Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 043

Количество 358 043

github логотип

GHSA-35hp-m7hg-c3cm

около 4 лет назад

HUAWEI P30 smart phones with versions earlier than 10.1.0.160(C00E160R2P11) have an information exposure vulnerability. The system does not properly authenticate the application that access a specified interface. Attackers can trick users into installing malicious software to exploit this vulnerability and obtain some information about the device. Successful exploit may cause information disclosure.

EPSS: Низкий
github логотип

GHSA-35hp-j5x2-wc4r

около 4 лет назад

User Profile Service Denial of Service Vulnerability

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-35hp-hqmv-8qg8

4 месяца назад

Fiber's cache middleware default key generator ignores query string, causing response mix-up across distinct query parameters

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-35hp-gw4q-r3gw

около 4 лет назад

Untrusted search path vulnerability in Installer for Shin Kikan Toukei Houkoku Data Nyuryokuyou Program (program released on 2013 September 30) Distributed on the website until 2017 May 17 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-35hj-qx98-rwpj

около 4 лет назад

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

EPSS: Низкий
github логотип

GHSA-35hj-qwr7-v3x4

больше 4 лет назад

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetTime param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-35hj-g5rm-v2ch

больше 4 лет назад

Multiple use-after-free vulnerabilities in epan/dissectors/packet-dec-dnart.c in the DEC DNA Routing Protocol dissector in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 allow remote attackers to cause a denial of service (application crash) via a crafted packet, related to the use of packet-scope memory instead of pinfo-scope memory.

EPSS: Низкий
github логотип

GHSA-35hj-f3wv-8wgc

около 4 лет назад

IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 202769.

EPSS: Низкий
github логотип

GHSA-35hh-4hmp-9jm3

больше 4 лет назад

Use-after-free vulnerability in Google Chrome before 17.0.963.56 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to drag-and-drop operations.

EPSS: Низкий
github логотип

GHSA-35hg-m22v-mcj5

4 месяца назад

A flaw has been found in assafelovic gpt-researcher up to 3.4.3. The impacted element is an unknown function of the file backend/server/app.py of the component Report API. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-35hg-hj3j-7whc

больше 3 лет назад

The Appointment Hour Booking Plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.3.72. This makes it possible for unauthenticated attackers to embed untrusted input into content during booking creation that may be exported as a CSV file when a site's administrator exports booking details. This can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-35hg-hhvc-v35w

около 4 лет назад

IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 196341.

EPSS: Низкий
github логотип

GHSA-35hg-f9qq-236g

почти 3 года назад

Eaton easyE4 PLC offers a device password protection functionality to facilitate a secure connection and prevent unauthorized access. It was observed that the device password was stored with a weak encoding algorithm in the easyE4 program file when exported to SD card (*.PRG file ending).

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-35hc-x2cw-2j4v

почти 8 лет назад

Denial of service vulnerability exists when .NET and .NET Core improperly process XML documents

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-35hc-p777-hj85

больше 4 лет назад

Integer underflow in the DecodeGRE function in src/decode.c in Snort 2.6.1.2 allows remote attackers to trigger dereferencing of certain memory locations via crafted GRE packets, which may cause corruption of log files or writing of sensitive information into log files.

EPSS: Низкий
github логотип

GHSA-35hc-96mm-v6rf

около 4 лет назад

An issue was discovered in Phalcon Eye through 0.4.1. The vulnerability exists due to insufficient filtration of user-supplied data in multiple HTTP GET parameters passed to the "phalconeye-master/public/external/pydio/plugins/editor.webodf/frame.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-35hc-25v2-p75r

около 2 лет назад

The SolarWinds Platform was determined to be affected by a reflected cross-site scripting vulnerability affecting the web console. A high-privileged user and user interaction is required to exploit this vulnerability.

CVSS3: 7.9
EPSS: Низкий
github логотип

GHSA-35h9-x59q-8xcf

больше 4 лет назад

In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to mount a FUSE file system with the 'allow_other' mount option regardless of whether 'user_allow_other' is set in the fuse configuration. An attacker may use this flaw to mount a FUSE file system, accessible by other users, and trick them into accessing files on that file system, possibly causing Denial of Service or other unspecified effects.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-35h9-jh69-pc24

4 месяца назад

Privilege escalation in the Debugger component. This vulnerability was fixed in Firefox 150 and Firefox ESR 140.10.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-35h9-h439-vvmr

больше 4 лет назад

Stored Cross-site Scripting vulnerability in Jenkins Environment Dashboard Plugin

CVSS3: 8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-35hp-m7hg-c3cm

HUAWEI P30 smart phones with versions earlier than 10.1.0.160(C00E160R2P11) have an information exposure vulnerability. The system does not properly authenticate the application that access a specified interface. Attackers can trick users into installing malicious software to exploit this vulnerability and obtain some information about the device. Successful exploit may cause information disclosure.

1%
Низкий
около 4 лет назад
github логотип
GHSA-35hp-j5x2-wc4r

User Profile Service Denial of Service Vulnerability

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-35hp-hqmv-8qg8

Fiber's cache middleware default key generator ignores query string, causing response mix-up across distinct query parameters

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-35hp-gw4q-r3gw

Untrusted search path vulnerability in Installer for Shin Kikan Toukei Houkoku Data Nyuryokuyou Program (program released on 2013 September 30) Distributed on the website until 2017 May 17 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-35hj-qx98-rwpj

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

2%
Низкий
около 4 лет назад
github логотип
GHSA-35hj-qwr7-v3x4

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetTime param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-35hj-g5rm-v2ch

Multiple use-after-free vulnerabilities in epan/dissectors/packet-dec-dnart.c in the DEC DNA Routing Protocol dissector in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 allow remote attackers to cause a denial of service (application crash) via a crafted packet, related to the use of packet-scope memory instead of pinfo-scope memory.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-35hj-f3wv-8wgc

IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 202769.

1%
Низкий
около 4 лет назад
github логотип
GHSA-35hh-4hmp-9jm3

Use-after-free vulnerability in Google Chrome before 17.0.963.56 allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to drag-and-drop operations.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-35hg-m22v-mcj5

A flaw has been found in assafelovic gpt-researcher up to 3.4.3. The impacted element is an unknown function of the file backend/server/app.py of the component Report API. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 4.3
0%
Низкий
4 месяца назад
github логотип
GHSA-35hg-hj3j-7whc

The Appointment Hour Booking Plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.3.72. This makes it possible for unauthenticated attackers to embed untrusted input into content during booking creation that may be exported as a CSV file when a site's administrator exports booking details. This can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-35hg-hhvc-v35w

IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 196341.

1%
Низкий
около 4 лет назад
github логотип
GHSA-35hg-f9qq-236g

Eaton easyE4 PLC offers a device password protection functionality to facilitate a secure connection and prevent unauthorized access. It was observed that the device password was stored with a weak encoding algorithm in the easyE4 program file when exported to SD card (*.PRG file ending).

CVSS3: 6.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-35hc-x2cw-2j4v

Denial of service vulnerability exists when .NET and .NET Core improperly process XML documents

CVSS3: 7.5
8%
Низкий
почти 8 лет назад
github логотип
GHSA-35hc-p777-hj85

Integer underflow in the DecodeGRE function in src/decode.c in Snort 2.6.1.2 allows remote attackers to trigger dereferencing of certain memory locations via crafted GRE packets, which may cause corruption of log files or writing of sensitive information into log files.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-35hc-96mm-v6rf

An issue was discovered in Phalcon Eye through 0.4.1. The vulnerability exists due to insufficient filtration of user-supplied data in multiple HTTP GET parameters passed to the "phalconeye-master/public/external/pydio/plugins/editor.webodf/frame.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-35hc-25v2-p75r

The SolarWinds Platform was determined to be affected by a reflected cross-site scripting vulnerability affecting the web console. A high-privileged user and user interaction is required to exploit this vulnerability.

CVSS3: 7.9
0%
Низкий
около 2 лет назад
github логотип
GHSA-35h9-x59q-8xcf

In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to mount a FUSE file system with the 'allow_other' mount option regardless of whether 'user_allow_other' is set in the fuse configuration. An attacker may use this flaw to mount a FUSE file system, accessible by other users, and trick them into accessing files on that file system, possibly causing Denial of Service or other unspecified effects.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-35h9-jh69-pc24

Privilege escalation in the Debugger component. This vulnerability was fixed in Firefox 150 and Firefox ESR 140.10.

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-35h9-h439-vvmr

Stored Cross-site Scripting vulnerability in Jenkins Environment Dashboard Plugin

CVSS3: 8
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу