Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 373 892

Количество 373 892

github логотип

GHSA-4m6r-mwr3-57wm

почти 5 лет назад

In isRequestPinItemSupported of ShortcutService.java, there is a possible cross-user leak of packages in which the default launcher supports requests to create pinned shortcuts due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-191772737

EPSS: Низкий
github логотип

GHSA-4m6r-j49h-94c5

почти 3 года назад

A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models could allow an attacker with physical or local access and elevated privileges the ability to bypass Secure Boot.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-4m6r-h473-x99p

около 3 лет назад

SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the group parameter within the /QueryView.php.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4m6r-4mpf-3p4q

больше 2 лет назад

Pexip Infinity before 31.2 has Improper Input Validation for signalling, allowing remote attackers to trigger an abort.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4m6q-wqc9-g2m5

4 месяца назад

HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images may introduce known vulnerabilities, potentially increasing the risk of exploitation in the application environment.

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-4m6q-rxhm-675w

почти 5 лет назад

OS Command Injection in adb-driver

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4m6p-f924-hjw4

больше 1 года назад

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.0 through 10.0.3. Users are recommended to upgrade to version 10.0.4, which fixes the issue.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-4m6p-3p5q-jx68

больше 4 лет назад

imcat 4.4 allow XSS via a crafted cookie to the root/tools/adbug/binfo.php?cookie URI.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4m6p-2r8v-vvqp

около 1 месяца назад

Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The application fails to stop processing an incoming request in VuFind\Controller\AbstractBase::validateAccessPermission after it has found that controller level access permissions do not allow access to the requested function. The requester receives a response indicating that access was denied, but the actual function is executed regardless of that.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4m6m-m354-7cfg

больше 1 года назад

Missing Authorization vulnerability in ammarahmad786 Calculate Prices based on Distance For WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Calculate Prices based on Distance For WooCommerce: from n/a through 1.3.5.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4m6m-g8v5-w4ff

больше 3 лет назад

In tee service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-4m6j-mh25-2w47

больше 4 лет назад

mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow remote attackers to bypass intended access restrictions.

EPSS: Средний
github логотип

GHSA-4m6j-23p2-8c54

больше 2 лет назад

Armeria SAML authentication bypass due to missing validation on unsigned SAML messages

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-4m6h-hp8h-qr9q

больше 4 лет назад

IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 148514.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4m6g-rphv-p56x

больше 4 лет назад

There is a Permission Control Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause certain codes to be executed.

EPSS: Низкий
github логотип

GHSA-4m6g-cqp8-43xm

больше 4 лет назад

An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4m6g-4889-mff3

около 3 лет назад

Affected versions Trend Micro Apex Central (on-premise) are vulnerable to potential authenticated reflected cross-site scripting (XSS) attacks due to user input validation and sanitization issues. Please note: an attacker must first obtain authentication to Apex Central on the target system in order to exploit this vulnerability. This is similar to, but not identical to CVE-2023-32537.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4m6f-x2gc-6fgq

больше 1 года назад

An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers who have gained user access to compromise the security of the system. We have already fixed the vulnerability in the following versions: File Station 5 5.5.6.4791 and later and later

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4m6f-v755-rgh3

больше 1 года назад

A vulnerability was found in propanetank Roommate-Bill-Tracking up to 288437f658fc9ee7d4b92a9da12557024d8bc55c. It has been declared as critical. This vulnerability affects unknown code of the file /includes/login.php. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The name of the patch is b32bb1b940f82d38fb9310cd66ebe349e20a1d0a. It is recommended to apply a patch to fix this issue.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4m6c-v88j-qqxh

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: fbdev: savage: Error out if pixclock equals zero The userspace program could pass any values to the driver through ioctl() interface. If the driver doesn't check the value of pixclock, it may cause divide-by-zero error. Although pixclock is checked in savagefb_decode_var(), but it is not checked properly in savagefb_probe(). Fix this by checking whether pixclock is zero in the function savagefb_check_var() before info->var.pixclock is used as the divisor. This is similar to CVE-2022-3061 in i740fb which was fixed by commit 15cf0b8.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4m6r-mwr3-57wm

In isRequestPinItemSupported of ShortcutService.java, there is a possible cross-user leak of packages in which the default launcher supports requests to create pinned shortcuts due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-191772737

0%
Низкий
почти 5 лет назад
github логотип
GHSA-4m6r-j49h-94c5

A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models could allow an attacker with physical or local access and elevated privileges the ability to bypass Secure Boot.

CVSS3: 6.7
0%
Низкий
почти 3 года назад
github логотип
GHSA-4m6r-h473-x99p

SQL injection vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to obtain sensitive information via the group parameter within the /QueryView.php.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-4m6r-4mpf-3p4q

Pexip Infinity before 31.2 has Improper Input Validation for signalling, allowing remote attackers to trigger an abort.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4m6q-wqc9-g2m5

HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images may introduce known vulnerabilities, potentially increasing the risk of exploitation in the application environment.

CVSS3: 4
0%
Низкий
4 месяца назад
github логотип
GHSA-4m6q-rxhm-675w

OS Command Injection in adb-driver

CVSS3: 9.8
4%
Низкий
почти 5 лет назад
github логотип
GHSA-4m6p-f924-hjw4

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.0 through 10.0.3. Users are recommended to upgrade to version 10.0.4, which fixes the issue.

CVSS3: 6.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-4m6p-3p5q-jx68

imcat 4.4 allow XSS via a crafted cookie to the root/tools/adbug/binfo.php?cookie URI.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4m6p-2r8v-vvqp

Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The application fails to stop processing an incoming request in VuFind\Controller\AbstractBase::validateAccessPermission after it has found that controller level access permissions do not allow access to the requested function. The requester receives a response indicating that access was denied, but the actual function is executed regardless of that.

CVSS3: 9.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-4m6m-m354-7cfg

Missing Authorization vulnerability in ammarahmad786 Calculate Prices based on Distance For WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Calculate Prices based on Distance For WooCommerce: from n/a through 1.3.5.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-4m6m-g8v5-w4ff

In tee service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.

CVSS3: 4.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4m6j-mh25-2w47

mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow remote attackers to bypass intended access restrictions.

11%
Средний
больше 4 лет назад
github логотип
GHSA-4m6j-23p2-8c54

Armeria SAML authentication bypass due to missing validation on unsigned SAML messages

CVSS3: 9.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4m6h-hp8h-qr9q

IBM Tivoli Key Lifecycle Manager 2.6, 2.7, and 3.0 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 148514.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4m6g-rphv-p56x

There is a Permission Control Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause certain codes to be executed.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4m6g-cqp8-43xm

An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVSS3: 8.8
6%
Низкий
больше 4 лет назад
github логотип
GHSA-4m6g-4889-mff3

Affected versions Trend Micro Apex Central (on-premise) are vulnerable to potential authenticated reflected cross-site scripting (XSS) attacks due to user input validation and sanitization issues. Please note: an attacker must first obtain authentication to Apex Central on the target system in order to exploit this vulnerability. This is similar to, but not identical to CVE-2023-32537.

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-4m6f-x2gc-6fgq

An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers who have gained user access to compromise the security of the system. We have already fixed the vulnerability in the following versions: File Station 5 5.5.6.4791 and later and later

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-4m6f-v755-rgh3

A vulnerability was found in propanetank Roommate-Bill-Tracking up to 288437f658fc9ee7d4b92a9da12557024d8bc55c. It has been declared as critical. This vulnerability affects unknown code of the file /includes/login.php. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The name of the patch is b32bb1b940f82d38fb9310cd66ebe349e20a1d0a. It is recommended to apply a patch to fix this issue.

CVSS3: 7.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-4m6c-v88j-qqxh

In the Linux kernel, the following vulnerability has been resolved: fbdev: savage: Error out if pixclock equals zero The userspace program could pass any values to the driver through ioctl() interface. If the driver doesn't check the value of pixclock, it may cause divide-by-zero error. Although pixclock is checked in savagefb_decode_var(), but it is not checked properly in savagefb_probe(). Fix this by checking whether pixclock is zero in the function savagefb_check_var() before info->var.pixclock is used as the divisor. This is similar to CVE-2022-3061 in i740fb which was fixed by commit 15cf0b8.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу