Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-4r7j-x8fr-p2q2

больше 4 лет назад

In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112328051

EPSS: Низкий
github логотип

GHSA-4r7h-v53j-c9qw

около 4 лет назад

Improper access control vulnerability in TelephonyUI prior to SMR Jul-2022 Release 1 allows attackers to change preferred network type by unprotected binder call.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-4r7h-hv98-vx5w

около 2 лет назад

A Unrestricted upload of file with dangerous type vulnerability in meeting management function in Hamastar MeetingHub Paperless Meetings 2021 allows remote authenticated users to perform arbitrary system commands via a crafted ASP file.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4r7h-4fx4-6prf

9 месяцев назад

A weakness has been identified in Kohana KodiCMS up to 13.82.135. This affects the function like of the file cms/modules/pages/classes/kodicms/model/page.php of the component Search API Endpoint. Executing manipulation of the argument keyword can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-4r7g-qqxf-m6v8

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: USB: hub: Ignore non-compliant devices with too many configs or interfaces Robert Morris created a test program which can cause usb_hub_to_struct_hub() to dereference a NULL or inappropriate pointer: Oops: general protection fault, probably for non-canonical address 0xcccccccccccccccc: 0000 [#1] SMP DEBUG_PAGEALLOC PTI CPU: 7 UID: 0 PID: 117 Comm: kworker/7:1 Not tainted 6.13.0-rc3-00017-gf44d154d6e3d #14 Hardware name: FreeBSD BHYVE/BHYVE, BIOS 14.0 10/17/2021 Workqueue: usb_hub_wq hub_event RIP: 0010:usb_hub_adjust_deviceremovable+0x78/0x110 ... Call Trace: <TASK> ? die_addr+0x31/0x80 ? exc_general_protection+0x1b4/0x3c0 ? asm_exc_general_protection+0x26/0x30 ? usb_hub_adjust_deviceremovable+0x78/0x110 hub_probe+0x7c7/0xab0 usb_probe_interface+0x14b/0x350 really_probe+0xd0/0x2d0 ? __pfx___device_attach_driver+0x10/0x10 __driver_probe_device+0x6e/0x110 driver_probe_device+0x1a/0x90 __device_attach_dr...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4r7g-h9xg-7p27

больше 4 лет назад

Heap-based buffer overflow in the progressive PNG Image loader (decoders/pngloader.cpp) in KHTML in KDE 4.0.x up to 4.0.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted image.

EPSS: Низкий
github логотип

GHSA-4r7g-fj95-jwpc

больше 4 лет назад

A flaw was found in the original fix for the netty-codec-http CVE-2021-21409, where the OpenShift Logging openshift-logging/elasticsearch6-rhel8 container was incomplete. The vulnerable netty-codec-http maven package was not removed from the image content. This flaw affects origin-aggregated-logging versions 3.11.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4r7g-8pjm-hmjc

больше 2 лет назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Booking Algorithms BA Book Everything.This issue affects BA Book Everything: from n/a through 1.6.4.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-4r7g-7cpj-5jr7

почти 8 лет назад

Apache Qpid Broker-J vulnerable to Denial of Service (DoS) via uncontrolled resource consumption

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4r7f-wp49-4mv2

больше 3 лет назад

The 404 to Start WordPress plugin through 1.6.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-4r7f-px9v-848g

больше 4 лет назад

HPUX sysdiag allows local users to gain root privileges via a symlink attack during log file creation.

EPSS: Низкий
github логотип

GHSA-4r7f-f866-24h2

больше 4 лет назад

Malicious translator is able to inject JavaScript code in few translatable strings (where HTML is allowed). The code could be executed in the Package manager. This issue affects: OTRS AG OTRS 7.0.x version: 7.0.32 and prior versions, 8.0.x version: 8.0.19 and prior versions.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4r7f-f57c-pgvm

около 1 месяца назад

Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Calculation Manager executes to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Calculation Manager accessible data as well as unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4r7f-8mqg-24xx

больше 1 года назад

OneNav 1.1.0 is vulnerable to Cross Site Scripting (XSS) in custom headers.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4r7f-44rf-3g28

больше 4 лет назад

The IPv6 implementation in the kernel in Apple Mac OS X before 10.6.8 allows local users to cause a denial of service (NULL pointer dereference and reboot) via vectors involving socket options.

EPSS: Низкий
github логотип

GHSA-4r7c-fr6m-vgjf

8 месяцев назад

Improper Control of Generation of Code ('Code Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Code Injection.This issue affects Nelio AB Testing: from n/a through <= 8.1.8.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-4r79-xrp7-h86m

больше 4 лет назад

An issue was discovered in JTBC(PHP) 3.0.1.6. Arbitrary file read operations are possible via a /console/#/console/file/manage.php?type=list&path=c:/ substring.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4r79-wrpg-4jmm

больше 3 лет назад

Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability. This CVE ID is unique from CVE-2023-21677, CVE-2023-21758.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4r79-wc6j-9275

почти 3 года назад

Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to information disclosure by an unauthenticated attacker. Exploitation of this issue does not require user interaction.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4r78-hx75-jjj2

больше 4 лет назад

golang.org/x/net/html has Improper Restriction of Operations within the Bounds of a Memory Buffer

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4r7j-x8fr-p2q2

In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112328051

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4r7h-v53j-c9qw

Improper access control vulnerability in TelephonyUI prior to SMR Jul-2022 Release 1 allows attackers to change preferred network type by unprotected binder call.

CVSS3: 3.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-4r7h-hv98-vx5w

A Unrestricted upload of file with dangerous type vulnerability in meeting management function in Hamastar MeetingHub Paperless Meetings 2021 allows remote authenticated users to perform arbitrary system commands via a crafted ASP file.

CVSS3: 8.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-4r7h-4fx4-6prf

A weakness has been identified in Kohana KodiCMS up to 13.82.135. This affects the function like of the file cms/modules/pages/classes/kodicms/model/page.php of the component Search API Endpoint. Executing manipulation of the argument keyword can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-4r7g-qqxf-m6v8

In the Linux kernel, the following vulnerability has been resolved: USB: hub: Ignore non-compliant devices with too many configs or interfaces Robert Morris created a test program which can cause usb_hub_to_struct_hub() to dereference a NULL or inappropriate pointer: Oops: general protection fault, probably for non-canonical address 0xcccccccccccccccc: 0000 [#1] SMP DEBUG_PAGEALLOC PTI CPU: 7 UID: 0 PID: 117 Comm: kworker/7:1 Not tainted 6.13.0-rc3-00017-gf44d154d6e3d #14 Hardware name: FreeBSD BHYVE/BHYVE, BIOS 14.0 10/17/2021 Workqueue: usb_hub_wq hub_event RIP: 0010:usb_hub_adjust_deviceremovable+0x78/0x110 ... Call Trace: <TASK> ? die_addr+0x31/0x80 ? exc_general_protection+0x1b4/0x3c0 ? asm_exc_general_protection+0x26/0x30 ? usb_hub_adjust_deviceremovable+0x78/0x110 hub_probe+0x7c7/0xab0 usb_probe_interface+0x14b/0x350 really_probe+0xd0/0x2d0 ? __pfx___device_attach_driver+0x10/0x10 __driver_probe_device+0x6e/0x110 driver_probe_device+0x1a/0x90 __device_attach_dr...

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-4r7g-h9xg-7p27

Heap-based buffer overflow in the progressive PNG Image loader (decoders/pngloader.cpp) in KHTML in KDE 4.0.x up to 4.0.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted image.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-4r7g-fj95-jwpc

A flaw was found in the original fix for the netty-codec-http CVE-2021-21409, where the OpenShift Logging openshift-logging/elasticsearch6-rhel8 container was incomplete. The vulnerable netty-codec-http maven package was not removed from the image content. This flaw affects origin-aggregated-logging versions 3.11.

CVSS3: 5.9
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4r7g-8pjm-hmjc

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Booking Algorithms BA Book Everything.This issue affects BA Book Everything: from n/a through 1.6.4.

CVSS3: 8.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4r7g-7cpj-5jr7

Apache Qpid Broker-J vulnerable to Denial of Service (DoS) via uncontrolled resource consumption

CVSS3: 7.5
4%
Низкий
почти 8 лет назад
github логотип
GHSA-4r7f-wp49-4mv2

The 404 to Start WordPress plugin through 1.6.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 4.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4r7f-px9v-848g

HPUX sysdiag allows local users to gain root privileges via a symlink attack during log file creation.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4r7f-f866-24h2

Malicious translator is able to inject JavaScript code in few translatable strings (where HTML is allowed). The code could be executed in the Package manager. This issue affects: OTRS AG OTRS 7.0.x version: 7.0.32 and prior versions, 8.0.x version: 8.0.19 and prior versions.

CVSS3: 5.4
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4r7f-f57c-pgvm

Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Calculation Manager executes to compromise Oracle Hyperion Calculation Manager. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Hyperion Calculation Manager accessible data as well as unauthorized read access to a subset of Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).

CVSS3: 5.4
0%
Низкий
около 1 месяца назад
github логотип
GHSA-4r7f-8mqg-24xx

OneNav 1.1.0 is vulnerable to Cross Site Scripting (XSS) in custom headers.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-4r7f-44rf-3g28

The IPv6 implementation in the kernel in Apple Mac OS X before 10.6.8 allows local users to cause a denial of service (NULL pointer dereference and reboot) via vectors involving socket options.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4r7c-fr6m-vgjf

Improper Control of Generation of Code ('Code Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Code Injection.This issue affects Nelio AB Testing: from n/a through <= 8.1.8.

CVSS3: 9.1
1%
Низкий
8 месяцев назад
github логотип
GHSA-4r79-xrp7-h86m

An issue was discovered in JTBC(PHP) 3.0.1.6. Arbitrary file read operations are possible via a /console/#/console/file/manage.php?type=list&path=c:/ substring.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4r79-wrpg-4jmm

Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability. This CVE ID is unique from CVE-2023-21677, CVE-2023-21758.

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-4r79-wc6j-9275

Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to information disclosure by an unauthenticated attacker. Exploitation of this issue does not require user interaction.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-4r78-hx75-jjj2

golang.org/x/net/html has Improper Restriction of Operations within the Bounds of a Memory Buffer

CVSS3: 7.5
2%
Низкий
больше 4 лет назад

Уязвимостей на страницу