Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 365 324

Количество 365 324

github логотип

GHSA-3wp4-f8xr-849x

3 месяца назад

A format string argument mismatch in Netatalk 3.0.3 through 4.4.2 allows a remote authenticated attacker to cause a minor denial of service via crafted input that triggers incorrect format string processing.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-3wp4-6pwm-vcxj

больше 4 лет назад

Buffer overflow in the polymorphic opcode support in the Regular Expression Engine (regcomp.c) in Perl 5.8 allows context-dependent attackers to execute arbitrary code by switching from byte to Unicode (UTF) characters in a regular expression.

EPSS: Низкий
github логотип

GHSA-3wp3-xxj9-5jqq

около 1 месяца назад

Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-3wp3-9r5c-77fc

больше 4 лет назад

IBM Maximo Asset Management 7.6.1.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 170961.

EPSS: Низкий
github логотип

GHSA-3wp3-9f4h-fqwh

больше 4 лет назад

IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.2 and IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the Admin Console to become unresponsive. IBM X-Force ID: 220485.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3wp2-xjg2-vxf4

23 дня назад

In the Linux kernel, the following vulnerability has been resolved: ASoC: tas2781: bound firmware description string parsing The TAS2781 firmware parser reads several variable-length description strings with strlen() before checking that the string terminator is present inside the firmware blob. A malformed firmware image without a NUL terminator can therefore make the parser walk past the end of the firmware buffer before the later size checks run. Add a small bounded string-length helper and use it for all description fields that are parsed from the firmware buffer. Keep the existing size checks for the fixed bytes that follow each string.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3wp2-2c4h-hf64

27 дней назад

Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3wmx-fc2q-p8g5

больше 4 лет назад

A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition when the device unexpectedly reloads. The vulnerability is due to improper input validation of certain type, length, value (TLV) fields of the LLDP frame header. An attacker could exploit this vulnerability by sending a crafted LLDP packet to an interface on the targeted device. A successful exploit could allow the attacker to cause the switch to reload unexpectedly.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3wmx-9qwp-h363

почти 3 года назад

Duplicate Advisory: EVE Doesn't Protect Config Partition with Measured Boot

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3wmx-48g3-x66g

около 2 лет назад

Backdrop CMS does not sufficiently sanitize field labels before they are displayed in certain places

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3wmw-g879-9gp5

больше 4 лет назад

SQL injection vulnerability in escribir.php in Foro Domus 2.10 allows remote attackers to execute arbitrary SQL commands via the email parameter. NOTE: the provenance of this information is unknown, although it may be based on post-disclosure analysis of CVE-2006-0110; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-3wmv-phhj-q327

около 4 лет назад

A CWE-787: Out-of-bounds Write vulnerability exists that could cause a denial of service of the webserver due to improper parsing of the HTTP Headers. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V1.0), OPC UA Modicon Communication Module (BMENUA0100) (V1.10 and prior)

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3wmv-7php-rhg5

больше 4 лет назад

Jenkins Vulnerable to Cross-Site Request Forgery (CSRF) Attack

EPSS: Низкий
github логотип

GHSA-3wmv-527f-7jxv

больше 4 лет назад

An exploitable use of an uninitialized pointer vulnerability exists in the JavaScript engine in Foxit PDF Reader version 9.0.1.1049. A specially crafted PDF document can lead to a dereference of an uninitialized pointer which, if under attacker control, can result in arbitrary code execution. An attacker needs to trick the user to open a malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3wmq-h2jq-wfgw

больше 4 лет назад

The SupportCandy WordPress plugin before 2.2.7 does not have CSRF check in the wpsc_tickets AJAX action, nor has any sanitisation or escaping in some of the filter fields which could allow attackers to make a logged in user having access to the ticket lists dashboard set an arbitrary filter (stored in their cookies) with an XSS payload in it.

EPSS: Низкий
github логотип

GHSA-3wmq-8jfx-8qrm

больше 4 лет назад

The get_results() and get_items() functions in the Survey Maker WordPress plugin before 1.5.6 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard

EPSS: Низкий
github логотип

GHSA-3wmp-g7x5-v6hv

больше 3 лет назад

In all versions, BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 8.8
EPSS: Критический
github логотип

GHSA-3wmp-c58m-j32f

больше 4 лет назад

OTRS 3.1.x before 3.1.21, 3.2.x before 3.2.16, and 3.3.x before 3.3.6 allows remote attackers to conduct clickjacking attacks via an IFRAME element.

EPSS: Низкий
github логотип

GHSA-3wmm-v973-qmxx

больше 4 лет назад

Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows local users to obtain root access by modifying a batch file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3wmm-94p8-9h9p

больше 4 лет назад

Unspecified vulnerability in the server in Firebird before 2.0.2 allows remote attackers to cause a denial of service (daemon crash) via an XNET session that makes multiple simultaneous requests to register events, aka CORE-1403.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3wp4-f8xr-849x

A format string argument mismatch in Netatalk 3.0.3 through 4.4.2 allows a remote authenticated attacker to cause a minor denial of service via crafted input that triggers incorrect format string processing.

CVSS3: 3.1
0%
Низкий
3 месяца назад
github логотип
GHSA-3wp4-6pwm-vcxj

Buffer overflow in the polymorphic opcode support in the Regular Expression Engine (regcomp.c) in Perl 5.8 allows context-dependent attackers to execute arbitrary code by switching from byte to Unicode (UTF) characters in a regular expression.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-3wp3-xxj9-5jqq

Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)

CVSS3: 3.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3wp3-9r5c-77fc

IBM Maximo Asset Management 7.6.1.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 170961.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3wp3-9f4h-fqwh

IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.2 and IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 do not limit the length of a connection which could allow for a Slowloris HTTP denial of service attack to take place. This can cause the Admin Console to become unresponsive. IBM X-Force ID: 220485.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3wp2-xjg2-vxf4

In the Linux kernel, the following vulnerability has been resolved: ASoC: tas2781: bound firmware description string parsing The TAS2781 firmware parser reads several variable-length description strings with strlen() before checking that the string terminator is present inside the firmware blob. A malformed firmware image without a NUL terminator can therefore make the parser walk past the end of the firmware buffer before the later size checks run. Add a small bounded string-length helper and use it for all description fields that are parsed from the firmware buffer. Keep the existing size checks for the fixed bytes that follow each string.

CVSS3: 7.1
0%
Низкий
23 дня назад
github логотип
GHSA-3wp2-2c4h-hf64

Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.

CVSS3: 9.8
0%
Низкий
27 дней назад
github логотип
GHSA-3wmx-fc2q-p8g5

A vulnerability in the Link Layer Discovery Protocol (LLDP) implementation for Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition when the device unexpectedly reloads. The vulnerability is due to improper input validation of certain type, length, value (TLV) fields of the LLDP frame header. An attacker could exploit this vulnerability by sending a crafted LLDP packet to an interface on the targeted device. A successful exploit could allow the attacker to cause the switch to reload unexpectedly.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3wmx-9qwp-h363

Duplicate Advisory: EVE Doesn't Protect Config Partition with Measured Boot

CVSS3: 8.8
почти 3 года назад
github логотип
GHSA-3wmx-48g3-x66g

Backdrop CMS does not sufficiently sanitize field labels before they are displayed in certain places

CVSS3: 4.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-3wmw-g879-9gp5

SQL injection vulnerability in escribir.php in Foro Domus 2.10 allows remote attackers to execute arbitrary SQL commands via the email parameter. NOTE: the provenance of this information is unknown, although it may be based on post-disclosure analysis of CVE-2006-0110; the details are obtained solely from third party information.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3wmv-phhj-q327

A CWE-787: Out-of-bounds Write vulnerability exists that could cause a denial of service of the webserver due to improper parsing of the HTTP Headers. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V1.0), OPC UA Modicon Communication Module (BMENUA0100) (V1.10 and prior)

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-3wmv-7php-rhg5

Jenkins Vulnerable to Cross-Site Request Forgery (CSRF) Attack

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3wmv-527f-7jxv

An exploitable use of an uninitialized pointer vulnerability exists in the JavaScript engine in Foxit PDF Reader version 9.0.1.1049. A specially crafted PDF document can lead to a dereference of an uninitialized pointer which, if under attacker control, can result in arbitrary code execution. An attacker needs to trick the user to open a malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

CVSS3: 8.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-3wmq-h2jq-wfgw

The SupportCandy WordPress plugin before 2.2.7 does not have CSRF check in the wpsc_tickets AJAX action, nor has any sanitisation or escaping in some of the filter fields which could allow attackers to make a logged in user having access to the ticket lists dashboard set an arbitrary filter (stored in their cookies) with an XSS payload in it.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3wmq-8jfx-8qrm

The get_results() and get_items() functions in the Survey Maker WordPress plugin before 1.5.6 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3wmp-g7x5-v6hv

In all versions, BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 8.8
92%
Критический
больше 3 лет назад
github логотип
GHSA-3wmp-c58m-j32f

OTRS 3.1.x before 3.1.21, 3.2.x before 3.2.16, and 3.3.x before 3.3.6 allows remote attackers to conduct clickjacking attacks via an IFRAME element.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3wmm-v973-qmxx

Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows local users to obtain root access by modifying a batch file.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3wmm-94p8-9h9p

Unspecified vulnerability in the server in Firebird before 2.0.2 allows remote attackers to cause a denial of service (daemon crash) via an XNET session that makes multiple simultaneous requests to register events, aka CORE-1403.

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу