Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 362 078

Количество 362 078

github логотип

GHSA-3gjj-f2w8-w88q

больше 4 лет назад

modules/rlm_unix/rlm_unix.c in FreeRADIUS before 2.2.0, when unix mode is enabled for user authentication, does not properly check the password expiration in /etc/shadow, which allows remote authenticated users to authenticate using an expired password.

EPSS: Низкий
github логотип

GHSA-3gjj-5f84-j9q6

24 дня назад

Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass no-referrer policy via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3gjh-xgvh-pw38

9 дней назад

Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3gjh-w777-5rg2

около 4 лет назад

Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Food and Beverage Applications. The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows low privileged attacker having Admin - Configuration privilege with network access via HTTP to compromise Oracle Hospitality Reporting and Analytics. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hospitality Reporting and Analytics accessible data as well as unauthorized access to critical data or complete access to all Oracle Hospitality Reporting and Analytics accessible data. CVSS 3.0 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3gjh-jvm6-6pfg

4 месяца назад

A vulnerability exists in the Buffalo Link Station version 1.85-0.01 that allows unauthenticated or guest-level users to enumerate valid usernames and their associated privilege roles. The issue is triggered by modifying a parameter within requests sent to the /nasapi endpoint.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3gjh-9hv9-8275

около 4 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

EPSS: Низкий
github логотип

GHSA-3gjh-47mj-p483

больше 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stephan Spencer SEO Title Tag allows Reflected XSS.This issue affects SEO Title Tag: from n/a through 3.5.9.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3gjh-29fv-8hr6

больше 2 лет назад

Nervos CKB Snappy decompress length can be very large and causes out of memory error

EPSS: Низкий
github логотип

GHSA-3gjh-276x-542v

почти 3 года назад

A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 single sign-on (SSO) for remote access VPN in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to intercept the SAML assertion of a user who is authenticating to a remote access VPN session. This vulnerability is due to insufficient validation of the login URL. An attacker could exploit this vulnerability by persuading a user to access a site that is under the control of the attacker, allowing the attacker to modify the login URL. A successful exploit could allow the attacker to intercept a successful SAML assertion and use that assertion to establish a remote access VPN session toward the affected device with the identity and permissions of the hijacked user, resulting in access to the protected network.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3gjg-87w5-fmgx

около 4 лет назад

Sandline Centraleyezer (On Premises) allows Unrestricted File Upload leading to Stored XSS. An HTML page running a script could be uploaded to the server. When a victim tries to download a CISO Report template, the script is loaded.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3gjg-222q-cwf6

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in BadBlue Personal Edition 1.7.3 allows remote attackers to execute arbitrary script as other users by injecting script into the cleanSearchString() function.

EPSS: Низкий
github логотип

GHSA-3gjf-8gc5-3w3x

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: drm/dp_mst: Fix resetting msg rx state after topology removal If the MST topology is removed during the reception of an MST down reply or MST up request sideband message, the drm_dp_mst_topology_mgr::up_req_recv/down_rep_recv states could be reset from one thread via drm_dp_mst_topology_mgr_set_mst(false), racing with the reading/parsing of the message from another thread via drm_dp_mst_handle_down_rep() or drm_dp_mst_handle_up_req(). The race is possible since the reader/parser doesn't hold any lock while accessing the reception state. This in turn can lead to a memory corruption in the reader/parser as described by commit bd2fccac61b4 ("drm/dp_mst: Fix MST sideband message body length check"). Fix the above by resetting the message reception state if needed before reading/parsing a message. Another solution would be to hold the drm_dp_mst_topology_mgr::lock for the whole duration of the message reception/parsin...

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-3gjf-837m-wxcw

11 дней назад

Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-3gjc-xppq-cq67

больше 4 лет назад

Integer signedness error in Apple QuickTime before 7.7.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted stsz atom in a movie file.

EPSS: Низкий
github логотип

GHSA-3gjc-wq56-9w9h

17 дней назад

Jenkins Summary Display Plugin 1.15 and earlier does not escape the job name in a JavaScript context in build report pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Create or Item/Configure permission.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3gjc-qgpj-p9mw

около 4 лет назад

Open Redirection vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4

EPSS: Низкий
github логотип

GHSA-3gjc-mp82-fj4q

больше 2 лет назад

Duplicate Advisory: TYPO3 Arbitrary File Read via Directory Traversal

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-3gjc-g73c-46x5

6 месяцев назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-3gj9-6vcr-2ph9

больше 2 лет назад

Missing Authorization vulnerability in Adrian Mörchen Embed Google Fonts.This issue affects Embed Google Fonts: from n/a through 3.1.0.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3gj9-56xx-rpr3

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wired Impact Wired Impact Volunteer Management allows Stored XSS. This issue affects Wired Impact Volunteer Management: from n/a through 2.5.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3gjj-f2w8-w88q

modules/rlm_unix/rlm_unix.c in FreeRADIUS before 2.2.0, when unix mode is enabled for user authentication, does not properly check the password expiration in /etc/shadow, which allows remote authenticated users to authenticate using an expired password.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3gjj-5f84-j9q6

Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass no-referrer policy via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 4.3
0%
Низкий
24 дня назад
github логотип
GHSA-3gjh-xgvh-pw38

Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.

CVSS3: 9.8
0%
Низкий
9 дней назад
github логотип
GHSA-3gjh-w777-5rg2

Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Food and Beverage Applications. The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows low privileged attacker having Admin - Configuration privilege with network access via HTTP to compromise Oracle Hospitality Reporting and Analytics. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hospitality Reporting and Analytics accessible data as well as unauthorized access to critical data or complete access to all Oracle Hospitality Reporting and Analytics accessible data. CVSS 3.0 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

CVSS3: 8.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-3gjh-jvm6-6pfg

A vulnerability exists in the Buffalo Link Station version 1.85-0.01 that allows unauthenticated or guest-level users to enumerate valid usernames and their associated privilege roles. The issue is triggered by modifying a parameter within requests sent to the /nasapi endpoint.

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-3gjh-9hv9-8275

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

2%
Низкий
около 4 лет назад
github логотип
GHSA-3gjh-47mj-p483

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stephan Spencer SEO Title Tag allows Reflected XSS.This issue affects SEO Title Tag: from n/a through 3.5.9.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3gjh-29fv-8hr6

Nervos CKB Snappy decompress length can be very large and causes out of memory error

больше 2 лет назад
github логотип
GHSA-3gjh-276x-542v

A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 single sign-on (SSO) for remote access VPN in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to intercept the SAML assertion of a user who is authenticating to a remote access VPN session. This vulnerability is due to insufficient validation of the login URL. An attacker could exploit this vulnerability by persuading a user to access a site that is under the control of the attacker, allowing the attacker to modify the login URL. A successful exploit could allow the attacker to intercept a successful SAML assertion and use that assertion to establish a remote access VPN session toward the affected device with the identity and permissions of the hijacked user, resulting in access to the protected network.

CVSS3: 6.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-3gjg-87w5-fmgx

Sandline Centraleyezer (On Premises) allows Unrestricted File Upload leading to Stored XSS. An HTML page running a script could be uploaded to the server. When a victim tries to download a CISO Report template, the script is loaded.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-3gjg-222q-cwf6

Cross-site scripting (XSS) vulnerability in BadBlue Personal Edition 1.7.3 allows remote attackers to execute arbitrary script as other users by injecting script into the cleanSearchString() function.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3gjf-8gc5-3w3x

In the Linux kernel, the following vulnerability has been resolved: drm/dp_mst: Fix resetting msg rx state after topology removal If the MST topology is removed during the reception of an MST down reply or MST up request sideband message, the drm_dp_mst_topology_mgr::up_req_recv/down_rep_recv states could be reset from one thread via drm_dp_mst_topology_mgr_set_mst(false), racing with the reading/parsing of the message from another thread via drm_dp_mst_handle_down_rep() or drm_dp_mst_handle_up_req(). The race is possible since the reader/parser doesn't hold any lock while accessing the reception state. This in turn can lead to a memory corruption in the reader/parser as described by commit bd2fccac61b4 ("drm/dp_mst: Fix MST sideband message body length check"). Fix the above by resetting the message reception state if needed before reading/parsing a message. Another solution would be to hold the drm_dp_mst_topology_mgr::lock for the whole duration of the message reception/parsin...

CVSS3: 7
0%
Низкий
больше 1 года назад
github логотип
GHSA-3gjf-837m-wxcw

Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
11 дней назад
github логотип
GHSA-3gjc-xppq-cq67

Integer signedness error in Apple QuickTime before 7.7.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted stsz atom in a movie file.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-3gjc-wq56-9w9h

Jenkins Summary Display Plugin 1.15 and earlier does not escape the job name in a JavaScript context in build report pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Create or Item/Configure permission.

CVSS3: 5.4
0%
Низкий
17 дней назад
github логотип
GHSA-3gjc-qgpj-p9mw

Open Redirection vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4

0%
Низкий
около 4 лет назад
github логотип
GHSA-3gjc-mp82-fj4q

Duplicate Advisory: TYPO3 Arbitrary File Read via Directory Traversal

CVSS3: 4.9
больше 2 лет назад
github логотип
GHSA-3gjc-g73c-46x5

Rejected reason: Not used

6 месяцев назад
github логотип
GHSA-3gj9-6vcr-2ph9

Missing Authorization vulnerability in Adrian Mörchen Embed Google Fonts.This issue affects Embed Google Fonts: from n/a through 3.1.0.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3gj9-56xx-rpr3

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wired Impact Wired Impact Volunteer Management allows Stored XSS. This issue affects Wired Impact Volunteer Management: from n/a through 2.5.

CVSS3: 6.5
0%
Низкий
больше 1 года назад

Уязвимостей на страницу