Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 267

Количество 359 267

github логотип

GHSA-3897-2crh-vgmr

2 месяца назад

The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing key without authentication. This is an instance of "CWE-306: Missing Authentication for Critical Function" and "CWE-327: Use of a Broken or Risky Cryptographic Algorithm," and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N (7.5 High).

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-3896-rgxr-mxjp

около 4 лет назад

An integer overflow issue has been reported in the general_composite_rect() function in pixman prior to version 0.32.8. An attacker could exploit this issue to cause an application using pixman to crash or, potentially, execute arbitrary code.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3896-fhmw-qp2v

около 4 лет назад

ACS Advanced Comment System 1.0 is affected by Directory Traversal via an advanced_component_system/index.php?ACS_path=..%2f URI.

EPSS: Средний
github логотип

GHSA-3896-29g2-49jx

4 месяца назад

Missing Authorization vulnerability in ILLID Share This Image share-this-image allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Share This Image: from n/a through <= 2.12.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3895-r4rf-j249

около 4 лет назад

IBM Security Guardium Insights 2.0.1 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 174408.

EPSS: Низкий
github логотип

GHSA-3895-33gv-76p5

больше 2 лет назад

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.2, macOS Ventura 13.6.3, macOS Monterey 12.7.2. An app may be able to monitor keystrokes without user permission.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3894-wcv8-w35r

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allow remote attackers to inject arbitrary web script or HTML via vectors involving templates, a different issue than CVE-2012-1262.

EPSS: Низкий
github логотип

GHSA-3893-j6q6-whq8

больше 4 лет назад

An issue was discovered in CALDERA 2.8.1. When activated, the Human plugin passes the unsanitized name parameter to a python "os.system" function. This allows attackers to use shell metacharacters (e.g., backticks "``" or dollar parenthesis "$()" ) in order to escape the current command and execute arbitrary shell commands.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-3893-7mx9-f68m

больше 4 лет назад

Due to insufficient input validation, SAPUI5 library(vbm) - versions 750, 753, 754, 755, 75, allows an unauthenticated attacker to inject a script into the URL and execute code. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3892-r6vc-28jh

больше 4 лет назад

Use-after-free vulnerability in the RangeData implementation in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3892-qqv6-h2qm

больше 4 лет назад

Stored XSS vulnerability in Jenkins S3 Publisher Plugin

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3892-fhf4-9jgg

больше 4 лет назад

Multiple SQL injection vulnerabilities in DUware DUpaypal Pro 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) iCat parameter to cat.asp, (2) iPro parameter to detail.asp, (3) iSub parameter to sub.asp, (4) iCat parameter to catEdit.asp.

EPSS: Низкий
github логотип

GHSA-3892-f347-5r3f

больше 4 лет назад

The Ads Free. Cz advert (aka cz.inzeratyzdarma.cz) application 1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-3892-2r52-p65m

около 5 лет назад

HTTP Request Smuggling in goliath

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-388x-h72v-g58j

больше 4 лет назад

Certain run-time memory protection mechanisms in the GNU C Library (aka glibc or libc6) print argv[0] and backtrace information, which might allow context-dependent attackers to obtain sensitive information from process memory by executing an incorrect program, as demonstrated by a setuid program that contains a stack-based buffer overflow error, related to the __fortify_fail function in debug/fortify_fail.c, and the __stack_chk_fail (aka stack protection) and __chk_fail (aka FORTIFY_SOURCE) implementations.

EPSS: Низкий
github логотип

GHSA-388x-f5qm-fvjg

около 4 лет назад

Memory leak in the gf_isom_get_root_od function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-388x-5h6x-87xj

больше 4 лет назад

Google Chrome before 14.0.835.163 on Linux does not use the PIC and PIE compiler options for position-independent code, which has unspecified impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-388v-j5gj-fhhc

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in index.php in miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the glang[] parameter in a registernew action.

EPSS: Низкий
github логотип

GHSA-388v-hgcc-fmvm

больше 4 лет назад

IBM FileNet WorkPlace XT could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-388v-c5f8-j95v

больше 4 лет назад

Cross-site request forgery (CSRF) vulnerability on Resource Data Management (RDM) Intuitive 650 TDB Controller devices before 2.1.24 allows remote authenticated users to hijack the authentication of arbitrary users.

CVSS3: 8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3897-2crh-vgmr

The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing key without authentication. This is an instance of "CWE-306: Missing Authentication for Critical Function" and "CWE-327: Use of a Broken or Risky Cryptographic Algorithm," and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N (7.5 High).

CVSS3: 10
0%
Низкий
2 месяца назад
github логотип
GHSA-3896-rgxr-mxjp

An integer overflow issue has been reported in the general_composite_rect() function in pixman prior to version 0.32.8. An attacker could exploit this issue to cause an application using pixman to crash or, potentially, execute arbitrary code.

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-3896-fhmw-qp2v

ACS Advanced Comment System 1.0 is affected by Directory Traversal via an advanced_component_system/index.php?ACS_path=..%2f URI.

21%
Средний
около 4 лет назад
github логотип
GHSA-3896-29g2-49jx

Missing Authorization vulnerability in ILLID Share This Image share-this-image allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Share This Image: from n/a through <= 2.12.

CVSS3: 5.3
0%
Низкий
4 месяца назад
github логотип
GHSA-3895-r4rf-j249

IBM Security Guardium Insights 2.0.1 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 174408.

1%
Низкий
около 4 лет назад
github логотип
GHSA-3895-33gv-76p5

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.2, macOS Ventura 13.6.3, macOS Monterey 12.7.2. An app may be able to monitor keystrokes without user permission.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3894-wcv8-w35r

Multiple cross-site scripting (XSS) vulnerabilities in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13 allow remote attackers to inject arbitrary web script or HTML via vectors involving templates, a different issue than CVE-2012-1262.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3893-j6q6-whq8

An issue was discovered in CALDERA 2.8.1. When activated, the Human plugin passes the unsanitized name parameter to a python "os.system" function. This allows attackers to use shell metacharacters (e.g., backticks "``" or dollar parenthesis "$()" ) in order to escape the current command and execute arbitrary shell commands.

CVSS3: 8.8
20%
Средний
больше 4 лет назад
github логотип
GHSA-3893-7mx9-f68m

Due to insufficient input validation, SAPUI5 library(vbm) - versions 750, 753, 754, 755, 75, allows an unauthenticated attacker to inject a script into the URL and execute code. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3892-r6vc-28jh

Use-after-free vulnerability in the RangeData implementation in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-3892-qqv6-h2qm

Stored XSS vulnerability in Jenkins S3 Publisher Plugin

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3892-fhf4-9jgg

Multiple SQL injection vulnerabilities in DUware DUpaypal Pro 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) iCat parameter to cat.asp, (2) iPro parameter to detail.asp, (3) iSub parameter to sub.asp, (4) iCat parameter to catEdit.asp.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3892-f347-5r3f

The Ads Free. Cz advert (aka cz.inzeratyzdarma.cz) application 1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3892-2r52-p65m

HTTP Request Smuggling in goliath

CVSS3: 7.5
1%
Низкий
около 5 лет назад
github логотип
GHSA-388x-h72v-g58j

Certain run-time memory protection mechanisms in the GNU C Library (aka glibc or libc6) print argv[0] and backtrace information, which might allow context-dependent attackers to obtain sensitive information from process memory by executing an incorrect program, as demonstrated by a setuid program that contains a stack-based buffer overflow error, related to the __fortify_fail function in debug/fortify_fail.c, and the __stack_chk_fail (aka stack protection) and __chk_fail (aka FORTIFY_SOURCE) implementations.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-388x-f5qm-fvjg

Memory leak in the gf_isom_get_root_od function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.

CVSS3: 5.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-388x-5h6x-87xj

Google Chrome before 14.0.835.163 on Linux does not use the PIC and PIE compiler options for position-independent code, which has unspecified impact and attack vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-388v-j5gj-fhhc

Cross-site scripting (XSS) vulnerability in index.php in miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the glang[] parameter in a registernew action.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-388v-hgcc-fmvm

IBM FileNet WorkPlace XT could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-388v-c5f8-j95v

Cross-site request forgery (CSRF) vulnerability on Resource Data Management (RDM) Intuitive 650 TDB Controller devices before 2.1.24 allows remote authenticated users to hijack the authentication of arbitrary users.

CVSS3: 8
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу