Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 370 914

Количество 370 914

github логотип

GHSA-4cwr-57j7-96p4

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the commenting system in Review Board before 1.5.7 and 1.6.x before 1.6.3 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) diff viewer or (2) screenshot component.

EPSS: Низкий
github логотип

GHSA-4cwq-wchg-fr2c

больше 4 лет назад

FreeRDP prior to version 2.0.0-rc4 contains several Out-Of-Bounds Reads in the NTLM Authentication module that results in a Denial of Service (segfault).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4cwq-w82q-39jg

больше 4 лет назад

A vulnerability is in the 'MNU_top.htm' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access this page without any authentication. When processed, it exposes some key information for the device.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4cwq-j7jv-qmwg

10 месяцев назад

Grav vulnerable to Information Disclosure via IDOR in Grav Admin Panel

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4cwp-gp88-gw4f

больше 4 лет назад

The scanner engine in PrivaWall Antivirus 5.6 and earlier does not recognize the Office XML (aka Open Document XML) file format, which allows remote attackers to bypass malware detection via a crafted file embedded in a WordML document.

EPSS: Низкий
github логотип

GHSA-4cwm-fr3q-8q5g

больше 4 лет назад

Heap-based buffer overflow in RenRen Talk 2.9 allows remote attackers to execute arbitrary code via a crafted image in a chat message, as demonstrated using a PNG file.

EPSS: Низкий
github логотип

GHSA-4cwm-fmh5-v7xw

больше 4 лет назад

Tizen RT RTOS version 3.0.GBB is vulnerable to integer wrap-around in functions_calloc and mm_zalloc. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash

EPSS: Низкий
github логотип

GHSA-4cwj-qj59-c6vc

около 2 месяцев назад

Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Low)

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4cwh-prx4-4w5p

5 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: ensure names are nul-terminated Reject names that lack a \0 character before feeding them to functions that expect c-strings. Fixes tag is the most recent commit that needs this change.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4cwh-m6gc-c4p6

больше 1 года назад

TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid parameter in the setWiFiGuestCfg function.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4cwh-j7h3-gc75

около 2 лет назад

A Path Traversal and Remote File Inclusion (RFI) vulnerability exists in the parisneo/lollms-webui application, affecting versions v9.7 to the latest. The vulnerability arises from insufficient input validation in the `/apply_settings` function, allowing an attacker to manipulate the `discussion_db_name` parameter to traverse the file system and include arbitrary files. This issue is compounded by the bypass of input filtering in the `install_binding`, `reinstall_binding`, and `unInstall_binding` endpoints, despite the presence of a `sanitize_path_from_endpoint(data.name)` filter. Successful exploitation enables an attacker to upload and execute malicious code on the victim's system, leading to Remote Code Execution (RCE).

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-4cwh-h77q-9rqx

больше 4 лет назад

The scheduler in HTCondor before 8.2.6 allows remote authenticated users to execute arbitrary code.

EPSS: Низкий
github логотип

GHSA-4cwh-8w4g-jxxh

больше 3 лет назад

Answer contains Improper Access Control vulnerability

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4cwg-vmj9-q8qf

около 2 лет назад

SAP Document Builder does not perform necessary authorization checks for one of the function modules resulting in escalation of privileges causing low impact on confidentiality of the application.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4cwg-v2m9-rqc9

больше 2 лет назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rank Math Rank Math SEO allows Path Traversal.This issue affects Rank Math SEO: from n/a through 1.0.107.2.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-4cwg-hw55-3pxx

больше 4 лет назад

An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer; the computation is a part of the WebCapture module. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the vulnerability. A successful attack can lead to sensitive data exposure.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4cwg-hq24-8wr2

около 1 года назад

An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd web server. The strstr() function allows unauthenticated access to any request containing "/nobody" in the URL, bypassing login controls.

EPSS: Низкий
github логотип

GHSA-4cwf-xqmm-mjpv

больше 4 лет назад

A use after free in PrintPreview in Google Chrome prior to 58.0.3029.81 for Windows allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4cwf-q6r9-gq5q

больше 4 лет назад

On SRX Series devices configured with UTM services a buffer overflow vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS may allow an attacker to arbitrarily execute code or commands on the target to take over or otherwise impact the device by sending crafted packets to or through the device. This issue affects: Juniper Networks Junos OS on SRX Series: 15.1X49 versions prior to 15.1X49-D190; 17.4 versions prior to 17.4R2-S9; 17.4R3 and later versions prior to 18.1R3-S9; 18.2 versions prior to 18.2R3-S1; 18.3 versions prior to 18.3R2-S3, 18.3R3; 18.4 versions prior to 18.4R2-S3, 18.4R3; 19.1 versions prior to 19.1R1-S4, 19.1R2; 19.2 versions prior to 19.2R1-S1, 19.2R2. An indicator of compromise can be the following text in the UTM log: RT_UTM: AV_FILE_NOT_SCANNED_PASSED_MT:

EPSS: Низкий
github логотип

GHSA-4cwc-669q-r7hf

больше 1 года назад

The backup ZIPs are not signed by the application, leading to the possibility that an attacker can download a backup ZIP, modify and re-upload it. This allows the attacker to disrupt the application by configuring the services in a way that they are unable to run, making the application unusable. They can redirect traffic that is meant to be internal to their own hosted services and gathering information.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4cwr-57j7-96p4

Multiple cross-site scripting (XSS) vulnerabilities in the commenting system in Review Board before 1.5.7 and 1.6.x before 1.6.3 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) diff viewer or (2) screenshot component.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4cwq-wchg-fr2c

FreeRDP prior to version 2.0.0-rc4 contains several Out-Of-Bounds Reads in the NTLM Authentication module that results in a Denial of Service (segfault).

CVSS3: 7.5
5%
Низкий
больше 4 лет назад
github логотип
GHSA-4cwq-w82q-39jg

A vulnerability is in the 'MNU_top.htm' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote attacker to access this page without any authentication. When processed, it exposes some key information for the device.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4cwq-j7jv-qmwg

Grav vulnerable to Information Disclosure via IDOR in Grav Admin Panel

CVSS3: 4.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-4cwp-gp88-gw4f

The scanner engine in PrivaWall Antivirus 5.6 and earlier does not recognize the Office XML (aka Open Document XML) file format, which allows remote attackers to bypass malware detection via a crafted file embedded in a WordML document.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4cwm-fr3q-8q5g

Heap-based buffer overflow in RenRen Talk 2.9 allows remote attackers to execute arbitrary code via a crafted image in a chat message, as demonstrated using a PNG file.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4cwm-fmh5-v7xw

Tizen RT RTOS version 3.0.GBB is vulnerable to integer wrap-around in functions_calloc and mm_zalloc. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4cwj-qj59-c6vc

Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Low)

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-4cwh-prx4-4w5p

In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: ensure names are nul-terminated Reject names that lack a \0 character before feeding them to functions that expect c-strings. Fixes tag is the most recent commit that needs this change.

CVSS3: 7.1
0%
Низкий
5 месяцев назад
github логотип
GHSA-4cwh-m6gc-c4p6

TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid parameter in the setWiFiGuestCfg function.

CVSS3: 8.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-4cwh-j7h3-gc75

A Path Traversal and Remote File Inclusion (RFI) vulnerability exists in the parisneo/lollms-webui application, affecting versions v9.7 to the latest. The vulnerability arises from insufficient input validation in the `/apply_settings` function, allowing an attacker to manipulate the `discussion_db_name` parameter to traverse the file system and include arbitrary files. This issue is compounded by the bypass of input filtering in the `install_binding`, `reinstall_binding`, and `unInstall_binding` endpoints, despite the presence of a `sanitize_path_from_endpoint(data.name)` filter. Successful exploitation enables an attacker to upload and execute malicious code on the victim's system, leading to Remote Code Execution (RCE).

CVSS3: 7.7
0%
Низкий
около 2 лет назад
github логотип
GHSA-4cwh-h77q-9rqx

The scheduler in HTCondor before 8.2.6 allows remote authenticated users to execute arbitrary code.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4cwh-8w4g-jxxh

Answer contains Improper Access Control vulnerability

CVSS3: 9.8
6%
Низкий
больше 3 лет назад
github логотип
GHSA-4cwg-vmj9-q8qf

SAP Document Builder does not perform necessary authorization checks for one of the function modules resulting in escalation of privileges causing low impact on confidentiality of the application.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-4cwg-v2m9-rqc9

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rank Math Rank Math SEO allows Path Traversal.This issue affects Rank Math SEO: from n/a through 1.0.107.2.

CVSS3: 7.6
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4cwg-hw55-3pxx

An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer; the computation is a part of the WebCapture module. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the vulnerability. A successful attack can lead to sensitive data exposure.

CVSS3: 8.8
7%
Низкий
больше 4 лет назад
github логотип
GHSA-4cwg-hq24-8wr2

An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd web server. The strstr() function allows unauthenticated access to any request containing "/nobody" in the URL, bypassing login controls.

1%
Низкий
около 1 года назад
github логотип
GHSA-4cwf-xqmm-mjpv

A use after free in PrintPreview in Google Chrome prior to 58.0.3029.81 for Windows allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4cwf-q6r9-gq5q

On SRX Series devices configured with UTM services a buffer overflow vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS may allow an attacker to arbitrarily execute code or commands on the target to take over or otherwise impact the device by sending crafted packets to or through the device. This issue affects: Juniper Networks Junos OS on SRX Series: 15.1X49 versions prior to 15.1X49-D190; 17.4 versions prior to 17.4R2-S9; 17.4R3 and later versions prior to 18.1R3-S9; 18.2 versions prior to 18.2R3-S1; 18.3 versions prior to 18.3R2-S3, 18.3R3; 18.4 versions prior to 18.4R2-S3, 18.4R3; 19.1 versions prior to 19.1R1-S4, 19.1R2; 19.2 versions prior to 19.2R1-S1, 19.2R2. An indicator of compromise can be the following text in the UTM log: RT_UTM: AV_FILE_NOT_SCANNED_PASSED_MT:

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4cwc-669q-r7hf

The backup ZIPs are not signed by the application, leading to the possibility that an attacker can download a backup ZIP, modify and re-upload it. This allows the attacker to disrupt the application by configuring the services in a way that they are unable to run, making the application unusable. They can redirect traffic that is meant to be internal to their own hosted services and gathering information.

CVSS3: 8.8
0%
Низкий
больше 1 года назад

Уязвимостей на страницу