-7c76

Dell Grab for Windows, versions 5.0.4 and below, contains an improper file permissions vulnerability. A locally authenticated attacker could potentially exploit this vulnerability, leading to the information disclosure of certain system information.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-2g3c-rmmx-7hq8

There is an invalid free in the Action::TaskFactory::cleanup function of actions.cpp in Exiv2 0.26. A crafted input will lead to a remote denial of service attack.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2g3c-qcgf-24jv

The WP Fusion Lite WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the startdate parameter found in the ~/includes/admin/logging/class-log-table-list.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.37.18.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2g3c-3p8m-g2p4

The escapeshellarg function in ext/standard/exec.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 on Windows allows remote attackers to execute arbitrary OS commands via a crafted string to an application that accepts command-line arguments for a call to the PHP system function.

CVSS3: 9.8
6%
Низкий
больше 3 лет назад
github логотип
GHSA-2g39-vw48-vrxc

PHP remote file inclusion vulnerability in configure.php in Vu Le An Virtual Path (VirtualPath) 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

6%
Низкий
почти 4 года назад

Уязвимостей на страницу