Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 367 277

Количество 367 277

github логотип

GHSA-452r-p733-r4gh

больше 2 лет назад

In gnss, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08580200; Issue ID: ALPS08580200.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-452p-q6qj-235g

больше 4 лет назад

Buffer overflow in Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on Windows and Mac OS X, before 10.3.183.43 and 11.x before 11.2.202.251 on Linux, before 11.1.111.24 on Android 2.x and 3.x, and before 11.1.115.27 on Android 4.x; Adobe AIR before 3.5.0.600; and Adobe AIR SDK before 3.5.0.600 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-5274, CVE-2012-5276, CVE-2012-5277, and CVE-2012-5280.

EPSS: Средний
github логотип

GHSA-452p-5pj4-w36g

больше 4 лет назад

Vulnerability in the Oracle Application Express Opportunity Tracker component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express Opportunity Tracker. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express Opportunity Tracker, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Application Express Opportunity Tracker accessible data as well as unauthorized read access to a subset of Oracle Application Express Opportunity Tracker accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).

EPSS: Низкий
github логотип

GHSA-452m-gc7f-x9g5

5 месяцев назад

A vulnerability was identified in Totolink A3300R 17.0.0cu.557_b20221024. This affects the function setLanCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. The manipulation of the argument lanIp leads to command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-452j-v697-rp7m

больше 4 лет назад

The Web To Print Shop : uDraw WordPress plugin before 3.3.3 does not validate the url parameter in its udraw_convert_url_to_base64 AJAX action (available to both unauthenticated and authenticated users) before using it in the file_get_contents function and returning its content base64 encoded in the response. As a result, unauthenticated users could read arbitrary files on the web server (such as /etc/passwd, wp-config.php etc)

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-452h-x3w8-jmmh

больше 2 лет назад

A improper neutralization of formula elements in a csv file in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.10, 6.4.0 through 6.4.9, 6.2.0 through 6.2.9, 6.0.0 through 6.0.8 allows attacker to execute unauthorized code or commands via specially crafted packets.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-452h-rx28-49w9

больше 4 лет назад

MoinMoin Cross-site scripting (XSS) vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-452h-fwmr-j9hp

11 месяцев назад

A security vulnerability has been detected in D-Link DI-7001 MINI 24.04.18B1. The affected element is an unknown function of the file /dbsrv.asp. Such manipulation of the argument str leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-452g-gx43-7wv5

почти 2 года назад

This issue was addressed with improved checks. This issue is fixed in iOS 18.0.1 and iPadOS 18.0.1. Audio messages in Messages may be able to capture a few seconds of audio before the microphone indicator is activated.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-452g-f7fp-9jf7

больше 5 лет назад

Type confusion during tensor casts lead to dereferencing null pointers

CVSS3: 2.5
EPSS: Низкий
github логотип

GHSA-452f-rx2g-gx8c

больше 4 лет назад

Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft and JDEdwards Suite 8.50.11 through 8.50.15 and 8.51GA through 8.51.05 allows remote attackers to affect confidentiality, integrity, and availability, related to PIA Core Technology.

EPSS: Низкий
github логотип

GHSA-452f-fqfm-q3xf

почти 3 года назад

In display, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07388762; Issue ID: ALPS07388762.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-452f-c962-qphr

больше 4 лет назад

The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 IR 04 has hardcoded credentials, which makes it easier for remote attackers to obtain access via an FTP session.

EPSS: Низкий
github логотип

GHSA-452f-9hr7-jmxv

больше 4 лет назад

An issue was discovered in ApiManager 1.1. there is sql injection vulnerability that can use in /index.php?act=api&tag=8.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-452f-6cjx-8x7j

больше 4 лет назад

The Downlevel DB2RA Support component in IBM DB2 9.1 before Fixpak 4a allows remote attackers to cause a denial of service (instance crash) via a crafted CONNECT data stream that simulates a V7 client connect request.

EPSS: Низкий
github логотип

GHSA-452c-qvj7-x6xq

больше 4 лет назад

A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook.

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-452c-mgc8-crh5

больше 4 лет назад

A XSS found in Advan VD-1 firmware versions up to 230. VD-1 responses a path error message when a requested resource was not found in page cgibin/ssi.cgi. It leads to a reflected XSS because the error message does not escape properly.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-4529-7wqq-6324

больше 4 лет назад

Unspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1832.

EPSS: Средний
github логотип

GHSA-4528-vmxj-v97w

почти 4 года назад

Insecure method vulnerability in which allowed HTTP methods are disclosed. E.g., OPTIONS, DELETE, TRACE, and PUT

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4528-h42g-x3c7

больше 1 года назад

Vulnerability in Hewlett Packard Enterprise HPE Performance Cluster Manager (HPCM).This issue affects HPE Performance Cluster Manager (HPCM): through 1.12.

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-452r-p733-r4gh

In gnss, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08580200; Issue ID: ALPS08580200.

CVSS3: 6.6
0%
Низкий
больше 2 лет назад
github логотип
GHSA-452p-q6qj-235g

Buffer overflow in Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on Windows and Mac OS X, before 10.3.183.43 and 11.x before 11.2.202.251 on Linux, before 11.1.111.24 on Android 2.x and 3.x, and before 11.1.115.27 on Android 4.x; Adobe AIR before 3.5.0.600; and Adobe AIR SDK before 3.5.0.600 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-5274, CVE-2012-5276, CVE-2012-5277, and CVE-2012-5280.

11%
Средний
больше 4 лет назад
github логотип
GHSA-452p-5pj4-w36g

Vulnerability in the Oracle Application Express Opportunity Tracker component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express Opportunity Tracker. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express Opportunity Tracker, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Application Express Opportunity Tracker accessible data as well as unauthorized read access to a subset of Oracle Application Express Opportunity Tracker accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).

1%
Низкий
больше 4 лет назад
github логотип
GHSA-452m-gc7f-x9g5

A vulnerability was identified in Totolink A3300R 17.0.0cu.557_b20221024. This affects the function setLanCfg of the file /cgi-bin/cstecgi.cgi of the component Parameter Handler. The manipulation of the argument lanIp leads to command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

CVSS3: 6.3
2%
Низкий
5 месяцев назад
github логотип
GHSA-452j-v697-rp7m

The Web To Print Shop : uDraw WordPress plugin before 3.3.3 does not validate the url parameter in its udraw_convert_url_to_base64 AJAX action (available to both unauthenticated and authenticated users) before using it in the file_get_contents function and returning its content base64 encoded in the response. As a result, unauthenticated users could read arbitrary files on the web server (such as /etc/passwd, wp-config.php etc)

CVSS3: 7.5
8%
Низкий
больше 4 лет назад
github логотип
GHSA-452h-x3w8-jmmh

A improper neutralization of formula elements in a csv file in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.10, 6.4.0 through 6.4.9, 6.2.0 through 6.2.9, 6.0.0 through 6.0.8 allows attacker to execute unauthorized code or commands via specially crafted packets.

CVSS3: 9.6
1%
Низкий
больше 2 лет назад
github логотип
GHSA-452h-rx28-49w9

MoinMoin Cross-site scripting (XSS) vulnerability

CVSS3: 6.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-452h-fwmr-j9hp

A security vulnerability has been detected in D-Link DI-7001 MINI 24.04.18B1. The affected element is an unknown function of the file /dbsrv.asp. Such manipulation of the argument str leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.

CVSS3: 8.8
1%
Низкий
11 месяцев назад
github логотип
GHSA-452g-gx43-7wv5

This issue was addressed with improved checks. This issue is fixed in iOS 18.0.1 and iPadOS 18.0.1. Audio messages in Messages may be able to capture a few seconds of audio before the microphone indicator is activated.

CVSS3: 4.3
9%
Низкий
почти 2 года назад
github логотип
GHSA-452g-f7fp-9jf7

Type confusion during tensor casts lead to dereferencing null pointers

CVSS3: 2.5
0%
Низкий
больше 5 лет назад
github логотип
GHSA-452f-rx2g-gx8c

Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft and JDEdwards Suite 8.50.11 through 8.50.15 and 8.51GA through 8.51.05 allows remote attackers to affect confidentiality, integrity, and availability, related to PIA Core Technology.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-452f-fqfm-q3xf

In display, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07388762; Issue ID: ALPS07388762.

CVSS3: 6.7
0%
Низкий
почти 3 года назад
github логотип
GHSA-452f-c962-qphr

The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 IR 04 has hardcoded credentials, which makes it easier for remote attackers to obtain access via an FTP session.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-452f-9hr7-jmxv

An issue was discovered in ApiManager 1.1. there is sql injection vulnerability that can use in /index.php?act=api&tag=8.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-452f-6cjx-8x7j

The Downlevel DB2RA Support component in IBM DB2 9.1 before Fixpak 4a allows remote attackers to cause a denial of service (instance crash) via a crafted CONNECT data stream that simulates a V7 client connect request.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-452c-qvj7-x6xq

A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook.

CVSS3: 7.8
29%
Средний
больше 4 лет назад
github логотип
GHSA-452c-mgc8-crh5

A XSS found in Advan VD-1 firmware versions up to 230. VD-1 responses a path error message when a requested resource was not found in page cgibin/ssi.cgi. It leads to a reflected XSS because the error message does not escape properly.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4529-7wqq-6324

Unspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1832.

63%
Средний
больше 4 лет назад
github логотип
GHSA-4528-vmxj-v97w

Insecure method vulnerability in which allowed HTTP methods are disclosed. E.g., OPTIONS, DELETE, TRACE, and PUT

CVSS3: 5.3
1%
Низкий
почти 4 года назад
github логотип
GHSA-4528-h42g-x3c7

Vulnerability in Hewlett Packard Enterprise HPE Performance Cluster Manager (HPCM).This issue affects HPE Performance Cluster Manager (HPCM): through 1.12.

CVSS3: 8.1
0%
Низкий
больше 1 года назад

Уязвимостей на страницу