Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 453

Количество 375 453

github логотип

GHSA-4v96-m8xv-x83v

больше 4 лет назад

Broken Authentication in Atlassian Connect Express

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-4v96-chmw-8jc6

29 дней назад

Firmware in KAON PG5298A and PG5298B routers allow an unauthenticated user to query a specific endpoint and acquire sensitive information such as a password to the administrative portal.   This vulnerability has been fixed in firmware version: 3.0.82 for PG5298A and 4.0.82 for PG5298B.

EPSS: Низкий
github логотип

GHSA-4v95-m49f-6w63

около 2 лет назад

A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-4v95-63wh-6gqh

около 1 года назад

A weakness has been identified in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the file /module/TabelaArredondamento/edit. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-4v94-xg93-8jj8

больше 4 лет назад

SQL injection vulnerability in guestbook.php in LI-Guestbook 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the country parameter. NOTE: it was later reported that 1.2 is also affected.

EPSS: Низкий
github логотип

GHSA-4v94-xg8j-pp22

больше 4 лет назад

The bmp_read_info_header function in bin/jp2/convertbmp.c in OpenJPEG 2.2.0 does not reject headers with a zero biBitCount, which allows remote attackers to cause a denial of service (memory allocation failure) in the opj_image_create function in lib/openjp2/image.c, related to the opj_aligned_alloc_n function in opj_malloc.c.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4v94-f8pq-mj8v

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: cdx: Fix possible UAF error in driver_override_show() Fixed a possible UAF problem in driver_override_show() in drivers/cdx/cdx.c This function driver_override_show() is part of DEVICE_ATTR_RW, which includes both driver_override_show() and driver_override_store(). These functions can be executed concurrently in sysfs. The driver_override_store() function uses driver_set_override() to update the driver_override value, and driver_set_override() internally locks the device (device_lock(dev)). If driver_override_show() reads cdx_dev->driver_override without locking, it could potentially access a freed pointer if driver_override_store() frees the string concurrently. This could lead to printing a kernel address, which is a security risk since DEVICE_ATTR can be read by all users. Additionally, a similar pattern is used in drivers/amba/bus.c, as well as many other bus drivers, where device_lock() is taken in the sho...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4v94-29mp-g6pq

больше 4 лет назад

Trusty contains a vulnerability in TSEC TA which deserializes the incoming messages even though the TSEC TA does not expose any command. This vulnerability might allow an attacker to exploit the deserializer to impact code execution, causing information disclosure.

EPSS: Низкий
github логотип

GHSA-4v93-238v-585f

больше 4 лет назад

Kernel/Output/HTML/CustomerNewTicketQueueSelectionGeneric.pm in Open Ticket Request System (OTRS) before 2.2.6, when the CustomerPanelOwnSelection and CustomerGroupSupport options are enabled, allows remote authenticated users to bypass intended access restrictions, and perform certain (1) list and (2) write operations on queues, via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-4v8x-qr64-whf2

больше 4 лет назад

In the Linux kernel before 2.6.20, there is an off-by-one bug in net/netlabel/netlabel_cipso_v4.c where it is possible to overflow the doi_def->tags[] array.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4v8x-g9mf-87fr

больше 3 лет назад

Microsoft Office Information Disclosure Vulnerability

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4v8x-9h4c-j4jc

больше 4 лет назад

The NBA Game Time 2013-2014 (aka com.nbadigital.gametimelite) application 4.11 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-4v8w-v3fq-rj46

больше 4 лет назад

libdw in elfutils 0.173 checks the end of the attributes list incorrectly in dwarf_getabbrev in dwarf_getabbrev.c and dwarf_hasattr in dwarf_hasattr.c, leading to a heap-based buffer over-read and an application crash.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4v8w-gmwj-mqp6

больше 4 лет назад

Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, intercept protected network traffic, or cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4v8w-gg5j-ph37

11 месяцев назад

MantisBT vulnerable to authentication bypass for some passwords due to PHP type juggling

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-4v8w-5cm8-f73w

больше 4 лет назад

Zucchetti InfoBusiness before and including 4.4.1 allows any authenticated user to upload .php files in order to achieve code execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4v8w-428c-cm63

больше 4 лет назад

Session fixation vulnerability in WikyBlog 1.7.3 rc2 allows remote attackers to hijack web sessions by setting the jsessionid parameter to (1) index.php/Comment/Main, (2) index.php/Comment/Main/Home_Wiky, or (3) index.php/Edit/Main.

EPSS: Низкий
github логотип

GHSA-4v8v-q38v-qx4j

больше 4 лет назад

Mozilla Firefox before 43.0 does not properly store the properties of unboxed objects, which allows remote attackers to execute arbitrary code via crafted JavaScript variable assignments.

EPSS: Низкий
github логотип

GHSA-4v8v-pr95-rhx7

почти 4 года назад

A NULL pointer dereference issue was discovered in the Linux kernel in the MPTCP protocol when traversing the subflow list at disconnect time. A local user could use this flaw to potentially crash the system causing a denial of service.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4v8r-37jq-35mj

больше 4 лет назад

Directory traversal vulnerability in blog.php in fuzzylime (cms) 3.01, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the file parameter. NOTE: it was later reported that 3.01a is also affected.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4v96-m8xv-x83v

Broken Authentication in Atlassian Connect Express

CVSS3: 7.7
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v96-chmw-8jc6

Firmware in KAON PG5298A and PG5298B routers allow an unauthenticated user to query a specific endpoint and acquire sensitive information such as a password to the administrative portal.   This vulnerability has been fixed in firmware version: 3.0.82 for PG5298A and 4.0.82 for PG5298B.

0%
Низкий
29 дней назад
github логотип
GHSA-4v95-m49f-6w63

A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.

CVSS3: 8.7
0%
Низкий
около 2 лет назад
github логотип
GHSA-4v95-63wh-6gqh

A weakness has been identified in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the file /module/TabelaArredondamento/edit. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited.

CVSS3: 6.3
1%
Низкий
около 1 года назад
github логотип
GHSA-4v94-xg93-8jj8

SQL injection vulnerability in guestbook.php in LI-Guestbook 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the country parameter. NOTE: it was later reported that 1.2 is also affected.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v94-xg8j-pp22

The bmp_read_info_header function in bin/jp2/convertbmp.c in OpenJPEG 2.2.0 does not reject headers with a zero biBitCount, which allows remote attackers to cause a denial of service (memory allocation failure) in the opj_image_create function in lib/openjp2/image.c, related to the opj_aligned_alloc_n function in opj_malloc.c.

CVSS3: 5.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4v94-f8pq-mj8v

In the Linux kernel, the following vulnerability has been resolved: cdx: Fix possible UAF error in driver_override_show() Fixed a possible UAF problem in driver_override_show() in drivers/cdx/cdx.c This function driver_override_show() is part of DEVICE_ATTR_RW, which includes both driver_override_show() and driver_override_store(). These functions can be executed concurrently in sysfs. The driver_override_store() function uses driver_set_override() to update the driver_override value, and driver_set_override() internally locks the device (device_lock(dev)). If driver_override_show() reads cdx_dev->driver_override without locking, it could potentially access a freed pointer if driver_override_store() frees the string concurrently. This could lead to printing a kernel address, which is a security risk since DEVICE_ATTR can be read by all users. Additionally, a similar pattern is used in drivers/amba/bus.c, as well as many other bus drivers, where device_lock() is taken in the sho...

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-4v94-29mp-g6pq

Trusty contains a vulnerability in TSEC TA which deserializes the incoming messages even though the TSEC TA does not expose any command. This vulnerability might allow an attacker to exploit the deserializer to impact code execution, causing information disclosure.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4v93-238v-585f

Kernel/Output/HTML/CustomerNewTicketQueueSelectionGeneric.pm in Open Ticket Request System (OTRS) before 2.2.6, when the CustomerPanelOwnSelection and CustomerGroupSupport options are enabled, allows remote authenticated users to bypass intended access restrictions, and perform certain (1) list and (2) write operations on queues, via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v8x-qr64-whf2

In the Linux kernel before 2.6.20, there is an off-by-one bug in net/netlabel/netlabel_cipso_v4.c where it is possible to overflow the doi_def->tags[] array.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4v8x-g9mf-87fr

Microsoft Office Information Disclosure Vulnerability

CVSS3: 5.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4v8x-9h4c-j4jc

The NBA Game Time 2013-2014 (aka com.nbadigital.gametimelite) application 4.11 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4v8w-v3fq-rj46

libdw in elfutils 0.173 checks the end of the attributes list incorrectly in dwarf_getabbrev in dwarf_getabbrev.c and dwarf_hasattr in dwarf_hasattr.c, leading to a heap-based buffer over-read and an application crash.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v8w-gmwj-mqp6

Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, intercept protected network traffic, or cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v8w-gg5j-ph37

MantisBT vulnerable to authentication bypass for some passwords due to PHP type juggling

CVSS3: 9.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-4v8w-5cm8-f73w

Zucchetti InfoBusiness before and including 4.4.1 allows any authenticated user to upload .php files in order to achieve code execution.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4v8w-428c-cm63

Session fixation vulnerability in WikyBlog 1.7.3 rc2 allows remote attackers to hijack web sessions by setting the jsessionid parameter to (1) index.php/Comment/Main, (2) index.php/Comment/Main/Home_Wiky, or (3) index.php/Edit/Main.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4v8v-q38v-qx4j

Mozilla Firefox before 43.0 does not properly store the properties of unboxed objects, which allows remote attackers to execute arbitrary code via crafted JavaScript variable assignments.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4v8v-pr95-rhx7

A NULL pointer dereference issue was discovered in the Linux kernel in the MPTCP protocol when traversing the subflow list at disconnect time. A local user could use this flaw to potentially crash the system causing a denial of service.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-4v8r-37jq-35mj

Directory traversal vulnerability in blog.php in fuzzylime (cms) 3.01, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the file parameter. NOTE: it was later reported that 3.01a is also affected.

4%
Низкий
больше 4 лет назад

Уязвимостей на страницу