Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 043

Количество 358 043

github логотип

GHSA-35m7-qv6j-fhf2

11 месяцев назад

Ashlar-Vellum Cobalt XE File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of XE files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26236.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-35m7-pw2x-j9f6

около 4 лет назад

fs/ext4/namei.c in the Linux kernel before 3.7 allows physically proximate attackers to cause a denial of service (system crash) via a crafted no-journal filesystem, a related issue to CVE-2013-2015.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-35m7-cqfx-w4jw

около 2 лет назад

Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.23, 21.3-21.14 and 23.4. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java VM. CVSS 3.1 Base Score 3.1 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-35m7-4c94-48cp

около 4 лет назад

The Bond Trading (aka com.appmakr.app613309) application 197705 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-35m6-rf3v-8cxx

больше 2 лет назад

A Denial of Service (Dos) vulnerability in Nozomi Networks Guardian, caused by improper input validation in certain fields used in the Radius parsing functionality of our IDS, allows an unauthenticated attacker sending specially crafted malformed network packets to cause the IDS module to stop updating nodes, links, and assets. Network traffic may not be analyzed until the IDS module is restarted.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-35m5-pgqp-r25w

больше 3 лет назад

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий
github логотип

GHSA-35m5-8cvj-8783

почти 5 лет назад

Improper hashing in enrocrypt

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-35m5-388q-jrx8

больше 4 лет назад

websendmail in Webgais 1.0 allows a remote user to access arbitrary files and execute arbitrary code via the receiver parameter ($VAR_receiver variable).

EPSS: Средний
github логотип

GHSA-35m5-23fr-x9rq

около 1 года назад

A vulnerability in the Software SMI handler (SwSmiInputValue 0xB2) allows a local attacker to control the RBX register, which is used to derive pointers (OcHeader, OcData) passed into power and thermal configuration logic. These buffers are not validated before performing multiple structured memory writes based on OcSetup NVRAM values, enabling arbitrary SMRAM corruption and potential SMM privilege escalation.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-35m4-rgx2-x5g9

около 4 лет назад

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 5.1 through 12.6.1. It has Incorrect Access Control.

EPSS: Низкий
github логотип

GHSA-35m3-cmx5-j422

больше 4 лет назад

AIX Licensed Program Product performance tools allow local users to gain root access.

EPSS: Низкий
github логотип

GHSA-35m3-cc92-wx4w

больше 4 лет назад

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.2.25013. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the clearItems XFA method. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5288.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-35m2-qpj3-cgx8

больше 1 года назад

The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'process_export_delete' and 'process_import_delete' functions in all versions up to, and including, 4.1.1.2. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-35m2-m75c-vmc4

больше 4 лет назад

Multiple SQL injection vulnerabilities in BytesFall Explorer (bfExplorer) 0.0.7.1 and earlier allow remote attackers to execute arbitrary SQL commands via the username ($User variable) to login/doLogin.php and other unspecified vectors.

EPSS: Низкий
github логотип

GHSA-35m2-m3ch-fgh4

больше 1 года назад

GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to execute arbitrary OS commands via shell metacharacters in an email Subject line.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-35m2-7wwc-q3px

больше 4 лет назад

TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via ISAKMP packets containing a Delete payload with a large number of SPI's, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.

EPSS: Низкий
github логотип

GHSA-35m2-6v5h-6f23

больше 3 лет назад

A file disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator with access to the web interface to export local files from the firewall through a race condition.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-35jx-jhjj-7m69

около 4 лет назад

In handle_ramdump of pixel_loader.c, there is a possible way to create a ramdump of non-secure memory due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-222348453References: N/A

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-35jw-fp6x-xpxj

больше 4 лет назад

RMForum stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for rmforum.mdb.

EPSS: Низкий
github логотип

GHSA-35jw-93qg-qxgw

больше 4 лет назад

Unspecified vulnerability in the Oracle Advanced Benefits component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-35m7-qv6j-fhf2

Ashlar-Vellum Cobalt XE File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of XE files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26236.

CVSS3: 7.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-35m7-pw2x-j9f6

fs/ext4/namei.c in the Linux kernel before 3.7 allows physically proximate attackers to cause a denial of service (system crash) via a crafted no-journal filesystem, a related issue to CVE-2013-2015.

CVSS3: 4.4
0%
Низкий
около 4 лет назад
github логотип
GHSA-35m7-cqfx-w4jw

Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.23, 21.3-21.14 and 23.4. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java VM. CVSS 3.1 Base Score 3.1 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).

CVSS3: 3.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-35m7-4c94-48cp

The Bond Trading (aka com.appmakr.app613309) application 197705 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
около 4 лет назад
github логотип
GHSA-35m6-rf3v-8cxx

A Denial of Service (Dos) vulnerability in Nozomi Networks Guardian, caused by improper input validation in certain fields used in the Radius parsing functionality of our IDS, allows an unauthenticated attacker sending specially crafted malformed network packets to cause the IDS module to stop updating nodes, links, and assets. Network traffic may not be analyzed until the IDS module is restarted.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-35m5-pgqp-r25w

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

больше 3 лет назад
github логотип
GHSA-35m5-8cvj-8783

Improper hashing in enrocrypt

CVSS3: 7.5
1%
Низкий
почти 5 лет назад
github логотип
GHSA-35m5-388q-jrx8

websendmail in Webgais 1.0 allows a remote user to access arbitrary files and execute arbitrary code via the receiver parameter ($VAR_receiver variable).

13%
Средний
больше 4 лет назад
github логотип
GHSA-35m5-23fr-x9rq

A vulnerability in the Software SMI handler (SwSmiInputValue 0xB2) allows a local attacker to control the RBX register, which is used to derive pointers (OcHeader, OcData) passed into power and thermal configuration logic. These buffers are not validated before performing multiple structured memory writes based on OcSetup NVRAM values, enabling arbitrary SMRAM corruption and potential SMM privilege escalation.

CVSS3: 8.2
0%
Низкий
около 1 года назад
github логотип
GHSA-35m4-rgx2-x5g9

An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 5.1 through 12.6.1. It has Incorrect Access Control.

1%
Низкий
около 4 лет назад
github логотип
GHSA-35m3-cmx5-j422

AIX Licensed Program Product performance tools allow local users to gain root access.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-35m3-cc92-wx4w

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.2.25013. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the clearItems XFA method. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5288.

CVSS3: 8.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-35m2-qpj3-cgx8

The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'process_export_delete' and 'process_import_delete' functions in all versions up to, and including, 4.1.1.2. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

CVSS3: 7.2
2%
Низкий
больше 1 года назад
github логотип
GHSA-35m2-m75c-vmc4

Multiple SQL injection vulnerabilities in BytesFall Explorer (bfExplorer) 0.0.7.1 and earlier allow remote attackers to execute arbitrary SQL commands via the username ($User variable) to login/doLogin.php and other unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-35m2-m3ch-fgh4

GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to execute arbitrary OS commands via shell metacharacters in an email Subject line.

CVSS3: 5.4
1%
Низкий
больше 1 года назад
github логотип
GHSA-35m2-7wwc-q3px

TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via ISAKMP packets containing a Delete payload with a large number of SPI's, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-35m2-6v5h-6f23

A file disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator with access to the web interface to export local files from the firewall through a race condition.

CVSS3: 4.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-35jx-jhjj-7m69

In handle_ramdump of pixel_loader.c, there is a possible way to create a ramdump of non-secure memory due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-222348453References: N/A

CVSS3: 4.4
0%
Низкий
около 4 лет назад
github логотип
GHSA-35jw-fp6x-xpxj

RMForum stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for rmforum.mdb.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-35jw-93qg-qxgw

Unspecified vulnerability in the Oracle Advanced Benefits component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу