Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 373 528

Количество 373 528

github логотип

GHSA-4jpc-fv5p-mh98

больше 2 лет назад

Improper input validation of a large HTTP request in the Controller 6000 and Controller 7000 optional diagnostic web interface (Port 80) can be used to perform a Denial of Service of the diagnostic web interface. This issue affects: Gallagher Controller 6000 and 7000 8.90 prior to vCR8.90.231204a (distributed in 8.90.1620 (MR2)), 8.80 prior to vCR8.80.231204a (distributed in 8.80.1369 (MR3)), 8.70 prior to vCR8.70.231204a (distributed in 8.70.2375 (MR5)), 8.60 prior to vCR8.60.231116a (distributed in 8.60.2550 (MR7)), all versions of 8.50 and prior.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-4jp9-q9g7-48gr

почти 2 года назад

When handling keypress events, an attacker may have been able to trick a user into bypassing the "Open Executable File?" confirmation dialog. This could have led to malicious code execution. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4jp9-m29w-rpw2

больше 4 лет назад

SQL injection vulnerability in usercp.php in MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the awayday parameter.

EPSS: Низкий
github логотип

GHSA-4jp8-fm2m-q8mc

больше 4 лет назад

The AV1_DuplicateConfig function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

EPSS: Низкий
github логотип

GHSA-4jp8-75fv-797w

больше 4 лет назад

Stack-based buffer overflow in the Read32s_64 function in src/lib/cdfread64.c in the NASA Goddard Space Flight Center Common Data Format (CDF) library before 3.2.1 allows context-dependent attackers to execute arbitrary code via a .cdf file with crafted length tags.

EPSS: Низкий
github логотип

GHSA-4jp7-8p85-rpc6

больше 4 лет назад

WordPress plugin wp-cleanfix has Remote Code Execution

EPSS: Низкий
github логотип

GHSA-4jp6-449x-6fgh

больше 4 лет назад

The SyncThru Web Service on Samsung SCX-6x55X printers allows an attacker to gain access to a list of SMB users and cleartext passwords by reading the HTML source code. Authentication is not required.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4jp5-cwfh-cp99

около 3 лет назад

Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. This is similar to, but not identical to CVE-2023-32532 through 32535.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4jp4-vqwc-qh78

10 месяцев назад

Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted WinBioControlUnit call can lead to memory corruption. An attacker can issue an api call to trigger this vulnerability. This vulnerability is triggered when submitting a `WinBioControlUnit` call to the StorageAdapter with the ControlCode 3 (`WBIO_USH_CREATE_CHALLENGE`) and with `0 < ReceiveBuferSize < 4`. Up to three null-bytes will be written past the end of the `ReceiveBuffer`.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4jp4-3xh6-74m2

30 дней назад

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-4jp4-3c62-r8jv

больше 4 лет назад

OpenStack Glance Denial of service by creating a large number of images

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4jp3-q2qm-9fmw

больше 4 лет назад

Improper Restriction of Rendered UI Layers or Frames in Sylius

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4jp2-rjmj-344p

около 3 лет назад

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Atarim Visual Website Collaboration, Feedback & Project Management – Atarim plugin <= 3.9.3 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4jmv-x65v-w43v

11 месяцев назад

Dimension versions 4.1.4 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4jmv-jvrv-qcv7

почти 3 года назад

Uncontrolled resource consumption in Zoom Team Chat for Zoom Desktop Client for Windows and Zoom VDI Client may allow an unauthenticated user to conduct a disclosure of information via network access.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4jmv-9vjw-mj58

16 дней назад

Dell PowerStore contains an Argument Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to gain unauthorized access to sensitive sensitive system information.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4jmv-526x-2x7f

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka bugs 104552 and 104703.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4jmv-3f44-7558

около 2 лет назад

Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4jmr-68h5-qq5j

около 4 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16663.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4jmq-69hm-3jp3

7 месяцев назад

Tanium addressed a use-after-free vulnerability in the Cloud Workloads Enforce client extension.

CVSS3: 4.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4jpc-fv5p-mh98

Improper input validation of a large HTTP request in the Controller 6000 and Controller 7000 optional diagnostic web interface (Port 80) can be used to perform a Denial of Service of the diagnostic web interface. This issue affects: Gallagher Controller 6000 and 7000 8.90 prior to vCR8.90.231204a (distributed in 8.90.1620 (MR2)), 8.80 prior to vCR8.80.231204a (distributed in 8.80.1369 (MR3)), 8.70 prior to vCR8.70.231204a (distributed in 8.70.2375 (MR5)), 8.60 prior to vCR8.60.231116a (distributed in 8.60.2550 (MR7)), all versions of 8.50 and prior.

CVSS3: 3.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4jp9-q9g7-48gr

When handling keypress events, an attacker may have been able to trick a user into bypassing the "Open Executable File?" confirmation dialog. This could have led to malicious code execution. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.

CVSS3: 8.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-4jp9-m29w-rpw2

SQL injection vulnerability in usercp.php in MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the awayday parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4jp8-fm2m-q8mc

The AV1_DuplicateConfig function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4jp8-75fv-797w

Stack-based buffer overflow in the Read32s_64 function in src/lib/cdfread64.c in the NASA Goddard Space Flight Center Common Data Format (CDF) library before 3.2.1 allows context-dependent attackers to execute arbitrary code via a .cdf file with crafted length tags.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-4jp7-8p85-rpc6

WordPress plugin wp-cleanfix has Remote Code Execution

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4jp6-449x-6fgh

The SyncThru Web Service on Samsung SCX-6x55X printers allows an attacker to gain access to a list of SMB users and cleartext passwords by reading the HTML source code. Authentication is not required.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4jp5-cwfh-cp99

Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. This is similar to, but not identical to CVE-2023-32532 through 32535.

CVSS3: 6.1
2%
Низкий
около 3 лет назад
github логотип
GHSA-4jp4-vqwc-qh78

Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted WinBioControlUnit call can lead to memory corruption. An attacker can issue an api call to trigger this vulnerability. This vulnerability is triggered when submitting a `WinBioControlUnit` call to the StorageAdapter with the ControlCode 3 (`WBIO_USH_CREATE_CHALLENGE`) and with `0 < ReceiveBuferSize < 4`. Up to three null-bytes will be written past the end of the `ReceiveBuffer`.

CVSS3: 7.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-4jp4-3xh6-74m2

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 4.4
0%
Низкий
30 дней назад
github логотип
GHSA-4jp4-3c62-r8jv

OpenStack Glance Denial of service by creating a large number of images

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4jp3-q2qm-9fmw

Improper Restriction of Rendered UI Layers or Frames in Sylius

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4jp2-rjmj-344p

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Atarim Visual Website Collaboration, Feedback & Project Management – Atarim plugin <= 3.9.3 versions.

CVSS3: 7.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-4jmv-x65v-w43v

Dimension versions 4.1.4 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-4jmv-jvrv-qcv7

Uncontrolled resource consumption in Zoom Team Chat for Zoom Desktop Client for Windows and Zoom VDI Client may allow an unauthenticated user to conduct a disclosure of information via network access.

CVSS3: 4.3
1%
Низкий
почти 3 года назад
github логотип
GHSA-4jmv-9vjw-mj58

Dell PowerStore contains an Argument Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to gain unauthorized access to sensitive sensitive system information.

CVSS3: 6.5
0%
Низкий
16 дней назад
github логотип
GHSA-4jmv-526x-2x7f

Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka bugs 104552 and 104703.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4jmv-3f44-7558

Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability

CVSS3: 7.8
7%
Низкий
около 2 лет назад
github логотип
GHSA-4jmr-68h5-qq5j

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16663.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-4jmq-69hm-3jp3

Tanium addressed a use-after-free vulnerability in the Cloud Workloads Enforce client extension.

CVSS3: 4.7
0%
Низкий
7 месяцев назад

Уязвимостей на страницу