Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-4qqg-wwj3-fxwq

4 месяца назад

A flaw has been found in itsourcecode Fees Management System 1.0. The impacted element is an unknown function of the file /manage_fee.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-4qqg-r6qm-rxgh

больше 4 лет назад

In getUiccCardsInfo of PhoneInterfaceManager.java, there is a possible permissions bypass due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-146570216

EPSS: Низкий
github логотип

GHSA-4qqg-m5c4-9c3g

больше 4 лет назад

Integer underflow in the visual_read function in wiretap/visual.c in Wireshark 1.2.x before 1.2.17 and 1.4.x before 1.4.7 allows remote attackers to cause a denial of service (application crash) via a malformed Visual Networks file that triggers a heap-based buffer over-read.

EPSS: Низкий
github логотип

GHSA-4qqg-523q-3vhc

около 3 лет назад

A vulnerability classified as critical was found in SourceCodester Simple Membership System 1.0. Affected by this vulnerability is an unknown functionality of the file club_validator.php. The manipulation of the argument club leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-239869 was assigned to this vulnerability.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-4qqf-xjmf-3h2v

больше 4 лет назад

Use of password hash with insufficient computational effort vulnerability in QSAN Storage Manager, XEVO, SANOS allows remote attackers to recover the plain-text password by brute-forcing the MD5 hash.

EPSS: Низкий
github логотип

GHSA-4qqf-vxv4-9698

больше 4 лет назад

Stack-based buffer overflow in the nestlex function in nestlex.c in Socat 1.5.0.0 through 1.7.1.2 and 2.0.0-b1 through 2.0.0-b3, when bidirectional data relay is enabled, allows context-dependent attackers to execute arbitrary code via long command-line arguments.

EPSS: Низкий
github логотип

GHSA-4qqf-hmv6-r6wh

больше 4 лет назад

Use of a Broken or Risky Cryptographic Algorithm in Apache WSS4J

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4qqf-9m5c-w2c5

больше 1 года назад

Weblate exposes personal IP address via e-mail

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4qqc-mp5f-ccv4

около 6 лет назад

Command Injection in bestzip

EPSS: Низкий
github логотип

GHSA-4qq9-rrq6-48ff

больше 7 лет назад

Cross site scripting in org.apache.nifi:nifi

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4qq9-qg7j-fcm9

больше 4 лет назад

Dolibarr Cross-Site Request Forgery (CSRF)

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-4qq8-xmrv-9779

около 1 года назад

Out-of-bounds array access issue due to insufficient data verification in the kernel ambient light module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-4qq8-w9wg-4qw8

больше 4 лет назад

The tjLoadImage function in libjpeg-turbo 2.0.1 has an integer overflow with a resultant heap-based buffer overflow via a BMP image because multiplication of pitch and height is mishandled, as demonstrated by tjbench.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4qq8-w3q5-56jf

больше 2 лет назад

Missing authorization vulnerability exists in Unifier and Unifier Cast Version.5.0 or later, and the patch "20240527" not applied. If this vulnerability is exploited, arbitrary code may be executed with LocalSystem privilege. As a result, a malicious program may be installed, data may be modified or deleted.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4qq8-cxv5-977h

больше 4 лет назад

The Mozilla Maintenance Service updater in Mozilla Firefox before 46.0 on Windows allows user-assisted remote attackers to delete arbitrary files by leveraging certain local file execution.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4qq8-38mm-j7jf

больше 4 лет назад

Stack-based buffer overflow in Pegasus Mail (PMail) 4.41 and possibly 4.51 allows remote POP3 servers to cause a denial of service (application crash) or possibly execute arbitrary code via a long error message.

EPSS: Низкий
github логотип

GHSA-4qq7-wjm7-pqjr

больше 4 лет назад

Microsoft Word 2003 SP3, 2007 SP3, and 2010 SP1; Office Compatibility Pack SP3; and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability."

EPSS: Средний
github логотип

GHSA-4qq7-cgf7-vrf3

больше 4 лет назад

There is Sensitive Information in Cloudera Manager before 5.4.6 Diagnostic Support Bundles.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4qq6-r634-f5m4

больше 4 лет назад

The HVMOP_set_mem_type control in Xen 4.1 through 4.4.x allows local guest HVM administrators to cause a denial of service (hypervisor crash) or possibly execute arbitrary code by leveraging a separate qemu-dm vulnerability to trigger invalid page table translations for unspecified memory page types.

EPSS: Низкий
github логотип

GHSA-4qq6-2mx2-7x37

больше 4 лет назад

Open redirect vulnerability in ui/dynamic/unsecured.html in Linksys EA6500 with firmware 1.1.28.147876 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the target parameter.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4qqg-wwj3-fxwq

A flaw has been found in itsourcecode Fees Management System 1.0. The impacted element is an unknown function of the file /manage_fee.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used.

CVSS3: 6.3
0%
Низкий
4 месяца назад
github логотип
GHSA-4qqg-r6qm-rxgh

In getUiccCardsInfo of PhoneInterfaceManager.java, there is a possible permissions bypass due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-146570216

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4qqg-m5c4-9c3g

Integer underflow in the visual_read function in wiretap/visual.c in Wireshark 1.2.x before 1.2.17 and 1.4.x before 1.4.7 allows remote attackers to cause a denial of service (application crash) via a malformed Visual Networks file that triggers a heap-based buffer over-read.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4qqg-523q-3vhc

A vulnerability classified as critical was found in SourceCodester Simple Membership System 1.0. Affected by this vulnerability is an unknown functionality of the file club_validator.php. The manipulation of the argument club leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-239869 was assigned to this vulnerability.

CVSS3: 6.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-4qqf-xjmf-3h2v

Use of password hash with insufficient computational effort vulnerability in QSAN Storage Manager, XEVO, SANOS allows remote attackers to recover the plain-text password by brute-forcing the MD5 hash.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4qqf-vxv4-9698

Stack-based buffer overflow in the nestlex function in nestlex.c in Socat 1.5.0.0 through 1.7.1.2 and 2.0.0-b1 through 2.0.0-b3, when bidirectional data relay is enabled, allows context-dependent attackers to execute arbitrary code via long command-line arguments.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4qqf-hmv6-r6wh

Use of a Broken or Risky Cryptographic Algorithm in Apache WSS4J

CVSS3: 5.9
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4qqf-9m5c-w2c5

Weblate exposes personal IP address via e-mail

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-4qqc-mp5f-ccv4

Command Injection in bestzip

около 6 лет назад
github логотип
GHSA-4qq9-rrq6-48ff

Cross site scripting in org.apache.nifi:nifi

CVSS3: 6.1
3%
Низкий
больше 7 лет назад
github логотип
GHSA-4qq9-qg7j-fcm9

Dolibarr Cross-Site Request Forgery (CSRF)

CVSS3: 8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4qq8-xmrv-9779

Out-of-bounds array access issue due to insufficient data verification in the kernel ambient light module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS3: 6.6
0%
Низкий
около 1 года назад
github логотип
GHSA-4qq8-w9wg-4qw8

The tjLoadImage function in libjpeg-turbo 2.0.1 has an integer overflow with a resultant heap-based buffer overflow via a BMP image because multiplication of pitch and height is mishandled, as demonstrated by tjbench.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4qq8-w3q5-56jf

Missing authorization vulnerability exists in Unifier and Unifier Cast Version.5.0 or later, and the patch "20240527" not applied. If this vulnerability is exploited, arbitrary code may be executed with LocalSystem privilege. As a result, a malicious program may be installed, data may be modified or deleted.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4qq8-cxv5-977h

The Mozilla Maintenance Service updater in Mozilla Firefox before 46.0 on Windows allows user-assisted remote attackers to delete arbitrary files by leveraging certain local file execution.

CVSS3: 5.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4qq8-38mm-j7jf

Stack-based buffer overflow in Pegasus Mail (PMail) 4.41 and possibly 4.51 allows remote POP3 servers to cause a denial of service (application crash) or possibly execute arbitrary code via a long error message.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-4qq7-wjm7-pqjr

Microsoft Word 2003 SP3, 2007 SP3, and 2010 SP1; Office Compatibility Pack SP3; and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability."

20%
Средний
больше 4 лет назад
github логотип
GHSA-4qq7-cgf7-vrf3

There is Sensitive Information in Cloudera Manager before 5.4.6 Diagnostic Support Bundles.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4qq6-r634-f5m4

The HVMOP_set_mem_type control in Xen 4.1 through 4.4.x allows local guest HVM administrators to cause a denial of service (hypervisor crash) or possibly execute arbitrary code by leveraging a separate qemu-dm vulnerability to trigger invalid page table translations for unspecified memory page types.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4qq6-2mx2-7x37

Open redirect vulnerability in ui/dynamic/unsecured.html in Linksys EA6500 with firmware 1.1.28.147876 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the target parameter.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу