Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 365 060

Количество 365 060

github логотип

GHSA-3v6f-955w-932h

больше 4 лет назад

In Apache HTTP Server versions 2.4.0 to 2.4.23, malicious input to mod_auth_digest can cause the server to crash, and each instance continues to crash even for subsequently valid requests.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-3v69-r3x2-qgp5

больше 4 лет назад

When running with FIPS mode enabled, Mirantis Container Runtime 20.10.8 leaks memory during TLS Handshakes which could be abused to cause a denial of service.

EPSS: Низкий
github логотип

GHSA-3v69-q96q-wq6c

больше 4 лет назад

Pydio Cells 2.0.4 allows XSS. A malicious user can either upload or create a new file that contains potentially malicious HTML and JavaScript code to personal folders or accessible cells.

EPSS: Низкий
github логотип

GHSA-3v69-2vx2-cxcc

больше 1 года назад

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_mppi_controller.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3v69-2jfv-2mr2

больше 4 лет назад

An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar via a crafted web site.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3v68-xjhw-g33j

больше 4 лет назад

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.4.1.16828. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the resetForm method when processing AcroForms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-8229.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3v68-wgp5-q8w6

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay Top 10 allows Stored XSS. This issue affects Top 10: from n/a through 4.1.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3v68-r58v-m4c2

больше 4 лет назад

The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as exploited in the wild by Gimmiv.A in October 2008, aka "Server Service Vulnerability."

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-3v68-phv5-4j3p

около 1 года назад

A vulnerability, which was classified as critical, has been found in Tenda FH451 1.0.0.9. Affected by this issue is the function fromP2pListFilter of the file /goform/P2pListFilter. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3v68-hp3q-c376

больше 3 лет назад

Out-of-bounds read was discovered in YDB server. An attacker could construct a query with insert statement that would allow him to read sensitive information from other memory locations or cause a crash.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-3v68-4wh3-g8fg

больше 4 лет назад

Race condition in providers/telephony/MmsProvider.java in Telephony in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows attackers to gain privileges via a crafted application that modifies a database between two open operations, aka internal bug 30481342.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3v67-94rm-j953

больше 4 лет назад

IBM Security Directory Server 6.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 165815.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3v67-76rr-2qc3

больше 4 лет назад

Use after free in developer tools in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3v67-545x-ffc3

больше 1 года назад

Apache Kylin Server-Side Request Forgery (SSRF) via `/kylin/api/xxx/diag` Endpoint

EPSS: Низкий
github логотип

GHSA-3v66-h3rq-pj5p

больше 4 лет назад

drupal6 version 6.16 has open redirection

EPSS: Низкий
github логотип

GHSA-3v66-3586-p5rh

больше 4 лет назад

** DISPUTED ** An issue was discovered in SMA Solar Technology products. If a user simultaneously has Sunny Explorer running and visits a malicious host, cross-site request forgery can be used to change settings in the inverters (for example, issuing a POST request to change the user password). All Sunny Explorer settings available to the authenticated user are also available to the attacker. (In some cases, this also includes changing settings that the user has no access to.) This may result in complete compromise of the device. NOTE: the vendor reports that exploitation is unlikely because Sunny Explorer is used only rarely. Also, only Sunny Boy TLST-21 and TL-21 and Sunny Tripower TL-10 and TL-30 could potentially be affected.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3v65-m7jv-mqrv

больше 1 года назад

Missing Authorization vulnerability in Andy Stratton Append Content allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Append Content: from n/a through 2.1.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3v63-qv3r-29hp

больше 2 лет назад

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-3v63-f83x-37x4

больше 4 лет назад

Improper Limitation of a Pathname to a Restricted Directory in Apache ActiveMQ

EPSS: Высокий
github логотип

GHSA-3v63-c44g-4vm5

больше 4 лет назад

Adobe Photoshop versions 22.5.6 (and earlier)and 23.2.2 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3v6f-955w-932h

In Apache HTTP Server versions 2.4.0 to 2.4.23, malicious input to mod_auth_digest can cause the server to crash, and each instance continues to crash even for subsequently valid requests.

CVSS3: 7.5
21%
Средний
больше 4 лет назад
github логотип
GHSA-3v69-r3x2-qgp5

When running with FIPS mode enabled, Mirantis Container Runtime 20.10.8 leaks memory during TLS Handshakes which could be abused to cause a denial of service.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3v69-q96q-wq6c

Pydio Cells 2.0.4 allows XSS. A malicious user can either upload or create a new file that contains potentially malicious HTML and JavaScript code to personal folders or accessible cells.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3v69-2vx2-cxcc

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_mppi_controller.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-3v69-2jfv-2mr2

An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar via a crafted web site.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3v68-xjhw-g33j

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.4.1.16828. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the resetForm method when processing AcroForms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-8229.

CVSS3: 5.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-3v68-wgp5-q8w6

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay Top 10 allows Stored XSS. This issue affects Top 10: from n/a through 4.1.0.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3v68-r58v-m4c2

The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as exploited in the wild by Gimmiv.A in October 2008, aka "Server Service Vulnerability."

CVSS3: 9.8
99%
Критический
больше 4 лет назад
github логотип
GHSA-3v68-phv5-4j3p

A vulnerability, which was classified as critical, has been found in Tenda FH451 1.0.0.9. Affected by this issue is the function fromP2pListFilter of the file /goform/P2pListFilter. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
3%
Низкий
около 1 года назад
github логотип
GHSA-3v68-hp3q-c376

Out-of-bounds read was discovered in YDB server. An attacker could construct a query with insert statement that would allow him to read sensitive information from other memory locations or cause a crash.

CVSS3: 9.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3v68-4wh3-g8fg

Race condition in providers/telephony/MmsProvider.java in Telephony in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows attackers to gain privileges via a crafted application that modifies a database between two open operations, aka internal bug 30481342.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3v67-94rm-j953

IBM Security Directory Server 6.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 165815.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3v67-76rr-2qc3

Use after free in developer tools in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3v67-545x-ffc3

Apache Kylin Server-Side Request Forgery (SSRF) via `/kylin/api/xxx/diag` Endpoint

1%
Низкий
больше 1 года назад
github логотип
GHSA-3v66-h3rq-pj5p

drupal6 version 6.16 has open redirection

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3v66-3586-p5rh

** DISPUTED ** An issue was discovered in SMA Solar Technology products. If a user simultaneously has Sunny Explorer running and visits a malicious host, cross-site request forgery can be used to change settings in the inverters (for example, issuing a POST request to change the user password). All Sunny Explorer settings available to the authenticated user are also available to the attacker. (In some cases, this also includes changing settings that the user has no access to.) This may result in complete compromise of the device. NOTE: the vendor reports that exploitation is unlikely because Sunny Explorer is used only rarely. Also, only Sunny Boy TLST-21 and TL-21 and Sunny Tripower TL-10 and TL-30 could potentially be affected.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3v65-m7jv-mqrv

Missing Authorization vulnerability in Andy Stratton Append Content allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Append Content: from n/a through 2.1.1.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3v63-qv3r-29hp

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

CVSS3: 9.8
11%
Средний
больше 2 лет назад
github логотип
GHSA-3v63-f83x-37x4

Improper Limitation of a Pathname to a Restricted Directory in Apache ActiveMQ

84%
Высокий
больше 4 лет назад
github логотип
GHSA-3v63-c44g-4vm5

Adobe Photoshop versions 22.5.6 (and earlier)and 23.2.2 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
3%
Низкий
больше 4 лет назад

Уязвимостей на страницу