Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 371 326

Количество 371 326

github логотип

GHSA-4g2g-8pcm-99w8

больше 3 лет назад

Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4g2g-3x54-996g

6 месяцев назад

FlexHEX 2.71 contains a local buffer overflow vulnerability in the Stream Name field that allows local attackers to execute arbitrary code by triggering a structured exception handler (SEH) overflow. Attackers can craft a malicious text file with carefully aligned shellcode and SEH chain pointers, paste the contents into the Stream Name dialog, and execute arbitrary commands like calc.exe when the exception handler is triggered.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-4g2f-xcph-2335

7 месяцев назад

ingress-nginx has Improper Check for Unusual or Exceptional Conditions

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-4g2f-wf65-x5xp

больше 4 лет назад

The API in the WebKit Plug-ins component in Apple Safari before 9 does not provide notification of an HTTP Redirection (aka 3xx) status code to a plugin, which allows remote attackers to bypass intended request restrictions via a crafted web site.

EPSS: Низкий
github логотип

GHSA-4g2f-q935-7ppv

больше 4 лет назад

PHP remote file inclusion vulnerability in end.php in ask_rave 0.9 PR, and other versions before 0.9b, allows remote attackers to execute arbitrary PHP code via a URL in the footfile parameter.

EPSS: Низкий
github логотип

GHSA-4g2f-j53w-6jfc

больше 2 лет назад

The database access credentials configured during installation are stored in a special table, and are encrypted with a shared key, same among all Comarch ERP XL client installations. This could allow an attacker with access to that table to retrieve plain text passwords. This issue affects ERP XL: from 2020.2.2 through 2023.2.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-4g2c-wq22-f9v3

больше 4 лет назад

** DISPUTED ** Mozilla Firefox 1.0.7 and 1.5.0.1 allows remote attackers to cause a denial of service (crash) via an HTML tag with a large number of script action handlers such as onload and onmouseover, which triggers the crash when the user views the page source. NOTE: Red Hat has disputed this issue, suggesting that "It is likely the reporter was running the IE Tab extension," and Mozilla also confirmed that this is not an issue in Firefox itself.

EPSS: Низкий
github логотип

GHSA-4g2c-w6c3-7ghw

больше 4 лет назад

Use-after-free vulnerability in the CPDF_Parser::IsLinearizedFile function in fpdfapi/fpdf_parser/fpdf_parser_parser.cpp in PDFium, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document.

EPSS: Низкий
github логотип

GHSA-4g2c-qjxv-9c24

больше 4 лет назад

LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs.

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-4g2c-h3mq-5rv5

больше 4 лет назад

Centrinity First Class Internet Services 5.50 allows for the circumventing of the default 'spam' filters via the presence of '<@>' in the 'From:' field, which allows remote attackers to send spoofed email with the identity of local users.

EPSS: Низкий
github логотип

GHSA-4g2c-9347-58ff

почти 3 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.0.3 versions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4g2c-8mg7-7g89

больше 4 лет назад

: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uploaditem.asp of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This issue affects: Telos Automated Message Handling System versions prior to 4.1.5.5.

EPSS: Низкий
github логотип

GHSA-4g29-r7vj-2rpv

почти 4 года назад

Jenkins Job Import Plugin allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4g29-fccr-p59w

больше 4 лет назад

Reflected Cross-site Scripting in Shopware storefront

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4g29-9cr3-v367

больше 4 лет назад

MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Change, as demonstrated by the port number of the web server.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4g28-wh72-jhwq

около 3 лет назад

Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusion and spoofing attacks. *This bug only affects Firefox and Focus for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox for Android < 112 and Focus for Android < 112.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-4g28-pqg3-vcxc

около 1 года назад

Improper Input Validation vulnerability in Samsung Open Source rLottie allows Overread Buffers.This issue affects rLottie: V0.2.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4g28-pcv2-qj5h

18 дней назад

wallabag 2 through 2.6.14 allows SSRF because a crafted title or content field is mishandled during PDF export.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-4g27-v2fc-m8fv

больше 4 лет назад

A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-4g27-q2w9-m8m8

около 3 лет назад

Magento affected by remote code execution vulnerability in the CMS page scheduled update feature

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4g2g-8pcm-99w8

Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-4g2g-3x54-996g

FlexHEX 2.71 contains a local buffer overflow vulnerability in the Stream Name field that allows local attackers to execute arbitrary code by triggering a structured exception handler (SEH) overflow. Attackers can craft a malicious text file with carefully aligned shellcode and SEH chain pointers, paste the contents into the Stream Name dialog, and execute arbitrary commands like calc.exe when the exception handler is triggered.

CVSS3: 8.4
0%
Низкий
6 месяцев назад
github логотип
GHSA-4g2f-xcph-2335

ingress-nginx has Improper Check for Unusual or Exceptional Conditions

CVSS3: 3.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-4g2f-wf65-x5xp

The API in the WebKit Plug-ins component in Apple Safari before 9 does not provide notification of an HTTP Redirection (aka 3xx) status code to a plugin, which allows remote attackers to bypass intended request restrictions via a crafted web site.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4g2f-q935-7ppv

PHP remote file inclusion vulnerability in end.php in ask_rave 0.9 PR, and other versions before 0.9b, allows remote attackers to execute arbitrary PHP code via a URL in the footfile parameter.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4g2f-j53w-6jfc

The database access credentials configured during installation are stored in a special table, and are encrypted with a shared key, same among all Comarch ERP XL client installations. This could allow an attacker with access to that table to retrieve plain text passwords. This issue affects ERP XL: from 2020.2.2 through 2023.2.

CVSS3: 6.2
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4g2c-wq22-f9v3

** DISPUTED ** Mozilla Firefox 1.0.7 and 1.5.0.1 allows remote attackers to cause a denial of service (crash) via an HTML tag with a large number of script action handlers such as onload and onmouseover, which triggers the crash when the user views the page source. NOTE: Red Hat has disputed this issue, suggesting that "It is likely the reporter was running the IE Tab extension," and Mozilla also confirmed that this is not an issue in Firefox itself.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4g2c-w6c3-7ghw

Use-after-free vulnerability in the CPDF_Parser::IsLinearizedFile function in fpdfapi/fpdf_parser/fpdf_parser_parser.cpp in PDFium, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4g2c-qjxv-9c24

LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs.

CVSS3: 5.6
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4g2c-h3mq-5rv5

Centrinity First Class Internet Services 5.50 allows for the circumventing of the default 'spam' filters via the presence of '<@>' in the 'From:' field, which allows remote attackers to send spoofed email with the identity of local users.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4g2c-9347-58ff

Cross-Site Request Forgery (CSRF) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.0.3 versions.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-4g2c-8mg7-7g89

: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uploaditem.asp of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This issue affects: Telos Automated Message Handling System versions prior to 4.1.5.5.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4g29-r7vj-2rpv

Jenkins Job Import Plugin allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins

CVSS3: 4.3
1%
Низкий
почти 4 года назад
github логотип
GHSA-4g29-fccr-p59w

Reflected Cross-site Scripting in Shopware storefront

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4g29-9cr3-v367

MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Change, as demonstrated by the port number of the web server.

CVSS3: 7.5
5%
Низкий
больше 4 лет назад
github логотип
GHSA-4g28-wh72-jhwq

Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusion and spoofing attacks. *This bug only affects Firefox and Focus for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox for Android < 112 and Focus for Android < 112.

CVSS3: 9.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-4g28-pqg3-vcxc

Improper Input Validation vulnerability in Samsung Open Source rLottie allows Overread Buffers.This issue affects rLottie: V0.2.

CVSS3: 9.8
0%
Низкий
около 1 года назад
github логотип
GHSA-4g28-pcv2-qj5h

wallabag 2 through 2.6.14 allows SSRF because a crafted title or content field is mishandled during PDF export.

CVSS3: 6.4
0%
Низкий
18 дней назад
github логотип
GHSA-4g27-v2fc-m8fv

A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP.

CVSS3: 6.7
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4g27-q2w9-m8m8

Magento affected by remote code execution vulnerability in the CMS page scheduled update feature

CVSS3: 9.1
2%
Низкий
около 3 лет назад

Уязвимостей на страницу