Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 364 463

Количество 364 463

github логотип

GHSA-3pvm-rcw8-28wj

больше 4 лет назад

An unhandled memory allocation failure in Core/AP4IkmsAtom.cpp of Bento 1.5.1-628 causes a NULL pointer dereference, leading to a denial of service (DOS).

EPSS: Низкий
github логотип

GHSA-3pvm-hf79-jr5w

больше 4 лет назад

Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. Cisco Bug IDs: CSCvg70904.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3pvm-h88r-3692

больше 4 лет назад

cPanel before 60.0.25 allows attackers to discover file contents during file copy operations (SEC-185).

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3pvj-q7qj-89fg

около 1 года назад

A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an attacker manages to exhaust the heap space, this error is not detected and may lead to libssh using a partially initialized cipher context. This occurs because the OpenSSL error code returned aliases with the SSH_OK code, resulting in libssh not properly detecting the error returned by the OpenSSL library. This issue can lead to undefined behavior, including compromised data confidentiality and integrity or crashes.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-3pvj-jv98-qhjq

2 месяца назад

Chrome DevTools for agents: daemon.pid write follows symlinks in /tmp fallback runtime directory

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3pvj-gf5m-rhhf

больше 1 года назад

MapUrlToZone Security Feature Bypass Vulnerability

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3pvh-h2xv-4jw7

больше 2 лет назад

PDF-XChange Editor PNG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PNG files. Crafted data in a PNG file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18663.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3pvh-8v83-x7v2

больше 4 лет назад

Allowing long password leads to denial of service in polonel/trudesk in GitHub repository polonel/trudesk prior to 1.2.2. This vulnerability can be abused by doing a DDoS attack for which genuine users will not able to access resources/applications.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3pvh-63gf-j9mw

около 1 месяца назад

LangBot: Authenticated RCE Via MCP Configuration

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3pvh-4h3w-f294

больше 4 лет назад

There is an invalid free in ReadImage in input-bmp.ci that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3pvh-38hr-8x7c

почти 4 года назад

The Trend Controls IC protocol through 2022-05-06 allows Cleartext Transmission of Sensitive Information. According to FSCT-2022-0050, there is a Trend Controls Inter-Controller (IC) protocol cleartext transmission of credentials issue. The affected components are characterized as: Inter-Controller (IC) protocol (57612/UDP). The potential impact is: Compromise of credentials. Several Trend Controls building automation controllers utilize the Inter-Controller (IC) protocol in for information exchange and automation purposes. This protocol offers authentication in the form of a 4-digit PIN in order to protect access to sensitive operations like strategy uploads and downloads as well as optional 0-30 character username and password protection for web page access protection. Both the PIN and usernames and passwords are transmitted in cleartext, allowing an attacker with passive interception capabilities to obtain these credentials. Credentials are transmitted in cleartext. An attacker w...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3pvg-8h3w-fc9m

больше 4 лет назад

Various Lexmark products have stored XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US.

EPSS: Низкий
github логотип

GHSA-3pvf-vxrv-hh9c

5 месяцев назад

Craft CMS: Low-privilege users could read private asset contents when editing an asset (IDOR)

EPSS: Низкий
github логотип

GHSA-3pvf-vxc3-wr36

больше 4 лет назад

Cross-site request forgery (CSRF) vulnerability in news/admin.php in N-13 News 3.4, 3.7, and 4.0 allows remote attackers to hijack the authentication of administrators for requests that create new users via the options action. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-3pvf-9jm4-6vxf

больше 2 лет назад

An issue in urban_project mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3pvf-92c7-q7p5

больше 2 лет назад

Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3pvf-8762-r99w

больше 4 лет назад

The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate an argument to an unspecified system call, which allows local users to gain privileges via a crafted application, aka "Windows Driver Class Registration Vulnerability."

EPSS: Низкий
github логотип

GHSA-3pvc-h22x-rq5v

5 месяцев назад

The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the ISO9660 filesystem parser where the parse_susp() function trusts len_id, len_des, and len_src fields from the disk image to memcpy data into a stack buffer without verifying that the source data falls within the parsed SUSP block. An attacker can craft a malicious ISO image that causes reads past the end of the SUSP data buffer, and a zero-length SUSP entry can trigger an infinite parsing loop.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-3pvc-g892-vvj8

больше 4 лет назад

SQL injection vulnerability in news.php in DGNews 2.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter in a newslist action. NOTE: this issue can produce resultant cross-site scripting (XSS).

EPSS: Низкий
github логотип

GHSA-3pv8-6f4r-ffg2

3 месяца назад

tar has a PAX header desynchronization issue

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3pvm-rcw8-28wj

An unhandled memory allocation failure in Core/AP4IkmsAtom.cpp of Bento 1.5.1-628 causes a NULL pointer dereference, leading to a denial of service (DOS).

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3pvm-hf79-jr5w

Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. Cisco Bug IDs: CSCvg70904.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3pvm-h88r-3692

cPanel before 60.0.25 allows attackers to discover file contents during file copy operations (SEC-185).

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3pvj-q7qj-89fg

A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an attacker manages to exhaust the heap space, this error is not detected and may lead to libssh using a partially initialized cipher context. This occurs because the OpenSSL error code returned aliases with the SSH_OK code, resulting in libssh not properly detecting the error returned by the OpenSSL library. This issue can lead to undefined behavior, including compromised data confidentiality and integrity or crashes.

CVSS3: 5
1%
Низкий
около 1 года назад
github логотип
GHSA-3pvj-jv98-qhjq

Chrome DevTools for agents: daemon.pid write follows symlinks in /tmp fallback runtime directory

CVSS3: 6.1
0%
Низкий
2 месяца назад
github логотип
GHSA-3pvj-gf5m-rhhf

MapUrlToZone Security Feature Bypass Vulnerability

CVSS3: 4.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-3pvh-h2xv-4jw7

PDF-XChange Editor PNG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PNG files. Crafted data in a PNG file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18663.

CVSS3: 7.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3pvh-8v83-x7v2

Allowing long password leads to denial of service in polonel/trudesk in GitHub repository polonel/trudesk prior to 1.2.2. This vulnerability can be abused by doing a DDoS attack for which genuine users will not able to access resources/applications.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3pvh-63gf-j9mw

LangBot: Authenticated RCE Via MCP Configuration

CVSS3: 8.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3pvh-4h3w-f294

There is an invalid free in ReadImage in input-bmp.ci that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3pvh-38hr-8x7c

The Trend Controls IC protocol through 2022-05-06 allows Cleartext Transmission of Sensitive Information. According to FSCT-2022-0050, there is a Trend Controls Inter-Controller (IC) protocol cleartext transmission of credentials issue. The affected components are characterized as: Inter-Controller (IC) protocol (57612/UDP). The potential impact is: Compromise of credentials. Several Trend Controls building automation controllers utilize the Inter-Controller (IC) protocol in for information exchange and automation purposes. This protocol offers authentication in the form of a 4-digit PIN in order to protect access to sensitive operations like strategy uploads and downloads as well as optional 0-30 character username and password protection for web page access protection. Both the PIN and usernames and passwords are transmitted in cleartext, allowing an attacker with passive interception capabilities to obtain these credentials. Credentials are transmitted in cleartext. An attacker w...

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-3pvg-8h3w-fc9m

Various Lexmark products have stored XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3pvf-vxrv-hh9c

Craft CMS: Low-privilege users could read private asset contents when editing an asset (IDOR)

0%
Низкий
5 месяцев назад
github логотип
GHSA-3pvf-vxc3-wr36

Cross-site request forgery (CSRF) vulnerability in news/admin.php in N-13 News 3.4, 3.7, and 4.0 allows remote attackers to hijack the authentication of administrators for requests that create new users via the options action. NOTE: some of these details are obtained from third party information.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3pvf-9jm4-6vxf

An issue in urban_project mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

CVSS3: 5.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3pvf-92c7-q7p5

Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability

CVSS3: 5.5
7%
Низкий
больше 2 лет назад
github логотип
GHSA-3pvf-8762-r99w

The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate an argument to an unspecified system call, which allows local users to gain privileges via a crafted application, aka "Windows Driver Class Registration Vulnerability."

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3pvc-h22x-rq5v

The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the ISO9660 filesystem parser where the parse_susp() function trusts len_id, len_des, and len_src fields from the disk image to memcpy data into a stack buffer without verifying that the source data falls within the parsed SUSP block. An attacker can craft a malicious ISO image that causes reads past the end of the SUSP data buffer, and a zero-length SUSP entry can trigger an infinite parsing loop.

CVSS3: 4.4
0%
Низкий
5 месяцев назад
github логотип
GHSA-3pvc-g892-vvj8

SQL injection vulnerability in news.php in DGNews 2.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter in a newslist action. NOTE: this issue can produce resultant cross-site scripting (XSS).

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3pv8-6f4r-ffg2

tar has a PAX header desynchronization issue

3 месяца назад

Уязвимостей на страницу