Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 727

Количество 375 727

github логотип

GHSA-4vv2-5vvw-4392

больше 4 лет назад

In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_body_to_str() function defined in osipparser2/osip_body.c, resulting in a remote DoS.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4vv2-435c-33ch

почти 3 года назад

Memory Corruption in Data Modem while making a MO call or MT VOLTE call.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-4vrx-hp2c-wxxw

больше 1 года назад

A vulnerability, which was classified as critical, has been found in SourceCodester Client Database Management System 1.0. This issue affects some unknown processing of the file /user_customer_create_order.php. The manipulation of the argument user_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4vrx-8phj-x3mg

больше 2 лет назад

Duplicate Advisory: Keycloak exposes sensitive information in Pushed Authorization Requests (PAR)

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4vrw-qvhf-f547

больше 2 лет назад

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service by an authenticated user using a specially crafted query. IBM X-Force ID: 282953.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4vrw-qvg8-27qc

почти 5 лет назад

An issue was discovered in HTCondor before 8.8.15, 9.0.x before 9.0.4, and 9.1.x before 9.1.2. Using standard command-line tools, a user with only READ access to an HTCondor SchedD or Collector daemon can discover secrets that could allow them to control other users' jobs and/or read their data.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-4vrw-8fx2-pj82

около 1 месяца назад

A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster's indexed search data. This is possible because the delta-sync write paths in search-indexer do not properly restrict UPDATE/DELETE operations to data owned by the calling cluster. An attacker could exploit this by crafting specific user identifiers (UIDs) with a different cluster's prefix.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-4vrv-fwxh-ff92

больше 4 лет назад

Multiple SQL injection vulnerabilities in search.php in WoltLab Burning Board (wBB) Lite 1.0.2 pl3e allow remote attackers to execute arbitrary SQL commands via the (1) showposts, (2) sortby, and (3) sortorder parameters.

EPSS: Низкий
github логотип

GHSA-4vrv-fq2h-vgq6

4 дня назад

The Real3D Flipbook Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lightboxtext' shortcode attribute (and other unsanitized attributes handled by on_shortcode()) in versions up to, and including, 5.1.1. This is due to insufficient input sanitization and output escaping in the on_shortcode() and print_global_options() functions: shortcode attribute values are copied verbatim into $this->flipbook_options and then emitted via wp_json_encode() inside a <script type="application/json"> block without the JSON_HEX_TAG flag, allowing a literal </script> byte sequence in the attribute value to break out of the JSON script context. Because WordPress's shortcode_parse_atts() applies stripcslashes() to attribute values, an attacker can encode the breakout tag as \x3c/script\x3e\x3cscript\x3e…\x3c/script\x3e, which survives the wp_kses_post save-time filter applied to Contributor content (the escape bytes are safe text characters, not HTML tags) and is decoded ...

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-4vrv-ch96-6h42

больше 4 лет назад

Improper Privilege Management in MySQL Connectors Java

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4vrv-93c7-m92j

около 3 лет назад

snyk Code Injection vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4vrv-8x2h-44vh

почти 3 года назад

Windows Common Log File System Driver Information Disclosure Vulnerability

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4vrv-84pc-9mcc

больше 4 лет назад

Open redirect vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-4vrv-6pj5-3c4x

больше 4 лет назад

Use after free in tab strip in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

EPSS: Низкий
github логотип

GHSA-4vrv-65m3-hf56

около 4 лет назад

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: XML Publisher). Supported versions that are affected are 8.58 and 8.59. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 4.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-4vrv-4wc3-4q25

больше 2 лет назад

Sourcecodester Human Resource Management System 1.0 is vulnerable to Insecure Permissions resulting in privilege escalation.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4vrr-rw92-55r5

больше 1 года назад

Missing Authorization vulnerability in Post SMTP Post SMTP allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post SMTP: from n/a through 2.9.11.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4vrr-rhf8-cpc9

6 дней назад

ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authorization Bypass Spring Security gates DWR endpoints by URL path pattern, but DWR itself dispatches method calls based on the POST body parameters c0-scriptName and c0-methodName. The crossDomainSessionSecurity setting in web.xml is set to false, which disables DWR's built-in origin validation. This means any authenticated user can invoke any DWR method (regardless of the URL-based access control) by sending their request to a URL they are permitted to access (e.g. MiscDwr.initializeLongPoll.dwr) while targeting a restricted class in the POST body. This is the systemic root cause that enables multiple other findings to be exploited as a low privilege user.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4vrr-r4j5-6m68

больше 2 лет назад

The Salon booking system plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SLN_Action_Ajax_ImportAssistants function along with missing authorization checks in all versions up to, and including, 10.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4vrr-7c2m-7wxq

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Fix some memory leaks in an error handling path of 'log_replay()' All error handling paths lead to 'out' where many resources are freed. Do it as well here instead of a direct return, otherwise 'log', 'ra' and 'log->one_page_buf' (at least) will leak.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4vv2-5vvw-4392

In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_body_to_str() function defined in osipparser2/osip_body.c, resulting in a remote DoS.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4vv2-435c-33ch

Memory Corruption in Data Modem while making a MO call or MT VOLTE call.

CVSS3: 8.2
0%
Низкий
почти 3 года назад
github логотип
GHSA-4vrx-hp2c-wxxw

A vulnerability, which was classified as critical, has been found in SourceCodester Client Database Management System 1.0. This issue affects some unknown processing of the file /user_customer_create_order.php. The manipulation of the argument user_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-4vrx-8phj-x3mg

Duplicate Advisory: Keycloak exposes sensitive information in Pushed Authorization Requests (PAR)

CVSS3: 7.5
больше 2 лет назад
github логотип
GHSA-4vrw-qvhf-f547

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service by an authenticated user using a specially crafted query. IBM X-Force ID: 282953.

CVSS3: 5.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4vrw-qvg8-27qc

An issue was discovered in HTCondor before 8.8.15, 9.0.x before 9.0.4, and 9.1.x before 9.1.2. Using standard command-line tools, a user with only READ access to an HTCondor SchedD or Collector daemon can discover secrets that could allow them to control other users' jobs and/or read their data.

CVSS3: 8.1
1%
Низкий
почти 5 лет назад
github логотип
GHSA-4vrw-8fx2-pj82

A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster's indexed search data. This is possible because the delta-sync write paths in search-indexer do not properly restrict UPDATE/DELETE operations to data owned by the calling cluster. An attacker could exploit this by crafting specific user identifiers (UIDs) with a different cluster's prefix.

CVSS3: 6.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-4vrv-fwxh-ff92

Multiple SQL injection vulnerabilities in search.php in WoltLab Burning Board (wBB) Lite 1.0.2 pl3e allow remote attackers to execute arbitrary SQL commands via the (1) showposts, (2) sortby, and (3) sortorder parameters.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4vrv-fq2h-vgq6

The Real3D Flipbook Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lightboxtext' shortcode attribute (and other unsanitized attributes handled by on_shortcode()) in versions up to, and including, 5.1.1. This is due to insufficient input sanitization and output escaping in the on_shortcode() and print_global_options() functions: shortcode attribute values are copied verbatim into $this->flipbook_options and then emitted via wp_json_encode() inside a <script type="application/json"> block without the JSON_HEX_TAG flag, allowing a literal </script> byte sequence in the attribute value to break out of the JSON script context. Because WordPress's shortcode_parse_atts() applies stripcslashes() to attribute values, an attacker can encode the breakout tag as \x3c/script\x3e\x3cscript\x3e…\x3c/script\x3e, which survives the wp_kses_post save-time filter applied to Contributor content (the escape bytes are safe text characters, not HTML tags) and is decoded ...

CVSS3: 6.4
0%
Низкий
4 дня назад
github логотип
GHSA-4vrv-ch96-6h42

Improper Privilege Management in MySQL Connectors Java

CVSS3: 8.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4vrv-93c7-m92j

snyk Code Injection vulnerability

CVSS3: 8.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-4vrv-8x2h-44vh

Windows Common Log File System Driver Information Disclosure Vulnerability

CVSS3: 5.5
8%
Низкий
почти 3 года назад
github логотип
GHSA-4vrv-84pc-9mcc

Open redirect vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-4vrv-6pj5-3c4x

Use after free in tab strip in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4vrv-65m3-hf56

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: XML Publisher). Supported versions that are affected are 8.58 and 8.59. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 4.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 4.9
1%
Низкий
около 4 лет назад
github логотип
GHSA-4vrv-4wc3-4q25

Sourcecodester Human Resource Management System 1.0 is vulnerable to Insecure Permissions resulting in privilege escalation.

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4vrr-rw92-55r5

Missing Authorization vulnerability in Post SMTP Post SMTP allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post SMTP: from n/a through 2.9.11.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-4vrr-rhf8-cpc9

ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authorization Bypass Spring Security gates DWR endpoints by URL path pattern, but DWR itself dispatches method calls based on the POST body parameters c0-scriptName and c0-methodName. The crossDomainSessionSecurity setting in web.xml is set to false, which disables DWR's built-in origin validation. This means any authenticated user can invoke any DWR method (regardless of the URL-based access control) by sending their request to a URL they are permitted to access (e.g. MiscDwr.initializeLongPoll.dwr) while targeting a restricted class in the POST body. This is the systemic root cause that enables multiple other findings to be exploited as a low privilege user.

CVSS3: 8.8
0%
Низкий
6 дней назад
github логотип
GHSA-4vrr-r4j5-6m68

The Salon booking system plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SLN_Action_Ajax_ImportAssistants function along with missing authorization checks in all versions up to, and including, 10.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4vrr-7c2m-7wxq

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Fix some memory leaks in an error handling path of 'log_replay()' All error handling paths lead to 'out' where many resources are freed. Do it as well here instead of a direct return, otherwise 'log', 'ra' and 'log->one_page_buf' (at least) will leak.

CVSS3: 5.5
0%
Низкий
больше 1 года назад

Уязвимостей на страницу