Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-4rj4-pwww-6m28

больше 4 лет назад

Unspecified vulnerability in the Oracle Web Applications Desktop Integrator component in Oracle E-Business Suite 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect integrity via vectors related to Application Service.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-4rj4-mjp8-mcgg

больше 4 лет назад

Untrusted search path vulnerability in OpenLDAP before 2.2.28-r3 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build directory, which is part of the RUNPATH.

EPSS: Низкий
github логотип

GHSA-4rj4-hw8f-rwmr

больше 2 лет назад

A vulnerability, which was classified as critical, has been found in Kashipara Billing Software 1.0. Affected by this issue is some unknown functionality of the file submit_delivery_list.php of the component HTTP POST Request Handler. The manipulation of the argument customer_details leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-250598 is the identifier assigned to this vulnerability.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-4rj4-795m-98x3

12 месяцев назад

A flaw has been found in code-projects Online Course Registration 1.0. Impacted is an unknown function of the file /admin/manage-students.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4rj3-h5c4-jprh

почти 3 года назад

An issue exists in SoftIron HyperCloud where drive caddy removal and reinsertion without a reboot may erroneously cause the system to recognize the caddy as new media and wipe all data on the drives due to a missing synchronization flaw, which impacts data availability and integrity. This issue only impacts SoftIron HyperCloud "density" storage nodes running HyperCloud software versions 1.0 to before 2.0.3.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-4rj2-pr7f-cmpg

3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Validate the passed in fops for ib_get_ucaps() Sashiko pointed out it is not safe to rely only on the devt because char/block alias so if the user finds a block device with the same dev_t it can masquerade as a ucap cdev fd. Test the f_ops to only accept authentic cdevs.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4rj2-hhfh-p3j7

больше 4 лет назад

The web management console in Trend Micro OfficeScan 7.0 through 8.0, Worry-Free Business Security 5.0, and Client/Server/Messaging Suite 3.5 and 3.6 creates a random session token based only on the login time, which makes it easier for remote attackers to hijack sessions via brute-force attacks. NOTE: this can be leveraged for code execution through an unspecified "manipulation of the configuration."

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-4rj2-gx5j-44h9

больше 4 лет назад

Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Uniscribe Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0072, CVE-2017-0084, CVE-2017-0086, CVE-2017-0087, CVE-2017-0088, CVE-2017-0089, and CVE-2017-0090.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-4rj2-gpmh-qq5x

7 месяцев назад

OpenClaw has an inbound allowlist policy bypass in voice-call extension (empty caller ID + suffix matching)

CVSS3: 9.4
EPSS: Низкий
github логотип

GHSA-4rj2-9gcx-5qhx

больше 1 года назад

MLflow has Weak Password Requirements

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-4rhw-pmr4-jxwm

больше 4 лет назад

The Facebook Status Via (aka com.StatusViaAdvanced) application 3.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-4rhw-49fx-p3h4

больше 4 лет назад

Digger Solutions Intranet Open Source (IOS) stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for data/intranet.mdb.

EPSS: Низкий
github логотип

GHSA-4rhw-3jx2-mpcf

7 месяцев назад

Privilege escalation via dll hijacking in Inno Setup 6.2.1 and ealier versions.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4rhv-r8jc-m23p

11 месяцев назад

The Easy Email Subscription plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing or incorrect nonce validation on the show_editsub_page() function. This makes it possible for unauthenticated attackers to delete arbitrary subscribers via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4rhv-54g5-f4cm

больше 4 лет назад

Buffer overflow in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0198, CVE-2010-0199, and CVE-2010-0203.

EPSS: Низкий
github логотип

GHSA-4rhr-pw6c-jrf4

больше 4 лет назад

There was an argument injection vulnerability in Atlassian Sourcetree for macOS from version 1.2 before version 3.1.1 via filenames in Mercurial repositories. A remote attacker with permission to commit to a Mercurial repository linked in Sourcetree for macOS is able to exploit this issue to gain code execution on the system.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4rhr-9xj2-x9gx

8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix hugetlb_pmd_shared() Patch series "mm/hugetlb: fixes for PMD table sharing (incl. using mmu_gather)", v3. One functional fix, one performance regression fix, and two related comment fixes. I cleaned up my prototype I recently shared [1] for the performance fix, deferring most of the cleanups I had in the prototype to a later point. While doing that I identified the other things. The goal of this patch set is to be backported to stable trees "fairly" easily. At least patch #1 and #4. Patch #1 fixes hugetlb_pmd_shared() not detecting any sharing Patch #2 + #3 are simple comment fixes that patch #4 interacts with. Patch #4 is a fix for the reported performance regression due to excessive IPI broadcasts during fork()+exit(). The last patch is all about TLB flushes, IPIs and mmu_gather. Read: complicated There are plenty of cleanups in the future to be had + one reasonable optimization on x86. B...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4rhr-3r55-929p

больше 2 лет назад

Missing Authorization vulnerability in Wpmet Metform Elementor Contact Form Builder.This issue affects Metform Elementor Contact Form Builder: from n/a through 3.8.3.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4rhr-2jf8-rw24

больше 4 лет назад

The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1863 and CVE-2016-4582.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4rhq-vq24-88gw

больше 3 лет назад

Uncontrolled Recursion in HTTP2ToRawGRPCServerCodec

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4rj4-pwww-6m28

Unspecified vulnerability in the Oracle Web Applications Desktop Integrator component in Oracle E-Business Suite 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect integrity via vectors related to Application Service.

CVSS3: 4.7
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4rj4-mjp8-mcgg

Untrusted search path vulnerability in OpenLDAP before 2.2.28-r3 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build directory, which is part of the RUNPATH.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4rj4-hw8f-rwmr

A vulnerability, which was classified as critical, has been found in Kashipara Billing Software 1.0. Affected by this issue is some unknown functionality of the file submit_delivery_list.php of the component HTTP POST Request Handler. The manipulation of the argument customer_details leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-250598 is the identifier assigned to this vulnerability.

CVSS3: 6.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4rj4-795m-98x3

A flaw has been found in code-projects Online Course Registration 1.0. Impacted is an unknown function of the file /admin/manage-students.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.

CVSS3: 7.3
0%
Низкий
12 месяцев назад
github логотип
GHSA-4rj3-h5c4-jprh

An issue exists in SoftIron HyperCloud where drive caddy removal and reinsertion without a reboot may erroneously cause the system to recognize the caddy as new media and wipe all data on the drives due to a missing synchronization flaw, which impacts data availability and integrity. This issue only impacts SoftIron HyperCloud "density" storage nodes running HyperCloud software versions 1.0 to before 2.0.3.

CVSS3: 7
0%
Низкий
почти 3 года назад
github логотип
GHSA-4rj2-pr7f-cmpg

In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Validate the passed in fops for ib_get_ucaps() Sashiko pointed out it is not safe to rely only on the devt because char/block alias so if the user finds a block device with the same dev_t it can masquerade as a ucap cdev fd. Test the f_ops to only accept authentic cdevs.

CVSS3: 8.8
0%
Низкий
3 месяца назад
github логотип
GHSA-4rj2-hhfh-p3j7

The web management console in Trend Micro OfficeScan 7.0 through 8.0, Worry-Free Business Security 5.0, and Client/Server/Messaging Suite 3.5 and 3.6 creates a random session token based only on the login time, which makes it easier for remote attackers to hijack sessions via brute-force attacks. NOTE: this can be leveraged for code execution through an unspecified "manipulation of the configuration."

CVSS3: 9.8
11%
Средний
больше 4 лет назад
github логотип
GHSA-4rj2-gx5j-44h9

Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Uniscribe Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0072, CVE-2017-0084, CVE-2017-0086, CVE-2017-0087, CVE-2017-0088, CVE-2017-0089, and CVE-2017-0090.

CVSS3: 8.8
43%
Средний
больше 4 лет назад
github логотип
GHSA-4rj2-gpmh-qq5x

OpenClaw has an inbound allowlist policy bypass in voice-call extension (empty caller ID + suffix matching)

CVSS3: 9.4
1%
Низкий
7 месяцев назад
github логотип
GHSA-4rj2-9gcx-5qhx

MLflow has Weak Password Requirements

CVSS3: 3.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-4rhw-pmr4-jxwm

The Facebook Status Via (aka com.StatusViaAdvanced) application 3.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4rhw-49fx-p3h4

Digger Solutions Intranet Open Source (IOS) stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for data/intranet.mdb.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4rhw-3jx2-mpcf

Privilege escalation via dll hijacking in Inno Setup 6.2.1 and ealier versions.

CVSS3: 7.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-4rhv-r8jc-m23p

The Easy Email Subscription plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing or incorrect nonce validation on the show_editsub_page() function. This makes it possible for unauthenticated attackers to delete arbitrary subscribers via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-4rhv-54g5-f4cm

Buffer overflow in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0198, CVE-2010-0199, and CVE-2010-0203.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-4rhr-pw6c-jrf4

There was an argument injection vulnerability in Atlassian Sourcetree for macOS from version 1.2 before version 3.1.1 via filenames in Mercurial repositories. A remote attacker with permission to commit to a Mercurial repository linked in Sourcetree for macOS is able to exploit this issue to gain code execution on the system.

CVSS3: 8.8
6%
Низкий
больше 4 лет назад
github логотип
GHSA-4rhr-9xj2-x9gx

In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix hugetlb_pmd_shared() Patch series "mm/hugetlb: fixes for PMD table sharing (incl. using mmu_gather)", v3. One functional fix, one performance regression fix, and two related comment fixes. I cleaned up my prototype I recently shared [1] for the performance fix, deferring most of the cleanups I had in the prototype to a later point. While doing that I identified the other things. The goal of this patch set is to be backported to stable trees "fairly" easily. At least patch #1 and #4. Patch #1 fixes hugetlb_pmd_shared() not detecting any sharing Patch #2 + #3 are simple comment fixes that patch #4 interacts with. Patch #4 is a fix for the reported performance regression due to excessive IPI broadcasts during fork()+exit(). The last patch is all about TLB flushes, IPIs and mmu_gather. Read: complicated There are plenty of cleanups in the future to be had + one reasonable optimization on x86. B...

CVSS3: 5.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-4rhr-3r55-929p

Missing Authorization vulnerability in Wpmet Metform Elementor Contact Form Builder.This issue affects Metform Elementor Contact Form Builder: from n/a through 3.8.3.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4rhr-2jf8-rw24

The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1863 and CVE-2016-4582.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4rhq-vq24-88gw

Uncontrolled Recursion in HTTP2ToRawGRPCServerCodec

2%
Низкий
больше 3 лет назад

Уязвимостей на страницу