Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 366 653

Количество 366 653

github логотип

GHSA-43rj-h44p-4j25

почти 2 года назад

SAP BusinessObjects Business Intelligence Platform allows a high privilege user to run client desktop applications even if some of the DLLs are not digitally signed or if the signature is broken. The attacker needs to have local access to the vulnerable system to perform DLL related tasks. This could result in a high impact on confidentiality and integrity of the application.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-43rh-v97q-9pr6

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: iio: temperature: mlx90635: Fix ERR_PTR dereference in mlx90635_probe() When devm_regmap_init_i2c() fails, regmap_ee could be error pointer, instead of checking for IS_ERR(regmap_ee), regmap is checked which looks like a copy paste error.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-43rg-xghf-cjwh

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Avoid overflow with array index The variable index is modified and reused as array index when modify register EIOINTC_ENABLE. There will be array index overflow problem.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-43rg-r573-6f25

26 дней назад

Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-43rg-mf7q-jmp2

больше 4 лет назад

CSRF exists on D-Link DIR-600M Rev. Cx devices before v3.05ENB01_beta_20170306. This can be used to bypass authentication and insert XSS sequences or possibly have unspecified other impact.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-43rg-56cq-gxxw

больше 2 лет назад

swftools v0.9.2 was discovered to contain a segmentation violation via the function state_free at swftools/src/swfc-history.c.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-43rf-fwx9-64w8

больше 4 лет назад

In Gradle Enterprise through 2021.3, probing of the server-side network environment can occur via an SMTP configuration test. The installation configuration user interface available to administrators allows testing the configured SMTP server settings. This test function can be used to identify the listening TCP ports available to the server, revealing information about the internal network environment.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-43rc-vwh5-26j7

больше 4 лет назад

The Xelex MobileTrack application 2.3.7 and earlier for Android uses hardcoded credentials, which allows remote attackers to obtain sensitive information via an unencrypted (1) FTP or (2) HTTP session.

EPSS: Низкий
github логотип

GHSA-43rc-rp87-3q62

больше 4 лет назад

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.

EPSS: Низкий
github логотип

GHSA-43rc-pcmf-f3g4

больше 4 лет назад

An issue was discovered in Simple Machines Forum (SMF) before release 2.0.17. There is SSRF related to Subs-Package.php and Subs.php because user-supplied data is used directly in curl calls.

EPSS: Низкий
github логотип

GHSA-43r8-qvvq-25fr

больше 4 лет назад

An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadFile URI.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-43r8-mvrp-6q9c

больше 4 лет назад

The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, does not restrict the size of values of environment variables, which allows local users to cause a denial of service (memory consumption or NULL pointer dereference) via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, related to (1) the "len +=" statement and (2) the apr_pcalloc function call, a different vulnerability than CVE-2011-3607.

EPSS: Низкий
github логотип

GHSA-43r8-6qx5-w655

больше 4 лет назад

SQL injection vulnerability in the Manage Albums feature in zp-core/admin-albumsort.php in ZENphoto 1.4.2 allows remote authenticated users to execute arbitrary SQL commands via the sortableList parameter.

EPSS: Низкий
github логотип

GHSA-43r8-23m5-329f

около 2 лет назад

Microsoft Outlook Remote Code Execution Vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-43r7-fmc5-8629

больше 4 лет назад

Processing a maliciously crafted image may lead to disclosure of user information. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5, iOS 14.6 and iPadOS 14.6. This issue was addressed with improved checks.

EPSS: Низкий
github логотип

GHSA-43r6-r8w4-qp6c

больше 4 лет назад

Basilix Webmail 0.9.7beta, and possibly other versions, stores *.class and *.inc files under the document root and does not restrict access, which could allows remote attackers to obtain sensitive information such as MySQL passwords and usernames from the mysql.class file.

EPSS: Низкий
github логотип

GHSA-43r5-v8pm-grg9

больше 4 лет назад

Cross-site request forgery (CSRF) vulnerability in the Commerce Balanced Payments module for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests that delete the user's configured bank accounts via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-43r5-42q2-7483

больше 4 лет назад

An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves mishandling of DMA in the "EFI" component. It allows physically proximate attackers to discover the FileVault 2 encryption password via a crafted Thunderbolt adapter.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-43r4-vm25-qm78

больше 4 лет назад

Moodle has multiple cross-site request forgery (CSRF) vulnerabilities in the Forum module

EPSS: Низкий
github логотип

GHSA-43r4-72q9-7mv7

больше 4 лет назад

Authentication vulnerability found in Dahua NVR models NVR50XX, NVR52XX, NVR54XX, NVR58XX with software before DH_NVR5xxx_Eng_P_V2.616.0000.0.R.20171102. Attacker could exploit this vulnerability to gain access to additional operations by means of forging json message.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-43rj-h44p-4j25

SAP BusinessObjects Business Intelligence Platform allows a high privilege user to run client desktop applications even if some of the DLLs are not digitally signed or if the signature is broken. The attacker needs to have local access to the vulnerable system to perform DLL related tasks. This could result in a high impact on confidentiality and integrity of the application.

CVSS3: 5.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-43rh-v97q-9pr6

In the Linux kernel, the following vulnerability has been resolved: iio: temperature: mlx90635: Fix ERR_PTR dereference in mlx90635_probe() When devm_regmap_init_i2c() fails, regmap_ee could be error pointer, instead of checking for IS_ERR(regmap_ee), regmap is checked which looks like a copy paste error.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-43rg-xghf-cjwh

In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Avoid overflow with array index The variable index is modified and reused as array index when modify register EIOINTC_ENABLE. There will be array index overflow problem.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-43rg-r573-6f25

Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.

CVSS3: 7.3
0%
Низкий
26 дней назад
github логотип
GHSA-43rg-mf7q-jmp2

CSRF exists on D-Link DIR-600M Rev. Cx devices before v3.05ENB01_beta_20170306. This can be used to bypass authentication and insert XSS sequences or possibly have unspecified other impact.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-43rg-56cq-gxxw

swftools v0.9.2 was discovered to contain a segmentation violation via the function state_free at swftools/src/swfc-history.c.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-43rf-fwx9-64w8

In Gradle Enterprise through 2021.3, probing of the server-side network environment can occur via an SMTP configuration test. The installation configuration user interface available to administrators allows testing the configured SMTP server settings. This test function can be used to identify the listening TCP ports available to the server, revealing information about the internal network environment.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-43rc-vwh5-26j7

The Xelex MobileTrack application 2.3.7 and earlier for Android uses hardcoded credentials, which allows remote attackers to obtain sensitive information via an unencrypted (1) FTP or (2) HTTP session.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-43rc-rp87-3q62

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-43rc-pcmf-f3g4

An issue was discovered in Simple Machines Forum (SMF) before release 2.0.17. There is SSRF related to Subs-Package.php and Subs.php because user-supplied data is used directly in curl calls.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-43r8-qvvq-25fr

An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadFile URI.

CVSS3: 8.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-43r8-mvrp-6q9c

The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, does not restrict the size of values of environment variables, which allows local users to cause a denial of service (memory consumption or NULL pointer dereference) via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, related to (1) the "len +=" statement and (2) the apr_pcalloc function call, a different vulnerability than CVE-2011-3607.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-43r8-6qx5-w655

SQL injection vulnerability in the Manage Albums feature in zp-core/admin-albumsort.php in ZENphoto 1.4.2 allows remote authenticated users to execute arbitrary SQL commands via the sortableList parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-43r8-23m5-329f

Microsoft Outlook Remote Code Execution Vulnerability

CVSS3: 8.8
3%
Низкий
около 2 лет назад
github логотип
GHSA-43r7-fmc5-8629

Processing a maliciously crafted image may lead to disclosure of user information. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5, iOS 14.6 and iPadOS 14.6. This issue was addressed with improved checks.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-43r6-r8w4-qp6c

Basilix Webmail 0.9.7beta, and possibly other versions, stores *.class and *.inc files under the document root and does not restrict access, which could allows remote attackers to obtain sensitive information such as MySQL passwords and usernames from the mysql.class file.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-43r5-v8pm-grg9

Cross-site request forgery (CSRF) vulnerability in the Commerce Balanced Payments module for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests that delete the user's configured bank accounts via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-43r5-42q2-7483

An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves mishandling of DMA in the "EFI" component. It allows physically proximate attackers to discover the FileVault 2 encryption password via a crafted Thunderbolt adapter.

CVSS3: 6.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-43r4-vm25-qm78

Moodle has multiple cross-site request forgery (CSRF) vulnerabilities in the Forum module

1%
Низкий
больше 4 лет назад
github логотип
GHSA-43r4-72q9-7mv7

Authentication vulnerability found in Dahua NVR models NVR50XX, NVR52XX, NVR54XX, NVR58XX with software before DH_NVR5xxx_Eng_P_V2.616.0000.0.R.20171102. Attacker could exploit this vulnerability to gain access to additional operations by means of forging json message.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу