Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 154

Количество 359 154

github логотип

GHSA-37hw-m3rc-6ww4

около 4 лет назад

A memory leak in the unittest_data_add() function in drivers/of/unittest.c in the Linux kernel before 5.3.10 allows attackers to cause a denial of service (memory consumption) by triggering of_fdt_unflatten_tree() failures, aka CID-e13de8fe0d6a.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-37hw-37wh-562h

около 4 лет назад

In Snowtide PDFxStream before 3.7.1 (for Java), a crafted PDF file can trigger an extremely long running computation because of page-tree mishandling.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-37hv-5w7w-hhjw

больше 4 лет назад

A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest and may result in a crash of QEMU or cause undefined behavior due to the access of an uninitialized pointer. The highest threat from this vulnerability is to system availability.

CVSS3: 6
EPSS: Низкий
github логотип

GHSA-37hv-4cjv-mxqq

около 4 лет назад

Windows Kernel Memory Information Disclosure Vulnerability

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-37hr-rhw9-q43g

больше 4 лет назад

Format string vulnerability in TrACESroute 6.0 GOLD (aka NANOG traceroute) allows local users to execute arbitrary code via the -T (terminator) command line argument.

EPSS: Низкий
github логотип

GHSA-37hr-r96j-6hcx

около 3 лет назад

A vulnerability, which was classified as problematic, was found in Creativeitem Ekushey Project Manager CRM 5.0. Affected is an unknown function of the file /index.php/client/message/message_read/xxxxxxxx[random-msg-hash]. The manipulation of the argument message leads to cross site scripting. It is possible to launch the attack remotely. VDB-234426 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-37hr-898c-hc2f

около 4 лет назад

A vulnerability has been identified in SiNVR 3 Central Control Server (CCS) (all versions), SiNVR 3 Video Server (all versions). The streaming service (default port 5410/tcp) of the SiNVR 3 Video Server contains a path traversal vulnerability, that could allow an unauthenticated remote attacker to access and download arbitrary files from the server.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-37hr-3fmf-v449

больше 1 года назад

A vulnerability classified as critical was found in TOTOLINK A6000R 1.0.1-B20201211.2000. Affected by this vulnerability is the function apcli_cancel_wps of the file /usr/lib/lua/luci/controller/mtkwifi.lua. The manipulation leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-37hr-348p-rmf4

около 4 лет назад

Improper handling of multiline messages in node-irc affects matrix-appservice-irc

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-37hq-frhq-c3c6

больше 4 лет назад

index.php in FTP Admin 0.1.0 allows remote attackers to bypass authentication and obtain administrative access via a loggedin parameter with a value of true, as demonstrated by adding a user account.

EPSS: Низкий
github логотип

GHSA-37hq-32h5-h6mj

больше 4 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.0.80. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JT files. Crafted data in a JT file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15375.

EPSS: Низкий
github логотип

GHSA-37hp-xmxv-j842

около 4 лет назад

Juniper Junos OS before 12.1X44-D60, 12.1X46 before 12.1X46-D40, 12.1X47 before 12.1X47-D30, 12.3 before 12.3R11, 12.3X48 before 12.3X48-D20, 13.2 before 13.2R9, 13.2X51 before 13.2X51-D39, 13.3 before 13.3R8, 14.1 before 14.1R6, 14.1X53 before 14.1X53-D30, 14.2 before 14.2R4-S1, 15.1 before 15.1R2, 15.1X49 before 15.1X49-D30, and 16.1 before 16.1R1 allow remote attackers to cause a denial of service (socket consumption) via crafted TCP timestamps.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-37hp-q495-2gv6

6 месяцев назад

code-projects Simple Student Alumni System code-projects v1.0 is vulnerable to SQL Injection in /TracerStudy/recordstudent_edit.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-37hp-765x-j95x

больше 7 лет назад

Django open redirect and possible XSS attack via user-supplied numeric redirect URLs

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-37hm-v5j4-vc79

10 дней назад

A maliciously crafted PDF file, when parsed through Autodesk Revit, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, disclose sensitive data, or execute arbitrary code in the context of the current process.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-37hm-h4p2-3xrx

больше 4 лет назад

Geert Moernaut LSrunasE allows local users to gain privileges by obtaining the encrypted password from a batch file, and constructing a modified batch file that specifies this password in the /password switch and specifies an arbitrary program in the /command switch.

EPSS: Низкий
github логотип

GHSA-37hm-8cwf-jp7f

около 2 лет назад

[A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-37hm-87pw-mw7f

больше 4 лет назад

Clam AntiVirus (ClamAV) 0.88 and earlier allows remote attackers to cause a denial of service (crash) via a malformed base64-encoded MIME attachment that triggers a null pointer dereference.

EPSS: Низкий
github логотип

GHSA-37hm-7427-xp37

больше 4 лет назад

Stack-based buffer overflow in Novell Client 4.91 SP4 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long username in the "forgotten password" dialog.

EPSS: Низкий
github логотип

GHSA-37hm-5m3h-f5px

больше 4 лет назад

gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-37hw-m3rc-6ww4

A memory leak in the unittest_data_add() function in drivers/of/unittest.c in the Linux kernel before 5.3.10 allows attackers to cause a denial of service (memory consumption) by triggering of_fdt_unflatten_tree() failures, aka CID-e13de8fe0d6a.

CVSS3: 7.5
4%
Низкий
около 4 лет назад
github логотип
GHSA-37hw-37wh-562h

In Snowtide PDFxStream before 3.7.1 (for Java), a crafted PDF file can trigger an extremely long running computation because of page-tree mishandling.

CVSS3: 5.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-37hv-5w7w-hhjw

A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest and may result in a crash of QEMU or cause undefined behavior due to the access of an uninitialized pointer. The highest threat from this vulnerability is to system availability.

CVSS3: 6
0%
Низкий
больше 4 лет назад
github логотип
GHSA-37hv-4cjv-mxqq

Windows Kernel Memory Information Disclosure Vulnerability

CVSS3: 6.3
3%
Низкий
около 4 лет назад
github логотип
GHSA-37hr-rhw9-q43g

Format string vulnerability in TrACESroute 6.0 GOLD (aka NANOG traceroute) allows local users to execute arbitrary code via the -T (terminator) command line argument.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-37hr-r96j-6hcx

A vulnerability, which was classified as problematic, was found in Creativeitem Ekushey Project Manager CRM 5.0. Affected is an unknown function of the file /index.php/client/message/message_read/xxxxxxxx[random-msg-hash]. The manipulation of the argument message leads to cross site scripting. It is possible to launch the attack remotely. VDB-234426 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-37hr-898c-hc2f

A vulnerability has been identified in SiNVR 3 Central Control Server (CCS) (all versions), SiNVR 3 Video Server (all versions). The streaming service (default port 5410/tcp) of the SiNVR 3 Video Server contains a path traversal vulnerability, that could allow an unauthenticated remote attacker to access and download arbitrary files from the server.

CVSS3: 7.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-37hr-3fmf-v449

A vulnerability classified as critical was found in TOTOLINK A6000R 1.0.1-B20201211.2000. Affected by this vulnerability is the function apcli_cancel_wps of the file /usr/lib/lua/luci/controller/mtkwifi.lua. The manipulation leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
3%
Низкий
больше 1 года назад
github логотип
GHSA-37hr-348p-rmf4

Improper handling of multiline messages in node-irc affects matrix-appservice-irc

CVSS3: 8
1%
Низкий
около 4 лет назад
github логотип
GHSA-37hq-frhq-c3c6

index.php in FTP Admin 0.1.0 allows remote attackers to bypass authentication and obtain administrative access via a loggedin parameter with a value of true, as demonstrated by adding a user account.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-37hq-32h5-h6mj

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.0.80. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JT files. Crafted data in a JT file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15375.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-37hp-xmxv-j842

Juniper Junos OS before 12.1X44-D60, 12.1X46 before 12.1X46-D40, 12.1X47 before 12.1X47-D30, 12.3 before 12.3R11, 12.3X48 before 12.3X48-D20, 13.2 before 13.2R9, 13.2X51 before 13.2X51-D39, 13.3 before 13.3R8, 14.1 before 14.1R6, 14.1X53 before 14.1X53-D30, 14.2 before 14.2R4-S1, 15.1 before 15.1R2, 15.1X49 before 15.1X49-D30, and 16.1 before 16.1R1 allow remote attackers to cause a denial of service (socket consumption) via crafted TCP timestamps.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-37hp-q495-2gv6

code-projects Simple Student Alumni System code-projects v1.0 is vulnerable to SQL Injection in /TracerStudy/recordstudent_edit.php.

CVSS3: 9.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-37hp-765x-j95x

Django open redirect and possible XSS attack via user-supplied numeric redirect URLs

CVSS3: 6.1
2%
Низкий
больше 7 лет назад
github логотип
GHSA-37hm-v5j4-vc79

A maliciously crafted PDF file, when parsed through Autodesk Revit, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, disclose sensitive data, or execute arbitrary code in the context of the current process.

CVSS3: 7.8
0%
Низкий
10 дней назад
github логотип
GHSA-37hm-h4p2-3xrx

Geert Moernaut LSrunasE allows local users to gain privileges by obtaining the encrypted password from a batch file, and constructing a modified batch file that specifies this password in the /password switch and specifies an arbitrary program in the /command switch.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-37hm-8cwf-jp7f

[A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

CVSS3: 8.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-37hm-87pw-mw7f

Clam AntiVirus (ClamAV) 0.88 and earlier allows remote attackers to cause a denial of service (crash) via a malformed base64-encoded MIME attachment that triggers a null pointer dereference.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-37hm-7427-xp37

Stack-based buffer overflow in Novell Client 4.91 SP4 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long username in the "forgotten password" dialog.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-37hm-5m3h-f5px

gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw

CVSS3: 9.8
2%
Низкий
больше 4 лет назад

Уязвимостей на страницу