Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 370 841

Количество 370 841

github логотип

GHSA-49w2-rrxr-3cwq

больше 4 лет назад

Format string vulnerability in the mod_tcl module 1.0 for Apache 2.x allows context-dependent attackers to execute arbitrary code via format string specifiers that are not properly handled in a set_var function call in (1) tcl_cmds.c and (2) tcl_core.c.

EPSS: Средний
github логотип

GHSA-49w2-42m2-3c53

около 1 года назад

A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted file may lead to heap corruption.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-49vx-vwj9-q95m

около 3 лет назад

An issue in the com.nextev.datastatistic component of NIO EC6 Aspen before v3.3.0 allows attackers to escalate privileges via path traversal.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-49vx-mpg8-2pgf

около 3 лет назад

Microsoft ActiveX Remote Code Execution Vulnerability

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-49vx-hxwx-pw63

около 4 лет назад

Hiby R3 PRO firmware v1.5 to v1.7 was discovered to contain a file upload vulnerability via the file upload feature.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-49vx-8hjm-wgxw

больше 4 лет назад

Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1037, CVE-2016-1063, CVE-2016-1064, CVE-2016-1071, CVE-2016-1072, CVE-2016-1073, CVE-2016-1074, CVE-2016-1076, CVE-2016-1077, CVE-2016-1078, CVE-2016-1080, CVE-2016-1081, CVE-2016-1082, CVE-2016-1083, CVE-2016-1084, CVE-2016-1085, CVE-2016-1086, CVE-2016-1088, CVE-2016-1093, CVE-2016-1095, CVE-2016-1116, CVE-2016-1118, CVE-2016-1119, CVE-2016-1120, CVE-2016-1123, CVE-2016-1124, CVE-2016-1125, CVE-2016-1126, CVE-2016-1127, CVE-2016-1128, CVE-2016-1129, CVE-2016-1130, CVE-2016-4088, CVE-2016-4089, CVE-2016-4090, CVE-2016-4094, CVE-2016-4096, CVE-2016-4097, CVE-2016-4098, CVE-2016-4099, CVE-2016-4100, CVE-2016-4101, CVE-2016-4103, CVE-2016-4104, and C...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-49vw-r5mp-wh5h

больше 4 лет назад

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while accessing global variable "debug_client" in multi-thread manner, Use after free issue occurs

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-49vw-hrrf-qq82

около 1 года назад

PDF-XChange Editor U3D File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26642.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-49vw-7j46-x482

больше 4 лет назад

In SonicWall SonicOS, administrators without full permissions can download imported certificates. Occurs when administrators who are not in the SonicWall Administrators user group attempt to download imported certificates. This vulnerability affected SonicOS Gen 5 version 5.9.1.10 and earlier, Gen 6 version 6.2.7.3, 6.5.1.3, 6.5.2.2, 6.5.3.1, 6.2.7.8, 6.4.0.0, 6.5.1.8, 6.0.5.3-86o and SonicOSv 6.5.0.2-8v_RC363 (VMWARE), 6.5.0.2.8v_RC367 (AZURE), SonicOSv 6.5.0.2.8v_RC368 (AWS), SonicOSv 6.5.0.2.8v_RC366 (HYPER_V).

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-49vw-4m5g-r9gp

около 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in josepsitjar StoryMap allows SQL Injection. This issue affects StoryMap: from n/a through 2.1.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-49vv-6q7q-w5cf

почти 5 лет назад

Duplicate Advisory: OS Command Injection in Strapi

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-49vv-25qx-mg44

5 месяцев назад

OpenRemote has Improper Access Control via updateUserRealmRoles function

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-49vr-v9q4-q4ph

почти 2 года назад

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to sensitive information disclosure of a WordPress site's database due to missing capability checks on the wp_ajax_wpvivid_add_remote AJAX action that allows low-level authenticated attackers to send back-ups to a remote location of their choice for review. This affects versions up to, and including 0.9.35.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-49vq-r69w-8m53

больше 1 года назад

A stack-based buffer overflow vulnerability exists in the wireless.cgi set_wifi_basic_mesh() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-49vq-qc87-chpf

больше 4 лет назад

Multiple buffer overflows in the PDF Distiller in the BlackBerry Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server 4.1.3 through 5.0.2, and Enterprise Server Express 5.0.1 and 5.0.2, allow remote attackers to execute arbitrary code via a crafted PDF file.

EPSS: Низкий
github логотип

GHSA-49vq-hvrf-jhjw

около 3 лет назад

D-Link DSL-G256DG version vBZ_1.00.27 web management interface allows authentication bypass via an unspecified method.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-49vq-f4w4-mc8m

больше 4 лет назад

PHP remote file inclusion vulnerability in protection.php in ePersonnel RC_2004_02 allows remote attackers to execute arbitrary PHP code via a URL in the logout_page parameter.

EPSS: Низкий
github логотип

GHSA-49vq-cqmq-frgf

5 месяцев назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий
github логотип

GHSA-49vp-rvr9-vh53

больше 4 лет назад

Local privilege escalation due to DLL hijacking vulnerability in Acronis Media Builder service. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 39612, Acronis True Image 2021 (Windows) before build 39287

EPSS: Низкий
github логотип

GHSA-49vp-m8x4-rpc3

около 3 лет назад

Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the session category management section.

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-49w2-rrxr-3cwq

Format string vulnerability in the mod_tcl module 1.0 for Apache 2.x allows context-dependent attackers to execute arbitrary code via format string specifiers that are not properly handled in a set_var function call in (1) tcl_cmds.c and (2) tcl_core.c.

16%
Средний
больше 4 лет назад
github логотип
GHSA-49w2-42m2-3c53

A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted file may lead to heap corruption.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-49vx-vwj9-q95m

An issue in the com.nextev.datastatistic component of NIO EC6 Aspen before v3.3.0 allows attackers to escalate privileges via path traversal.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-49vx-mpg8-2pgf

Microsoft ActiveX Remote Code Execution Vulnerability

CVSS3: 7
1%
Низкий
около 3 лет назад
github логотип
GHSA-49vx-hxwx-pw63

Hiby R3 PRO firmware v1.5 to v1.7 was discovered to contain a file upload vulnerability via the file upload feature.

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-49vx-8hjm-wgxw

Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1037, CVE-2016-1063, CVE-2016-1064, CVE-2016-1071, CVE-2016-1072, CVE-2016-1073, CVE-2016-1074, CVE-2016-1076, CVE-2016-1077, CVE-2016-1078, CVE-2016-1080, CVE-2016-1081, CVE-2016-1082, CVE-2016-1083, CVE-2016-1084, CVE-2016-1085, CVE-2016-1086, CVE-2016-1088, CVE-2016-1093, CVE-2016-1095, CVE-2016-1116, CVE-2016-1118, CVE-2016-1119, CVE-2016-1120, CVE-2016-1123, CVE-2016-1124, CVE-2016-1125, CVE-2016-1126, CVE-2016-1127, CVE-2016-1128, CVE-2016-1129, CVE-2016-1130, CVE-2016-4088, CVE-2016-4089, CVE-2016-4090, CVE-2016-4094, CVE-2016-4096, CVE-2016-4097, CVE-2016-4098, CVE-2016-4099, CVE-2016-4100, CVE-2016-4101, CVE-2016-4103, CVE-2016-4104, and C...

CVSS3: 9.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-49vw-r5mp-wh5h

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while accessing global variable "debug_client" in multi-thread manner, Use after free issue occurs

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-49vw-hrrf-qq82

PDF-XChange Editor U3D File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26642.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-49vw-7j46-x482

In SonicWall SonicOS, administrators without full permissions can download imported certificates. Occurs when administrators who are not in the SonicWall Administrators user group attempt to download imported certificates. This vulnerability affected SonicOS Gen 5 version 5.9.1.10 and earlier, Gen 6 version 6.2.7.3, 6.5.1.3, 6.5.2.2, 6.5.3.1, 6.2.7.8, 6.4.0.0, 6.5.1.8, 6.0.5.3-86o and SonicOSv 6.5.0.2-8v_RC363 (VMWARE), 6.5.0.2.8v_RC367 (AZURE), SonicOSv 6.5.0.2.8v_RC368 (AWS), SonicOSv 6.5.0.2.8v_RC366 (HYPER_V).

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-49vw-4m5g-r9gp

Cross-Site Request Forgery (CSRF) vulnerability in josepsitjar StoryMap allows SQL Injection. This issue affects StoryMap: from n/a through 2.1.

CVSS3: 8.2
0%
Низкий
около 1 года назад
github логотип
GHSA-49vv-6q7q-w5cf

Duplicate Advisory: OS Command Injection in Strapi

CVSS3: 7.2
почти 5 лет назад
github логотип
GHSA-49vv-25qx-mg44

OpenRemote has Improper Access Control via updateUserRealmRoles function

CVSS3: 7
0%
Низкий
5 месяцев назад
github логотип
GHSA-49vr-v9q4-q4ph

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to sensitive information disclosure of a WordPress site's database due to missing capability checks on the wp_ajax_wpvivid_add_remote AJAX action that allows low-level authenticated attackers to send back-ups to a remote location of their choice for review. This affects versions up to, and including 0.9.35.

CVSS3: 4.9
1%
Низкий
почти 2 года назад
github логотип
GHSA-49vq-r69w-8m53

A stack-based buffer overflow vulnerability exists in the wireless.cgi set_wifi_basic_mesh() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVSS3: 9.1
2%
Низкий
больше 1 года назад
github логотип
GHSA-49vq-qc87-chpf

Multiple buffer overflows in the PDF Distiller in the BlackBerry Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server 4.1.3 through 5.0.2, and Enterprise Server Express 5.0.1 and 5.0.2, allow remote attackers to execute arbitrary code via a crafted PDF file.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-49vq-hvrf-jhjw

D-Link DSL-G256DG version vBZ_1.00.27 web management interface allows authentication bypass via an unspecified method.

CVSS3: 9.8
2%
Низкий
около 3 лет назад
github логотип
GHSA-49vq-f4w4-mc8m

PHP remote file inclusion vulnerability in protection.php in ePersonnel RC_2004_02 allows remote attackers to execute arbitrary PHP code via a URL in the logout_page parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-49vq-cqmq-frgf

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

5 месяцев назад
github логотип
GHSA-49vp-rvr9-vh53

Local privilege escalation due to DLL hijacking vulnerability in Acronis Media Builder service. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 39612, Acronis True Image 2021 (Windows) before build 39287

0%
Низкий
больше 4 лет назад
github логотип
GHSA-49vp-m8x4-rpc3

Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the session category management section.

CVSS3: 4.8
0%
Низкий
около 3 лет назад

Уязвимостей на страницу