Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 373 892

Количество 373 892

github логотип

GHSA-4m4x-qm8m-cxqj

больше 4 лет назад

When the Mozilla Updater is run, if the Updater's log file in the working directory points to a hardlink, data can be appended to an arbitrary local file. This vulnerability requires local system access. Note: this issue only affects Windows operating systems. This vulnerability affects Firefox ESR < 45.5 and Firefox < 50.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4m4w-x26h-2qjx

около 2 лет назад

In shouldWrite of OwnersData.java, there is a possible edge case that prevents MDM policies from being persisted due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4m4w-ppgv-r57x

больше 4 лет назад

An authenticated attacker with low privileges can activate high privileged user and use it to expand attack surface in Eltex ESP-200 firmware version 1.2.0.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4m4w-p55h-jwjh

больше 4 лет назад

Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-4m4w-7ph3-mcfg

больше 1 года назад

An issue has been discovered in GitLab EE affecting all versions from 12.0 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Under certain conditions users could bypass IP access restrictions and view sensitive information.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-4m4w-79q4-3hfv

больше 4 лет назад

Heap-based buffer overflow in SceneKit in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code via a crafted Collada file.

EPSS: Низкий
github логотип

GHSA-4m4v-vqhc-mhjp

больше 4 лет назад

The Windows 2000 telnet client attempts to perform NTLM authentication by default, which allows remote attackers to capture and replay the NTLM challenge/response via a telnet:// URL that points to the malicious server, aka the "Windows 2000 Telnet Client NTLM Authentication" vulnerability.

EPSS: Средний
github логотип

GHSA-4m4v-fx7f-gv2r

12 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: dma: fix memory leak running mt76_dma_tx_cleanup Fix device unregister memory leak and alway cleanup all configured rx queues in mt76_dma_tx_cleanup routine.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4m4v-764q-rwgh

больше 4 лет назад

Unspecified vulnerability in Oracle MySQL Server 5.6.26 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Replication.

EPSS: Низкий
github логотип

GHSA-4m4r-xmfg-wvf5

больше 4 лет назад

winetricks before 20081223 allows local users to overwrite arbitrary files via a symlink attack on the x_showmenu.txt temporary file.

EPSS: Низкий
github логотип

GHSA-4m4r-x763-43q2

больше 4 лет назад

Trend Micro ServerProtect 6.0/5.8 Information Server uses a static credential to perform authentication when a specific command is typed in the console. An unauthenticated remote attacker with access to the Information Server could exploit this to register to the server and perform authenticated actions.

EPSS: Низкий
github логотип

GHSA-4m4r-j72q-7w52

больше 1 года назад

A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability is the function display_info of the file binutils/bucomm.c of the component objdump. The manipulation leads to memory leak. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is named ba6ad3a18cb26b79e0e3b84c39f707535bbc344d. It is recommended to apply a patch to fix this issue.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-4m4q-9cc6-g4mh

больше 4 лет назад

Multiple SQL injection vulnerabilities in Xlight FTP Server before 3.2.1, when ODBC authentication is enabled, allow remote attackers to execute arbitrary SQL commands via the (1) USER (aka username) or (2) PASS (aka password) command.

EPSS: Низкий
github логотип

GHSA-4m4q-85vx-69pj

больше 4 лет назад

Media Foundation Information Disclosure Vulnerability. This CVE ID is unique from CVE-2022-21977.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4m4p-5pj4-3gv8

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.0.1 allows remote attackers to inject arbitrary web script or HTML via the set_theme parameter.

EPSS: Низкий
github логотип

GHSA-4m4m-vm74-rqv4

9 месяцев назад

Mattermost Desktop App versions <6.0.0 fail to enable the Hardened Runtime on the Mattermost Desktop App when packaged for Mac App Store which allows an attacker to inherit TCC permissions via copying the binary to a tmp folder.

CVSS3: 3.9
EPSS: Низкий
github логотип

GHSA-4m4m-m2pr-j3q8

7 месяцев назад

Inclusion of Functionality from Untrusted Control Sphere vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Royal Elementor Addons: from n/a through <= 1.7.1049.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-4m4m-6w8x-jm7p

больше 4 лет назад

Google Chrome OS before 26.0.1410.57 does not properly enforce origin restrictions for the O3D and Google Talk plug-ins, which allows remote attackers to bypass the domain-whitelist protection mechanism via a crafted web site, a different vulnerability than CVE-2013-2834.

EPSS: Низкий
github логотип

GHSA-4m4m-6fm5-244f

10 месяцев назад

Inappropriate implementation in Permissions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4m4j-w3qr-4gcc

больше 2 лет назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PenciDesign Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme.This issue affects Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme: from n/a through 8.4.1.

CVSS3: 8.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4m4x-qm8m-cxqj

When the Mozilla Updater is run, if the Updater's log file in the working directory points to a hardlink, data can be appended to an arbitrary local file. This vulnerability requires local system access. Note: this issue only affects Windows operating systems. This vulnerability affects Firefox ESR < 45.5 and Firefox < 50.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4m4w-x26h-2qjx

In shouldWrite of OwnersData.java, there is a possible edge case that prevents MDM policies from being persisted due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-4m4w-ppgv-r57x

An authenticated attacker with low privileges can activate high privileged user and use it to expand attack surface in Eltex ESP-200 firmware version 1.2.0.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4m4w-p55h-jwjh

Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access.

CVSS3: 6.2
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4m4w-7ph3-mcfg

An issue has been discovered in GitLab EE affecting all versions from 12.0 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Under certain conditions users could bypass IP access restrictions and view sensitive information.

CVSS3: 3.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-4m4w-79q4-3hfv

Heap-based buffer overflow in SceneKit in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code via a crafted Collada file.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4m4v-vqhc-mhjp

The Windows 2000 telnet client attempts to perform NTLM authentication by default, which allows remote attackers to capture and replay the NTLM challenge/response via a telnet:// URL that points to the malicious server, aka the "Windows 2000 Telnet Client NTLM Authentication" vulnerability.

40%
Средний
больше 4 лет назад
github логотип
GHSA-4m4v-fx7f-gv2r

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: dma: fix memory leak running mt76_dma_tx_cleanup Fix device unregister memory leak and alway cleanup all configured rx queues in mt76_dma_tx_cleanup routine.

CVSS3: 5.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-4m4v-764q-rwgh

Unspecified vulnerability in Oracle MySQL Server 5.6.26 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Replication.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4m4r-xmfg-wvf5

winetricks before 20081223 allows local users to overwrite arbitrary files via a symlink attack on the x_showmenu.txt temporary file.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4m4r-x763-43q2

Trend Micro ServerProtect 6.0/5.8 Information Server uses a static credential to perform authentication when a specific command is typed in the console. An unauthenticated remote attacker with access to the Information Server could exploit this to register to the server and perform authenticated actions.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4m4r-j72q-7w52

A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability is the function display_info of the file binutils/bucomm.c of the component objdump. The manipulation leads to memory leak. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is named ba6ad3a18cb26b79e0e3b84c39f707535bbc344d. It is recommended to apply a patch to fix this issue.

CVSS3: 3.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-4m4q-9cc6-g4mh

Multiple SQL injection vulnerabilities in Xlight FTP Server before 3.2.1, when ODBC authentication is enabled, allow remote attackers to execute arbitrary SQL commands via the (1) USER (aka username) or (2) PASS (aka password) command.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4m4q-85vx-69pj

Media Foundation Information Disclosure Vulnerability. This CVE ID is unique from CVE-2022-21977.

CVSS3: 5.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4m4p-5pj4-3gv8

Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.0.1 allows remote attackers to inject arbitrary web script or HTML via the set_theme parameter.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4m4m-vm74-rqv4

Mattermost Desktop App versions <6.0.0 fail to enable the Hardened Runtime on the Mattermost Desktop App when packaged for Mac App Store which allows an attacker to inherit TCC permissions via copying the binary to a tmp folder.

CVSS3: 3.9
0%
Низкий
9 месяцев назад
github логотип
GHSA-4m4m-m2pr-j3q8

Inclusion of Functionality from Untrusted Control Sphere vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Royal Elementor Addons: from n/a through <= 1.7.1049.

CVSS3: 8.2
0%
Низкий
7 месяцев назад
github логотип
GHSA-4m4m-6w8x-jm7p

Google Chrome OS before 26.0.1410.57 does not properly enforce origin restrictions for the O3D and Google Talk plug-ins, which allows remote attackers to bypass the domain-whitelist protection mechanism via a crafted web site, a different vulnerability than CVE-2013-2834.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4m4m-6fm5-244f

Inappropriate implementation in Permissions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 5.4
0%
Низкий
10 месяцев назад
github логотип
GHSA-4m4j-w3qr-4gcc

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PenciDesign Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme.This issue affects Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme: from n/a through 8.4.1.

CVSS3: 8.5
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу