Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 371 326

Количество 371 326

github логотип

GHSA-4g82-3jcr-q52w

больше 4 лет назад

Malware in ctx

EPSS: Низкий
github логотип

GHSA-4g7x-pvhw-3mph

почти 2 года назад

In isp, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09071481; Issue ID: MSV-1730.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-4g7x-7vgq-3j28

почти 5 лет назад

Vulnerability in list function leads to arbitrary code execution via filePath parameters

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4g7v-x2gv-v9qf

больше 4 лет назад

Heap-based buffer overflow in the opj_j2k_read_SPCod_SPCoc function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 51.0.2704.63, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4g7v-38jx-hv6c

почти 3 года назад

In wifi service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4g7r-3q85-mg82

больше 4 лет назад

SGI syserr program allows local users to corrupt files.

EPSS: Низкий
github логотип

GHSA-4g7q-xrgc-v37w

больше 1 года назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ashan Perera EventON allows PHP Local File Inclusion. This issue affects EventON: from n/a through 2.3.2.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4g7q-85r5-pm7w

больше 3 лет назад

Improper usage of implicit intent in Bluetooth prior to SMR Mar-2023 Release 1 allows attacker to get MAC address of connected device.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-4g7q-85g4-qw3w

больше 3 лет назад

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected system. An attacker could exploit this vulnerability by persuading a user of the interface to click a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user. These actions could include modifying the system configuration and deleting accounts.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-4g7q-7v9w-3x8m

больше 2 лет назад

DoS in KAS in GitLab CE/EE affecting all versions from 16.10.0 prior to 16.10.6 and 16.11.0 prior to 16.11.3 allows an attacker to crash KAS via crafted gRPC requests.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-4g7q-7553-2768

больше 4 лет назад

Improper permissions for Intel(R) USB 3.0 Creator Utility all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4g7q-44qp-cc5c

4 месяца назад

Concrete CMS is vulnerable to unauthenticated file usage disclosure

EPSS: Низкий
github логотип

GHSA-4g7p-889h-qvww

больше 1 года назад

Authenticated privilege escalation in NetScaler Console and NetScaler Agent allows.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-4g7p-5pq3-g6vh

больше 4 лет назад

An exploitable vulnerability exists in the remote control functionality of Circle with Disney running firmware 2.0.1. SSL certificates for specific domain names can cause the goclient daemon to accept a different certificate than intended. An attacker can host an HTTPS server with this certificate to trigger this vulnerability.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4g7p-53pf-4mw9

около 2 лет назад

Improper input validation in the Central Filestore in Ivanti Avalanche 6.3.1 allows a remote authenticated attacker with admin rights to achieve RCE.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-4g7m-g45x-47rp

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: ovl: fix warning in ovl_create_real() Syzbot triggered the following warning in ovl_workdir_create() -> ovl_create_real(): if (!err && WARN_ON(!newdentry->d_inode)) { The reason is that the cgroup2 filesystem returns from mkdir without instantiating the new dentry. Weird filesystems such as this will be rejected by overlayfs at a later stage during setup, but to prevent such a warning, call ovl_mkdir_real() directly from ovl_workdir_create() and reject this case early.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4g7m-fgrx-qqc3

больше 4 лет назад

Cisco IOS 12.3 and 12.4 on Aironet access points allows remote attackers to cause a denial of service (radio-interface input-queue hang) via IAPP 0x3281 packets, aka Bug ID CSCtc12426.

EPSS: Низкий
github логотип

GHSA-4g7j-qx49-cxcp

около 3 лет назад

Improper authentication vulnerability in Proself Enterprise/Standard Edition Ver5.61 and earlier, Proself Gateway Edition Ver1.62 and earlier, and Proself Mail Sanitize Edition Ver1.07 and earlier allow a remote unauthenticated attacker to log in to the product's Control Panel and perform an unintended operation.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4g7j-fjgw-f3qw

больше 4 лет назад

IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 have a vulnerability that allows an unauthenticated attacker to access memory ("write-what-where") from an attacker-chosen device address within the same subnet.

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-4g7j-ccqc-2759

больше 4 лет назад

The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as the management of access rights for such IP, including modification of a license-deny response to a license grant. The methods are flawed and, in the most egregious cases, enable attack vectors that allow recovery of the entire underlying plaintext IP. Implementations of IEEE P1735 may be weak to cryptographic attacks that allow an attacker to obtain plaintext intellectual property without the key, among other impacts.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4g82-3jcr-q52w

Malware in ctx

больше 4 лет назад
github логотип
GHSA-4g7x-pvhw-3mph

In isp, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09071481; Issue ID: MSV-1730.

CVSS3: 4.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-4g7x-7vgq-3j28

Vulnerability in list function leads to arbitrary code execution via filePath parameters

CVSS3: 9.8
2%
Низкий
почти 5 лет назад
github логотип
GHSA-4g7v-x2gv-v9qf

Heap-based buffer overflow in the opj_j2k_read_SPCod_SPCoc function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 51.0.2704.63, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4g7v-38jx-hv6c

In wifi service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-4g7r-3q85-mg82

SGI syserr program allows local users to corrupt files.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4g7q-xrgc-v37w

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ashan Perera EventON allows PHP Local File Inclusion. This issue affects EventON: from n/a through 2.3.2.

CVSS3: 8.8
2%
Низкий
больше 1 года назад
github логотип
GHSA-4g7q-85r5-pm7w

Improper usage of implicit intent in Bluetooth prior to SMR Mar-2023 Release 1 allows attacker to get MAC address of connected device.

CVSS3: 3.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4g7q-85g4-qw3w

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected system. An attacker could exploit this vulnerability by persuading a user of the interface to click a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user. These actions could include modifying the system configuration and deleting accounts.

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4g7q-7v9w-3x8m

DoS in KAS in GitLab CE/EE affecting all versions from 16.10.0 prior to 16.10.6 and 16.11.0 prior to 16.11.3 allows an attacker to crash KAS via crafted gRPC requests.

CVSS3: 3.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4g7q-7553-2768

Improper permissions for Intel(R) USB 3.0 Creator Utility all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4g7q-44qp-cc5c

Concrete CMS is vulnerable to unauthenticated file usage disclosure

1%
Низкий
4 месяца назад
github логотип
GHSA-4g7p-889h-qvww

Authenticated privilege escalation in NetScaler Console and NetScaler Agent allows.

CVSS3: 8.8
13%
Средний
больше 1 года назад
github логотип
GHSA-4g7p-5pq3-g6vh

An exploitable vulnerability exists in the remote control functionality of Circle with Disney running firmware 2.0.1. SSL certificates for specific domain names can cause the goclient daemon to accept a different certificate than intended. An attacker can host an HTTPS server with this certificate to trigger this vulnerability.

CVSS3: 5.9
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4g7p-53pf-4mw9

Improper input validation in the Central Filestore in Ivanti Avalanche 6.3.1 allows a remote authenticated attacker with admin rights to achieve RCE.

CVSS3: 7.2
2%
Низкий
около 2 лет назад
github логотип
GHSA-4g7m-g45x-47rp

In the Linux kernel, the following vulnerability has been resolved: ovl: fix warning in ovl_create_real() Syzbot triggered the following warning in ovl_workdir_create() -> ovl_create_real(): if (!err && WARN_ON(!newdentry->d_inode)) { The reason is that the cgroup2 filesystem returns from mkdir without instantiating the new dentry. Weird filesystems such as this will be rejected by overlayfs at a later stage during setup, but to prevent such a warning, call ovl_mkdir_real() directly from ovl_workdir_create() and reject this case early.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-4g7m-fgrx-qqc3

Cisco IOS 12.3 and 12.4 on Aironet access points allows remote attackers to cause a denial of service (radio-interface input-queue hang) via IAPP 0x3281 packets, aka Bug ID CSCtc12426.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4g7j-qx49-cxcp

Improper authentication vulnerability in Proself Enterprise/Standard Edition Ver5.61 and earlier, Proself Gateway Edition Ver1.62 and earlier, and Proself Mail Sanitize Edition Ver1.07 and earlier allow a remote unauthenticated attacker to log in to the product's Control Panel and perform an unintended operation.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-4g7j-fjgw-f3qw

IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 have a vulnerability that allows an unauthenticated attacker to access memory ("write-what-where") from an attacker-chosen device address within the same subnet.

CVSS3: 8.3
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4g7j-ccqc-2759

The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as the management of access rights for such IP, including modification of a license-deny response to a license grant. The methods are flawed and, in the most egregious cases, enable attack vectors that allow recovery of the entire underlying plaintext IP. Implementations of IEEE P1735 may be weak to cryptographic attacks that allow an attacker to obtain plaintext intellectual property without the key, among other impacts.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу