Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 371 326

Количество 371 326

github логотип

GHSA-4g54-g63j-qr8v

больше 4 лет назад

An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. XSS can occur via a link on an error page.

EPSS: Низкий
github логотип

GHSA-4g54-95xv-f353

около 8 лет назад

http-proxy.js is malware

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4g53-vp7q-gfjv

больше 5 лет назад

constructEvent does not verify header

EPSS: Низкий
github логотип

GHSA-4g53-844p-p879

больше 1 года назад

In Raptor RDF Syntax Library through 2.0.16, there is a heap-based buffer over-read when parsing triples with the nquads parser in raptor_ntriples_parse_term_internal().

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-4g52-qrp4-6j69

почти 3 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Ulf Benjaminsson WP-dTree plugin <= 4.4.5 versions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4g52-pqcj-phvh

больше 5 лет назад

BLS Signature "Malleability"

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4g52-pq8j-6qv5

больше 1 года назад

TYPO3 Extension Manager Module vulnerable to Cross-Site Request Forgery

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4g52-pmx3-v5c4

больше 4 лет назад

The DNS packet parser in YADIFA before 2.2.6 does not check for the presence of infinite pointer loops, and thus it is possible to force it to enter an infinite loop. This can cause high CPU usage and makes the server unresponsive.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4g4x-f7hr-8q9p

около 4 лет назад

Persistent cross-site scripting (XSS) in Crime Reporting System 1.0 allows a remote attacker to introduce arbitary Javascript via manipulation of an unsanitized POST parameter

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4g4x-f3f9-gpq4

6 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: apparmor: fix race between freeing data and fs accessing it AppArmor was putting the reference to i_private data on its end after removing the original entry from the file system. However the inode can aand does live beyond that point and it is possible that some of the fs call back functions will be invoked after the reference has been put, which results in a race between freeing the data and accessing it through the fs. While the rawdata/loaddata is the most likely candidate to fail the race, as it has the fewest references. If properly crafted it might be possible to trigger a race for the other types stored in i_private. Fix this by moving the put of i_private referenced data to the correct place which is during inode eviction.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4g4w-x2j6-rp8q

около 4 лет назад

Honeywell Experion PKS Safety Manager 5.02 uses Hard-coded Credentials. According to FSCT-2022-0052, there is a Honeywell Experion PKS Safety Manager hardcoded credentials issue. The affected components are characterized as: POLO bootloader. The potential impact is: Manipulate firmware. The Honeywell Experion PKS Safety Manager utilizes the DCOM-232/485 serial interface for firmware management purposes. When booting, the Safety Manager exposes the Enea POLO bootloader via this interface. Access to the boot configuration is controlled by means of credentials hardcoded in the Safety Manager firmware. The credentials for the bootloader are hardcoded in the firmware. An attacker with access to the serial interface (either through physical access, a compromised EWS or an exposed serial-to-ethernet gateway) can utilize these credentials to control the boot process and manipulate the unauthenticated firmware image (see FSCT-2022-0054).

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-4g4w-jrfj-2m5p

почти 2 года назад

Boa web server - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4g4v-5cg8-c9g6

больше 3 лет назад

inventory in Atos Unify OpenScape 4000 Platform and OpenScape 4000 Manager Platform 10 R1 before 10 R1.34.4 allows an unauthenticated attacker to run arbitrary commands on the platform operating system and achieve administrative access, aka OSFOURK-23543.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4g4r-m9qf-wf8m

больше 4 лет назад

An out-of-bounds read can be exploited in Autodesk TrueView 2022 may lead to an exposure of sensitive information or a crash through using a maliciously crafted DWG file as an Input. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4g4r-f763-vv8x

больше 2 лет назад

Memory safety bugs present in Firefox 124. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 125.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-4g4q-v35j-pfp4

9 месяцев назад

NVIDIA Merlin Transformers4Rec for Linux contains a vulnerability in the Trainer component, where a user could cause a deserialization issue. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4g4q-q7g9-8775

больше 4 лет назад

Multiple off-by-one errors in src/text.c in Vilistextum before 2.6.9 have unknown impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-4g4q-fph6-6vcc

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in omnipressteam Omnipress allows DOM-Based XSS. This issue affects Omnipress: from n/a through 1.6.3.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4g4p-rr9c-6r55

больше 1 года назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий
github логотип

GHSA-4g4p-chhg-9v66

больше 4 лет назад

A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The Gif_loader.dll library in affected applications lacks proper validation of user-supplied data when parsing GIF files. This could result in an out of bounds write past the end of an allocated structure. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-13340)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4g54-g63j-qr8v

An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. XSS can occur via a link on an error page.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4g54-95xv-f353

http-proxy.js is malware

CVSS3: 7.5
1%
Низкий
около 8 лет назад
github логотип
GHSA-4g53-vp7q-gfjv

constructEvent does not verify header

больше 5 лет назад
github логотип
GHSA-4g53-844p-p879

In Raptor RDF Syntax Library through 2.0.16, there is a heap-based buffer over-read when parsing triples with the nquads parser in raptor_ntriples_parse_term_internal().

CVSS3: 4
0%
Низкий
больше 1 года назад
github логотип
GHSA-4g52-qrp4-6j69

Cross-Site Request Forgery (CSRF) vulnerability in Ulf Benjaminsson WP-dTree plugin <= 4.4.5 versions.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-4g52-pqcj-phvh

BLS Signature "Malleability"

CVSS3: 5.9
1%
Низкий
больше 5 лет назад
github логотип
GHSA-4g52-pq8j-6qv5

TYPO3 Extension Manager Module vulnerable to Cross-Site Request Forgery

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-4g52-pmx3-v5c4

The DNS packet parser in YADIFA before 2.2.6 does not check for the presence of infinite pointer loops, and thus it is possible to force it to enter an infinite loop. This can cause high CPU usage and makes the server unresponsive.

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4g4x-f7hr-8q9p

Persistent cross-site scripting (XSS) in Crime Reporting System 1.0 allows a remote attacker to introduce arbitary Javascript via manipulation of an unsanitized POST parameter

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-4g4x-f3f9-gpq4

In the Linux kernel, the following vulnerability has been resolved: apparmor: fix race between freeing data and fs accessing it AppArmor was putting the reference to i_private data on its end after removing the original entry from the file system. However the inode can aand does live beyond that point and it is possible that some of the fs call back functions will be invoked after the reference has been put, which results in a race between freeing the data and accessing it through the fs. While the rawdata/loaddata is the most likely candidate to fail the race, as it has the fewest references. If properly crafted it might be possible to trigger a race for the other types stored in i_private. Fix this by moving the put of i_private referenced data to the correct place which is during inode eviction.

CVSS3: 7.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-4g4w-x2j6-rp8q

Honeywell Experion PKS Safety Manager 5.02 uses Hard-coded Credentials. According to FSCT-2022-0052, there is a Honeywell Experion PKS Safety Manager hardcoded credentials issue. The affected components are characterized as: POLO bootloader. The potential impact is: Manipulate firmware. The Honeywell Experion PKS Safety Manager utilizes the DCOM-232/485 serial interface for firmware management purposes. When booting, the Safety Manager exposes the Enea POLO bootloader via this interface. Access to the boot configuration is controlled by means of credentials hardcoded in the Safety Manager firmware. The credentials for the bootloader are hardcoded in the firmware. An attacker with access to the serial interface (either through physical access, a compromised EWS or an exposed serial-to-ethernet gateway) can utilize these credentials to control the boot process and manipulate the unauthenticated firmware image (see FSCT-2022-0054).

CVSS3: 4.6
0%
Низкий
около 4 лет назад
github логотип
GHSA-4g4w-jrfj-2m5p

Boa web server - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSS3: 7.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-4g4v-5cg8-c9g6

inventory in Atos Unify OpenScape 4000 Platform and OpenScape 4000 Manager Platform 10 R1 before 10 R1.34.4 allows an unauthenticated attacker to run arbitrary commands on the platform operating system and achieve administrative access, aka OSFOURK-23543.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4g4r-m9qf-wf8m

An out-of-bounds read can be exploited in Autodesk TrueView 2022 may lead to an exposure of sensitive information or a crash through using a maliciously crafted DWG file as an Input. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

CVSS3: 7.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4g4r-f763-vv8x

Memory safety bugs present in Firefox 124. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 125.

CVSS3: 8.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4g4q-v35j-pfp4

NVIDIA Merlin Transformers4Rec for Linux contains a vulnerability in the Trainer component, where a user could cause a deserialization issue. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.

CVSS3: 8.8
1%
Низкий
9 месяцев назад
github логотип
GHSA-4g4q-q7g9-8775

Multiple off-by-one errors in src/text.c in Vilistextum before 2.6.9 have unknown impact and attack vectors.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4g4q-fph6-6vcc

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in omnipressteam Omnipress allows DOM-Based XSS. This issue affects Omnipress: from n/a through 1.6.3.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-4g4p-rr9c-6r55

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

больше 1 года назад
github логотип
GHSA-4g4p-chhg-9v66

A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The Gif_loader.dll library in affected applications lacks proper validation of user-supplied data when parsing GIF files. This could result in an out of bounds write past the end of an allocated structure. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-13340)

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу