Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 367 277

Количество 367 277

github логотип

GHSA-44x3-ghwf-jp4g

почти 2 года назад

A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < V7.2.12 only if the IP interface is enabled (which is not the default configuration)). The web server of affected devices does not authenticate GET requests that execute specific commands (such as `ping`) on operating system level.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-44x3-96q8-6c96

больше 4 лет назад

Microsoft GDI Component in Windows 7 SP1 and Windows Server 2008 SP2 and R2 SP1 allows an attacker to log on to an affected system and run a specially crafted application to compromise the user's system, due improperly disclosing kernel memory addresses, aka "Windows GDI Information Disclosure Vulnerability".

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-44x3-2gc7-3w5m

около 2 лет назад

An unauthenticated IEEE 802.15.4 'co-ordinator realignment' packet can be used to force Zigbee nodes to change their network identifier (pan ID), leading to a denial of service. This packet type is not useful in production and should be used only for PHY qualification.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-44x2-g266-gvmh

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in manager/xmedia.php in Plume CMS 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the dir parameter.

EPSS: Низкий
github логотип

GHSA-44wx-pxp5-fjxm

больше 4 лет назад

An issue was discovered on Samsung mobile devices with software through 2016-09-13 (Exynos AP chipsets). There is a memcpy heap-based buffer overflow in the OTP service. The Samsung ID is SVE-2016-7114 (December 2016).

EPSS: Низкий
github логотип

GHSA-44wx-mcwc-xfg9

больше 4 лет назад

Postfix 2.5 before 2.5.4 and 2.6 before 2.6-20080814 delivers to a mailbox file even when this file is not owned by the recipient, which allows local users to read e-mail messages by creating a mailbox file corresponding to another user's account name.

EPSS: Низкий
github логотип

GHSA-44ww-rw32-794r

3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: apparmor: Fix & Optimize table creation from possibly unaligned memory Source blob may come from userspace and might be unaligned. Try to optize the copying process by avoiding unaligned memory accesses. - Added Fixes tag - Added "Fix &" to description as this doesn't just optimize but fixes a potential unaligned memory access [jj: remove duplicate word "convert" in comment trigger checkpatch warning]

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-44wv-r39h-27hr

10 месяцев назад

PHPGurukul Student Record Management System 3.20 is vulnerable to SQL Injection via the id and password parameters in login.php.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-44wr-rmwq-3phw

около 3 лет назад

Craft CMS vulnerable to Remote Code Execution via validatePath bypass

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-44wr-9xpq-76v2

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: powerpc/pseries/iommu: IOMMU table is not initialized for kdump over SR-IOV When kdump kernel tries to copy dump data over SR-IOV, LPAR panics due to NULL pointer exception: Kernel attempted to read user page (0) - exploit attempt? (uid: 0) BUG: Kernel NULL pointer dereference on read at 0x00000000 Faulting instruction address: 0xc000000020847ad4 Oops: Kernel access of bad area, sig: 11 [#1] LE PAGE_SIZE=64K MMU=Radix SMP NR_CPUS=2048 NUMA pSeries Modules linked in: mlx5_core(+) vmx_crypto pseries_wdt papr_scm libnvdimm mlxfw tls psample sunrpc fuse overlay squashfs loop CPU: 12 PID: 315 Comm: systemd-udevd Not tainted 6.4.0-Test102+ #12 Hardware name: IBM,9080-HEX POWER10 (raw) 0x800200 0xf000006 of:IBM,FW1060.00 (NH1060_008) hv:phyp pSeries NIP: c000000020847ad4 LR: c00000002083b2dc CTR: 00000000006cd18c REGS: c000000029162ca0 TRAP: 0300 Not tainted (6.4.0-Test102+) MSR: 800000000280b...

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-44wr-733h-5gmq

больше 4 лет назад

Unspecified vulnerability in WebKit on Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to use Safari as an indirect proxy and send attacker-controlled data to arbitrary TCP ports via unknown vectors.

EPSS: Низкий
github логотип

GHSA-44wq-g436-pmwv

около 2 лет назад

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-44wq-cf78-w397

больше 4 лет назад

The mixing functions in the random number generator in Libgcrypt before 1.5.6, 1.6.x before 1.6.6, and 1.7.x before 1.7.3 and GnuPG before 1.4.21 make it easier for attackers to obtain the values of 160 bits by leveraging knowledge of the previous 4640 bits.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-44wq-7fm8-j2j2

больше 4 лет назад

Lack of authentication in file-viewing components in DDRT Dashcom Live 2019-05-09 allows anyone to remotely access all claim details by visiting easily guessable dashboard/uploads/claim_files/claim_id_ URLs.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-44wq-5x49-35cx

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in webfolio/admin/users/edit in Webfolio CMS 1.1.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) First name, (2) Last name or (3) Email (required) fields.

EPSS: Низкий
github логотип

GHSA-44wq-5r6v-x59g

больше 4 лет назад

The Morocco Weather (aka com.mobilesoft.meteomaroc) application 3.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-44wp-g8f4-f4v5

3 месяца назад

Filament: Unauthenticated temporary file upload on auth pages

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-44wp-6pqg-r5gm

больше 4 лет назад

Unspecified vulnerability in Oracle Sun Solaris 11.2 allows local users to affect confidentiality, integrity, and availability via vectors related to NSCD.

EPSS: Низкий
github логотип

GHSA-44wm-jgm7-qv4v

больше 4 лет назад

Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.6.50 and prior, 5.7.32 and prior and 8.0.22 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Client accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Client. CVSS 3.1 Base Score 4.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L).

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-44wm-f244-xhp3

больше 2 лет назад

Pillow buffer overflow vulnerability

CVSS3: 6.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-44x3-ghwf-jp4g

A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < V7.2.12 only if the IP interface is enabled (which is not the default configuration)). The web server of affected devices does not authenticate GET requests that execute specific commands (such as `ping`) on operating system level.

CVSS3: 7.2
1%
Низкий
почти 2 года назад
github логотип
GHSA-44x3-96q8-6c96

Microsoft GDI Component in Windows 7 SP1 and Windows Server 2008 SP2 and R2 SP1 allows an attacker to log on to an affected system and run a specially crafted application to compromise the user's system, due improperly disclosing kernel memory addresses, aka "Windows GDI Information Disclosure Vulnerability".

CVSS3: 4.7
2%
Низкий
больше 4 лет назад
github логотип
GHSA-44x3-2gc7-3w5m

An unauthenticated IEEE 802.15.4 'co-ordinator realignment' packet can be used to force Zigbee nodes to change their network identifier (pan ID), leading to a denial of service. This packet type is not useful in production and should be used only for PHY qualification.

CVSS3: 7.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-44x2-g266-gvmh

Cross-site scripting (XSS) vulnerability in manager/xmedia.php in Plume CMS 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the dir parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-44wx-pxp5-fjxm

An issue was discovered on Samsung mobile devices with software through 2016-09-13 (Exynos AP chipsets). There is a memcpy heap-based buffer overflow in the OTP service. The Samsung ID is SVE-2016-7114 (December 2016).

0%
Низкий
больше 4 лет назад
github логотип
GHSA-44wx-mcwc-xfg9

Postfix 2.5 before 2.5.4 and 2.6 before 2.6-20080814 delivers to a mailbox file even when this file is not owned by the recipient, which allows local users to read e-mail messages by creating a mailbox file corresponding to another user's account name.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-44ww-rw32-794r

In the Linux kernel, the following vulnerability has been resolved: apparmor: Fix & Optimize table creation from possibly unaligned memory Source blob may come from userspace and might be unaligned. Try to optize the copying process by avoiding unaligned memory accesses. - Added Fixes tag - Added "Fix &" to description as this doesn't just optimize but fixes a potential unaligned memory access [jj: remove duplicate word "convert" in comment trigger checkpatch warning]

CVSS3: 7.1
0%
Низкий
3 месяца назад
github логотип
GHSA-44wv-r39h-27hr

PHPGurukul Student Record Management System 3.20 is vulnerable to SQL Injection via the id and password parameters in login.php.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-44wr-rmwq-3phw

Craft CMS vulnerable to Remote Code Execution via validatePath bypass

CVSS3: 7.2
2%
Низкий
около 3 лет назад
github логотип
GHSA-44wr-9xpq-76v2

In the Linux kernel, the following vulnerability has been resolved: powerpc/pseries/iommu: IOMMU table is not initialized for kdump over SR-IOV When kdump kernel tries to copy dump data over SR-IOV, LPAR panics due to NULL pointer exception: Kernel attempted to read user page (0) - exploit attempt? (uid: 0) BUG: Kernel NULL pointer dereference on read at 0x00000000 Faulting instruction address: 0xc000000020847ad4 Oops: Kernel access of bad area, sig: 11 [#1] LE PAGE_SIZE=64K MMU=Radix SMP NR_CPUS=2048 NUMA pSeries Modules linked in: mlx5_core(+) vmx_crypto pseries_wdt papr_scm libnvdimm mlxfw tls psample sunrpc fuse overlay squashfs loop CPU: 12 PID: 315 Comm: systemd-udevd Not tainted 6.4.0-Test102+ #12 Hardware name: IBM,9080-HEX POWER10 (raw) 0x800200 0xf000006 of:IBM,FW1060.00 (NH1060_008) hv:phyp pSeries NIP: c000000020847ad4 LR: c00000002083b2dc CTR: 00000000006cd18c REGS: c000000029162ca0 TRAP: 0300 Not tainted (6.4.0-Test102+) MSR: 800000000280b...

CVSS3: 4.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-44wr-733h-5gmq

Unspecified vulnerability in WebKit on Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to use Safari as an indirect proxy and send attacker-controlled data to arbitrary TCP ports via unknown vectors.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-44wq-g436-pmwv

SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability

CVSS3: 8.8
2%
Низкий
около 2 лет назад
github логотип
GHSA-44wq-cf78-w397

The mixing functions in the random number generator in Libgcrypt before 1.5.6, 1.6.x before 1.6.6, and 1.7.x before 1.7.3 and GnuPG before 1.4.21 make it easier for attackers to obtain the values of 160 bits by leveraging knowledge of the previous 4640 bits.

CVSS3: 5.3
4%
Низкий
больше 4 лет назад
github логотип
GHSA-44wq-7fm8-j2j2

Lack of authentication in file-viewing components in DDRT Dashcom Live 2019-05-09 allows anyone to remotely access all claim details by visiting easily guessable dashboard/uploads/claim_files/claim_id_ URLs.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-44wq-5x49-35cx

Multiple cross-site scripting (XSS) vulnerabilities in webfolio/admin/users/edit in Webfolio CMS 1.1.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) First name, (2) Last name or (3) Email (required) fields.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-44wq-5r6v-x59g

The Morocco Weather (aka com.mobilesoft.meteomaroc) application 3.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-44wp-g8f4-f4v5

Filament: Unauthenticated temporary file upload on auth pages

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-44wp-6pqg-r5gm

Unspecified vulnerability in Oracle Sun Solaris 11.2 allows local users to affect confidentiality, integrity, and availability via vectors related to NSCD.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-44wm-jgm7-qv4v

Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.6.50 and prior, 5.7.32 and prior and 8.0.22 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Client accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Client. CVSS 3.1 Base Score 4.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L).

CVSS3: 4.2
1%
Низкий
больше 4 лет назад
github логотип
GHSA-44wm-f244-xhp3

Pillow buffer overflow vulnerability

CVSS3: 6.7
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу