Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 370 914

Количество 370 914

github логотип

GHSA-4f79-fxh8-vgq2

больше 4 лет назад

ChakraCore RCE Vulnerability

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-4f78-qhmw-8j8m

около 1 месяца назад

Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-4f77-xqjh-98gr

больше 4 лет назад

This issue was addressed with improved checks. This issue is fixed in tvOS 14.6, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. A local attacker may be able to elevate their privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4f76-h37g-4r3h

больше 1 года назад

The School Management System for Wordpress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'mj_smgt_remove_feetype' and 'mj_smgt_remove_category_new' AJAX actions in all versions up to, and including, 93.0.0. This makes it possible for unauthenticated attackers to delete arbitrary posts.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4f76-c3p6-5cgx

около 3 лет назад

A stack-based buffer overflow issue was found in ImageMagick's coders/tiff.c. This flaw allows an attacker to trick the user into opening a specially crafted malicious tiff file, causing an application to crash, resulting in a denial of service.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4f76-8jp4-59r6

больше 4 лет назад

LiquidFiles 3.4.15 has stored XSS through the "send email" functionality when sending a file via email to an administrator. When a file has no extension and contains malicious HTML / JavaScript content (such as SVG with HTML content), the payload is executed upon a click. This is fixed in 3.5.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4f74-wg9f-2vfm

больше 4 лет назад

Unspecified vulnerability in the autofs module in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv_108, allows local users to cause a denial of service (autofs mount outage) or possibly gain privileges via vectors related to "xdr processing problems."

EPSS: Низкий
github логотип

GHSA-4f74-rpch-f3gc

около 1 месяца назад

A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Such manipulation of the argument Comment leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4f74-84v3-j9q5

почти 3 года назад

matrix-synapse vulnerable to temporary storage of plaintext passwords during password changes

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-4f73-vfvh-47v4

больше 4 лет назад

Buffer overflow in the PostScript file interpreter code for Xerox CopyCentre and Xerox WorkCentre Pro, running software 1.001.02.073 or earlier, or 1.001.02.074 before 1.001.02.715, allows attackers to cause a denial of service via unknown vectors.

EPSS: Низкий
github логотип

GHSA-4f73-r2j2-j4h5

больше 4 лет назад

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a buffer overflow on an affected system. The vulnerability is due to insufficient boundary checks for specific data that is provided to the web services interface of an affected system. An attacker could exploit this vulnerability by sending a malicious HTTP request. A successful exploit could allow the attacker to cause a buffer overflow condition on the affected system, which could disclose data fragments or cause the device to reload, resulting in a denial of service (DoS) condition.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4f73-836m-4mcr

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: NFSD: Never decrement pending_async_copies on error The error flow in nfsd4_copy() calls cleanup_async_copy(), which already decrements nn->pending_async_copies.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4f73-499v-x32x

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Don't treat wb connector as physical in create_validate_stream_for_sink Don't try to operate on a drm_wb_connector as an amdgpu_dm_connector. While dereferencing aconnector->base will "work" it's wrong and might lead to unknown bad things. Just... don't.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4f72-c7gm-9h2j

больше 4 лет назад

Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Advanced Outbound Telephony, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Outbound Telephony accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Outbound Telephony accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).

EPSS: Средний
github логотип

GHSA-4f72-53xg-j632

больше 4 лет назад

The XMLHTTP ActiveX controls in XML Core Services 3.0 in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to bypass the Same Origin Policy via a web page that is visited in Internet Explorer, aka "MSXML Information Disclosure Vulnerability."

EPSS: Средний
github логотип

GHSA-4f6x-h73m-pq6f

6 месяцев назад

Authentication Bypass Using an Alternate Path or Channel vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Authentication Abuse.This issue affects Contest Gallery: from n/a through <= 28.1.2.2.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4f6x-h2gv-fj5p

больше 4 лет назад

Automotive Shop Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via /asms/classes/Master.php?f=save_product, name.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4f6x-g5vh-8jm5

больше 4 лет назад

Stored XSS vulnerability in Jenkins Active Choices Plugin

CVSS3: 4.6
EPSS: Высокий
github логотип

GHSA-4f6x-49g2-99fm

почти 5 лет назад

Cross-site Scripting in Mermaid

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4f6w-wg6v-cghx

около 3 лет назад

IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information due to an insecure security configuration in InfoSphere Data Flow Designer. IBM X-Force ID: 259352.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4f79-fxh8-vgq2

ChakraCore RCE Vulnerability

CVSS3: 7.5
69%
Средний
больше 4 лет назад
github логотип
GHSA-4f78-qhmw-8j8m

Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter

CVSS3: 5.7
0%
Низкий
около 1 месяца назад
github логотип
GHSA-4f77-xqjh-98gr

This issue was addressed with improved checks. This issue is fixed in tvOS 14.6, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. A local attacker may be able to elevate their privileges.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4f76-h37g-4r3h

The School Management System for Wordpress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'mj_smgt_remove_feetype' and 'mj_smgt_remove_category_new' AJAX actions in all versions up to, and including, 93.0.0. This makes it possible for unauthenticated attackers to delete arbitrary posts.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-4f76-c3p6-5cgx

A stack-based buffer overflow issue was found in ImageMagick's coders/tiff.c. This flaw allows an attacker to trick the user into opening a specially crafted malicious tiff file, causing an application to crash, resulting in a denial of service.

CVSS3: 5.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-4f76-8jp4-59r6

LiquidFiles 3.4.15 has stored XSS through the "send email" functionality when sending a file via email to an administrator. When a file has no extension and contains malicious HTML / JavaScript content (such as SVG with HTML content), the payload is executed upon a click. This is fixed in 3.5.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4f74-wg9f-2vfm

Unspecified vulnerability in the autofs module in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv_108, allows local users to cause a denial of service (autofs mount outage) or possibly gain privileges via vectors related to "xdr processing problems."

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4f74-rpch-f3gc

A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. Such manipulation of the argument Comment leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.

CVSS3: 8.8
1%
Низкий
около 1 месяца назад
github логотип
GHSA-4f74-84v3-j9q5

matrix-synapse vulnerable to temporary storage of plaintext passwords during password changes

CVSS3: 3.7
0%
Низкий
почти 3 года назад
github логотип
GHSA-4f73-vfvh-47v4

Buffer overflow in the PostScript file interpreter code for Xerox CopyCentre and Xerox WorkCentre Pro, running software 1.001.02.073 or earlier, or 1.001.02.074 before 1.001.02.715, allows attackers to cause a denial of service via unknown vectors.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4f73-r2j2-j4h5

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a buffer overflow on an affected system. The vulnerability is due to insufficient boundary checks for specific data that is provided to the web services interface of an affected system. An attacker could exploit this vulnerability by sending a malicious HTTP request. A successful exploit could allow the attacker to cause a buffer overflow condition on the affected system, which could disclose data fragments or cause the device to reload, resulting in a denial of service (DoS) condition.

CVSS3: 7.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4f73-836m-4mcr

In the Linux kernel, the following vulnerability has been resolved: NFSD: Never decrement pending_async_copies on error The error flow in nfsd4_copy() calls cleanup_async_copy(), which already decrements nn->pending_async_copies.

CVSS3: 5.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-4f73-499v-x32x

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Don't treat wb connector as physical in create_validate_stream_for_sink Don't try to operate on a drm_wb_connector as an amdgpu_dm_connector. While dereferencing aconnector->base will "work" it's wrong and might lead to unknown bad things. Just... don't.

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-4f72-c7gm-9h2j

Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Advanced Outbound Telephony, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Outbound Telephony accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Outbound Telephony accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).

66%
Средний
больше 4 лет назад
github логотип
GHSA-4f72-53xg-j632

The XMLHTTP ActiveX controls in XML Core Services 3.0 in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to bypass the Same Origin Policy via a web page that is visited in Internet Explorer, aka "MSXML Information Disclosure Vulnerability."

19%
Средний
больше 4 лет назад
github логотип
GHSA-4f6x-h73m-pq6f

Authentication Bypass Using an Alternate Path or Channel vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Authentication Abuse.This issue affects Contest Gallery: from n/a through <= 28.1.2.2.

CVSS3: 9.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-4f6x-h2gv-fj5p

Automotive Shop Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via /asms/classes/Master.php?f=save_product, name.

CVSS3: 5.4
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4f6x-g5vh-8jm5

Stored XSS vulnerability in Jenkins Active Choices Plugin

CVSS3: 4.6
79%
Высокий
больше 4 лет назад
github логотип
GHSA-4f6x-49g2-99fm

Cross-site Scripting in Mermaid

CVSS3: 6.1
1%
Низкий
почти 5 лет назад
github логотип
GHSA-4f6w-wg6v-cghx

IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information due to an insecure security configuration in InfoSphere Data Flow Designer. IBM X-Force ID: 259352.

CVSS3: 4.3
1%
Низкий
около 3 лет назад

Уязвимостей на страницу