Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 267

Количество 359 267

github логотип

GHSA-3834-9q92-mj44

больше 4 лет назад

Denial of service in Gauntlet Firewall via a malformed ICMP packet.

EPSS: Низкий
github логотип

GHSA-3833-2c44-c48p

10 месяцев назад

Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affect availability.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3832-qfwh-78wc

почти 2 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Sumit Surai Featured Posts with Multiple Custom Groups (FPMCG) allows Reflected XSS.This issue affects Featured Posts with Multiple Custom Groups (FPMCG): from n/a through 4.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3832-gg43-7qm4

около 2 лет назад

Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to directory traversal vulnerability which allows the user to upload new files to the server folder.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3832-cq7m-8xc3

около 2 лет назад

A vulnerability has been found in EnvaySoft FleetCart up to 4.1.1 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument razorpayKeyId leads to information disclosure. The attack can be launched remotely. It is recommended to upgrade the affected component. The identifier VDB-265981 was assigned to this vulnerability.

CVSS3: 5.3
EPSS: Средний
github логотип

GHSA-3832-9276-x7gf

больше 4 лет назад

Improper Certificate Validation in Apache Commons HttpClient

EPSS: Низкий
github логотип

GHSA-382x-f95g-95c7

больше 4 лет назад

The Bunny Run (aka com.stargirlgames.google.bunnyrun) application 1.1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-382x-9fjr-hvxc

5 месяцев назад

Deserialization of Untrusted Data vulnerability in ThemeREX Love Story lovestory allows Object Injection.This issue affects Love Story: from n/a through <= 1.3.12.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-382x-6jh5-7rh9

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix legacy client tracking initialization Get rid of the nfsd4_legacy_tracking_ops->init() call in check_for_legacy_methods(). That will be handled in the caller (nfsd4_client_tracking_init()). Otherwise, we'll wind up calling nfsd4_legacy_tracking_ops->init() twice, and the second time we'll trigger the BUG_ON() in nfsd4_init_recdir().

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-382w-xv39-jcj4

больше 4 лет назад

Libnotify in Apple iOS before 8 and Apple TV before 7 lacks proper bounds checking on write operations, which allows attackers to execute arbitrary code as root via a crafted application.

EPSS: Низкий
github логотип

GHSA-382w-v37j-732p

около 4 лет назад

A vulnerability, which was classified as problematic, has been found in Teleopti WFM up to 7.1.0. Affected by this issue is some unknown functionality of the component Administration. The manipulation as part of JSON leads to information disclosure (Credentials). The attack may be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-382w-q5p9-3f2h

5 месяцев назад

ipmi-oem in FreeIPMI before 1.16.17 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management. It is most commonly used for sensor reading (e.g., CPU temperatures through the ipmi-sensors command within FreeIPMI) and remote power control (the ipmipower command). The ipmi-oem client command implements a set of a IPMI OEM commands for specific hardware vendors. If a user has supported hardware, they may wish to use the ipmi-oem command to send a request to a server to retrieve specific information. Three subcommands were found to have exploitable buffer overflows on response messages. They are: "ipmi-oem dell get-last-post-code - get the last POST code and string describing the error on some Dell servers," "ipmi-oem supermicro extra-firmware-info - get extra firmware info on Super...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-382w-q3v4-xc76

почти 2 года назад

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. Processing a maliciously crafted texture may lead to unexpected app termination.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-382w-3hrq-xh95

больше 4 лет назад

An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a different vulnerability than CVE-2014-4394, CVE-2014-4395, CVE-2014-4396, CVE-2014-4398, CVE-2014-4399, CVE-2014-4400, CVE-2014-4401, and CVE-2014-4416.

EPSS: Низкий
github логотип

GHSA-382v-j99g-hw2p

почти 3 года назад

A vulnerability was found in GeoServer GeoWebCache up to 1.15.1. It has been declared as problematic. This vulnerability affects unknown code of the file /geoserver/gwc/rest.html. The manipulation leads to direct request. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-243592.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-382v-gxj9-ffhc

больше 4 лет назад

Moodle uses predictable password-recovery tokens

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-382v-cr8r-vrf3

почти 3 года назад

In stc, there is a possible out of bounds read due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08048635; Issue ID: ALPS08048635.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-382v-9f98-h3x7

больше 4 лет назад

The (1) uploadify and (2) flowplayer SWF files in Gallery 3 before 3.0.8 do not properly remove query parameters and fragments, which allows remote attackers to have an unspecified impact via a replay attack.

EPSS: Низкий
github логотип

GHSA-382v-76mx-pqx3

7 месяцев назад

Out-of-bounds Write, Heap-based Buffer Overflow vulnerability in Is-Daouda is-Engine.This issue affects is-Engine: before 3.3.4.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-382v-24ph-q459

больше 3 лет назад

Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3834-9q92-mj44

Denial of service in Gauntlet Firewall via a malformed ICMP packet.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3833-2c44-c48p

Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affect availability.

CVSS3: 5.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-3832-qfwh-78wc

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Sumit Surai Featured Posts with Multiple Custom Groups (FPMCG) allows Reflected XSS.This issue affects Featured Posts with Multiple Custom Groups (FPMCG): from n/a through 4.0.

CVSS3: 7.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-3832-gg43-7qm4

Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to directory traversal vulnerability which allows the user to upload new files to the server folder.

CVSS3: 5.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-3832-cq7m-8xc3

A vulnerability has been found in EnvaySoft FleetCart up to 4.1.1 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument razorpayKeyId leads to information disclosure. The attack can be launched remotely. It is recommended to upgrade the affected component. The identifier VDB-265981 was assigned to this vulnerability.

CVSS3: 5.3
19%
Средний
около 2 лет назад
github логотип
GHSA-3832-9276-x7gf

Improper Certificate Validation in Apache Commons HttpClient

9%
Низкий
больше 4 лет назад
github логотип
GHSA-382x-f95g-95c7

The Bunny Run (aka com.stargirlgames.google.bunnyrun) application 1.1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-382x-9fjr-hvxc

Deserialization of Untrusted Data vulnerability in ThemeREX Love Story lovestory allows Object Injection.This issue affects Love Story: from n/a through <= 1.3.12.

CVSS3: 9.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-382x-6jh5-7rh9

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix legacy client tracking initialization Get rid of the nfsd4_legacy_tracking_ops->init() call in check_for_legacy_methods(). That will be handled in the caller (nfsd4_client_tracking_init()). Otherwise, we'll wind up calling nfsd4_legacy_tracking_ops->init() twice, and the second time we'll trigger the BUG_ON() in nfsd4_init_recdir().

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-382w-xv39-jcj4

Libnotify in Apple iOS before 8 and Apple TV before 7 lacks proper bounds checking on write operations, which allows attackers to execute arbitrary code as root via a crafted application.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-382w-v37j-732p

A vulnerability, which was classified as problematic, has been found in Teleopti WFM up to 7.1.0. Affected by this issue is some unknown functionality of the component Administration. The manipulation as part of JSON leads to information disclosure (Credentials). The attack may be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-382w-q5p9-3f2h

ipmi-oem in FreeIPMI before 1.16.17 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management. It is most commonly used for sensor reading (e.g., CPU temperatures through the ipmi-sensors command within FreeIPMI) and remote power control (the ipmipower command). The ipmi-oem client command implements a set of a IPMI OEM commands for specific hardware vendors. If a user has supported hardware, they may wish to use the ipmi-oem command to send a request to a server to retrieve specific information. Three subcommands were found to have exploitable buffer overflows on response messages. They are: "ipmi-oem dell get-last-post-code - get the last POST code and string describing the error on some Dell servers," "ipmi-oem supermicro extra-firmware-info - get extra firmware info on Super...

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-382w-q3v4-xc76

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. Processing a maliciously crafted texture may lead to unexpected app termination.

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-382w-3hrq-xh95

An unspecified integrated graphics driver routine in the Intel Graphics Driver subsystem in Apple OS X before 10.9.5 does not properly validate calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application, a different vulnerability than CVE-2014-4394, CVE-2014-4395, CVE-2014-4396, CVE-2014-4398, CVE-2014-4399, CVE-2014-4400, CVE-2014-4401, and CVE-2014-4416.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-382v-j99g-hw2p

A vulnerability was found in GeoServer GeoWebCache up to 1.15.1. It has been declared as problematic. This vulnerability affects unknown code of the file /geoserver/gwc/rest.html. The manipulation leads to direct request. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-243592.

CVSS3: 5.3
1%
Низкий
почти 3 года назад
github логотип
GHSA-382v-gxj9-ffhc

Moodle uses predictable password-recovery tokens

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-382v-cr8r-vrf3

In stc, there is a possible out of bounds read due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08048635; Issue ID: ALPS08048635.

CVSS3: 6.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-382v-9f98-h3x7

The (1) uploadify and (2) flowplayer SWF files in Gallery 3 before 3.0.8 do not properly remove query parameters and fragments, which allows remote attackers to have an unspecified impact via a replay attack.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-382v-76mx-pqx3

Out-of-bounds Write, Heap-based Buffer Overflow vulnerability in Is-Daouda is-Engine.This issue affects is-Engine: before 3.3.4.

CVSS3: 6.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-382v-24ph-q459

Adobe Dimension versions 3.4.7 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу