Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 043

Количество 358 043

github логотип

GHSA-35x6-cfx8-j8gm

больше 4 лет назад

Stack-based buffer overflow in the Chinagames CGAgent ActiveX control 1.x in CGAgent.dll, as distributed in Chinagames iGame 2009, allows remote attackers to execute arbitrary code via a long argument to the CreateChinagames method, as exploited in the wild in April and May 2009. NOTE: some of these details are obtained from third party information.

EPSS: Средний
github логотип

GHSA-35x5-m3xw-vp7p

около 4 лет назад

As a result of an observable discrepancy in returned messages, OPSWAT MetaDefender Core (MDCore) before 5.1.2 could allow an authenticated user to enumerate filenames on the server.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-35x5-g32v-j75x

больше 4 лет назад

Buffer overflow in the embedded HTTP server for Cisco Catalyst switches running CatOS 5.4 through 7.3 allows remote attackers to cause a denial of service (reset) via a long HTTP request.

EPSS: Низкий
github логотип

GHSA-35x5-8hjg-m53r

больше 4 лет назад

tftpd in Philippe Jounin Tftpd32 2.74 and earlier, as used in Wyse Simple Imager (WSI) and other products, allows remote attackers to cause a denial of service (daemon crash) via a long filename in a TFTP read (aka RRQ or get) request, a different vulnerability than CVE-2002-2226.

EPSS: Низкий
github логотип

GHSA-35x3-v7hw-gc2g

больше 2 лет назад

std::bad_alloc is mishandled in Precomp 0.4.8. NOTE: this is disputed because it should be categorized as a usability problem.

EPSS: Низкий
github логотип

GHSA-35x3-rj44-584q

больше 4 лет назад

In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-35x2-6j99-3gv6

почти 4 года назад

In Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' flag to be changed after the first scan of the image, leading to an unknown integer-related vulnerability in Stream.cc.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-35wx-v489-5vx6

больше 1 года назад

Missing Authorization vulnerability in Conversios Conversios.io allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Conversios.io: from n/a through 7.2.3.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-35wx-qhfj-hc3p

около 4 лет назад

Cross-site scripting (XSS) vulnerability in IBM iNotes 8.5.x before 8.5.3 FP4 allows user-assisted remote attackers to inject arbitrary web script or HTML via vectors involving mail, aka SPR JDOE8ZZS9.

EPSS: Низкий
github логотип

GHSA-35ww-qxmq-894v

около 4 лет назад

WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-04-01-1.

EPSS: Низкий
github логотип

GHSA-35wv-xg96-7j37

больше 4 лет назад

Multiple unspecified vulnerabilities in the Importer in Flip4Mac WMV before 2.2.1 have unknown impact and attack vectors, different vulnerabilities than CVE-2007-6713.

EPSS: Низкий
github логотип

GHSA-35wr-x7v6-9fv2

3 месяца назад

Dalfox Server Mode has an Unauthenticated Arbitrary File Read with Out-of-Band Exfiltration via `custom-payload-file`

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-35wr-c9xh-h9cf

около 4 лет назад

Microsoft Defender for Endpoint Tampering Vulnerability.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-35wp-vg6r-qrm4

11 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: parisc: Drop WARN_ON_ONCE() from flush_cache_vmap I have observed warning to occassionally trigger.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-35wp-mq65-94rh

больше 4 лет назад

CRLF injection vulnerability in Infoblox Network Automation NetMRI before 7.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the contentType parameter in a login action to config/userAdmin/login.tdf.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-35wm-wmj3-cw44

больше 4 лет назад

SQL injection vulnerability in class/show.php in FaScript FaPersianHack 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to show.php.

EPSS: Низкий
github логотип

GHSA-35wm-rx84-28c3

около 4 лет назад

Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0964, CVE-2016-0965, CVE-2016-0966, CVE-2016-0967, CVE-2016-0968, CVE-2016-0969, CVE-2016-0970, CVE-2016-0972, CVE-2016-0976, CVE-2016-0977, CVE-2016-0978, CVE-2016-0979, and CVE-2016-0981.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-35wm-hq5r-2p36

8 месяцев назад

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device contains a USB port which allows unauthenticated connections. This could allow an attacker with physical access to the device to trigger reboot that could cause denial of service condition.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-35wj-mf36-r4h7

около 4 лет назад

WSR-1166DHP3 firmware Ver.1.16 and prior and WSR-1166DHP4 firmware Ver.1.02 and prior allow an attacker to execute arbitrary OS commands with root privileges via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-35wj-849x-phrf

больше 4 лет назад

Integer overflow in Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-35x6-cfx8-j8gm

Stack-based buffer overflow in the Chinagames CGAgent ActiveX control 1.x in CGAgent.dll, as distributed in Chinagames iGame 2009, allows remote attackers to execute arbitrary code via a long argument to the CreateChinagames method, as exploited in the wild in April and May 2009. NOTE: some of these details are obtained from third party information.

11%
Средний
больше 4 лет назад
github логотип
GHSA-35x5-m3xw-vp7p

As a result of an observable discrepancy in returned messages, OPSWAT MetaDefender Core (MDCore) before 5.1.2 could allow an authenticated user to enumerate filenames on the server.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-35x5-g32v-j75x

Buffer overflow in the embedded HTTP server for Cisco Catalyst switches running CatOS 5.4 through 7.3 allows remote attackers to cause a denial of service (reset) via a long HTTP request.

9%
Низкий
больше 4 лет назад
github логотип
GHSA-35x5-8hjg-m53r

tftpd in Philippe Jounin Tftpd32 2.74 and earlier, as used in Wyse Simple Imager (WSI) and other products, allows remote attackers to cause a denial of service (daemon crash) via a long filename in a TFTP read (aka RRQ or get) request, a different vulnerability than CVE-2002-2226.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-35x3-v7hw-gc2g

std::bad_alloc is mishandled in Precomp 0.4.8. NOTE: this is disputed because it should be categorized as a usability problem.

0%
Низкий
больше 2 лет назад
github логотип
GHSA-35x3-rj44-584q

In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload.

CVSS3: 8.8
7%
Низкий
больше 4 лет назад
github логотип
GHSA-35x2-6j99-3gv6

In Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' flag to be changed after the first scan of the image, leading to an unknown integer-related vulnerability in Stream.cc.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-35wx-v489-5vx6

Missing Authorization vulnerability in Conversios Conversios.io allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Conversios.io: from n/a through 7.2.3.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-35wx-qhfj-hc3p

Cross-site scripting (XSS) vulnerability in IBM iNotes 8.5.x before 8.5.3 FP4 allows user-assisted remote attackers to inject arbitrary web script or HTML via vectors involving mail, aka SPR JDOE8ZZS9.

1%
Низкий
около 4 лет назад
github логотип
GHSA-35ww-qxmq-894v

WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-04-01-1.

2%
Низкий
около 4 лет назад
github логотип
GHSA-35wv-xg96-7j37

Multiple unspecified vulnerabilities in the Importer in Flip4Mac WMV before 2.2.1 have unknown impact and attack vectors, different vulnerabilities than CVE-2007-6713.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-35wr-x7v6-9fv2

Dalfox Server Mode has an Unauthenticated Arbitrary File Read with Out-of-Band Exfiltration via `custom-payload-file`

CVSS3: 7.5
0%
Низкий
3 месяца назад
github логотип
GHSA-35wr-c9xh-h9cf

Microsoft Defender for Endpoint Tampering Vulnerability.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-35wp-vg6r-qrm4

In the Linux kernel, the following vulnerability has been resolved: parisc: Drop WARN_ON_ONCE() from flush_cache_vmap I have observed warning to occassionally trigger.

CVSS3: 5.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-35wp-mq65-94rh

CRLF injection vulnerability in Infoblox Network Automation NetMRI before 7.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the contentType parameter in a login action to config/userAdmin/login.tdf.

CVSS3: 6.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-35wm-wmj3-cw44

SQL injection vulnerability in class/show.php in FaScript FaPersianHack 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to show.php.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-35wm-rx84-28c3

Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0964, CVE-2016-0965, CVE-2016-0966, CVE-2016-0967, CVE-2016-0968, CVE-2016-0969, CVE-2016-0970, CVE-2016-0972, CVE-2016-0976, CVE-2016-0977, CVE-2016-0978, CVE-2016-0979, and CVE-2016-0981.

CVSS3: 9.8
4%
Низкий
около 4 лет назад
github логотип
GHSA-35wm-hq5r-2p36

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device contains a USB port which allows unauthenticated connections. This could allow an attacker with physical access to the device to trigger reboot that could cause denial of service condition.

CVSS3: 4.6
0%
Низкий
8 месяцев назад
github логотип
GHSA-35wj-mf36-r4h7

WSR-1166DHP3 firmware Ver.1.16 and prior and WSR-1166DHP4 firmware Ver.1.02 and prior allow an attacker to execute arbitrary OS commands with root privileges via unspecified vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-35wj-849x-phrf

Integer overflow in Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image.

4%
Низкий
больше 4 лет назад

Уязвимостей на страницу