Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 367 635

Количество 367 635

github логотип

GHSA-45w3-2hvv-pfxq

больше 4 лет назад

XML Injection in Apache Solr

EPSS: Средний
github логотип

GHSA-45vw-wh46-2vx8

4 месяца назад

Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation

EPSS: Низкий
github логотип

GHSA-45vw-7wgw-wvc6

11 месяцев назад

Creative Cloud Desktop versions 6.7.0.278 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to arbitrary file system write. A low-privileged attacker could exploit the timing between the check and use of a resource, potentially allowing unauthorized modifications to files. Exploitation of this issue does not require user interaction.

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-45vv-7v97-qmf3

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in templates/1/login.php in phpCommunity 2 2.1.8 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

EPSS: Низкий
github логотип

GHSA-45vv-5qvx-vg7v

больше 4 лет назад

Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2531.

EPSS: Средний
github логотип

GHSA-45vv-2cpw-48c4

больше 2 лет назад

The LightStart – Maintenance Mode, Coming Soon and Landing Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the insert_template function in all versions up to, and including, 2.6.8. This makes it possible for authenticated attackers, with subscriber-level access and above, to change page designs.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-45vr-rcqj-853w

больше 4 лет назад

Cross Site Scripting (XSS) exists on the D-Link DIR-600M C1 3.01 via the SSID or the name of a user account.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-45vr-8xvm-rhpc

больше 4 лет назад

In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, the SIGCOMP protocol dissector could crash. This was addressed in epan/dissectors/packet-sigcomp.c by validating operand offsets.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-45vr-76fp-gmwx

около 2 лет назад

Prototype pollution in allpro form-manager 0.7.4 allows attackers to run arbitrary code and cause other impacts via the functions setDefaults, mergeBranch, and Object.setObjectValue.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-45vq-73jx-ggvm

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: IB/core: Implement a limit on UMAD receive List The existing behavior of ib_umad, which maintains received MAD packets in an unbounded list, poses a risk of uncontrolled growth. As user-space applications extract packets from this list, the rate of extraction may not match the rate of incoming packets, leading to potential list overflow. To address this, we introduce a limit to the size of the list. After considering typical scenarios, such as OpenSM processing, which can handle approximately 100k packets per second, and the 1-second retry timeout for most packets, we set the list size limit to 200k. Packets received beyond this limit are dropped, assuming they are likely timed out by the time they are handled by user-space. Notably, packets queued on the receive list due to reasons like timed-out sends are preserved even when the list is full.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-45vq-42x3-g38f

больше 4 лет назад

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a length variable which is used to copy data has a size of only 8 bits and can be exceeded resulting in a denial of service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-45vp-vx4c-9jr2

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: net: mscc: ocelot: fix use-after-free in ocelot_vlan_del() ocelot_vlan_member_del() will free the struct ocelot_bridge_vlan, so if this is the same as the port's pvid_vlan which we access afterwards, what we're accessing is freed memory. Fix the bug by determining whether to clear ocelot_port->pvid_vlan prior to calling ocelot_vlan_member_del().

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-45vp-4854-43r7

4 дня назад

A vulnerability was found in SourceCodester Online Voting System 1.0. The impacted element is an unknown function of the file /ajax.php?action=delete_category. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-45vm-xm4v-hvqm

больше 4 лет назад

Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability when parsing an MP4 header. Successful exploitation could lead to arbitrary code execution.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-45vm-92vp-645q

больше 4 лет назад

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2517, CVE-2015-2518, and CVE-2015-2546.

EPSS: Низкий
github логотип

GHSA-45vm-3j38-7p78

больше 2 лет назад

PrestaShop cross-site scripting via customer contact form in FO, through file upload

CVSS3: 9.6
EPSS: Средний
github логотип

GHSA-45vj-xfvh-24j4

больше 4 лет назад

Fixed sizes of HTTPS responses in Tinder iOS app and Tinder Android app allow an attacker to extract private sensitive information by sniffing network traffic.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-45vj-ppvp-9gq3

почти 3 года назад

A SQL injection vulnerability in Cloudroits Website Job Search v.15.0 allows a remote authenticated attacker to execute arbitrary code via the name parameter in controllers/main.py component.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-45vh-w274-3hx8

больше 4 лет назад

Internet Explorer 4.0 allows remote attackers to cause a denial of service (crash) via HTML code that contains a long CLASSID parameter in an OBJECT tag.

EPSS: Средний
github логотип

GHSA-45vh-rpc8-hxpp

6 месяцев назад

Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-45w3-2hvv-pfxq

XML Injection in Apache Solr

11%
Средний
больше 4 лет назад
github логотип
GHSA-45vw-wh46-2vx8

Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation

1%
Низкий
4 месяца назад
github логотип
GHSA-45vw-7wgw-wvc6

Creative Cloud Desktop versions 6.7.0.278 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to arbitrary file system write. A low-privileged attacker could exploit the timing between the check and use of a resource, potentially allowing unauthorized modifications to files. Exploitation of this issue does not require user interaction.

CVSS3: 5.6
0%
Низкий
11 месяцев назад
github логотип
GHSA-45vv-7v97-qmf3

Cross-site scripting (XSS) vulnerability in templates/1/login.php in phpCommunity 2 2.1.8 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-45vv-5qvx-vg7v

Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2531.

23%
Средний
больше 4 лет назад
github логотип
GHSA-45vv-2cpw-48c4

The LightStart – Maintenance Mode, Coming Soon and Landing Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the insert_template function in all versions up to, and including, 2.6.8. This makes it possible for authenticated attackers, with subscriber-level access and above, to change page designs.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-45vr-rcqj-853w

Cross Site Scripting (XSS) exists on the D-Link DIR-600M C1 3.01 via the SSID or the name of a user account.

CVSS3: 5.4
2%
Низкий
больше 4 лет назад
github логотип
GHSA-45vr-8xvm-rhpc

In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, the SIGCOMP protocol dissector could crash. This was addressed in epan/dissectors/packet-sigcomp.c by validating operand offsets.

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-45vr-76fp-gmwx

Prototype pollution in allpro form-manager 0.7.4 allows attackers to run arbitrary code and cause other impacts via the functions setDefaults, mergeBranch, and Object.setObjectValue.

CVSS3: 9.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-45vq-73jx-ggvm

In the Linux kernel, the following vulnerability has been resolved: IB/core: Implement a limit on UMAD receive List The existing behavior of ib_umad, which maintains received MAD packets in an unbounded list, poses a risk of uncontrolled growth. As user-space applications extract packets from this list, the rate of extraction may not match the rate of incoming packets, leading to potential list overflow. To address this, we introduce a limit to the size of the list. After considering typical scenarios, such as OpenSM processing, which can handle approximately 100k packets per second, and the 1-second retry timeout for most packets, we set the list size limit to 200k. Packets received beyond this limit are dropped, assuming they are likely timed out by the time they are handled by user-space. Notably, packets queued on the receive list due to reasons like timed-out sends are preserved even when the list is full.

CVSS3: 5.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-45vq-42x3-g38f

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a length variable which is used to copy data has a size of only 8 bits and can be exceeded resulting in a denial of service.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-45vp-vx4c-9jr2

In the Linux kernel, the following vulnerability has been resolved: net: mscc: ocelot: fix use-after-free in ocelot_vlan_del() ocelot_vlan_member_del() will free the struct ocelot_bridge_vlan, so if this is the same as the port's pvid_vlan which we access afterwards, what we're accessing is freed memory. Fix the bug by determining whether to clear ocelot_port->pvid_vlan prior to calling ocelot_vlan_member_del().

CVSS3: 7.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-45vp-4854-43r7

A vulnerability was found in SourceCodester Online Voting System 1.0. The impacted element is an unknown function of the file /ajax.php?action=delete_category. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.

CVSS3: 7.3
0%
Низкий
4 дня назад
github логотип
GHSA-45vm-xm4v-hvqm

Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability when parsing an MP4 header. Successful exploitation could lead to arbitrary code execution.

CVSS3: 9.8
33%
Средний
больше 4 лет назад
github логотип
GHSA-45vm-92vp-645q

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2517, CVE-2015-2518, and CVE-2015-2546.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-45vm-3j38-7p78

PrestaShop cross-site scripting via customer contact form in FO, through file upload

CVSS3: 9.6
56%
Средний
больше 2 лет назад
github логотип
GHSA-45vj-xfvh-24j4

Fixed sizes of HTTPS responses in Tinder iOS app and Tinder Android app allow an attacker to extract private sensitive information by sniffing network traffic.

CVSS3: 9.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-45vj-ppvp-9gq3

A SQL injection vulnerability in Cloudroits Website Job Search v.15.0 allows a remote authenticated attacker to execute arbitrary code via the name parameter in controllers/main.py component.

CVSS3: 8.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-45vh-w274-3hx8

Internet Explorer 4.0 allows remote attackers to cause a denial of service (crash) via HTML code that contains a long CLASSID parameter in an OBJECT tag.

13%
Средний
больше 4 лет назад
github логотип
GHSA-45vh-rpc8-hxpp

Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload

CVSS3: 4.3
0%
Низкий
6 месяцев назад

Уязвимостей на страницу