Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 365 324

Количество 365 324

github логотип

GHSA-3w95-9p64-7q7q

больше 4 лет назад

FlatNuke 2.5.3 allows remote attackers to obtain sensitive information via invalid parameters to certain scripts, which leaks the web document root in an error message.

EPSS: Низкий
github логотип

GHSA-3w95-9g93-92fj

около 3 лет назад

In vcu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07645149; Issue ID: ALPS07645178.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3w95-95fc-gjxf

больше 4 лет назад

SQL injection vulnerability in philboard_forum.asp in Husrev BlackBoard 2.0.2 allows remote attackers to execute arbitrary SQL commands via the forumid parameter.

EPSS: Низкий
github логотип

GHSA-3w95-3q7c-6v47

больше 4 лет назад

services/go.php in Horde Application Framework 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1 does not properly restrict its image proxy capability, which allows remote attackers to perform "Web tunneling" attacks and use the server as a proxy via (1) http, (2) https, and (3) ftp URL in the url parameter, which is requested from the server.

EPSS: Низкий
github логотип

GHSA-3w94-w3gc-69pw

больше 4 лет назад

SQL injection vulnerability in sorter.php in the phpManufaktur kitForm extension 0.43 and earlier for the KeepInTouch (KIT) module allows remote attackers to execute arbitrary SQL commands via the sorter_value parameter.

EPSS: Низкий
github логотип

GHSA-3w94-vq2x-v5wr

около 1 года назад

ethereum does not check transaction malleability for EIP-2930, EIP-1559 and EIP-7702 transactions

EPSS: Низкий
github логотип

GHSA-3w94-4jxf-2v59

больше 4 лет назад

SQL injection vulnerability in gallery.php in MyCard 1.0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

EPSS: Низкий
github логотип

GHSA-3w93-xggv-pqrq

больше 4 лет назад

IBM Jazz Foundation (IBM Rational Engineering Lifecycle Manager 5.0 through 6.0.6) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152740.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3w93-f425-v54j

3 месяца назад

Unauthenticated Broken Access Control in Classified Listing <= 5.3.8 versions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3w8x-qf95-v2x7

больше 4 лет назад

Stack-based buffer overflow in Novell iPrint Client before 5.90 allows remote attackers to execute arbitrary code via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3w8x-p539-469j

почти 2 года назад

In query of DownloadManager.java, there is a possible read/write of arbitrary files due to a permissions bypass. This could lead to local information disclosure and file rewriting with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-3w8x-76pc-54fp

больше 4 лет назад

The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-information page.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3w8w-mhj7-j5rc

почти 4 года назад

systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation methodology is to crash a binary calling the same function recursively, and put it in a deeply nested directory to make its backtrace large enough to cause the deadlock. This must be done 16 times when MaxConnections=16 is set for the systemd/units/systemd-coredump.socket file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3w8w-875g-xvfg

около 4 лет назад

Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow a NULL pointer dereference when this.Span is used for oState of Collab.addStateModel, because this.Span.text can be NULL.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3w8r-3jh9-89v9

почти 3 года назад

xxl-job-admin vulnerable to Insecure Permissions

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3w8r-2x8f-g5jx

около 4 лет назад

It was reported that watchman in openshift node-utils creates /var/run/watchman.pid and /var/log/watchman.ouput with world writable permission.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3w8q-xq97-5j7x

9 месяцев назад

Rhino has high CPU usage and potential DoS when passing specific numbers to `toFixed()` function

EPSS: Низкий
github логотип

GHSA-3w8q-xg7c-33gv

больше 4 лет назад

syslogd in the syslog subsystem in Apple iOS before 8 and Apple TV before 7 allows local users to change the permissions of arbitrary files via a symlink attack on an unspecified file.

EPSS: Низкий
github логотип

GHSA-3w8q-vg6g-cg46

9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: crypto: lib/mpi - avoid null pointer deref in mpi_cmp_ui() During NVMeTCP Authentication a controller can trigger a kernel oops by specifying the 8192 bit Diffie Hellman group and passing a correctly sized, but zeroed Diffie Hellamn value. mpi_cmp_ui() was detecting this if the second parameter was 0, but 1 is passed from dh_is_pubkey_valid(). This causes the null pointer u->d to be dereferenced towards the end of mpi_cmp_ui()

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3w8q-3783-r4v7

около 1 года назад

A vulnerability classified as problematic was found in LitmusChaos Litmus up to 3.19.0. Affected by this vulnerability is an unknown functionality. The manipulation of the argument projectID leads to improper control of resource identifiers. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3w95-9p64-7q7q

FlatNuke 2.5.3 allows remote attackers to obtain sensitive information via invalid parameters to certain scripts, which leaks the web document root in an error message.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3w95-9g93-92fj

In vcu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07645149; Issue ID: ALPS07645178.

CVSS3: 6.7
0%
Низкий
около 3 лет назад
github логотип
GHSA-3w95-95fc-gjxf

SQL injection vulnerability in philboard_forum.asp in Husrev BlackBoard 2.0.2 allows remote attackers to execute arbitrary SQL commands via the forumid parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3w95-3q7c-6v47

services/go.php in Horde Application Framework 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1 does not properly restrict its image proxy capability, which allows remote attackers to perform "Web tunneling" attacks and use the server as a proxy via (1) http, (2) https, and (3) ftp URL in the url parameter, which is requested from the server.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3w94-w3gc-69pw

SQL injection vulnerability in sorter.php in the phpManufaktur kitForm extension 0.43 and earlier for the KeepInTouch (KIT) module allows remote attackers to execute arbitrary SQL commands via the sorter_value parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3w94-vq2x-v5wr

ethereum does not check transaction malleability for EIP-2930, EIP-1559 and EIP-7702 transactions

0%
Низкий
около 1 года назад
github логотип
GHSA-3w94-4jxf-2v59

SQL injection vulnerability in gallery.php in MyCard 1.0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3w93-xggv-pqrq

IBM Jazz Foundation (IBM Rational Engineering Lifecycle Manager 5.0 through 6.0.6) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152740.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3w93-f425-v54j

Unauthenticated Broken Access Control in Classified Listing <= 5.3.8 versions.

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-3w8x-qf95-v2x7

Stack-based buffer overflow in Novell iPrint Client before 5.90 allows remote attackers to execute arbitrary code via unspecified vectors.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-3w8x-p539-469j

In query of DownloadManager.java, there is a possible read/write of arbitrary files due to a permissions bypass. This could lead to local information disclosure and file rewriting with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.7
0%
Низкий
почти 2 года назад
github логотип
GHSA-3w8x-76pc-54fp

The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-information page.

CVSS3: 7.5
4%
Низкий
больше 4 лет назад
github логотип
GHSA-3w8w-mhj7-j5rc

systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation methodology is to crash a binary calling the same function recursively, and put it in a deeply nested directory to make its backtrace large enough to cause the deadlock. This must be done 16 times when MaxConnections=16 is set for the systemd/units/systemd-coredump.socket file.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-3w8w-875g-xvfg

Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow a NULL pointer dereference when this.Span is used for oState of Collab.addStateModel, because this.Span.text can be NULL.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-3w8r-3jh9-89v9

xxl-job-admin vulnerable to Insecure Permissions

CVSS3: 5.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-3w8r-2x8f-g5jx

It was reported that watchman in openshift node-utils creates /var/run/watchman.pid and /var/log/watchman.ouput with world writable permission.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-3w8q-xq97-5j7x

Rhino has high CPU usage and potential DoS when passing specific numbers to `toFixed()` function

0%
Низкий
9 месяцев назад
github логотип
GHSA-3w8q-xg7c-33gv

syslogd in the syslog subsystem in Apple iOS before 8 and Apple TV before 7 allows local users to change the permissions of arbitrary files via a symlink attack on an unspecified file.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3w8q-vg6g-cg46

In the Linux kernel, the following vulnerability has been resolved: crypto: lib/mpi - avoid null pointer deref in mpi_cmp_ui() During NVMeTCP Authentication a controller can trigger a kernel oops by specifying the 8192 bit Diffie Hellman group and passing a correctly sized, but zeroed Diffie Hellamn value. mpi_cmp_ui() was detecting this if the second parameter was 0, but 1 is passed from dh_is_pubkey_valid(). This causes the null pointer u->d to be dereferenced towards the end of mpi_cmp_ui()

CVSS3: 7.5
1%
Низкий
9 месяцев назад
github логотип
GHSA-3w8q-3783-r4v7

A vulnerability classified as problematic was found in LitmusChaos Litmus up to 3.19.0. Affected by this vulnerability is an unknown functionality. The manipulation of the argument projectID leads to improper control of resource identifiers. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
0%
Низкий
около 1 года назад

Уязвимостей на страницу