Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 154

Количество 359 154

github логотип

GHSA-37m2-v8vp-gx9v

9 месяцев назад

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

EPSS: Низкий
github логотип

GHSA-37m2-9j5v-c4v4

около 1 года назад

A path traversal vulnerability exists in the Karel IP1211 IP Phone's web management panel. The /cgi-bin/cgiServer.exx endpoint fails to properly sanitize user input to the page parameter, allowing remote authenticated attackers to access arbitrary files on the underlying system by using crafted path traversal sequences (e.g., ../../). This can expose sensitive files such as /etc/passwd and /etc/shadow.

EPSS: Низкий
github логотип

GHSA-37jx-v87h-x8gc

больше 4 лет назад

Pidgin 2.10.0 uses DBUS for certain cleartext communication, which allows local users to obtain sensitive information via a dbus session monitor.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-37jx-fgfr-x4xh

больше 4 лет назад

Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0107, CVE-2016-0111, CVE-2016-0112, and CVE-2016-0113.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-37jw-xgjq-3fmq

около 4 лет назад

A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to the current namespace of the user performing the upgrade. This flaw can allow an unprivileged user to escalate their privileges to those allowed by the privileged Security Context Constraints.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-37jw-9hhw-q8w8

около 4 лет назад

An elevation of privilege vulnerability exists when the Windows Picker Platform improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Picker Platform Elevation of Privilege Vulnerability'.

EPSS: Низкий
github логотип

GHSA-37jv-v9vv-wxwv

3 месяца назад

Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks. These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash or password.

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-37jv-rq4h-f78r

почти 2 года назад

Missing Authorization vulnerability in Atarim allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Atarim: from n/a through 4.0.1.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-37jr-rxv8-wwqj

около 4 лет назад

In wpas_ctrl_msg_queue_timeout of ctrl_iface_unix.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-168314741

EPSS: Низкий
github логотип

GHSA-37jr-8vrf-hwhp

около 3 лет назад

Improper input validation in the Zoom Desktop Client for Windows before version 5.15.0 may allow an unauthorized user to enable an escalation of privilege via network access.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-37jr-2q49-7p4m

около 1 года назад

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-37jq-2j66-w398

больше 4 лет назад

Apple TV before 6.1 does not properly restrict logging, which allows local users to obtain sensitive information by reading log data.

EPSS: Низкий
github логотип

GHSA-37jp-3q9w-phcm

24 дня назад

A NULL pointer dereference in the MMS Write Named Variable List handler, which may allow a network adjacent attacker to crash the server by sending a WriteRequest with an empty listOfData field.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-37jm-qcw2-gcqg

около 2 месяцев назад

Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-37jm-q7wj-f2wc

почти 2 года назад

MZK-DP300N firmware versions 1.04 and earlier contains a cross-site request forger vulnerability. Viewing a malicious page while logging in to the web management page of the affected product may lead the user to perform unintended operations such as changing the login password, etc.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-37jm-8h4h-w52w

почти 4 года назад

Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /items/manage_item.php.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-37jj-wp7g-7wj4

почти 5 лет назад

Read of uninitialized memory in cdr

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-37jj-q8h7-hv43

почти 2 года назад

The Flat UI Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's flatbtn shortcode in version 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-37jj-p98x-q9ff

больше 2 лет назад

In multiple locations, there is a possible failure to persist or enforce user restrictions due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-37jj-mf3j-h43w

больше 4 лет назад

Multiple stack-based buffer overflows in utilities/smb4k_*.cpp in Smb4K before 0.8.0 allow local users, when present on the Smb4K sudoers list, to gain privileges via unspecified vectors related to the args variable and unspecified other variables, in conjunction with the sudo configuration.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-37m2-v8vp-gx9v

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

9 месяцев назад
github логотип
GHSA-37m2-9j5v-c4v4

A path traversal vulnerability exists in the Karel IP1211 IP Phone's web management panel. The /cgi-bin/cgiServer.exx endpoint fails to properly sanitize user input to the page parameter, allowing remote authenticated attackers to access arbitrary files on the underlying system by using crafted path traversal sequences (e.g., ../../). This can expose sensitive files such as /etc/passwd and /etc/shadow.

1%
Низкий
около 1 года назад
github логотип
GHSA-37jx-v87h-x8gc

Pidgin 2.10.0 uses DBUS for certain cleartext communication, which allows local users to obtain sensitive information via a dbus session monitor.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-37jx-fgfr-x4xh

Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0107, CVE-2016-0111, CVE-2016-0112, and CVE-2016-0113.

CVSS3: 7.5
14%
Средний
больше 4 лет назад
github логотип
GHSA-37jw-xgjq-3fmq

A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to the current namespace of the user performing the upgrade. This flaw can allow an unprivileged user to escalate their privileges to those allowed by the privileged Security Context Constraints.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-37jw-9hhw-q8w8

An elevation of privilege vulnerability exists when the Windows Picker Platform improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Picker Platform Elevation of Privilege Vulnerability'.

1%
Низкий
около 4 лет назад
github логотип
GHSA-37jv-v9vv-wxwv

Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks. These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash or password.

CVSS3: 5.1
0%
Низкий
3 месяца назад
github логотип
GHSA-37jv-rq4h-f78r

Missing Authorization vulnerability in Atarim allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Atarim: from n/a through 4.0.1.

CVSS3: 5.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-37jr-rxv8-wwqj

In wpas_ctrl_msg_queue_timeout of ctrl_iface_unix.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-168314741

0%
Низкий
около 4 лет назад
github логотип
GHSA-37jr-8vrf-hwhp

Improper input validation in the Zoom Desktop Client for Windows before version 5.15.0 may allow an unauthorized user to enable an escalation of privilege via network access.

CVSS3: 8.2
1%
Низкий
около 3 лет назад
github логотип
GHSA-37jr-2q49-7p4m

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
около 1 года назад
github логотип
GHSA-37jq-2j66-w398

Apple TV before 6.1 does not properly restrict logging, which allows local users to obtain sensitive information by reading log data.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-37jp-3q9w-phcm

A NULL pointer dereference in the MMS Write Named Variable List handler, which may allow a network adjacent attacker to crash the server by sending a WriteRequest with an empty listOfData field.

CVSS3: 7.5
0%
Низкий
24 дня назад
github логотип
GHSA-37jm-qcw2-gcqg

Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVSS3: 9.6
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-37jm-q7wj-f2wc

MZK-DP300N firmware versions 1.04 and earlier contains a cross-site request forger vulnerability. Viewing a malicious page while logging in to the web management page of the affected product may lead the user to perform unintended operations such as changing the login password, etc.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-37jm-8h4h-w52w

Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /items/manage_item.php.

CVSS3: 8.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-37jj-wp7g-7wj4

Read of uninitialized memory in cdr

CVSS3: 9.8
2%
Низкий
почти 5 лет назад
github логотип
GHSA-37jj-q8h7-hv43

The Flat UI Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's flatbtn shortcode in version 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-37jj-p98x-q9ff

In multiple locations, there is a possible failure to persist or enforce user restrictions due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-37jj-mf3j-h43w

Multiple stack-based buffer overflows in utilities/smb4k_*.cpp in Smb4K before 0.8.0 allow local users, when present on the Smb4K sudoers list, to gain privileges via unspecified vectors related to the args variable and unspecified other variables, in conjunction with the sudo configuration.

0%
Низкий
больше 4 лет назад

Уязвимостей на страницу