Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 364 920

Количество 364 920

github логотип

GHSA-3rjm-q6hg-6jw8

больше 4 лет назад

RealOne Player 2.0 Build 6.0.11.872 allows remote attackers to cause a denial of service (array out-of-bounds access and application crash) via a crafted .aiff file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3rjm-jwr3-fh58

больше 4 лет назад

Buffer overflow in the Napster client beta 5 allows remote attackers to cause a denial of service via a long message.

EPSS: Низкий
github логотип

GHSA-3rjj-rpg2-4f2q

больше 4 лет назад

Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Branch Intelligent Management System Software Module (aka BIMS) allows remote attackers to obtain sensitive information via unknown vectors, aka ZDI-CAN-1607.

EPSS: Средний
github логотип

GHSA-3rjh-r4h7-c3mq

23 дня назад

Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic controller overload. This type of attack can be carried out remotely over radio frequency.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3rjh-fcp5-cg7v

больше 4 лет назад

In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization is not secure by TLS and may allow on-path attackers to read / modify confidential data in transit.

EPSS: Низкий
github логотип

GHSA-3rjh-cgv2-5vr4

больше 4 лет назад

Directory traversal vulnerability in filemanager.asp for Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arbitrary files, and execute commands, via a .. (dot dot) in the OpenPath parameter.

EPSS: Низкий
github логотип

GHSA-3rjg-j65w-6v3j

8 месяцев назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-3rjg-j575-7f6p

больше 4 лет назад

Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-3rjg-j22m-wrv3

больше 4 лет назад

A mediaforaction expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

EPSS: Низкий
github логотип

GHSA-3rjg-g3j8-q837

больше 4 лет назад

D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formLanguageChange. This vulnerability allows attackers to cause a Denial of Service (DoS) via the nextPage parameter.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3rjg-ff6r-x2c7

больше 2 лет назад

A vulnerability was found in Rebuild up to 3.5.5. It has been classified as problematic. Affected is the function getFileOfData of the file /filex/read-raw. The manipulation of the argument url leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252456.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-3rjg-586v-gcmf

больше 4 лет назад

Beauty Parlour Booking Script 1.0 has SQL Injection via the /list gender or city parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3rjf-4xj2-6g8f

больше 4 лет назад

** DISPUTED ** Race condition in Norman Security Suite PRO 8.0 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.

EPSS: Низкий
github логотип

GHSA-3rjc-xpqg-5mh4

больше 3 лет назад

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3rjc-6hx2-f4rh

почти 2 года назад

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "sta_log_htm" API which are not properly sanitized before being concatenated to OS level commands.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3rjc-33r8-4463

больше 4 лет назад

Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1 and 11.1.1.6.0 allows remote attackers to affect integrity via unknown vectors related to Content Server.

EPSS: Низкий
github логотип

GHSA-3rj9-ppgw-ffcc

около 1 года назад

In the PatientService.pl service, the "getPatientIdentifier" function is vulnerable to SQL injection through the "pesel" parameter.

EPSS: Низкий
github логотип

GHSA-3rj8-qvqp-3335

больше 4 лет назад

Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-3rj8-qrpc-rrvr

около 2 месяцев назад

HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form of authentication in another browser. This allows any network user to invoke these APIs and interact with the application without verification of their identity or authorization level.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3rj8-3jwx-jcjj

больше 4 лет назад

Amberdms Billing System (ABS) before 1.4.1, when a multi-instance installation is configured, might allow local users to obtain sensitive information by reading the cache in between runs of the include/cron/services_usage.php cron job.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3rjm-q6hg-6jw8

RealOne Player 2.0 Build 6.0.11.872 allows remote attackers to cause a denial of service (array out-of-bounds access and application crash) via a crafted .aiff file.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3rjm-jwr3-fh58

Buffer overflow in the Napster client beta 5 allows remote attackers to cause a denial of service via a long message.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3rjj-rpg2-4f2q

Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Branch Intelligent Management System Software Module (aka BIMS) allows remote attackers to obtain sensitive information via unknown vectors, aka ZDI-CAN-1607.

38%
Средний
больше 4 лет назад
github логотип
GHSA-3rjh-r4h7-c3mq

Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic controller overload. This type of attack can be carried out remotely over radio frequency.

CVSS3: 5.3
0%
Низкий
23 дня назад
github логотип
GHSA-3rjh-fcp5-cg7v

In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization is not secure by TLS and may allow on-path attackers to read / modify confidential data in transit.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3rjh-cgv2-5vr4

Directory traversal vulnerability in filemanager.asp for Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arbitrary files, and execute commands, via a .. (dot dot) in the OpenPath parameter.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-3rjg-j65w-6v3j

Rejected reason: Not used

8 месяцев назад
github логотип
GHSA-3rjg-j575-7f6p

Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.

CVSS3: 4.7
3%
Низкий
больше 4 лет назад
github логотип
GHSA-3rjg-j22m-wrv3

A mediaforaction expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3rjg-g3j8-q837

D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formLanguageChange. This vulnerability allows attackers to cause a Denial of Service (DoS) via the nextPage parameter.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3rjg-ff6r-x2c7

A vulnerability was found in Rebuild up to 3.5.5. It has been classified as problematic. Affected is the function getFileOfData of the file /filex/read-raw. The manipulation of the argument url leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252456.

CVSS3: 3.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3rjg-586v-gcmf

Beauty Parlour Booking Script 1.0 has SQL Injection via the /list gender or city parameter.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3rjf-4xj2-6g8f

** DISPUTED ** Race condition in Norman Security Suite PRO 8.0 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3rjc-xpqg-5mh4

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3rjc-6hx2-f4rh

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "sta_log_htm" API which are not properly sanitized before being concatenated to OS level commands.

CVSS3: 7.2
1%
Низкий
почти 2 года назад
github логотип
GHSA-3rjc-33r8-4463

Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1 and 11.1.1.6.0 allows remote attackers to affect integrity via unknown vectors related to Content Server.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3rj9-ppgw-ffcc

In the PatientService.pl service, the "getPatientIdentifier" function is vulnerable to SQL injection through the "pesel" parameter.

0%
Низкий
около 1 года назад
github логотип
GHSA-3rj8-qvqp-3335

Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

CVSS3: 9.8
25%
Средний
больше 4 лет назад
github логотип
GHSA-3rj8-qrpc-rrvr

HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form of authentication in another browser. This allows any network user to invoke these APIs and interact with the application without verification of their identity or authorization level.

CVSS3: 6.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3rj8-3jwx-jcjj

Amberdms Billing System (ABS) before 1.4.1, when a multi-instance installation is configured, might allow local users to obtain sensitive information by reading the cache in between runs of the include/cron/services_usage.php cron job.

0%
Низкий
больше 4 лет назад

Уязвимостей на страницу