Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 369 608

Количество 369 608

github логотип

GHSA-47w8-68x4-mmm6

больше 1 года назад

Deserialization of Untrusted Data vulnerability in NotFound ARPrice allows Object Injection. This issue affects ARPrice: from n/a through 4.0.3.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-47w7-9fq8-cxp2

3 месяца назад

An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to leak sensitive user information.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-47w6-j2rq-rff7

больше 4 лет назад

A vulnerability exists in Arctic Torrent 1.4 via unspecified vectors in .torrent file handling, which could let a malicious user cause a Denial of Service.

EPSS: Низкий
github логотип

GHSA-47w6-hx3r-xcc6

больше 4 лет назад

Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-47w6-gwp4-w6vc

около 2 месяцев назад

vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review

EPSS: Низкий
github логотип

GHSA-47w5-94q8-w9x4

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in unspecified administration pages in the OSF module 7.x-3.x before 7.x-3.1 for Drupal, when the OSF Ontology module is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-47w3-v9wp-56q9

больше 4 лет назад

Multiple buffer overflows in unspecified COM objects in Rational Common Licensing 7.0 through 7.1.1.4 in IBM Rational ClearCase 7.0.0.4 through 7.1.1.4, ClearQuest 7.0.0.4 through 7.1.1.4, and other products allow local users to gain privileges via a Trojan horse HTML document in the My Computer zone.

EPSS: Низкий
github логотип

GHSA-47w3-h8x8-xwp9

больше 4 лет назад

An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Speech" component. It allows attackers to bypass a sandbox protection mechanism to obtain microphone access.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-47w3-66wq-cpxg

больше 4 лет назад

Improper Input Validation in Apache Kafka

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-47vx-qx7p-xf23

больше 4 лет назад

Multiple SQL injection vulnerabilities in DUware DUclassified 4.0 through 4.2 allows remote attackers to bypass authentication and execute other commands on the server's underlying database via the (1) cat_id or (2) sub_id parameters in adDetail.asp, or (2) the password parameter in the login form.

EPSS: Низкий
github логотип

GHSA-47vx-fqr5-j2gw

больше 3 лет назад

HuTool vulnerable to Uncontrolled Resource Consumption

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-47vx-6pch-wf2r

2 дня назад

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-47vw-q2cv-jhr7

8 месяцев назад

Abacre Retail Point of Sale 14.0.0.396 is affected by a stored cross-site scripting (XSS) vulnerability in the Clients module. The application fails to properly sanitize user-supplied input stored in the Name and Surname fields. An attacker can insert malicious HTML or script content into these fields, which, persisted in the database.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-47vw-3hx2-6877

почти 3 года назад

Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted avif file. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-47vv-g4p6-hqp5

11 месяцев назад

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a POST request. The relationship between parameter and assigned identifier is a 'm' parameter in '/clt/LOGINFRM.ASP'.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-47vr-rjfv-j542

больше 4 лет назад

Multiple PHP remote file inclusion vulnerabilities in WebCreator 0.2.6-rc3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the moddir parameter to (1) content/load.inc.php, (2) config/load.inc.php, (3) http/load.inc.php, and unspecified other files.

EPSS: Низкий
github логотип

GHSA-47vr-m75r-g978

больше 4 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Swing. NOTE: the previous information was obtained from the February 2011 CPU. Oracle has not commented on claims from a downstream vendor that this issue is related to the lack of framework support by AWT event dispatch, and/or "clipboard access in Applets."

EPSS: Низкий
github логотип

GHSA-47vr-crpx-w72f

больше 4 лет назад

The Onion module in toxcore before 0.2.2 doesn't restrict which packets can be onion-routed, which allows a remote attacker to discover a target user's IP address (when knowing only their Tox Id) by positioning themselves close to target's Tox Id in the DHT for the target to establish an onion connection with the attacker, guessing the target's DHT public key and creating a DHT node with public key close to it, and finally onion-routing a NAT Ping Request to the target, requesting it to ping the just created DHT node.

EPSS: Низкий
github логотип

GHSA-47vr-832f-crm9

больше 4 лет назад

An uncontrolled resource consumption (memory leak) flaw was found in the ZeroMQ client in versions before 4.3.3 in src/pipe.cpp. This issue causes a client that connects to multiple malicious or compromised servers to crash. The highest threat from this vulnerability is to system availability.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-47vq-f5r8-c96h

больше 4 лет назад

Inappropriate implementation in iframe sandbox in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-47w8-68x4-mmm6

Deserialization of Untrusted Data vulnerability in NotFound ARPrice allows Object Injection. This issue affects ARPrice: from n/a through 4.0.3.

CVSS3: 9.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-47w7-9fq8-cxp2

An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to leak sensitive user information.

CVSS3: 5.3
0%
Низкий
3 месяца назад
github логотип
GHSA-47w6-j2rq-rff7

A vulnerability exists in Arctic Torrent 1.4 via unspecified vectors in .torrent file handling, which could let a malicious user cause a Denial of Service.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-47w6-hx3r-xcc6

Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 7.5
11%
Средний
больше 4 лет назад
github логотип
GHSA-47w6-gwp4-w6vc

vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-47w5-94q8-w9x4

Cross-site scripting (XSS) vulnerability in unspecified administration pages in the OSF module 7.x-3.x before 7.x-3.1 for Drupal, when the OSF Ontology module is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-47w3-v9wp-56q9

Multiple buffer overflows in unspecified COM objects in Rational Common Licensing 7.0 through 7.1.1.4 in IBM Rational ClearCase 7.0.0.4 through 7.1.1.4, ClearQuest 7.0.0.4 through 7.1.1.4, and other products allow local users to gain privileges via a Trojan horse HTML document in the My Computer zone.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-47w3-h8x8-xwp9

An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Speech" component. It allows attackers to bypass a sandbox protection mechanism to obtain microphone access.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-47w3-66wq-cpxg

Improper Input Validation in Apache Kafka

CVSS3: 8.8
5%
Низкий
больше 4 лет назад
github логотип
GHSA-47vx-qx7p-xf23

Multiple SQL injection vulnerabilities in DUware DUclassified 4.0 through 4.2 allows remote attackers to bypass authentication and execute other commands on the server's underlying database via the (1) cat_id or (2) sub_id parameters in adDetail.asp, or (2) the password parameter in the login form.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-47vx-fqr5-j2gw

HuTool vulnerable to Uncontrolled Resource Consumption

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-47vx-6pch-wf2r

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
2 дня назад
github логотип
GHSA-47vw-q2cv-jhr7

Abacre Retail Point of Sale 14.0.0.396 is affected by a stored cross-site scripting (XSS) vulnerability in the Clients module. The application fails to properly sanitize user-supplied input stored in the Name and Surname fields. An attacker can insert malicious HTML or script content into these fields, which, persisted in the database.

CVSS3: 6.1
0%
Низкий
8 месяцев назад
github логотип
GHSA-47vw-3hx2-6877

Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted avif file. (Chromium security severity: High)

CVSS3: 8.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-47vv-g4p6-hqp5

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a POST request. The relationship between parameter and assigned identifier is a 'm' parameter in '/clt/LOGINFRM.ASP'.

CVSS3: 9.8
1%
Низкий
11 месяцев назад
github логотип
GHSA-47vr-rjfv-j542

Multiple PHP remote file inclusion vulnerabilities in WebCreator 0.2.6-rc3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the moddir parameter to (1) content/load.inc.php, (2) config/load.inc.php, (3) http/load.inc.php, and unspecified other files.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-47vr-m75r-g978

Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Swing. NOTE: the previous information was obtained from the February 2011 CPU. Oracle has not commented on claims from a downstream vendor that this issue is related to the lack of framework support by AWT event dispatch, and/or "clipboard access in Applets."

4%
Низкий
больше 4 лет назад
github логотип
GHSA-47vr-crpx-w72f

The Onion module in toxcore before 0.2.2 doesn't restrict which packets can be onion-routed, which allows a remote attacker to discover a target user's IP address (when knowing only their Tox Id) by positioning themselves close to target's Tox Id in the DHT for the target to establish an onion connection with the attacker, guessing the target's DHT public key and creating a DHT node with public key close to it, and finally onion-routing a NAT Ping Request to the target, requesting it to ping the just created DHT node.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-47vr-832f-crm9

An uncontrolled resource consumption (memory leak) flaw was found in the ZeroMQ client in versions before 4.3.3 in src/pipe.cpp. This issue causes a client that connects to multiple malicious or compromised servers to crash. The highest threat from this vulnerability is to system availability.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-47vq-f5r8-c96h

Inappropriate implementation in iframe sandbox in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу