Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 315 253

Количество 315 253

github логотип

GHSA-296m-rvp8-vc89

больше 3 лет назад

Artica Web Proxy before 3.06.112911 allows remote attackers to execute arbitrary code as root by conducting a cross-site scripting (XSS) attack involving the username-form-id parameter to freeradius.users.php.

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-296m-g577-qvpq

больше 3 лет назад

Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.

EPSS: Низкий
github логотип

GHSA-296j-r9gr-7w2c

больше 1 года назад

Dell Dock Firmware and Dell Client Platform contain an Improper Link Resolution vulnerability during installation resulting in arbitrary folder deletion, which could lead to Privilege Escalation or Denial of Service.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-296j-2h87-8rxh

больше 3 лет назад

Visual Studio Code ESLint Extension Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-296j-266h-6jc4

больше 3 лет назад

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-296h-f7c6-qrvp

почти 4 года назад

Stack-based buffer overflow in Jasc Paint Shop Pro 8.10 (aka Corel Paint Shop Pro) allows user-assisted remote attackers to execute arbitrary code via a crafted PNG file. NOTE: this might be the same issue as CVE-2007-2366.

EPSS: Низкий
github логотип

GHSA-296g-m5cw-f8p9

больше 3 лет назад

A vulnerability in Cisco AMP for Endpoints Linux Connector Software and Cisco AMP for Endpoints Mac Connector Software could allow an authenticated, local attacker to cause a buffer overflow on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted packet to an affected device. A successful exploit could allow the attacker to cause the Cisco AMP for Endpoints service to crash and restart.

EPSS: Низкий
github логотип

GHSA-296f-j97f-9r25

больше 3 лет назад

IOHIDFamily in Apple OS X before 10.10 allows attackers to cause denial of service (out-of-bounds read operation) via a crafted application.

EPSS: Низкий
github логотип

GHSA-296f-cx2x-g274

12 месяцев назад

SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the userService API model.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-296f-9hr7-4mwq

около 1 года назад

Stored Cross-Site Scripting in the Access Request History in Omada Identity before version 15 update 1 allows an authenticated attacker to execute arbitrary code in the browser of a victim via a specially crafted link or by viewing a manipulated Access Request History

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-296f-4hq2-5r99

почти 4 года назад

Web authoring command in Microsoft Content Management Server (MCMS) 2001 allows attackers to authenticate and upload executable content, by modifying the upload location, aka "Program Execution via MCMS Authoring Function."

EPSS: Низкий
github логотип

GHSA-296c-8m99-q77p

больше 1 года назад

Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-2969-8hh9-57jc

около 4 лет назад

Allocation of Resources Without Limits or Throttling in ckb

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2969-2qqp-g57c

больше 3 лет назад

cPanel before 67.9999.103 allows code execution in the context of the mailman account because of incorrect environment-variable filtering (SEC-302).

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2968-xc5j-q436

больше 3 лет назад

The OC_Util::getUrlContent function in ownCloud Server before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 allows remote attackers to read arbitrary files via a file:// protocol.

EPSS: Низкий
github логотип

GHSA-2968-wv79-2wqf

4 месяца назад

HCL BigFix Mobile 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset of endpoint actions, potentially allowing access to select internal functions.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2968-fmvc-r6gw

почти 3 года назад

Signal Handler Race Condition vulnerability in Mitsubishi Electric India GC-ENET-COM whose first 2 digits of 11-digit serial number of unit are "16" allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition in Ethernet communication by sending a large number of specially crafted packets to any UDP port when GC-ENET-COM is configured as a Modbus TCP Server. The communication resumes only when the power of the main unit is turned off and on or when the GC-ENET-COM is hot-swapped from the main unit.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2968-6vjj-whq8

около 3 лет назад

Phicomm K2G v22.6.3.20 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade function.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2967-w8m2-xw7h

почти 4 года назад

PHP remote file inclusion vulnerability in class.cs_phpmailer.php in CS-Cart 1.3.3 allows remote attackers to execute arbitrary PHP code via a URL in the classes_dir parameter.

EPSS: Низкий
github логотип

GHSA-2966-gh5h-j633

почти 4 года назад

The session extension in PHP 4 before 4.4.5, and PHP 5 before 5.2.1, calculates the reference count for the session variables without considering the internal pointer from the session globals, which allows context-dependent attackers to execute arbitrary code via a crafted string in the session_register after unsetting HTTP_SESSION_VARS and _SESSION, which destroys the session data Hashtable.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-296m-rvp8-vc89

Artica Web Proxy before 3.06.112911 allows remote attackers to execute arbitrary code as root by conducting a cross-site scripting (XSS) attack involving the username-form-id parameter to freeradius.users.php.

CVSS3: 9
5%
Низкий
больше 3 лет назад
github логотип
GHSA-296m-g577-qvpq

Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-296j-r9gr-7w2c

Dell Dock Firmware and Dell Client Platform contain an Improper Link Resolution vulnerability during installation resulting in arbitrary folder deletion, which could lead to Privilege Escalation or Denial of Service.

CVSS3: 6.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-296j-2h87-8rxh

Visual Studio Code ESLint Extension Remote Code Execution Vulnerability

CVSS3: 7.8
12%
Средний
больше 3 лет назад
github логотип
GHSA-296j-266h-6jc4

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-296h-f7c6-qrvp

Stack-based buffer overflow in Jasc Paint Shop Pro 8.10 (aka Corel Paint Shop Pro) allows user-assisted remote attackers to execute arbitrary code via a crafted PNG file. NOTE: this might be the same issue as CVE-2007-2366.

8%
Низкий
почти 4 года назад
github логотип
GHSA-296g-m5cw-f8p9

A vulnerability in Cisco AMP for Endpoints Linux Connector Software and Cisco AMP for Endpoints Mac Connector Software could allow an authenticated, local attacker to cause a buffer overflow on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted packet to an affected device. A successful exploit could allow the attacker to cause the Cisco AMP for Endpoints service to crash and restart.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-296f-j97f-9r25

IOHIDFamily in Apple OS X before 10.10 allows attackers to cause denial of service (out-of-bounds read operation) via a crafted application.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-296f-cx2x-g274

SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the userService API model.

CVSS3: 9.1
0%
Низкий
12 месяцев назад
github логотип
GHSA-296f-9hr7-4mwq

Stored Cross-Site Scripting in the Access Request History in Omada Identity before version 15 update 1 allows an authenticated attacker to execute arbitrary code in the browser of a victim via a specially crafted link or by viewing a manipulated Access Request History

CVSS3: 8
0%
Низкий
около 1 года назад
github логотип
GHSA-296f-4hq2-5r99

Web authoring command in Microsoft Content Management Server (MCMS) 2001 allows attackers to authenticate and upload executable content, by modifying the upload location, aka "Program Execution via MCMS Authoring Function."

9%
Низкий
почти 4 года назад
github логотип
GHSA-296c-8m99-q77p

Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager.

CVSS3: 8.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-2969-8hh9-57jc

Allocation of Resources Without Limits or Throttling in ckb

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2969-2qqp-g57c

cPanel before 67.9999.103 allows code execution in the context of the mailman account because of incorrect environment-variable filtering (SEC-302).

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2968-xc5j-q436

The OC_Util::getUrlContent function in ownCloud Server before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 allows remote attackers to read arbitrary files via a file:// protocol.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-2968-wv79-2wqf

HCL BigFix Mobile 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset of endpoint actions, potentially allowing access to select internal functions.

CVSS3: 5.3
0%
Низкий
4 месяца назад
github логотип
GHSA-2968-fmvc-r6gw

Signal Handler Race Condition vulnerability in Mitsubishi Electric India GC-ENET-COM whose first 2 digits of 11-digit serial number of unit are "16" allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition in Ethernet communication by sending a large number of specially crafted packets to any UDP port when GC-ENET-COM is configured as a Modbus TCP Server. The communication resumes only when the power of the main unit is turned off and on or when the GC-ENET-COM is hot-swapped from the main unit.

CVSS3: 5.9
0%
Низкий
почти 3 года назад
github логотип
GHSA-2968-6vjj-whq8

Phicomm K2G v22.6.3.20 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade function.

CVSS3: 7.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-2967-w8m2-xw7h

PHP remote file inclusion vulnerability in class.cs_phpmailer.php in CS-Cart 1.3.3 allows remote attackers to execute arbitrary PHP code via a URL in the classes_dir parameter.

9%
Низкий
почти 4 года назад
github логотип
GHSA-2966-gh5h-j633

The session extension in PHP 4 before 4.4.5, and PHP 5 before 5.2.1, calculates the reference count for the session variables without considering the internal pointer from the session globals, which allows context-dependent attackers to execute arbitrary code via a crafted string in the session_register after unsetting HTTP_SESSION_VARS and _SESSION, which destroys the session data Hashtable.

4%
Низкий
почти 4 года назад

Уязвимостей на страницу