Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 367 277

Количество 367 277

github логотип

GHSA-4555-c4vh-gv67

больше 4 лет назад

Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_B20200911 were discovered to contain a stack overflow in the function setNoticeCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via the IpTo parameter.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4555-4gmg-wpcm

больше 4 лет назад

An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component of the affected CODESYS products which leads to a crash.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4554-x3mc-5827

20 дней назад

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-4554-7vw9-cmc7

больше 4 лет назад

SQL injection vulnerability in featured_article.php in AJ Article 1.0 allows remote attackers to execute arbitrary SQL commands via the artid parameter in a search detail action.

EPSS: Низкий
github логотип

GHSA-4553-jf72-r93q

больше 4 лет назад

A SQL injection on the /admin/display_errors.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to execute arbitrary SQL requests (including data reading and modification) on the database.

EPSS: Низкий
github логотип

GHSA-4553-hq82-8654

больше 2 лет назад

Duplicate Advisory: encoded_id-rails potential DOS vulnerability due to URIs with extremely long encoded IDs

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-454x-wfc9-v689

больше 4 лет назад

Microsoft Excel in Office 2000 SP3, Office XP SP3, Office 2003 SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via a Workspace with a certain index value that triggers memory corruption.

EPSS: Средний
github логотип

GHSA-454x-hmf4-97vq

больше 4 лет назад

In Wireshark 3.2.x before 3.2.1, the WASSP dissector could crash. This was addressed in epan/dissectors/packet-wassp.c by using >= and <= to resolve off-by-one errors.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-454x-h9g9-7vmj

больше 4 лет назад

A null pointer dereference vulnerability exists in gpac 1.1.0 in the BD_CheckSFTimeOffset function, which causes a segmentation fault and application crash.

EPSS: Низкий
github логотип

GHSA-454x-8f5c-p2fv

больше 4 лет назад

An improper input validation vulnerability in the service of ezPDFReader allows attacker to execute arbitrary command. This issue occurred when the ezPDF launcher received and executed crafted input values through JSON-RPC communication.

EPSS: Низкий
github логотип

GHSA-454w-g337-r9mr

больше 2 лет назад

Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'txtTitle' parameter of the Employer/InsertWalkin.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-454w-5cf7-2xqx

больше 3 лет назад

When a TLS Certificate error occurs on a domain protected by the HSTS header, the browser should not allow the user to bypass the certificate error. On Firefox for Android, the user was presented with the option to bypass the error; this could only have been done by the user explicitly. <br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 102.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-454v-7vh4-hcxm

больше 4 лет назад

Pydio Cells 2.0.4 allows an authenticated user to write or overwrite existing files in another user’s personal and cells folders (repositories) by uploading a custom generated ZIP file and leveraging the file extraction feature present in the web application. The extracted files will be placed in the targeted user folders.

EPSS: Низкий
github логотип

GHSA-454r-jccq-96q8

больше 4 лет назад

Moodle Exposure of Sensitive Information to an Unauthorized Actor

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-454r-4qj4-9rgw

больше 4 лет назад

admin/options.php in Extreme CMS 0.9, and possibly earlier, does not require authentication, which might allow remote attackers to conduct unauthorized activities. NOTE: this issue can be combined with another vulnerability to expand the scope of a cross-site scripting (XSS) attack without authentication. NOTE: the provenance of this information is unknown; details are obtained from third party sources.

EPSS: Низкий
github логотип

GHSA-454r-4cjv-vc9h

больше 4 лет назад

Moodle allows attackers to obtain manager privileges

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-454q-hw5x-cp28

больше 4 лет назад

An issue was discovered in Concrete CMS through 8.5.5. Path Traversal can lead to Arbitrary File Reading and SSRF.

EPSS: Низкий
github логотип

GHSA-454q-7qq2-3pwv

больше 4 лет назад

IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV near NULL starting at BabaCAD4Image!ShowPlugInOptions+0x000000000001b3f3."

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-454p-q268-hrcx

больше 3 лет назад

In btm_ble_write_adv_enable_complete of btm_ble_gap.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-260568367

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-454p-pvqj-9jv5

больше 2 лет назад

Substance3D - Painter versions 9.1.1 and earlier are affected by a Write-what-where Condition vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4555-c4vh-gv67

Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_B20200911 were discovered to contain a stack overflow in the function setNoticeCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via the IpTo parameter.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4555-4gmg-wpcm

An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component of the affected CODESYS products which leads to a crash.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4554-x3mc-5827

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).

CVSS3: 8.7
0%
Низкий
20 дней назад
github логотип
GHSA-4554-7vw9-cmc7

SQL injection vulnerability in featured_article.php in AJ Article 1.0 allows remote attackers to execute arbitrary SQL commands via the artid parameter in a search detail action.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4553-jf72-r93q

A SQL injection on the /admin/display_errors.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to execute arbitrary SQL requests (including data reading and modification) on the database.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-4553-hq82-8654

Duplicate Advisory: encoded_id-rails potential DOS vulnerability due to URIs with extremely long encoded IDs

CVSS3: 7.5
больше 2 лет назад
github логотип
GHSA-454x-wfc9-v689

Microsoft Excel in Office 2000 SP3, Office XP SP3, Office 2003 SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via a Workspace with a certain index value that triggers memory corruption.

29%
Средний
больше 4 лет назад
github логотип
GHSA-454x-hmf4-97vq

In Wireshark 3.2.x before 3.2.1, the WASSP dissector could crash. This was addressed in epan/dissectors/packet-wassp.c by using >= and <= to resolve off-by-one errors.

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-454x-h9g9-7vmj

A null pointer dereference vulnerability exists in gpac 1.1.0 in the BD_CheckSFTimeOffset function, which causes a segmentation fault and application crash.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-454x-8f5c-p2fv

An improper input validation vulnerability in the service of ezPDFReader allows attacker to execute arbitrary command. This issue occurred when the ezPDF launcher received and executed crafted input values through JSON-RPC communication.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-454w-g337-r9mr

Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'txtTitle' parameter of the Employer/InsertWalkin.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
больше 2 лет назад
github логотип
GHSA-454w-5cf7-2xqx

When a TLS Certificate error occurs on a domain protected by the HSTS header, the browser should not allow the user to bypass the certificate error. On Firefox for Android, the user was presented with the option to bypass the error; this could only have been done by the user explicitly. <br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 102.

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-454v-7vh4-hcxm

Pydio Cells 2.0.4 allows an authenticated user to write or overwrite existing files in another user’s personal and cells folders (repositories) by uploading a custom generated ZIP file and leveraging the file extraction feature present in the web application. The extracted files will be placed in the targeted user folders.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-454r-jccq-96q8

Moodle Exposure of Sensitive Information to an Unauthorized Actor

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-454r-4qj4-9rgw

admin/options.php in Extreme CMS 0.9, and possibly earlier, does not require authentication, which might allow remote attackers to conduct unauthorized activities. NOTE: this issue can be combined with another vulnerability to expand the scope of a cross-site scripting (XSS) attack without authentication. NOTE: the provenance of this information is unknown; details are obtained from third party sources.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-454r-4cjv-vc9h

Moodle allows attackers to obtain manager privileges

CVSS3: 6.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-454q-hw5x-cp28

An issue was discovered in Concrete CMS through 8.5.5. Path Traversal can lead to Arbitrary File Reading and SSRF.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-454q-7qq2-3pwv

IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV near NULL starting at BabaCAD4Image!ShowPlugInOptions+0x000000000001b3f3."

CVSS3: 7.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-454p-q268-hrcx

In btm_ble_write_adv_enable_complete of btm_ble_gap.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-260568367

CVSS3: 4.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-454p-pvqj-9jv5

Substance3D - Painter versions 9.1.1 and earlier are affected by a Write-what-where Condition vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу