Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 357 575

Количество 357 575

github логотип

GHSA-34hv-w8p5-75g4

около 4 лет назад

The XML parser in Cisco Prime Service Catalog before 10.1 allows remote authenticated users to read arbitrary files or cause a denial of service (CPU and memory consumption) via an external entity declaration in conjunction with an entity reference, as demonstrated by reading private keys, related to an XML External Entity (XXE) issue, aka Bug ID CSCup92880.

EPSS: Низкий
github логотип

GHSA-34hv-f45p-4qfq

больше 4 лет назад

Open redirect in wwbn/avideo

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-34hq-hcr2-mw2m

около 4 лет назад

In Android before 2018-04-05 or earlier security patch level on Qualcomm Small Cell SoC, Snapdragon Mobile, and Snapdragon Wear FSM9055, MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 835, and SDX20, while logging debug statements or ftrace events from rmnet_data, the socket buffer function uses normal format specifiers which may result in information exposure.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-34hq-9mwc-3x47

около 4 лет назад

The mintToken function of a smart contract implementation for ProjectJ, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-34hq-5g67-gh24

около 4 лет назад

Fenrir Grani 4.5 and earlier does not prevent interaction between web script and the clipboard, which allows remote attackers to read or modify the clipboard contents via a crafted web site.

EPSS: Низкий
github логотип

GHSA-34hp-m978-mc59

почти 3 года назад

ASUS RT-AC86U AiProtection security- related function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-34hm-qhxq-8vfv

около 1 года назад

The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2 via the rename function which can be used to rename uploaded PHP code with a png extension to use a php extension. This allows unauthenticated attackers to execute code on the server.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-34hm-859p-77vj

больше 4 лет назад

Novell eDirectory (eDir) 8.6.2 and Netware 5.1 eDir 85.x allows users with expired passwords to gain inappropriate permissions when logging in from Remote Manager.

EPSS: Низкий
github логотип

GHSA-34hj-xw38-hm2j

около 4 лет назад

Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for Mac, and Cisco Jabber for mobile platforms could allow an attacker to access sensitive information or cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory.

EPSS: Низкий
github логотип

GHSA-34hj-v8fm-x887

около 3 лет назад

Pimcore Path Traversal Vulnerability in AssetController:importServerFilesAction

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-34hj-48ww-g9qc

около 4 лет назад

The Endpoint Manager for Remote Control component in IBM Tivoli Endpoint Manager for Lifecycle Management 9.0.1 before IF6 and 9.1.0 before IF6 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

EPSS: Низкий
github логотип

GHSA-34hg-wrhc-3jwp

около 4 лет назад

A vulnerability classified as critical has been found in Telecommunication Software SAMwin Contact Center Suite 5.1. This affects the function getCurrentDBVersion in the library SAMwinLIBVB.dll of the database handler. The manipulation leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 6.2 is able to address this issue. It is recommended to upgrade the affected component.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-34hg-pm9j-p7gx

около 4 лет назад

A vulnerability affecting F-Secure antivirus engine was discovered whereby unpacking UPX file can lead to denial-of-service. The vulnerability can be exploited remotely by an attacker. A successful attack will result in denial-of-service of the antivirus engine.

EPSS: Низкий
github логотип

GHSA-34hg-76xw-p647

около 4 лет назад

HTTP header injection vulnerability in SEIKO EPSON printers and scanners (DS-570W firmware versions released prior to 2018 March 13, DS-780N firmware versions released prior to 2018 March 13, EP-10VA firmware versions released prior to 2017 September 4, EP-30VA firmware versions released prior to 2017 June 19, EP-707A firmware versions released prior to 2017 August 1, EP-708A firmware versions released prior to 2017 August 7, EP-709A firmware versions released prior to 2017 June 12, EP-777A firmware versions released prior to 2017 August 1, EP-807AB/AW/AR firmware versions released prior to 2017 August 1, EP-808AB/AW/AR firmware versions released prior to 2017 August 7, EP-879AB/AW/AR firmware versions released prior to 2017 June 12, EP-907F firmware versions released prior to 2017 August 1, EP-977A3 firmware versions released prior to 2017 August 1, EP-978A3 firmware versions released prior to 2017 August 7, EP-979A3 firmware versions released prior to 2017 June 12, EP-M570T firmwa...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-34hf-rwhq-v47w

около 4 лет назад

Directory listing is a web server function that displays the directory contents when there is no index file in a specific website directory. A directory listing provides an attacker with the complete index of all the resources located inside of the directory. The specific risks and consequences vary depending on which files are listed and accessible.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-34hf-g744-jw64

около 4 лет назад

i18n Vulnerable to Denial of Service Attack

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-34hf-76gv-wxmv

около 4 лет назад

ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling columns.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-34hc-f35h-vj85

около 4 лет назад

Windows Subsystem for Linux in Windows 10 1703, allows a denial of service vulnerability due to the way it handles objects in memory, aka "Windows Subsystem for Linux Denial of Service Vulnerability".

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-34hc-3v68-5757

около 4 лет назад

Unspecified vulnerability in the configuration service in SAP J2EE Engine allows remote attackers to obtain credential information via unknown vectors.

EPSS: Низкий
github логотип

GHSA-34h9-j269-66p2

около 4 лет назад

Directory traversal vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allows remote administrators to execute arbitrary files via unspecified vectors.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-34hv-w8p5-75g4

The XML parser in Cisco Prime Service Catalog before 10.1 allows remote authenticated users to read arbitrary files or cause a denial of service (CPU and memory consumption) via an external entity declaration in conjunction with an entity reference, as demonstrated by reading private keys, related to an XML External Entity (XXE) issue, aka Bug ID CSCup92880.

2%
Низкий
около 4 лет назад
github логотип
GHSA-34hv-f45p-4qfq

Open redirect in wwbn/avideo

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-34hq-hcr2-mw2m

In Android before 2018-04-05 or earlier security patch level on Qualcomm Small Cell SoC, Snapdragon Mobile, and Snapdragon Wear FSM9055, MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 835, and SDX20, while logging debug statements or ftrace events from rmnet_data, the socket buffer function uses normal format specifiers which may result in information exposure.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-34hq-9mwc-3x47

The mintToken function of a smart contract implementation for ProjectJ, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-34hq-5g67-gh24

Fenrir Grani 4.5 and earlier does not prevent interaction between web script and the clipboard, which allows remote attackers to read or modify the clipboard contents via a crafted web site.

1%
Низкий
около 4 лет назад
github логотип
GHSA-34hp-m978-mc59

ASUS RT-AC86U AiProtection security- related function has insufficient filtering of special character. A remote attacker with regular user privilege can exploit this vulnerability to perform command injection attack to execute arbitrary commands, disrupt system or terminate services.

CVSS3: 8.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-34hm-qhxq-8vfv

The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2 via the rename function which can be used to rename uploaded PHP code with a png extension to use a php extension. This allows unauthenticated attackers to execute code on the server.

CVSS3: 9.8
18%
Средний
около 1 года назад
github логотип
GHSA-34hm-859p-77vj

Novell eDirectory (eDir) 8.6.2 and Netware 5.1 eDir 85.x allows users with expired passwords to gain inappropriate permissions when logging in from Remote Manager.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-34hj-xw38-hm2j

Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for Mac, and Cisco Jabber for mobile platforms could allow an attacker to access sensitive information or cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory.

1%
Низкий
около 4 лет назад
github логотип
GHSA-34hj-v8fm-x887

Pimcore Path Traversal Vulnerability in AssetController:importServerFilesAction

CVSS3: 6.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-34hj-48ww-g9qc

The Endpoint Manager for Remote Control component in IBM Tivoli Endpoint Manager for Lifecycle Management 9.0.1 before IF6 and 9.1.0 before IF6 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

1%
Низкий
около 4 лет назад
github логотип
GHSA-34hg-wrhc-3jwp

A vulnerability classified as critical has been found in Telecommunication Software SAMwin Contact Center Suite 5.1. This affects the function getCurrentDBVersion in the library SAMwinLIBVB.dll of the database handler. The manipulation leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 6.2 is able to address this issue. It is recommended to upgrade the affected component.

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-34hg-pm9j-p7gx

A vulnerability affecting F-Secure antivirus engine was discovered whereby unpacking UPX file can lead to denial-of-service. The vulnerability can be exploited remotely by an attacker. A successful attack will result in denial-of-service of the antivirus engine.

0%
Низкий
около 4 лет назад
github логотип
GHSA-34hg-76xw-p647

HTTP header injection vulnerability in SEIKO EPSON printers and scanners (DS-570W firmware versions released prior to 2018 March 13, DS-780N firmware versions released prior to 2018 March 13, EP-10VA firmware versions released prior to 2017 September 4, EP-30VA firmware versions released prior to 2017 June 19, EP-707A firmware versions released prior to 2017 August 1, EP-708A firmware versions released prior to 2017 August 7, EP-709A firmware versions released prior to 2017 June 12, EP-777A firmware versions released prior to 2017 August 1, EP-807AB/AW/AR firmware versions released prior to 2017 August 1, EP-808AB/AW/AR firmware versions released prior to 2017 August 7, EP-879AB/AW/AR firmware versions released prior to 2017 June 12, EP-907F firmware versions released prior to 2017 August 1, EP-977A3 firmware versions released prior to 2017 August 1, EP-978A3 firmware versions released prior to 2017 August 7, EP-979A3 firmware versions released prior to 2017 June 12, EP-M570T firmwa...

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-34hf-rwhq-v47w

Directory listing is a web server function that displays the directory contents when there is no index file in a specific website directory. A directory listing provides an attacker with the complete index of all the resources located inside of the directory. The specific risks and consequences vary depending on which files are listed and accessible.

CVSS3: 5.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-34hf-g744-jw64

i18n Vulnerable to Denial of Service Attack

CVSS3: 7.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-34hf-76gv-wxmv

ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling columns.

CVSS3: 8.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-34hc-f35h-vj85

Windows Subsystem for Linux in Windows 10 1703, allows a denial of service vulnerability due to the way it handles objects in memory, aka "Windows Subsystem for Linux Denial of Service Vulnerability".

CVSS3: 4.7
2%
Низкий
около 4 лет назад
github логотип
GHSA-34hc-3v68-5757

Unspecified vulnerability in the configuration service in SAP J2EE Engine allows remote attackers to obtain credential information via unknown vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-34h9-j269-66p2

Directory traversal vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allows remote administrators to execute arbitrary files via unspecified vectors.

2%
Низкий
около 4 лет назад

Уязвимостей на страницу