Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 363 419

Количество 363 419

github логотип

GHSA-3mc9-3c2c-xqg4

почти 3 года назад

Windows Graphics Component Elevation of Privilege Vulnerability

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-3mc8-x7c9-wfw9

8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: tcp: use dst_dev_rcu() in tcp_fastopen_active_disable_ofo_check() Use RCU to avoid a pair of atomic operations and a potential UAF on dst_dev()->flags.

EPSS: Низкий
github логотип

GHSA-3mc8-g687-m3cf

больше 4 лет назад

A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0787, CVE-2019-1290, CVE-2019-1291.

EPSS: Средний
github логотип

GHSA-3mc8-8xr7-cw36

больше 4 лет назад

Unspecified vulnerability in HP StorageWorks Command View Advanced Edition for XP before 5.6.0-01, XP Replication Monitor before 5.6.0-01, and XP Tiered Storage Manager before 5.5.0-02 allows local users to access other accounts via unspecified vectors during registration or addition of new users.

EPSS: Низкий
github логотип

GHSA-3mc7-mrgm-m6rp

больше 4 лет назад

The ReadSGIImage function in sgi.c in ImageMagick 7.0.5-4 allows remote attackers to consume an amount of available memory via a crafted file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3mc7-4q67-w48m

почти 4 года назад

Uncontrolled Resource Consumption in snakeyaml

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3mc6-qj9j-9v96

6 месяцев назад

Glory RBG-100 recycler systems using the ISPK-08 software component contain hard-coded operating system credentials that allow remote authentication to the underlying Linux system. Multiple local user accounts, including accounts with administrative privileges, were found to have fixed, embedded passwords. An attacker with network access to exposed services such as SSH may authenticate using these credentials and gain unauthorized access to the system. Successful exploitation allows remote access with elevated privileges and may result in full system compromise.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3mc6-pq7x-jqgv

около 1 месяца назад

A vulnerability was identified in zevorn rt-claw up to 0.2.0. This affects the function claw_net_get/claw_net_post of the file claw/tools/tool_net.c of the component http_request. Such manipulation of the argument url leads to server-side request forgery. The attack may be performed from remote. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3mc5-w7jh-66fj

больше 4 лет назад

BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier, and 7.0 SP5 and earlier, when fullyDelegatedAuthorization is enabled for a servlet, does not cause servlet deployment to fail when failures occur in authorization or role providers, which might prevent the servlet from being "fully protected."

EPSS: Низкий
github логотип

GHSA-3mc5-mh5x-w6p9

около 3 лет назад

An issue was discovered in Geomatika IsiGeo Web 6.0. It allows remote authenticated users to execute commands.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3mc5-fgv9-jrpv

больше 4 лет назад

IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 180761.

EPSS: Низкий
github логотип

GHSA-3mc5-93px-3fm6

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Open Business Management (OBM) 2.4.0-rc13 and probably earlier allow remote attackers to inject arbitrary web script or HTML via the (1) tf_delegation, (2) tf_ip, or (3) tf_name parameter in a search action to host/host_index.php; (4) login parameter to obm.php; or (5) tf_user parameter in a search action to group/group_index.php.

EPSS: Низкий
github логотип

GHSA-3mc4-hxgv-pc7g

4 месяца назад

Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic. Panorama and Cloud NGFW are not impacted by these vulnerabilities.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3mc3-h6g8-mp72

больше 4 лет назад

IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or execute arbitrary code via a crafted file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!LdrpResCompareResourceNames+0x0000000000000087."

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3mc3-9p24-hxhq

больше 4 лет назад

Delta Electronics TPEditor Versions 1.97 and prior. A heap-based buffer overflow may be exploited by processing a specially crafted project file. Successful exploitation of this vulnerability may allow an attacker to read/modify information, execute arbitrary code, and/or crash the application.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3mc3-5mhp-vcrq

больше 4 лет назад

SQL injection vulnerability in browse.php in TriO 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

EPSS: Низкий
github логотип

GHSA-3mc2-p59g-jpp4

около 2 месяцев назад

Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H: before DKCMAIN Ver. 93-07-26-xx/00, GUM Ver. 93-07-26/00; Hitachi Virtual Storage Platform 5100, 5500, 5100H, 5500H, 5200, 5600, 5200H, 5600H: before DKCMAIN Ver. 90-09-27-00/00, GUM Ver. 90-09-27/00; Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900: before DKCMAIN Ver. 88-08-16-xx/00, GUM Ver. 88-08-20/00.

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-3mc2-p4vf-gp83

больше 4 лет назад

The NVIDIA media driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 27253079.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-3mc2-42q3-6cgp

12 месяцев назад

In pfSense CE /suricata/suricata_app_parsers.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before being directly displayed. This can result in stored cross-site scripting. The attacker must be authenticated with at least "WebCfg - Services: suricata package" permissions.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3m9x-xqwx-4x9c

около 1 года назад

A vulnerability classified as critical has been found in D-Link DCS-5020L 1.01_B2. This affects the function websReadEvent of the file /rame/ptdc.cgi. The manipulation of the argument Authorization leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3mc9-3c2c-xqg4

Windows Graphics Component Elevation of Privilege Vulnerability

CVSS3: 7
6%
Низкий
почти 3 года назад
github логотип
GHSA-3mc8-x7c9-wfw9

In the Linux kernel, the following vulnerability has been resolved: tcp: use dst_dev_rcu() in tcp_fastopen_active_disable_ofo_check() Use RCU to avoid a pair of atomic operations and a potential UAF on dst_dev()->flags.

0%
Низкий
8 месяцев назад
github логотип
GHSA-3mc8-g687-m3cf

A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0787, CVE-2019-1290, CVE-2019-1291.

12%
Средний
больше 4 лет назад
github логотип
GHSA-3mc8-8xr7-cw36

Unspecified vulnerability in HP StorageWorks Command View Advanced Edition for XP before 5.6.0-01, XP Replication Monitor before 5.6.0-01, and XP Tiered Storage Manager before 5.5.0-02 allows local users to access other accounts via unspecified vectors during registration or addition of new users.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3mc7-mrgm-m6rp

The ReadSGIImage function in sgi.c in ImageMagick 7.0.5-4 allows remote attackers to consume an amount of available memory via a crafted file.

CVSS3: 6.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-3mc7-4q67-w48m

Uncontrolled Resource Consumption in snakeyaml

CVSS3: 7.5
2%
Низкий
почти 4 года назад
github логотип
GHSA-3mc6-qj9j-9v96

Glory RBG-100 recycler systems using the ISPK-08 software component contain hard-coded operating system credentials that allow remote authentication to the underlying Linux system. Multiple local user accounts, including accounts with administrative privileges, were found to have fixed, embedded passwords. An attacker with network access to exposed services such as SSH may authenticate using these credentials and gain unauthorized access to the system. Successful exploitation allows remote access with elevated privileges and may result in full system compromise.

CVSS3: 9.8
1%
Низкий
6 месяцев назад
github логотип
GHSA-3mc6-pq7x-jqgv

A vulnerability was identified in zevorn rt-claw up to 0.2.0. This affects the function claw_net_get/claw_net_post of the file claw/tools/tool_net.c of the component http_request. Such manipulation of the argument url leads to server-side request forgery. The attack may be performed from remote. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 7.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3mc5-w7jh-66fj

BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier, and 7.0 SP5 and earlier, when fullyDelegatedAuthorization is enabled for a servlet, does not cause servlet deployment to fail when failures occur in authorization or role providers, which might prevent the servlet from being "fully protected."

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3mc5-mh5x-w6p9

An issue was discovered in Geomatika IsiGeo Web 6.0. It allows remote authenticated users to execute commands.

CVSS3: 8.8
2%
Низкий
около 3 лет назад
github логотип
GHSA-3mc5-fgv9-jrpv

IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 180761.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mc5-93px-3fm6

Multiple cross-site scripting (XSS) vulnerabilities in Open Business Management (OBM) 2.4.0-rc13 and probably earlier allow remote attackers to inject arbitrary web script or HTML via the (1) tf_delegation, (2) tf_ip, or (3) tf_name parameter in a search action to host/host_index.php; (4) login parameter to obm.php; or (5) tf_user parameter in a search action to group/group_index.php.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mc4-hxgv-pc7g

Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic. Panorama and Cloud NGFW are not impacted by these vulnerabilities.

CVSS3: 7.5
0%
Низкий
4 месяца назад
github логотип
GHSA-3mc3-h6g8-mp72

IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or execute arbitrary code via a crafted file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!LdrpResCompareResourceNames+0x0000000000000087."

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mc3-9p24-hxhq

Delta Electronics TPEditor Versions 1.97 and prior. A heap-based buffer overflow may be exploited by processing a specially crafted project file. Successful exploitation of this vulnerability may allow an attacker to read/modify information, execute arbitrary code, and/or crash the application.

CVSS3: 7.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3mc3-5mhp-vcrq

SQL injection vulnerability in browse.php in TriO 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mc2-p59g-jpp4

Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H: before DKCMAIN Ver. 93-07-26-xx/00, GUM Ver. 93-07-26/00; Hitachi Virtual Storage Platform 5100, 5500, 5100H, 5500H, 5200, 5600, 5200H, 5600H: before DKCMAIN Ver. 90-09-27-00/00, GUM Ver. 90-09-27/00; Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900: before DKCMAIN Ver. 88-08-16-xx/00, GUM Ver. 88-08-20/00.

CVSS3: 8.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3mc2-p4vf-gp83

The NVIDIA media driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 27253079.

CVSS3: 7
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3mc2-42q3-6cgp

In pfSense CE /suricata/suricata_app_parsers.php, the value of the policy_name parameter is not sanitized of HTML-related strings/characters before being directly displayed. This can result in stored cross-site scripting. The attacker must be authenticated with at least "WebCfg - Services: suricata package" permissions.

CVSS3: 5.4
4%
Низкий
12 месяцев назад
github логотип
GHSA-3m9x-xqwx-4x9c

A vulnerability classified as critical has been found in D-Link DCS-5020L 1.01_B2. This affects the function websReadEvent of the file /rame/ptdc.cgi. The manipulation of the argument Authorization leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 8.8
1%
Низкий
около 1 года назад

Уязвимостей на страницу