Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 366 653

Количество 366 653

github логотип

GHSA-4422-2p52-phgf

больше 4 лет назад

Apple Mac OS X 10.3.4, 10.4, 10.5, and possibly other versions does not properly clear memory for login (aka Loginwindow.app), Keychain, or FileVault passwords, which could allow the root user or an attacker with physical access to obtain sensitive information by reading memory.

EPSS: Низкий
github логотип

GHSA-43xx-wfwg-ffh4

больше 2 лет назад

An issue in Kap for macOS version 3.6.0 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-43xx-j7mw-696v

10 месяцев назад

Multiple issues were addressed by disabling array allocation sinking. This issue is fixed in iOS 26.1 and iPadOS 26.1, Safari 26.1, visionOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-43xw-wcqh-j8wq

больше 4 лет назад

In InvoicePlane 1.5.11, the upload feature discloses the full path of the file upload directory.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-43xw-w72r-jr6p

больше 4 лет назад

Multiple unspecified vulnerabilities in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 have unknown impact and attack vectors, related to (1) an Immediate Image Overwrite (IIO) error message at the Local User Interface (LUI) if overwrite fails, (2) an IIO failure when a Held Job is deleted, and (3) an On Demand Image Overwrite failure when the overwrite is greater than 2 Gb.

EPSS: Низкий
github логотип

GHSA-43xw-grf3-j6mj

больше 4 лет назад

Unspecified vulnerability in the Oracle Secure Global Desktop component in Oracle Virtualization 4.63, 4.71, and 5.2 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to OpenSSL.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-43xr-rg35-2prq

больше 4 лет назад

Cross-site request forgery (CSRF) vulnerability in the communicate function in estmaster.c for Hyper Estraier before 1.3.3 allows remote attackers to perform unauthorized actions as other users via unknown vectors.

EPSS: Низкий
github логотип

GHSA-43xr-qfv7-4j2q

7 месяцев назад

IPFire 2.21 Core Update 127 contains multiple reflected cross-site scripting vulnerabilities in the fwhosts.cgi script that allow attackers to inject malicious scripts through multiple parameters including HOSTNAME, IP, SUBNET, NETREMARK, HOSTREMARK, newhost, grp_name, remark, SRV_NAME, SRV_PORT, SRVGRP_NAME, SRVGRP_REMARK, and updatesrvgrp. Attackers can submit POST requests with script payloads in these parameters to execute arbitrary JavaScript in the context of authenticated users' browsers.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-43xr-mj98-366j

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in (a) PMOS Help Desk 2.4, formerly (b) InverseFlow Help Desk 2.31 and also sold as (c) Ace Helpdesk 2.31, allow remote attackers to inject arbitrary web script or HTML via the (1) id or email parameter to ticketview.php, or (2) the email parameter to ticket.php.

EPSS: Низкий
github логотип

GHSA-43xq-5x33-h3j9

больше 3 лет назад

Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2023-21548.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-43xp-p639-52h2

больше 4 лет назад

Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-43xm-v588-p23q

больше 4 лет назад

Nortek Linear eMerge 50P/5000P devices have Default Credentials.

EPSS: Низкий
github логотип

GHSA-43xj-jq6q-9wr8

больше 4 лет назад

Buffer overflow in Analog before 4.16 allows remote attackers to execute arbitrary commands by using the ALIAS command to construct large strings.

EPSS: Низкий
github логотип

GHSA-43xj-hvp7-hp7w

больше 4 лет назад

Unrestricted file upload vulnerability in calendar_admin.asp in Full Revolution aspWebCalendar 2008 allows remote attackers to upload and execute arbitrary code via the FILE1 parameter in an uploadfileprocess action, probably followed by a direct request to the file in calendar/eventimages/.

EPSS: Средний
github логотип

GHSA-43xj-fv89-3qq5

больше 4 лет назад

SQL injection vulnerability in prodshow.php in Maran PHP Shop allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-4879.

EPSS: Низкий
github логотип

GHSA-43xj-964v-hcjf

больше 4 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions. NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-43xj-7j8x-m26r

почти 2 года назад

A vulnerability, which was classified as critical, has been found in Codezips Free Exam Hall Seating Management System 1.0. This issue affects some unknown processing of the file /pages/save_user.php. The manipulation of the argument image leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The initial researcher disclosure contains confusing vulnerability classes and file names.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-43xj-352m-99m9

больше 2 лет назад

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the pmsvcs kernel extension to cause a denial of service. IBM X-Force ID: 267967.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-43xj-26f5-3q3h

9 месяцев назад

TinyWebGallery v2.5 contains a remote code execution vulnerability in the admin upload functionality that allows unauthenticated attackers to upload malicious PHP files. Attackers can upload .phar files with embedded system commands to execute arbitrary code on the server by accessing the uploaded file's URL.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-43xh-q266-jr4x

больше 4 лет назад

ReadCode() in decompress.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service (invalid write access) via a crafted HDF5 file. This issue was triggered while converting a GIF file to an HDF file.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4422-2p52-phgf

Apple Mac OS X 10.3.4, 10.4, 10.5, and possibly other versions does not properly clear memory for login (aka Loginwindow.app), Keychain, or FileVault passwords, which could allow the root user or an attacker with physical access to obtain sensitive information by reading memory.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-43xx-wfwg-ffh4

An issue in Kap for macOS version 3.6.0 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-43xx-j7mw-696v

Multiple issues were addressed by disabling array allocation sinking. This issue is fixed in iOS 26.1 and iPadOS 26.1, Safari 26.1, visionOS 26.1. Processing maliciously crafted web content may lead to an unexpected process crash.

CVSS3: 4.3
1%
Низкий
10 месяцев назад
github логотип
GHSA-43xw-wcqh-j8wq

In InvoicePlane 1.5.11, the upload feature discloses the full path of the file upload directory.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-43xw-w72r-jr6p

Multiple unspecified vulnerabilities in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 have unknown impact and attack vectors, related to (1) an Immediate Image Overwrite (IIO) error message at the Local User Interface (LUI) if overwrite fails, (2) an IIO failure when a Held Job is deleted, and (3) an On Demand Image Overwrite failure when the overwrite is greater than 2 Gb.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-43xw-grf3-j6mj

Unspecified vulnerability in the Oracle Secure Global Desktop component in Oracle Virtualization 4.63, 4.71, and 5.2 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to OpenSSL.

CVSS3: 9.8
5%
Низкий
больше 4 лет назад
github логотип
GHSA-43xr-rg35-2prq

Cross-site request forgery (CSRF) vulnerability in the communicate function in estmaster.c for Hyper Estraier before 1.3.3 allows remote attackers to perform unauthorized actions as other users via unknown vectors.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-43xr-qfv7-4j2q

IPFire 2.21 Core Update 127 contains multiple reflected cross-site scripting vulnerabilities in the fwhosts.cgi script that allow attackers to inject malicious scripts through multiple parameters including HOSTNAME, IP, SUBNET, NETREMARK, HOSTREMARK, newhost, grp_name, remark, SRV_NAME, SRV_PORT, SRVGRP_NAME, SRVGRP_REMARK, and updatesrvgrp. Attackers can submit POST requests with script payloads in these parameters to execute arbitrary JavaScript in the context of authenticated users' browsers.

CVSS3: 5.4
0%
Низкий
7 месяцев назад
github логотип
GHSA-43xr-mj98-366j

Multiple cross-site scripting (XSS) vulnerabilities in (a) PMOS Help Desk 2.4, formerly (b) InverseFlow Help Desk 2.31 and also sold as (c) Ace Helpdesk 2.31, allow remote attackers to inject arbitrary web script or HTML via the (1) id or email parameter to ticketview.php, or (2) the email parameter to ticket.php.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-43xq-5x33-h3j9

Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2023-21548.

CVSS3: 8.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-43xp-p639-52h2

Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-43xm-v588-p23q

Nortek Linear eMerge 50P/5000P devices have Default Credentials.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-43xj-jq6q-9wr8

Buffer overflow in Analog before 4.16 allows remote attackers to execute arbitrary commands by using the ALIAS command to construct large strings.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-43xj-hvp7-hp7w

Unrestricted file upload vulnerability in calendar_admin.asp in Full Revolution aspWebCalendar 2008 allows remote attackers to upload and execute arbitrary code via the FILE1 parameter in an uploadfileprocess action, probably followed by a direct request to the file in calendar/eventimages/.

12%
Средний
больше 4 лет назад
github логотип
GHSA-43xj-fv89-3qq5

SQL injection vulnerability in prodshow.php in Maran PHP Shop allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-4879.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-43xj-964v-hcjf

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions. NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.

CVSS3: 9.8
98%
Критический
больше 4 лет назад
github логотип
GHSA-43xj-7j8x-m26r

A vulnerability, which was classified as critical, has been found in Codezips Free Exam Hall Seating Management System 1.0. This issue affects some unknown processing of the file /pages/save_user.php. The manipulation of the argument image leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The initial researcher disclosure contains confusing vulnerability classes and file names.

CVSS3: 6.3
1%
Низкий
почти 2 года назад
github логотип
GHSA-43xj-352m-99m9

IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the pmsvcs kernel extension to cause a denial of service. IBM X-Force ID: 267967.

CVSS3: 6.2
0%
Низкий
больше 2 лет назад
github логотип
GHSA-43xj-26f5-3q3h

TinyWebGallery v2.5 contains a remote code execution vulnerability in the admin upload functionality that allows unauthenticated attackers to upload malicious PHP files. Attackers can upload .phar files with embedded system commands to execute arbitrary code on the server by accessing the uploaded file's URL.

CVSS3: 9.8
1%
Низкий
9 месяцев назад
github логотип
GHSA-43xh-q266-jr4x

ReadCode() in decompress.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service (invalid write access) via a crafted HDF5 file. This issue was triggered while converting a GIF file to an HDF file.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу