Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 370 841

Количество 370 841

github логотип

GHSA-49v6-8hgf-2jxx

больше 4 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

EPSS: Низкий
github логотип

GHSA-49v5-wqh2-vj5q

больше 4 лет назад

The hb_buffer_ensure function in hb-buffer.c in HarfBuzz, as used in Pango 1.28.3, Firefox, and other products, does not verify that memory reallocations succeed, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via crafted OpenType font data that triggers use of an incorrect index.

EPSS: Низкий
github логотип

GHSA-49v5-vhqj-7pjx

больше 4 лет назад

Buffer overflow in the DoCommand function in jhead before 2.84 might allow context-dependent attackers to cause a denial of service (crash) via (1) a long -cmd argument and (2) unspecified vectors related to "a bunch of potential string overflows."

EPSS: Низкий
github логотип

GHSA-49v5-h84x-33xp

больше 4 лет назад

Unquoted Windows search path vulnerability in Schneider Electric Floating License Manager 1.0.0 through 1.4.0 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-49v5-72w5-rv6v

больше 4 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: LDAP Auth). Supported versions that are affected are 5.7.31 and prior and 8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Server accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-49v5-397q-f66m

9 месяцев назад

A vulnerability has been found in itsourcecode Student Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /new_school_year.php. The manipulation of the argument sy leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-49v4-h2mj-qhxf

больше 1 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in sudipto Link to URL / Post allows Blind SQL Injection. This issue affects Link to URL / Post: from n/a through 1.3.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-49v3-47vp-q76c

больше 4 лет назад

Integer Overflow vulnerability in function filter16_prewitt in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.

EPSS: Низкий
github логотип

GHSA-49v2-hj2q-248f

17 дней назад

Path traversal vulnerability in UnPoller 2.33.0 password field allows arbitrary file read and network exfiltration.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-49v2-h77h-w34h

больше 4 лет назад

Apache HTTP Server, when running on Linux with a document root on a Windows share mounted using smbfs, allows remote attackers to obtain unprocessed content such as source files for .php programs via a trailing "\" (backslash), which is not handled by the intended AddType directive.

EPSS: Средний
github логотип

GHSA-49v2-77fm-rc22

больше 4 лет назад

The analytics page on Cisco Video Surveillance 4000 IP cameras has hardcoded credentials, which allows remote attackers to watch the video feed by leveraging knowledge of the password, aka Bug IDs CSCuj70402 and CSCuj70419.

EPSS: Низкий
github логотип

GHSA-49rx-x2rw-pc6f

почти 5 лет назад

Heap OOB read in all `tf.raw_ops.QuantizeAndDequantizeV*` ops

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-49rx-vpxq-535f

больше 1 года назад

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.  This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have valid administrative credentials.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-49rx-f747-mq9v

больше 4 лет назад

Unspecified vulnerability in the Oracle Advanced Collections component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, and 12.1.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Administration, a different vulnerability than CVE-2016-0557.

EPSS: Низкий
github логотип

GHSA-49rx-72gp-wfgj

больше 1 года назад

A vulnerability in modelscope/agentscope, specifically in the AgentScope Studio backend server, allows for Cross-Site Request Forgery (CSRF) due to overly permissive CORS headers. This issue affects the latest commit on the main branch (21161fe). The vulnerability permits an attacker to access all backend endpoints, including the `api/file` endpoint, enabling the reading of arbitrary files on the target's local file system through CSRF.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-49rw-j488-xw8m

почти 2 года назад

Protection mechanism failure for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-49rw-2cx9-hjm3

5 месяцев назад

A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument maxRtrAdvInterval causes os command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-49rv-vwhv-6vcw

больше 4 лет назад

This vulnerability allows attackers with physical access to escalate privileges on affected installations of Arlo Q Plus 1.9.0.3_278. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SSH service. The device can be booted into a special operation mode where hard-coded credentials are accepted for SSH authentication. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root. Was ZDI-CAN-12890.

EPSS: Низкий
github логотип

GHSA-49rv-j9qq-fvfq

8 месяцев назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-49rv-g7w5-m8xx

около 6 лет назад

Cross-Site Scripting in @novnc/novnc

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-49v6-8hgf-2jxx

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-49v5-wqh2-vj5q

The hb_buffer_ensure function in hb-buffer.c in HarfBuzz, as used in Pango 1.28.3, Firefox, and other products, does not verify that memory reallocations succeed, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via crafted OpenType font data that triggers use of an incorrect index.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-49v5-vhqj-7pjx

Buffer overflow in the DoCommand function in jhead before 2.84 might allow context-dependent attackers to cause a denial of service (crash) via (1) a long -cmd argument and (2) unspecified vectors related to "a bunch of potential string overflows."

2%
Низкий
больше 4 лет назад
github логотип
GHSA-49v5-h84x-33xp

Unquoted Windows search path vulnerability in Schneider Electric Floating License Manager 1.0.0 through 1.4.0 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character.

CVSS3: 5.9
0%
Низкий
больше 4 лет назад
github логотип
GHSA-49v5-72w5-rv6v

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: LDAP Auth). Supported versions that are affected are 5.7.31 and prior and 8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Server accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-49v5-397q-f66m

A vulnerability has been found in itsourcecode Student Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /new_school_year.php. The manipulation of the argument sy leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-49v4-h2mj-qhxf

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in sudipto Link to URL / Post allows Blind SQL Injection. This issue affects Link to URL / Post: from n/a through 1.3.

CVSS3: 7.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-49v3-47vp-q76c

Integer Overflow vulnerability in function filter16_prewitt in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-49v2-hj2q-248f

Path traversal vulnerability in UnPoller 2.33.0 password field allows arbitrary file read and network exfiltration.

CVSS3: 7.5
0%
Низкий
17 дней назад
github логотип
GHSA-49v2-h77h-w34h

Apache HTTP Server, when running on Linux with a document root on a Windows share mounted using smbfs, allows remote attackers to obtain unprocessed content such as source files for .php programs via a trailing "\" (backslash), which is not handled by the intended AddType directive.

38%
Средний
больше 4 лет назад
github логотип
GHSA-49v2-77fm-rc22

The analytics page on Cisco Video Surveillance 4000 IP cameras has hardcoded credentials, which allows remote attackers to watch the video feed by leveraging knowledge of the password, aka Bug IDs CSCuj70402 and CSCuj70419.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-49rx-x2rw-pc6f

Heap OOB read in all `tf.raw_ops.QuantizeAndDequantizeV*` ops

CVSS3: 7.1
0%
Низкий
почти 5 лет назад
github логотип
GHSA-49rx-vpxq-535f

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.  This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have valid administrative credentials.

CVSS3: 4.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-49rx-f747-mq9v

Unspecified vulnerability in the Oracle Advanced Collections component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, and 12.1.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Administration, a different vulnerability than CVE-2016-0557.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-49rx-72gp-wfgj

A vulnerability in modelscope/agentscope, specifically in the AgentScope Studio backend server, allows for Cross-Site Request Forgery (CSRF) due to overly permissive CORS headers. This issue affects the latest commit on the main branch (21161fe). The vulnerability permits an attacker to access all backend endpoints, including the `api/file` endpoint, enabling the reading of arbitrary files on the target's local file system through CSRF.

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-49rw-j488-xw8m

Protection mechanism failure for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-49rw-2cx9-hjm3

A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument maxRtrAdvInterval causes os command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.

CVSS3: 9.8
2%
Низкий
5 месяцев назад
github логотип
GHSA-49rv-vwhv-6vcw

This vulnerability allows attackers with physical access to escalate privileges on affected installations of Arlo Q Plus 1.9.0.3_278. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SSH service. The device can be booted into a special operation mode where hard-coded credentials are accepted for SSH authentication. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root. Was ZDI-CAN-12890.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-49rv-j9qq-fvfq

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

8 месяцев назад
github логотип
GHSA-49rv-g7w5-m8xx

Cross-Site Scripting in @novnc/novnc

CVSS3: 6.1
5%
Низкий
около 6 лет назад

Уязвимостей на страницу