Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 377 914

Количество 377 914

github логотип

GHSA-52w9-4w5g-hqxc

больше 4 лет назад

The IBM i 7.1, 7.2, 7.3, and 7.4 Extended Dynamic Remote SQL server (EDRSQL) could allow a remote authenticated user to send a specially crafted request and cause a denial of service. IBM X-Force ID: 214537.

EPSS: Низкий
github логотип

GHSA-52w8-9f8q-6r2v

больше 3 лет назад

In append_camera_metadata of camera_metadata.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-236688120References: N/A

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-52w5-q3hg-34x8

7 месяцев назад

A vulnerability was detected in code-projects Simple Flight Ticket Booking System 1.0. Affected is an unknown function of the file /Adminupdate.php. The manipulation of the argument flightno/airplaneid/departure/dtime/arrival/atime/ec/ep/bc/bp results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-52w5-6rqq-mwq5

больше 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. A group owner may be able to bypass External Authorization check, if it is enabled, to access git repositories and package registries by using Deploy tokens or Deploy keys .

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-52w5-48fj-c3qf

больше 2 лет назад

A vulnerability was found in code-projects E-Commerce Website 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file user_signup.php. The manipulation of the argument firstname/middlename/email/address/contact/username leads to sql injection. The attack may be launched remotely. VDB-249002 is the identifier assigned to this vulnerability.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-52w3-gj28-xfx3

больше 4 лет назад

procfs in FreeBSD and possibly other operating systems allows local users to bypass access control restrictions for a jail environment and gain additional privileges.

EPSS: Низкий
github логотип

GHSA-52w2-9c5h-2xqj

больше 4 лет назад

Heap-based Buffer Overflow in the psf_binheader_writef function in common.c in libsndfile through 1.0.28 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-52vw-wff4-8w2j

больше 4 лет назад

LibreOffice documents can contain macros. The execution of those macros is controlled by the document security settings, typically execution of macros are blocked by default. A URL decoding flaw existed in how the urls to the macros within the document were processed and categorized, resulting in the possibility to construct a document where macro execution bypassed the security settings. The documents were correctly detected as containing macros, and prompted the user to their existence within the documents, but macros within the document were subsequently not controlled by the security settings allowing arbitrary macro execution This issue affects: LibreOffice 6.2 series versions prior to 6.2.7; LibreOffice 6.3 series versions prior to 6.3.1.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-52vw-r24f-727x

больше 4 лет назад

Multiple integer overflows in Poppler 0.10.5 and earlier allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF file, related to (1) glib/poppler-page.cc; (2) ArthurOutputDev.cc, (3) CairoOutputDev.cc, (4) GfxState.cc, (5) JBIG2Stream.cc, (6) PSOutputDev.cc, and (7) SplashOutputDev.cc in poppler/; and (8) SplashBitmap.cc, (9) Splash.cc, and (10) SplashFTFont.cc in splash/. NOTE: this may overlap CVE-2009-0791.

EPSS: Низкий
github логотип

GHSA-52vw-gr9g-vp37

больше 4 лет назад

A improper authentication using the HOST header in SUSE Linux SMT allows remote attackers to spoof a sibling server. Affected releases are SUSE Linux SMT: versions prior to 3.0.37.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-52vw-82cp-qw7c

почти 4 года назад

Use of a Broken or Risky Cryptographic Algorithm in SICK RFU62x firmware version < 2.21 allows a low-privileged remote attacker to decrypt the encrypted data if the user requested weak cipher suites to be used for encryption via the SSH interface. The patch and installation procedure for the firmware update is available from the responsible SICK customer contact person.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-52vw-4m9g-pqh6

около 3 лет назад

A memory corruption vulnerability Panasonic Control FPWIN Pro versions 7.6.0.3 and all previous versions may allow arbitrary code execution when opening specially crafted project files.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-52vv-qjqj-cp86

больше 4 лет назад

The Mahabharata Audiocast (aka com.wordbox.mahabharataAudiocast) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-52vv-jxvg-7g67

больше 1 года назад

A Stored Cross-Site Scripting (XSS) vulnerability exists in Vtiger CRM Open Source Edition v8.3.0, exploitable via the Services Import feature. An attacker can craft a malicious CSV file containing an XSS payload, mapped to the Service Name field. When the file is uploaded, the application improperly sanitizes user input, leading to persistent script execution.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-52vv-c34v-c37f

больше 4 лет назад

GoodTech FTP server allows remote attackers to cause a denial of service via a large number of RNTO commands.

EPSS: Низкий
github логотип

GHSA-52vv-5wf4-fghj

7 месяцев назад

Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete permission to delete a PAM account that is currently checked out by selecting it alongside at least one non-checked-out account and performing a bulk deletion.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-52vv-5jc5-5gmv

больше 2 лет назад

Memory corruption when malformed message payload is received from firmware.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-52vv-3vf7-f7wh

больше 4 лет назад

Server-Side Request Forgery and Uncontrolled Resource Consumption in LemMinX

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-52vv-26j5-647x

10 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Cross Site Request Forgery.This issue affects Salon booking system: from n/a through <= 10.30.3.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-52vr-v6fr-rfg8

больше 4 лет назад

An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. The Special:GlobalRenameRequest page is vulnerable to infinite loops and denial of service attacks when a user's current username is beyond an arbitrary maximum configuration value (MaxNameChars).

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-52w9-4w5g-hqxc

The IBM i 7.1, 7.2, 7.3, and 7.4 Extended Dynamic Remote SQL server (EDRSQL) could allow a remote authenticated user to send a specially crafted request and cause a denial of service. IBM X-Force ID: 214537.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-52w8-9f8q-6r2v

In append_camera_metadata of camera_metadata.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-236688120References: N/A

CVSS3: 4.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-52w5-q3hg-34x8

A vulnerability was detected in code-projects Simple Flight Ticket Booking System 1.0. Affected is an unknown function of the file /Adminupdate.php. The manipulation of the argument flightno/airplaneid/departure/dtime/arrival/atime/ec/ep/bc/bp results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.

CVSS3: 4.7
0%
Низкий
7 месяцев назад
github логотип
GHSA-52w5-6rqq-mwq5

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. A group owner may be able to bypass External Authorization check, if it is enabled, to access git repositories and package registries by using Deploy tokens or Deploy keys .

CVSS3: 4.9
1%
Низкий
больше 3 лет назад
github логотип
GHSA-52w5-48fj-c3qf

A vulnerability was found in code-projects E-Commerce Website 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file user_signup.php. The manipulation of the argument firstname/middlename/email/address/contact/username leads to sql injection. The attack may be launched remotely. VDB-249002 is the identifier assigned to this vulnerability.

CVSS3: 7.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-52w3-gj28-xfx3

procfs in FreeBSD and possibly other operating systems allows local users to bypass access control restrictions for a jail environment and gain additional privileges.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-52w2-9c5h-2xqj

Heap-based Buffer Overflow in the psf_binheader_writef function in common.c in libsndfile through 1.0.28 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.

CVSS3: 9.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-52vw-wff4-8w2j

LibreOffice documents can contain macros. The execution of those macros is controlled by the document security settings, typically execution of macros are blocked by default. A URL decoding flaw existed in how the urls to the macros within the document were processed and categorized, resulting in the possibility to construct a document where macro execution bypassed the security settings. The documents were correctly detected as containing macros, and prompted the user to their existence within the documents, but macros within the document were subsequently not controlled by the security settings allowing arbitrary macro execution This issue affects: LibreOffice 6.2 series versions prior to 6.2.7; LibreOffice 6.3 series versions prior to 6.3.1.

CVSS3: 7.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-52vw-r24f-727x

Multiple integer overflows in Poppler 0.10.5 and earlier allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF file, related to (1) glib/poppler-page.cc; (2) ArthurOutputDev.cc, (3) CairoOutputDev.cc, (4) GfxState.cc, (5) JBIG2Stream.cc, (6) PSOutputDev.cc, and (7) SplashOutputDev.cc in poppler/; and (8) SplashBitmap.cc, (9) Splash.cc, and (10) SplashFTFont.cc in splash/. NOTE: this may overlap CVE-2009-0791.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-52vw-gr9g-vp37

A improper authentication using the HOST header in SUSE Linux SMT allows remote attackers to spoof a sibling server. Affected releases are SUSE Linux SMT: versions prior to 3.0.37.

CVSS3: 9.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-52vw-82cp-qw7c

Use of a Broken or Risky Cryptographic Algorithm in SICK RFU62x firmware version < 2.21 allows a low-privileged remote attacker to decrypt the encrypted data if the user requested weak cipher suites to be used for encryption via the SSH interface. The patch and installation procedure for the firmware update is available from the responsible SICK customer contact person.

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-52vw-4m9g-pqh6

A memory corruption vulnerability Panasonic Control FPWIN Pro versions 7.6.0.3 and all previous versions may allow arbitrary code execution when opening specially crafted project files.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-52vv-qjqj-cp86

The Mahabharata Audiocast (aka com.wordbox.mahabharataAudiocast) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-52vv-jxvg-7g67

A Stored Cross-Site Scripting (XSS) vulnerability exists in Vtiger CRM Open Source Edition v8.3.0, exploitable via the Services Import feature. An attacker can craft a malicious CSV file containing an XSS payload, mapped to the Service Name field. When the file is uploaded, the application improperly sanitizes user input, leading to persistent script execution.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-52vv-c34v-c37f

GoodTech FTP server allows remote attackers to cause a denial of service via a large number of RNTO commands.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-52vv-5wf4-fghj

Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete permission to delete a PAM account that is currently checked out by selecting it alongside at least one non-checked-out account and performing a bulk deletion.

CVSS3: 9.8
1%
Низкий
7 месяцев назад
github логотип
GHSA-52vv-5jc5-5gmv

Memory corruption when malformed message payload is received from firmware.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-52vv-3vf7-f7wh

Server-Side Request Forgery and Uncontrolled Resource Consumption in LemMinX

CVSS3: 9.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-52vv-26j5-647x

Cross-Site Request Forgery (CSRF) vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Cross Site Request Forgery.This issue affects Salon booking system: from n/a through <= 10.30.3.

CVSS3: 8.8
0%
Низкий
10 месяцев назад
github логотип
GHSA-52vr-v6fr-rfg8

An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. The Special:GlobalRenameRequest page is vulnerable to infinite loops and denial of service attacks when a user's current username is beyond an arbitrary maximum configuration value (MaxNameChars).

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу