Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 380

Количество 355 380

github логотип

GHSA-xrcr-w67r-mpp3

около 4 лет назад

writtercontrol in cdcontrol 1.90 allows local users to overwrite arbitrary files via a symlink attack on /tmp/v-recorder*-out temporary files.

EPSS: Низкий
github логотип

GHSA-xrcr-vp89-pv9v

почти 2 года назад

In Dell Secure Connect Gateway Application and Secure Connect Gateway Appliance (between v5.10.00.00 and v5.18.00.00), a security concern has been identified, where a malicious user with a valid User session may inject malicious content in filters of IP Range Rest API. This issue may potentially lead to unintentional information disclosure from the product database.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xrcr-v699-vfjr

около 4 лет назад

Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to delete the common_member_wechatmp data structure via an ac=unbindmp request to plugin.php.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xrcr-j9jp-xv96

около 4 лет назад

fetchmail 5.9.9 through 6.3.19 does not properly limit the wait time after issuing a (1) STARTTLS or (2) STLS request, which allows remote servers to cause a denial of service (application hang) by acknowledging the request but not sending additional packets.

EPSS: Низкий
github логотип

GHSA-xrcr-gmf5-2r8j

5 месяцев назад

Gogs: Stored XSS via data URI in issue comments

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-xrcq-mfw4-37wc

больше 4 лет назад

Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not restrict registration of the "wpad" hostname, which allows remote authenticated users to hijack the Web Proxy Auto-Discovery (WPAD) feature, and conduct man-in-the-middle attacks by spoofing a proxy server, via a Dynamic Update request for this hostname, aka "DNS Server Vulnerability in WPAD Registration Vulnerability," a related issue to CVE-2007-1692.

EPSS: Средний
github логотип

GHSA-xrcq-533q-8rxw

11 месяцев назад

TYPO3 Bookmark Toolbar vulnerable to denial of service

EPSS: Низкий
github логотип

GHSA-xrcm-jr5x-65vm

больше 2 лет назад

A maliciously crafted PRT file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xrcm-f723-98ww

больше 4 лет назад

CRLF injection vulnerability in down.asp for Snitz Forums 2000 3.4.04 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the location parameter.

EPSS: Низкий
github логотип

GHSA-xrcm-f288-wxqh

3 месяца назад

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

EPSS: Низкий
github логотип

GHSA-xrcm-65v6-9p73

почти 3 года назад

A command execution vulnerability exists in the validate.so diag_ping_start functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xrcm-374r-cvgh

около 4 лет назад

In Message and toBundle of Notification.java, there is a possible UI slowdown or crash due to improper input validation. This could lead to remote denial of service if a malicious contact file is received, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.0 Android-8.1 Android-9Android ID: A-147358092

EPSS: Низкий
github логотип

GHSA-xrcj-j2px-vg49

больше 4 лет назад

layout/base/nsCSSFrameConstructor.cpp in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 does not properly handle first-letter frames, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.

EPSS: Средний
github логотип

GHSA-xrcj-fc8v-w45w

больше 4 лет назад

Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to execute arbitrary script in other domains via a setter function for a variable in the target domain, which is executed when the user visits that domain, aka "Cross-site scripting through global scope pollution."

EPSS: Низкий
github логотип

GHSA-xrcj-6jgv-j54v

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Giannopoulos Kostas WPsoonOnlinePage.This issue affects WPsoonOnlinePage: from n/a through 1.9.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xrcj-4qfw-rxvm

почти 2 года назад

Improper access control for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via local access..

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xrch-m74q-rcf4

около 2 лет назад

The parameter used in the certain page of ASUS Download Master is not properly filtered for user input. A remote attacker with administrative privilege can insert JavaScript code to the parameter for Stored Cross-site scripting attacks.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xrch-89q4-fgm4

около 4 лет назад

Improper casting of structure while handling the buffer leads to out of bound read in display in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9650, MSM8909W, MSM8996AU, QCS405, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20

EPSS: Низкий
github логотип

GHSA-xrcg-wf6c-6jc9

около 4 лет назад

The NTP implementation in Cisco IOS and IOS XE does not properly support use of the access-group command for a "deny all" configuration, which allows remote attackers to bypass intended restrictions on time synchronization via a standard query, aka Bug ID CSCuj66318.

EPSS: Низкий
github логотип

GHSA-xrcg-gh3c-46m5

больше 4 лет назад

Buffer overflow in PlanetDNS PlanetWeb 1.14 and earlier allows remote attackers to execute arbitrary code via (1) an HTTP GET request with a long URL or (2) a request with a long method name.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xrcr-w67r-mpp3

writtercontrol in cdcontrol 1.90 allows local users to overwrite arbitrary files via a symlink attack on /tmp/v-recorder*-out temporary files.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xrcr-vp89-pv9v

In Dell Secure Connect Gateway Application and Secure Connect Gateway Appliance (between v5.10.00.00 and v5.18.00.00), a security concern has been identified, where a malicious user with a valid User session may inject malicious content in filters of IP Range Rest API. This issue may potentially lead to unintentional information disclosure from the product database.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-xrcr-v699-vfjr

Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to delete the common_member_wechatmp data structure via an ac=unbindmp request to plugin.php.

CVSS3: 5.9
1%
Низкий
около 4 лет назад
github логотип
GHSA-xrcr-j9jp-xv96

fetchmail 5.9.9 through 6.3.19 does not properly limit the wait time after issuing a (1) STARTTLS or (2) STLS request, which allows remote servers to cause a denial of service (application hang) by acknowledging the request but not sending additional packets.

3%
Низкий
около 4 лет назад
github логотип
GHSA-xrcr-gmf5-2r8j

Gogs: Stored XSS via data URI in issue comments

CVSS3: 8.7
0%
Низкий
5 месяцев назад
github логотип
GHSA-xrcq-mfw4-37wc

Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not restrict registration of the "wpad" hostname, which allows remote authenticated users to hijack the Web Proxy Auto-Discovery (WPAD) feature, and conduct man-in-the-middle attacks by spoofing a proxy server, via a Dynamic Update request for this hostname, aka "DNS Server Vulnerability in WPAD Registration Vulnerability," a related issue to CVE-2007-1692.

17%
Средний
больше 4 лет назад
github логотип
GHSA-xrcq-533q-8rxw

TYPO3 Bookmark Toolbar vulnerable to denial of service

0%
Низкий
11 месяцев назад
github логотип
GHSA-xrcm-jr5x-65vm

A maliciously crafted PRT file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xrcm-f723-98ww

CRLF injection vulnerability in down.asp for Snitz Forums 2000 3.4.04 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the location parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xrcm-f288-wxqh

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

3 месяца назад
github логотип
GHSA-xrcm-65v6-9p73

A command execution vulnerability exists in the validate.so diag_ping_start functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability.

CVSS3: 8.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-xrcm-374r-cvgh

In Message and toBundle of Notification.java, there is a possible UI slowdown or crash due to improper input validation. This could lead to remote denial of service if a malicious contact file is received, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.0 Android-8.1 Android-9Android ID: A-147358092

1%
Низкий
около 4 лет назад
github логотип
GHSA-xrcj-j2px-vg49

layout/base/nsCSSFrameConstructor.cpp in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 does not properly handle first-letter frames, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.

11%
Средний
больше 4 лет назад
github логотип
GHSA-xrcj-fc8v-w45w

Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to execute arbitrary script in other domains via a setter function for a variable in the target domain, which is executed when the user visits that domain, aka "Cross-site scripting through global scope pollution."

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xrcj-6jgv-j54v

Cross-Site Request Forgery (CSRF) vulnerability in Giannopoulos Kostas WPsoonOnlinePage.This issue affects WPsoonOnlinePage: from n/a through 1.9.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xrcj-4qfw-rxvm

Improper access control for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via local access..

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-xrch-m74q-rcf4

The parameter used in the certain page of ASUS Download Master is not properly filtered for user input. A remote attacker with administrative privilege can insert JavaScript code to the parameter for Stored Cross-site scripting attacks.

CVSS3: 4.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-xrch-89q4-fgm4

Improper casting of structure while handling the buffer leads to out of bound read in display in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9650, MSM8909W, MSM8996AU, QCS405, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20

0%
Низкий
около 4 лет назад
github логотип
GHSA-xrcg-wf6c-6jc9

The NTP implementation in Cisco IOS and IOS XE does not properly support use of the access-group command for a "deny all" configuration, which allows remote attackers to bypass intended restrictions on time synchronization via a standard query, aka Bug ID CSCuj66318.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xrcg-gh3c-46m5

Buffer overflow in PlanetDNS PlanetWeb 1.14 and earlier allows remote attackers to execute arbitrary code via (1) an HTTP GET request with a long URL or (2) a request with a long method name.

11%
Средний
больше 4 лет назад

Уязвимостей на страницу