Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-4q9q-728x-j7v5

больше 4 лет назад

An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c is vulnerable to an off-by-one error caused by malicious server responses, leading to DoS or possibly unspecified other impact.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4q9p-mqc7-6hw7

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in search.php in CMS Faethon 2.2 Ultimate allows remote attackers to inject arbitrary web script or HTML via the what parameter. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-4q9j-rxq5-9m9j

больше 4 лет назад

An issue was discovered in MK-AUTH 19.01. There are SQL injection issues in mkt/ PHP scripts, as demonstrated by arp.php, dhcp.php, hotspot.php, ip.php, pgaviso.php, pgcorte.php, pppoe.php, queues.php, and wifi.php.

EPSS: Низкий
github логотип

GHSA-4q9j-c8xc-j26g

больше 4 лет назад

Windows 2000, XP, and Server 2003 does not properly "validate the use of memory regions" for COM structured storage files, which allows attackers to execute arbitrary code, aka the "COM Structured Storage Vulnerability."

EPSS: Низкий
github логотип

GHSA-4q9j-6299-gxmr

3 месяца назад

Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth

EPSS: Низкий
github логотип

GHSA-4q9j-5567-rg22

больше 1 года назад

Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the funcpara1 parameter in the formSetCfm function.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-4q9h-rhrc-98f3

больше 2 лет назад

D-Link DAP-2622 DDP Set Date-Time NTP Server Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the DDP service. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-20085.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4q9h-j8g6-f49h

10 месяцев назад

KissFFT versions prior to the fix commit 1b083165 contain an integer overflow in kiss_fft_alloc() in kiss_fft.c on platforms where size_t is 32-bit. The nfft parameter is not validated before being used in a size calculation (sizeof(kiss_fft_cpx) * (nfft - 1)), which can wrap to a small value when nfft is large. As a result, malloc() allocates an undersized buffer and the subsequent twiddle-factor initialization loop writes nfft elements, causing a heap buffer overflow. This vulnerability only affects 32-bit architectures.

EPSS: Низкий
github логотип

GHSA-4q9h-f32p-4hpq

больше 4 лет назад

The mintToken function of a smart contract implementation for AppleToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4q9h-crq4-9xjq

6 месяцев назад

A vulnerability has been found in gougucms 4.08.18. This affects the function reg_submit of the file gougucms-master\app\home\controller\Login.php of the component User Registration Handler. Such manipulation of the argument level leads to dynamically-determined object attributes. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-4q9g-wrwc-6wc5

12 месяцев назад

Memory corruption while processing escape commands from userspace.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4q9g-gjc2-2pf4

больше 4 лет назад

Double-free vulnerability in the sPLT chunk structure and png.c in pngcrush before 1.7.87 allows attackers to have unspecified impact via unknown vectors.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4q9f-hqxm-8fcg

больше 4 лет назад

Unspecified vulnerability in the CoreServices daemon in CarbonCore in Apple Mac OS X 10.4 through 10.4.9 allows local users to gain privileges via unspecified vectors involving "obtaining a send right to [the] Mach task port."

EPSS: Низкий
github логотип

GHSA-4q9f-cg77-mm2c

2 месяца назад

Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4q9f-96v5-4x47

больше 4 лет назад

Stack-based buffer overflow in NodeManager Professional 2.00 allows remote attackers to execute arbitrary commands via a LinkDown-Trap packet that contains a long OCTET-STRING in the Trap variable-bindings field.

EPSS: Низкий
github логотип

GHSA-4q9c-rhf4-v5c8

больше 4 лет назад

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing the SENDACTIONFRAME IOCTL, a buffer over-read can occur if the payload length is less than 7.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4q9c-mwqm-w5g3

больше 4 лет назад

Perlbal before 1.70, when buffered upload is enabled, allows remote attackers to cause a denial of service (crash) via a zero-byte chunked upload.

EPSS: Низкий
github логотип

GHSA-4q9c-h5m8-8ffp

больше 4 лет назад

The export_data function of the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4 had no capability or nonce checks making it possible for unauthenticated users to export a site's redirects.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4q9c-fvpx-pq67

больше 4 лет назад

deepin-clone before 1.1.3 uses a fixed path /tmp/repo.iso in the BootDoctor::fix() function to download an ISO file, and follows symlinks there. An unprivileged user can prepare a symlink attack there to create or overwrite files in arbitrary file system locations. The content is not attacker controlled. By winning a race condition to replace the /tmp/repo.iso symlink by an attacker controlled ISO file, further privilege escalation may be possible.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-4q9c-cjp5-mvrv

больше 4 лет назад

Vulnerability in the Application Management Pack for Oracle E-Business Suite component of Oracle E-Business Suite (subcomponent: User Monitoring). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Application Management Pack for Oracle E-Business Suite. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Application Management Pack for Oracle E-Business Suite accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVSS3: 5.3
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4q9q-728x-j7v5

An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c is vulnerable to an off-by-one error caused by malicious server responses, leading to DoS or possibly unspecified other impact.

CVSS3: 9.8
5%
Низкий
больше 4 лет назад
github логотип
GHSA-4q9p-mqc7-6hw7

Cross-site scripting (XSS) vulnerability in search.php in CMS Faethon 2.2 Ultimate allows remote attackers to inject arbitrary web script or HTML via the what parameter. NOTE: some of these details are obtained from third party information.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4q9j-rxq5-9m9j

An issue was discovered in MK-AUTH 19.01. There are SQL injection issues in mkt/ PHP scripts, as demonstrated by arp.php, dhcp.php, hotspot.php, ip.php, pgaviso.php, pgcorte.php, pppoe.php, queues.php, and wifi.php.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4q9j-c8xc-j26g

Windows 2000, XP, and Server 2003 does not properly "validate the use of memory regions" for COM structured storage files, which allows attackers to execute arbitrary code, aka the "COM Structured Storage Vulnerability."

4%
Низкий
больше 4 лет назад
github логотип
GHSA-4q9j-6299-gxmr

Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth

0%
Низкий
3 месяца назад
github логотип
GHSA-4q9j-5567-rg22

Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the funcpara1 parameter in the formSetCfm function.

CVSS3: 5.7
1%
Низкий
больше 1 года назад
github логотип
GHSA-4q9h-rhrc-98f3

D-Link DAP-2622 DDP Set Date-Time NTP Server Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the DDP service. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-20085.

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4q9h-j8g6-f49h

KissFFT versions prior to the fix commit 1b083165 contain an integer overflow in kiss_fft_alloc() in kiss_fft.c on platforms where size_t is 32-bit. The nfft parameter is not validated before being used in a size calculation (sizeof(kiss_fft_cpx) * (nfft - 1)), which can wrap to a small value when nfft is large. As a result, malloc() allocates an undersized buffer and the subsequent twiddle-factor initialization loop writes nfft elements, causing a heap buffer overflow. This vulnerability only affects 32-bit architectures.

0%
Низкий
10 месяцев назад
github логотип
GHSA-4q9h-f32p-4hpq

The mintToken function of a smart contract implementation for AppleToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4q9h-crq4-9xjq

A vulnerability has been found in gougucms 4.08.18. This affects the function reg_submit of the file gougucms-master\app\home\controller\Login.php of the component User Registration Handler. Such manipulation of the argument level leads to dynamically-determined object attributes. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-4q9g-wrwc-6wc5

Memory corruption while processing escape commands from userspace.

CVSS3: 7.8
0%
Низкий
12 месяцев назад
github логотип
GHSA-4q9g-gjc2-2pf4

Double-free vulnerability in the sPLT chunk structure and png.c in pngcrush before 1.7.87 allows attackers to have unspecified impact via unknown vectors.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4q9f-hqxm-8fcg

Unspecified vulnerability in the CoreServices daemon in CarbonCore in Apple Mac OS X 10.4 through 10.4.9 allows local users to gain privileges via unspecified vectors involving "obtaining a send right to [the] Mach task port."

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4q9f-cg77-mm2c

Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

CVSS3: 7.5
0%
Низкий
2 месяца назад
github логотип
GHSA-4q9f-96v5-4x47

Stack-based buffer overflow in NodeManager Professional 2.00 allows remote attackers to execute arbitrary commands via a LinkDown-Trap packet that contains a long OCTET-STRING in the Trap variable-bindings field.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-4q9c-rhf4-v5c8

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing the SENDACTIONFRAME IOCTL, a buffer over-read can occur if the payload length is less than 7.

CVSS3: 5.3
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4q9c-mwqm-w5g3

Perlbal before 1.70, when buffered upload is enabled, allows remote attackers to cause a denial of service (crash) via a zero-byte chunked upload.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4q9c-h5m8-8ffp

The export_data function of the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4 had no capability or nonce checks making it possible for unauthenticated users to export a site's redirects.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4q9c-fvpx-pq67

deepin-clone before 1.1.3 uses a fixed path /tmp/repo.iso in the BootDoctor::fix() function to download an ISO file, and follows symlinks there. An unprivileged user can prepare a symlink attack there to create or overwrite files in arbitrary file system locations. The content is not attacker controlled. By winning a race condition to replace the /tmp/repo.iso symlink by an attacker controlled ISO file, further privilege escalation may be possible.

CVSS3: 4.7
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4q9c-cjp5-mvrv

Vulnerability in the Application Management Pack for Oracle E-Business Suite component of Oracle E-Business Suite (subcomponent: User Monitoring). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Application Management Pack for Oracle E-Business Suite. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Application Management Pack for Oracle E-Business Suite accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVSS3: 5.3
17%
Средний
больше 4 лет назад

Уязвимостей на страницу