Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 043

Количество 358 043

github логотип

GHSA-35v6-cwhg-f55m

около 4 лет назад

This issue was addressed with improved checks. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. A malicious application may be able to modify protected parts of the file system.

EPSS: Низкий
github логотип

GHSA-35v6-2x4q-9wxq

около 4 лет назад

An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-35v5-c7c4-jcvm

больше 4 лет назад

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in SDL_FillRect in video/SDL_surface.c.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-35v5-5w5j-5cx2

4 месяца назад

Development and test API endpoints are present that mirror production functionality.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-35v4-cfj4-wrvg

около 4 лет назад

Cross-site request forgery (CSRF) vulnerability in the web-management interface in the fabric interconnect (FI) component in Cisco Unified Computing System (UCS) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCtg20755.

EPSS: Низкий
github логотип

GHSA-35v3-mvqh-7ffm

около 3 лет назад

Auth. (contrinbutor+) Cross-Site Scripting (XSS) vulnerability in WebArea | Vera Nedvyzhenko Simple PDF Viewer plugin <= 1.9 versions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-35v3-9ffw-rmxv

около 4 лет назад

A kernel pool overflow in the driver hitmanpro37.sys in Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in the HitmanPro.Alert solution and Sophos Clean) allows local users to escalate privileges via a malformed IOCTL call.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-35v2-w3c7-q3qc

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in Ryan Duff, Peter Westwood WP Contact Form.This issue affects WP Contact Form: from n/a through 1.6.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-35v2-vq8r-rrr8

больше 4 лет назад

LibreSSL before 2.6.5 and 2.7.x before 2.7.4 allows a memory-cache side-channel attack on DSA and ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover a key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-35v2-m9fq-hvxf

около 4 лет назад

An elevation of privilege vulnerability exists when the Windows Work Folder Service improperly handles file operations, aka 'Windows Work Folder Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0777, CVE-2020-0797, CVE-2020-0800, CVE-2020-0864, CVE-2020-0866, CVE-2020-0897.

EPSS: Низкий
github логотип

GHSA-35v2-jpj3-grq4

больше 4 лет назад

A regression error in the restore_all code path of the 4/4GB split support for non-hugemem Linux kernels on Red Hat Linux Desktop and Enterprise Linux 4 allows local users to cause a denial of service (panic) via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-35v2-77rf-53pc

11 дней назад

A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function logread.get_system_log of the file /usr/lib/oui-httpd/rpc/logread of the component Logread Lua RPC plugin. The manipulation of the argument module results in command injection. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-35rx-r627-2cf6

около 4 лет назад

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects RBW30 before 2.6.2.2, RBK852 before 3.2.17.12, RBK852 before 3.2.17.12, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, RBS850 before 3.2.17.12, RBK752 before 3.2.17.12, RBK753 before 3.2.17.12, RBK753S before 3.2.17.12, RBK754 before 3.2.17.12, RBR750 before 3.2.17.12, and RBS750 before 3.2.17.12.

EPSS: Низкий
github логотип

GHSA-35rx-7pc8-6963

почти 4 года назад

API keys stored in plain text by Jenkins Katalon Plugin

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-35rw-8ffm-c585

около 4 лет назад

Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system, gain access to sensitive information, and view information that they are not authorized to access. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-35rv-2jpx-mq5h

12 месяцев назад

A vulnerability was identified in Surbowl dormitory-management-php up to 9f1d9d1f528cabffc66fda3652c56ff327fda317. Affected is an unknown function of the file /admin/violation_add.php?id=2. Such manipulation of the argument ID leads to sql injection. The attack may be performed from a remote location. The exploit is publicly available and might be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-35rr-w5p6-529c

больше 4 лет назад

Buffer overflow in the Windows logon process (winlogon) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1, when a member of a domain, allows remote attackers to execute arbitrary code.

EPSS: Средний
github логотип

GHSA-35rr-mpm9-g6jw

около 4 лет назад

Blind SQL injection in the login form in ServiceTonic Helpdesk software < 9.0.35937 allows attacker to exfiltrate information via specially crafted HQL-compatible time-based SQL queries.

EPSS: Низкий
github логотип

GHSA-35rp-m2pf-5xvg

больше 4 лет назад

AlstraSoft Video Share Enterprise allows remote attackers to obtain sensitive information (the full path) via (1) a ' (quote) character in the category parameter to view_video.php, or (2) an XSS sequence in the UID parameter to (a) uprofile.php, (b) channel_detail.php, (c) uvideos.php, (d) groups_home.php, or (e) ufriends.php.

EPSS: Низкий
github логотип

GHSA-35rm-h9jc-25g2

больше 4 лет назад

tog-Pegasus has a package hash collision DoS vulnerability

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-35v6-cwhg-f55m

This issue was addressed with improved checks. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. A malicious application may be able to modify protected parts of the file system.

1%
Низкий
около 4 лет назад
github логотип
GHSA-35v6-2x4q-9wxq

An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'.

CVSS3: 5.5
5%
Низкий
около 4 лет назад
github логотип
GHSA-35v5-c7c4-jcvm

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in SDL_FillRect in video/SDL_surface.c.

CVSS3: 8.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-35v5-5w5j-5cx2

Development and test API endpoints are present that mirror production functionality.

CVSS3: 5.3
0%
Низкий
4 месяца назад
github логотип
GHSA-35v4-cfj4-wrvg

Cross-site request forgery (CSRF) vulnerability in the web-management interface in the fabric interconnect (FI) component in Cisco Unified Computing System (UCS) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCtg20755.

1%
Низкий
около 4 лет назад
github логотип
GHSA-35v3-mvqh-7ffm

Auth. (contrinbutor+) Cross-Site Scripting (XSS) vulnerability in WebArea | Vera Nedvyzhenko Simple PDF Viewer plugin <= 1.9 versions.

CVSS3: 6.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-35v3-9ffw-rmxv

A kernel pool overflow in the driver hitmanpro37.sys in Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in the HitmanPro.Alert solution and Sophos Clean) allows local users to escalate privileges via a malformed IOCTL call.

CVSS3: 7.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-35v2-w3c7-q3qc

Cross-Site Request Forgery (CSRF) vulnerability in Ryan Duff, Peter Westwood WP Contact Form.This issue affects WP Contact Form: from n/a through 1.6.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-35v2-vq8r-rrr8

LibreSSL before 2.6.5 and 2.7.x before 2.7.4 allows a memory-cache side-channel attack on DSA and ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover a key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.

CVSS3: 4.7
0%
Низкий
больше 4 лет назад
github логотип
GHSA-35v2-m9fq-hvxf

An elevation of privilege vulnerability exists when the Windows Work Folder Service improperly handles file operations, aka 'Windows Work Folder Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0777, CVE-2020-0797, CVE-2020-0800, CVE-2020-0864, CVE-2020-0866, CVE-2020-0897.

1%
Низкий
около 4 лет назад
github логотип
GHSA-35v2-jpj3-grq4

A regression error in the restore_all code path of the 4/4GB split support for non-hugemem Linux kernels on Red Hat Linux Desktop and Enterprise Linux 4 allows local users to cause a denial of service (panic) via unspecified vectors.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-35v2-77rf-53pc

A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function logread.get_system_log of the file /usr/lib/oui-httpd/rpc/logread of the component Logread Lua RPC plugin. The manipulation of the argument module results in command injection. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.

CVSS3: 8.8
2%
Низкий
11 дней назад
github логотип
GHSA-35rx-r627-2cf6

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects RBW30 before 2.6.2.2, RBK852 before 3.2.17.12, RBK852 before 3.2.17.12, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12, RBS850 before 3.2.17.12, RBK752 before 3.2.17.12, RBK753 before 3.2.17.12, RBK753S before 3.2.17.12, RBK754 before 3.2.17.12, RBR750 before 3.2.17.12, and RBS750 before 3.2.17.12.

0%
Низкий
около 4 лет назад
github логотип
GHSA-35rx-7pc8-6963

API keys stored in plain text by Jenkins Katalon Plugin

CVSS3: 4.3
1%
Низкий
почти 4 года назад
github логотип
GHSA-35rw-8ffm-c585

Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system, gain access to sensitive information, and view information that they are not authorized to access. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS3: 6.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-35rv-2jpx-mq5h

A vulnerability was identified in Surbowl dormitory-management-php up to 9f1d9d1f528cabffc66fda3652c56ff327fda317. Affected is an unknown function of the file /admin/violation_add.php?id=2. Such manipulation of the argument ID leads to sql injection. The attack may be performed from a remote location. The exploit is publicly available and might be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 7.3
0%
Низкий
12 месяцев назад
github логотип
GHSA-35rr-w5p6-529c

Buffer overflow in the Windows logon process (winlogon) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1, when a member of a domain, allows remote attackers to execute arbitrary code.

33%
Средний
больше 4 лет назад
github логотип
GHSA-35rr-mpm9-g6jw

Blind SQL injection in the login form in ServiceTonic Helpdesk software < 9.0.35937 allows attacker to exfiltrate information via specially crafted HQL-compatible time-based SQL queries.

1%
Низкий
около 4 лет назад
github логотип
GHSA-35rp-m2pf-5xvg

AlstraSoft Video Share Enterprise allows remote attackers to obtain sensitive information (the full path) via (1) a ' (quote) character in the category parameter to view_video.php, or (2) an XSS sequence in the UID parameter to (a) uprofile.php, (b) channel_detail.php, (c) uvideos.php, (d) groups_home.php, or (e) ufriends.php.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-35rm-h9jc-25g2

tog-Pegasus has a package hash collision DoS vulnerability

CVSS3: 7.5
3%
Низкий
больше 4 лет назад

Уязвимостей на страницу