Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 367 277

Количество 367 277

github логотип

GHSA-453r-h2v5-6vmq

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: s390/fpu: Re-add exception handling in load_fpu_state() With the recent rewrite of the fpu code exception handling for the lfpc instruction within load_fpu_state() was erroneously removed. Add it again to prevent that loading invalid floating point register values cause an unhandled specification exception.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-453r-g2pg-cxxq

5 месяцев назад

Local Incus UI web server vulnerable to nuthentication bypass

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-453r-cx7v-94wr

больше 4 лет назад

A denial-of-service (DoS) vulnerability was discovered in the web user interface of F-Secure Internet Gatekeeper. The vulnerability occurs because of an attacker can trigger assertion via malformed HTTP packet to web interface. An unauthenticated attacker could exploit this vulnerability by sending a large username parameter. A successful exploitation could lead to a denial-of-service of the product.

EPSS: Низкий
github логотип

GHSA-453q-q3mp-9cq4

больше 4 лет назад

Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to load and execute it.

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-453p-67r6-5c96

больше 4 лет назад

Directory traversal vulnerability in Trend Micro Interscan Web Viruswall in InterScan VirusWall 3.5x allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

EPSS: Низкий
github логотип

GHSA-453m-fcx3-j43g

больше 1 года назад

An os command injection vulnerability exists in the firewall.cgi iptablesWebsFilterRun() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-453j-q27h-5p8x

около 1 года назад

NULL Pointer Dereference in PHP SOAP Extension via Large XML Namespace Prefix

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-453j-gwgw-838r

почти 3 года назад

Sensitive information disclosure due to spell-jacking. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-453j-2h25-w552

больше 4 лет назад

There is an Improper verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause out-of-bounds read.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-453h-cfq2-hp69

около 4 лет назад

The Microsoft Advertising Universal Event Tracking (UET) WordPress plugin before 1.0.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. Due to the nature of this plugin, well crafted XSS can also leak into the frontpage.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-453g-g6g4-pqp9

больше 4 лет назад

An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. The vulnerability is caused by the computation that writes data past the end of the intended buffer; the computation is part of the image conversion engine when processing Enhanced Metafile Format Plus (EMF+) data. An attacker can potentially leverage the vulnerability to corrupt sensitive data or execute arbitrary code.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-453g-5mrh-qccr

больше 1 года назад

Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-453c-xr7g-2ph7

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in pam_login.cgi in Webmin before 1.350 and Usermin before 1.280 allow remote attackers to inject arbitrary web script or HTML via the (1) cid, (2) message, or (3) question parameter. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-453c-q86v-w8mr

больше 4 лет назад

The directory page parameter of the Orca HCM digital learning platform does not filter special characters. Remote attackers can access the system directory thru Path Traversal without logging in.

EPSS: Низкий
github логотип

GHSA-453c-jgvw-m9c9

больше 4 лет назад

The Commons Wikis module before 7.x-3.1 for Drupal, as used in the Commons module before 7.x-3.1, does not properly restrict access to groups, which allows remote attackers to post arbitrary content to groups via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-453c-hx6c-v5gq

больше 4 лет назад

IBM Cloud App Management 2019.3.0 and 2019.4.0 reveals a stack trace on certain API requests which can allow an attacker further information about the implementation of the offering. IBM X-Force ID: 173311.

EPSS: Низкий
github логотип

GHSA-453c-44v9-38fg

больше 4 лет назад

bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly systems, uses the permissions of symbolic links instead of the actual files when creating an archive, which could cause the files to be extracted with less restrictive permissions than intended.

EPSS: Низкий
github логотип

GHSA-4539-59fr-99v5

больше 4 лет назад

Undocumented Factory Backdoor in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows the vendor to extract confidential information via remote root SSH access.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4538-wpvw-289w

больше 4 лет назад

A security feature bypass vulnerability exists when Windows Host Guardian Service improperly handles hashes recorded and logged, aka 'Windows Host Guardian Service Security Feature Bypass Vulnerability'.

EPSS: Низкий
github логотип

GHSA-4538-g7mm-6mqj

больше 4 лет назад

The installation of Sun Source (sunsrc) tapes allows local users to gain root privileges via setuid root programs (1) makeinstall or (2) winstall.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-453r-h2v5-6vmq

In the Linux kernel, the following vulnerability has been resolved: s390/fpu: Re-add exception handling in load_fpu_state() With the recent rewrite of the fpu code exception handling for the lfpc instruction within load_fpu_state() was erroneously removed. Add it again to prevent that loading invalid floating point register values cause an unhandled specification exception.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-453r-g2pg-cxxq

Local Incus UI web server vulnerable to nuthentication bypass

CVSS3: 8.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-453r-cx7v-94wr

A denial-of-service (DoS) vulnerability was discovered in the web user interface of F-Secure Internet Gatekeeper. The vulnerability occurs because of an attacker can trigger assertion via malformed HTTP packet to web interface. An unauthenticated attacker could exploit this vulnerability by sending a large username parameter. A successful exploitation could lead to a denial-of-service of the product.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-453q-q3mp-9cq4

Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to load and execute it.

CVSS3: 9.8
99%
Критический
больше 4 лет назад
github логотип
GHSA-453p-67r6-5c96

Directory traversal vulnerability in Trend Micro Interscan Web Viruswall in InterScan VirusWall 3.5x allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

8%
Низкий
больше 4 лет назад
github логотип
GHSA-453m-fcx3-j43g

An os command injection vulnerability exists in the firewall.cgi iptablesWebsFilterRun() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVSS3: 9.1
8%
Низкий
больше 1 года назад
github логотип
GHSA-453j-q27h-5p8x

NULL Pointer Dereference in PHP SOAP Extension via Large XML Namespace Prefix

CVSS3: 5.9
1%
Низкий
около 1 года назад
github логотип
GHSA-453j-gwgw-838r

Sensitive information disclosure due to spell-jacking. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.

CVSS3: 5.7
1%
Низкий
почти 3 года назад
github логотип
GHSA-453j-2h25-w552

There is an Improper verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause out-of-bounds read.

CVSS3: 9.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-453h-cfq2-hp69

The Microsoft Advertising Universal Event Tracking (UET) WordPress plugin before 1.0.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. Due to the nature of this plugin, well crafted XSS can also leak into the frontpage.

CVSS3: 4.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-453g-g6g4-pqp9

An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. The vulnerability is caused by the computation that writes data past the end of the intended buffer; the computation is part of the image conversion engine when processing Enhanced Metafile Format Plus (EMF+) data. An attacker can potentially leverage the vulnerability to corrupt sensitive data or execute arbitrary code.

CVSS3: 9.8
14%
Средний
больше 4 лет назад
github логотип
GHSA-453g-5mrh-qccr

Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability

CVSS3: 8.1
1%
Низкий
больше 1 года назад
github логотип
GHSA-453c-xr7g-2ph7

Multiple cross-site scripting (XSS) vulnerabilities in pam_login.cgi in Webmin before 1.350 and Usermin before 1.280 allow remote attackers to inject arbitrary web script or HTML via the (1) cid, (2) message, or (3) question parameter. NOTE: some of these details are obtained from third party information.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-453c-q86v-w8mr

The directory page parameter of the Orca HCM digital learning platform does not filter special characters. Remote attackers can access the system directory thru Path Traversal without logging in.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-453c-jgvw-m9c9

The Commons Wikis module before 7.x-3.1 for Drupal, as used in the Commons module before 7.x-3.1, does not properly restrict access to groups, which allows remote attackers to post arbitrary content to groups via unspecified vectors.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-453c-hx6c-v5gq

IBM Cloud App Management 2019.3.0 and 2019.4.0 reveals a stack trace on certain API requests which can allow an attacker further information about the implementation of the offering. IBM X-Force ID: 173311.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-453c-44v9-38fg

bzip2 before 1.0.2 in FreeBSD 4.5 and earlier, OpenLinux 3.1 and 3.1.1, and possibly systems, uses the permissions of symbolic links instead of the actual files when creating an archive, which could cause the files to be extracted with less restrictive permissions than intended.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-4539-59fr-99v5

Undocumented Factory Backdoor in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows the vendor to extract confidential information via remote root SSH access.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4538-wpvw-289w

A security feature bypass vulnerability exists when Windows Host Guardian Service improperly handles hashes recorded and logged, aka 'Windows Host Guardian Service Security Feature Bypass Vulnerability'.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4538-g7mm-6mqj

The installation of Sun Source (sunsrc) tapes allows local users to gain root privileges via setuid root programs (1) makeinstall or (2) winstall.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу