Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 043

Количество 358 043

github логотип

GHSA-35rm-gh88-rf95

около 4 лет назад

Cross-site scripting vulnerability in Splunk Enterprise 6.3.x prior to 6.3.5 and Splunk Light 6.3.x prior to 6.3.5 allows attacker with administrator rights to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-35rm-7j9c-2f7m

около 1 месяца назад

async-tar PAX extension-header desync enables tar entry/content smuggling

EPSS: Низкий
github логотип

GHSA-35rm-77cm-584v

около 4 лет назад

An issue was discovered on Samsung mobile devices with Q(10.0) (exynos9830 chipsets) software. RKP allows arbitrary code execution. The Samsung ID is SVE-2020-17435 (August 2020).

EPSS: Низкий
github логотип

GHSA-35rj-j8qg-5vgh

больше 4 лет назад

daemon.c in cman (redhat-cluster-suite) before 20070622 does not clear a buffer for reading requests, which might allow local users to obtain sensitive information from previous requests.

EPSS: Низкий
github логотип

GHSA-35rj-4m65-59q8

больше 3 лет назад

In getTrampolineIntent of SettingsActivity.java, there is a possible launch of arbitrary activity due to an Intent mismatch in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12L Android-13Android ID: A-246300272

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-35rh-9jh6-cw7p

больше 4 лет назад

The barracudavpn component of the Barracuda VPN Client prior to version 5.0.2.7 for Linux, macOS, and OpenBSD runs as a privileged process and can allow an unprivileged local attacker to load a malicious library, resulting in arbitrary code executing as root.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-35rh-6mjx-86f8

около 4 лет назад

VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds read vulnerabilities in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perform a Denial of Service on the Windows OS that runs the Horizon View Client. Exploitation is only possible if virtual printing has been enabled. This feature is not enabled by default on Workstation but it is enabled by default on Horizon View.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-35rg-pjrx-fc55

больше 4 лет назад

Directory traversal vulnerability in geohttpserver in Geovision Digital Video Surveillance System 8.2 allows remote attackers to read arbitrary files via a .. (dot dot) in a GET request.

EPSS: Низкий
github логотип

GHSA-35rg-466w-77h3

около 5 лет назад

Cross-site scripting in Products.CMFCore, Products.PluggableAuthService, Plone

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-35rf-xg9j-vr62

больше 4 лет назад

Microsoft Office 2013 Gold, SP1, RT, and RT SP1 allows remote attackers to obtain sensitive token information via a web site that sends a crafted response during opening of an Office document, aka "Token Reuse Vulnerability."

EPSS: Средний
github логотип

GHSA-35rf-v5xv-3376

больше 4 лет назад

Snort 1.6, when running in straight ASCII packet logging mode or IDS mode with straight decoded ASCII packet logging selected, allows remote attackers to cause a denial of service (crash) by sending non-IP protocols that Snort does not know about, as demonstrated by an nmap protocol scan.

EPSS: Низкий
github логотип

GHSA-35rf-v2jv-gfg7

больше 4 лет назад

Privilege escalation to cluster admin on multi-tenant environments

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-35rf-7vhx-9phr

около 4 лет назад

Redis v7.0 was discovered to contain a memory leak via the component streamGetEdgeID.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-35rf-2xxr-prvf

больше 1 года назад

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Bowo System Dashboard allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects System Dashboard: from n/a through 2.8.18.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-35rc-qr7q-j9jm

около 4 лет назад

Use after free issue due to using of invalidated iterator to delete an object in sensors HAL in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8096AU, MSM8909W, Nicobar, QCS605, SA6155P, SDA845, SDM429W, SDM670, SDM710, SDM845, SM6150, SM8150, SM8250, SXR1130, SXR2130

EPSS: Низкий
github логотип

GHSA-35rc-fmpw-cvfv

больше 1 года назад

An unauthenticated attacker can check the existence of usernames in the system by querying an API.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-35rc-2vcv-r6q5

около 1 месяца назад

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

CVSS3: 10
EPSS: Высокий
github логотип

GHSA-35r9-gfqf-r6cw

около 4 лет назад

Missing permission check in Jenkins vRealize Orchestrator Plugin

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-35r8-c3gc-mfvr

больше 2 лет назад

Leave Management System Project v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'setearnleave' parameter of the admin/setleaves.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-35r7-w24m-px2g

больше 4 лет назад

A configuration problem in the Ad Server Sample directory (AdSamples) in Microsoft Site Server 3.0 allows an attacker to obtain the SITE.CSC file, which exposes sensitive SQL database information.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-35rm-gh88-rf95

Cross-site scripting vulnerability in Splunk Enterprise 6.3.x prior to 6.3.5 and Splunk Light 6.3.x prior to 6.3.5 allows attacker with administrator rights to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 4.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-35rm-7j9c-2f7m

async-tar PAX extension-header desync enables tar entry/content smuggling

около 1 месяца назад
github логотип
GHSA-35rm-77cm-584v

An issue was discovered on Samsung mobile devices with Q(10.0) (exynos9830 chipsets) software. RKP allows arbitrary code execution. The Samsung ID is SVE-2020-17435 (August 2020).

1%
Низкий
около 4 лет назад
github логотип
GHSA-35rj-j8qg-5vgh

daemon.c in cman (redhat-cluster-suite) before 20070622 does not clear a buffer for reading requests, which might allow local users to obtain sensitive information from previous requests.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-35rj-4m65-59q8

In getTrampolineIntent of SettingsActivity.java, there is a possible launch of arbitrary activity due to an Intent mismatch in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12L Android-13Android ID: A-246300272

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-35rh-9jh6-cw7p

The barracudavpn component of the Barracuda VPN Client prior to version 5.0.2.7 for Linux, macOS, and OpenBSD runs as a privileged process and can allow an unprivileged local attacker to load a malicious library, resulting in arbitrary code executing as root.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-35rh-6mjx-86f8

VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds read vulnerabilities in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perform a Denial of Service on the Windows OS that runs the Horizon View Client. Exploitation is only possible if virtual printing has been enabled. This feature is not enabled by default on Workstation but it is enabled by default on Horizon View.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-35rg-pjrx-fc55

Directory traversal vulnerability in geohttpserver in Geovision Digital Video Surveillance System 8.2 allows remote attackers to read arbitrary files via a .. (dot dot) in a GET request.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-35rg-466w-77h3

Cross-site scripting in Products.CMFCore, Products.PluggableAuthService, Plone

CVSS3: 6.1
1%
Низкий
около 5 лет назад
github логотип
GHSA-35rf-xg9j-vr62

Microsoft Office 2013 Gold, SP1, RT, and RT SP1 allows remote attackers to obtain sensitive token information via a web site that sends a crafted response during opening of an Office document, aka "Token Reuse Vulnerability."

10%
Средний
больше 4 лет назад
github логотип
GHSA-35rf-v5xv-3376

Snort 1.6, when running in straight ASCII packet logging mode or IDS mode with straight decoded ASCII packet logging selected, allows remote attackers to cause a denial of service (crash) by sending non-IP protocols that Snort does not know about, as demonstrated by an nmap protocol scan.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-35rf-v2jv-gfg7

Privilege escalation to cluster admin on multi-tenant environments

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-35rf-7vhx-9phr

Redis v7.0 was discovered to contain a memory leak via the component streamGetEdgeID.

CVSS3: 7.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-35rf-2xxr-prvf

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Bowo System Dashboard allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects System Dashboard: from n/a through 2.8.18.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-35rc-qr7q-j9jm

Use after free issue due to using of invalidated iterator to delete an object in sensors HAL in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8096AU, MSM8909W, Nicobar, QCS605, SA6155P, SDA845, SDM429W, SDM670, SDM710, SDM845, SM6150, SM8150, SM8250, SXR1130, SXR2130

0%
Низкий
около 4 лет назад
github логотип
GHSA-35rc-fmpw-cvfv

An unauthenticated attacker can check the existence of usernames in the system by querying an API.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-35rc-2vcv-r6q5

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

CVSS3: 10
74%
Высокий
около 1 месяца назад
github логотип
GHSA-35r9-gfqf-r6cw

Missing permission check in Jenkins vRealize Orchestrator Plugin

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-35r8-c3gc-mfvr

Leave Management System Project v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'setearnleave' parameter of the admin/setleaves.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-35r7-w24m-px2g

A configuration problem in the Ad Server Sample directory (AdSamples) in Microsoft Site Server 3.0 allows an attacker to obtain the SITE.CSC file, which exposes sensitive SQL database information.

12%
Средний
больше 4 лет назад

Уязвимостей на страницу