Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 043

Количество 358 043

github логотип

GHSA-35qw-3m24-r2j5

почти 3 года назад

Insufficient control flow management in firmware for some Intel(R) Optane(TM) SSD products may allow a privileged user to potentially enable denial of service via local access.

CVSS3: 6.9
EPSS: Низкий
github логотип

GHSA-35qw-39fh-853x

около 4 лет назад

Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to retrieve passwords in cleartext due to a weak hashing algorithm.

EPSS: Низкий
github логотип

GHSA-35qr-m9p5-57hv

больше 4 лет назад

Multiple unspecified vulnerabilities in IBM WebSphere MQ 6.0 have unknown impact and remote attack vectors involving "memory corruption." NOTE: as of 20071116, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.

EPSS: Низкий
github логотип

GHSA-35qr-4q99-cqm9

больше 1 года назад

Missing Authorization vulnerability in Eivin Landa Bring Fraktguiden for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Bring Fraktguiden for WooCommerce: from n/a through 1.11.4.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-35qq-wvhr-hv5f

больше 4 лет назад

Dynamic Guestbook 3.0 allows remote attackers to execute arbitrary code via shell metacharacters in the gbdaten parameter.

EPSS: Низкий
github логотип

GHSA-35qq-95r4-7cg5

больше 4 лет назад

Reports executed in the IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 contains a vulnerability that could allow an authenticated user to execute a report they do not have access to. IBM X-Force ID: 126866.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-35qp-xq9f-2rjx

около 5 лет назад

Improper Privilege Management in HashiCorp Nomad

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-35qp-vx95-wwwf

7 месяцев назад

A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting participant to conduct remote code execution of the MMR via network access.

CVSS3: 9.9
EPSS: Средний
github логотип

GHSA-35qp-jhrv-w6cv

больше 4 лет назад

TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-authtype variable in the pptp_server.lua file.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-35qp-cqfp-xw3g

больше 1 года назад

Missing Authorization vulnerability in MultiVendorX Product Catalog Enquiry for WooCommerce by MultiVendorX allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Catalog Enquiry for WooCommerce by MultiVendorX: from n/a through 5.0.2.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-35qp-2m3w-q656

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: net/sched: taprio: extend minimum interval restriction to entire cycle too It is possible for syzbot to side-step the restriction imposed by the blamed commit in the Fixes: tag, because the taprio UAPI permits a cycle-time different from (and potentially shorter than) the sum of entry intervals. We need one more restriction, which is that the cycle time itself must be larger than N * ETH_ZLEN bit times, where N is the number of schedule entries. This restriction needs to apply regardless of whether the cycle time came from the user or was the implicit, auto-calculated value, so we move the existing "cycle == 0" check outside the "if "(!new->cycle_time)" branch. This way covers both conditions and scenarios. Add a selftest which illustrates the issue triggered by syzbot.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-35qm-p6wq-8wpf

почти 4 года назад

OTFCC v0.10.4 was discovered to contain a heap-buffer overflow via /release-x64/otfccdump+0x6b84b1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-35qj-2v2r-6c2g

около 3 лет назад

Use of Hard-coded Cryptographic Key vulnerability in SonicWall GMS, SonicWall Analytics. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-35qh-7f6c-rjf7

больше 2 лет назад

A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the configuration of unbound.service. This flaw allows an unprivileged attacker to manipulate a running instance, potentially altering forwarders, allowing them to track all queries forwarded by the local resolver, and, in some cases, disrupting resolving altogether.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-35qg-4gg3-p395

10 месяцев назад

An issue was discovered in BESSystem BES Application Server thru 9.5.x allowing unauthorized attackers to gain sensitive information via the "pre-resource" option in bes-web.xml.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-35qg-2852-82xj

больше 4 лет назад

Peercast places a cleartext password in a query string, which might allow attackers to obtain sensitive information by sniffing the network, or obtaining Referer or browser history information.

EPSS: Низкий
github логотип

GHSA-35qc-7cp5-9q9m

около 1 года назад

Insufficient data validation in DevTools in Google Chrome on Windows prior to 138.0.7204.49 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-35qc-5x66-f277

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Take state lock during tx timeout reporter mlx5e_safe_reopen_channels() requires the state lock taken. The referenced changed in the Fixes tag removed the lock to fix another issue. This patch adds it back but at a later point (when calling mlx5e_safe_reopen_channels()) to avoid the deadlock referenced in the Fixes tag.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-35q9-qwff-qmh4

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: net: dsa: microchip: Added the condition for scheduling ksz_mib_read_work When the ksz module is installed and removed using rmmod, kernel crashes with null pointer dereferrence error. During rmmod, ksz_switch_remove function tries to cancel the mib_read_workqueue using cancel_delayed_work_sync routine and unregister switch from dsa. During dsa_unregister_switch it calls ksz_mac_link_down, which in turn reschedules the workqueue since mib_interval is non-zero. Due to which queue executed after mib_interval and it tries to access dp->slave. But the slave is unregistered in the ksz_switch_remove function. Hence kernel crashes. To avoid this crash, before canceling the workqueue, resetted the mib_interval to 0. v1 -> v2: -Removed the if condition in ksz_mib_read_work

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-35q9-q5hh-hmc4

больше 1 года назад

Improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a folder where the attacker doesn't have permission to list content.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-35qw-3m24-r2j5

Insufficient control flow management in firmware for some Intel(R) Optane(TM) SSD products may allow a privileged user to potentially enable denial of service via local access.

CVSS3: 6.9
0%
Низкий
почти 3 года назад
github логотип
GHSA-35qw-39fh-853x

Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to retrieve passwords in cleartext due to a weak hashing algorithm.

0%
Низкий
около 4 лет назад
github логотип
GHSA-35qr-m9p5-57hv

Multiple unspecified vulnerabilities in IBM WebSphere MQ 6.0 have unknown impact and remote attack vectors involving "memory corruption." NOTE: as of 20071116, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-35qr-4q99-cqm9

Missing Authorization vulnerability in Eivin Landa Bring Fraktguiden for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Bring Fraktguiden for WooCommerce: from n/a through 1.11.4.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-35qq-wvhr-hv5f

Dynamic Guestbook 3.0 allows remote attackers to execute arbitrary code via shell metacharacters in the gbdaten parameter.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-35qq-95r4-7cg5

Reports executed in the IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 contains a vulnerability that could allow an authenticated user to execute a report they do not have access to. IBM X-Force ID: 126866.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-35qp-xq9f-2rjx

Improper Privilege Management in HashiCorp Nomad

CVSS3: 7.5
1%
Низкий
около 5 лет назад
github логотип
GHSA-35qp-vx95-wwwf

A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting participant to conduct remote code execution of the MMR via network access.

CVSS3: 9.9
13%
Средний
7 месяцев назад
github логотип
GHSA-35qp-jhrv-w6cv

TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-authtype variable in the pptp_server.lua file.

CVSS3: 7.2
4%
Низкий
больше 4 лет назад
github логотип
GHSA-35qp-cqfp-xw3g

Missing Authorization vulnerability in MultiVendorX Product Catalog Enquiry for WooCommerce by MultiVendorX allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Catalog Enquiry for WooCommerce by MultiVendorX: from n/a through 5.0.2.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-35qp-2m3w-q656

In the Linux kernel, the following vulnerability has been resolved: net/sched: taprio: extend minimum interval restriction to entire cycle too It is possible for syzbot to side-step the restriction imposed by the blamed commit in the Fixes: tag, because the taprio UAPI permits a cycle-time different from (and potentially shorter than) the sum of entry intervals. We need one more restriction, which is that the cycle time itself must be larger than N * ETH_ZLEN bit times, where N is the number of schedule entries. This restriction needs to apply regardless of whether the cycle time came from the user or was the implicit, auto-calculated value, so we move the existing "cycle == 0" check outside the "if "(!new->cycle_time)" branch. This way covers both conditions and scenarios. Add a selftest which illustrates the issue triggered by syzbot.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-35qm-p6wq-8wpf

OTFCC v0.10.4 was discovered to contain a heap-buffer overflow via /release-x64/otfccdump+0x6b84b1.

CVSS3: 6.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-35qj-2v2r-6c2g

Use of Hard-coded Cryptographic Key vulnerability in SonicWall GMS, SonicWall Analytics. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-35qh-7f6c-rjf7

A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the configuration of unbound.service. This flaw allows an unprivileged attacker to manipulate a running instance, potentially altering forwarders, allowing them to track all queries forwarded by the local resolver, and, in some cases, disrupting resolving altogether.

CVSS3: 8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-35qg-4gg3-p395

An issue was discovered in BESSystem BES Application Server thru 9.5.x allowing unauthorized attackers to gain sensitive information via the "pre-resource" option in bes-web.xml.

CVSS3: 7.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-35qg-2852-82xj

Peercast places a cleartext password in a query string, which might allow attackers to obtain sensitive information by sniffing the network, or obtaining Referer or browser history information.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-35qc-7cp5-9q9m

Insufficient data validation in DevTools in Google Chrome on Windows prior to 138.0.7204.49 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 5.4
0%
Низкий
около 1 года назад
github логотип
GHSA-35qc-5x66-f277

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Take state lock during tx timeout reporter mlx5e_safe_reopen_channels() requires the state lock taken. The referenced changed in the Fixes tag removed the lock to fix another issue. This patch adds it back but at a later point (when calling mlx5e_safe_reopen_channels()) to avoid the deadlock referenced in the Fixes tag.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-35q9-qwff-qmh4

In the Linux kernel, the following vulnerability has been resolved: net: dsa: microchip: Added the condition for scheduling ksz_mib_read_work When the ksz module is installed and removed using rmmod, kernel crashes with null pointer dereferrence error. During rmmod, ksz_switch_remove function tries to cancel the mib_read_workqueue using cancel_delayed_work_sync routine and unregister switch from dsa. During dsa_unregister_switch it calls ksz_mac_link_down, which in turn reschedules the workqueue since mib_interval is non-zero. Due to which queue executed after mib_interval and it tries to access dp->slave. But the slave is unregistered in the ksz_switch_remove function. Hence kernel crashes. To avoid this crash, before canceling the workqueue, resetted the mib_interval to 0. v1 -> v2: -Removed the if condition in ksz_mib_read_work

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-35q9-q5hh-hmc4

Improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a folder where the attacker doesn't have permission to list content.

CVSS3: 6.5
3%
Низкий
больше 1 года назад

Уязвимостей на страницу