Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 376 080

Количество 376 080

github логотип

GHSA-4wx4-jx62-422q

больше 4 лет назад

An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in a pointer dereference of the parse_SST function.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4wx3-gv33-fjg8

больше 4 лет назад

Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input at “stss” decoder can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4wx3-54gh-9fr9

почти 2 года назад

Cross site scripting in markdown-to-jsx

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4wx2-rgfv-9pwv

больше 4 лет назад

Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Partition.

EPSS: Низкий
github логотип

GHSA-4wx2-q5jr-v2wg

больше 4 лет назад

Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: UIF Open UI). Supported versions that are affected are 16.0 and 17.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel UI Framework. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel UI Framework, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Siebel UI Framework accessible data as well as unauthorized read access to a subset of Siebel UI Framework accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4wx2-mhc4-vv9j

больше 2 лет назад

A vulnerability was found in Campcodes Online Examination System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file submitAnswerExe.php. The manipulation of the argument exmne_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264452.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-4wx2-7gvj-qfq3

около 2 месяцев назад

Ghost: Archived Offers can be Redeemed

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-4wwx-wcpc-49m3

больше 4 лет назад

Buffer overflow can occur due to usage of wrong datatype and missing length check before copying into buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, MSM8998, Nicobar, QCN7605, QCS405, QCS605, QM215, SDA660, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SDX24, SM6150, SM7150, SM8150

EPSS: Низкий
github логотип

GHSA-4wwx-hr93-hq4g

больше 4 лет назад

An issue was discovered in YxtCMF 3.1. RbacController.class.php has CSRF, as demonstrated by modifying an administrator account via index.php/admin/user/add_post.html.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4wwx-9cqc-h3f9

8 дней назад

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4www-jw36-m87h

больше 2 лет назад

Out of bounds read in Swiftshader in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4www-5p9h-95mh

больше 1 года назад

http-proxy-middleware can call writeBody twice because "else if" is not used

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-4wwv-835r-3cxc

больше 4 лет назад

Integer overflow in the gdk_cairo_set_source_pixbuf function in gdk/gdkcairo.c in GTK+ before 3.9.8, as used in eom, gnome-photos, eog, gambas3, thunar, pinpoint, and possibly other applications, allows remote attackers to cause a denial of service (crash) via a large image file, which triggers a large memory allocation.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4wwr-7h7c-chqr

6 месяцев назад

AVideo's CSRF on Admin Plugin Configuration Enables Payment Credential Hijacking

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-4wwr-56pj-4v9h

почти 3 года назад

Path traversal vulnerability in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior allows an unauthenticated user to steal the Windows access token of the user account configured for accessing external DB resources.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4wwr-4536-fchr

больше 4 лет назад

The NDMP protocol implementation in Symantec Backup Exec 2010 R3 before 2010 R3 SP3 and 2012 before SP2 allows remote authenticated users to obtain sensitive host-version information via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-4wwq-x9v9-792h

больше 4 лет назад

IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 allows remote authenticated users to cause a denial of service (infinite loop) via a login redirect.

EPSS: Низкий
github логотип

GHSA-4wwq-c55m-qf6c

больше 4 лет назад

This issue was addressed with improved checks. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, Security Update 2021-005 Catalina, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing a maliciously crafted dfont file may lead to arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-4wwq-85c4-8p8r

больше 1 года назад

Infinxt iEdge 100 2.1.32 is vulnerable to Cross Site Scripting (XSS) via the "Description" field during LAN configuration.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4wwp-q772-ccjv

5 месяцев назад

Netskope was notified about a potential gap in the Endpoint DLP Module for Netskope Client on Windows systems. The successful exploitation of the gap can potentially allow an unprivileged user to trigger an out-of-bounds read within a driver, leading to a Blue-Screen-of-Death (BSOD). Successful exploitation would require the Endpoint DLP module to be enabled in the client configuration. A successful exploit can potentially result in a denial-of-service for the local machine.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4wx4-jx62-422q

An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in a pointer dereference of the parse_SST function.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4wx3-gv33-fjg8

Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input at “stss” decoder can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4wx3-54gh-9fr9

Cross site scripting in markdown-to-jsx

CVSS3: 6.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-4wx2-rgfv-9pwv

Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Partition.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4wx2-q5jr-v2wg

Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: UIF Open UI). Supported versions that are affected are 16.0 and 17.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel UI Framework. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel UI Framework, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Siebel UI Framework accessible data as well as unauthorized read access to a subset of Siebel UI Framework accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4wx2-mhc4-vv9j

A vulnerability was found in Campcodes Online Examination System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file submitAnswerExe.php. The manipulation of the argument exmne_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264452.

CVSS3: 6.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4wx2-7gvj-qfq3

Ghost: Archived Offers can be Redeemed

CVSS3: 4.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-4wwx-wcpc-49m3

Buffer overflow can occur due to usage of wrong datatype and missing length check before copying into buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, MSM8998, Nicobar, QCN7605, QCS405, QCS605, QM215, SDA660, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SDX24, SM6150, SM7150, SM8150

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4wwx-hr93-hq4g

An issue was discovered in YxtCMF 3.1. RbacController.class.php has CSRF, as demonstrated by modifying an administrator account via index.php/admin/user/add_post.html.

CVSS3: 8.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4wwx-9cqc-h3f9

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 7.5
0%
Низкий
8 дней назад
github логотип
GHSA-4www-jw36-m87h

Out of bounds read in Swiftshader in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4www-5p9h-95mh

http-proxy-middleware can call writeBody twice because "else if" is not used

CVSS3: 4
0%
Низкий
больше 1 года назад
github логотип
GHSA-4wwv-835r-3cxc

Integer overflow in the gdk_cairo_set_source_pixbuf function in gdk/gdkcairo.c in GTK+ before 3.9.8, as used in eom, gnome-photos, eog, gambas3, thunar, pinpoint, and possibly other applications, allows remote attackers to cause a denial of service (crash) via a large image file, which triggers a large memory allocation.

CVSS3: 6.5
5%
Низкий
больше 4 лет назад
github логотип
GHSA-4wwr-7h7c-chqr

AVideo's CSRF on Admin Plugin Configuration Enables Payment Credential Hijacking

CVSS3: 8.1
0%
Низкий
6 месяцев назад
github логотип
GHSA-4wwr-56pj-4v9h

Path traversal vulnerability in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior allows an unauthenticated user to steal the Windows access token of the user account configured for accessing external DB resources.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-4wwr-4536-fchr

The NDMP protocol implementation in Symantec Backup Exec 2010 R3 before 2010 R3 SP3 and 2012 before SP2 allows remote authenticated users to obtain sensitive host-version information via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4wwq-x9v9-792h

IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 allows remote authenticated users to cause a denial of service (infinite loop) via a login redirect.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4wwq-c55m-qf6c

This issue was addressed with improved checks. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, Security Update 2021-005 Catalina, tvOS 15, iOS 15 and iPadOS 15, watchOS 8. Processing a maliciously crafted dfont file may lead to arbitrary code execution.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4wwq-85c4-8p8r

Infinxt iEdge 100 2.1.32 is vulnerable to Cross Site Scripting (XSS) via the "Description" field during LAN configuration.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-4wwp-q772-ccjv

Netskope was notified about a potential gap in the Endpoint DLP Module for Netskope Client on Windows systems. The successful exploitation of the gap can potentially allow an unprivileged user to trigger an out-of-bounds read within a driver, leading to a Blue-Screen-of-Death (BSOD). Successful exploitation would require the Endpoint DLP module to be enabled in the client configuration. A successful exploit can potentially result in a denial-of-service for the local machine.

0%
Низкий
5 месяцев назад

Уязвимостей на страницу