Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 371 326

Количество 371 326

github логотип

GHSA-4gc8-34fv-2837

больше 4 лет назад

Multiple PHP remote file inclusion vulnerabilities in OpenBASE Alpha 0.6 allow remote attackers to execute arbitrary PHP code via a URL in the root_prefix parameter to (1) index.php, (2) email_subscribe.php, (3) download.php, or (4) development.php.

EPSS: Низкий
github логотип

GHSA-4gc7-qcvf-38wg

7 месяцев назад

In OpenClaw, manually adding sort to tools.exec.safeBins could bypass allowlist approval via --compress-program

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4gc7-cx8r-39w5

больше 4 лет назад

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/edit-field.php by adding a question mark (?) followed by the payload.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-4gc7-5j7h-4qph

почти 2 года назад

Spring Framework DataBinder Case Sensitive Match Exception

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4gc6-9xr6-qwc7

больше 4 лет назад

Integer overflow in the AudioInputRendererHost::OnCreateStream function in content/browser/renderer_host/media/audio_input_renderer_host.cc in Google Chrome before 35.0.1916.114 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a large shared-memory allocation.

EPSS: Низкий
github логотип

GHSA-4gc5-v3fx-mpqc

28 дней назад

Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4gc5-387r-vqmc

больше 4 лет назад

Integer overflow in WebKit, as used on the Research In Motion (RIM) BlackBerry Torch 9800 with firmware 6.0.0.246, in Google Chrome before 10.0.648.133, and in Apple Safari before 5.0.5, allows remote attackers to execute arbitrary code via unknown vectors related to CSS "style handling," nodesets, and a length value, as demonstrated by Vincenzo Iozzo, Willem Pinckaers, and Ralf-Philipp Weinmann during a Pwn2Own competition at CanSecWest 2011.

EPSS: Низкий
github логотип

GHSA-4gc4-vfjg-7w73

почти 4 года назад

Memory corruption in diag due to use after free while processing dci packet in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4gc3-hqxg-hgp9

больше 4 лет назад

When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file can specify that requests to the localhost are to be sent through the proxy to another server. This behavior is disallowed by default when a proxy is manually configured, but when enabled could allow for attacks on services and tools that bind to the localhost for networked behavior if they are accessed through browsing. This vulnerability affects Firefox < 65.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4gc3-8hmv-3556

больше 4 лет назад

PHP remote file inclusion vulnerability in news.php in Fantastic News 2.1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[script_path] parameter. NOTE: it was later reported that 2.1.5 is also affected.

EPSS: Низкий
github логотип

GHSA-4gc3-2mvv-h54m

больше 4 лет назад

WorkforceROI Xpede 4.1 allows remote attackers to read user timesheets by modifying the TSN ID parameter to the ts_app_process.asp script, which is easily guessable because it is incremented by 1 for each new timesheet.

EPSS: Низкий
github логотип

GHSA-4gc2-344q-r2rw

7 месяцев назад

MS-Agent vulnerable to Command Injection

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4g9x-m9qw-6m5h

больше 4 лет назад

The Fabulas Infantiles (aka com.mobincube.android.sc_9I1A3) application 3.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-4g9x-932h-9gm7

больше 4 лет назад

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16.6, RBK852 before 3.2.16.6, RBR850 before 3.2.16.6, and RBS850 before 3.2.16.6.

EPSS: Низкий
github логотип

GHSA-4g9x-65q8-9448

больше 4 лет назад

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4g9w-hcf4-wx2j

больше 4 лет назад

IObit Advanced SystemCare, which includes Monitor_win10_x64.sys or Monitor_win7_x64.sys, 1.2.0.5 (and possibly earlier versions) allows a user to send an IOCTL (0x9C402088) with a buffer containing user defined content. The driver's subroutine will execute a wrmsr instruction with the user's buffer for input.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4g9w-6f9w-cjc7

больше 2 лет назад

MP-SPDZ v0.3.8 was discovered to contain a stack overflow via the function OTExtensionWithMatrix::extend in /OT/OTExtensionWithMatrix.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted message.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4g9v-q78c-rpv5

больше 4 лет назад

The mintToken function of a smart contract implementation for HBCM, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4g9v-p2mj-pg7w

больше 4 лет назад

** DISPUTED ** The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 does not recognize attack patterns designed to operate against web pages that are encoded with utf-7, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting crafted utf-7 content. NOTE: the vendor reportedly disputes this issue, stating "Behaviour is by design."

EPSS: Средний
github логотип

GHSA-4g9r-vxhx-9pgx

больше 2 лет назад

Apache Commons Compress: Denial of service caused by an infinite loop for a corrupted DUMP file

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4gc8-34fv-2837

Multiple PHP remote file inclusion vulnerabilities in OpenBASE Alpha 0.6 allow remote attackers to execute arbitrary PHP code via a URL in the root_prefix parameter to (1) index.php, (2) email_subscribe.php, (3) download.php, or (4) development.php.

9%
Низкий
больше 4 лет назад
github логотип
GHSA-4gc7-qcvf-38wg

In OpenClaw, manually adding sort to tools.exec.safeBins could bypass allowlist approval via --compress-program

CVSS3: 8.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-4gc7-cx8r-39w5

The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/edit-field.php by adding a question mark (?) followed by the payload.

CVSS3: 4.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4gc7-5j7h-4qph

Spring Framework DataBinder Case Sensitive Match Exception

CVSS3: 5.3
1%
Низкий
почти 2 года назад
github логотип
GHSA-4gc6-9xr6-qwc7

Integer overflow in the AudioInputRendererHost::OnCreateStream function in content/browser/renderer_host/media/audio_input_renderer_host.cc in Google Chrome before 35.0.1916.114 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a large shared-memory allocation.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4gc5-v3fx-mpqc

Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 5.3
0%
Низкий
28 дней назад
github логотип
GHSA-4gc5-387r-vqmc

Integer overflow in WebKit, as used on the Research In Motion (RIM) BlackBerry Torch 9800 with firmware 6.0.0.246, in Google Chrome before 10.0.648.133, and in Apple Safari before 5.0.5, allows remote attackers to execute arbitrary code via unknown vectors related to CSS "style handling," nodesets, and a length value, as demonstrated by Vincenzo Iozzo, Willem Pinckaers, and Ralf-Philipp Weinmann during a Pwn2Own competition at CanSecWest 2011.

10%
Низкий
больше 4 лет назад
github логотип
GHSA-4gc4-vfjg-7w73

Memory corruption in diag due to use after free while processing dci packet in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-4gc3-hqxg-hgp9

When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file can specify that requests to the localhost are to be sent through the proxy to another server. This behavior is disallowed by default when a proxy is manually configured, but when enabled could allow for attacks on services and tools that bind to the localhost for networked behavior if they are accessed through browsing. This vulnerability affects Firefox < 65.

CVSS3: 5.9
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4gc3-8hmv-3556

PHP remote file inclusion vulnerability in news.php in Fantastic News 2.1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[script_path] parameter. NOTE: it was later reported that 2.1.5 is also affected.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4gc3-2mvv-h54m

WorkforceROI Xpede 4.1 allows remote attackers to read user timesheets by modifying the TSN ID parameter to the ts_app_process.asp script, which is easily guessable because it is incremented by 1 for each new timesheet.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4gc2-344q-r2rw

MS-Agent vulnerable to Command Injection

CVSS3: 6.5
2%
Низкий
7 месяцев назад
github логотип
GHSA-4g9x-m9qw-6m5h

The Fabulas Infantiles (aka com.mobincube.android.sc_9I1A3) application 3.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4g9x-932h-9gm7

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16.6, RBK852 before 3.2.16.6, RBR850 before 3.2.16.6, and RBS850 before 3.2.16.6.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4g9x-65q8-9448

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4g9w-hcf4-wx2j

IObit Advanced SystemCare, which includes Monitor_win10_x64.sys or Monitor_win7_x64.sys, 1.2.0.5 (and possibly earlier versions) allows a user to send an IOCTL (0x9C402088) with a buffer containing user defined content. The driver's subroutine will execute a wrmsr instruction with the user's buffer for input.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4g9w-6f9w-cjc7

MP-SPDZ v0.3.8 was discovered to contain a stack overflow via the function OTExtensionWithMatrix::extend in /OT/OTExtensionWithMatrix.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted message.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4g9v-q78c-rpv5

The mintToken function of a smart contract implementation for HBCM, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4g9v-p2mj-pg7w

** DISPUTED ** The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 does not recognize attack patterns designed to operate against web pages that are encoded with utf-7, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting crafted utf-7 content. NOTE: the vendor reportedly disputes this issue, stating "Behaviour is by design."

11%
Средний
больше 4 лет назад
github логотип
GHSA-4g9r-vxhx-9pgx

Apache Commons Compress: Denial of service caused by an infinite loop for a corrupted DUMP file

CVSS3: 5.9
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу