Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-4r2r-f9mj-hf53

больше 4 лет назад

examples/framework/news/news3.py in Kiwi 1.9.22 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4r2r-cf85-vmc7

почти 3 года назад

A vulnerability has been identified in the Node.js (.msi version) installation process, specifically affecting Windows users who install Node.js using the .msi installer. This vulnerability emerges during the repair operation, where the "msiexec.exe" process, running under the NT AUTHORITY\SYSTEM context, attempts to read the %USERPROFILE% environment variable from the current user's registry. The issue arises when the path referenced by the %USERPROFILE% environment variable does not exist. In such cases, the "msiexec.exe" process attempts to create the specified path in an unsafe manner, potentially leading to the creation of arbitrary folders in arbitrary locations. The severity of this vulnerability is heightened by the fact that the %USERPROFILE% environment variable in the Windows registry can be modified by standard (or "non-privileged") users. Consequently, unprivileged actors, including malicious entities or trojans, can manipulate the environment variable key to deceive ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4r2q-mgcp-7w6w

больше 4 лет назад

Xen 4.0 and 4.1 allows local HVM guest OS kernels to cause a denial of service (domain 0 VCPU hang and kernel panic) by modifying the physical address space in a way that triggers excessive shared page search time during the p2m teardown.

EPSS: Низкий
github логотип

GHSA-4r2q-5ff4-r8pg

больше 4 лет назад

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D3600 before 1.0.0.75, D6000 before 1.0.0.75, D6100 before 1.0.0.60, R7800 before 1.0.2.52, R8900 before 1.0.4.2, R9000 before 1.0.4.2, WNDR3700v4 before 1.0.2.102, WNDR4300 before 1.0.2.104, WNDR4300v2 before 1.0.0.58, WNDR4500v3 before 1.0.0.58, and WNR2000v5 before 1.0.0.66.

EPSS: Низкий
github логотип

GHSA-4r2p-wpv5-683w

больше 4 лет назад

Moodle XSS Vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4r2p-352m-7q6g

почти 4 года назад

The kernel server has a vulnerability of not verifying the length of the data transferred in the user space.Successful exploitation of this vulnerability may cause out-of-bounds read in the kernel, which affects the device confidentiality and availability.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4r2p-27mh-5m22

около 2 месяцев назад

Open WebUI: Stored web worker XSS via Pyodide

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4r2j-8c42-5wfc

3 месяца назад

Server side template inject (SSTI) in the expression evaluation component in Genshi Template Engine version 0.7.9 allows a remote attacker to achieve remote code execution (RCE) via crafted template expressions.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4r2j-6r55-j9g2

почти 2 года назад

Netgear XR300 v1.0.3.78 was discovered to contain a command injection vulnerability in the system_name parameter at genie_dyn.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-4r2h-p7qv-cxcx

больше 4 лет назад

Microsoft Office 2016 allows a remote code execution vulnerability when it fails to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8631, CVE-2017-8632, and CVE-2017-8744.

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-4r2h-m6wp-gxg9

4 месяца назад

A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via a second client connection while changing those counters. This may be used to crash the server, or for privilege escalation if the X server runs as root.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4r2h-hc45-gpwj

больше 4 лет назад

SQL injection vulnerability in index.php in Community CMS 0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

EPSS: Низкий
github логотип

GHSA-4r2g-j5rc-7wqf

больше 4 лет назад

A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the `driver->nwfilters` mutex before iterating over virNWFilterObj instances. There was no protection to stop another thread from concurrently modifying the `driver->nwfilters` object. This flaw allows a malicious, unprivileged user to exploit this issue via libvirt’s API virConnectNumOfNWFilters to crash the network filter management daemon (libvirtd/virtnwfilterd).

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4r2g-6q9v-69ff

больше 4 лет назад

Microsoft ActiveSync 4.1, as used in Windows Mobile 5.0, uses weak encryption (XOR obfuscation with a fixed key) when sending the user's PIN/Password over the USB connection from the host to the device, which might make it easier for attackers to decode a PIN/Password obtained by (1) sniffing or (2) spoofing the docking process.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-4r2f-6fm9-2qgh

больше 3 лет назад

Duplicate Advisory: Ecto lacks a protection mechanism

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4r2f-37c7-gqhr

больше 4 лет назад

Unspecified vulnerability in Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code via a crafted Cascading Style Sheets (CSS) tag that triggers memory corruption.

EPSS: Средний
github логотип

GHSA-4r2c-8h46-hvf9

больше 4 лет назад

NullSoft Winamp 5.02 allows remote attackers to cause a denial of service (crash) by creating a file with a long filename, which causes the victim's player to crash when the file is opened from the command line.

EPSS: Низкий
github логотип

GHSA-4r29-8mxj-xp6m

больше 4 лет назад

Off-by-one error in the inflate function in mszipd.c in libmspack before 0.5 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted CAB archive.

EPSS: Низкий
github логотип

GHSA-4r29-3qq2-w2vw

10 месяцев назад

Emlog Pro 2.5.20 has an arbitrary file deletion vulnerability. This vulnerability stems from the admin/template.php component and the admin/plugin.php component. They fail to perform path verification and dangerous code filtering for deletion parameters, allowing attackers to exploit this feature for directory traversal.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4r29-2h26-2x44

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: coresight: syscfg: Fix memleak on registration failure in cscfg_create_device device_register() calls device_initialize(), according to doc of device_initialize: Use put_device() to give up your reference instead of freeing * @dev directly once you have called this function. To prevent potential memleak, use put_device() for error handling.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4r2r-f9mj-hf53

examples/framework/news/news3.py in Kiwi 1.9.22 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4r2r-cf85-vmc7

A vulnerability has been identified in the Node.js (.msi version) installation process, specifically affecting Windows users who install Node.js using the .msi installer. This vulnerability emerges during the repair operation, where the "msiexec.exe" process, running under the NT AUTHORITY\SYSTEM context, attempts to read the %USERPROFILE% environment variable from the current user's registry. The issue arises when the path referenced by the %USERPROFILE% environment variable does not exist. In such cases, the "msiexec.exe" process attempts to create the specified path in an unsafe manner, potentially leading to the creation of arbitrary folders in arbitrary locations. The severity of this vulnerability is heightened by the fact that the %USERPROFILE% environment variable in the Windows registry can be modified by standard (or "non-privileged") users. Consequently, unprivileged actors, including malicious entities or trojans, can manipulate the environment variable key to deceive ...

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-4r2q-mgcp-7w6w

Xen 4.0 and 4.1 allows local HVM guest OS kernels to cause a denial of service (domain 0 VCPU hang and kernel panic) by modifying the physical address space in a way that triggers excessive shared page search time during the p2m teardown.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4r2q-5ff4-r8pg

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D3600 before 1.0.0.75, D6000 before 1.0.0.75, D6100 before 1.0.0.60, R7800 before 1.0.2.52, R8900 before 1.0.4.2, R9000 before 1.0.4.2, WNDR3700v4 before 1.0.2.102, WNDR4300 before 1.0.2.104, WNDR4300v2 before 1.0.0.58, WNDR4500v3 before 1.0.0.58, and WNR2000v5 before 1.0.0.66.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4r2p-wpv5-683w

Moodle XSS Vulnerability

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4r2p-352m-7q6g

The kernel server has a vulnerability of not verifying the length of the data transferred in the user space.Successful exploitation of this vulnerability may cause out-of-bounds read in the kernel, which affects the device confidentiality and availability.

CVSS3: 7.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-4r2p-27mh-5m22

Open WebUI: Stored web worker XSS via Pyodide

CVSS3: 7.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-4r2j-8c42-5wfc

Server side template inject (SSTI) in the expression evaluation component in Genshi Template Engine version 0.7.9 allows a remote attacker to achieve remote code execution (RCE) via crafted template expressions.

CVSS3: 9.8
1%
Низкий
3 месяца назад
github логотип
GHSA-4r2j-6r55-j9g2

Netgear XR300 v1.0.3.78 was discovered to contain a command injection vulnerability in the system_name parameter at genie_dyn.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.

CVSS3: 8
2%
Низкий
почти 2 года назад
github логотип
GHSA-4r2h-p7qv-cxcx

Microsoft Office 2016 allows a remote code execution vulnerability when it fails to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8631, CVE-2017-8632, and CVE-2017-8744.

CVSS3: 7.8
21%
Средний
больше 4 лет назад
github логотип
GHSA-4r2h-m6wp-gxg9

A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via a second client connection while changing those counters. This may be used to crash the server, or for privilege escalation if the X server runs as root.

CVSS3: 7.8
0%
Низкий
4 месяца назад
github логотип
GHSA-4r2h-hc45-gpwj

SQL injection vulnerability in index.php in Community CMS 0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4r2g-j5rc-7wqf

A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the `driver->nwfilters` mutex before iterating over virNWFilterObj instances. There was no protection to stop another thread from concurrently modifying the `driver->nwfilters` object. This flaw allows a malicious, unprivileged user to exploit this issue via libvirt’s API virConnectNumOfNWFilters to crash the network filter management daemon (libvirtd/virtnwfilterd).

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4r2g-6q9v-69ff

Microsoft ActiveSync 4.1, as used in Windows Mobile 5.0, uses weak encryption (XOR obfuscation with a fixed key) when sending the user's PIN/Password over the USB connection from the host to the device, which might make it easier for attackers to decode a PIN/Password obtained by (1) sniffing or (2) spoofing the docking process.

CVSS3: 4.6
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4r2f-6fm9-2qgh

Duplicate Advisory: Ecto lacks a protection mechanism

CVSS3: 9.8
больше 3 лет назад
github логотип
GHSA-4r2f-37c7-gqhr

Unspecified vulnerability in Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code via a crafted Cascading Style Sheets (CSS) tag that triggers memory corruption.

31%
Средний
больше 4 лет назад
github логотип
GHSA-4r2c-8h46-hvf9

NullSoft Winamp 5.02 allows remote attackers to cause a denial of service (crash) by creating a file with a long filename, which causes the victim's player to crash when the file is opened from the command line.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4r29-8mxj-xp6m

Off-by-one error in the inflate function in mszipd.c in libmspack before 0.5 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted CAB archive.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4r29-3qq2-w2vw

Emlog Pro 2.5.20 has an arbitrary file deletion vulnerability. This vulnerability stems from the admin/template.php component and the admin/plugin.php component. They fail to perform path verification and dangerous code filtering for deletion parameters, allowing attackers to exploit this feature for directory traversal.

CVSS3: 6.5
1%
Низкий
10 месяцев назад
github логотип
GHSA-4r29-2h26-2x44

In the Linux kernel, the following vulnerability has been resolved: coresight: syscfg: Fix memleak on registration failure in cscfg_create_device device_register() calls device_initialize(), according to doc of device_initialize: Use put_device() to give up your reference instead of freeing * @dev directly once you have called this function. To prevent potential memleak, use put_device() for error handling.

CVSS3: 5.5
0%
Низкий
больше 1 года назад

Уязвимостей на страницу