Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 364 463

Количество 364 463

github логотип

GHSA-3q2f-qcg5-6425

больше 4 лет назад

A vulnerability in the TLS protocol implementation of legacy Cisco ASA 5500 Series (ASA 5505, 5510, 5520, 5540, and 5550) devices could allow an unauthenticated, remote attacker to access sensitive information, aka a Return of Bleichenbacher's Oracle Threat (ROBOT) attack. An attacker could iteratively query a server running a vulnerable TLS stack implementation to perform cryptanalytic operations that may allow decryption of previously captured TLS sessions. Cisco Bug IDs: CSCvg97652.

CVSS3: 5.9
EPSS: Средний
github логотип

GHSA-3q2f-pq2q-f9qf

почти 2 года назад

TP-Link TL-IPC42C V4.0_20211227_1.0.16 is vulnerable to command injection due to the lack of malicious code verification on both the frontend and backend.

CVSS3: 8
EPSS: Средний
github логотип

GHSA-3q2f-m5vm-7r8q

больше 4 лет назад

An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions before 7.20A.202.307. A Cross-Site Request Forgery (CSRF) vulnerability in the management web interface allows remote attackers to execute malicious and unauthorized actions, because CSRFProtection=1 is not a default and is not documented.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3q2f-h5rm-7qv7

больше 4 лет назад

An ACL bypass flaw was found in pacemaker before 1.1.24-rc1 and 2.0.5-rc2. An attacker having a local account on the cluster and in the haclient group could use IPC communication with various daemons directly to perform certain tasks that they would be prevented by ACLs from doing if they went through the configuration.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3q2c-pvp5-3cqp

больше 2 лет назад

Verifying a certificate chain which contains a certificate with an unknown public key algorithm will cause Certificate.Verify to panic. This affects all crypto/tls clients, and servers that set Config.ClientAuth to VerifyClientCertIfGiven or RequireAndVerifyClientCert. The default behavior is for TLS servers to not verify client certificates.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3q2c-9v2r-vjgj

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in WebTester 5.0.20060927 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to POST parameters to multiple files.

EPSS: Низкий
github логотип

GHSA-3q29-89cr-qgvj

больше 4 лет назад

GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3q29-6c6h-84hh

около 4 лет назад

The Guest account feature in Mattermost version 6.7.0 and earlier fails to properly restrict the permissions, which allows a guest user to fetch a list of all public channels in the team, in spite of not being part of those channels.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3q28-xfw3-2q35

больше 4 лет назад

phpMyAdmin XSS Vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3q28-wqh2-j2f3

больше 4 лет назад

An unlimited recursion in DxeCore in EDK II.

EPSS: Низкий
github логотип

GHSA-3q28-qjrv-qr39

6 месяцев назад

Tinyauth vulnerable to TOTP/2FA bypass via OIDC authorize endpoint

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-3q28-p7pm-8p98

больше 4 лет назад

The firmware on Cisco Unified IP phones 8961, 9951, and 9971 uses weak permissions for memory block devices, which allows local users to gain privileges by mounting a device with a setuid file in its filesystem, aka Bug ID CSCui04382.

EPSS: Низкий
github логотип

GHSA-3q28-p6jr-9gpc

больше 4 лет назад

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-3q28-mmq2-xhcr

больше 4 лет назад

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6220 before 1.1.0.100 and R6230 before 1.1.0.100.

EPSS: Низкий
github логотип

GHSA-3q28-9x2c-2fcm

больше 4 лет назад

In aee driver, there is a possible reference count mistake due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06209201; Issue ID: ALPS06209201.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3q28-7xrx-5524

больше 4 лет назад

An issue was discovered in Adobe Digital Editions 4.5.6 and earlier versions. An exploitable memory corruption vulnerability exists, which could lead to disclosure of memory addresses.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3q28-538h-7pqq

почти 2 года назад

Application is vulnerable to Cross Site Scripting (XSS) an authenticated attacker with users’ permissions can modify a variable with a payload.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3q27-8g46-2vwm

около 2 лет назад

Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-3q27-7qjq-p9c5

5 месяцев назад

Grafana public dashboards disclose all direct mode datasources

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3q27-5m93-xfm4

больше 1 года назад

Avi Load Balancer contains an unauthenticated blind SQL Injection vulnerability which was privately reported to VMware. Patches are available to remediate this vulnerability in affected VMware products.  A malicious user with network access may be able to use specially crafted SQL queries to gain database access.

CVSS3: 8.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3q2f-qcg5-6425

A vulnerability in the TLS protocol implementation of legacy Cisco ASA 5500 Series (ASA 5505, 5510, 5520, 5540, and 5550) devices could allow an unauthenticated, remote attacker to access sensitive information, aka a Return of Bleichenbacher's Oracle Threat (ROBOT) attack. An attacker could iteratively query a server running a vulnerable TLS stack implementation to perform cryptanalytic operations that may allow decryption of previously captured TLS sessions. Cisco Bug IDs: CSCvg97652.

CVSS3: 5.9
13%
Средний
больше 4 лет назад
github логотип
GHSA-3q2f-pq2q-f9qf

TP-Link TL-IPC42C V4.0_20211227_1.0.16 is vulnerable to command injection due to the lack of malicious code verification on both the frontend and backend.

CVSS3: 8
10%
Средний
почти 2 года назад
github логотип
GHSA-3q2f-m5vm-7r8q

An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions before 7.20A.202.307. A Cross-Site Request Forgery (CSRF) vulnerability in the management web interface allows remote attackers to execute malicious and unauthorized actions, because CSRFProtection=1 is not a default and is not documented.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3q2f-h5rm-7qv7

An ACL bypass flaw was found in pacemaker before 1.1.24-rc1 and 2.0.5-rc2. An attacker having a local account on the cluster and in the haclient group could use IPC communication with various daemons directly to perform certain tasks that they would be prevented by ACLs from doing if they went through the configuration.

CVSS3: 7.2
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3q2c-pvp5-3cqp

Verifying a certificate chain which contains a certificate with an unknown public key algorithm will cause Certificate.Verify to panic. This affects all crypto/tls clients, and servers that set Config.ClientAuth to VerifyClientCertIfGiven or RequireAndVerifyClientCert. The default behavior is for TLS servers to not verify client certificates.

CVSS3: 5.9
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3q2c-9v2r-vjgj

Multiple cross-site scripting (XSS) vulnerabilities in WebTester 5.0.20060927 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to POST parameters to multiple files.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3q29-89cr-qgvj

GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc.

CVSS3: 5.3
3%
Низкий
больше 4 лет назад
github логотип
GHSA-3q29-6c6h-84hh

The Guest account feature in Mattermost version 6.7.0 and earlier fails to properly restrict the permissions, which allows a guest user to fetch a list of all public channels in the team, in spite of not being part of those channels.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-3q28-xfw3-2q35

phpMyAdmin XSS Vulnerability

CVSS3: 6.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3q28-wqh2-j2f3

An unlimited recursion in DxeCore in EDK II.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3q28-qjrv-qr39

Tinyauth vulnerable to TOTP/2FA bypass via OIDC authorize endpoint

CVSS3: 8.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-3q28-p7pm-8p98

The firmware on Cisco Unified IP phones 8961, 9951, and 9971 uses weak permissions for memory block devices, which allows local users to gain privileges by mounting a device with a setuid file in its filesystem, aka Bug ID CSCui04382.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3q28-p6jr-9gpc

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to arbitrary code execution.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3q28-mmq2-xhcr

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6220 before 1.1.0.100 and R6230 before 1.1.0.100.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3q28-9x2c-2fcm

In aee driver, there is a possible reference count mistake due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06209201; Issue ID: ALPS06209201.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3q28-7xrx-5524

An issue was discovered in Adobe Digital Editions 4.5.6 and earlier versions. An exploitable memory corruption vulnerability exists, which could lead to disclosure of memory addresses.

CVSS3: 5.3
3%
Низкий
больше 4 лет назад
github логотип
GHSA-3q28-538h-7pqq

Application is vulnerable to Cross Site Scripting (XSS) an authenticated attacker with users’ permissions can modify a variable with a payload.

CVSS3: 4.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-3q27-8g46-2vwm

Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine.

CVSS3: 9.1
1%
Низкий
около 2 лет назад
github логотип
GHSA-3q27-7qjq-p9c5

Grafana public dashboards disclose all direct mode datasources

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-3q27-5m93-xfm4

Avi Load Balancer contains an unauthenticated blind SQL Injection vulnerability which was privately reported to VMware. Patches are available to remediate this vulnerability in affected VMware products.  A malicious user with network access may be able to use specially crafted SQL queries to gain database access.

CVSS3: 8.6
1%
Низкий
больше 1 года назад

Уязвимостей на страницу