Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 364 543

Количество 364 543

github логотип

GHSA-3qgf-m686-2pqj

больше 4 лет назад

Vulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite (component: Outcome-Result). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Customer Interaction History. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Customer Interaction History accessible data. CVSS 3.0 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).

EPSS: Низкий
github логотип

GHSA-3qgf-4qfv-p6fh

6 месяцев назад

HCL AION is affected by a vulnerability where model packaging and distribution mechanisms may not include sufficient authenticity verification. This may allow the possibility of unverified or modified model artifacts being used, potentially leading to integrity concerns or unintended behaviour.

CVSS3: 1.9
EPSS: Низкий
github логотип

GHSA-3qgc-vrvv-mv2r

почти 2 года назад

Memory corruption while processing voice packet with arbitrary data received from ADSP.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3qgc-jrrr-25jv

почти 2 года назад

PHP RCE: A Bypass of CVE-2012-1823, Argument Injection in PHP-CGI

EPSS: Критический
github логотип

GHSA-3qgc-gmq8-h85r

больше 4 лет назад

Xavier PHP Management Panel 2.4 allows SQL injection via the usertoedit parameter to admin/adminuseredit.php or the log_id parameter to admin/editgroup.php.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3qg9-j2gc-w8g9

5 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: io_uring/zcrx: fix page array leak d9f595b9a65e ("io_uring/zcrx: fix leaking pages on sg init fail") fixed a page leakage but didn't free the page array, release it as well.

EPSS: Низкий
github логотип

GHSA-3qg9-h6qr-3w9j

больше 4 лет назад

Buffer overflow in Apple iTunes before 4.8 allows remote attackers to execute arbitrary code via a crafted MPEG4 file.

EPSS: Низкий
github логотип

GHSA-3qg9-cv5p-h6hq

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Horde before 3.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) gzip/tar and (2) css MIME viewers, which do not filter or escape dangerous HTML when extracting and displaying attachments.

EPSS: Низкий
github логотип

GHSA-3qg9-856j-f4jv

больше 4 лет назад

The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote attackers to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

EPSS: Низкий
github логотип

GHSA-3qg9-5cr6-vjmf

больше 4 лет назад

Micro Focus Solutions Business Manager versions prior to 11.4 might reveal certain sensitive information in server log files.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3qg8-hq7j-jj33

3 месяца назад

Duplicate Advisory: OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-3qg8-96ff-3xhq

около 1 года назад

A vulnerability, which was classified as critical, was found in JeeWMS up to 20250504. This affects the function filedeal of the file /systemController/filedeal.do of the component File Handler. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. This product does not use versioning. This is why information about affected and unaffected releases are unavailable.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3qg8-5g3r-79v5

3 месяца назад

praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowing token forgery for any user when PLATFORM_ENV is unset

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3qg7-jq5x-jmf9

11 дней назад

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3qg7-hh88-r5c3

около 3 лет назад

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Andy Moyle Church Admin plugin <= 3.7.5 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3qg7-9j56-rpfq

5 дней назад

Dolibarr 21.0.0 before 24.0.0 contains an authorization bypass vulnerability caused by an inverted boolean condition in the private-project membership check within the clonetasks mass action handler in htdocs/core/actions_massactions.inc.php. Authenticated users with project creation permission but without access to a target private project can exploit the flawed !in_array() check to clone tasks into unauthorized private projects.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3qg7-2p3j-xrqp

около 3 лет назад

Product: AndroidVersions: Android SoCAndroid ID: A-278156680

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3qg6-gw2x-w9cq

больше 4 лет назад

Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
EPSS: Высокий
github логотип

GHSA-3qg6-cc82-q3g9

больше 4 лет назад

epan/dissectors/packet-x509af.c in the X.509AF dissector in Wireshark 2.0.x before 2.0.2 mishandles the algorithm ID, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3qg5-qhw5-vc9x

почти 2 года назад

In mayAdminGrantPermission of AdminRestrictedPermissionsUtils.java, there is a possible way to access the microphone due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3qgf-m686-2pqj

Vulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite (component: Outcome-Result). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Customer Interaction History. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Customer Interaction History accessible data. CVSS 3.0 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3qgf-4qfv-p6fh

HCL AION is affected by a vulnerability where model packaging and distribution mechanisms may not include sufficient authenticity verification. This may allow the possibility of unverified or modified model artifacts being used, potentially leading to integrity concerns or unintended behaviour.

CVSS3: 1.9
0%
Низкий
6 месяцев назад
github логотип
GHSA-3qgc-vrvv-mv2r

Memory corruption while processing voice packet with arbitrary data received from ADSP.

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-3qgc-jrrr-25jv

PHP RCE: A Bypass of CVE-2012-1823, Argument Injection in PHP-CGI

100%
Критический
почти 2 года назад
github логотип
GHSA-3qgc-gmq8-h85r

Xavier PHP Management Panel 2.4 allows SQL injection via the usertoedit parameter to admin/adminuseredit.php or the log_id parameter to admin/editgroup.php.

CVSS3: 7.2
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3qg9-j2gc-w8g9

In the Linux kernel, the following vulnerability has been resolved: io_uring/zcrx: fix page array leak d9f595b9a65e ("io_uring/zcrx: fix leaking pages on sg init fail") fixed a page leakage but didn't free the page array, release it as well.

0%
Низкий
5 месяцев назад
github логотип
GHSA-3qg9-h6qr-3w9j

Buffer overflow in Apple iTunes before 4.8 allows remote attackers to execute arbitrary code via a crafted MPEG4 file.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-3qg9-cv5p-h6hq

Multiple cross-site scripting (XSS) vulnerabilities in Horde before 3.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) gzip/tar and (2) css MIME viewers, which do not filter or escape dangerous HTML when extracting and displaying attachments.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3qg9-856j-f4jv

The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote attackers to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

9%
Низкий
больше 4 лет назад
github логотип
GHSA-3qg9-5cr6-vjmf

Micro Focus Solutions Business Manager versions prior to 11.4 might reveal certain sensitive information in server log files.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3qg8-hq7j-jj33

Duplicate Advisory: OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers

CVSS3: 7.7
3 месяца назад
github логотип
GHSA-3qg8-96ff-3xhq

A vulnerability, which was classified as critical, was found in JeeWMS up to 20250504. This affects the function filedeal of the file /systemController/filedeal.do of the component File Handler. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. This product does not use versioning. This is why information about affected and unaffected releases are unavailable.

CVSS3: 6.3
0%
Низкий
около 1 года назад
github логотип
GHSA-3qg8-5g3r-79v5

praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowing token forgery for any user when PLATFORM_ENV is unset

CVSS3: 9.8
1%
Низкий
3 месяца назад
github логотип
GHSA-3qg7-jq5x-jmf9

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 6.5
0%
Низкий
11 дней назад
github логотип
GHSA-3qg7-hh88-r5c3

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Andy Moyle Church Admin plugin <= 3.7.5 versions.

CVSS3: 7.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-3qg7-9j56-rpfq

Dolibarr 21.0.0 before 24.0.0 contains an authorization bypass vulnerability caused by an inverted boolean condition in the private-project membership check within the clonetasks mass action handler in htdocs/core/actions_massactions.inc.php. Authenticated users with project creation permission but without access to a target private project can exploit the flawed !in_array() check to clone tasks into unauthorized private projects.

CVSS3: 4.3
0%
Низкий
5 дней назад
github логотип
GHSA-3qg7-2p3j-xrqp

Product: AndroidVersions: Android SoCAndroid ID: A-278156680

CVSS3: 9.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-3qg6-gw2x-w9cq

Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
73%
Высокий
больше 4 лет назад
github логотип
GHSA-3qg6-cc82-q3g9

epan/dissectors/packet-x509af.c in the X.509AF dissector in Wireshark 2.0.x before 2.0.2 mishandles the algorithm ID, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

CVSS3: 5.9
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3qg5-qhw5-vc9x

In mayAdminGrantPermission of AdminRestrictedPermissionsUtils.java, there is a possible way to access the microphone due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
0%
Низкий
почти 2 года назад

Уязвимостей на страницу