Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 365 324

Количество 365 324

github логотип

GHSA-3w9c-vcrh-mvp2

больше 4 лет назад

Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a 0x7fffffff argument to the setSlice method on a WebViewFolderIcon ActiveX object, which leads to an invalid memory copy.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-3w9c-7hfp-qxrc

почти 3 года назад

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Lasso Simple URLs plugin <= 117 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3w9c-6884-377r

больше 4 лет назад

The Assets subsystem in Apple iOS before 8 and Apple TV before 7 allows man-in-the-middle attackers to spoof a device's update status via a crafted Last-Modified HTTP response header.

EPSS: Низкий
github логотип

GHSA-3w99-q2jm-p4jj

больше 4 лет назад

SQL injection vulnerability in general/sendpassword.php in (1) PHPCollab 2.4 and 2.5.rc3, and (2) NetOffice 2.5.3-pl1 and 2.6.0b2 allows remote attackers to execute arbitrary SQL commands via the loginForm parameter in the "forgotten password" option.

EPSS: Низкий
github логотип

GHSA-3w99-p9rf-w2qj

5 месяцев назад

A weakness has been identified in Trendnet TEW-657BRM 1.00.1. This affects the function add_wps_client of the file /setup.cgi. This manipulation of the argument wl_enrolee_pin causes os command injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor confirms, that "[t]he product in question (...) has been discontinued and end of life since June 23, 2011, that is more than 14 years ago. We no longer provide support for this product, so we are not able to confirm the vulnerabilities. We will make an announcement on our website's product support page and notify customers who registered their products with us." This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3w99-p52w-wfq4

больше 4 лет назад

Cross-site request forgery (CSRF) vulnerability in MetalGenix GeniXCMS before 0.0.2 allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via a request in the users page to gxadmin/index.php.

EPSS: Низкий
github логотип

GHSA-3w99-gx9w-vc94

около 3 лет назад

A vulnerability was found in Templatecookie Adlisting 2.14.0. It has been classified as problematic. Affected is an unknown function of the file /ad-list of the component Redirect Handler. The manipulation leads to information disclosure. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-236184. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
EPSS: Средний
github логотип

GHSA-3w99-5f2g-rxfc

около 3 лет назад

There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could execute arbitrary JavaScript code in the victim’s browser.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3w98-hgq4-9vr4

больше 4 лет назад

On D-Link DIR-550A and DIR-604M devices through v2.10KR, a malicious user can forge an HTTP request to inject operating system commands that can be executed on the device with higher privileges, aka remote code execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3w97-v426-7jw9

около 1 года назад

An OS command injection vulnerability exists in WebTester version 5.x via the install2.php installation script. The parameters cpusername, cppassword, and cpdomain are passed directly to shell commands without sanitization. A remote unauthenticated attacker can exploit this flaw by sending a crafted HTTP POST request, resulting in arbitrary command execution on the underlying system with web server privileges.

EPSS: Низкий
github логотип

GHSA-3w97-prq2-5cjc

больше 4 лет назад

Meross MSS110 devices through 1.1.24 contain an unauthenticated admin.htm administrative interface.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3w97-9v6v-7c57

около 4 лет назад

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability in Brocade Fabric OS versions v7.4.1b and v7.3.1d could allow local users to conduct privileged directory transversal. Brocade Fabric OS versions v7.4.1.x and v7.3.x have reached end of life. Brocade Fabric OS Users should upgrade to supported versions as described in the Product End-of-Life Publish report.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3w97-3qww-vxj8

больше 4 лет назад

Buffer Overflow vulnerability in FFmpeg 4.2 in mov_write_video_tag due to the out of bounds in libavformat/movenc.c, which could let a remote malicious user obtain sensitive information, cause a Denial of Service, or execute arbitrary code.

EPSS: Низкий
github логотип

GHSA-3w96-rhq8-qmh8

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in app/views/layouts/base.rhtml in Redmine 1.0.1 through 1.1.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to projects/hg-helloworld/news/. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-3w96-p6vh-c298

больше 3 лет назад

Cross-site Scripting in pimcore

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3w96-9326-4rfg

больше 4 лет назад

Object lifetime issue in V8 in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3w96-2pj9-mfjc

больше 4 лет назад

An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory, aka 'Windows Network Connections Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0802, CVE-2020-0803, CVE-2020-0804, CVE-2020-0845.

EPSS: Низкий
github логотип

GHSA-3w95-jpf5-784j

больше 1 года назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Lomu WPCOM Member allows PHP Local File Inclusion. This issue affects WPCOM Member: from n/a through 1.7.7.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3w95-fv8q-2wr8

больше 2 лет назад

An OS command injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following version: QuMagie 2.2.1 and later

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-3w95-ccww-mwv8

5 месяцев назад

NVIDIA Megatron-LM contains a vulnerability in inferencing where an Attacker may cause an RCE by convincing a user to load a maliciously crafted input. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, and data tampering.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3w9c-vcrh-mvp2

Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a 0x7fffffff argument to the setSlice method on a WebViewFolderIcon ActiveX object, which leads to an invalid memory copy.

CVSS3: 8.8
64%
Средний
больше 4 лет назад
github логотип
GHSA-3w9c-7hfp-qxrc

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Lasso Simple URLs plugin <= 117 versions.

CVSS3: 7.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-3w9c-6884-377r

The Assets subsystem in Apple iOS before 8 and Apple TV before 7 allows man-in-the-middle attackers to spoof a device's update status via a crafted Last-Modified HTTP response header.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3w99-q2jm-p4jj

SQL injection vulnerability in general/sendpassword.php in (1) PHPCollab 2.4 and 2.5.rc3, and (2) NetOffice 2.5.3-pl1 and 2.6.0b2 allows remote attackers to execute arbitrary SQL commands via the loginForm parameter in the "forgotten password" option.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-3w99-p9rf-w2qj

A weakness has been identified in Trendnet TEW-657BRM 1.00.1. This affects the function add_wps_client of the file /setup.cgi. This manipulation of the argument wl_enrolee_pin causes os command injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor confirms, that "[t]he product in question (...) has been discontinued and end of life since June 23, 2011, that is more than 14 years ago. We no longer provide support for this product, so we are not able to confirm the vulnerabilities. We will make an announcement on our website's product support page and notify customers who registered their products with us." This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 6.3
5%
Низкий
5 месяцев назад
github логотип
GHSA-3w99-p52w-wfq4

Cross-site request forgery (CSRF) vulnerability in MetalGenix GeniXCMS before 0.0.2 allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via a request in the users page to gxadmin/index.php.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-3w99-gx9w-vc94

A vulnerability was found in Templatecookie Adlisting 2.14.0. It has been classified as problematic. Affected is an unknown function of the file /ad-list of the component Redirect Handler. The manipulation leads to information disclosure. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-236184. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
46%
Средний
около 3 лет назад
github логотип
GHSA-3w99-5f2g-rxfc

There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could execute arbitrary JavaScript code in the victim’s browser.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-3w98-hgq4-9vr4

On D-Link DIR-550A and DIR-604M devices through v2.10KR, a malicious user can forge an HTTP request to inject operating system commands that can be executed on the device with higher privileges, aka remote code execution.

CVSS3: 8.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-3w97-v426-7jw9

An OS command injection vulnerability exists in WebTester version 5.x via the install2.php installation script. The parameters cpusername, cppassword, and cpdomain are passed directly to shell commands without sanitization. A remote unauthenticated attacker can exploit this flaw by sending a crafted HTTP POST request, resulting in arbitrary command execution on the underlying system with web server privileges.

10%
Низкий
около 1 года назад
github логотип
GHSA-3w97-prq2-5cjc

Meross MSS110 devices through 1.1.24 contain an unauthenticated admin.htm administrative interface.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3w97-9v6v-7c57

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability in Brocade Fabric OS versions v7.4.1b and v7.3.1d could allow local users to conduct privileged directory transversal. Brocade Fabric OS versions v7.4.1.x and v7.3.x have reached end of life. Brocade Fabric OS Users should upgrade to supported versions as described in the Product End-of-Life Publish report.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-3w97-3qww-vxj8

Buffer Overflow vulnerability in FFmpeg 4.2 in mov_write_video_tag due to the out of bounds in libavformat/movenc.c, which could let a remote malicious user obtain sensitive information, cause a Denial of Service, or execute arbitrary code.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3w96-rhq8-qmh8

Cross-site scripting (XSS) vulnerability in app/views/layouts/base.rhtml in Redmine 1.0.1 through 1.1.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to projects/hg-helloworld/news/. NOTE: some of these details are obtained from third party information.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-3w96-p6vh-c298

Cross-site Scripting in pimcore

CVSS3: 6.3
3%
Низкий
больше 3 лет назад
github логотип
GHSA-3w96-9326-4rfg

Object lifetime issue in V8 in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3w96-2pj9-mfjc

An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory, aka 'Windows Network Connections Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0802, CVE-2020-0803, CVE-2020-0804, CVE-2020-0845.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3w95-jpf5-784j

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Lomu WPCOM Member allows PHP Local File Inclusion. This issue affects WPCOM Member: from n/a through 1.7.7.

CVSS3: 8.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-3w95-fv8q-2wr8

An OS command injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following version: QuMagie 2.2.1 and later

CVSS3: 7.4
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3w95-ccww-mwv8

NVIDIA Megatron-LM contains a vulnerability in inferencing where an Attacker may cause an RCE by convincing a user to load a maliciously crafted input. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, and data tampering.

CVSS3: 7.8
0%
Низкий
5 месяцев назад

Уязвимостей на страницу