Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 371 326

Количество 371 326

github логотип

GHSA-4g5m-c9r5-49xf

около 2 месяцев назад

LiteLLM: Local file read via request-supplied OIDC file references

EPSS: Низкий
github логотип

GHSA-4g5j-f8c3-p2cx

5 дней назад

Dell ThinOS 10, versions prior to 2605_10.2616, contain a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to arbitrary code execution.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-4g5h-x2gw-q6h2

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in JBMC Software DirectAdmin before 1.293 does not properly display log files, which allows remote authenticated users to inject arbitrary web script or HTML via (1) http or (2) ftp requests logged in /var/log/directadmin/security.log; (3) allows context-dependent attackers to inject arbitrary web script or HTML into /var/log/messages via a PHP script that invokes /usr/bin/logger; (4) allows local users to inject arbitrary web script or HTML into /var/log/messages by invoking /usr/bin/logger at the command line; and allows remote attackers to inject arbitrary web script or HTML via remote requests logged in the (5) /var/log/exim/rejectlog, (6) /var/log/exim/mainlog, (7) /var/log/proftpd/auth.log, (8) /var/log/httpd/error_log, (9) /var/log/httpd/access_log, (10) /var/log/directadmin/error.log, and (11) /var/log/directadmin/security.log files.

EPSS: Низкий
github логотип

GHSA-4g5h-vp8c-mrhf

почти 5 лет назад

SAF-T Framework Transaction SAFTN_G allows an attacker to exploit insufficient validation of path information provided by normal user, leading to full server directory access. The attacker can see the whole filesystem structure but cannot overwrite, delete, or corrupt arbitrary files on the server.

EPSS: Низкий
github логотип

GHSA-4g5h-7prv-mvj5

около 3 лет назад

An issue was discovered in IceCMS version 2.0.1, allows attackers to escalate privileges and gain sensitive information via UserID parameter in api/User/ChangeUser.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4g5g-f23m-c94v

почти 2 года назад

Concurrent variable access vulnerability in the ability module Impact: Successful exploitation of this vulnerability may affect availability.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-4g5f-w3mh-w99m

почти 3 года назад

Jenkins Nexus Platform Plugin missing permission check

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-4g5c-r533-fvfw

больше 1 года назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий
github логотип

GHSA-4g5c-cjq7-xrqv

больше 4 лет назад

On BIG-IP versions 14.1.4 and 16.0.1.1, when the Traffic Management Microkernel (TMM) process handles certain undisclosed traffic, it may start dropping all fragmented IP traffic. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

EPSS: Низкий
github логотип

GHSA-4g5c-5cvj-g3xc

почти 3 года назад

Improper usage of implicit intent in Contacts prior to SMR Dec-2023 Release 1 allows attacker to get sensitive information.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-4g59-wgcx-qw47

больше 4 лет назад

An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4g59-c88f-q65h

больше 4 лет назад

WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.

EPSS: Низкий
github логотип

GHSA-4g58-p6wm-2vf3

больше 4 лет назад

In updateCapabilities of ConnectivityService.java, there is a possible incorrect network state determination due to a logic error in the code. This could lead to biasing of networking tasks to occur on non-VPN networks, which could lead to remote information disclosure, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-179053823

EPSS: Низкий
github логотип

GHSA-4g58-3rh2-qf9r

больше 4 лет назад

Delta Electronics ISPSoft version 3.0.5 and prior allow an attacker, by opening a crafted file, to cause the application to read past the boundary allocated to a stack object, which could allow execution of code under the context of the application.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4g57-hx3x-hg92

около 1 года назад

Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4g56-8mc7-hpjq

больше 4 лет назад

A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.

CVSS3: 8.8
EPSS: Критический
github логотип

GHSA-4g55-jg35-rh33

больше 4 лет назад

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may lead to arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-4g55-4rvx-39f6

19 дней назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

EPSS: Низкий
github логотип

GHSA-4g55-4fxv-2g82

больше 4 лет назад

A vulnerability was found in Radare2 in versions prior to 5.6.2, 5.6.0, 5.5.4 and 5.5.2. Mapping a huge section filled with zeros of an ELF64 binary for MIPS architecture can lead to uncontrolled resource consumption and DoS.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4g54-v22x-6xq2

около 2 месяцев назад

schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the host parsing logic. The dismantle_host() function parses untrusted host and URL input, and subsequent code uses clone_from() to copy parsed host, request host, extension and query_string segments into fixed heap buffers without boundary checking.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4g5m-c9r5-49xf

LiteLLM: Local file read via request-supplied OIDC file references

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-4g5j-f8c3-p2cx

Dell ThinOS 10, versions prior to 2605_10.2616, contain a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to arbitrary code execution.

CVSS3: 6.8
0%
Низкий
5 дней назад
github логотип
GHSA-4g5h-x2gw-q6h2

Cross-site scripting (XSS) vulnerability in JBMC Software DirectAdmin before 1.293 does not properly display log files, which allows remote authenticated users to inject arbitrary web script or HTML via (1) http or (2) ftp requests logged in /var/log/directadmin/security.log; (3) allows context-dependent attackers to inject arbitrary web script or HTML into /var/log/messages via a PHP script that invokes /usr/bin/logger; (4) allows local users to inject arbitrary web script or HTML into /var/log/messages by invoking /usr/bin/logger at the command line; and allows remote attackers to inject arbitrary web script or HTML via remote requests logged in the (5) /var/log/exim/rejectlog, (6) /var/log/exim/mainlog, (7) /var/log/proftpd/auth.log, (8) /var/log/httpd/error_log, (9) /var/log/httpd/access_log, (10) /var/log/directadmin/error.log, and (11) /var/log/directadmin/security.log files.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4g5h-vp8c-mrhf

SAF-T Framework Transaction SAFTN_G allows an attacker to exploit insufficient validation of path information provided by normal user, leading to full server directory access. The attacker can see the whole filesystem structure but cannot overwrite, delete, or corrupt arbitrary files on the server.

1%
Низкий
почти 5 лет назад
github логотип
GHSA-4g5h-7prv-mvj5

An issue was discovered in IceCMS version 2.0.1, allows attackers to escalate privileges and gain sensitive information via UserID parameter in api/User/ChangeUser.

CVSS3: 9.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-4g5g-f23m-c94v

Concurrent variable access vulnerability in the ability module Impact: Successful exploitation of this vulnerability may affect availability.

CVSS3: 6.2
0%
Низкий
почти 2 года назад
github логотип
GHSA-4g5f-w3mh-w99m

Jenkins Nexus Platform Plugin missing permission check

CVSS3: 4.2
0%
Низкий
почти 3 года назад
github логотип
GHSA-4g5c-r533-fvfw

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

больше 1 года назад
github логотип
GHSA-4g5c-cjq7-xrqv

On BIG-IP versions 14.1.4 and 16.0.1.1, when the Traffic Management Microkernel (TMM) process handles certain undisclosed traffic, it may start dropping all fragmented IP traffic. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4g5c-5cvj-g3xc

Improper usage of implicit intent in Contacts prior to SMR Dec-2023 Release 1 allows attacker to get sensitive information.

CVSS3: 3.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-4g59-wgcx-qw47

An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.

CVSS3: 6.5
7%
Низкий
больше 4 лет назад
github логотип
GHSA-4g59-c88f-q65h

WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4g58-p6wm-2vf3

In updateCapabilities of ConnectivityService.java, there is a possible incorrect network state determination due to a logic error in the code. This could lead to biasing of networking tasks to occur on non-VPN networks, which could lead to remote information disclosure, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-179053823

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4g58-3rh2-qf9r

Delta Electronics ISPSoft version 3.0.5 and prior allow an attacker, by opening a crafted file, to cause the application to read past the boundary allocated to a stack object, which could allow execution of code under the context of the application.

CVSS3: 7.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4g57-hx3x-hg92

Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.

CVSS3: 8.8
8%
Низкий
около 1 года назад
github логотип
GHSA-4g56-8mc7-hpjq

A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.

CVSS3: 8.8
100%
Критический
больше 4 лет назад
github логотип
GHSA-4g55-jg35-rh33

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1, Safari 12.1.1, iTunes for Windows 12.9.5, iCloud for Windows 7.12. Processing maliciously crafted web content may lead to arbitrary code execution.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-4g55-4rvx-39f6

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

19 дней назад
github логотип
GHSA-4g55-4fxv-2g82

A vulnerability was found in Radare2 in versions prior to 5.6.2, 5.6.0, 5.5.4 and 5.5.2. Mapping a huge section filled with zeros of an ELF64 binary for MIPS architecture can lead to uncontrolled resource consumption and DoS.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4g54-v22x-6xq2

schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the host parsing logic. The dismantle_host() function parses untrusted host and URL input, and subsequent code uses clone_from() to copy parsed host, request host, extension and query_string segments into fixed heap buffers without boundary checking.

CVSS3: 9.8
около 2 месяцев назад

Уязвимостей на страницу