Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 453

Количество 375 453

github логотип

GHSA-4v56-r8gq-q83w

7 месяцев назад

In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10320471; Issue ID: MSV-5540.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-4v56-mrhv-6j2m

больше 4 лет назад

SerenityOS Unspecified is affected by: Buffer Overflow. The impact is: obtain sensitive information (context-dependent). The component is: /Userland/Libraries/LibCrypto/ASN1/DER.h Crypto::der_decode_sequence() function. The attack vector is: Parsing RSA Key ASN.1.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4v56-g6h4-6655

7 месяцев назад

A security vulnerability has been detected in itsourcecode College Management System 1.0. This affects an unknown part of the file /admin/display-teacher.php. The manipulation of the argument teacher_id leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-4v55-v7j8-2w76

около 1 года назад

DuraComm SPM-500 DP-10iN-100-MU is vulnerable to a cross-site scripting attack. This could allow an attacker to prevent legitimate users from accessing the web interface.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-4v55-cpmv-3vcm

3 месяца назад

CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite Bypass

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-4v55-6j3q-q3g7

почти 3 года назад

Unrestricted Upload of File with Dangerous Type vulnerability in Jeff Starr User Submitted Posts – Enable Users to Submit Posts from the Front End.This issue affects User Submitted Posts – Enable Users to Submit Posts from the Front End: from n/a through 20230902.

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-4v53-v62j-2637

больше 4 лет назад

An issue was discovered on Intex N150 devices. The router firmware suffers from multiple CSRF injection point vulnerabilities including changing user passwords and router settings.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4v53-9g52-rm7v

больше 2 лет назад

The BackWPup WordPress plugin before 4.0.4 does not prevent visitors from leaking key information about ongoing backups, allowing unauthenticated attackers to download backups of a site's database.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4v52-wcg8-75c9

больше 4 лет назад

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 835, SD 845, SD 850, and SDX20, improper initialization of ike_sa_handle_ptr in IPSEC leads to system denial of service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4v52-cjf4-53w4

больше 4 лет назад

WFTPD and WFTPD Pro 2.41 RC12 allows remote attackers to obtain the full pathname of the server via a "%C" command, which generates an error message that includes the pathname.

EPSS: Низкий
github логотип

GHSA-4v52-cfm2-5xvm

больше 4 лет назад

A stack-based buffer overflow vulnerability exists in the BlynkConsole.h runCommand functionality of Blynk -Library v1.0.1. A specially-crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4v52-8764-fm33

больше 4 лет назад

autopsy version <= 4.9.0 contains a XML External Entity (XXE) vulnerability in CaseMetadata XML Parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via Specially crafted CaseMetadata.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-4v52-7q2x-v4xj

больше 2 лет назад

eyre: Parts of Report are dropped as the wrong type during downcast

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4v52-6x48-9c47

больше 3 лет назад

An uspecified endpoint in the web server of the switch does not properly authenticate the user identity, and may allow downloading a config page with the password to the switch in clear text.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4v4x-mh67-4m6p

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: blk-mq: don't touch ->tagset in blk_mq_get_sq_hctx blk_mq_run_hw_queues() could be run when there isn't queued request and after queue is cleaned up, at that time tagset is freed, because tagset lifetime is covered by driver, and often freed after blk_cleanup_queue() returns. So don't touch ->tagset for figuring out current default hctx by the mapping built in request queue, so use-after-free on tagset can be avoided. Meantime this way should be fast than retrieving mapping from tagset.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4v4x-hh7w-55p3

2 месяца назад

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4v4w-xc3p-xc43

больше 4 лет назад

An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10. Android ID: A-32401526. References: N-CVE-2017-0428.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4v4w-p37f-qvm2

больше 2 лет назад

Privilege Escalation in WRSA.EXE in Webroot Antivirus 8.0.1X- 9.0.35.12 on Windows64 bit and 32 bit allows malicious software to abuse WRSA.EXE to delete arbitrary and protected files.

CVSS3: 7.9
EPSS: Низкий
github логотип

GHSA-4v4w-685q-cqmx

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: NFSv4.2: Rework scratch handling for READ_PLUS (again) I found that the read code might send multiple requests using the same nfs_pgio_header, but nfs4_proc_read_setup() is only called once. This is how we ended up occasionally double-freeing the scratch buffer, but also means we set a NULL pointer but non-zero length to the xdr scratch buffer. This results in an oops the first time decoding needs to copy something to scratch, which frequently happens when decoding READ_PLUS hole segments. I fix this by moving scratch handling into the pageio read code. I provide a function to allocate scratch space for decoding read replies, and free the scratch buffer when the nfs_pgio_header is freed.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4v4w-44q3-ww8w

12 месяцев назад

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments) contain two hardcoded private keys that are shipped in the application containers (printerlogic/pi, printerlogic/printer-admin-api, and printercloud/pi). The keys are stored in clear text under /var/www/app/config/ as keyfile.ppk.dev and keyfile.saasid.ppk.dev. The application uses these keys as the symmetric secret for AES‑256‑CBC encryption/decryption of the “SaaS Id” (external identifier) through the getEncryptedExternalId() / getDecryptedExternalId() methods. Because the secret is embedded in the deployed image, any attacker who can obtain a copy of the Docker image, read the configuration files, or otherwise enumerate the filesystem can recover the encryption key. This vulnerability has been confirmed to be remediated, but it is unclear as to when the patch was introduced.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4v56-r8gq-q83w

In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10320471; Issue ID: MSV-5540.

CVSS3: 4.4
0%
Низкий
7 месяцев назад
github логотип
GHSA-4v56-mrhv-6j2m

SerenityOS Unspecified is affected by: Buffer Overflow. The impact is: obtain sensitive information (context-dependent). The component is: /Userland/Libraries/LibCrypto/ASN1/DER.h Crypto::der_decode_sequence() function. The attack vector is: Parsing RSA Key ASN.1.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4v56-g6h4-6655

A security vulnerability has been detected in itsourcecode College Management System 1.0. This affects an unknown part of the file /admin/display-teacher.php. The manipulation of the argument teacher_id leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.

CVSS3: 6.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-4v55-v7j8-2w76

DuraComm SPM-500 DP-10iN-100-MU is vulnerable to a cross-site scripting attack. This could allow an attacker to prevent legitimate users from accessing the web interface.

CVSS3: 8.1
0%
Низкий
около 1 года назад
github логотип
GHSA-4v55-cpmv-3vcm

CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite Bypass

CVSS3: 3.7
0%
Низкий
3 месяца назад
github логотип
GHSA-4v55-6j3q-q3g7

Unrestricted Upload of File with Dangerous Type vulnerability in Jeff Starr User Submitted Posts – Enable Users to Submit Posts from the Front End.This issue affects User Submitted Posts – Enable Users to Submit Posts from the Front End: from n/a through 20230902.

CVSS3: 9
1%
Низкий
почти 3 года назад
github логотип
GHSA-4v53-v62j-2637

An issue was discovered on Intex N150 devices. The router firmware suffers from multiple CSRF injection point vulnerabilities including changing user passwords and router settings.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v53-9g52-rm7v

The BackWPup WordPress plugin before 4.0.4 does not prevent visitors from leaking key information about ongoing backups, allowing unauthenticated attackers to download backups of a site's database.

CVSS3: 7.5
2%
Низкий
больше 2 лет назад
github логотип
GHSA-4v52-wcg8-75c9

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 835, SD 845, SD 850, and SDX20, improper initialization of ike_sa_handle_ptr in IPSEC leads to system denial of service.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v52-cjf4-53w4

WFTPD and WFTPD Pro 2.41 RC12 allows remote attackers to obtain the full pathname of the server via a "%C" command, which generates an error message that includes the pathname.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4v52-cfm2-5xvm

A stack-based buffer overflow vulnerability exists in the BlynkConsole.h runCommand functionality of Blynk -Library v1.0.1. A specially-crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4v52-8764-fm33

autopsy version <= 4.9.0 contains a XML External Entity (XXE) vulnerability in CaseMetadata XML Parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via Specially crafted CaseMetadata.

CVSS3: 10
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4v52-7q2x-v4xj

eyre: Parts of Report are dropped as the wrong type during downcast

CVSS3: 7.5
больше 2 лет назад
github логотип
GHSA-4v52-6x48-9c47

An uspecified endpoint in the web server of the switch does not properly authenticate the user identity, and may allow downloading a config page with the password to the switch in clear text.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4v4x-mh67-4m6p

In the Linux kernel, the following vulnerability has been resolved: blk-mq: don't touch ->tagset in blk_mq_get_sq_hctx blk_mq_run_hw_queues() could be run when there isn't queued request and after queue is cleaned up, at that time tagset is freed, because tagset lifetime is covered by driver, and often freed after blk_cleanup_queue() returns. So don't touch ->tagset for figuring out current default hctx by the mapping built in request queue, so use-after-free on tagset can be avoided. Meantime this way should be fast than retrieving mapping from tagset.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-4v4x-hh7w-55p3

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
0%
Низкий
2 месяца назад
github логотип
GHSA-4v4w-xc3p-xc43

An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10. Android ID: A-32401526. References: N-CVE-2017-0428.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4v4w-p37f-qvm2

Privilege Escalation in WRSA.EXE in Webroot Antivirus 8.0.1X- 9.0.35.12 on Windows64 bit and 32 bit allows malicious software to abuse WRSA.EXE to delete arbitrary and protected files.

CVSS3: 7.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4v4w-685q-cqmx

In the Linux kernel, the following vulnerability has been resolved: NFSv4.2: Rework scratch handling for READ_PLUS (again) I found that the read code might send multiple requests using the same nfs_pgio_header, but nfs4_proc_read_setup() is only called once. This is how we ended up occasionally double-freeing the scratch buffer, but also means we set a NULL pointer but non-zero length to the xdr scratch buffer. This results in an oops the first time decoding needs to copy something to scratch, which frequently happens when decoding READ_PLUS hole segments. I fix this by moving scratch handling into the pageio read code. I provide a function to allocate scratch space for decoding read replies, and free the scratch buffer when the nfs_pgio_header is freed.

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-4v4w-44q3-ww8w

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (VA/SaaS deployments) contain two hardcoded private keys that are shipped in the application containers (printerlogic/pi, printerlogic/printer-admin-api, and printercloud/pi). The keys are stored in clear text under /var/www/app/config/ as keyfile.ppk.dev and keyfile.saasid.ppk.dev. The application uses these keys as the symmetric secret for AES‑256‑CBC encryption/decryption of the “SaaS Id” (external identifier) through the getEncryptedExternalId() / getDecryptedExternalId() methods. Because the secret is embedded in the deployed image, any attacker who can obtain a copy of the Docker image, read the configuration files, or otherwise enumerate the filesystem can recover the encryption key. This vulnerability has been confirmed to be remediated, but it is unclear as to when the patch was introduced.

CVSS3: 7.5
0%
Низкий
12 месяцев назад

Уязвимостей на страницу