Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 366 653

Количество 366 653

github логотип

GHSA-4363-m599-g24f

больше 4 лет назад

An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0704, CVE-2019-0821.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-4363-fqg7-xrx3

3 месяца назад

Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-4363-7gmx-qcmr

больше 4 лет назад

An issue was discovered in Tiny Issue 1.3.1 and pixeline Bugs through 1.3.2c. install/config-setup.php allows remote attackers to execute arbitrary PHP code via the database_host parameter if the installer remains present in its original directory after installation is completed.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4362-x25f-c5ch

7 месяцев назад

Tanium addressed an unauthorized code execution vulnerability in Tanium Appliance.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4362-m95h-qf9r

больше 2 лет назад

Adobe Aero Desktop versions 23.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4362-8cgf-69g7

больше 4 лет назад

Privilege Escalation vulnerability in McAfee Total Protection (MTP) before 16.0.R26 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file. This is achieved through running a malicious script or program on the target machine.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-435x-xc34-27p6

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in mod.php in eNdonesia 8.3 allow remote attackers to inject arbitrary web script or HTML via (1) the mod parameter in a viewcat operation or (2) the query parameter in a search operation in the publisher module.

EPSS: Низкий
github логотип

GHSA-435x-7wvp-mx4w

больше 4 лет назад

A broken access control vulnerability in SmartHome app (Android versions up to 3.0.42_190515, ios versions up to 2.0.22) allows an attacker in the same local area network to list user accounts and control IoT devices that connect with its gateway (HG100) via http://[target]/smarthome/devicecontrol without any authentication.

EPSS: Низкий
github логотип

GHSA-435v-q3pr-69h4

больше 1 года назад

A vulnerability in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to elevate privileges to Administrator for a limited set of functions on an affected system. This vulnerability is due to insufficient server-side validation of user-supplied parameters in API or HTTP requests. An attacker could exploit this vulnerability by submitting a crafted API or HTTP request to an affected system. A successful exploit could allow the attacker to access, modify, or delete data beyond the sphere of their intended access level, including obtaining potentially sensitive information stored in the system.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-435v-f8gv-q7r4

11 месяцев назад

An improper authentication vulnerability has been reported to affect QNAP Authenticator. If an attacker gains physical access, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: QNAP Authenticator 1.3.1.1227 and later

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-435q-93x7-pxxj

почти 3 года назад

A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific circumstances which could allow unauthorized access.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-435q-8pxf-fr67

больше 4 лет назад

The irccd.exe service in EMC Replication Manager Client before 5.3 and NetWorker Module for Microsoft Applications 2.1.x and 2.2.x allows remote attackers to execute arbitrary commands via the RunProgram function to TCP port 6542.

EPSS: Средний
github логотип

GHSA-435q-7mpf-fcmp

больше 4 лет назад

Microsoft Internet Explorer 7 sometimes attempts to access a deleted object, which allows remote attackers to execute arbitrary code via a crafted HTML document that triggers memory corruption, aka "Uninitialized Memory Corruption Vulnerability."

EPSS: Средний
github логотип

GHSA-435p-pf44-5x2x

больше 4 лет назад

An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) software. An attacker can bypass the password requirement for tablet user switching by folding the magnetic cover. The Samsung ID is SVE-2017-10602 (December 2017).

EPSS: Низкий
github логотип

GHSA-435p-f82x-mxwm

около 5 лет назад

Command injection in Yamale

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-435p-f446-gxf4

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix a deadlock problem when config TC during resetting When config TC during the reset process, may cause a deadlock, the flow is as below: pf reset start │ ▼ ...... setup tc │ │ ▼ ▼ DOWN: napi_disable() napi_disable()(skip) │ │ │ ▼ ▼ ...... ...... │ │ ▼ │ napi_enable() │ ▼ UINIT: netif_napi_del() │ ▼ ...... ...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-435p-4r6f-2842

больше 4 лет назад

A stack-buffer-overflow was found in QEMU in the NVME component. The flaw lies in nvme_changed_nslist() where a malicious guest controlling certain input can read out of bounds memory. A malicious user could use this flaw leading to disclosure of sensitive information.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-435m-r226-x7g6

больше 4 лет назад

Unspecified vulnerability in Oracle Agent in Oracle Enterprise Manager 9.0.4.1 up to 10.1.0.4 has unknown impact and attack vectors, as identified by Oracle Vuln# EM01.

EPSS: Низкий
github логотип

GHSA-435m-534h-fq69

почти 4 года назад

Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter enable_band_steering.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-435j-x75q-84gh

больше 4 лет назад

The Liver Health - Hepatitis C (aka gov.nyc.dohmh.HepC) application 2.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4363-m599-g24f

An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0704, CVE-2019-0821.

CVSS3: 6.5
10%
Низкий
больше 4 лет назад
github логотип
GHSA-4363-fqg7-xrx3

Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally.

CVSS3: 7.1
0%
Низкий
3 месяца назад
github логотип
GHSA-4363-7gmx-qcmr

An issue was discovered in Tiny Issue 1.3.1 and pixeline Bugs through 1.3.2c. install/config-setup.php allows remote attackers to execute arbitrary PHP code via the database_host parameter if the installer remains present in its original directory after installation is completed.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-4362-x25f-c5ch

Tanium addressed an unauthorized code execution vulnerability in Tanium Appliance.

CVSS3: 7.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-4362-m95h-qf9r

Adobe Aero Desktop versions 23.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4362-8cgf-69g7

Privilege Escalation vulnerability in McAfee Total Protection (MTP) before 16.0.R26 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file. This is achieved through running a malicious script or program on the target machine.

CVSS3: 6.3
0%
Низкий
больше 4 лет назад
github логотип
GHSA-435x-xc34-27p6

Multiple cross-site scripting (XSS) vulnerabilities in mod.php in eNdonesia 8.3 allow remote attackers to inject arbitrary web script or HTML via (1) the mod parameter in a viewcat operation or (2) the query parameter in a search operation in the publisher module.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-435x-7wvp-mx4w

A broken access control vulnerability in SmartHome app (Android versions up to 3.0.42_190515, ios versions up to 2.0.22) allows an attacker in the same local area network to list user accounts and control IoT devices that connect with its gateway (HG100) via http://[target]/smarthome/devicecontrol without any authentication.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-435v-q3pr-69h4

A vulnerability in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to elevate privileges to Administrator for a limited set of functions on an affected system. This vulnerability is due to insufficient server-side validation of user-supplied parameters in API or HTTP requests. An attacker could exploit this vulnerability by submitting a crafted API or HTTP request to an affected system. A successful exploit could allow the attacker to access, modify, or delete data beyond the sphere of their intended access level, including obtaining potentially sensitive information stored in the system.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-435v-f8gv-q7r4

An improper authentication vulnerability has been reported to affect QNAP Authenticator. If an attacker gains physical access, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: QNAP Authenticator 1.3.1.1227 and later

CVSS3: 6.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-435q-93x7-pxxj

A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific circumstances which could allow unauthorized access.

CVSS3: 6.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-435q-8pxf-fr67

The irccd.exe service in EMC Replication Manager Client before 5.3 and NetWorker Module for Microsoft Applications 2.1.x and 2.2.x allows remote attackers to execute arbitrary commands via the RunProgram function to TCP port 6542.

64%
Средний
больше 4 лет назад
github логотип
GHSA-435q-7mpf-fcmp

Microsoft Internet Explorer 7 sometimes attempts to access a deleted object, which allows remote attackers to execute arbitrary code via a crafted HTML document that triggers memory corruption, aka "Uninitialized Memory Corruption Vulnerability."

19%
Средний
больше 4 лет назад
github логотип
GHSA-435p-pf44-5x2x

An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) software. An attacker can bypass the password requirement for tablet user switching by folding the magnetic cover. The Samsung ID is SVE-2017-10602 (December 2017).

0%
Низкий
больше 4 лет назад
github логотип
GHSA-435p-f82x-mxwm

Command injection in Yamale

CVSS3: 7.8
2%
Низкий
около 5 лет назад
github логотип
GHSA-435p-f446-gxf4

In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix a deadlock problem when config TC during resetting When config TC during the reset process, may cause a deadlock, the flow is as below: pf reset start │ ▼ ...... setup tc │ │ ▼ ▼ DOWN: napi_disable() napi_disable()(skip) │ │ │ ▼ ▼ ...... ...... │ │ ▼ │ napi_enable() │ ▼ UINIT: netif_napi_del() │ ▼ ...... ...

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-435p-4r6f-2842

A stack-buffer-overflow was found in QEMU in the NVME component. The flaw lies in nvme_changed_nslist() where a malicious guest controlling certain input can read out of bounds memory. A malicious user could use this flaw leading to disclosure of sensitive information.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-435m-r226-x7g6

Unspecified vulnerability in Oracle Agent in Oracle Enterprise Manager 9.0.4.1 up to 10.1.0.4 has unknown impact and attack vectors, as identified by Oracle Vuln# EM01.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-435m-534h-fq69

Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter enable_band_steering.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-435j-x75q-84gh

The Liver Health - Hepatitis C (aka gov.nyc.dohmh.HepC) application 2.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад

Уязвимостей на страницу