Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 366 653

Количество 366 653

github логотип

GHSA-432r-553m-gq3p

больше 4 лет назад

Multiple buffer overflows in (1) internal/XMLReader.cpp, (2) util/XMLURL.cpp, and (3) util/XMLUri.cpp in the XML Parser library in Apache Xerces-C before 3.1.3 allow remote attackers to cause a denial of service (segmentation fault or memory corruption) or possibly execute arbitrary code via a crafted document.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-432q-7x98-83cg

больше 4 лет назад

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-432q-3g9r-5rr6

больше 4 лет назад

Multiple buffer overflows in WS_FTP Server 5.03 2004.10.14 allow remote attackers to cause a denial of service (service crash) via long (1) SITE, (2) XMKD, (3) MKD, and (4) RNFR commands.

EPSS: Средний
github логотип

GHSA-432p-g7rx-g388

больше 4 лет назад

In Apache Fineract 0.4.0-incubating, 0.5.0-incubating, and 0.6.0-incubating, an authenticated user with client/loan/center/staff/group read permissions is able to inject malicious SQL into SELECT queries. The 'sqlSearch' parameter on a number of endpoints is not sanitized and appended directly to the query.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-432m-fhgv-3568

больше 4 лет назад

PHP remote file inclusion vulnerability in pda_projects.php in WebDynamite ProjectButler 1.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the offset parameter.

EPSS: Низкий
github логотип

GHSA-432m-34f7-gx5j

больше 4 лет назад

There is a Credentials Management Errors Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect service confidentiality.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-432m-25cj-wjgv

около 4 лет назад

Use After Free in GitHub repository vim/vim prior to 9.0.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-432j-m9p2-95fc

больше 4 лет назад

Google Chrome before 15.0.874.102 does not properly handle history data, which allows user-assisted remote attackers to spoof the URL bar via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-432j-87hp-h33w

почти 2 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Woopy Plugins SmartLink Dynamic URLs allows Stored XSS.This issue affects SmartLink Dynamic URLs: from n/a through 1.1.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-432j-4fw9-2g6f

больше 7 лет назад

libsbml downloads Resources over HTTP

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-432h-j3jm-6982

9 месяцев назад

A Reflected Cross-Site Scripting (XSS) vulnerability in yohanawi Hotel Management System (commit 87e004a) allows a remote attacker to execute arbitrary web script via the 'error' parameter in pages/room.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-432h-4h4q-x6r2

25 дней назад

Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-432h-4cw6-prpw

больше 4 лет назад

In ng_pkt in transports/smart_pkt.c in libgit2 before 0.26.6 and 0.27.x before 0.27.4, a remote attacker can send a crafted smart-protocol "ng" packet that lacks a '\0' byte to trigger an out-of-bounds read that leads to DoS.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-432h-375x-96r4

больше 4 лет назад

admin/forums.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to bypass authentication and gain administrative access via a large value of the current_user[users_level] parameter.

EPSS: Низкий
github логотип

GHSA-432g-39xc-whrc

больше 4 лет назад

Unquoted service executable path in DXL Broker in McAfee Data eXchange Layer (DXL) Framework 6.0.0 and earlier allows local users to cause a denial of service and malicious file execution via carefully crafted and named executable files.

EPSS: Низкий
github логотип

GHSA-432f-m59q-xvcj

больше 1 года назад

Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security). Supported versions that are affected are Prior to 9.2.9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Orchestrator. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Orchestrator accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-432f-98h9-v2fw

больше 4 лет назад

Pulse Secure Client 9.0R1 and 5.3RX before 5.3R5, when configured to authenticate VPN users during Windows Logon, can allow attackers to bypass Windows authentication and execute commands on the system with the privileges of Pulse Secure Client. The attacker must interrupt the client's network connectivity, and trigger a connection to a crafted proxy server with an invalid SSL certificate that allows certification-manager access, leading to the ability to browse local files and execute local programs.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-432f-967f-vxg4

почти 3 года назад

Evolution CMS Cross-site Scripting vulnerability

CVSS3: 5.2
EPSS: Низкий
github логотип

GHSA-432c-wxpg-m4q3

больше 1 года назад

xml2rfc has file inclusion irregularities

EPSS: Низкий
github логотип

GHSA-432c-r3mr-pxjf

больше 1 года назад

The Particle Background plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'particleground' shortcode in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-432r-553m-gq3p

Multiple buffer overflows in (1) internal/XMLReader.cpp, (2) util/XMLURL.cpp, and (3) util/XMLUri.cpp in the XML Parser library in Apache Xerces-C before 3.1.3 allow remote attackers to cause a denial of service (segmentation fault or memory corruption) or possibly execute arbitrary code via a crafted document.

CVSS3: 9.8
9%
Низкий
больше 4 лет назад
github логотип
GHSA-432q-7x98-83cg

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 7.2
1%
Низкий
больше 4 лет назад
github логотип
GHSA-432q-3g9r-5rr6

Multiple buffer overflows in WS_FTP Server 5.03 2004.10.14 allow remote attackers to cause a denial of service (service crash) via long (1) SITE, (2) XMKD, (3) MKD, and (4) RNFR commands.

50%
Средний
больше 4 лет назад
github логотип
GHSA-432p-g7rx-g388

In Apache Fineract 0.4.0-incubating, 0.5.0-incubating, and 0.6.0-incubating, an authenticated user with client/loan/center/staff/group read permissions is able to inject malicious SQL into SELECT queries. The 'sqlSearch' parameter on a number of endpoints is not sanitized and appended directly to the query.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-432m-fhgv-3568

PHP remote file inclusion vulnerability in pda_projects.php in WebDynamite ProjectButler 1.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the offset parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-432m-34f7-gx5j

There is a Credentials Management Errors Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect service confidentiality.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-432m-25cj-wjgv

Use After Free in GitHub repository vim/vim prior to 9.0.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-432j-m9p2-95fc

Google Chrome before 15.0.874.102 does not properly handle history data, which allows user-assisted remote attackers to spoof the URL bar via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-432j-87hp-h33w

Cross-Site Request Forgery (CSRF) vulnerability in Woopy Plugins SmartLink Dynamic URLs allows Stored XSS.This issue affects SmartLink Dynamic URLs: from n/a through 1.1.0.

CVSS3: 7.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-432j-4fw9-2g6f

libsbml downloads Resources over HTTP

CVSS3: 8.1
2%
Низкий
больше 7 лет назад
github логотип
GHSA-432h-j3jm-6982

A Reflected Cross-Site Scripting (XSS) vulnerability in yohanawi Hotel Management System (commit 87e004a) allows a remote attacker to execute arbitrary web script via the 'error' parameter in pages/room.php.

CVSS3: 6.1
0%
Низкий
9 месяцев назад
github логотип
GHSA-432h-4h4q-x6r2

Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.

CVSS3: 8.8
1%
Низкий
25 дней назад
github логотип
GHSA-432h-4cw6-prpw

In ng_pkt in transports/smart_pkt.c in libgit2 before 0.26.6 and 0.27.x before 0.27.4, a remote attacker can send a crafted smart-protocol "ng" packet that lacks a '\0' byte to trigger an out-of-bounds read that leads to DoS.

CVSS3: 7.5
4%
Низкий
больше 4 лет назад
github логотип
GHSA-432h-375x-96r4

admin/forums.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to bypass authentication and gain administrative access via a large value of the current_user[users_level] parameter.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-432g-39xc-whrc

Unquoted service executable path in DXL Broker in McAfee Data eXchange Layer (DXL) Framework 6.0.0 and earlier allows local users to cause a denial of service and malicious file execution via carefully crafted and named executable files.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-432f-m59q-xvcj

Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security). Supported versions that are affected are Prior to 9.2.9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Orchestrator. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Orchestrator accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-432f-98h9-v2fw

Pulse Secure Client 9.0R1 and 5.3RX before 5.3R5, when configured to authenticate VPN users during Windows Logon, can allow attackers to bypass Windows authentication and execute commands on the system with the privileges of Pulse Secure Client. The attacker must interrupt the client's network connectivity, and trigger a connection to a crafted proxy server with an invalid SSL certificate that allows certification-manager access, leading to the ability to browse local files and execute local programs.

CVSS3: 6.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-432f-967f-vxg4

Evolution CMS Cross-site Scripting vulnerability

CVSS3: 5.2
0%
Низкий
почти 3 года назад
github логотип
GHSA-432c-wxpg-m4q3

xml2rfc has file inclusion irregularities

больше 1 года назад
github логотип
GHSA-432c-r3mr-pxjf

The Particle Background plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'particleground' shortcode in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 1 года назад

Уязвимостей на страницу