Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 234

Количество 358 234

github логотип

GHSA-36hh-hpjf-wc4x

4 месяца назад

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in kutethemes DukaMarket dukamarket allows Code Injection.This issue affects DukaMarket: from n/a through <= 1.3.0.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-36hf-6hp2-9g4c

почти 7 лет назад

Local file inclusion allows unauthorized access to internal resources in Alkacon OpenCms

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-36hf-56qm-gmg9

почти 4 года назад

A vulnerability has been found in Exiv2 and classified as critical. This vulnerability affects the function QuickTimeVideo::userDataDecoder of the file quicktimevideo.cpp of the component QuickTime Video Handler. The manipulation leads to heap-based buffer overflow. The attack can be initiated remotely. The name of the patch is a38e124076138e529774d5ec9890d0731058115a. It is recommended to apply a patch to fix this issue. VDB-212350 is the identifier assigned to this vulnerability.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-36hf-3x3x-vfch

больше 3 лет назад

An improper check for unusual or exceptional conditions in the HTTP request processing function of Zyxel GS1920-24v2 firmware prior to V4.70(ABMH.8)C0, which could allow an unauthenticated attacker to corrupt the contents of the memory and result in a denial-of-service (DoS) condition on a vulnerable device.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-36hc-h5x4-r596

больше 2 лет назад

A vulnerability was found in Bdtask Hospita AutoManager up to 20240223 and classified as problematic. This issue affects some unknown processing of the file /hospital_activities/birth/form of the component Hospital Activities Page. The manipulation of the argument Description with the input <img src=a onerror=alert(1)> leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-255497 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-36hc-97p3-9m65

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in default.asp in Dora Emlak 1.0, when the goster parameter is set to iletisim, allow remote attackers to inject arbitrary web script or HTML via the (1) Adiniz and (2) Soyadiniz parameters; and possibly other unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-36hc-6992-m5r4

больше 4 лет назад

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-Force ID: 155892.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-36h9-cqj8-x2vg

больше 4 лет назад

In PoDoFo 0.9.5, there is an Excessive Iteration in the PdfParser::ReadObjectsInternal function of base/PdfParser.cpp. Remote attackers could leverage this vulnerability to cause a denial of service through a crafted pdf file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-36h8-r92j-w9vw

больше 1 года назад

The AspNetCore Remote Authenticator for SPID Allows SAML Response Signature Verification Bypass

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-36h7-c8f4-vc3p

3 месяца назад

A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A remote attacker may be able to cause a denial of service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-36h7-836c-vp8g

больше 3 лет назад

Improper access control in the Intel(R) Connect M Android application before version 1.82 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-36h6-rv4g-3jg5

6 месяцев назад

A security vulnerability has been detected in D-Link DWR-M960 1.01.07. Affected is the function sub_457C5C of the file /boafrm/formWsc. Such manipulation of the argument save_apply leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-36h6-r4f5-cjrw

больше 4 лет назад

apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalized Chunked value in the Transfer-Encoding HTTP header.

EPSS: Низкий
github логотип

GHSA-36h6-q98c-7j6j

около 4 лет назад

HHVM supports the use of an "admin" server which accepts administrative requests over HTTP. One of those request handlers, dump-pcre-cache, can be used to output cached regular expressions from the current execution context into a file. The handler takes a parameter which specifies where on the filesystem to write this data. The parameter is not validated, allowing a malicious user to overwrite arbitrary files where the user running HHVM has write access. This issue affects HHVM versions prior to 4.56.2, all versions between 4.57.0 and 4.78.0, as well as 4.79.0, 4.80.0, 4.81.0, 4.82.0, and 4.83.0.

EPSS: Низкий
github логотип

GHSA-36h6-cr3x-fx7f

почти 4 года назад

Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/editorder.php.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-36h5-vrq6-pp34

7 месяцев назад

Jervis's Salt for PBKDF2 derived from password

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-36h5-gw9w-mwx2

больше 2 лет назад

IBM Db2 for Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow a local user to escalate their privileges to the SYSTEM user using the MSI repair functionality. IBM X-Force ID: 270402.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-36h4-8mh8-f386

около 4 лет назад

Cross-site request forgery (CSRF) vulnerability in D-Link DCS-931L with firmware 1.04 and earlier allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

EPSS: Низкий
github логотип

GHSA-36h4-78rm-pf8m

около 4 лет назад

A memory buffer error vulnerability exists in a component interface of Huawei Smartphone. Local attackers may exploit this vulnerability by carefully constructing attack scenarios to cause out-of-bounds read.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-36h4-32cj-m84w

6 месяцев назад

A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: QuTS hero h5.3.2.3354 build 20251225 and later

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-36hh-hpjf-wc4x

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in kutethemes DukaMarket dukamarket allows Code Injection.This issue affects DukaMarket: from n/a through <= 1.3.0.

CVSS3: 5.3
0%
Низкий
4 месяца назад
github логотип
GHSA-36hf-6hp2-9g4c

Local file inclusion allows unauthorized access to internal resources in Alkacon OpenCms

CVSS3: 4.3
7%
Низкий
почти 7 лет назад
github логотип
GHSA-36hf-56qm-gmg9

A vulnerability has been found in Exiv2 and classified as critical. This vulnerability affects the function QuickTimeVideo::userDataDecoder of the file quicktimevideo.cpp of the component QuickTime Video Handler. The manipulation leads to heap-based buffer overflow. The attack can be initiated remotely. The name of the patch is a38e124076138e529774d5ec9890d0731058115a. It is recommended to apply a patch to fix this issue. VDB-212350 is the identifier assigned to this vulnerability.

CVSS3: 9.8
почти 4 года назад
github логотип
GHSA-36hf-3x3x-vfch

An improper check for unusual or exceptional conditions in the HTTP request processing function of Zyxel GS1920-24v2 firmware prior to V4.70(ABMH.8)C0, which could allow an unauthenticated attacker to corrupt the contents of the memory and result in a denial-of-service (DoS) condition on a vulnerable device.

CVSS3: 8.2
1%
Низкий
больше 3 лет назад
github логотип
GHSA-36hc-h5x4-r596

A vulnerability was found in Bdtask Hospita AutoManager up to 20240223 and classified as problematic. This issue affects some unknown processing of the file /hospital_activities/birth/form of the component Hospital Activities Page. The manipulation of the argument Description with the input <img src=a onerror=alert(1)> leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-255497 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 2.4
1%
Низкий
больше 2 лет назад
github логотип
GHSA-36hc-97p3-9m65

Multiple cross-site scripting (XSS) vulnerabilities in default.asp in Dora Emlak 1.0, when the goster parameter is set to iletisim, allow remote attackers to inject arbitrary web script or HTML via the (1) Adiniz and (2) Soyadiniz parameters; and possibly other unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-36hc-6992-m5r4

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-Force ID: 155892.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-36h9-cqj8-x2vg

In PoDoFo 0.9.5, there is an Excessive Iteration in the PdfParser::ReadObjectsInternal function of base/PdfParser.cpp. Remote attackers could leverage this vulnerability to cause a denial of service through a crafted pdf file.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-36h8-r92j-w9vw

The AspNetCore Remote Authenticator for SPID Allows SAML Response Signature Verification Bypass

CVSS3: 9.1
1%
Низкий
больше 1 года назад
github логотип
GHSA-36h7-c8f4-vc3p

A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A remote attacker may be able to cause a denial of service.

CVSS3: 7.5
1%
Низкий
3 месяца назад
github логотип
GHSA-36h7-836c-vp8g

Improper access control in the Intel(R) Connect M Android application before version 1.82 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-36h6-rv4g-3jg5

A security vulnerability has been detected in D-Link DWR-M960 1.01.07. Affected is the function sub_457C5C of the file /boafrm/formWsc. Such manipulation of the argument save_apply leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.

CVSS3: 8.8
1%
Низкий
6 месяцев назад
github логотип
GHSA-36h6-r4f5-cjrw

apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalized Chunked value in the Transfer-Encoding HTTP header.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-36h6-q98c-7j6j

HHVM supports the use of an "admin" server which accepts administrative requests over HTTP. One of those request handlers, dump-pcre-cache, can be used to output cached regular expressions from the current execution context into a file. The handler takes a parameter which specifies where on the filesystem to write this data. The parameter is not validated, allowing a malicious user to overwrite arbitrary files where the user running HHVM has write access. This issue affects HHVM versions prior to 4.56.2, all versions between 4.57.0 and 4.78.0, as well as 4.79.0, 4.80.0, 4.81.0, 4.82.0, and 4.83.0.

2%
Низкий
около 4 лет назад
github логотип
GHSA-36h6-cr3x-fx7f

Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/editorder.php.

CVSS3: 7.2
1%
Низкий
почти 4 года назад
github логотип
GHSA-36h5-vrq6-pp34

Jervis's Salt for PBKDF2 derived from password

CVSS3: 7.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-36h5-gw9w-mwx2

IBM Db2 for Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow a local user to escalate their privileges to the SYSTEM user using the MSI repair functionality. IBM X-Force ID: 270402.

CVSS3: 8.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-36h4-8mh8-f386

Cross-site request forgery (CSRF) vulnerability in D-Link DCS-931L with firmware 1.04 and earlier allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-36h4-78rm-pf8m

A memory buffer error vulnerability exists in a component interface of Huawei Smartphone. Local attackers may exploit this vulnerability by carefully constructing attack scenarios to cause out-of-bounds read.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-36h4-32cj-m84w

A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: QuTS hero h5.3.2.3354 build 20251225 and later

CVSS3: 8.1
0%
Низкий
6 месяцев назад

Уязвимостей на страницу