Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 367 277

Количество 367 277

github логотип

GHSA-4598-m5q3-95hq

больше 4 лет назад

Buffer overflow in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted transform attribute in a text3GTrack element in a QuickTime TeXML file.

EPSS: Низкий
github логотип

GHSA-4598-cfq4-7mqj

больше 4 лет назад

Symbol Access Portable Data Terminal (PDT) 8100 does not hide the default WEP keys if they are not changed, which could allow attackers to retrieve the keys and gain access to the wireless network.

EPSS: Низкий
github логотип

GHSA-4597-h46x-2mwj

больше 4 лет назад

Siemens SIMATIC S7-1500 CPU devices before 1.8.3 allow remote attackers to bypass a replay protection mechanism via packets on TCP port 102.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4597-8mcf-pw36

больше 4 лет назад

Multiple heap-based buffer overflows in the rc4 (1) encryption (aka exsltCryptoRc4EncryptFunction) and (2) decryption (aka exsltCryptoRc4DecryptFunction) functions in crypto.c in libexslt in libxslt 1.1.8 through 1.1.24 allow context-dependent attackers to execute arbitrary code via an XML file containing a long string as "an argument in the XSL input."

EPSS: Средний
github логотип

GHSA-4596-vv4r-8q24

больше 4 лет назад

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects R6700v2 before 1.1.0.42, R6800 before 1.1.0.42, and R6900v2 before 1.1.0.42.

EPSS: Низкий
github логотип

GHSA-4596-9g7p-jgfv

больше 4 лет назад

A cross-site scripting (XSS) vulnerability in Online Catering Reservation System using PHP on Sourcecodester allows an attacker to arbitrarily inject code in the search bar.

EPSS: Низкий
github логотип

GHSA-4595-c58r-mv75

6 месяцев назад

wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows administrators to inject persistent JavaScript via forum description fields echoed without output escaping across multiple theme template files. On multisite installations or with a compromised admin account, attackers set a forum description containing HTML event handlers that execute when any user views the forum listing.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-4595-c522-xw7r

около 1 года назад

4C Strategies Exonaut before v21.6.2.1-1 was discovered to contain a Server-Side Request Forgery (SSRF).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4595-95wg-87wc

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in ZipList ZipList Recipe allows Cross Site Request Forgery. This issue affects ZipList Recipe: from n/a through 3.1.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4595-7fjw-r3jh

3 месяца назад

Tiptap for PHP before version 2.1.1 contains an input validation vulnerability that allows authenticated attackers to cause a denial of service by submitting Tiptap JSON with the attrs.href field set to an array instead of a string, causing an unhandled TypeError in the Link::isAllowedUri() function when passed to preg_match(). Attackers can persist malformed JSON records that permanently crash the server-side HTML rendering pipeline for all subsequent viewers of that record until the database entry is manually repaired.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4594-3h26-2mp7

больше 4 лет назад

Multiple stack-based buffer overflows in Microsoft Visual Basic 6 allow user-assisted remote attackers to cause a denial of service (CPU consumption) or execute arbitrary code via a Visual Basic Project (vbp) file with a long (1) Description or (2) Company Name (VersionCompanyName) field.

EPSS: Средний
github логотип

GHSA-4592-7p97-jfvp

больше 4 лет назад

duck before 0.10 did not properly handle loading of untrusted code from the current directory.

EPSS: Низкий
github логотип

GHSA-458x-w2cv-xvrx

больше 4 лет назад

A Server-Side Request Forgery (SSRF) in Rebuild v2.8.3 allows attackers to obtain the real IP address and scan Intranet information via the fileurl parameter.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-458x-pm5m-qh42

почти 2 года назад

eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via edit_file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-458x-p845-2qr2

больше 4 лет назад

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Sound). Supported versions that are affected are Java SE: 6u201, 7u191 and 8u182; Java SE Embedded: 8u181; JRockit: R28.3.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded, JRockit. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g. through a web service which supplies data to the APIs. CVSS 3.0 Base Score 5.3 ...

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-458x-mgv4-wcmj

больше 4 лет назад

RSA BSAFE SSL-J versions prior to 6.2.4 contain a Heap Inspection vulnerability that could allow an attacker with physical access to the system to recover sensitive key material.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-458x-3ww9-6x4c

больше 4 лет назад

Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; Adobe AIR before 3.4.0.2710; and Adobe AIR SDK before 3.4.0.2710 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than other Flash Player memory corruption CVEs listed in APSB12-22.

EPSS: Низкий
github логотип

GHSA-458w-jj2m-xf97

больше 4 лет назад

SystemUI in Android 5.x before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to read screenshots and consequently gain privileges via a crafted application, aka internal bug 19121797.

EPSS: Низкий
github логотип

GHSA-458v-4hrf-g3m4

около 5 лет назад

socket2 invalidly assumes the memory layout of std::net::SocketAddr

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-458r-vh8h-c3cp

больше 4 лет назад

Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote attackers to gain shell access and execute arbitrary code with root privileges via unspecified vectors.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4598-m5q3-95hq

Buffer overflow in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted transform attribute in a text3GTrack element in a QuickTime TeXML file.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-4598-cfq4-7mqj

Symbol Access Portable Data Terminal (PDT) 8100 does not hide the default WEP keys if they are not changed, which could allow attackers to retrieve the keys and gain access to the wireless network.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4597-h46x-2mwj

Siemens SIMATIC S7-1500 CPU devices before 1.8.3 allow remote attackers to bypass a replay protection mechanism via packets on TCP port 102.

CVSS3: 5.3
3%
Низкий
больше 4 лет назад
github логотип
GHSA-4597-8mcf-pw36

Multiple heap-based buffer overflows in the rc4 (1) encryption (aka exsltCryptoRc4EncryptFunction) and (2) decryption (aka exsltCryptoRc4DecryptFunction) functions in crypto.c in libexslt in libxslt 1.1.8 through 1.1.24 allow context-dependent attackers to execute arbitrary code via an XML file containing a long string as "an argument in the XSL input."

13%
Средний
больше 4 лет назад
github логотип
GHSA-4596-vv4r-8q24

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects R6700v2 before 1.1.0.42, R6800 before 1.1.0.42, and R6900v2 before 1.1.0.42.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4596-9g7p-jgfv

A cross-site scripting (XSS) vulnerability in Online Catering Reservation System using PHP on Sourcecodester allows an attacker to arbitrarily inject code in the search bar.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4595-c58r-mv75

wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows administrators to inject persistent JavaScript via forum description fields echoed without output escaping across multiple theme template files. On multisite installations or with a compromised admin account, attackers set a forum description containing HTML event handlers that execute when any user views the forum listing.

CVSS3: 5.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-4595-c522-xw7r

4C Strategies Exonaut before v21.6.2.1-1 was discovered to contain a Server-Side Request Forgery (SSRF).

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-4595-95wg-87wc

Cross-Site Request Forgery (CSRF) vulnerability in ZipList ZipList Recipe allows Cross Site Request Forgery. This issue affects ZipList Recipe: from n/a through 3.1.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-4595-7fjw-r3jh

Tiptap for PHP before version 2.1.1 contains an input validation vulnerability that allows authenticated attackers to cause a denial of service by submitting Tiptap JSON with the attrs.href field set to an array instead of a string, causing an unhandled TypeError in the Link::isAllowedUri() function when passed to preg_match(). Attackers can persist malformed JSON records that permanently crash the server-side HTML rendering pipeline for all subsequent viewers of that record until the database entry is manually repaired.

CVSS3: 6.5
1%
Низкий
3 месяца назад
github логотип
GHSA-4594-3h26-2mp7

Multiple stack-based buffer overflows in Microsoft Visual Basic 6 allow user-assisted remote attackers to cause a denial of service (CPU consumption) or execute arbitrary code via a Visual Basic Project (vbp) file with a long (1) Description or (2) Company Name (VersionCompanyName) field.

36%
Средний
больше 4 лет назад
github логотип
GHSA-4592-7p97-jfvp

duck before 0.10 did not properly handle loading of untrusted code from the current directory.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-458x-w2cv-xvrx

A Server-Side Request Forgery (SSRF) in Rebuild v2.8.3 allows attackers to obtain the real IP address and scan Intranet information via the fileurl parameter.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-458x-pm5m-qh42

eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via edit_file.

CVSS3: 6.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-458x-p845-2qr2

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Sound). Supported versions that are affected are Java SE: 6u201, 7u191 and 8u182; Java SE Embedded: 8u181; JRockit: R28.3.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded, JRockit. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g. through a web service which supplies data to the APIs. CVSS 3.0 Base Score 5.3 ...

CVSS3: 5.3
7%
Низкий
больше 4 лет назад
github логотип
GHSA-458x-mgv4-wcmj

RSA BSAFE SSL-J versions prior to 6.2.4 contain a Heap Inspection vulnerability that could allow an attacker with physical access to the system to recover sensitive key material.

CVSS3: 4.6
0%
Низкий
больше 4 лет назад
github логотип
GHSA-458x-3ww9-6x4c

Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; Adobe AIR before 3.4.0.2710; and Adobe AIR SDK before 3.4.0.2710 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than other Flash Player memory corruption CVEs listed in APSB12-22.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-458w-jj2m-xf97

SystemUI in Android 5.x before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to read screenshots and consequently gain privileges via a crafted application, aka internal bug 19121797.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-458v-4hrf-g3m4

socket2 invalidly assumes the memory layout of std::net::SocketAddr

CVSS3: 5.5
0%
Низкий
около 5 лет назад
github логотип
GHSA-458r-vh8h-c3cp

Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote attackers to gain shell access and execute arbitrary code with root privileges via unspecified vectors.

CVSS3: 9.8
6%
Низкий
больше 4 лет назад

Уязвимостей на страницу