Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 043

Количество 358 043

github логотип

GHSA-35jh-2r79-5r66

около 4 лет назад

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0710, CVE-2020-0711, CVE-2020-0712, CVE-2020-0713, CVE-2020-0767.

CVSS3: 7.5
EPSS: Высокий
github логотип

GHSA-35jg-8pwm-5q3v

около 4 лет назад

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.32 and prior to 6.0.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.0 Base Score 2.8 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L).

EPSS: Низкий
github логотип

GHSA-35jf-jfrv-9p25

около 4 лет назад

The diag-router module has a vulnerability in intercepting excessive long and short instructions. Successful exploitation of this vulnerability will cause the diag-router module to crash.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-35jf-fw8j-m7v3

больше 4 лет назад

Auerswald COMsuite CTI ControlCenter 3.1 creates a default "runasositron" user account with an easily guessable password, which allows local users or remote attackers to gain access.

EPSS: Низкий
github логотип

GHSA-35jc-cjp6-54c4

больше 4 лет назад

Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-35jc-5h4r-p9cg

2 месяца назад

Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-35j8-v8xw-wrrr

около 4 лет назад

Stack-based buffer overflow in the smc program in smcFanControl 2.1.2 allows local users to execute arbitrary code and gain privileges via a long -k option.

EPSS: Низкий
github логотип

GHSA-35j6-m37x-rh4q

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the embedded webserver in Daniel Naber LanguageTool before 0.8.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving an error message, possibly the demultiplex method in HTTPServer.java.

EPSS: Низкий
github логотип

GHSA-35j6-7x52-47f7

около 4 лет назад

WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-04-01-1.

EPSS: Низкий
github логотип

GHSA-35j6-76jp-jqcj

около 4 лет назад

An issue was discovered in Sysdig through 0.24.2, as used in Falco through 0.14.0 and other products. A bypass allows local users to run malicious code without being detected because record_event_consumer in driver/main.c in sysdig-probe.ko (and falco-probe.ko) mishandles a free space calculation.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-35j5-m29r-xfq5

почти 3 года назад

XWiki Rendering's footnote macro vulnerable to privilege escalation via the footnote macro

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-35j5-3cvj-g2x4

около 4 лет назад

An issue was discovered in Veritas NetBackup through 8.3.0.1 and OpsCenter through 8.3.0.1. Processes using OpenSSL attempt to load and execute libraries from paths that do not exist by default on the Windows operating system. By default, on Windows systems, users can create directories under the top level of any drive. If a low privileged user creates an affected path with a library that the Veritas product attempts to load, they can execute arbitrary code as SYSTEM or Administrator. This gives the attacker administrator access on the system, allowing the attacker (by default) to access all data, access all installed applications, etc. This vulnerability affects master servers, media servers, clients, and OpsCenter servers on the Windows platform. The system is vulnerable during an install or upgrade and post-install during normal operations.

EPSS: Низкий
github логотип

GHSA-35j4-qh5f-vwv5

почти 2 года назад

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Layout Templates). Supported versions that are affected are 7.0.0.0.0, 7.6.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L).

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-35j4-pxc2-3gcf

больше 2 лет назад

Cross Site Scripting vulnerability in ITFlow.org before commit v.432488eca3998c5be6b6b9e8f8ba01f54bc12378 allows a remtoe attacker to execute arbitrary code and obtain sensitive information via the settings.php, settings+company.php, settings_defaults.php,settings_integrations.php, settings_invoice.php, settings_localization.php, settings_mail.php components.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-35j4-fgvf-285h

5 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in don-themes Molla molla allows PHP Local File Inclusion.This issue affects Molla: from n/a through <= 1.5.16.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-35j4-3hfm-6mj2

больше 2 лет назад

There is Stored Cross-Site Scripting (XSS) in dzzoffice 2.02.1 SC UTF8 in uploadfile to index.php, with the XSS payload in an SVG document.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-35j3-xgpv-8g44

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the Navigate module for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-35j3-w22f-jh7w

около 4 лет назад

An issue was discovered in Luvion Grand Elite 3 Connect through 2020-02-25. Authentication to the device is based on a username and password. The root credentials are the same across all devices of this model.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-35j2-xmwj-f25h

7 месяцев назад

Missing Authorization vulnerability in FmeAddons Registration & Login with Mobile Phone Number for WooCommerce registration-login-with-mobile-phone-number allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Registration & Login with Mobile Phone Number for WooCommerce: from n/a through <= 1.3.1.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-35j2-p8fh-x966

около 4 лет назад

Elastic APM agent for Ruby vulnerable to Improper Certificate Validation

CVSS3: 7.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-35jh-2r79-5r66

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0710, CVE-2020-0711, CVE-2020-0712, CVE-2020-0713, CVE-2020-0767.

CVSS3: 7.5
87%
Высокий
около 4 лет назад
github логотип
GHSA-35jg-8pwm-5q3v

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.32 and prior to 6.0.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.0 Base Score 2.8 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L).

0%
Низкий
около 4 лет назад
github логотип
GHSA-35jf-jfrv-9p25

The diag-router module has a vulnerability in intercepting excessive long and short instructions. Successful exploitation of this vulnerability will cause the diag-router module to crash.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-35jf-fw8j-m7v3

Auerswald COMsuite CTI ControlCenter 3.1 creates a default "runasositron" user account with an easily guessable password, which allows local users or remote attackers to gain access.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-35jc-cjp6-54c4

Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-35jc-5h4r-p9cg

Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

CVSS3: 8.8
0%
Низкий
2 месяца назад
github логотип
GHSA-35j8-v8xw-wrrr

Stack-based buffer overflow in the smc program in smcFanControl 2.1.2 allows local users to execute arbitrary code and gain privileges via a long -k option.

1%
Низкий
около 4 лет назад
github логотип
GHSA-35j6-m37x-rh4q

Cross-site scripting (XSS) vulnerability in the embedded webserver in Daniel Naber LanguageTool before 0.8.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving an error message, possibly the demultiplex method in HTTPServer.java.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-35j6-7x52-47f7

WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-04-01-1.

2%
Низкий
около 4 лет назад
github логотип
GHSA-35j6-76jp-jqcj

An issue was discovered in Sysdig through 0.24.2, as used in Falco through 0.14.0 and other products. A bypass allows local users to run malicious code without being detected because record_event_consumer in driver/main.c in sysdig-probe.ko (and falco-probe.ko) mishandles a free space calculation.

CVSS3: 5.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-35j5-m29r-xfq5

XWiki Rendering's footnote macro vulnerable to privilege escalation via the footnote macro

CVSS3: 8.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-35j5-3cvj-g2x4

An issue was discovered in Veritas NetBackup through 8.3.0.1 and OpsCenter through 8.3.0.1. Processes using OpenSSL attempt to load and execute libraries from paths that do not exist by default on the Windows operating system. By default, on Windows systems, users can create directories under the top level of any drive. If a low privileged user creates an affected path with a library that the Veritas product attempts to load, they can execute arbitrary code as SYSTEM or Administrator. This gives the attacker administrator access on the system, allowing the attacker (by default) to access all data, access all installed applications, etc. This vulnerability affects master servers, media servers, clients, and OpsCenter servers on the Windows platform. The system is vulnerable during an install or upgrade and post-install during normal operations.

0%
Низкий
около 4 лет назад
github логотип
GHSA-35j4-qh5f-vwv5

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Layout Templates). Supported versions that are affected are 7.0.0.0.0, 7.6.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L).

CVSS3: 7.6
0%
Низкий
почти 2 года назад
github логотип
GHSA-35j4-pxc2-3gcf

Cross Site Scripting vulnerability in ITFlow.org before commit v.432488eca3998c5be6b6b9e8f8ba01f54bc12378 allows a remtoe attacker to execute arbitrary code and obtain sensitive information via the settings.php, settings+company.php, settings_defaults.php,settings_integrations.php, settings_invoice.php, settings_localization.php, settings_mail.php components.

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-35j4-fgvf-285h

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in don-themes Molla molla allows PHP Local File Inclusion.This issue affects Molla: from n/a through <= 1.5.16.

CVSS3: 8.1
1%
Низкий
5 месяцев назад
github логотип
GHSA-35j4-3hfm-6mj2

There is Stored Cross-Site Scripting (XSS) in dzzoffice 2.02.1 SC UTF8 in uploadfile to index.php, with the XSS payload in an SVG document.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-35j3-xgpv-8g44

Cross-site scripting (XSS) vulnerability in the Navigate module for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-35j3-w22f-jh7w

An issue was discovered in Luvion Grand Elite 3 Connect through 2020-02-25. Authentication to the device is based on a username and password. The root credentials are the same across all devices of this model.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-35j2-xmwj-f25h

Missing Authorization vulnerability in FmeAddons Registration & Login with Mobile Phone Number for WooCommerce registration-login-with-mobile-phone-number allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Registration & Login with Mobile Phone Number for WooCommerce: from n/a through <= 1.3.1.

CVSS3: 9.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-35j2-p8fh-x966

Elastic APM agent for Ruby vulnerable to Improper Certificate Validation

CVSS3: 7.4
1%
Низкий
около 4 лет назад

Уязвимостей на страницу