Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 365 324

Количество 365 324

github логотип

GHSA-3wgw-h3pq-p82c

больше 2 лет назад

Generation of Error Message Containing Sensitive Information vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Agent modules).This issue affects Hitachi Device Manager: before 8.8.5-04.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3wgw-9fm4-w9hv

больше 4 лет назад

The Chartboost library before 2.0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-3wgv-24f6-hqhj

больше 3 лет назад

CVE was unused by HPE.

EPSS: Низкий
github логотип

GHSA-3wgr-c9q2-xcp3

больше 2 лет назад

Insecure Permissions issue in Raiden Professional Server RaidenFTPD v.2.4 build 4005 allows a local attacker to gain privileges and execute arbitrary code via crafted executable running from the installation directory.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3wgq-wrwc-vqmv

11 месяцев назад

astral-tokio-tar has a path traversal in tar extraction

EPSS: Низкий
github логотип

GHSA-3wgq-h4fr-cwg5

больше 1 года назад

laravel-crud-wizard-free has File Validation Bypass

EPSS: Низкий
github логотип

GHSA-3wgq-7p7q-x7pg

больше 4 лет назад

A iccselectdevtype expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

EPSS: Низкий
github логотип

GHSA-3wgq-2r52-v65w

больше 4 лет назад

The start_authentication function in lightdm-gtk-greeter.c in LightDM GTK+ Greeter before 1.7.1 does not properly handle the return value from the lightdm_greeter_get_authentication_user function, which allows local users to cause a denial of service (NULL pointer dereference) via an empty username.

EPSS: Низкий
github логотип

GHSA-3wgp-p23j-5xjj

больше 4 лет назад

SAP Commerce Cloud (previously known as SAP Hybris Commerce), (HY_COM, versions 6.3, 6.4, 6.5, 6.6, 6.7, 1808, 1811), allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3wgp-8w96-g9f5

11 месяцев назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-3wgm-hxjc-v3w2

около 1 месяца назад

Inappropriate implementation in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3wgm-5fw2-jv64

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in HP Service Manager 9.30 through 9.32 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3wgm-584m-j4r6

больше 4 лет назад

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-3wgm-2gw2-vh5m

больше 1 года назад

Kubernetes GitRepo Volume Inadvertent Local Repository Access

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3wgj-c2hg-vm6q

4 месяца назад

Open WebUI vulnerable to stored XSS via OAuth picture claim stored as SVG data URI in profile_image_url

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3wgh-5r9h-pf5v

больше 4 лет назад

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.36 and Prior to 5.2.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data and unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H).

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-3wgg-cmh5-mrf4

больше 4 лет назад

NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-3wgg-3j4j-3f69

около 1 года назад

Jenkins Aqua Security Scanner Plugin vulnerability exposes scanner tokens

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3wgf-ccpx-rv72

5 месяцев назад

Improper handling of insufficient permissions or privileges in Windows Installer allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3wgc-2cj2-h23p

больше 2 лет назад

A vulnerability was found in Tenda A15 15.13.07.13. It has been classified as critical. This affects an unknown part of the file /goform/setBlackRule of the component Web-based Management Interface. The manipulation of the argument deviceList leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-250701 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3wgw-h3pq-p82c

Generation of Error Message Containing Sensitive Information vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Agent modules).This issue affects Hitachi Device Manager: before 8.8.5-04.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3wgw-9fm4-w9hv

The Chartboost library before 2.0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3wgv-24f6-hqhj

CVE was unused by HPE.

больше 3 лет назад
github логотип
GHSA-3wgr-c9q2-xcp3

Insecure Permissions issue in Raiden Professional Server RaidenFTPD v.2.4 build 4005 allows a local attacker to gain privileges and execute arbitrary code via crafted executable running from the installation directory.

CVSS3: 7.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3wgq-wrwc-vqmv

astral-tokio-tar has a path traversal in tar extraction

0%
Низкий
11 месяцев назад
github логотип
GHSA-3wgq-h4fr-cwg5

laravel-crud-wizard-free has File Validation Bypass

больше 1 года назад
github логотип
GHSA-3wgq-7p7q-x7pg

A iccselectdevtype expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

7%
Низкий
больше 4 лет назад
github логотип
GHSA-3wgq-2r52-v65w

The start_authentication function in lightdm-gtk-greeter.c in LightDM GTK+ Greeter before 1.7.1 does not properly handle the return value from the lightdm_greeter_get_authentication_user function, which allows local users to cause a denial of service (NULL pointer dereference) via an empty username.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3wgp-p23j-5xjj

SAP Commerce Cloud (previously known as SAP Hybris Commerce), (HY_COM, versions 6.3, 6.4, 6.5, 6.6, 6.7, 1808, 1811), allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-3wgp-8w96-g9f5

Rejected reason: Not used

11 месяцев назад
github логотип
GHSA-3wgm-hxjc-v3w2

Inappropriate implementation in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3wgm-5fw2-jv64

Cross-site scripting (XSS) vulnerability in HP Service Manager 9.30 through 9.32 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3wgm-584m-j4r6

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-3wgm-2gw2-vh5m

Kubernetes GitRepo Volume Inadvertent Local Repository Access

CVSS3: 6.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-3wgj-c2hg-vm6q

Open WebUI vulnerable to stored XSS via OAuth picture claim stored as SVG data URI in profile_image_url

CVSS3: 7.3
4 месяца назад
github логотип
GHSA-3wgh-5r9h-pf5v

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.36 and Prior to 5.2.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data and unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H).

CVSS3: 6.6
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3wgg-cmh5-mrf4

NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.

CVSS3: 9.8
14%
Средний
больше 4 лет назад
github логотип
GHSA-3wgg-3j4j-3f69

Jenkins Aqua Security Scanner Plugin vulnerability exposes scanner tokens

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-3wgf-ccpx-rv72

Improper handling of insufficient permissions or privileges in Windows Installer allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-3wgc-2cj2-h23p

A vulnerability was found in Tenda A15 15.13.07.13. It has been classified as critical. This affects an unknown part of the file /goform/setBlackRule of the component Web-based Management Interface. The manipulation of the argument deviceList leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-250701 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.2
2%
Низкий
больше 2 лет назад

Уязвимостей на страницу