Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 370 914

Количество 370 914

github логотип

GHSA-4c7v-wvrw-qr33

больше 4 лет назад

RealNetworks RealPlayer 11.0 through 11.1, SP 1.0 through 1.1.5, and 14.0.0 through 14.0.1, and Enterprise 2.0 through 2.1.4, uses predictable names for temporary files, which allows remote attackers to conduct cross-domain scripting attacks and execute arbitrary code via the OpenURLinPlayerBrowser function.

EPSS: Низкий
github логотип

GHSA-4c7r-p7xg-3p7g

больше 4 лет назад

Buffer overflow in CG-WLR300NM Firmware version 1.90 and earlier allows an attacker to execute arbitrary code via unspecified vectors.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-4c7r-2m52-xmv2

больше 4 лет назад

The dissect_nhdr_extopt function in epan/dissectors/packet-lbmc.c in the LBMC dissector in Wireshark 2.0.x before 2.0.2 does not validate length values, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted packet.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4c7q-c36w-gpm4

больше 4 лет назад

An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "kext tools" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4c7q-995f-pxpc

больше 4 лет назад

Adobe Genuine Service versions 7.3 (and earlier) are affected by a privilege escalation vulnerability in the AGSService installer. An authenticated attacker could leverage this vulnerability to achieve read / write privileges to execute arbitrary code. User interaction is required to abuse this vulnerability.

EPSS: Низкий
github логотип

GHSA-4c7q-4928-8445

2 месяца назад

chmod: --preserve-root bypassed by any path that resolves to root (e.g. /../)

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4c7q-44j3-76m6

больше 4 лет назад

Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-4c7p-c7mq-74m6

6 месяцев назад

ASPRunner.NET 10.1 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the table name field. Attackers can input a buffer of 10000 characters in the table name parameter during database table creation to trigger an application crash.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-4c7m-wxvm-r7gc

больше 5 лет назад

Improper parsing of octal bytes in netmask

CVSS3: 9.1
EPSS: Средний
github логотип

GHSA-4c7m-vv47-7c69

больше 5 лет назад

Insecure Permissions in Gogs

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4c7m-gh7v-c837

больше 4 лет назад

Use-after-free vulnerability in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) via a crafted WMF file to the (1) wmf2gd or (2) wmf2eps command.

EPSS: Низкий
github логотип

GHSA-4c7m-2jpf-639x

11 месяцев назад

rplay through 3.3.2 allows attackers to cause a denial of service (SIGSEGV and daemon crash) or possibly have unspecified other impact. This occurs in memcpy in the RPLAY_DATA case in rplay_unpack in librplay/rplay.c, potentially reachable via packet data with no authentication.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4c7j-v446-xgx3

почти 3 года назад

In multiple functions of protocolembmsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4c7j-5rpp-4x8h

больше 4 лет назад

JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 22, allows remote attackers to cause a denial of service (heap-based out-of-bounds write and application crash) or possibly have unspecified other impact via crafted JavaScript code that triggers access to red-zone memory locations, related to jit/ThunkGenerators.cpp, llint/LowLevelInterpreter32_64.asm, and llint/LowLevelInterpreter64.asm.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4c7h-f2j9-9c46

больше 4 лет назад

Missing permission Jenkins Pipeline Phoenix AutoTest Plugin

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4c7h-552f-7g3h

около 3 лет назад

Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-4c7g-cv49-499p

почти 2 года назад

Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4c7g-99hq-whpv

больше 2 лет назад

Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Campaign LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Marketing accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4c7f-qhrm-6jc8

2 месяца назад

Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing. This issue affects AI (Artificial Intelligence) versions: from 0.0.0 to 1.2.17, from 1.3.0 to 1.3.8, from 1.4.0 to 1.4.3.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4c7f-4gjq-hwgh

больше 4 лет назад

Use-after-free vulnerability in the mozilla::dom::HTMLFormElement::IsDefaultSubmitElement function in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving a destroyed SELECT element.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4c7v-wvrw-qr33

RealNetworks RealPlayer 11.0 through 11.1, SP 1.0 through 1.1.5, and 14.0.0 through 14.0.1, and Enterprise 2.0 through 2.1.4, uses predictable names for temporary files, which allows remote attackers to conduct cross-domain scripting attacks and execute arbitrary code via the OpenURLinPlayerBrowser function.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-4c7r-p7xg-3p7g

Buffer overflow in CG-WLR300NM Firmware version 1.90 and earlier allows an attacker to execute arbitrary code via unspecified vectors.

CVSS3: 6.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4c7r-2m52-xmv2

The dissect_nhdr_extopt function in epan/dissectors/packet-lbmc.c in the LBMC dissector in Wireshark 2.0.x before 2.0.2 does not validate length values, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted packet.

CVSS3: 5.9
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4c7q-c36w-gpm4

An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "kext tools" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

CVSS3: 7.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-4c7q-995f-pxpc

Adobe Genuine Service versions 7.3 (and earlier) are affected by a privilege escalation vulnerability in the AGSService installer. An authenticated attacker could leverage this vulnerability to achieve read / write privileges to execute arbitrary code. User interaction is required to abuse this vulnerability.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4c7q-4928-8445

chmod: --preserve-root bypassed by any path that resolves to root (e.g. /../)

CVSS3: 7.3
0%
Низкий
2 месяца назад
github логотип
GHSA-4c7q-44j3-76m6

Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-4c7p-c7mq-74m6

ASPRunner.NET 10.1 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the table name field. Attackers can input a buffer of 10000 characters in the table name parameter during database table creation to trigger an application crash.

CVSS3: 6.2
0%
Низкий
6 месяцев назад
github логотип
GHSA-4c7m-wxvm-r7gc

Improper parsing of octal bytes in netmask

CVSS3: 9.1
17%
Средний
больше 5 лет назад
github логотип
GHSA-4c7m-vv47-7c69

Insecure Permissions in Gogs

CVSS3: 5.3
1%
Низкий
больше 5 лет назад
github логотип
GHSA-4c7m-gh7v-c837

Use-after-free vulnerability in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) via a crafted WMF file to the (1) wmf2gd or (2) wmf2eps command.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-4c7m-2jpf-639x

rplay through 3.3.2 allows attackers to cause a denial of service (SIGSEGV and daemon crash) or possibly have unspecified other impact. This occurs in memcpy in the RPLAY_DATA case in rplay_unpack in librplay/rplay.c, potentially reachable via packet data with no authentication.

CVSS3: 5.3
1%
Низкий
11 месяцев назад
github логотип
GHSA-4c7j-v446-xgx3

In multiple functions of protocolembmsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-4c7j-5rpp-4x8h

JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 22, allows remote attackers to cause a denial of service (heap-based out-of-bounds write and application crash) or possibly have unspecified other impact via crafted JavaScript code that triggers access to red-zone memory locations, related to jit/ThunkGenerators.cpp, llint/LowLevelInterpreter32_64.asm, and llint/LowLevelInterpreter64.asm.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4c7h-f2j9-9c46

Missing permission Jenkins Pipeline Phoenix AutoTest Plugin

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4c7h-552f-7g3h

Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.

CVSS3: 9.8
100%
Критический
около 3 лет назад
github логотип
GHSA-4c7g-cv49-499p

Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-4c7g-99hq-whpv

Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Campaign LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Marketing accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4c7f-qhrm-6jc8

Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing. This issue affects AI (Artificial Intelligence) versions: from 0.0.0 to 1.2.17, from 1.3.0 to 1.3.8, from 1.4.0 to 1.4.3.

CVSS3: 9.8
0%
Низкий
2 месяца назад
github логотип
GHSA-4c7f-4gjq-hwgh

Use-after-free vulnerability in the mozilla::dom::HTMLFormElement::IsDefaultSubmitElement function in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving a destroyed SELECT element.

6%
Низкий
больше 4 лет назад

Уязвимостей на страницу