Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 727

Количество 375 727

github логотип

GHSA-4w97-57v2-3w44

больше 6 лет назад

False-negative validation results in MINT transactions with invalid baton

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-4w96-3hrf-qq67

больше 4 лет назад

Use-after-free vulnerability in Google Chrome before 9.0.597.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to blocked plug-ins.

EPSS: Низкий
github логотип

GHSA-4w94-xc6r-9grm

больше 4 лет назад

Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger any of these vulnerabilities. An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser<EW>::read_vertex() vh->svertices_last().

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4w94-x732-jcmm

6 месяцев назад

Authorization Bypass Through User-Controlled Key vulnerability in LatePoint LatePoint latepoint allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LatePoint: from n/a through <= 5.2.6.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4w94-8ff7-4xmw

больше 4 лет назад

An improper authentication issue was discovered in Johnson & Johnson Ethicon Endo-Surgery Generator Gen11, all versions released before November 29, 2017. The security authentication mechanism used between the Ethicon Endo-Surgery Generator Gen11 and single-patient use products can be bypassed, allowing for unauthorized devices to be connected to the generator, which could result in a loss of integrity or availability.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-4w94-4xq8-3wqx

больше 4 лет назад

QL Office in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted office document.

EPSS: Низкий
github логотип

GHSA-4w93-m9qg-7rwr

больше 4 лет назад

A vulnerability was discovered in GitLab versions prior to 13.1. Under certain conditions the restriction for Github project import could be bypassed.

EPSS: Низкий
github логотип

GHSA-4w93-8r29-p2r9

больше 2 лет назад

JumpCloud Agent before 1.178.0 Creates a Temporary File in a Directory with Insecure Permissions. This allows privilege escalation to SYSTEM via a repair action in the installer.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4w93-8hmg-4r2c

больше 4 лет назад

Directory traversal vulnerability in getfile.asp in Ultimate HelpDesk allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.

EPSS: Низкий
github логотип

GHSA-4w93-6768-q548

больше 4 лет назад

The mintToken function of a smart contract implementation for ENTER (ENTR) (Contract Name: EnterCoin), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4w92-vgp9-22jp

больше 4 лет назад

Soft3304 04WebServer before 1.41 does not properly check file names, which allows remote attackers to obtain sensitive information (CGI source code).

EPSS: Низкий
github логотип

GHSA-4w92-qgpc-qcc9

около 1 года назад

A vulnerability in ABB Aspect.This issue affects Aspect: before <3.08.04-s01.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-4w8x-p5gf-gh2h

больше 2 лет назад

IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a user to cause a denial of service due to missing API rate limiting. IBM X-Force ID: 248533.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4w8v-rh82-h7w8

3 месяца назад

IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-4w8v-46j6-77cf

больше 4 лет назад

The HTTPS implementation in Google Chrome before 28.0.1500.71 does not ensure that headers are terminated by \r\n\r\n (carriage return, newline, carriage return, newline), which allows man-in-the-middle attackers to have an unspecified impact via vectors that trigger header truncation.

EPSS: Низкий
github логотип

GHSA-4w8r-4268-4w28

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weptile ShopApper allows Stored XSS. This issue affects ShopApper: from n/a through 0.4.39.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4w8r-3xrw-v25g

около 3 лет назад

Craft CMS Remote Code Execution vulnerability

CVSS3: 10
EPSS: Критический
github логотип

GHSA-4w8q-c6h3-w87x

больше 4 лет назад

The multiplayer menu in OpenTTD 0.4.7 allows remote attackers to cause a denial of service via a UDP packet with an incorrect size, which causes the client to return to the main menu.

EPSS: Низкий
github логотип

GHSA-4w8q-7wmj-6f3m

больше 4 лет назад

In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06126832; Issue ID: ALPS06126832.

EPSS: Низкий
github логотип

GHSA-4w8p-xx38-h33q

27 дней назад

An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could allow an attacker to gain access to some user accounts.

CVSS3: 9.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4w97-57v2-3w44

False-negative validation results in MINT transactions with invalid baton

CVSS3: 8.6
1%
Низкий
больше 6 лет назад
github логотип
GHSA-4w96-3hrf-qq67

Use-after-free vulnerability in Google Chrome before 9.0.597.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to blocked plug-ins.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4w94-xc6r-9grm

Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger any of these vulnerabilities. An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser<EW>::read_vertex() vh->svertices_last().

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4w94-x732-jcmm

Authorization Bypass Through User-Controlled Key vulnerability in LatePoint LatePoint latepoint allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LatePoint: from n/a through <= 5.2.6.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-4w94-8ff7-4xmw

An improper authentication issue was discovered in Johnson & Johnson Ethicon Endo-Surgery Generator Gen11, all versions released before November 29, 2017. The security authentication mechanism used between the Ethicon Endo-Surgery Generator Gen11 and single-patient use products can be bypassed, allowing for unauthorized devices to be connected to the generator, which could result in a loss of integrity or availability.

CVSS3: 4.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4w94-4xq8-3wqx

QL Office in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted office document.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4w93-m9qg-7rwr

A vulnerability was discovered in GitLab versions prior to 13.1. Under certain conditions the restriction for Github project import could be bypassed.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4w93-8r29-p2r9

JumpCloud Agent before 1.178.0 Creates a Temporary File in a Directory with Insecure Permissions. This allows privilege escalation to SYSTEM via a repair action in the installer.

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4w93-8hmg-4r2c

Directory traversal vulnerability in getfile.asp in Ultimate HelpDesk allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4w93-6768-q548

The mintToken function of a smart contract implementation for ENTER (ENTR) (Contract Name: EnterCoin), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4w92-vgp9-22jp

Soft3304 04WebServer before 1.41 does not properly check file names, which allows remote attackers to obtain sensitive information (CGI source code).

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4w92-qgpc-qcc9

A vulnerability in ABB Aspect.This issue affects Aspect: before <3.08.04-s01.

CVSS3: 7
около 1 года назад
github логотип
GHSA-4w8x-p5gf-gh2h

IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a user to cause a denial of service due to missing API rate limiting. IBM X-Force ID: 248533.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4w8v-rh82-h7w8

IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS3: 6.4
0%
Низкий
3 месяца назад
github логотип
GHSA-4w8v-46j6-77cf

The HTTPS implementation in Google Chrome before 28.0.1500.71 does not ensure that headers are terminated by \r\n\r\n (carriage return, newline, carriage return, newline), which allows man-in-the-middle attackers to have an unspecified impact via vectors that trigger header truncation.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4w8r-4268-4w28

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weptile ShopApper allows Stored XSS. This issue affects ShopApper: from n/a through 0.4.39.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-4w8r-3xrw-v25g

Craft CMS Remote Code Execution vulnerability

CVSS3: 10
94%
Критический
около 3 лет назад
github логотип
GHSA-4w8q-c6h3-w87x

The multiplayer menu in OpenTTD 0.4.7 allows remote attackers to cause a denial of service via a UDP packet with an incorrect size, which causes the client to return to the main menu.

9%
Низкий
больше 4 лет назад
github логотип
GHSA-4w8q-7wmj-6f3m

In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06126832; Issue ID: ALPS06126832.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4w8p-xx38-h33q

An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could allow an attacker to gain access to some user accounts.

CVSS3: 9.3
0%
Низкий
27 дней назад

Уязвимостей на страницу