Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 370 132

Количество 370 132

github логотип

GHSA-48qc-hgg4-x87r

больше 4 лет назад

Unspecified vulnerability in (1) Tor 0.1.0.x before 0.1.0.18 and 0.1.1.x before 0.1.1.23, and (2) ScatterChat before 1.0.2, allows remote attackers operating a Tor entry node to route arbitrary Tor traffic through clients or cause a denial of service (flood) via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-48q9-vxr9-j39f

11 месяцев назад

E3 Site Supervisor (firmware version < 2.31F01) has a default admin user "ONEDAY" with a daily generated password. An attacker can predictably generate the password for ONEDAY. The oneday user cannot be deleted or modified by any user.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-48q9-qvmx-w7gq

больше 4 лет назад

Stack-based buffer overflow in the getline function in Ppm/ppm.C in NASA Ames Research Center BigView 1.8 allows user-assisted remote attackers to execute arbitrary code via a crafted PNM file.

EPSS: Низкий
github логотип

GHSA-48q9-j4qm-rxcw

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in WPExpertsio New User Approve.This issue affects New User Approve: from n/a through 2.5.1.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-48q8-jcx3-378c

больше 1 года назад

Memory corruption while processing input message passed from FE driver.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-48q8-4r5f-p5pf

около 3 лет назад

An improper input validation vulnerability in OTRS Survey modules allows any attacker with a link to a valid and unanswered survey request to inject javascript code in free text answers. This allows a cross site scripting attack while reading the replies as authenticated agent. This issue affects OTRS Survey module from 7.0.X before 7.0.32, from 8.0.X before 8.0.13 and ((OTRS)) Community Edition Survey module from 6.0.X through 6.0.22.

CVSS3: 4.1
EPSS: Низкий
github логотип

GHSA-48q8-3ggg-p434

больше 4 лет назад

Buffer overflow in the HP HTTP Server 5.0 through 5.95 of the HP Web-enabled Management Software allows remote attackers to execute arbitrary code via unknown vectors.

EPSS: Средний
github логотип

GHSA-48q7-w7r3-3jjg

29 дней назад

Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-48q7-r6r9-rhx2

больше 4 лет назад

Multiple directory traversal vulnerabilities in index.php in Nullam Blog 0.1.2 allow remote attackers to include or execute arbitrary files via a .. (dot dot) in the (1) p and (2) s parameters.

EPSS: Низкий
github логотип

GHSA-48q7-j5wr-pmw9

больше 2 лет назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RexTheme Product Feed Manager.This issue affects Product Feed Manager: from n/a through 7.3.15.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-48q6-j89g-2jvq

больше 4 лет назад

The Lenovo Service Framework Android application executes some system commands without proper sanitization of external input. In certain cases, this could lead to command injection which, in turn, could lead to remote code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-48q6-hpwm-mqh2

4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst() bareudp_fill_metadata_dst() passes bareudp->sock to udp_tunnel6_dst_lookup() in the IPv6 path without a NULL check. The socket is only created in bareudp_open() and NULLed in bareudp_stop(), so calling this function while the device is down triggers a NULL dereference via sock->sk. BUG: kernel NULL pointer dereference, address: 0000000000000018 RIP: 0010:udp_tunnel6_dst_lookup (net/ipv6/ip6_udp_tunnel.c:160) Call Trace: <TASK> bareudp_fill_metadata_dst (drivers/net/bareudp.c:532) do_execute_actions (net/openvswitch/actions.c:901) ovs_execute_actions (net/openvswitch/actions.c:1589) ovs_packet_cmd_execute (net/openvswitch/datapath.c:700) genl_family_rcv_msg_doit (net/netlink/genetlink.c:1114) genl_rcv_msg (net/netlink/genetlink.c:1209) netlink_rcv_skb (net/netlink/af_netlink.c:2550) </TASK> Add a NULL check returning -ESHUTD...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-48q6-99pr-mcvm

7 месяцев назад

Memory safety bugs present in Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, and Firefox ESR < 140.8.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-48q6-73v9-grfj

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the WddxPacket::recursiveAddVar function in HHVM (aka the HipHop Virtual Machine) before 3.5.0 allows remote attackers to inject arbitrary web script or HTML via a crafted string to the wddx_serialize_value function.

EPSS: Низкий
github логотип

GHSA-48q5-x6fp-8893

больше 2 лет назад

This issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.4. An app may be able to access sensitive user data.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-48q5-w887-33wv

3 месяца назад

Incus has a restricted project bypass leading to arbitrary command execution

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-48q5-pr9g-5rx6

больше 4 лет назад

An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-8254.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-48q5-2vm3-g897

больше 4 лет назад

Buffer overflow in Microsoft Windows Media Player 7.1 and earlier allows remote attackers to execute arbitrary commands via a malformed Windows Media Station (.NSC) file.

EPSS: Средний
github логотип

GHSA-48q4-vrg4-8rx4

больше 4 лет назад

Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL but not in any official releases, allows remote attackers to execute arbitrary code.

EPSS: Низкий
github логотип

GHSA-48q4-vhg7-552r

22 дня назад

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the PowerVM hypervisor call interface. An attacker with root access to a guest partition can issue a specially crafted hypervisor call to inject an arbitrary amount of data into hypervisor or partition memory, resulting in either a crash causing a full platform re-IPL and terminating all hosted partitions, or corruption of hypervisor or partition memory. The PowerVM hypervisor will restart automatically; however, repeated exploitation could result in a sustained availability impact. Successful exploitation results in an integrity and availability impact to the managed system.

CVSS3: 8.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-48qc-hgg4-x87r

Unspecified vulnerability in (1) Tor 0.1.0.x before 0.1.0.18 and 0.1.1.x before 0.1.1.23, and (2) ScatterChat before 1.0.2, allows remote attackers operating a Tor entry node to route arbitrary Tor traffic through clients or cause a denial of service (flood) via unspecified vectors.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-48q9-vxr9-j39f

E3 Site Supervisor (firmware version < 2.31F01) has a default admin user "ONEDAY" with a daily generated password. An attacker can predictably generate the password for ONEDAY. The oneday user cannot be deleted or modified by any user.

CVSS3: 9.8
1%
Низкий
11 месяцев назад
github логотип
GHSA-48q9-qvmx-w7gq

Stack-based buffer overflow in the getline function in Ppm/ppm.C in NASA Ames Research Center BigView 1.8 allows user-assisted remote attackers to execute arbitrary code via a crafted PNM file.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-48q9-j4qm-rxcw

Cross-Site Request Forgery (CSRF) vulnerability in WPExpertsio New User Approve.This issue affects New User Approve: from n/a through 2.5.1.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-48q8-jcx3-378c

Memory corruption while processing input message passed from FE driver.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-48q8-4r5f-p5pf

An improper input validation vulnerability in OTRS Survey modules allows any attacker with a link to a valid and unanswered survey request to inject javascript code in free text answers. This allows a cross site scripting attack while reading the replies as authenticated agent. This issue affects OTRS Survey module from 7.0.X before 7.0.32, from 8.0.X before 8.0.13 and ((OTRS)) Community Edition Survey module from 6.0.X through 6.0.22.

CVSS3: 4.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-48q8-3ggg-p434

Buffer overflow in the HP HTTP Server 5.0 through 5.95 of the HP Web-enabled Management Software allows remote attackers to execute arbitrary code via unknown vectors.

13%
Средний
больше 4 лет назад
github логотип
GHSA-48q7-w7r3-3jjg

Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions.

CVSS3: 6.5
0%
Низкий
29 дней назад
github логотип
GHSA-48q7-r6r9-rhx2

Multiple directory traversal vulnerabilities in index.php in Nullam Blog 0.1.2 allow remote attackers to include or execute arbitrary files via a .. (dot dot) in the (1) p and (2) s parameters.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-48q7-j5wr-pmw9

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RexTheme Product Feed Manager.This issue affects Product Feed Manager: from n/a through 7.3.15.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-48q6-j89g-2jvq

The Lenovo Service Framework Android application executes some system commands without proper sanitization of external input. In certain cases, this could lead to command injection which, in turn, could lead to remote code execution.

CVSS3: 9.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-48q6-hpwm-mqh2

In the Linux kernel, the following vulnerability has been resolved: bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst() bareudp_fill_metadata_dst() passes bareudp->sock to udp_tunnel6_dst_lookup() in the IPv6 path without a NULL check. The socket is only created in bareudp_open() and NULLed in bareudp_stop(), so calling this function while the device is down triggers a NULL dereference via sock->sk. BUG: kernel NULL pointer dereference, address: 0000000000000018 RIP: 0010:udp_tunnel6_dst_lookup (net/ipv6/ip6_udp_tunnel.c:160) Call Trace: <TASK> bareudp_fill_metadata_dst (drivers/net/bareudp.c:532) do_execute_actions (net/openvswitch/actions.c:901) ovs_execute_actions (net/openvswitch/actions.c:1589) ovs_packet_cmd_execute (net/openvswitch/datapath.c:700) genl_family_rcv_msg_doit (net/netlink/genetlink.c:1114) genl_rcv_msg (net/netlink/genetlink.c:1209) netlink_rcv_skb (net/netlink/af_netlink.c:2550) </TASK> Add a NULL check returning -ESHUTD...

CVSS3: 5.5
0%
Низкий
4 месяца назад
github логотип
GHSA-48q6-99pr-mcvm

Memory safety bugs present in Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, and Firefox ESR < 140.8.

CVSS3: 9.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-48q6-73v9-grfj

Cross-site scripting (XSS) vulnerability in the WddxPacket::recursiveAddVar function in HHVM (aka the HipHop Virtual Machine) before 3.5.0 allows remote attackers to inject arbitrary web script or HTML via a crafted string to the wddx_serialize_value function.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-48q5-x6fp-8893

This issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.4. An app may be able to access sensitive user data.

CVSS3: 6.2
0%
Низкий
больше 2 лет назад
github логотип
GHSA-48q5-w887-33wv

Incus has a restricted project bypass leading to arbitrary command execution

CVSS3: 9.9
1%
Низкий
3 месяца назад
github логотип
GHSA-48q5-pr9g-5rx6

An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-8254.

CVSS3: 5.4
3%
Низкий
больше 4 лет назад
github логотип
GHSA-48q5-2vm3-g897

Buffer overflow in Microsoft Windows Media Player 7.1 and earlier allows remote attackers to execute arbitrary commands via a malformed Windows Media Station (.NSC) file.

16%
Средний
больше 4 лет назад
github логотип
GHSA-48q4-vrg4-8rx4

Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL but not in any official releases, allows remote attackers to execute arbitrary code.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-48q4-vhg7-552r

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the PowerVM hypervisor call interface. An attacker with root access to a guest partition can issue a specially crafted hypervisor call to inject an arbitrary amount of data into hypervisor or partition memory, resulting in either a crash causing a full platform re-IPL and terminating all hosted partitions, or corruption of hypervisor or partition memory. The PowerVM hypervisor will restart automatically; however, repeated exploitation could result in a sustained availability impact. Successful exploitation results in an integrity and availability impact to the managed system.

CVSS3: 8.4
0%
Низкий
22 дня назад

Уязвимостей на страницу