Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 366 653

Количество 366 653

github логотип

GHSA-43g6-p2gr-59p7

больше 4 лет назад

OpenBSD 2.6 and earlier allows remote attackers to cause a denial of service by flooding the server with ARP requests.

EPSS: Низкий
github логотип

GHSA-43g5-2wr2-q7vj

больше 1 года назад

MongoDB Shell may be susceptible to Control Character Injection via autocomplete

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-43g4-v893-w7hq

26 дней назад

Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-43g4-jfv8-9wgq

почти 3 года назад

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Abel Ruiz GuruWalk Affiliates plugin <= 1.0.0 versions.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-43g4-6p45-h9cf

больше 4 лет назад

The FTP proxy server in Apple AirPort Express, AirPort Extreme, and Time Capsule with firmware 7.5 does not restrict the IP address and port specified in a PORT command from a client, which allows remote attackers to leverage intranet FTP servers for arbitrary TCP forwarding via a crafted PORT command.

EPSS: Низкий
github логотип

GHSA-43g4-4j68-8xj3

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: xen: fix UAF in dmabuf_exp_from_pages() [dma_buf_fd() fixes; no preferences regarding the tree it goes through - up to xen folks] As soon as we'd inserted a file reference into descriptor table, another thread could close it. That's fine for the case when all we are doing is returning that descriptor to userland (it's a race, but it's a userland race and there's nothing the kernel can do about it). However, if we follow fd_install() with any kind of access to objects that would be destroyed on close (be it the struct file itself or anything destroyed by its ->release()), we have a UAF. dma_buf_fd() is a combination of reserving a descriptor and fd_install(). gntdev dmabuf_exp_from_pages() calls it and then proceeds to access the objects destroyed on close - starting with gntdev_dmabuf itself. Fix that by doing reserving descriptor before anything else and do fd_install() only when everything had been set up.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-43g4-487m-5q6m

больше 1 года назад

Open WebUI Vulnerable to a Session Fixation Attack

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-43g3-jf9m-f6f5

больше 4 лет назад

Tad Uploader edit book list function is vulnerable to authorization bypass, thus remote attackers can use the function to amend the folder names in the book list without logging in.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-43g3-9hv3-rp7w

больше 4 лет назад

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D7800 before 1.0.1.44, R7500v2 before 1.0.3.38, R7800 before 1.0.2.52, RBK20 before 2.3.0.28, RBR20 before 2.3.0.28, RBS20 before 2.3.0.28, RBK40 before 2.3.0.28, RBS40 before 2.3.0.28, RBK50 before 2.3.0.32, RBR50 before 2.3.0.32, and RBS50 before 2.3.0.32.

EPSS: Низкий
github логотип

GHSA-43g3-5cf8-2gm2

больше 4 лет назад

In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501.

EPSS: Низкий
github логотип

GHSA-43g2-2w55-rgfp

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in CMD_DOMAIN in JBMC Software DirectAdmin 1.403 allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via the (1) select0 or (2) select8 parameters.

EPSS: Низкий
github логотип

GHSA-43fx-m629-rhfw

больше 4 лет назад

Microsoft Edge allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Microsoft Edge Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0158.

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-43fx-4mqw-qphw

около 1 месяца назад

A vulnerability was identified in OWASP DefectDojo 2.59.0. This issue affects the function UserSerializer of the file dojo/api_v2/serializers.py of the component API/Web. Such manipulation of the argument is_staff leads to improper privilege management. The attack may be performed from remote. The exploit is publicly available and might be used. Upgrading to version 2.58.3 and 3.0.0 is capable of addressing this issue. The name of the patch is 68a272f299d096249fd3ba9c2676bf69012857bf. It is advisable to upgrade the affected component. 2.59.0 was not intended to be released and has been removed.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-43fx-2cfr-rfxj

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Simple Booking Simple Booking Widget allows Stored XSS.This issue affects Simple Booking Widget: from n/a through 1.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-43fw-xm94-j3mx

около 3 лет назад

An issue was discovered in the Clario VPN client through 5.9.1.1662 for macOS. The VPN client insecurely configures the operating system such that traffic to the local network is sent in plaintext outside the VPN tunnel even if the local network is using a non-RFC1918 IP subnet. This allows an adversary to trick the victim into sending arbitrary IP traffic in plaintext outside the VPN tunnel. NOTE: the tunnelcrack.mathyvanhoef.com website uses this CVE ID to refer more generally to "LocalNet attack resulting in leakage of traffic in plaintext" rather than to only Clario.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-43fw-h62p-gjw8

больше 2 лет назад

Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-43fw-536j-w37j

почти 3 года назад

Yamcs API Directory Traversal vulnerability

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-43fw-27v6-42x2

больше 4 лет назад

In ImageMagick 7.0.8-35 Q16, there is a stack-based buffer overflow in the function PopHexPixel of coders/ps.c, which allows an attacker to cause a denial of service or code execution via a crafted image file.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-43fv-wgqf-rwjq

около 1 месяца назад

An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote authenticated users with administrator privileges to execute arbitrary commands by uploading a crafted ZIP archive containing a server-executable file.

EPSS: Низкий
github логотип

GHSA-43fv-rqxp-47v5

больше 4 лет назад

Multiple SQL injection vulnerabilities in MH Products Projekt Shop allow remote attackers to execute arbitrary SQL commands via the (1) ts parameter to details.php and possibly the (2) ilceler parameter to index.php.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-43g6-p2gr-59p7

OpenBSD 2.6 and earlier allows remote attackers to cause a denial of service by flooding the server with ARP requests.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-43g5-2wr2-q7vj

MongoDB Shell may be susceptible to Control Character Injection via autocomplete

CVSS3: 7.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-43g4-v893-w7hq

Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.

CVSS3: 8.8
1%
Низкий
26 дней назад
github логотип
GHSA-43g4-jfv8-9wgq

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Abel Ruiz GuruWalk Affiliates plugin <= 1.0.0 versions.

CVSS3: 5.9
0%
Низкий
почти 3 года назад
github логотип
GHSA-43g4-6p45-h9cf

The FTP proxy server in Apple AirPort Express, AirPort Extreme, and Time Capsule with firmware 7.5 does not restrict the IP address and port specified in a PORT command from a client, which allows remote attackers to leverage intranet FTP servers for arbitrary TCP forwarding via a crafted PORT command.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-43g4-4j68-8xj3

In the Linux kernel, the following vulnerability has been resolved: xen: fix UAF in dmabuf_exp_from_pages() [dma_buf_fd() fixes; no preferences regarding the tree it goes through - up to xen folks] As soon as we'd inserted a file reference into descriptor table, another thread could close it. That's fine for the case when all we are doing is returning that descriptor to userland (it's a race, but it's a userland race and there's nothing the kernel can do about it). However, if we follow fd_install() with any kind of access to objects that would be destroyed on close (be it the struct file itself or anything destroyed by its ->release()), we have a UAF. dma_buf_fd() is a combination of reserving a descriptor and fd_install(). gntdev dmabuf_exp_from_pages() calls it and then proceeds to access the objects destroyed on close - starting with gntdev_dmabuf itself. Fix that by doing reserving descriptor before anything else and do fd_install() only when everything had been set up.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-43g4-487m-5q6m

Open WebUI Vulnerable to a Session Fixation Attack

CVSS3: 7.6
больше 1 года назад
github логотип
GHSA-43g3-jf9m-f6f5

Tad Uploader edit book list function is vulnerable to authorization bypass, thus remote attackers can use the function to amend the folder names in the book list without logging in.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-43g3-9hv3-rp7w

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D7800 before 1.0.1.44, R7500v2 before 1.0.3.38, R7800 before 1.0.2.52, RBK20 before 2.3.0.28, RBR20 before 2.3.0.28, RBS20 before 2.3.0.28, RBK40 before 2.3.0.28, RBS40 before 2.3.0.28, RBK50 before 2.3.0.32, RBR50 before 2.3.0.32, and RBS50 before 2.3.0.32.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-43g3-5cf8-2gm2

In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-43g2-2w55-rgfp

Multiple cross-site scripting (XSS) vulnerabilities in CMD_DOMAIN in JBMC Software DirectAdmin 1.403 allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via the (1) select0 or (2) select8 parameters.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-43fx-m629-rhfw

Microsoft Edge allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Microsoft Edge Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0158.

CVSS3: 6.5
69%
Средний
больше 4 лет назад
github логотип
GHSA-43fx-4mqw-qphw

A vulnerability was identified in OWASP DefectDojo 2.59.0. This issue affects the function UserSerializer of the file dojo/api_v2/serializers.py of the component API/Web. Such manipulation of the argument is_staff leads to improper privilege management. The attack may be performed from remote. The exploit is publicly available and might be used. Upgrading to version 2.58.3 and 3.0.0 is capable of addressing this issue. The name of the patch is 68a272f299d096249fd3ba9c2676bf69012857bf. It is advisable to upgrade the affected component. 2.59.0 was not intended to be released and has been removed.

CVSS3: 6.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-43fx-2cfr-rfxj

Cross-Site Request Forgery (CSRF) vulnerability in Simple Booking Simple Booking Widget allows Stored XSS.This issue affects Simple Booking Widget: from n/a through 1.1.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-43fw-xm94-j3mx

An issue was discovered in the Clario VPN client through 5.9.1.1662 for macOS. The VPN client insecurely configures the operating system such that traffic to the local network is sent in plaintext outside the VPN tunnel even if the local network is using a non-RFC1918 IP subnet. This allows an adversary to trick the victim into sending arbitrary IP traffic in plaintext outside the VPN tunnel. NOTE: the tunnelcrack.mathyvanhoef.com website uses this CVE ID to refer more generally to "LocalNet attack resulting in leakage of traffic in plaintext" rather than to only Clario.

CVSS3: 5.7
1%
Низкий
около 3 лет назад
github логотип
GHSA-43fw-h62p-gjw8

Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents.

CVSS3: 8.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-43fw-536j-w37j

Yamcs API Directory Traversal vulnerability

CVSS3: 9.1
2%
Низкий
почти 3 года назад
github логотип
GHSA-43fw-27v6-42x2

In ImageMagick 7.0.8-35 Q16, there is a stack-based buffer overflow in the function PopHexPixel of coders/ps.c, which allows an attacker to cause a denial of service or code execution via a crafted image file.

CVSS3: 8.8
6%
Низкий
больше 4 лет назад
github логотип
GHSA-43fv-wgqf-rwjq

An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote authenticated users with administrator privileges to execute arbitrary commands by uploading a crafted ZIP archive containing a server-executable file.

1%
Низкий
около 1 месяца назад
github логотип
GHSA-43fv-rqxp-47v5

Multiple SQL injection vulnerabilities in MH Products Projekt Shop allow remote attackers to execute arbitrary SQL commands via the (1) ts parameter to details.php and possibly the (2) ilceler parameter to index.php.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу