Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 727

Количество 375 727

github логотип

GHSA-4w8p-x6g8-fv64

больше 4 лет назад

Server-Side Request Forgery in calibreweb

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4w8p-vqv2-2g8w

больше 4 лет назад

kbx/keybox-search.c in GnuPG before 1.4.19, 2.0.x before 2.0.27, and 2.1.x before 2.1.2 does not properly handle bitwise left-shifts, which allows remote attackers to cause a denial of service (invalid read operation) via a crafted keyring file, related to sign extensions and "memcpy with overlapping ranges."

EPSS: Низкий
github логотип

GHSA-4w8p-q3qp-3qg2

больше 4 лет назад

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4w8p-fpvp-22x8

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - Call crypto layer directly when padata_do_parallel() return -EBUSY Since commit 8f4f68e788c3 ("crypto: pcrypt - Fix hungtask for PADATA_RESET"), the pcrypt encryption and decryption operations return -EAGAIN when the CPU goes online or offline. In alg_test(), a WARN is generated when pcrypt_aead_decrypt() or pcrypt_aead_encrypt() returns -EAGAIN, the unnecessary panic will occur when panic_on_warn set 1. Fix this issue by calling crypto layer directly without parallelization in that case.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4w8m-wcw8-4mmj

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix null pointer dereferences without iommu Check if 'aspace' is set before using it as it will stay null without IOMMU, such as on msm8974.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4w8m-m9vr-qjm9

больше 3 лет назад

Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions that are affected are Prior to 6.3.1.3 and Prior to 7.0.0.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Health Sciences InForm. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Health Sciences InForm, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Health Sciences InForm accessible data as well as unauthorized read access to a subset of Oracle Health Sciences InForm accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Health Sciences InForm. CVSS 3.1 Base Score 5.9 (Confidentiality, Integrity and Availability impact...

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4w8m-g472-95vj

больше 4 лет назад

SQL injection vulnerability in show.php in vbzoom 1.11 allow remote attackers to execute arbitrary SQL commands via the MainID parameter. NOTE: the SubjectID vector is already covered by CVE-2005-4729.

EPSS: Низкий
github логотип

GHSA-4w8m-c933-mrf8

около 1 месяца назад

The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4w8m-96v9-2c86

больше 4 лет назад

Moodle CRLF Injection Vulnerability in Calendar Component

EPSS: Низкий
github логотип

GHSA-4w8m-8vvx-gcw2

около 1 месяца назад

Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4w8j-9239-gvhw

8 месяцев назад

Tanium addressed a denial of service vulnerability in Tanium Client.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-4w8j-4c9q-3cj8

6 месяцев назад

Doom Launcher 3.8.1.0 is vulnerable to Directory Traversal due to missing file path validation during the extraction of game files

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4w8h-rwcr-pvw9

больше 4 лет назад

An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The GitLab API allowed project Maintainers and Owners to view the trigger tokens of other project users.

EPSS: Низкий
github логотип

GHSA-4w8h-jccj-5h68

почти 3 года назад

DOS vulnerability that could allow an attacker to register a new VNF (Virtual Network Function) value. This action could trigger the args_assets() function defined in the arg-log.php file, which would then execute the args-abort.c file, causing the service to crash.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4w8h-g4h9-3c46

около 1 месяца назад

Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4w8h-2hjm-3r6x

больше 4 лет назад

Workgroup Manager in Apple Mac OS X Server 10.2 through 10.2.6 does not disable a password for a new account before it is saved for the first time, which allows remote attackers to gain unauthorized access via the new account before it is saved.

EPSS: Низкий
github логотип

GHSA-4w8g-vwqf-w48w

больше 4 лет назад

Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building. A remote unauthenticated malicious attacker could hijack the DNS entry for the dependency, and inject malicious code into the component.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4w8g-q38j-gm8m

3 месяца назад

The Wertheim SafeController 5400, Controller 5400 - AssemblyVersion 6.11.8130.22320, uses RS-485 communication between the server and the microcontroller without cryptographic protection. An attacker with access to the communication path between the server and the microcontroller can sniff RS-485 messages and replay previously observed messages. This can be used, for example, to spoof a "quit alarm" message and continuously deactivate the safe alarm.

EPSS: Низкий
github логотип

GHSA-4w8g-cx67-fxgx

почти 3 года назад

Adobe Premiere Pro version 24.0 (and earlier) and 23.6 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4w8f-w8xh-rq2w

больше 1 года назад

Improper access control of endpoint in HCL Domino Leap allows certain admin users to import applications from the server's filesystem.

CVSS3: 4.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4w8p-x6g8-fv64

Server-Side Request Forgery in calibreweb

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4w8p-vqv2-2g8w

kbx/keybox-search.c in GnuPG before 1.4.19, 2.0.x before 2.0.27, and 2.1.x before 2.1.2 does not properly handle bitwise left-shifts, which allows remote attackers to cause a denial of service (invalid read operation) via a crafted keyring file, related to sign extensions and "memcpy with overlapping ranges."

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4w8p-q3qp-3qg2

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

CVSS3: 8.8
5%
Низкий
больше 4 лет назад
github логотип
GHSA-4w8p-fpvp-22x8

In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - Call crypto layer directly when padata_do_parallel() return -EBUSY Since commit 8f4f68e788c3 ("crypto: pcrypt - Fix hungtask for PADATA_RESET"), the pcrypt encryption and decryption operations return -EAGAIN when the CPU goes online or offline. In alg_test(), a WARN is generated when pcrypt_aead_decrypt() or pcrypt_aead_encrypt() returns -EAGAIN, the unnecessary panic will occur when panic_on_warn set 1. Fix this issue by calling crypto layer directly without parallelization in that case.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-4w8m-wcw8-4mmj

In the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix null pointer dereferences without iommu Check if 'aspace' is set before using it as it will stay null without IOMMU, such as on msm8974.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-4w8m-m9vr-qjm9

Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions that are affected are Prior to 6.3.1.3 and Prior to 7.0.0.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Health Sciences InForm. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Health Sciences InForm, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Health Sciences InForm accessible data as well as unauthorized read access to a subset of Oracle Health Sciences InForm accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Health Sciences InForm. CVSS 3.1 Base Score 5.9 (Confidentiality, Integrity and Availability impact...

CVSS3: 5.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4w8m-g472-95vj

SQL injection vulnerability in show.php in vbzoom 1.11 allow remote attackers to execute arbitrary SQL commands via the MainID parameter. NOTE: the SubjectID vector is already covered by CVE-2005-4729.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4w8m-c933-mrf8

The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.

CVSS3: 9.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-4w8m-96v9-2c86

Moodle CRLF Injection Vulnerability in Calendar Component

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4w8m-8vvx-gcw2

Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.

CVSS3: 7.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-4w8j-9239-gvhw

Tanium addressed a denial of service vulnerability in Tanium Client.

CVSS3: 3.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-4w8j-4c9q-3cj8

Doom Launcher 3.8.1.0 is vulnerable to Directory Traversal due to missing file path validation during the extraction of game files

CVSS3: 7.5
1%
Низкий
6 месяцев назад
github логотип
GHSA-4w8h-rwcr-pvw9

An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The GitLab API allowed project Maintainers and Owners to view the trigger tokens of other project users.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4w8h-jccj-5h68

DOS vulnerability that could allow an attacker to register a new VNF (Virtual Network Function) value. This action could trigger the args_assets() function defined in the arg-log.php file, which would then execute the args-abort.c file, causing the service to crash.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-4w8h-g4h9-3c46

Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions.

CVSS3: 7.1
0%
Низкий
около 1 месяца назад
github логотип
GHSA-4w8h-2hjm-3r6x

Workgroup Manager in Apple Mac OS X Server 10.2 through 10.2.6 does not disable a password for a new account before it is saved for the first time, which allows remote attackers to gain unauthorized access via the new account before it is saved.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4w8g-vwqf-w48w

Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building. A remote unauthenticated malicious attacker could hijack the DNS entry for the dependency, and inject malicious code into the component.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4w8g-q38j-gm8m

The Wertheim SafeController 5400, Controller 5400 - AssemblyVersion 6.11.8130.22320, uses RS-485 communication between the server and the microcontroller without cryptographic protection. An attacker with access to the communication path between the server and the microcontroller can sniff RS-485 messages and replay previously observed messages. This can be used, for example, to spoof a "quit alarm" message and continuously deactivate the safe alarm.

0%
Низкий
3 месяца назад
github логотип
GHSA-4w8g-cx67-fxgx

Adobe Premiere Pro version 24.0 (and earlier) and 23.6 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-4w8f-w8xh-rq2w

Improper access control of endpoint in HCL Domino Leap allows certain admin users to import applications from the server's filesystem.

CVSS3: 4.1
0%
Низкий
больше 1 года назад

Уязвимостей на страницу