Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 453

Количество 375 453

github логотип

GHSA-4vcc-6pw6-88rm

больше 4 лет назад

Microsoft Internet Security and Acceleration (ISA) Server 2004 allows remote attackers to bypass file extension filters via a request with a trailing "#" character. NOTE: as of 20060715, this could not be reproduced by third parties.

EPSS: Средний
github логотип

GHSA-4vc9-4xpq-77vm

больше 4 лет назад

Cobbler Arbitrary File Read

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4vc8-xh76-x4r3

3 месяца назад

Use after free in Cast Receiver in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4vc8-wvhw-m5gv

около 1 года назад

Juju allows arbitrary executable uploads via authenticated endpoint without authorization

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4vc8-pg5c-vg4x

больше 2 лет назад

Keycloak's improper input validation allows using email as username

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-4vc8-3r3m-hhj4

больше 3 лет назад

Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in platform API of IPMI module. A low-privileged user with permission to read logs on the cluster could potentially exploit this vulnerability, leading to Information disclosure and denial of service.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-4vc7-vx93-f2cp

больше 4 лет назад

In ImageMagick 7.0.7-1 Q16, a memory exhaustion vulnerability was found in the function ReadTIFFImage in coders/tiff.c, which allow remote attackers to cause a denial of service via a crafted file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4vc6-9m66-j82c

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 8.14 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed an unauthenticated user to create a denial of service condition by sending specially crafted payloads to specific integration API endpoints.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4vc6-7qhx-wxq5

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: virtio_net: correct netdev_tx_reset_queue() invocation point When virtnet_close is followed by virtnet_open, some TX completions can possibly remain unconsumed, until they are finally processed during the first NAPI poll after the netdev_tx_reset_queue(), resulting in a crash [1]. Commit b96ed2c97c79 ("virtio_net: move netdev_tx_reset_queue() call before RX napi enable") was not sufficient to eliminate all BQL crash cases for virtio-net. This issue can be reproduced with the latest net-next master by running: `while :; do ip l set DEV down; ip l set DEV up; done` under heavy network TX load from inside the machine. netdev_tx_reset_queue() can actually be dropped from virtnet_open path; the device is not stopped in any case. For BQL core part, it's just like traffic nearly ceases to exist for some period. For stall detector added to BQL, even if virtnet_close could somehow lead to some TX completions delayed for ...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4vc4-vv83-m3fr

больше 4 лет назад

Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 does not properly restrict access to frameworkgui/config, which allows remote attackers to obtain the plaintext database password via a direct request.

EPSS: Низкий
github логотип

GHSA-4vc4-pm9p-xmjm

больше 4 лет назад

In radare2 through 3.5.1, cmd_mount in libr/core/cmd_mount.c has a double free for the ms command.

EPSS: Низкий
github логотип

GHSA-4vc4-m8qh-g8jm

больше 1 года назад

Ruby SAML allows a SAML authentication bypass due to DOCTYPE handling (parser differential)

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-4vc4-6jgc-cg63

больше 4 лет назад

Finder 10.4.6 on Apple Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a long volume name in a DMG disk image, which results in memory corruption.

EPSS: Низкий
github логотип

GHSA-4vc3-629x-6rhv

больше 4 лет назад

Cross-site request forgery (CSRF) vulnerability in PHPX 3.0 through 3.2.6 allows remote attackers to execute arbitrary commands via URLs that are automatically executed on behalf of the administrator, as demonstrated using (1) admin/page.php, (2) admin/news.php, (3) admin/user.php, (4) admin/images.php, (5) admin/page.php, or (6) admin/forums.php.

EPSS: Средний
github логотип

GHSA-4vc2-wm37-4628

около 3 лет назад

An issue has been discovered in GitLab affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to trigger a stored XSS vulnerability via user interaction with a crafted URL in the WebIDE beta.

CVSS3: 5.4
EPSS: Средний
github логотип

GHSA-4v9x-x766-gmm3

больше 4 лет назад

This issue was addressed by verifying host keys when connecting to a previously-known SSH server. This issue is fixed in iOS 13.1 and iPadOS 13.1. An attacker in a privileged network position may be able to intercept SSH traffic from the “Run script over SSH” action.

EPSS: Низкий
github логотип

GHSA-4v9x-wfx7-57r9

почти 3 года назад

FactoryTalk Linx, in the Rockwell Automation PanelView Plus, allows an unauthenticated threat actor to read data from memory via crafted malicious packets. Sending a size larger than the buffer size results in leakage of data from memory resulting in an information disclosure. If the size is large enough, it causes communications over the common industrial protocol to become unresponsive to any type of packet, resulting in a denial-of-service to FactoryTalk Linx over the common industrial protocol.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-4v9x-qxmv-4h58

больше 1 года назад

Out of bounds memory access in V8 in Google Chrome prior to 133.0.6943.98 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4v9x-p3f6-cp58

больше 4 лет назад

SQL injection vulnerability in shop/page.php in iGeneric (iG) Shop 1.4 allows remote attackers to execute arbitrary SQL commands via the type_id[] parameter, a different vector than CVE-2005-0537.

EPSS: Низкий
github логотип

GHSA-4v9x-j7pr-8wxq

больше 4 лет назад

An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in to a device. This issue affects: QNAP Systems Inc. HBS 3 versions prior to v16.0.0415 on QTS 4.5.2; versions prior to v3.0.210412 on QTS 4.3.6; versions prior to v3.0.210411 on QTS 4.3.4; versions prior to v3.0.210411 on QTS 4.3.3; versions prior to v16.0.0419 on QuTS hero h4.5.1; versions prior to v16.0.0419 on QuTScloud c4.5.1~c4.5.4. This issue does not affect: QNAP Systems Inc. HBS 2 . QNAP Systems Inc. HBS 1.3 .

CVSS3: 9.8
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4vcc-6pw6-88rm

Microsoft Internet Security and Acceleration (ISA) Server 2004 allows remote attackers to bypass file extension filters via a request with a trailing "#" character. NOTE: as of 20060715, this could not be reproduced by third parties.

19%
Средний
больше 4 лет назад
github логотип
GHSA-4vc9-4xpq-77vm

Cobbler Arbitrary File Read

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4vc8-xh76-x4r3

Use after free in Cast Receiver in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 8.8
0%
Низкий
3 месяца назад
github логотип
GHSA-4vc8-wvhw-m5gv

Juju allows arbitrary executable uploads via authenticated endpoint without authorization

CVSS3: 8.8
1%
Низкий
около 1 года назад
github логотип
GHSA-4vc8-pg5c-vg4x

Keycloak's improper input validation allows using email as username

CVSS3: 3.7
2%
Низкий
больше 2 лет назад
github логотип
GHSA-4vc8-3r3m-hhj4

Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in platform API of IPMI module. A low-privileged user with permission to read logs on the cluster could potentially exploit this vulnerability, leading to Information disclosure and denial of service.

CVSS3: 8.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4vc7-vx93-f2cp

In ImageMagick 7.0.7-1 Q16, a memory exhaustion vulnerability was found in the function ReadTIFFImage in coders/tiff.c, which allow remote attackers to cause a denial of service via a crafted file.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4vc6-9m66-j82c

An issue has been discovered in GitLab CE/EE affecting all versions from 8.14 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed an unauthenticated user to create a denial of service condition by sending specially crafted payloads to specific integration API endpoints.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-4vc6-7qhx-wxq5

In the Linux kernel, the following vulnerability has been resolved: virtio_net: correct netdev_tx_reset_queue() invocation point When virtnet_close is followed by virtnet_open, some TX completions can possibly remain unconsumed, until they are finally processed during the first NAPI poll after the netdev_tx_reset_queue(), resulting in a crash [1]. Commit b96ed2c97c79 ("virtio_net: move netdev_tx_reset_queue() call before RX napi enable") was not sufficient to eliminate all BQL crash cases for virtio-net. This issue can be reproduced with the latest net-next master by running: `while :; do ip l set DEV down; ip l set DEV up; done` under heavy network TX load from inside the machine. netdev_tx_reset_queue() can actually be dropped from virtnet_open path; the device is not stopped in any case. For BQL core part, it's just like traffic nearly ceases to exist for some period. For stall detector added to BQL, even if virtnet_close could somehow lead to some TX completions delayed for ...

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-4vc4-vv83-m3fr

Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 does not properly restrict access to frameworkgui/config, which allows remote attackers to obtain the plaintext database password via a direct request.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4vc4-pm9p-xmjm

In radare2 through 3.5.1, cmd_mount in libr/core/cmd_mount.c has a double free for the ms command.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4vc4-m8qh-g8jm

Ruby SAML allows a SAML authentication bypass due to DOCTYPE handling (parser differential)

CVSS3: 9.8
21%
Средний
больше 1 года назад
github логотип
GHSA-4vc4-6jgc-cg63

Finder 10.4.6 on Apple Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a long volume name in a DMG disk image, which results in memory corruption.

8%
Низкий
больше 4 лет назад
github логотип
GHSA-4vc3-629x-6rhv

Cross-site request forgery (CSRF) vulnerability in PHPX 3.0 through 3.2.6 allows remote attackers to execute arbitrary commands via URLs that are automatically executed on behalf of the administrator, as demonstrated using (1) admin/page.php, (2) admin/news.php, (3) admin/user.php, (4) admin/images.php, (5) admin/page.php, or (6) admin/forums.php.

11%
Средний
больше 4 лет назад
github логотип
GHSA-4vc2-wm37-4628

An issue has been discovered in GitLab affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to trigger a stored XSS vulnerability via user interaction with a crafted URL in the WebIDE beta.

CVSS3: 5.4
65%
Средний
около 3 лет назад
github логотип
GHSA-4v9x-x766-gmm3

This issue was addressed by verifying host keys when connecting to a previously-known SSH server. This issue is fixed in iOS 13.1 and iPadOS 13.1. An attacker in a privileged network position may be able to intercept SSH traffic from the “Run script over SSH” action.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4v9x-wfx7-57r9

FactoryTalk Linx, in the Rockwell Automation PanelView Plus, allows an unauthenticated threat actor to read data from memory via crafted malicious packets. Sending a size larger than the buffer size results in leakage of data from memory resulting in an information disclosure. If the size is large enough, it causes communications over the common industrial protocol to become unresponsive to any type of packet, resulting in a denial-of-service to FactoryTalk Linx over the common industrial protocol.

CVSS3: 8.2
10%
Низкий
почти 3 года назад
github логотип
GHSA-4v9x-qxmv-4h58

Out of bounds memory access in V8 in Google Chrome prior to 133.0.6943.98 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 5.9
больше 1 года назад
github логотип
GHSA-4v9x-p3f6-cp58

SQL injection vulnerability in shop/page.php in iGeneric (iG) Shop 1.4 allows remote attackers to execute arbitrary SQL commands via the type_id[] parameter, a different vector than CVE-2005-0537.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v9x-j7pr-8wxq

An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in to a device. This issue affects: QNAP Systems Inc. HBS 3 versions prior to v16.0.0415 on QTS 4.5.2; versions prior to v3.0.210412 on QTS 4.3.6; versions prior to v3.0.210411 on QTS 4.3.4; versions prior to v3.0.210411 on QTS 4.3.3; versions prior to v16.0.0419 on QuTS hero h4.5.1; versions prior to v16.0.0419 on QuTScloud c4.5.1~c4.5.4. This issue does not affect: QNAP Systems Inc. HBS 2 . QNAP Systems Inc. HBS 1.3 .

CVSS3: 9.8
78%
Высокий
больше 4 лет назад

Уязвимостей на страницу