Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 365 324

Количество 365 324

github логотип

GHSA-3whx-4rww-hfm4

больше 4 лет назад

The Instachat -Instagram Messenger (aka com.instachat.android) application 1.6.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-3whw-wqrp-r5hq

почти 2 года назад

The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to blind SQL Injection via the 'order' parameter in all versions up to, and including, 7.7.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3whw-hf82-whpw

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in sNews 1.3 allows remote attackers to inject arbitrary web script or HTML via the comment field.

EPSS: Низкий
github логотип

GHSA-3whw-f76p-rq86

больше 4 лет назад

The File Repository Server (FRS) CORBA listener in SAP BussinessObjects Edge 4.0 allows remote attackers to write to arbitrary files via a full pathname, aka SAP Note 2018681.

EPSS: Низкий
github логотип

GHSA-3whv-8qg8-4ffw

7 месяцев назад

Authentication Bypass by Primary Weakness vulnerability in Jamf Jamf Pro allows unspecified impact.This issue affects Jamf Pro: from 11.20 through 11.24.

EPSS: Низкий
github логотип

GHSA-3whv-7544-3cv4

больше 3 лет назад

SQL injection vulnerability in mccms 2.6 allows remote attackers to run arbitrary SQL commands via Author Center ->Reader Comments ->Search.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3whv-622v-7cx9

больше 4 лет назад

Unspecified vulnerability in the Service Tag Registry on Sun Solaris 10, and Sun Service Tag before 1.1.3, allows local users to cause a denial of service (disk consumption) via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3whv-3wrh-jjqq

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: scsi: iscsi: Fix conn use after free during resets If we haven't done a unbind target call we can race where iscsi_conn_teardown wakes up the EH thread and then frees the conn while those threads are still accessing the conn ehwait. We can only do one TMF per session so this just moves the TMF fields from the conn to the session. We can then rely on the iscsi_session_teardown->iscsi_remove_session->__iscsi_unbind_session call to remove the target and it's devices, and know after that point there is no device or scsi-ml callout trying to access the session.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3whr-wp9q-7v74

6 месяцев назад

code-projects Simple Gym Management System v1.0 is vulnerable to SQL Injection in /gym/trainer_search.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3whr-qgm8-hgrg

больше 4 лет назад

webmail/modules/filesystem/edit.php in U-Mail Webmail server 4.91 allows remote attackers to overwrite arbitrary files via an absolute pathname in the path parameter and arbitrary content in the content parameter. NOTE: this can be leveraged for code execution by writing to a file under the web document root.

EPSS: Низкий
github логотип

GHSA-3whr-c946-j943

больше 4 лет назад

Stack-based buffer overflow in lzh.fmt in WinRAR 3.00 through 3.60 beta 6 allows remote attackers to execute arbitrary code via a long filename in a LHA archive.

EPSS: Низкий
github логотип

GHSA-3whq-vc2m-hq82

больше 4 лет назад

Directory traversal vulnerability in the IMAP service (meimaps.exe) of MailEnable Professional 1.6 and earlier and Enterprise 1.1 and earlier allows remote attackers to create or rename arbitrary mail directories via the mailbox name argument of the (1) create or (2) rename commands.

EPSS: Низкий
github логотип

GHSA-3whq-m5gj-947w

больше 4 лет назад

A vulnerability was found when an attacker, while communicating with the ClearPass management interface, is able to intercept and change parameters in the HTTP packets resulting in the compromise of some of ClearPass' service accounts. Resolution: Fixed in 6.7.10, 6.8.1, 6.9.0 and higher.

EPSS: Низкий
github логотип

GHSA-3whq-64q2-qfj6

больше 2 лет назад

vyper performs double eval of raw_args in create_from_blueprint

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3whp-4f2f-273p

6 месяцев назад

A flaw has been found in Tenda i3 1.0.0.6(2204). This impacts the function formSetCfm of the file /goform/setcfm. This manipulation of the argument funcpara1 causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3whp-4394-49gc

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: tools/power turbostat: Fix offset overflow issue in index converting The idx_to_offset() function returns type int (32-bit signed), but MSR_PKG_ENERGY_STAT is u32 and would be interpreted as a negative number. The end result is that it hits the if (offset < 0) check in update_msr_sum() which prevents the timer callback from updating the stat in the background when long durations are used. The similar issue exists in offset_to_idx() and update_msr_sum(). Fix this issue by converting the 'int' to 'off_t' accordingly.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3whm-j4xm-rv8x

больше 1 года назад

Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Due to the way this function is used, we do not believe this leakage is enough to allow recovery of the private key when P-256 is used in any well known protocols.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-3whj-7m92-7898

больше 4 лет назад

SQL injection vulnerability in artreplydelete.asp in ASP EDGE 1.3a and earlier allows remote attackers to execute arbitrary SQL commands via a username cookie, a different vector than CVE-2007-0560.

EPSS: Низкий
github логотип

GHSA-3whf-vgf2-9w6g

около 1 месяца назад

zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit

EPSS: Низкий
github логотип

GHSA-3whc-qvhv-xqjp

2 месяца назад

goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3whx-4rww-hfm4

The Instachat -Instagram Messenger (aka com.instachat.android) application 1.6.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3whw-wqrp-r5hq

The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to blind SQL Injection via the 'order' parameter in all versions up to, and including, 7.7.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 7.2
1%
Низкий
почти 2 года назад
github логотип
GHSA-3whw-hf82-whpw

Cross-site scripting (XSS) vulnerability in sNews 1.3 allows remote attackers to inject arbitrary web script or HTML via the comment field.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3whw-f76p-rq86

The File Repository Server (FRS) CORBA listener in SAP BussinessObjects Edge 4.0 allows remote attackers to write to arbitrary files via a full pathname, aka SAP Note 2018681.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3whv-8qg8-4ffw

Authentication Bypass by Primary Weakness vulnerability in Jamf Jamf Pro allows unspecified impact.This issue affects Jamf Pro: from 11.20 through 11.24.

0%
Низкий
7 месяцев назад
github логотип
GHSA-3whv-7544-3cv4

SQL injection vulnerability in mccms 2.6 allows remote attackers to run arbitrary SQL commands via Author Center ->Reader Comments ->Search.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3whv-622v-7cx9

Unspecified vulnerability in the Service Tag Registry on Sun Solaris 10, and Sun Service Tag before 1.1.3, allows local users to cause a denial of service (disk consumption) via unspecified vectors.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3whv-3wrh-jjqq

In the Linux kernel, the following vulnerability has been resolved: scsi: iscsi: Fix conn use after free during resets If we haven't done a unbind target call we can race where iscsi_conn_teardown wakes up the EH thread and then frees the conn while those threads are still accessing the conn ehwait. We can only do one TMF per session so this just moves the TMF fields from the conn to the session. We can then rely on the iscsi_session_teardown->iscsi_remove_session->__iscsi_unbind_session call to remove the target and it's devices, and know after that point there is no device or scsi-ml callout trying to access the session.

CVSS3: 7.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3whr-wp9q-7v74

code-projects Simple Gym Management System v1.0 is vulnerable to SQL Injection in /gym/trainer_search.php.

CVSS3: 9.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-3whr-qgm8-hgrg

webmail/modules/filesystem/edit.php in U-Mail Webmail server 4.91 allows remote attackers to overwrite arbitrary files via an absolute pathname in the path parameter and arbitrary content in the content parameter. NOTE: this can be leveraged for code execution by writing to a file under the web document root.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-3whr-c946-j943

Stack-based buffer overflow in lzh.fmt in WinRAR 3.00 through 3.60 beta 6 allows remote attackers to execute arbitrary code via a long filename in a LHA archive.

8%
Низкий
больше 4 лет назад
github логотип
GHSA-3whq-vc2m-hq82

Directory traversal vulnerability in the IMAP service (meimaps.exe) of MailEnable Professional 1.6 and earlier and Enterprise 1.1 and earlier allows remote attackers to create or rename arbitrary mail directories via the mailbox name argument of the (1) create or (2) rename commands.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3whq-m5gj-947w

A vulnerability was found when an attacker, while communicating with the ClearPass management interface, is able to intercept and change parameters in the HTTP packets resulting in the compromise of some of ClearPass' service accounts. Resolution: Fixed in 6.7.10, 6.8.1, 6.9.0 and higher.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3whq-64q2-qfj6

vyper performs double eval of raw_args in create_from_blueprint

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3whp-4f2f-273p

A flaw has been found in Tenda i3 1.0.0.6(2204). This impacts the function formSetCfm of the file /goform/setcfm. This manipulation of the argument funcpara1 causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.

CVSS3: 8.8
1%
Низкий
6 месяцев назад
github логотип
GHSA-3whp-4394-49gc

In the Linux kernel, the following vulnerability has been resolved: tools/power turbostat: Fix offset overflow issue in index converting The idx_to_offset() function returns type int (32-bit signed), but MSR_PKG_ENERGY_STAT is u32 and would be interpreted as a negative number. The end result is that it hits the if (offset < 0) check in update_msr_sum() which prevents the timer callback from updating the stat in the background when long durations are used. The similar issue exists in offset_to_idx() and update_msr_sum(). Fix this issue by converting the 'int' to 'off_t' accordingly.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3whm-j4xm-rv8x

Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Due to the way this function is used, we do not believe this leakage is enough to allow recovery of the private key when P-256 is used in any well known protocols.

CVSS3: 8.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-3whj-7m92-7898

SQL injection vulnerability in artreplydelete.asp in ASP EDGE 1.3a and earlier allows remote attackers to execute arbitrary SQL commands via a username cookie, a different vector than CVE-2007-0560.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3whf-vgf2-9w6g

zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit

около 1 месяца назад
github логотип
GHSA-3whc-qvhv-xqjp

goshs: WebDAV listener ignores --read-only, --upload-only, and --no-delete mode flags

CVSS3: 8.1
0%
Низкий
2 месяца назад

Уязвимостей на страницу