Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 370 841

Количество 370 841

github логотип

GHSA-49ww-54rq-93w9

больше 4 лет назад

This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.7, Security Update 2020-005 High Sierra, Security Update 2020-005 Mojave. A remote attacker may be able to unexpectedly alter application state.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-49wv-48xc-36fh

больше 4 лет назад

The Data Warehouse component in NetApp OnCommand Insight before 7.2.3 allows remote attackers to obtain administrative access by leveraging a default privileged account.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-49wr-6x3m-4p8x

больше 4 лет назад

Cross-site request forgery (CSRF) vulnerability in Forms/PortForwarding_Edit_1 on the ZyXEL O2 DSL Router Classic allows remote attackers to hijack the authentication of administrators for requests that insert cross-site scripting (XSS) sequences via the PortRule_Name parameter.

EPSS: Низкий
github логотип

GHSA-49wq-r246-v593

больше 4 лет назад

A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft Windows Denial of Service Vulnerability'.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-49wq-p4gj-4m2v

больше 4 лет назад

Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 2 of 2).

EPSS: Низкий
github логотип

GHSA-49wq-jfhc-9pmg

почти 3 года назад

Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the time parameter in the function saveParentControlInfo . This vulnerability allows attackers to cause a Denial of Service (DoS) attack

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-49wq-h6fq-vf8p

больше 4 лет назад

In SoX 14.4.2, there is a floating-point exception in lsx_aiffstartwrite in aiff.c in libsox.a.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-49wq-86c4-8qrv

больше 4 лет назад

SQL injection vulnerability in GForge Advanced Server 6.0.0 and other versions before 6.0.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-49wp-r47r-jrr5

больше 4 лет назад

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, Websafe software version 12.0.0 to 12.1.2, 11.6.0 to 11.6.1, 11.4.0 to 11.5.4, 11.2.1, in some cases TMM may crash when processing TCP traffic. This vulnerability affects TMM via a virtual server configured with TCP profile. Traffic processing is disrupted while Traffic Management Microkernel (TMM) restarts. If the affected BIG-IP system is configured to be part of a device group, it will trigger a failover to the peer device.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-49wp-qq6x-g2rf

больше 5 лет назад

Cross-site Request Forgery in fastify-csrf

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-49wp-pqpg-rf2j

больше 4 лет назад

Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Connector Framework). Supported versions that are affected are 12.1.0.5, 13.2.0.0 and 13.3.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Enterprise Manager Base Platform accessible data as well as unauthorized update, insert or delete access to some of Enterprise Manager Base Platform accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Enterprise Manager Base Platform. CVSS 3.0 Base Score 6.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L).

CVSS3: 6
EPSS: Низкий
github логотип

GHSA-49wp-jvpr-8f2w

больше 4 лет назад

The Renny McLean Ministries (aka com.subsplash.thechurchapp.s_GJQX72) application 2.8.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-49wp-8p26-hh26

больше 4 лет назад

The SaveBarCode function in the Taltech Tal Bar Code ActiveX control allows remote attackers to cause a denial of service (disk consumption) by uploading multiple bar codes, as demonstrated by a WSF package.

EPSS: Низкий
github логотип

GHSA-49wm-g2r8-jvx4

больше 4 лет назад

D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formAdvanceSetup. This vulnerability allows attackers to cause a Denial of Service (DoS) via the webpage parameter.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-49wm-7m27-7m24

больше 4 лет назад

GitLab Enterprise Edition (EE) 8.2 and later through 12.5 has Insecure Permissions.

EPSS: Низкий
github логотип

GHSA-49wm-6v24-hgfm

около 2 лет назад

Adobe Experience Manager versions 6.5.20 and earlier Answer: are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser session. Exploitation of this issue requires user interaction, such as convincing a victim to click on a specially crafted link or to submit a form that triggers the vulnerability.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-49wm-4fp6-h59c

почти 4 года назад

OctoPrint vulnerable to Unrestricted Upload of File with Dangerous Type

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-49wm-3mm7-4pj9

почти 3 года назад

A stack-based buffer overflow vulnerability exists in the httpd do_wds functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to stack-based buffer overflow. An attacker can send a network request to trigger this vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-49wj-vp5r-r79v

больше 4 лет назад

Kerberos in Microsoft Windows Server 2008 R2 and Windows 7 does not prevent a session from changing from strong encryption to DES encryption, which allows man-in-the-middle attackers to spoof network traffic and obtain sensitive information via a DES downgrade, aka "Kerberos Spoofing Vulnerability."

EPSS: Низкий
github логотип

GHSA-49wj-p4f6-8g7j

12 месяцев назад

Missing Authorization vulnerability in Syed Balkhi All In One SEO Pack allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects All In One SEO Pack: from n/a through 4.8.7.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-49ww-54rq-93w9

This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.7, Security Update 2020-005 High Sierra, Security Update 2020-005 Mojave. A remote attacker may be able to unexpectedly alter application state.

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-49wv-48xc-36fh

The Data Warehouse component in NetApp OnCommand Insight before 7.2.3 allows remote attackers to obtain administrative access by leveraging a default privileged account.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-49wr-6x3m-4p8x

Cross-site request forgery (CSRF) vulnerability in Forms/PortForwarding_Edit_1 on the ZyXEL O2 DSL Router Classic allows remote attackers to hijack the authentication of administrators for requests that insert cross-site scripting (XSS) sequences via the PortRule_Name parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-49wq-r246-v593

A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft Windows Denial of Service Vulnerability'.

CVSS3: 7.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-49wq-p4gj-4m2v

Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 2 of 2).

1%
Низкий
больше 4 лет назад
github логотип
GHSA-49wq-jfhc-9pmg

Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the time parameter in the function saveParentControlInfo . This vulnerability allows attackers to cause a Denial of Service (DoS) attack

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-49wq-h6fq-vf8p

In SoX 14.4.2, there is a floating-point exception in lsx_aiffstartwrite in aiff.c in libsox.a.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-49wq-86c4-8qrv

SQL injection vulnerability in GForge Advanced Server 6.0.0 and other versions before 6.0.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-49wp-r47r-jrr5

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, Websafe software version 12.0.0 to 12.1.2, 11.6.0 to 11.6.1, 11.4.0 to 11.5.4, 11.2.1, in some cases TMM may crash when processing TCP traffic. This vulnerability affects TMM via a virtual server configured with TCP profile. Traffic processing is disrupted while Traffic Management Microkernel (TMM) restarts. If the affected BIG-IP system is configured to be part of a device group, it will trigger a failover to the peer device.

CVSS3: 5.9
2%
Низкий
больше 4 лет назад
github логотип
GHSA-49wp-qq6x-g2rf

Cross-site Request Forgery in fastify-csrf

CVSS3: 8.8
1%
Низкий
больше 5 лет назад
github логотип
GHSA-49wp-pqpg-rf2j

Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Connector Framework). Supported versions that are affected are 12.1.0.5, 13.2.0.0 and 13.3.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Enterprise Manager Base Platform accessible data as well as unauthorized update, insert or delete access to some of Enterprise Manager Base Platform accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Enterprise Manager Base Platform. CVSS 3.0 Base Score 6.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L).

CVSS3: 6
1%
Низкий
больше 4 лет назад
github логотип
GHSA-49wp-jvpr-8f2w

The Renny McLean Ministries (aka com.subsplash.thechurchapp.s_GJQX72) application 2.8.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-49wp-8p26-hh26

The SaveBarCode function in the Taltech Tal Bar Code ActiveX control allows remote attackers to cause a denial of service (disk consumption) by uploading multiple bar codes, as demonstrated by a WSF package.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-49wm-g2r8-jvx4

D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formAdvanceSetup. This vulnerability allows attackers to cause a Denial of Service (DoS) via the webpage parameter.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-49wm-7m27-7m24

GitLab Enterprise Edition (EE) 8.2 and later through 12.5 has Insecure Permissions.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-49wm-6v24-hgfm

Adobe Experience Manager versions 6.5.20 and earlier Answer: are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser session. Exploitation of this issue requires user interaction, such as convincing a victim to click on a specially crafted link or to submit a form that triggers the vulnerability.

CVSS3: 5.4
1%
Низкий
около 2 лет назад
github логотип
GHSA-49wm-4fp6-h59c

OctoPrint vulnerable to Unrestricted Upload of File with Dangerous Type

CVSS3: 3.7
1%
Низкий
почти 4 года назад
github логотип
GHSA-49wm-3mm7-4pj9

A stack-based buffer overflow vulnerability exists in the httpd do_wds functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to stack-based buffer overflow. An attacker can send a network request to trigger this vulnerability.

CVSS3: 8.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-49wj-vp5r-r79v

Kerberos in Microsoft Windows Server 2008 R2 and Windows 7 does not prevent a session from changing from strong encryption to DES encryption, which allows man-in-the-middle attackers to spoof network traffic and obtain sensitive information via a DES downgrade, aka "Kerberos Spoofing Vulnerability."

5%
Низкий
больше 4 лет назад
github логотип
GHSA-49wj-p4f6-8g7j

Missing Authorization vulnerability in Syed Balkhi All In One SEO Pack allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects All In One SEO Pack: from n/a through 4.8.7.

CVSS3: 5.4
0%
Низкий
12 месяцев назад

Уязвимостей на страницу