Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 373 528

Количество 373 528

github логотип

GHSA-4jm9-44mg-28r7

больше 4 лет назад

Integer overflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a long DOC file, which triggers a buffer overflow.

EPSS: Средний
github логотип

GHSA-4jm9-2wwx-qxgm

больше 4 лет назад

The eID module has a null pointer reference vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.

EPSS: Низкий
github логотип

GHSA-4jm8-qw96-rm2j

около 1 года назад

A vulnerability was identified in INSTAR 2K+ and 4K 3.11.1 Build 1124. This affects the function base64_decode of the component fcgi_server. The manipulation of the argument Authorization leads to buffer overflow. It is possible to initiate the attack remotely.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4jm8-hmxq-7xq6

больше 1 года назад

The Evertz SVDN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for Video Application. This device exposes a web management interface on port 80. This web management interface can be used by administrators to control product features, setup network switching, and register license among other features. The application has been developed in PHP with the webEASY SDK, also named ‘ewb’ by Evertz. This web interface has two endpoints that are vulnerable to arbitrary command injection and the authentication mechanism has a flaw leading to authentication bypass. Remote unauthenticated attackers can gain arbitrary command execution with elevated privileges ( root ) on affected devices. This level of access could lead to serious business impact such as the interruption of media streaming, modification of media being streamed, alteration of closed captions being generated, among others.

EPSS: Высокий
github логотип

GHSA-4jm8-crf9-ff85

больше 2 лет назад

Insecure permissions in DNSCrypt-proxy v2.0.0alpha9 to v2.1.5 allows non-privileged attackers to escalate privileges to root via overwriting the binary dnscrypt-proxy.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4jm8-6c5j-h7mf

больше 4 лет назад

ImageMagick 6.8.9-9 allows remote attackers to cause a denial of service via a crafted xpm file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4jm7-rq6c-7qj9

около 1 года назад

Missing Authorization vulnerability in pietro MobiLoud allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MobiLoud: from n/a through 4.6.5.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-4jm7-cxrm-w3f4

больше 4 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure (issue 2 of 5).

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4jm6-vv65-r63r

больше 4 лет назад

Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows attackers with physical access to restore the phone to factory defaults without authentication via a menu option, which sets the administrator password to null.

EPSS: Низкий
github логотип

GHSA-4jm6-9pwc-w558

6 месяцев назад

The LotekMedia Popup Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the frontend of the site where the popup is displayed.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-4jm4-gh3x-cq86

4 месяца назад

Insufficient validation of untrusted input in USB in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4jm4-7jcw-x46f

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in GNU Mailman before 2.1.14rc1 allow remote authenticated users to inject arbitrary web script or HTML via vectors involving (1) the list information field or (2) the list description field.

EPSS: Низкий
github логотип

GHSA-4jm3-pfpf-h54p

почти 9 лет назад

espeak-ruby allows arbitrary command execution

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4jm2-q7gv-xrg4

больше 4 лет назад

Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/table_edit_ajax.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4jm2-c9jr-6prf

больше 4 лет назад

Moodle allows attackers to bypass a messaging-disabled setting

EPSS: Низкий
github логотип

GHSA-4jjw-xrr6-9v3p

больше 4 лет назад

Mortbay Jetty Double Slash URI Information Disclosure Vulnerability

EPSS: Низкий
github логотип

GHSA-4jjw-pwvw-q6w3

около 1 месяца назад

Duplicate Advisory: Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-4jjw-p5j8-wcgh

больше 1 года назад

A vulnerability, which was classified as problematic, was found in lmxcms 1.41. Affected is an unknown function of the file db.inc.php of the component Maintenance. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.1
EPSS: Низкий
github логотип

GHSA-4jjw-9p2j-2v46

почти 2 года назад

A null pointer dereference in Palo Alto Networks PAN-OS software on PA-800 Series, PA-3200 Series, PA-5200 Series, and PA-7000 Series hardware platforms when Decryption policy is enabled allows an unauthenticated attacker to crash PAN-OS by sending specific traffic through the data plane, resulting in a denial of service (DoS) condition. Repeated attempts to trigger this condition will result in PAN-OS entering maintenance mode. Palo Alto Networks VM-Series, Cloud NGFW, and Prisma Access are not affected. This issue only affects PA-800 Series, PA-3200 Series, PA-5200 Series, and PA-7000 Series running these specific versions of PAN-OS: * 10.2.7-h12 * 10.2.8-h10 * 10.2.9-h9 * 10.2.9-h11 * 10.2.10-h2 * 10.2.10-h3 * 10.2.11 * 10.2.11-h1 * 10.2.11-h2 * 10.2.11-h3 * 11.1.2-h9 * 11.1.2-h12 * 11.1.3-h2 * 11.1.3-h4 * 11.1.3-h6 * 11.2.2 * 11.2.2-h1

EPSS: Низкий
github логотип

GHSA-4jjw-785r-x9vr

больше 4 лет назад

users_adm/start1.php in IMGallery 2.5 and earlier does not properly handle files with multiple extensions, which allows remote authenticated users to upload and execute arbitrary PHP scripts.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4jm9-44mg-28r7

Integer overflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a long DOC file, which triggers a buffer overflow.

13%
Средний
больше 4 лет назад
github логотип
GHSA-4jm9-2wwx-qxgm

The eID module has a null pointer reference vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4jm8-qw96-rm2j

A vulnerability was identified in INSTAR 2K+ and 4K 3.11.1 Build 1124. This affects the function base64_decode of the component fcgi_server. The manipulation of the argument Authorization leads to buffer overflow. It is possible to initiate the attack remotely.

CVSS3: 9.8
1%
Низкий
около 1 года назад
github логотип
GHSA-4jm8-hmxq-7xq6

The Evertz SVDN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for Video Application. This device exposes a web management interface on port 80. This web management interface can be used by administrators to control product features, setup network switching, and register license among other features. The application has been developed in PHP with the webEASY SDK, also named ‘ewb’ by Evertz. This web interface has two endpoints that are vulnerable to arbitrary command injection and the authentication mechanism has a flaw leading to authentication bypass. Remote unauthenticated attackers can gain arbitrary command execution with elevated privileges ( root ) on affected devices. This level of access could lead to serious business impact such as the interruption of media streaming, modification of media being streamed, alteration of closed captions being generated, among others.

71%
Высокий
больше 1 года назад
github логотип
GHSA-4jm8-crf9-ff85

Insecure permissions in DNSCrypt-proxy v2.0.0alpha9 to v2.1.5 allows non-privileged attackers to escalate privileges to root via overwriting the binary dnscrypt-proxy.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4jm8-6c5j-h7mf

ImageMagick 6.8.9-9 allows remote attackers to cause a denial of service via a crafted xpm file.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4jm7-rq6c-7qj9

Missing Authorization vulnerability in pietro MobiLoud allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MobiLoud: from n/a through 4.6.5.

CVSS3: 8.1
0%
Низкий
около 1 года назад
github логотип
GHSA-4jm7-cxrm-w3f4

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure (issue 2 of 5).

CVSS3: 5.9
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4jm6-vv65-r63r

Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows attackers with physical access to restore the phone to factory defaults without authentication via a menu option, which sets the administrator password to null.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4jm6-9pwc-w558

The LotekMedia Popup Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the frontend of the site where the popup is displayed.

CVSS3: 4.4
0%
Низкий
6 месяцев назад
github логотип
GHSA-4jm4-gh3x-cq86

Insufficient validation of untrusted input in USB in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 8.8
0%
Низкий
4 месяца назад
github логотип
GHSA-4jm4-7jcw-x46f

Multiple cross-site scripting (XSS) vulnerabilities in GNU Mailman before 2.1.14rc1 allow remote authenticated users to inject arbitrary web script or HTML via vectors involving (1) the list information field or (2) the list description field.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4jm3-pfpf-h54p

espeak-ruby allows arbitrary command execution

CVSS3: 9.8
2%
Низкий
почти 9 лет назад
github логотип
GHSA-4jm2-q7gv-xrg4

Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/table_edit_ajax.php.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4jm2-c9jr-6prf

Moodle allows attackers to bypass a messaging-disabled setting

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4jjw-xrr6-9v3p

Mortbay Jetty Double Slash URI Information Disclosure Vulnerability

4%
Низкий
больше 4 лет назад
github логотип
GHSA-4jjw-pwvw-q6w3

Duplicate Advisory: Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint

CVSS3: 6.2
около 1 месяца назад
github логотип
GHSA-4jjw-p5j8-wcgh

A vulnerability, which was classified as problematic, was found in lmxcms 1.41. Affected is an unknown function of the file db.inc.php of the component Maintenance. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.1
1%
Низкий
больше 1 года назад
github логотип
GHSA-4jjw-9p2j-2v46

A null pointer dereference in Palo Alto Networks PAN-OS software on PA-800 Series, PA-3200 Series, PA-5200 Series, and PA-7000 Series hardware platforms when Decryption policy is enabled allows an unauthenticated attacker to crash PAN-OS by sending specific traffic through the data plane, resulting in a denial of service (DoS) condition. Repeated attempts to trigger this condition will result in PAN-OS entering maintenance mode. Palo Alto Networks VM-Series, Cloud NGFW, and Prisma Access are not affected. This issue only affects PA-800 Series, PA-3200 Series, PA-5200 Series, and PA-7000 Series running these specific versions of PAN-OS: * 10.2.7-h12 * 10.2.8-h10 * 10.2.9-h9 * 10.2.9-h11 * 10.2.10-h2 * 10.2.10-h3 * 10.2.11 * 10.2.11-h1 * 10.2.11-h2 * 10.2.11-h3 * 11.1.2-h9 * 11.1.2-h12 * 11.1.3-h2 * 11.1.3-h4 * 11.1.3-h6 * 11.2.2 * 11.2.2-h1

0%
Низкий
почти 2 года назад
github логотип
GHSA-4jjw-785r-x9vr

users_adm/start1.php in IMGallery 2.5 and earlier does not properly handle files with multiple extensions, which allows remote authenticated users to upload and execute arbitrary PHP scripts.

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу