Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 370 914

Количество 370 914

github логотип

GHSA-4f5r-74rh-r693

больше 4 лет назад

Buffer overflow in AOL Instant Messenger (AIM) 4.7.2480, 4.8.2616, and other versions allows remote attackers to execute arbitrary code via a long argument in a game request (AddGame).

EPSS: Средний
github логотип

GHSA-4f5q-mmm6-fj92

7 месяцев назад

On TP-Link Tapo C260 v1, command injection vulnerability exists due to improper sanitization in certain POST parameters during configuration synchronization. An authenticated attacker can execute arbitrary system commands with high impact on confidentiality, integrity and availability. It may cause full device compromise.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-4f5q-9rv6-mx34

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in StaticStore Search Engine 1.189A and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to search.cgi, possibly the keywords parameter. NOTE: this issue was originally disputed by the vendor, but it has since been acknowledged.

EPSS: Низкий
github логотип

GHSA-4f5p-gq89-4wfh

9 месяцев назад

An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A hardcoded Flickr API key and secret are present in the publicly accessible Flickr Zimlet used by Zimbra Collaboration. Because these credentials are embedded directly in the Zimlet, any unauthorized party could retrieve them and misuse the Flickr integration. An attacker with access to the exposed credentials could impersonate the legitimate application and initiate valid Flickr OAuth flows. If a user is tricked into approving such a request, the attacker could gain access to the user s Flickr data. The hardcoded credentials have since been removed from the Zimlet code, and the associated key has been revoked.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-4f5p-28mj-x3pv

почти 2 года назад

A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been declared as critical. This vulnerability affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument command leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-4f5j-wqjr-hx49

около 1 месяца назад

A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-4f5j-ff9g-x3f2

больше 4 лет назад

Microsoft Office 2010 SP2, Office Compatibility Pack SP3, Word 2007 SP3, and Word 2010 SP2 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability." This vulnerability is different from those described in CVE-2017-0006, CVE-2017-0019, CVE-2017-0020, CVE-2017-0030, CVE-2017-0052, and CVE-2017-0053.

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-4f5h-wcj8-92w2

больше 4 лет назад

Untrusted search path vulnerability in the add_filename_to_string function in intl/gettext/loadmsgcat.c for Elinks 0.11.1 allows local users to cause Elinks to use an untrusted gettext message catalog (.po file) in a "../po" directory, which can be leveraged to conduct format string attacks.

EPSS: Низкий
github логотип

GHSA-4f5h-cx3j-mxcj

около 3 лет назад

In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07536951; Issue ID: ALPS07536951.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-4f5h-cfp2-m9r7

больше 4 лет назад

SAP Note Assistant tool (SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31,7.40, from 7.50 to 7.52) supports upload of digitally signed note file of type 'SAR'. The digital signature verification is done together with the extraction of note file contained in the SAR archive. It is possible to append a tampered file to the SAR archive using SAPCAR tool and during the extraction, digital signature verification fails but the tampered file is extracted.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4f5h-42qx-mp6w

почти 2 года назад

Incorrect default permissions in the AMD Management Console installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4f5g-j7wg-7w8j

больше 4 лет назад

ChakraCore RCE Vulnerability

CVSS3: 7.5
EPSS: Высокий
github логотип

GHSA-4f5g-h3x2-8v9x

около 3 лет назад

An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in renesas_usb3_remove in drivers/usb/gadget/udc/renesas_usb3.c.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-4f5g-64px-29pq

больше 4 лет назад

The remove_bad_chars function in utils/cups-browsed.c in cups-filters before 1.0.66 allows remote IPP printers to execute arbitrary commands via consecutive shell metacharacters in the (1) model or (2) PDL. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2707.

EPSS: Низкий
github логотип

GHSA-4f5g-544m-849j

больше 4 лет назад

The employee management page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the employee ID in specific parameters to arbitrary access employee's data, modify it, and then obtain administrator privilege and execute arbitrary command.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4f5f-jrp7-rch3

больше 4 лет назад

The mintToken function of a smart contract implementation for Mimicoin, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4f5c-wcxh-wgv3

4 месяца назад

A buffer overflow vulnerability within AMD Sensor Fusion Hub Driver can allow a local attacker to write out of bounds, potentially resulting in denial of service or crash

EPSS: Низкий
github логотип

GHSA-4f5c-56m7-ww92

около 4 лет назад

Windows Bluetooth Service Remote Code Execution Vulnerability.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4f5c-477m-3p63

больше 3 лет назад

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1376.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4f59-x6gm-7h9h

больше 4 лет назад

TG Soft Vir.IT eXplorer Lite 8.5.42 allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a NULL value in a 0x82730010 DeviceIoControl request to \\.\Viragtlt.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4f5r-74rh-r693

Buffer overflow in AOL Instant Messenger (AIM) 4.7.2480, 4.8.2616, and other versions allows remote attackers to execute arbitrary code via a long argument in a game request (AddGame).

16%
Средний
больше 4 лет назад
github логотип
GHSA-4f5q-mmm6-fj92

On TP-Link Tapo C260 v1, command injection vulnerability exists due to improper sanitization in certain POST parameters during configuration synchronization. An authenticated attacker can execute arbitrary system commands with high impact on confidentiality, integrity and availability. It may cause full device compromise.

CVSS3: 8.8
22%
Средний
7 месяцев назад
github логотип
GHSA-4f5q-9rv6-mx34

Cross-site scripting (XSS) vulnerability in StaticStore Search Engine 1.189A and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to search.cgi, possibly the keywords parameter. NOTE: this issue was originally disputed by the vendor, but it has since been acknowledged.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4f5p-gq89-4wfh

An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A hardcoded Flickr API key and secret are present in the publicly accessible Flickr Zimlet used by Zimbra Collaboration. Because these credentials are embedded directly in the Zimlet, any unauthorized party could retrieve them and misuse the Flickr integration. An attacker with access to the exposed credentials could impersonate the legitimate application and initiate valid Flickr OAuth flows. If a user is tricked into approving such a request, the attacker could gain access to the user s Flickr data. The hardcoded credentials have since been removed from the Zimlet code, and the associated key has been revoked.

CVSS3: 4.7
0%
Низкий
9 месяцев назад
github логотип
GHSA-4f5p-28mj-x3pv

A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been declared as critical. This vulnerability affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument command leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
3%
Низкий
почти 2 года назад
github логотип
GHSA-4f5j-wqjr-hx49

A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.

CVSS3: 4.4
0%
Низкий
около 1 месяца назад
github логотип
GHSA-4f5j-ff9g-x3f2

Microsoft Office 2010 SP2, Office Compatibility Pack SP3, Word 2007 SP3, and Word 2010 SP2 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability." This vulnerability is different from those described in CVE-2017-0006, CVE-2017-0019, CVE-2017-0020, CVE-2017-0030, CVE-2017-0052, and CVE-2017-0053.

CVSS3: 7.8
26%
Средний
больше 4 лет назад
github логотип
GHSA-4f5h-wcj8-92w2

Untrusted search path vulnerability in the add_filename_to_string function in intl/gettext/loadmsgcat.c for Elinks 0.11.1 allows local users to cause Elinks to use an untrusted gettext message catalog (.po file) in a "../po" directory, which can be leveraged to conduct format string attacks.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4f5h-cx3j-mxcj

In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07536951; Issue ID: ALPS07536951.

CVSS3: 4.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-4f5h-cfp2-m9r7

SAP Note Assistant tool (SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31,7.40, from 7.50 to 7.52) supports upload of digitally signed note file of type 'SAR'. The digital signature verification is done together with the extraction of note file contained in the SAR archive. It is possible to append a tampered file to the SAR archive using SAPCAR tool and during the extraction, digital signature verification fails but the tampered file is extracted.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4f5h-42qx-mp6w

Incorrect default permissions in the AMD Management Console installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

CVSS3: 7.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-4f5g-j7wg-7w8j

ChakraCore RCE Vulnerability

CVSS3: 7.5
80%
Высокий
больше 4 лет назад
github логотип
GHSA-4f5g-h3x2-8v9x

An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in renesas_usb3_remove in drivers/usb/gadget/udc/renesas_usb3.c.

CVSS3: 7
1%
Низкий
около 3 лет назад
github логотип
GHSA-4f5g-64px-29pq

The remove_bad_chars function in utils/cups-browsed.c in cups-filters before 1.0.66 allows remote IPP printers to execute arbitrary commands via consecutive shell metacharacters in the (1) model or (2) PDL. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2707.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4f5g-544m-849j

The employee management page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated as a general user, remote attackers can manipulate the employee ID in specific parameters to arbitrary access employee's data, modify it, and then obtain administrator privilege and execute arbitrary command.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4f5f-jrp7-rch3

The mintToken function of a smart contract implementation for Mimicoin, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4f5c-wcxh-wgv3

A buffer overflow vulnerability within AMD Sensor Fusion Hub Driver can allow a local attacker to write out of bounds, potentially resulting in denial of service or crash

0%
Низкий
4 месяца назад
github логотип
GHSA-4f5c-56m7-ww92

Windows Bluetooth Service Remote Code Execution Vulnerability.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-4f5c-477m-3p63

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1376.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-4f59-x6gm-7h9h

TG Soft Vir.IT eXplorer Lite 8.5.42 allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a NULL value in a 0x82730010 DeviceIoControl request to \\.\Viragtlt.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу