Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 365 324

Количество 365 324

github логотип

GHSA-3w77-rf68-cjm6

больше 4 лет назад

The Region_createFromParcel function in core/jni/android/graphics/Region.cpp in Region in Android before 5.1.1 LMY48M does not check the return values of certain read operations, which allows attackers to execute arbitrary code via an application that sends a crafted message to a service, aka internal bug 21585255.

EPSS: Низкий
github логотип

GHSA-3w77-j752-v9mg

больше 4 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via vectors related to RMI. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to cross-site scripting (XSS) in the sun.rmi.transport.proxy CGIHandler class that does not properly handle error messages in a (1) command or (2) port number.

EPSS: Низкий
github логотип

GHSA-3w77-cv9r-g8qj

больше 4 лет назад

The Classic Meeting Server in IBM Sametime 8.x through 8.5.2.1 allows physically proximate attackers to discover a meeting password hash by leveraging access to an unattended workstation to read HTML source code within a victim's browser.

EPSS: Низкий
github логотип

GHSA-3w77-ccg9-93q6

почти 2 года назад

A vulnerability was found in code-projects University Event Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /dodelete.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3w76-xwmv-869f

больше 4 лет назад

NUUO CMS all versions 3.1 and prior, The application uses a session identification mechanism that could allow attackers to obtain the active session ID, which could allow arbitrary remote code execution.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-3w76-x94r-pw44

больше 7 лет назад

Downloads Resources over HTTP in rs-brightcove

EPSS: Низкий
github логотип

GHSA-3w76-w7w4-rg38

больше 4 лет назад

Stack-based buffer overflow in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1a allows remote attackers to execute arbitrary code via an opcode 0x6c request.

EPSS: Средний
github логотип

GHSA-3w75-3vfv-c67r

больше 4 лет назад

IBM QRadar SIEM 7.2 and 7.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 134177.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3w74-m667-5gqh

больше 4 лет назад

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 410/12, SD 425, SD 430, SD 450, SD 617, SD 625, SD 650/52, SD 820, and SD 820A, TOCTOU vulnerabilities may occur while sanitizing userspace values passed to tQSEE system call.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3w74-38gg-gj48

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPtouch WPtouch allows Stored XSS. This issue affects WPtouch: from n/a through 4.3.60.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3w73-v39x-4p8h

больше 4 лет назад

Quake 2 server allows remote attackers to cause a denial of service via a spoofed UDP packet with a source address of 127.0.0.1, which causes the server to attempt to connect to itself.

EPSS: Низкий
github логотип

GHSA-3w73-fmf3-hg5c

почти 5 лет назад

Policies not properly enforced in OWASP Java HTML Sanitizer

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3w73-fhv4-qr7q

5 месяцев назад

A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to perform an SQL injection attack against an affected device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP(S) request to the web-based management interface of an affected device. A successful exploit could allow the attacker to view data on the affected device.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3w73-8wv6-hfqr

больше 4 лет назад

In wma_ndp_end_response_event_handler(), the variable len_end_rsp is a uint32 which can be overflowed if the value of variable "event->num_ndp_end_rsp_per_ndi_list" is very large which can then lead to a heap overwrite of the heap object end_rsp in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3w73-4p4p-f992

больше 4 лет назад

Checkmk <=2.0.0p19 contains a Cross Site Scripting (XSS) vulnerability. While creating or editing a user attribute, the Help Text is subject to HTML injection, which can be triggered for editing a user.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3w6x-xqhx-2c63

9 месяцев назад

Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable to NTLM Hash Exposure.  This vulnerability is exploitable only by technicians who have the “Impersonate as Admin” option enabled.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-3w6x-jcm9-p8w3

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: net: wwan: iosm: Fix tainted pointer delete is case of region creation fail In case of region creation fail in ipc_devlink_create_region(), previously created regions delete process starts from tainted pointer which actually holds error code value. Fix this bug by decreasing region index before delete. Found by Linux Verification Center (linuxtesting.org) with SVACE.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3w6x-j894-mcx4

8 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in Page Carbajal Custom Post Status allows Stored XSS.This issue affects Custom Post Status: from n/a through 1.1.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3w6x-gv34-mqpf

5 месяцев назад

OpenClaw's mutating internal ACP chat commands missed operator.admin scope enforcement

EPSS: Низкий
github логотип

GHSA-3w6x-g2w9-f5ph

больше 4 лет назад

Unspecified vulnerability in the Portal component in Oracle Application Server 10.1.3 up to 10.1.3.2.0, 10.1.2 up to 10.1.2.2.0, and 9.0.4.3 has unknown impact and attack vectors, aka AS04.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3w77-rf68-cjm6

The Region_createFromParcel function in core/jni/android/graphics/Region.cpp in Region in Android before 5.1.1 LMY48M does not check the return values of certain read operations, which allows attackers to execute arbitrary code via an application that sends a crafted message to a service, aka internal bug 21585255.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3w77-j752-v9mg

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via vectors related to RMI. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to cross-site scripting (XSS) in the sun.rmi.transport.proxy CGIHandler class that does not properly handle error messages in a (1) command or (2) port number.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-3w77-cv9r-g8qj

The Classic Meeting Server in IBM Sametime 8.x through 8.5.2.1 allows physically proximate attackers to discover a meeting password hash by leveraging access to an unattended workstation to read HTML source code within a victim's browser.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3w77-ccg9-93q6

A vulnerability was found in code-projects University Event Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /dodelete.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-3w76-xwmv-869f

NUUO CMS all versions 3.1 and prior, The application uses a session identification mechanism that could allow attackers to obtain the active session ID, which could allow arbitrary remote code execution.

CVSS3: 9.8
30%
Средний
больше 4 лет назад
github логотип
GHSA-3w76-x94r-pw44

Downloads Resources over HTTP in rs-brightcove

2%
Низкий
больше 7 лет назад
github логотип
GHSA-3w76-w7w4-rg38

Stack-based buffer overflow in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1a allows remote attackers to execute arbitrary code via an opcode 0x6c request.

66%
Средний
больше 4 лет назад
github логотип
GHSA-3w75-3vfv-c67r

IBM QRadar SIEM 7.2 and 7.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 134177.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3w74-m667-5gqh

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 410/12, SD 425, SD 430, SD 450, SD 617, SD 625, SD 650/52, SD 820, and SD 820A, TOCTOU vulnerabilities may occur while sanitizing userspace values passed to tQSEE system call.

CVSS3: 8.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3w74-38gg-gj48

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPtouch WPtouch allows Stored XSS. This issue affects WPtouch: from n/a through 4.3.60.

CVSS3: 5.9
0%
Низкий
около 1 года назад
github логотип
GHSA-3w73-v39x-4p8h

Quake 2 server allows remote attackers to cause a denial of service via a spoofed UDP packet with a source address of 127.0.0.1, which causes the server to attempt to connect to itself.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3w73-fmf3-hg5c

Policies not properly enforced in OWASP Java HTML Sanitizer

CVSS3: 9.8
3%
Низкий
почти 5 лет назад
github логотип
GHSA-3w73-fhv4-qr7q

A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to perform an SQL injection attack against an affected device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP(S) request to the web-based management interface of an affected device. A successful exploit could allow the attacker to view data on the affected device.

CVSS3: 4.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-3w73-8wv6-hfqr

In wma_ndp_end_response_event_handler(), the variable len_end_rsp is a uint32 which can be overflowed if the value of variable "event->num_ndp_end_rsp_per_ndi_list" is very large which can then lead to a heap overwrite of the heap object end_rsp in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3w73-4p4p-f992

Checkmk <=2.0.0p19 contains a Cross Site Scripting (XSS) vulnerability. While creating or editing a user attribute, the Help Text is subject to HTML injection, which can be triggered for editing a user.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3w6x-xqhx-2c63

Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable to NTLM Hash Exposure.  This vulnerability is exploitable only by technicians who have the “Impersonate as Admin” option enabled.

CVSS3: 6.4
0%
Низкий
9 месяцев назад
github логотип
GHSA-3w6x-jcm9-p8w3

In the Linux kernel, the following vulnerability has been resolved: net: wwan: iosm: Fix tainted pointer delete is case of region creation fail In case of region creation fail in ipc_devlink_create_region(), previously created regions delete process starts from tainted pointer which actually holds error code value. Fix this bug by decreasing region index before delete. Found by Linux Verification Center (linuxtesting.org) with SVACE.

CVSS3: 7.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-3w6x-j894-mcx4

Cross-Site Request Forgery (CSRF) vulnerability in Page Carbajal Custom Post Status allows Stored XSS.This issue affects Custom Post Status: from n/a through 1.1.0.

CVSS3: 7.1
0%
Низкий
8 месяцев назад
github логотип
GHSA-3w6x-gv34-mqpf

OpenClaw's mutating internal ACP chat commands missed operator.admin scope enforcement

5 месяцев назад
github логотип
GHSA-3w6x-g2w9-f5ph

Unspecified vulnerability in the Portal component in Oracle Application Server 10.1.3 up to 10.1.3.2.0, 10.1.2 up to 10.1.2.2.0, and 9.0.4.3 has unknown impact and attack vectors, aka AS04.

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу