Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 374 825

Количество 374 825

github логотип

GHSA-4pf9-63f3-43qh

больше 4 лет назад

The mintToken function of a smart contract implementation for BiteduToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4pf8-rcwc-5q5p

больше 4 лет назад

In sqlite3_str_vappendf of sqlite3.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege if the user can also inject a printf into a privileged process's SQL with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-153352319

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4pf8-c4v6-2grg

больше 4 лет назад

Microsoft Internet Explorer 6 through 10 allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information from any visited document via a crafted web page that is not properly handled during a print-preview action, aka "Internet Explorer Information Disclosure Vulnerability."

EPSS: Средний
github логотип

GHSA-4pf8-34m3-m5j2

больше 4 лет назад

The installer in NetApp OnCommand Workflow Automation before 2.2.1P1 and 3.x before 3.0P1 sets up the Java Debugging Wire Protocol (JDWP) service, which allows remote attackers to execute arbitrary code via unspecified vectors.

EPSS: Средний
github логотип

GHSA-4pf7-cc4r-g63h

2 месяца назад

YesWiki has Authenticated SQL Injection via ReactionManager

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4pf7-579w-f4gm

больше 7 лет назад

dwebp-bin downloads Resources over HTTP

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-4pf5-fg6f-r7pr

больше 4 лет назад

Sybari AntiGen for Domino 7.0 Build 722 SR2 allows remote attackers to cause a denial of service (hang) via an encrypted ZIP file with the "include full path info" option set, as used by certain variants of the Beagle/Bagle worm.

EPSS: Низкий
github логотип

GHSA-4pf5-5v9x-5hc3

больше 4 лет назад

SITOS six Build v6.2.1 permits unauthorised users to upload and import a SCORM 2004 package by browsing directly to affected pages. An unauthenticated attacker could use the upload and import functionality to import a malicious SCORM package that includes a PHP file, which could execute arbitrary PHP code.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4pf5-5rrg-5jj5

больше 4 лет назад

The Administration GUI in the web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier does not properly implement access control, which allows remote attackers to enumerate account names via a crafted URL, aka Bug IDs CSCun39631 and CSCun39643.

EPSS: Низкий
github логотип

GHSA-4pf4-vf9p-vxx6

больше 4 лет назад

VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.

EPSS: Низкий
github логотип

GHSA-4pf4-m389-3pxh

больше 4 лет назад

A CWE-248: Uncaught Exception vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a Denial of Service attack on the PLC when upgrading the controller with an empty firmware package using FTP protocol.

EPSS: Низкий
github логотип

GHSA-4pf4-jp4v-4g5c

6 месяцев назад

Mitigation bypass in the Networking: HTTP component. This vulnerability affects Firefox < 149 and Firefox ESR < 140.9.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4pf4-j777-cgmf

3 месяца назад

IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4pf4-7qqr-5387

больше 4 лет назад

Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

EPSS: Низкий
github логотип

GHSA-4pf4-6f6p-fjw5

больше 4 лет назад

In sdpu_extract_attr_seq of sdp_utils.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-78136677.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4pf3-6jcp-46gf

около 2 лет назад

Rejected reason: reserved but not needed

EPSS: Низкий
github логотип

GHSA-4pf2-p694-fvc4

около 2 месяцев назад

Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eProcurement). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Argentina. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN Common Objects Argentina accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Common Objects Argentina accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-4pf2-mx2w-v6h4

5 месяцев назад

Missing Authorization vulnerability in Wpbens Filter Plus filter-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Filter Plus: from n/a through <= 1.1.17.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4pf2-94cv-wj99

больше 4 лет назад

Cross-Site Request Forgery (CSRF) in the Basic Settings screen on Vonage (Grandstream) HT802 devices allows attackers to modify settings, related to cgi-bin/update.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-4pf2-5j8p-ghjv

около 1 месяца назад

The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements to query sensitive data in the feedback.db database across tables, including user accounts, phone numbers, feedback content, and local debug log paths, thereby enabling the theft of local privacy data.

CVSS3: 3.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4pf9-63f3-43qh

The mintToken function of a smart contract implementation for BiteduToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4pf8-rcwc-5q5p

In sqlite3_str_vappendf of sqlite3.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege if the user can also inject a printf into a privileged process's SQL with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-153352319

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4pf8-c4v6-2grg

Microsoft Internet Explorer 6 through 10 allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information from any visited document via a crafted web page that is not properly handled during a print-preview action, aka "Internet Explorer Information Disclosure Vulnerability."

36%
Средний
больше 4 лет назад
github логотип
GHSA-4pf8-34m3-m5j2

The installer in NetApp OnCommand Workflow Automation before 2.2.1P1 and 3.x before 3.0P1 sets up the Java Debugging Wire Protocol (JDWP) service, which allows remote attackers to execute arbitrary code via unspecified vectors.

12%
Средний
больше 4 лет назад
github логотип
GHSA-4pf7-cc4r-g63h

YesWiki has Authenticated SQL Injection via ReactionManager

CVSS3: 8.8
0%
Низкий
2 месяца назад
github логотип
GHSA-4pf7-579w-f4gm

dwebp-bin downloads Resources over HTTP

CVSS3: 8.1
2%
Низкий
больше 7 лет назад
github логотип
GHSA-4pf5-fg6f-r7pr

Sybari AntiGen for Domino 7.0 Build 722 SR2 allows remote attackers to cause a denial of service (hang) via an encrypted ZIP file with the "include full path info" option set, as used by certain variants of the Beagle/Bagle worm.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4pf5-5v9x-5hc3

SITOS six Build v6.2.1 permits unauthorised users to upload and import a SCORM 2004 package by browsing directly to affected pages. An unauthenticated attacker could use the upload and import functionality to import a malicious SCORM package that includes a PHP file, which could execute arbitrary PHP code.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4pf5-5rrg-5jj5

The Administration GUI in the web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier does not properly implement access control, which allows remote attackers to enumerate account names via a crafted URL, aka Bug IDs CSCun39631 and CSCun39643.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4pf4-vf9p-vxx6

VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4pf4-m389-3pxh

A CWE-248: Uncaught Exception vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a Denial of Service attack on the PLC when upgrading the controller with an empty firmware package using FTP protocol.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4pf4-jp4v-4g5c

Mitigation bypass in the Networking: HTTP component. This vulnerability affects Firefox < 149 and Firefox ESR < 140.9.

CVSS3: 9.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-4pf4-j777-cgmf

IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.

CVSS3: 9.8
0%
Низкий
3 месяца назад
github логотип
GHSA-4pf4-7qqr-5387

Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

4%
Низкий
больше 4 лет назад
github логотип
GHSA-4pf4-6f6p-fjw5

In sdpu_extract_attr_seq of sdp_utils.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-78136677.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4pf3-6jcp-46gf

Rejected reason: reserved but not needed

около 2 лет назад
github логотип
GHSA-4pf2-p694-fvc4

Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eProcurement). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Argentina. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FIN Common Objects Argentina accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Common Objects Argentina accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

CVSS3: 9.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-4pf2-mx2w-v6h4

Missing Authorization vulnerability in Wpbens Filter Plus filter-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Filter Plus: from n/a through <= 1.1.17.

CVSS3: 5.4
0%
Низкий
5 месяцев назад
github логотип
GHSA-4pf2-94cv-wj99

Cross-Site Request Forgery (CSRF) in the Basic Settings screen on Vonage (Grandstream) HT802 devices allows attackers to modify settings, related to cgi-bin/update.

CVSS3: 8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4pf2-5j8p-ghjv

The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements to query sensitive data in the feedback.db database across tables, including user accounts, phone numbers, feedback content, and local debug log paths, thereby enabling the theft of local privacy data.

CVSS3: 3.9
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу