Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 374 825

Количество 374 825

github логотип

GHSA-4ph9-3c4q-r2hh

4 месяца назад

Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4ph8-r85v-ggp6

больше 4 лет назад

A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-1010, CVE-2018-1013, CVE-2018-1015, CVE-2018-1016.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-4ph7-5c44-pppv

больше 4 лет назад

kajam allows local users to obtain sensitive information by listing the process

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4ph6-v858-6wh9

больше 4 лет назад

huft_build in archival/libarchive/decompress_gunzip.c in BusyBox before 1.27.2 misuses a pointer, causing segfaults and an application crash during an unzip operation on a specially crafted ZIP file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4ph6-mjv7-3fq6

25 дней назад

netfoil vulnerable to improper handling of untrusted DoH response data

EPSS: Низкий
github логотип

GHSA-4ph6-9589-22h5

больше 4 лет назад

Haakon Nilsen Simple Internet Publishing System (SIPS) 0.2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain password and other user information via a direct request to a user-specific configuration directory.

EPSS: Низкий
github логотип

GHSA-4ph5-83mw-vm42

4 месяца назад

A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing the screen saver, leading to information disclosure.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4ph5-3333-xv3f

больше 4 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier and 6 Update 35 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.

EPSS: Низкий
github логотип

GHSA-4ph4-q9r5-6wm6

больше 4 лет назад

Deserialization of Untrusted Data in Spring Batch

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-4ph4-gqf8-q98f

больше 4 лет назад

Directory traversal vulnerability in shopsessionsubs.asp in Rocksalt International VP-ASP Shopping Cart 6.50 and earlier might allow remote attackers to determine the existence of arbitrary files via directory traversal sequences in the client's DNS hostname (aka the REMOTE_HOST variable), related to the CookielessGenerateFilename and CookielessReadFile functions.

EPSS: Низкий
github логотип

GHSA-4ph4-7xqm-67v8

около 3 лет назад

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CRUDLab Jazz Popups plugin <= 1.8.7 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4ph4-5rpm-wrw9

около 2 месяцев назад

The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disabled for the targeted account, allowing an unauthenticated attacker to obtain a valid authentication session as that account, including an administrator, by naming its login in a single registration request.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-4ph3-v6j7-j4pw

6 месяцев назад

A weakness has been identified in PHPGurukul Online Shopping Portal Project 2.1. This issue affects some unknown processing of the file /sub-category.php of the component Parameter Handler. This manipulation of the argument pid causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-4ph3-7qqh-5h7g

больше 2 лет назад

In ss_SendCallBarringPwdRequiredIndMsg of ss_CallBarring.c, there is a possible null pointer deref due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4ph2-f6pf-79wv

5 месяцев назад

PraisonAI Has Arbitrary File Write (Zip Slip) in Templates Extraction

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-4ph2-c8x7-g842

больше 4 лет назад

D-Link DIR-601 B1 2.00NA devices are vulnerable to authentication bypass. They do not check for authentication at the server side and rely on client-side validation, which is bypassable. NOTE: this is an end-of-life product.

EPSS: Низкий
github логотип

GHSA-4ph2-8337-hm62

больше 5 лет назад

Key Caching behavior in the DynamoDB Encryption Client.

EPSS: Низкий
github логотип

GHSA-4pgx-8hjp-cmmq

22 дня назад

openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the portable USB drive feature, whose threat model treats the removable drive as untrusted (attacker with physical write access). USBDriveCreator._verify_integrity_file only validates files listed in the manifest, so files added to the drive — including a root-level autorun payload — are not detected and integrity verification still passes. Additionally, a globally constant, source-embedded KDF salt (_LEGACY_FIXED_SALT) is used to derive the drive encryption key for any drive lacking a per-drive salt file, defeating precomputation resistance and enabling an offline rainbow-table attack.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-4pgv-p58j-ghpx

больше 2 лет назад

Apport argument parsing mishandles filename splitting on older kernels resulting in argument spoofing

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4pgr-wr6g-rxf6

22 дня назад

When the ClickHouse plugin uses Native protocol (the default) with PDC or secure SOCKS, it asks for TLS but the connection library ignores that and talks to ClickHouse in the clear. Username, password, queries, and results can be read on the hop after the proxy. The server certificate is never checked, and a configured client certificate is not sent.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4ph9-3c4q-r2hh

Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.

CVSS3: 7.5
0%
Низкий
4 месяца назад
github логотип
GHSA-4ph8-r85v-ggp6

A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-1010, CVE-2018-1013, CVE-2018-1015, CVE-2018-1016.

CVSS3: 8.8
24%
Средний
больше 4 лет назад
github логотип
GHSA-4ph7-5c44-pppv

kajam allows local users to obtain sensitive information by listing the process

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4ph6-v858-6wh9

huft_build in archival/libarchive/decompress_gunzip.c in BusyBox before 1.27.2 misuses a pointer, causing segfaults and an application crash during an unzip operation on a specially crafted ZIP file.

CVSS3: 5.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4ph6-mjv7-3fq6

netfoil vulnerable to improper handling of untrusted DoH response data

25 дней назад
github логотип
GHSA-4ph6-9589-22h5

Haakon Nilsen Simple Internet Publishing System (SIPS) 0.2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain password and other user information via a direct request to a user-specific configuration directory.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4ph5-83mw-vm42

A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing the screen saver, leading to information disclosure.

CVSS3: 5.5
0%
Низкий
4 месяца назад
github логотип
GHSA-4ph5-3333-xv3f

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier and 6 Update 35 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-4ph4-q9r5-6wm6

Deserialization of Untrusted Data in Spring Batch

CVSS3: 8.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4ph4-gqf8-q98f

Directory traversal vulnerability in shopsessionsubs.asp in Rocksalt International VP-ASP Shopping Cart 6.50 and earlier might allow remote attackers to determine the existence of arbitrary files via directory traversal sequences in the client's DNS hostname (aka the REMOTE_HOST variable), related to the CookielessGenerateFilename and CookielessReadFile functions.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4ph4-7xqm-67v8

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CRUDLab Jazz Popups plugin <= 1.8.7 versions.

CVSS3: 7.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-4ph4-5rpm-wrw9

The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disabled for the targeted account, allowing an unauthenticated attacker to obtain a valid authentication session as that account, including an administrator, by naming its login in a single registration request.

CVSS3: 8.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-4ph3-v6j7-j4pw

A weakness has been identified in PHPGurukul Online Shopping Portal Project 2.1. This issue affects some unknown processing of the file /sub-category.php of the component Parameter Handler. This manipulation of the argument pid causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.

CVSS3: 6.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-4ph3-7qqh-5h7g

In ss_SendCallBarringPwdRequiredIndMsg of ss_CallBarring.c, there is a possible null pointer deref due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4ph2-f6pf-79wv

PraisonAI Has Arbitrary File Write (Zip Slip) in Templates Extraction

CVSS3: 8.1
0%
Низкий
5 месяцев назад
github логотип
GHSA-4ph2-c8x7-g842

D-Link DIR-601 B1 2.00NA devices are vulnerable to authentication bypass. They do not check for authentication at the server side and rely on client-side validation, which is bypassable. NOTE: this is an end-of-life product.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4ph2-8337-hm62

Key Caching behavior in the DynamoDB Encryption Client.

больше 5 лет назад
github логотип
GHSA-4pgx-8hjp-cmmq

openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the portable USB drive feature, whose threat model treats the removable drive as untrusted (attacker with physical write access). USBDriveCreator._verify_integrity_file only validates files listed in the manifest, so files added to the drive — including a root-level autorun payload — are not detected and integrity verification still passes. Additionally, a globally constant, source-embedded KDF salt (_LEGACY_FIXED_SALT) is used to derive the drive encryption key for any drive lacking a per-drive salt file, defeating precomputation resistance and enabling an offline rainbow-table attack.

CVSS3: 3.5
0%
Низкий
22 дня назад
github логотип
GHSA-4pgv-p58j-ghpx

Apport argument parsing mishandles filename splitting on older kernels resulting in argument spoofing

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4pgr-wr6g-rxf6

When the ClickHouse plugin uses Native protocol (the default) with PDC or secure SOCKS, it asks for TLS but the connection library ignores that and talks to ClickHouse in the clear. Username, password, queries, and results can be read on the hop after the proxy. The server certificate is never checked, and a configured client certificate is not sent.

CVSS3: 6.1
0%
Низкий
22 дня назад

Уязвимостей на страницу