Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-4r53-8549-7m3r

больше 4 лет назад

Envoy before 1.12.1 allows a remote denial of service because of resource loops, as demonstrated by a single idle TCP connection being able to keep a worker thread in an infinite busy loop when continue_on_listener_filters_timeout is used.

EPSS: Низкий
github логотип

GHSA-4r52-wvcw-74vw

больше 4 лет назад

Clustered Data ONTAP versions prior to 9.7P13 and 9.8P3 are susceptible to a vulnerability which could allow single workloads to cause a Denial of Service (DoS) on a cluster node.

EPSS: Низкий
github логотип

GHSA-4r52-jjv6-vvm7

12 дней назад

Information loss or omission in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4r52-fgmg-vqxc

7 месяцев назад

Some HTTP security headers are not properly set by the web server when sending responses to the client application.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4r52-ff3g-g952

больше 4 лет назад

The ath_rate_sample function in the ath_rate/sample/sample.c sample code in MadWifi before 0.9.3 allows remote attackers to cause a denial of service (failed KASSERT and system crash) by moving a connected system to a location with low signal strength, and possibly other vectors related to a race condition between interface enabling and packet transmission.

EPSS: Низкий
github логотип

GHSA-4r4x-7f2r-2f4c

больше 4 лет назад

Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.1.2, 9.0.6, and 8.2.9 suffer from SMB User Authentication Bypass. Nextcloud/ownCloud include an optional and not by default enabled SMB authentication component that allows authenticating users against an SMB server. This backend is implemented in a way that tries to connect to a SMB server and if that succeeded consider the user logged-in. The backend did not properly take into account SMB servers that have any kind of anonymous auth configured. This is the default on SMB servers nowadays and allows an unauthenticated attacker to gain access to an account without valid credentials. Note: The SMB backend is disabled by default and requires manual configuration in the Nextcloud/ownCloud config file. If you have not configured the SMB backend then you're not affected by this vulnerability.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-4r4x-49qh-hfgv

больше 4 лет назад

Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 displays web service tokens associated with (1) disabled services and (2) users who no longer have authorization, which allows remote authenticated users to have an unspecified impact by reading these tokens.

EPSS: Низкий
github логотип

GHSA-4r4w-h2xw-494x

около 1 месяца назад

Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4r4w-cm3v-q4m9

больше 1 года назад

A vulnerability was found in itsourcecode Restaurant Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/member_save.php. The manipulation of the argument last leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4r4w-2wgp-w7cj

3 месяца назад

Open WebUI Prompt history IDOR: unbound history_id allows cross-prompt read and deletion

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-4r4v-x4wj-59wx

больше 3 лет назад

A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in Security Update 2022-003 Catalina, macOS Big Sur 11.6.5, macOS Monterey 12.3. A local user may be able to write arbitrary files.

CVSS3: 5.5
EPSS: Средний
github логотип

GHSA-4r4v-f3wv-mqw2

больше 4 лет назад

A OS Command Injection vulnerability was discovered in Artica Proxy 4.30.000000. Attackers can execute OS commands in cyrus.events.php with GET param logs and POST param rp.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4r4v-5gvp-ww57

больше 4 лет назад

SQL injection vulnerability in welcome.php in AJ Square AJ HYIP PRIME allows remote attackers to execute arbitrary SQL commands via the id parameter.

EPSS: Низкий
github логотип

GHSA-4r4v-5cjx-r22j

больше 4 лет назад

SAP HANA extended application services, version 1, advanced does not sufficiently validate an XML document accepted from an authenticated developer with privileges to the SAP space (XML External Entity vulnerability).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4r4v-4fqg-3m5p

больше 4 лет назад

In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf100283c.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4r4v-3jc5-hrg9

4 месяца назад

TCC-TRANSACTION has an Improper Input Validation vulnerability

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-4r4v-2j2q-ch33

около 2 лет назад

A vulnerability, which was classified as problematic, has been found in yzane vscode-markdown-pdf 1.5.0. Affected by this issue is some unknown functionality of the component Markdown File Handler. The manipulation leads to pathname traversal. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-4r4r-hj2w-xx29

больше 4 лет назад

A low privileged admin account with a weak default password of admin exists on the Foxconn FEMTO AP-FC4064-T AP_GT_B38_5.8.3lb15-W47 LTE Build 15. In addition, its web management page relies on the existence or values of cookies when performing security-critical operations. One can gain privileges by modifying cookies.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4r4r-4jp4-wwf9

7 месяцев назад

FUXA has JWT Authentication Bypass via HTTP Referer header spoofing

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4r4r-44h4-6pmr

8 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Muji muji allows PHP Local File Inclusion.This issue affects Muji: from n/a through <= 1.2.0.

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4r53-8549-7m3r

Envoy before 1.12.1 allows a remote denial of service because of resource loops, as demonstrated by a single idle TCP connection being able to keep a worker thread in an infinite busy loop when continue_on_listener_filters_timeout is used.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4r52-wvcw-74vw

Clustered Data ONTAP versions prior to 9.7P13 and 9.8P3 are susceptible to a vulnerability which could allow single workloads to cause a Denial of Service (DoS) on a cluster node.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4r52-jjv6-vvm7

Information loss or omission in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
0%
Низкий
12 дней назад
github логотип
GHSA-4r52-fgmg-vqxc

Some HTTP security headers are not properly set by the web server when sending responses to the client application.

CVSS3: 6.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-4r52-ff3g-g952

The ath_rate_sample function in the ath_rate/sample/sample.c sample code in MadWifi before 0.9.3 allows remote attackers to cause a denial of service (failed KASSERT and system crash) by moving a connected system to a location with low signal strength, and possibly other vectors related to a race condition between interface enabling and packet transmission.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4r4x-7f2r-2f4c

Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.1.2, 9.0.6, and 8.2.9 suffer from SMB User Authentication Bypass. Nextcloud/ownCloud include an optional and not by default enabled SMB authentication component that allows authenticating users against an SMB server. This backend is implemented in a way that tries to connect to a SMB server and if that succeeded consider the user logged-in. The backend did not properly take into account SMB servers that have any kind of anonymous auth configured. This is the default on SMB servers nowadays and allows an unauthenticated attacker to gain access to an account without valid credentials. Note: The SMB backend is disabled by default and requires manual configuration in the Nextcloud/ownCloud config file. If you have not configured the SMB backend then you're not affected by this vulnerability.

CVSS3: 8.1
4%
Низкий
больше 4 лет назад
github логотип
GHSA-4r4x-49qh-hfgv

Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 displays web service tokens associated with (1) disabled services and (2) users who no longer have authorization, which allows remote authenticated users to have an unspecified impact by reading these tokens.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4r4w-h2xw-494x

Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.

CVSS3: 5.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-4r4w-cm3v-q4m9

A vulnerability was found in itsourcecode Restaurant Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/member_save.php. The manipulation of the argument last leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

CVSS3: 7.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-4r4w-2wgp-w7cj

Open WebUI Prompt history IDOR: unbound history_id allows cross-prompt read and deletion

CVSS3: 6.4
0%
Низкий
3 месяца назад
github логотип
GHSA-4r4v-x4wj-59wx

A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in Security Update 2022-003 Catalina, macOS Big Sur 11.6.5, macOS Monterey 12.3. A local user may be able to write arbitrary files.

CVSS3: 5.5
18%
Средний
больше 3 лет назад
github логотип
GHSA-4r4v-f3wv-mqw2

A OS Command Injection vulnerability was discovered in Artica Proxy 4.30.000000. Attackers can execute OS commands in cyrus.events.php with GET param logs and POST param rp.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4r4v-5gvp-ww57

SQL injection vulnerability in welcome.php in AJ Square AJ HYIP PRIME allows remote attackers to execute arbitrary SQL commands via the id parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4r4v-5cjx-r22j

SAP HANA extended application services, version 1, advanced does not sufficiently validate an XML document accepted from an authenticated developer with privileges to the SAP space (XML External Entity vulnerability).

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4r4v-4fqg-3m5p

In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf100283c.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4r4v-3jc5-hrg9

TCC-TRANSACTION has an Improper Input Validation vulnerability

CVSS3: 6.3
0%
Низкий
4 месяца назад
github логотип
GHSA-4r4v-2j2q-ch33

A vulnerability, which was classified as problematic, has been found in yzane vscode-markdown-pdf 1.5.0. Affected by this issue is some unknown functionality of the component Markdown File Handler. The manipulation leads to pathname traversal. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

CVSS3: 3.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-4r4r-hj2w-xx29

A low privileged admin account with a weak default password of admin exists on the Foxconn FEMTO AP-FC4064-T AP_GT_B38_5.8.3lb15-W47 LTE Build 15. In addition, its web management page relies on the existence or values of cookies when performing security-critical operations. One can gain privileges by modifying cookies.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4r4r-4jp4-wwf9

FUXA has JWT Authentication Bypass via HTTP Referer header spoofing

CVSS3: 9.8
6%
Низкий
7 месяцев назад
github логотип
GHSA-4r4r-44h4-6pmr

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Muji muji allows PHP Local File Inclusion.This issue affects Muji: from n/a through <= 1.2.0.

CVSS3: 8.1
1%
Низкий
8 месяцев назад

Уязвимостей на страницу