Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 453

Количество 375 453

github логотип

GHSA-4v5r-2vpm-gvgv

больше 2 лет назад

Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4v5q-p386-f6mv

больше 4 лет назад

Microsoft Excel allows user-assisted attackers to execute arbitrary javascript and redirect users to arbitrary sites via an Excel spreadsheet with an embedded Shockwave Flash Player ActiveX Object, which is automatically executed when the user opens the spreadsheet.

EPSS: Средний
github логотип

GHSA-4v5p-wg3c-r4x4

больше 4 лет назад

The Goodix GT9xx touchscreen driver for custom Linux kernels on Xiaomi daisy-o-oss and daisy-p-oss as used in Mi A2 Lite and RedMi6 pro devices through 2018-08-27 has a NULL pointer dereference in kfree after a kmalloc failure in gtp_read_Color in drivers/input/touchscreen/gt917d/gt9xx.c.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4v5p-v5h9-6xjx

больше 4 лет назад

`CHECK`-failures in Tensorflow

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4v5p-cf5h-v9cq

почти 2 года назад

Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) a command injection vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4v5p-6cwv-27q5

больше 4 лет назад

A remote code execution vulnerability exists when the Windows Camera Codec Pack improperly handles objects in memory, aka 'Windows Camera Codec Pack Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-16967.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4v5m-vwvp-p7w8

около 4 лет назад

Pagekit vulnerable to Unrestricted Upload of File with Dangerous Type

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-4v5m-fgg9-qf7f

8 дней назад

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27. Processing a maliciously crafted file may lead to unexpected app termination.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4v5m-7xcr-cg68

11 месяцев назад

Deck Mate 1 executes firmware directly from an external EEPROM without verifying authenticity or integrity. An attacker with physical access can replace or reflash the EEPROM to run arbitrary code that persists across reboots. Because this design predates modern secure-boot or signed-update mechanisms, affected systems should be physically protected or retired from service. The vendor has not indicated that firmware updates are available for this legacy model.

EPSS: Низкий
github логотип

GHSA-4v5j-ww69-fg82

больше 2 лет назад

A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) could allow a low-privileged, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient input validation by the web-based management interface. An attacker could exploit this vulnerability by inserting malicious data in a specific data field in the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4v5j-2xrq-6cqp

больше 4 лет назад

Unspecified vulnerability in Sun Integrated Lights Out Manager (ILOM) in SysFW 8.1.0.a and earlier for various Oracle SPARC T3, SPARC Netra T3, Sun Blade, and Sun Fire servers allows remote attackers to affect confidentiality, integrity, and availability, related to ILOM.

EPSS: Низкий
github логотип

GHSA-4v5h-xfpr-xr45

больше 4 лет назад

Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement any mechanism to avoid CSRF attacks. Successful exploitation of this vulnerability can lead to the takeover of a local account on the device.

EPSS: Низкий
github логотип

GHSA-4v5h-vp2v-p65r

почти 2 года назад

SQL Server Native Client Remote Code Execution Vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4v5h-q8j3-g849

больше 1 года назад

Improper authentication in Secure Folder prior to version 1.8.12.0 in Android 13, and 1.9.21.00 in Android 14 allows physical attackers to reset the lock type of Secure Folder.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4v5h-79rq-8rw9

больше 4 лет назад

Adobe Shockwave Player before 12.0.9.149 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0500.

EPSS: Низкий
github логотип

GHSA-4v5h-4j58-whhg

больше 4 лет назад

A vulnerability has been identified in SIMATIC CP 343-1 Advanced (incl. SIPLUS NET variant) (All versions < V3.0.53), SIMATIC CP 443-1 Advanced (incl. SIPLUS NET variant) (All versions < V3.2.17), SIMATIC S7-300 PN/DP CPU family (incl. SIPLUS variants) (All versions), SIMATIC S7-400 PN/DP CPU family (incl. SIPLUS variants) (All versions). The integrated web server at port 80/TCP or port 443/TCP of the affected devices could allow remote attackers to perform actions with the permissions of an authenticated user, provided the targeted user has an active session and is induced to trigger the malicious request.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4v5g-xjvw-59g6

больше 2 лет назад

An issue was found in the tiffcp utility distributed by the libtiff package where a crafted TIFF file on processing may cause a heap-based buffer overflow leads to an application crash.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4v5g-vxpg-qw6q

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in SeleniumServer Web Server 1.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-4v5g-r6mf-cq6v

больше 4 лет назад

IBM MQ 9.0 and 9.1 is vulnerable to a denial of service attack due to an error in the Channel processing function. IBM X-Force ID: 173625.

EPSS: Низкий
github логотип

GHSA-4v5g-qj5x-c7jp

больше 4 лет назад

Adobe Document Server for Reader Extensions 6.0, during log on, provides different error messages depending on whether the user ID is valid or invalid, which allows remote attackers to more easily identify valid user IDs via brute force attacks.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4v5r-2vpm-gvgv

Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4v5q-p386-f6mv

Microsoft Excel allows user-assisted attackers to execute arbitrary javascript and redirect users to arbitrary sites via an Excel spreadsheet with an embedded Shockwave Flash Player ActiveX Object, which is automatically executed when the user opens the spreadsheet.

30%
Средний
больше 4 лет назад
github логотип
GHSA-4v5p-wg3c-r4x4

The Goodix GT9xx touchscreen driver for custom Linux kernels on Xiaomi daisy-o-oss and daisy-p-oss as used in Mi A2 Lite and RedMi6 pro devices through 2018-08-27 has a NULL pointer dereference in kfree after a kmalloc failure in gtp_read_Color in drivers/input/touchscreen/gt917d/gt9xx.c.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v5p-v5h9-6xjx

`CHECK`-failures in Tensorflow

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4v5p-cf5h-v9cq

Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) a command injection vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution.

CVSS3: 7.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-4v5p-6cwv-27q5

A remote code execution vulnerability exists when the Windows Camera Codec Pack improperly handles objects in memory, aka 'Windows Camera Codec Pack Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-16967.

CVSS3: 7.8
5%
Низкий
больше 4 лет назад
github логотип
GHSA-4v5m-vwvp-p7w8

Pagekit vulnerable to Unrestricted Upload of File with Dangerous Type

CVSS3: 9.8
18%
Средний
около 4 лет назад
github логотип
GHSA-4v5m-fgg9-qf7f

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27. Processing a maliciously crafted file may lead to unexpected app termination.

CVSS3: 7.8
0%
Низкий
8 дней назад
github логотип
GHSA-4v5m-7xcr-cg68

Deck Mate 1 executes firmware directly from an external EEPROM without verifying authenticity or integrity. An attacker with physical access can replace or reflash the EEPROM to run arbitrary code that persists across reboots. Because this design predates modern secure-boot or signed-update mechanisms, affected systems should be physically protected or retired from service. The vendor has not indicated that firmware updates are available for this legacy model.

0%
Низкий
11 месяцев назад
github логотип
GHSA-4v5j-ww69-fg82

A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) could allow a low-privileged, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient input validation by the web-based management interface. An attacker could exploit this vulnerability by inserting malicious data in a specific data field in the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4v5j-2xrq-6cqp

Unspecified vulnerability in Sun Integrated Lights Out Manager (ILOM) in SysFW 8.1.0.a and earlier for various Oracle SPARC T3, SPARC Netra T3, Sun Blade, and Sun Fire servers allows remote attackers to affect confidentiality, integrity, and availability, related to ILOM.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4v5h-xfpr-xr45

Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement any mechanism to avoid CSRF attacks. Successful exploitation of this vulnerability can lead to the takeover of a local account on the device.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4v5h-vp2v-p65r

SQL Server Native Client Remote Code Execution Vulnerability

CVSS3: 8.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-4v5h-q8j3-g849

Improper authentication in Secure Folder prior to version 1.8.12.0 in Android 13, and 1.9.21.00 in Android 14 allows physical attackers to reset the lock type of Secure Folder.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-4v5h-79rq-8rw9

Adobe Shockwave Player before 12.0.9.149 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0500.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-4v5h-4j58-whhg

A vulnerability has been identified in SIMATIC CP 343-1 Advanced (incl. SIPLUS NET variant) (All versions < V3.0.53), SIMATIC CP 443-1 Advanced (incl. SIPLUS NET variant) (All versions < V3.2.17), SIMATIC S7-300 PN/DP CPU family (incl. SIPLUS variants) (All versions), SIMATIC S7-400 PN/DP CPU family (incl. SIPLUS variants) (All versions). The integrated web server at port 80/TCP or port 443/TCP of the affected devices could allow remote attackers to perform actions with the permissions of an authenticated user, provided the targeted user has an active session and is induced to trigger the malicious request.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v5g-xjvw-59g6

An issue was found in the tiffcp utility distributed by the libtiff package where a crafted TIFF file on processing may cause a heap-based buffer overflow leads to an application crash.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4v5g-vxpg-qw6q

Cross-site scripting (XSS) vulnerability in SeleniumServer Web Server 1.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4v5g-r6mf-cq6v

IBM MQ 9.0 and 9.1 is vulnerable to a denial of service attack due to an error in the Channel processing function. IBM X-Force ID: 173625.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4v5g-qj5x-c7jp

Adobe Document Server for Reader Extensions 6.0, during log on, provides different error messages depending on whether the user ID is valid or invalid, which allows remote attackers to more easily identify valid user IDs via brute force attacks.

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу