Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 380

Количество 355 380

github логотип

GHSA-xrc3-9jj6-mqcm

больше 1 года назад

A Path Traversal Information Disclosure vulnerability exists in "Sante PACS Server.exe". An unauthenticated remote attacker can exploit it to download arbitrary files on the disk drive where the application is installed.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-xrc2-5gr8-655q

около 4 лет назад

GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to place malicious files within the installer file directory, which may allow an attacker to gain administrative privileges on a system during installation or upgrade.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xr9x-r78c-5hrm

8 дней назад

Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing

EPSS: Низкий
github логотип

GHSA-xr9x-fhcv-6qm7

больше 3 лет назад

In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300) before 3.6.2.0.795, Virtual SmartZone (vSZ) before 3.6.2.0.795, ZoneDirector 1100 9.10.2.0.130, ZoneDirector 1200 10.2.1.0.218, ZoneDirector 3000 10.2.1.0.218, ZoneDirector 5000 10.0.1.0.151, a vulnerability allows attackers to exploit the official image signature to force injection unauthorized image signature.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xr9w-x6gw-c9mj

больше 3 лет назад

Duplicate advisory: Deno vulnerable to Regular Expression Denial of Service

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xr9w-r8gw-wjhw

8 месяцев назад

IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 stores unencrypted sensitive information in environmental variables files which can be obtained by an authenticated user.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xr9r-hxj6-96p6

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: cifs: fix small mempool leak in SMB2_negotiate() In some cases of failure (dialect mismatches) in SMB2_negotiate(), after the request is sent, the checks would return -EIO when they should be rather setting rc = -EIO and jumping to neg_exit to free the response buffer from mempool.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xr9r-3v5q-97c3

около 4 лет назад

The play/modules component in Cisco WebEx Meetings Server allows remote attackers to obtain administrator access via crafted API requests, aka Bug ID CSCuj40421.

EPSS: Низкий
github логотип

GHSA-xr9q-qqh9-m7h3

больше 4 лет назад

The Java Message Service (JMS) in IBM WebSphere Application Server (WAS) before 6.1.0.7 allows attackers to cause a denial of service via unknown vectors involving the "double release [of] a bytebuffer input stream," possibly a double free vulnerability.

EPSS: Низкий
github логотип

GHSA-xr9q-p253-xqxh

около 4 лет назад

In smsSelected of AnswerFragment.java, there is a way to send an SMS from the lock screen due to a permissions bypass. This could lead to local escalation of privilege on the lock screen with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-137102479

EPSS: Низкий
github логотип

GHSA-xr9q-h9c7-xw8q

больше 1 года назад

Rancher allows an unauthenticated stack overflow in /v3-public/authproviders API

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-xr9q-85p6-f6xr

около 1 года назад

The Premium Age Verification / Restriction for WordPress plugin for WordPress is vulnerable to arbitrary file read and write due to the existence of an insufficiently protected remote support functionality in remote_tunnel.php in all versions up to, and including, 3.0.2. This makes it possible for unauthenticated attackers to read from or write to arbitrary files on the affected site's server which may make the exposure of sensitive information or remote code execution possible.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xr9p-wqhw-3w78

около 4 лет назад

Authenticated and encrypted payload MMEs can be forged and remotely sent to any HPAV2 system using a jailbreak key recoverable from code.

EPSS: Низкий
github логотип

GHSA-xr9p-qj4x-c6c7

больше 4 лет назад

The ICQ Webserver allows remote attackers to use .. to access arbitrary files outside of the user's personal directory.

EPSS: Низкий
github логотип

GHSA-xr9p-mfhc-2mwc

около 4 лет назад

Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality via unknown vectors related to Test Manager for Web Apps. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the DownloadServlet servlet, which allows remote attackers to read arbitrary files via directory traversal sequences in the scriptPath parameter.

EPSS: Средний
github логотип

GHSA-xr9m-34vg-p986

больше 4 лет назад

The Wipe Free Space utility in PGP Desktop Home 8.0 and Desktop Professional 9.0.3 Build 2932 and earlier does not clear file slack space in the last cluster for the file, which allows local users to access the previous contents of the disk.

EPSS: Низкий
github логотип

GHSA-xr9j-c7v6-7542

почти 3 года назад

A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe-oF/TCP subsystem in the Linux kernel. This issue may allow a malicious user to cause a use-after-free and double-free problem, which may permit remote code execution or lead to local privilege escalation in case that the attacker already has local privileges.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xr9j-92x7-g2w2

около 4 лет назад

In Afian Filerun 20220202, lack of sanitization of the POST parameter "metadata[]" in `/?module=fileman&section=get&page=grid` leads to SQL injection.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xr9j-2jxx-p2h8

6 месяцев назад

Integer Overflow or Wraparound vulnerability in Ralim IronOS.This issue affects IronOS: before v2.23-rc2.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xr9h-p2rc-rpqm

больше 3 лет назад

WWBN/AVideo stored XSS vulnerability leads to takeover of any user's account, including admin's account

CVSS3: 8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xrc3-9jj6-mqcm

A Path Traversal Information Disclosure vulnerability exists in "Sante PACS Server.exe". An unauthenticated remote attacker can exploit it to download arbitrary files on the disk drive where the application is installed.

CVSS3: 7.5
39%
Средний
больше 1 года назад
github логотип
GHSA-xrc2-5gr8-655q

GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to place malicious files within the installer file directory, which may allow an attacker to gain administrative privileges on a system during installation or upgrade.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-xr9x-r78c-5hrm

Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing

2%
Низкий
8 дней назад
github логотип
GHSA-xr9x-fhcv-6qm7

In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300) before 3.6.2.0.795, Virtual SmartZone (vSZ) before 3.6.2.0.795, ZoneDirector 1100 9.10.2.0.130, ZoneDirector 1200 10.2.1.0.218, ZoneDirector 3000 10.2.1.0.218, ZoneDirector 5000 10.0.1.0.151, a vulnerability allows attackers to exploit the official image signature to force injection unauthorized image signature.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xr9w-x6gw-c9mj

Duplicate advisory: Deno vulnerable to Regular Expression Denial of Service

CVSS3: 7.5
больше 3 лет назад
github логотип
GHSA-xr9w-r8gw-wjhw

IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 stores unencrypted sensitive information in environmental variables files which can be obtained by an authenticated user.

CVSS3: 6.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-xr9r-hxj6-96p6

In the Linux kernel, the following vulnerability has been resolved: cifs: fix small mempool leak in SMB2_negotiate() In some cases of failure (dialect mismatches) in SMB2_negotiate(), after the request is sent, the checks would return -EIO when they should be rather setting rc = -EIO and jumping to neg_exit to free the response buffer from mempool.

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-xr9r-3v5q-97c3

The play/modules component in Cisco WebEx Meetings Server allows remote attackers to obtain administrator access via crafted API requests, aka Bug ID CSCuj40421.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xr9q-qqh9-m7h3

The Java Message Service (JMS) in IBM WebSphere Application Server (WAS) before 6.1.0.7 allows attackers to cause a denial of service via unknown vectors involving the "double release [of] a bytebuffer input stream," possibly a double free vulnerability.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xr9q-p253-xqxh

In smsSelected of AnswerFragment.java, there is a way to send an SMS from the lock screen due to a permissions bypass. This could lead to local escalation of privilege on the lock screen with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-137102479

0%
Низкий
около 4 лет назад
github логотип
GHSA-xr9q-h9c7-xw8q

Rancher allows an unauthenticated stack overflow in /v3-public/authproviders API

CVSS3: 8.2
1%
Низкий
больше 1 года назад
github логотип
GHSA-xr9q-85p6-f6xr

The Premium Age Verification / Restriction for WordPress plugin for WordPress is vulnerable to arbitrary file read and write due to the existence of an insufficiently protected remote support functionality in remote_tunnel.php in all versions up to, and including, 3.0.2. This makes it possible for unauthenticated attackers to read from or write to arbitrary files on the affected site's server which may make the exposure of sensitive information or remote code execution possible.

CVSS3: 9.8
1%
Низкий
около 1 года назад
github логотип
GHSA-xr9p-wqhw-3w78

Authenticated and encrypted payload MMEs can be forged and remotely sent to any HPAV2 system using a jailbreak key recoverable from code.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xr9p-qj4x-c6c7

The ICQ Webserver allows remote attackers to use .. to access arbitrary files outside of the user's personal directory.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xr9p-mfhc-2mwc

Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality via unknown vectors related to Test Manager for Web Apps. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the DownloadServlet servlet, which allows remote attackers to read arbitrary files via directory traversal sequences in the scriptPath parameter.

22%
Средний
около 4 лет назад
github логотип
GHSA-xr9m-34vg-p986

The Wipe Free Space utility in PGP Desktop Home 8.0 and Desktop Professional 9.0.3 Build 2932 and earlier does not clear file slack space in the last cluster for the file, which allows local users to access the previous contents of the disk.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xr9j-c7v6-7542

A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe-oF/TCP subsystem in the Linux kernel. This issue may allow a malicious user to cause a use-after-free and double-free problem, which may permit remote code execution or lead to local privilege escalation in case that the attacker already has local privileges.

CVSS3: 8.8
9%
Низкий
почти 3 года назад
github логотип
GHSA-xr9j-92x7-g2w2

In Afian Filerun 20220202, lack of sanitization of the POST parameter "metadata[]" in `/?module=fileman&section=get&page=grid` leads to SQL injection.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xr9j-2jxx-p2h8

Integer Overflow or Wraparound vulnerability in Ralim IronOS.This issue affects IronOS: before v2.23-rc2.

CVSS3: 9.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-xr9h-p2rc-rpqm

WWBN/AVideo stored XSS vulnerability leads to takeover of any user's account, including admin's account

CVSS3: 8
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу