Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 366 653

Количество 366 653

github логотип

GHSA-4323-cfj5-98mh

больше 4 лет назад

Dolibarr ERP and CRM contain XSS Vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-4322-j82q-j25q

больше 2 лет назад

D-Link DAP-2622 DDP User Verification Auth Username Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the DDP service. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-20052.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4322-9574-7cv6

около 3 лет назад

In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an authenticated remote attacker with admin privileges could upload a crafted XML file which causes a denial-of-service.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-42xx-v9rj-x9mp

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the newpassword2 parameter.

EPSS: Низкий
github логотип

GHSA-42xx-38jq-4844

больше 2 лет назад

Kofax Power PDF PCX File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PCX files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-20389.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-42xw-p62x-hwcf

больше 4 лет назад

Improper Access Control in Apache Derby

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-42xw-2xvc-qx8m

больше 7 лет назад

Denial of Service in axios

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-42xw-2v8p-rrf7

больше 4 лет назад

An issue was discovered in Open XDMoD through 7.5.0. An authentication bypass (account takeover) exists due to a weak password reset mechanism. A brute-force attack against an MD5 rid value requires only 600 guesses in the plausible situation where the attacker knows that the victim has started a password-reset process (pass_reset.php, password_reset.php, XDUser.php) in the past few minutes.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-42xv-889g-w333

почти 2 года назад

In m3326_gps_write and m3326_gps_read of gps.s, there is a possible Out Of Bounds Read due to a missing bounds check. This could lead to a local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-42xr-w96f-53vq

больше 4 лет назад

Information disclosure of .esp source code on the Cohu 3960 allows an attacker to view sensitive information such as application logic with a simple web browser.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-42xr-jggh-w47m

больше 4 лет назад

Cisco Wireless LAN Controller (WLC) devices 7.2 before 7.2.115.2, 7.3, and 7.4 before 7.4.110.0 allow remote attackers to cause a denial of service (device restart) via a crafted 802.11 Ethernet frame, aka Bug ID CSCue87929.

EPSS: Низкий
github логотип

GHSA-42xr-fff6-m3hh

больше 4 лет назад

The nsHtml5TreeBuilder::resetTheInsertionMode function in the HTML5 Tree Builder in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 does not properly maintain the state of the insertion-mode stack for template elements, which allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer over-read) by triggering use of this stack in its empty state.

EPSS: Низкий
github логотип

GHSA-42xr-8p7f-gqh6

15 дней назад

Joomla Extension - yootheme.com - Authenticated, privileged arbitrary file read in YOOtheme Pro 2.3.0-5.0.40 - The Filesystem source's path filter is vulnerable to glob-based pattern attacks, allowing authorized users to read arbitrary files.

EPSS: Низкий
github логотип

GHSA-42xr-3hw9-x5g4

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management Reference Data Management (RDM) Hub 10.1 and 11.0 before 11.0.0.0-MDM-IF008 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

EPSS: Низкий
github логотип

GHSA-42xq-j3ww-cxh9

больше 4 лет назад

On BIG-IP ASM & Advanced WAF version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x and 12.1.x, an authenticated user with low privileges, such as a guest, can upload data using an undisclosed REST endpoint causing an increase in disk resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

EPSS: Низкий
github логотип

GHSA-42xq-c5pj-29x5

больше 4 лет назад

OpenText Documentum D2 (formerly EMC Documentum D2) 4.x allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the BeanShell (bsh) and Apache Commons Collections (ACC) libraries.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-42xq-25q2-4fv9

больше 2 лет назад

An issue in the component segwindrvx64.sys of Insyde Software Corp SEG Windows Driver v100.00.07.02 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-42xp-w6p2-r2j3

больше 4 лет назад

Untrusted search path vulnerability in McAfee VirusScan for Linux 4510e and earlier includes the current working directory in the DT_RPATH environment variable, which allows local users to load arbitrary ELF DSO libraries and execute arbitrary code by installing malicious libraries in that directory.

EPSS: Низкий
github логотип

GHSA-42xp-gpw5-93cm

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php in MOStlyCE before 2.4, as used in Mambo 4.6.3 and earlier, allows remote attackers to inject arbitrary web script or HTML via the Command parameter.

EPSS: Низкий
github логотип

GHSA-42xp-cpcp-hvvm

больше 4 лет назад

Double free vulnerability in epan/proto.c in the dissection engine in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 allows remote attackers to cause a denial of service (application crash) via a malformed packet.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4323-cfj5-98mh

Dolibarr ERP and CRM contain XSS Vulnerability

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4322-j82q-j25q

D-Link DAP-2622 DDP User Verification Auth Username Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the DDP service. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-20052.

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-4322-9574-7cv6

In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an authenticated remote attacker with admin privileges could upload a crafted XML file which causes a denial-of-service.

CVSS3: 4.9
1%
Низкий
около 3 лет назад
github логотип
GHSA-42xx-v9rj-x9mp

Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the newpassword2 parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-42xx-38jq-4844

Kofax Power PDF PCX File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PCX files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-20389.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-42xw-p62x-hwcf

Improper Access Control in Apache Derby

CVSS3: 5.3
5%
Низкий
больше 4 лет назад
github логотип
GHSA-42xw-2xvc-qx8m

Denial of Service in axios

CVSS3: 7.5
6%
Низкий
больше 7 лет назад
github логотип
GHSA-42xw-2v8p-rrf7

An issue was discovered in Open XDMoD through 7.5.0. An authentication bypass (account takeover) exists due to a weak password reset mechanism. A brute-force attack against an MD5 rid value requires only 600 guesses in the plausible situation where the attacker knows that the victim has started a password-reset process (pass_reset.php, password_reset.php, XDUser.php) in the past few minutes.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-42xv-889g-w333

In m3326_gps_write and m3326_gps_read of gps.s, there is a possible Out Of Bounds Read due to a missing bounds check. This could lead to a local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-42xr-w96f-53vq

Information disclosure of .esp source code on the Cohu 3960 allows an attacker to view sensitive information such as application logic with a simple web browser.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-42xr-jggh-w47m

Cisco Wireless LAN Controller (WLC) devices 7.2 before 7.2.115.2, 7.3, and 7.4 before 7.4.110.0 allow remote attackers to cause a denial of service (device restart) via a crafted 802.11 Ethernet frame, aka Bug ID CSCue87929.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-42xr-fff6-m3hh

The nsHtml5TreeBuilder::resetTheInsertionMode function in the HTML5 Tree Builder in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 does not properly maintain the state of the insertion-mode stack for template elements, which allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer over-read) by triggering use of this stack in its empty state.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-42xr-8p7f-gqh6

Joomla Extension - yootheme.com - Authenticated, privileged arbitrary file read in YOOtheme Pro 2.3.0-5.0.40 - The Filesystem source's path filter is vulnerable to glob-based pattern attacks, allowing authorized users to read arbitrary files.

0%
Низкий
15 дней назад
github логотип
GHSA-42xr-3hw9-x5g4

Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management Reference Data Management (RDM) Hub 10.1 and 11.0 before 11.0.0.0-MDM-IF008 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-42xq-j3ww-cxh9

On BIG-IP ASM & Advanced WAF version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x and 12.1.x, an authenticated user with low privileges, such as a guest, can upload data using an undisclosed REST endpoint causing an increase in disk resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-42xq-c5pj-29x5

OpenText Documentum D2 (formerly EMC Documentum D2) 4.x allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the BeanShell (bsh) and Apache Commons Collections (ACC) libraries.

CVSS3: 9.8
25%
Средний
больше 4 лет назад
github логотип
GHSA-42xq-25q2-4fv9

An issue in the component segwindrvx64.sys of Insyde Software Corp SEG Windows Driver v100.00.07.02 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.

CVSS3: 8.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-42xp-w6p2-r2j3

Untrusted search path vulnerability in McAfee VirusScan for Linux 4510e and earlier includes the current working directory in the DT_RPATH environment variable, which allows local users to load arbitrary ELF DSO libraries and execute arbitrary code by installing malicious libraries in that directory.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-42xp-gpw5-93cm

Cross-site scripting (XSS) vulnerability in mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php in MOStlyCE before 2.4, as used in Mambo 4.6.3 and earlier, allows remote attackers to inject arbitrary web script or HTML via the Command parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-42xp-cpcp-hvvm

Double free vulnerability in epan/proto.c in the dissection engine in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 allows remote attackers to cause a denial of service (application crash) via a malformed packet.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу