Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 362 078

Количество 362 078

github логотип

GHSA-3gg5-c54v-vxvr

больше 4 лет назад

xpdf PDF viewer client earlier than 0.91 allows local users to overwrite arbitrary files via a symlink attack.

EPSS: Низкий
github логотип

GHSA-3gg5-933f-4wgh

около 4 лет назад

An elevation of privilege vulnerability exists when Group Policy improperly checks access, aka 'Group Policy Elevation of Privilege Vulnerability'.

EPSS: Низкий
github логотип

GHSA-3gg4-vpvx-4gr9

10 месяцев назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Hosts templates configuration modules) allows Stored XSS by users with elevated privileges. This issue affects Infra Monitoring: from 24.10.0 before 24.10.13, from 24.04.0 before 24.04.18, from 23.10.0 before 23.10.28.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-3gg4-v4m9-rj55

больше 2 лет назад

Lantronix XPort sends weakly encoded credentials within web request headers.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-3gg4-6p9p-6fgc

больше 4 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-3gg4-6hqg-2vjx

больше 4 лет назад

Logstash Logs Sensitive Information

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3gg4-3mqm-xx5v

больше 4 лет назад

CoreText in Apple iOS before 9.1, OS X before 10.11.1, and iTunes before 12.3.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6975 and CVE-2015-6992.

EPSS: Низкий
github логотип

GHSA-3gg3-qcqf-2r64

около 4 лет назад

IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 could disclose sensitive information due to responding to unauthenticated HTTP requests. IBM X-Force ID: 184180.

EPSS: Низкий
github логотип

GHSA-3gg3-cwcp-3cpw

4 месяца назад

A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM attacker to impersonate managed devices. Due to insufficient SSH host key validation an attacker can perform a machine-in-the-middle attack on the SSH connections from Apstra to managed devices, enabling an attacker to impersonate a managed device and capture user credentials. This issue affects all versions of Apstra before 6.1.1.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-3gfx-cq94-vpjw

больше 4 лет назад

The TNS Listener in Oracle 10g allows remote attackers to cause a denial of service (listener crash) via a malformed service_register_NSGR request containing a value that is used as an invalid offset for a pointer that references incorrect memory.

EPSS: Низкий
github логотип

GHSA-3gfx-c6cm-vch8

больше 4 лет назад

Heap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3gfw-xw8c-gm3c

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Complianz, Really Simple Plugins Complianz Premium allows Cross-Site Request Forgery.This issue affects Complianz: from n/a through 6.4.5; Complianz Premium: from n/a through 6.4.7.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3gfv-wh5m-jv67

около 4 лет назад

The drxhello package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3gfv-q5hp-jpcf

8 дней назад

OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By associating another project's QoS policy with an amphora, an authenticated user may prevent deletion of that policy. All Octavia deployments are affected.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3gfv-m98r-3x9r

больше 4 лет назад

Vulnerability in the Oracle Financial Services Market Risk Measurement and Management component of Oracle Financial Services Applications (subcomponent: User Interface). The supported version that is affected is 8.0.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Market Risk Measurement and Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Market Risk Measurement and Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Financial Services Market Risk Measurement and Management accessible data. CVSS 3.0 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3gfr-cm88-25f2

больше 4 лет назад

Iris 3.8 before build 1548, as used in Xpient point of sale (POS) systems, allows remote attackers to execute arbitrary commands via a crafted request to TCP port 7510, as demonstrated by opening the cash drawer.

EPSS: Средний
github логотип

GHSA-3gfr-938g-v48x

больше 3 лет назад

When resizing a popup after requesting fullscreen access, the popup would not display the fullscreen notification. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3gfq-rwmc-frjq

около 4 лет назад

Inadequate security UI in iOS UI in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3gfq-rwf3-mgrm

больше 4 лет назад

The HP ProLiant SL Advanced Power Manager (SL-APM) with firmware before 1.20 does not properly validate users, which allows remote attackers to cause a denial of service via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3gfq-rr85-4p5x

около 1 месяца назад

A vulnerability was identified in macrozheng mall up to 1.0.3. This impacts an unknown function of the file /returnApply/create of the component Portal Endpoint. The manipulation of the argument orderId leads to improper control of resource identifiers. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor deleted the GitHub issue for this vulnerability without any explanation.

CVSS3: 6.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3gg5-c54v-vxvr

xpdf PDF viewer client earlier than 0.91 allows local users to overwrite arbitrary files via a symlink attack.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3gg5-933f-4wgh

An elevation of privilege vulnerability exists when Group Policy improperly checks access, aka 'Group Policy Elevation of Privilege Vulnerability'.

4%
Низкий
около 4 лет назад
github логотип
GHSA-3gg4-vpvx-4gr9

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Hosts templates configuration modules) allows Stored XSS by users with elevated privileges. This issue affects Infra Monitoring: from 24.10.0 before 24.10.13, from 24.04.0 before 24.04.18, from 23.10.0 before 23.10.28.

CVSS3: 6.8
0%
Низкий
10 месяцев назад
github логотип
GHSA-3gg4-v4m9-rj55

Lantronix XPort sends weakly encoded credentials within web request headers.

CVSS3: 5.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3gg4-6p9p-6fgc

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3gg4-6hqg-2vjx

Logstash Logs Sensitive Information

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3gg4-3mqm-xx5v

CoreText in Apple iOS before 9.1, OS X before 10.11.1, and iTunes before 12.3.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6975 and CVE-2015-6992.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-3gg3-qcqf-2r64

IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 could disclose sensitive information due to responding to unauthenticated HTTP requests. IBM X-Force ID: 184180.

1%
Низкий
около 4 лет назад
github логотип
GHSA-3gg3-cwcp-3cpw

A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM attacker to impersonate managed devices. Due to insufficient SSH host key validation an attacker can perform a machine-in-the-middle attack on the SSH connections from Apstra to managed devices, enabling an attacker to impersonate a managed device and capture user credentials. This issue affects all versions of Apstra before 6.1.1.

CVSS3: 8.7
0%
Низкий
4 месяца назад
github логотип
GHSA-3gfx-cq94-vpjw

The TNS Listener in Oracle 10g allows remote attackers to cause a denial of service (listener crash) via a malformed service_register_NSGR request containing a value that is used as an invalid offset for a pointer that references incorrect memory.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-3gfx-c6cm-vch8

Heap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

CVSS3: 7.8
7%
Низкий
больше 4 лет назад
github логотип
GHSA-3gfw-xw8c-gm3c

Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Complianz, Really Simple Plugins Complianz Premium allows Cross-Site Request Forgery.This issue affects Complianz: from n/a through 6.4.5; Complianz Premium: from n/a through 6.4.7.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3gfv-wh5m-jv67

The drxhello package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-3gfv-q5hp-jpcf

OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By associating another project's QoS policy with an amphora, an authenticated user may prevent deletion of that policy. All Octavia deployments are affected.

CVSS3: 4.3
0%
Низкий
8 дней назад
github логотип
GHSA-3gfv-m98r-3x9r

Vulnerability in the Oracle Financial Services Market Risk Measurement and Management component of Oracle Financial Services Applications (subcomponent: User Interface). The supported version that is affected is 8.0.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Market Risk Measurement and Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Market Risk Measurement and Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Financial Services Market Risk Measurement and Management accessible data. CVSS 3.0 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

CVSS3: 8.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3gfr-cm88-25f2

Iris 3.8 before build 1548, as used in Xpient point of sale (POS) systems, allows remote attackers to execute arbitrary commands via a crafted request to TCP port 7510, as demonstrated by opening the cash drawer.

16%
Средний
больше 4 лет назад
github логотип
GHSA-3gfr-938g-v48x

When resizing a popup after requesting fullscreen access, the popup would not display the fullscreen notification. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3gfq-rwmc-frjq

Inadequate security UI in iOS UI in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-3gfq-rwf3-mgrm

The HP ProLiant SL Advanced Power Manager (SL-APM) with firmware before 1.20 does not properly validate users, which allows remote attackers to cause a denial of service via unspecified vectors.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3gfq-rr85-4p5x

A vulnerability was identified in macrozheng mall up to 1.0.3. This impacts an unknown function of the file /returnApply/create of the component Portal Endpoint. The manipulation of the argument orderId leads to improper control of resource identifiers. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor deleted the GitHub issue for this vulnerability without any explanation.

CVSS3: 6.3
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу