Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 370 841

Количество 370 841

github логотип

GHSA-49x9-pc8p-4j9g

больше 4 лет назад

The Install Framework Legacy component in Apple OS X before 10.11 allows local users to obtain root privileges via vectors involving a privileged executable file.

EPSS: Низкий
github логотип

GHSA-49x9-m6h4-h7g6

4 дня назад

Heap-based buffer overflow in Windows VOLSNAP.SYS allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-49x8-xrpp-pg4g

почти 4 года назад

readelf in ToaruOS 2.0.1 has some arbitrary address read vulnerabilities when parsing a crafted ELF file.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-49x8-j53w-mv4c

больше 4 лет назад

Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters). The supported version that is affected are 8.5.3 and 8.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Outside In Technology accessible data as well as unauthorized update, insert or delete access to some of Oracle Outside In Technology accessible data. Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS score depend on the software that uses the Outside In Technology code. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology code, but if data is not received o...

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-49x8-h5pm-mv5h

больше 4 лет назад

SQL injection vulnerability in liga.php in H&H WebSoccer 2.80 allows remote attackers to execute arbitrary SQL commands via the id parameter.

EPSS: Низкий
github логотип

GHSA-49x7-6q87-679m

больше 4 лет назад

MySQLDumper 1.24.4 allows remote attackers to obtain sensitive information via a direct request to learn/cubemail/refresh_dblist.php, which reveals the installation path in an error message.

EPSS: Низкий
github логотип

GHSA-49x6-w2c9-99x9

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Sandi Verdev Watermark RELOADED allows Stored XSS.This issue affects Watermark RELOADED: from n/a through 1.3.5.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-49x6-mxm3-h3x2

больше 4 лет назад

Use-after-free vulnerability in WebKit, as used in Google Chrome before 6.0.472.59, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to nested SVG elements.

EPSS: Низкий
github логотип

GHSA-49x6-ghrc-w4q6

6 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in foreverpinetree Thebe thebe allows Reflected XSS.This issue affects Thebe: from n/a through <= 1.3.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-49x5-pp3j-h44f

9 месяцев назад

In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and versions below 3.9.10, 3.8.58 and 3.7.28 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a malicious payload through the `label` column field after adding a new device in the Splunk Secure Gateway app. This could potentially lead to a client-side denial of service (DoS).

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-49x4-gm58-wgqp

почти 3 года назад

Cross-Site Request Forgery (CSRF) vulnerability in AWP Classifieds Team Ad Directory & Listings by AWP Classifieds plugin <= 4.3 versions.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-49x3-8228-3w3m

почти 5 лет назад

Inefficient Regular Expression Complexity in code-server

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-49x2-m4xp-j5pw

3 месяца назад

Heap buffer overflow in WebRTC in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-49x2-3324-g739

16 дней назад

WatchGuard Dimension contains an authenticated SQL injection vulnerability in the audit report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests.

EPSS: Низкий
github логотип

GHSA-49wx-m47g-hrrr

около 1 года назад

A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The affected device may be susceptible to resource exhaustion when subjected to high volumes of query requests. This could allow an attacker to cause a temporary denial of service, with the system recovering once the activity stops.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-49wx-9m54-894m

больше 3 лет назад

An issue in the __nss_database_lookup component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-49wx-9h9f-8c9g

больше 2 лет назад

An out-of-bounds memory access flaw was found in the X.Org server. This issue can be triggered when a device frozen by a sync grab is reattached to a different master device. This issue may lead to an application crash, local privilege escalation (if the server runs with extended privileges), or remote code execution in SSH X11 forwarding environments.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-49wx-869f-rxhj

около 2 месяцев назад

The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains a local privilege escalation vulnerability in the core firmware. This is due to improper privilege delegation and insufficient input validation in a maintenance script.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-49wx-627v-6mcq

больше 4 лет назад

sshd in OpenSSH 3.6.1p2 and earlier, when PermitRootLogin is disabled and using PAM keyboard-interactive authentication, does not insert a delay after a root login attempt with the correct password, which makes it easier for remote attackers to use timing differences to determine if the password step of a multi-step authentication is successful, a different vulnerability than CVE-2003-0190.

EPSS: Низкий
github логотип

GHSA-49ww-c2gw-f75j

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in index.php in Docmint 1.0 and 2.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: some of these details are obtained from third party information.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-49x9-pc8p-4j9g

The Install Framework Legacy component in Apple OS X before 10.11 allows local users to obtain root privileges via vectors involving a privileged executable file.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-49x9-m6h4-h7g6

Heap-based buffer overflow in Windows VOLSNAP.SYS allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
4 дня назад
github логотип
GHSA-49x8-xrpp-pg4g

readelf in ToaruOS 2.0.1 has some arbitrary address read vulnerabilities when parsing a crafted ELF file.

CVSS3: 3.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-49x8-j53w-mv4c

Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters). The supported version that is affected are 8.5.3 and 8.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Outside In Technology accessible data as well as unauthorized update, insert or delete access to some of Oracle Outside In Technology accessible data. Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS score depend on the software that uses the Outside In Technology code. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology code, but if data is not received o...

CVSS3: 7.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-49x8-h5pm-mv5h

SQL injection vulnerability in liga.php in H&H WebSoccer 2.80 allows remote attackers to execute arbitrary SQL commands via the id parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-49x7-6q87-679m

MySQLDumper 1.24.4 allows remote attackers to obtain sensitive information via a direct request to learn/cubemail/refresh_dblist.php, which reveals the installation path in an error message.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-49x6-w2c9-99x9

Cross-Site Request Forgery (CSRF) vulnerability in Sandi Verdev Watermark RELOADED allows Stored XSS.This issue affects Watermark RELOADED: from n/a through 1.3.5.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-49x6-mxm3-h3x2

Use-after-free vulnerability in WebKit, as used in Google Chrome before 6.0.472.59, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to nested SVG elements.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-49x6-ghrc-w4q6

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in foreverpinetree Thebe thebe allows Reflected XSS.This issue affects Thebe: from n/a through <= 1.3.0.

CVSS3: 7.1
0%
Низкий
6 месяцев назад
github логотип
GHSA-49x5-pp3j-h44f

In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and versions below 3.9.10, 3.8.58 and 3.7.28 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a malicious payload through the `label` column field after adding a new device in the Splunk Secure Gateway app. This could potentially lead to a client-side denial of service (DoS).

CVSS3: 4.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-49x4-gm58-wgqp

Cross-Site Request Forgery (CSRF) vulnerability in AWP Classifieds Team Ad Directory & Listings by AWP Classifieds plugin <= 4.3 versions.

CVSS3: 5.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-49x3-8228-3w3m

Inefficient Regular Expression Complexity in code-server

CVSS3: 7.5
1%
Низкий
почти 5 лет назад
github логотип
GHSA-49x2-m4xp-j5pw

Heap buffer overflow in WebRTC in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
0%
Низкий
3 месяца назад
github логотип
GHSA-49x2-3324-g739

WatchGuard Dimension contains an authenticated SQL injection vulnerability in the audit report feature which allows an authenticated user with report administration permissions gain arbitrary command execution as the Dimension WebUI process user by sending specially crafted requests.

1%
Низкий
16 дней назад
github логотип
GHSA-49wx-m47g-hrrr

A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The affected device may be susceptible to resource exhaustion when subjected to high volumes of query requests. This could allow an attacker to cause a temporary denial of service, with the system recovering once the activity stops.

CVSS3: 3.1
0%
Низкий
около 1 года назад
github логотип
GHSA-49wx-9m54-894m

An issue in the __nss_database_lookup component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-49wx-9h9f-8c9g

An out-of-bounds memory access flaw was found in the X.Org server. This issue can be triggered when a device frozen by a sync grab is reattached to a different master device. This issue may lead to an application crash, local privilege escalation (if the server runs with extended privileges), or remote code execution in SSH X11 forwarding environments.

CVSS3: 7.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-49wx-869f-rxhj

The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains a local privilege escalation vulnerability in the core firmware. This is due to improper privilege delegation and insufficient input validation in a maintenance script.

CVSS3: 7.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-49wx-627v-6mcq

sshd in OpenSSH 3.6.1p2 and earlier, when PermitRootLogin is disabled and using PAM keyboard-interactive authentication, does not insert a delay after a root login attempt with the correct password, which makes it easier for remote attackers to use timing differences to determine if the password step of a multi-step authentication is successful, a different vulnerability than CVE-2003-0190.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-49ww-c2gw-f75j

Cross-site scripting (XSS) vulnerability in index.php in Docmint 1.0 and 2.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: some of these details are obtained from third party information.

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу