Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 043

Количество 358 043

github логотип

GHSA-35mj-mc7c-rc4m

около 4 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14270.

EPSS: Средний
github логотип

GHSA-35mj-3pg9-j9v7

больше 4 лет назад

Stack-based buffer overflow in net80211/ieee80211_wireless.c in MadWifi before 0.9.2.1 allows remote attackers to execute arbitrary code via unspecified vectors, related to the encode_ie and giwscan_cb functions.

EPSS: Средний
github логотип

GHSA-35mj-225p-fxvg

почти 4 года назад

Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the schedStartTime parameter in the setSchedWifi function.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-35mh-v24c-mjw6

10 месяцев назад

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted LSA Update packet.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-35mh-m2vc-vgv8

3 дня назад

Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-35mh-jj82-w9jm

8 дней назад

Unauthenticated Broken Access Control in Legal Text Connector of the IT-Recht Kanzlei <= 1.0.13 versions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-35mh-hxcm-w9xp

10 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in appscreo Hello Followers hellofollowers allows Reflected XSS.This issue affects Hello Followers: from n/a through <= 2.5.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-35mh-f6p8-pj2c

больше 4 лет назад

WPGlobus plugin Stored XSS & CSRF security vulnerability

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-35mh-7m7p-jcq9

около 1 года назад

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-35mh-4fxp-w6v9

около 4 лет назад

FarLinX X25 Gateway through 2014-09-25 allows attackers to write arbitrary data to fsUI.xyz via fsSaveUIPersistence.php.

EPSS: Низкий
github логотип

GHSA-35mh-362p-8hhw

около 4 лет назад

The pdf-print plugin before 1.9.4 for WordPress has multiple XSS issues.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-35mg-p597-mvg8

больше 4 лет назад

The List Users API of Piwigo 2.9.2 is vulnerable to SQL Injection via the /admin/user_list_backend.php sSortDir_0 parameter. An attacker can exploit this to gain access to the data in a connected MySQL database.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-35mg-4h75-f9m6

около 4 лет назад

Xen 4.4.x, when running on an ARM system and "handling an unknown system register access from 64-bit userspace," returns to an instruction of the trap handler for kernel space faults instead of an instruction that is associated with faults in 64-bit userspace, which allows local guest users to cause a denial of service (crash) and possibly gain privileges via a crafted process.

EPSS: Низкий
github логотип

GHSA-35mf-vj2p-cr8q

около 4 лет назад

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0313, CVE-2015-0315, and CVE-2015-0322.

EPSS: Низкий
github логотип

GHSA-35mf-hw36-wj5c

больше 4 лет назад

Integer signedness error in the DIRAPI module in Adobe Shockwave Player before 11.5.8.612 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a count value associated with an "undocumented structure" and the tSAC chunk in a Director movie.

EPSS: Средний
github логотип

GHSA-35mf-f26v-97c5

около 4 лет назад

Microsoft Dataverse Information Disclosure Vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-35mf-cxwv-h9xm

больше 4 лет назад

wbook_addworksheet in workbook.c in libexcel.a in libexcel 0.01 allows attackers to cause a denial of service (SEGV) via a long name. NOTE: this is not a Microsoft product.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-35m9-r2q7-2ggv

2 месяца назад

Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-35m9-hm95-j6w7

больше 4 лет назад

The Visual Form Builder WordPress plugin before 3.0.8 does not enforce nonce checks which could allow attackers to make a logged in admin or editor delete and restore arbitrary form entries via CSRF attacks

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-35m9-g697-gr77

больше 4 лет назад

Lack of buffer length check before copying in WLAN function while processing FIPS event, can lead to a buffer overflow in Snapdragon Mobile in version SD 845.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-35mj-mc7c-rc4m

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14270.

62%
Средний
около 4 лет назад
github логотип
GHSA-35mj-3pg9-j9v7

Stack-based buffer overflow in net80211/ieee80211_wireless.c in MadWifi before 0.9.2.1 allows remote attackers to execute arbitrary code via unspecified vectors, related to the encode_ie and giwscan_cb functions.

20%
Средний
больше 4 лет назад
github логотип
GHSA-35mj-225p-fxvg

Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the schedStartTime parameter in the setSchedWifi function.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-35mh-v24c-mjw6

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted LSA Update packet.

CVSS3: 7.5
1%
Низкий
10 месяцев назад
github логотип
GHSA-35mh-m2vc-vgv8

Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
3 дня назад
github логотип
GHSA-35mh-jj82-w9jm

Unauthenticated Broken Access Control in Legal Text Connector of the IT-Recht Kanzlei <= 1.0.13 versions.

CVSS3: 6.5
0%
Низкий
8 дней назад
github логотип
GHSA-35mh-hxcm-w9xp

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in appscreo Hello Followers hellofollowers allows Reflected XSS.This issue affects Hello Followers: from n/a through <= 2.5.

CVSS3: 7.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-35mh-f6p8-pj2c

WPGlobus plugin Stored XSS & CSRF security vulnerability

CVSS3: 4.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-35mh-7m7p-jcq9

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
около 1 года назад
github логотип
GHSA-35mh-4fxp-w6v9

FarLinX X25 Gateway through 2014-09-25 allows attackers to write arbitrary data to fsUI.xyz via fsSaveUIPersistence.php.

1%
Низкий
около 4 лет назад
github логотип
GHSA-35mh-362p-8hhw

The pdf-print plugin before 1.9.4 for WordPress has multiple XSS issues.

CVSS3: 6.1
2%
Низкий
около 4 лет назад
github логотип
GHSA-35mg-p597-mvg8

The List Users API of Piwigo 2.9.2 is vulnerable to SQL Injection via the /admin/user_list_backend.php sSortDir_0 parameter. An attacker can exploit this to gain access to the data in a connected MySQL database.

CVSS3: 4.9
1%
Низкий
больше 4 лет назад
github логотип
GHSA-35mg-4h75-f9m6

Xen 4.4.x, when running on an ARM system and "handling an unknown system register access from 64-bit userspace," returns to an instruction of the trap handler for kernel space faults instead of an instruction that is associated with faults in 64-bit userspace, which allows local guest users to cause a denial of service (crash) and possibly gain privileges via a crafted process.

0%
Низкий
около 4 лет назад
github логотип
GHSA-35mf-vj2p-cr8q

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0313, CVE-2015-0315, and CVE-2015-0322.

10%
Низкий
около 4 лет назад
github логотип
GHSA-35mf-hw36-wj5c

Integer signedness error in the DIRAPI module in Adobe Shockwave Player before 11.5.8.612 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a count value associated with an "undocumented structure" and the tSAC chunk in a Director movie.

13%
Средний
больше 4 лет назад
github логотип
GHSA-35mf-f26v-97c5

Microsoft Dataverse Information Disclosure Vulnerability

CVSS3: 6.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-35mf-cxwv-h9xm

wbook_addworksheet in workbook.c in libexcel.a in libexcel 0.01 allows attackers to cause a denial of service (SEGV) via a long name. NOTE: this is not a Microsoft product.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-35m9-r2q7-2ggv

Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
0%
Низкий
2 месяца назад
github логотип
GHSA-35m9-hm95-j6w7

The Visual Form Builder WordPress plugin before 3.0.8 does not enforce nonce checks which could allow attackers to make a logged in admin or editor delete and restore arbitrary form entries via CSRF attacks

CVSS3: 8.1
0%
Низкий
больше 4 лет назад
github логотип
GHSA-35m9-g697-gr77

Lack of buffer length check before copying in WLAN function while processing FIPS event, can lead to a buffer overflow in Snapdragon Mobile in version SD 845.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу