Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 366 653

Количество 366 653

github логотип

GHSA-4444-8mhw-c9m5

больше 4 лет назад

There is a heap-buffer-overflow at jmem-poolman.c:165 in jmem_pools_collect_empty in JerryScript 2.2.0.

EPSS: Низкий
github логотип

GHSA-4444-267r-x82x

больше 4 лет назад

The HTTP client in Cisco IOS 12.4 and 15.0 allows user-assisted remote attackers to cause a denial of service (device crash) via a malformed HTTP response to a request for service installation, aka Bug ID CSCts12249.

EPSS: Низкий
github логотип

GHSA-4443-73qg-vxgj

больше 4 лет назад

showme.php in CelerBB 0.0.2 allows remote attackers to obtain "reserved information" via the user parameter.

EPSS: Низкий
github логотип

GHSA-4443-6wcq-ghrh

больше 4 лет назад

Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4257, CVE-2016-4258, CVE-2016-4259, CVE-2016-4260, CVE-2016-4261, and CVE-2016-4262.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4442-gqg3-5qvm

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: fix memory corruption on open The probe session-duplication overflow check incremented the session count also when there were no more available sessions so that memory beyond the fixed-size slab-allocated session array could be corrupted in fastrpc_session_alloc() on open().

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4442-448q-43m4

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Hostel allows Reflected XSS. This issue affects Hostel: from n/a through 1.1.5.5.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-443x-fg59-93h7

11 месяцев назад

A vulnerability was identified in Campcodes Online Apartment Visitor Management System 1.0. Impacted is an unknown function of the file /search-visitor.php. The manipulation of the argument searchdata leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-443w-gf2f-8h6x

больше 1 года назад

Untrusted pointer dereference in Windows Kernel Memory allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-443w-3rq3-5m5h

5 месяцев назад

AWS SDK for Java 2.0: Improper Handling of Special Characters in CloudFront Signing Utilities

EPSS: Низкий
github логотип

GHSA-443r-v97h-37x3

больше 4 лет назад

Microarchitectural Store Buffer Data Sampling (MSBDS): Store buffers on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-information/SA00233-microcode-update-guidance_05132019.pdf

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-443r-2qp2-x75x

больше 4 лет назад

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0093, CVE-2016-0094, and CVE-2016-0096.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-443p-ggjw-7w6x

около 2 лет назад

Missing Authorization vulnerability in reputeinfosystems ARForms.This issue affects ARForms: from n/a through 6.4.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-443p-64xr-9cq7

больше 2 лет назад

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/add_postlogin.php. The manipulation of the argument SingleLoginId leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259711.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-443m-f58x-jx9j

2 месяца назад

Capgo before 12.128.2 contains an information disclosure vulnerability in the public.invite_user_to_org RPC function that allows unauthenticated attackers to enumerate organization existence by observing distinct error responses. Attackers can call the SECURITY DEFINER function with a publishable API key to determine if an organization ID exists based on NO_ORG versus NO_RIGHTS responses, enabling tenant enumeration attacks.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-443m-3fr6-w8wj

около 3 лет назад

PowerJob incorrect access control vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-443j-grxv-2pgv

почти 2 года назад

Apache ActiveMQ Artemis: Authenticated users could perform RCE via Jolokia MBeans

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-443j-8jp8-4xch

больше 3 лет назад

Web-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing the frame-ancestors directive when it was used in the Web Extension's Content Security Policy. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-443j-7m97-75j3

больше 4 лет назад

This vulnerability allows remote attackers to overwrite files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the org.apache.jsp.u.jsp.reports.templates.network.traffic_005freport_jsp servlet, which listens on TCP port 8081 by default. When parsing the filename parameter, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to overwrite any files accessible to the Administrator. Was ZDI-CAN-5191.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-443j-6p7g-6v4w

больше 4 лет назад

OpenStack Mistral DoS

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-443h-2c59-36vf

больше 4 лет назад

pam_wheel in Linux-PAM 0.78, with the trust option enabled and the use_uid option disabled, allows local users to spoof log entries and gain privileges by causing getlogin() to return a spoofed user name.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4444-8mhw-c9m5

There is a heap-buffer-overflow at jmem-poolman.c:165 in jmem_pools_collect_empty in JerryScript 2.2.0.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4444-267r-x82x

The HTTP client in Cisco IOS 12.4 and 15.0 allows user-assisted remote attackers to cause a denial of service (device crash) via a malformed HTTP response to a request for service installation, aka Bug ID CSCts12249.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4443-73qg-vxgj

showme.php in CelerBB 0.0.2 allows remote attackers to obtain "reserved information" via the user parameter.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-4443-6wcq-ghrh

Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4257, CVE-2016-4258, CVE-2016-4259, CVE-2016-4260, CVE-2016-4261, and CVE-2016-4262.

CVSS3: 9.8
5%
Низкий
больше 4 лет назад
github логотип
GHSA-4442-gqg3-5qvm

In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: fix memory corruption on open The probe session-duplication overflow check incremented the session count also when there were no more available sessions so that memory beyond the fixed-size slab-allocated session array could be corrupted in fastrpc_session_alloc() on open().

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-4442-448q-43m4

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Hostel allows Reflected XSS. This issue affects Hostel: from n/a through 1.1.5.5.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-443x-fg59-93h7

A vulnerability was identified in Campcodes Online Apartment Visitor Management System 1.0. Impacted is an unknown function of the file /search-visitor.php. The manipulation of the argument searchdata leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.

CVSS3: 7.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-443w-gf2f-8h6x

Untrusted pointer dereference in Windows Kernel Memory allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-443w-3rq3-5m5h

AWS SDK for Java 2.0: Improper Handling of Special Characters in CloudFront Signing Utilities

5 месяцев назад
github логотип
GHSA-443r-v97h-37x3

Microarchitectural Store Buffer Data Sampling (MSBDS): Store buffers on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-information/SA00233-microcode-update-guidance_05132019.pdf

CVSS3: 5.6
2%
Низкий
больше 4 лет назад
github логотип
GHSA-443r-2qp2-x75x

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0093, CVE-2016-0094, and CVE-2016-0096.

CVSS3: 7.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-443p-ggjw-7w6x

Missing Authorization vulnerability in reputeinfosystems ARForms.This issue affects ARForms: from n/a through 6.4.

CVSS3: 7.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-443p-64xr-9cq7

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/add_postlogin.php. The manipulation of the argument SingleLoginId leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259711.

CVSS3: 6.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-443m-f58x-jx9j

Capgo before 12.128.2 contains an information disclosure vulnerability in the public.invite_user_to_org RPC function that allows unauthenticated attackers to enumerate organization existence by observing distinct error responses. Attackers can call the SECURITY DEFINER function with a publishable API key to determine if an organization ID exists based on NO_ORG versus NO_RIGHTS responses, enabling tenant enumeration attacks.

CVSS3: 5.3
0%
Низкий
2 месяца назад
github логотип
GHSA-443m-3fr6-w8wj

PowerJob incorrect access control vulnerability

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-443j-grxv-2pgv

Apache ActiveMQ Artemis: Authenticated users could perform RCE via Jolokia MBeans

CVSS3: 8.8
17%
Средний
почти 2 года назад
github логотип
GHSA-443j-8jp8-4xch

Web-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing the frame-ancestors directive when it was used in the Web Extension's Content Security Policy. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-443j-7m97-75j3

This vulnerability allows remote attackers to overwrite files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the org.apache.jsp.u.jsp.reports.templates.network.traffic_005freport_jsp servlet, which listens on TCP port 8081 by default. When parsing the filename parameter, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to overwrite any files accessible to the Administrator. Was ZDI-CAN-5191.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-443j-6p7g-6v4w

OpenStack Mistral DoS

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-443h-2c59-36vf

pam_wheel in Linux-PAM 0.78, with the trust option enabled and the use_uid option disabled, allows local users to spoof log entries and gain privileges by causing getlogin() to return a spoofed user name.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу