Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 370 227

Количество 370 227

github логотип

GHSA-48wj-mfx4-4qc2

больше 4 лет назад

Use after free in Media in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to execute arbitrary code via a crafted HTML page.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-48wj-39w8-38rp

больше 4 лет назад

Heap-based buffer overflow in RealNetworks RealPlayer before 16.0.1.18 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers to execute arbitrary code via a malformed MP4 file.

EPSS: Низкий
github логотип

GHSA-48wh-3c8h-65w6

больше 4 лет назад

ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read in MagickCore/fourier.c in ComplexImages.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-48wh-29xq-96fm

больше 4 лет назад

SkPictureShader.cpp in Skia, as used in Google Chrome before 44.0.2403.89, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging access to a renderer process and providing crafted serialized data.

EPSS: Низкий
github логотип

GHSA-48wg-v88q-c99m

почти 4 года назад

An attacker with physical access can exploit this vulnerability to execute arbitrary code during DXE phase. A malicious code installed as a result of vulnerability exploitation in DXE driver could survive across an operating system (OS) boot process and runtime This issue affects: Module name: AMITSE SHA256: 288769fcb374d9280735e259c579e2dc209491f4da43b085d6aabc2d6e6ee57d Module GUID: b1da0adf-4f77-4070-a88e-bffe1c60529a This issue affects: AMI Aptio 5.x.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-48wg-8g2h-89wf

больше 4 лет назад

TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the iface variable in the interface_wan.lua file.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-48wg-55fj-pvx6

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: ALSA: asihpi: Fix potential OOB array access ASIHPI driver stores some values in the static array upon a response from the driver, and its index depends on the firmware. We shouldn't trust it blindly. This patch adds a sanity check of the array index to fit in the array size.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-48wf-gfw2-hm84

больше 4 лет назад

SQL injection vulnerability in urunbak.asp in W1L3D4 WEBmarket 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

EPSS: Низкий
github логотип

GHSA-48wf-g7cp-gr3m

6 месяцев назад

OpenClaw has allowlist exec-guard bypass via env -S

EPSS: Низкий
github логотип

GHSA-48wf-8584-rpqx

больше 4 лет назад

Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Code execution in context of TEE core (kernel). The component is: optee_os. The fixed version is: 3.4.0 and later.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-48wc-mjph-v799

больше 4 лет назад

applications/luci-app-ddns/luasrc/model/cbi/ddns/detail.lua in the DDNS package for OpenWrt 19.07 allows remote authenticated users to inject arbitrary commands via POST requests.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-48wc-j2j8-q9cr

больше 4 лет назад

Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters). The supported version that is affected is 8.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology. Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS score depend on the software that uses the Outside In Technology code. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology code, but if data is not received over a network t...

CVSS3: 7.1
EPSS: Средний
github логотип

GHSA-48wc-9j2c-rwp5

около 2 лет назад

Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x, contain(s) an Use of Hard-coded Password vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Client-side request forgery and Information disclosure.

CVSS3: 7.9
EPSS: Низкий
github логотип

GHSA-48w9-cx3r-qxr5

больше 4 лет назад

Afian FileRun (before 2018.02.13) suffers from a remote SQL injection vulnerability, when logged in as superuser, via the search parameter in a /?module=users&section=cpanel&page=list request.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-48w8-mmwr-cpgc

больше 4 лет назад

IBM Tivoli Storage Manager Server 7.1 could allow an authenticated user with TSM administrator privileges to cause a buffer overflow using a specially crafted SQL query and execute arbitrary code on the server. IBM Reference #: 1998747.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-48w7-xgfc-4wm7

около 1 месяца назад

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of a client-supplied profile name.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-48w7-jgwg-c3p5

больше 4 лет назад

The nd-donations plugin before 1.4 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-48w7-7v5c-hxxv

больше 3 лет назад

The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_required_theme' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to activate the 'royal-elementor-kit' theme. If no such theme is installed doing so can also impact site availability as the site attempts to load a nonexistent theme.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-48w7-3xpj-xq9c

больше 2 лет назад

HDF5 through 1.14.3 contains a buffer overflow in H5O__linfo_decode, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-48w5-fx89-4hg4

больше 4 лет назад

Revelation 0.4.13-2 and earlier uses only the first 32 characters of a password followed by a sequence of zeros, which reduces the entropy and makes it easier for context-dependent attackers to crack passwords and obtain access to keys via a brute-force attack.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-48wj-mfx4-4qc2

Use after free in Media in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to execute arbitrary code via a crafted HTML page.

CVSS3: 8.8
11%
Средний
больше 4 лет назад
github логотип
GHSA-48wj-39w8-38rp

Heap-based buffer overflow in RealNetworks RealPlayer before 16.0.1.18 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers to execute arbitrary code via a malformed MP4 file.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-48wh-3c8h-65w6

ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read in MagickCore/fourier.c in ComplexImages.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-48wh-29xq-96fm

SkPictureShader.cpp in Skia, as used in Google Chrome before 44.0.2403.89, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging access to a renderer process and providing crafted serialized data.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-48wg-v88q-c99m

An attacker with physical access can exploit this vulnerability to execute arbitrary code during DXE phase. A malicious code installed as a result of vulnerability exploitation in DXE driver could survive across an operating system (OS) boot process and runtime This issue affects: Module name: AMITSE SHA256: 288769fcb374d9280735e259c579e2dc209491f4da43b085d6aabc2d6e6ee57d Module GUID: b1da0adf-4f77-4070-a88e-bffe1c60529a This issue affects: AMI Aptio 5.x.

CVSS3: 7.2
почти 4 года назад
github логотип
GHSA-48wg-8g2h-89wf

TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the iface variable in the interface_wan.lua file.

CVSS3: 7.2
4%
Низкий
больше 4 лет назад
github логотип
GHSA-48wg-55fj-pvx6

In the Linux kernel, the following vulnerability has been resolved: ALSA: asihpi: Fix potential OOB array access ASIHPI driver stores some values in the static array upon a response from the driver, and its index depends on the firmware. We shouldn't trust it blindly. This patch adds a sanity check of the array index to fit in the array size.

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-48wf-gfw2-hm84

SQL injection vulnerability in urunbak.asp in W1L3D4 WEBmarket 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-48wf-g7cp-gr3m

OpenClaw has allowlist exec-guard bypass via env -S

0%
Низкий
6 месяцев назад
github логотип
GHSA-48wf-8584-rpqx

Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Code execution in context of TEE core (kernel). The component is: optee_os. The fixed version is: 3.4.0 and later.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-48wc-mjph-v799

applications/luci-app-ddns/luasrc/model/cbi/ddns/detail.lua in the DDNS package for OpenWrt 19.07 allows remote authenticated users to inject arbitrary commands via POST requests.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-48wc-j2j8-q9cr

Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters). The supported version that is affected is 8.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology. Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS score depend on the software that uses the Outside In Technology code. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology code, but if data is not received over a network t...

CVSS3: 7.1
36%
Средний
больше 4 лет назад
github логотип
GHSA-48wc-9j2c-rwp5

Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x, contain(s) an Use of Hard-coded Password vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Client-side request forgery and Information disclosure.

CVSS3: 7.9
0%
Низкий
около 2 лет назад
github логотип
GHSA-48w9-cx3r-qxr5

Afian FileRun (before 2018.02.13) suffers from a remote SQL injection vulnerability, when logged in as superuser, via the search parameter in a /?module=users&section=cpanel&page=list request.

CVSS3: 7.2
1%
Низкий
больше 4 лет назад
github логотип
GHSA-48w8-mmwr-cpgc

IBM Tivoli Storage Manager Server 7.1 could allow an authenticated user with TSM administrator privileges to cause a buffer overflow using a specially crafted SQL query and execute arbitrary code on the server. IBM Reference #: 1998747.

CVSS3: 7.2
2%
Низкий
больше 4 лет назад
github логотип
GHSA-48w7-xgfc-4wm7

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of a client-supplied profile name.

CVSS3: 8.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-48w7-jgwg-c3p5

The nd-donations plugin before 1.4 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-48w7-7v5c-hxxv

The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_required_theme' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to activate the 'royal-elementor-kit' theme. If no such theme is installed doing so can also impact site availability as the site attempts to load a nonexistent theme.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-48w7-3xpj-xq9c

HDF5 through 1.14.3 contains a buffer overflow in H5O__linfo_decode, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

CVSS3: 5.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-48w5-fx89-4hg4

Revelation 0.4.13-2 and earlier uses only the first 32 characters of a password followed by a sequence of zeros, which reduces the entropy and makes it easier for context-dependent attackers to crack passwords and obtain access to keys via a brute-force attack.

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу