Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 341 526

Количество 341 526

github логотип

GHSA-26mc-6xx6-g2q4

около 4 лет назад

** DISPUTED ** The libfsntfs_reparse_point_values_read_data function in libfsntfs_reparse_point_values.c in libfsntfs through 2018-04-20 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted ntfs file. NOTE: the vendor has disputed this as described in libyal/libfsntfs issue 8 on GitHub.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-26m9-9qmg-7c26

около 4 лет назад

eBrigade before 5.0 has evenement_ical.php evenement SQL Injection.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-26m8-fjr7-qf85

больше 4 лет назад

Heap-based buffer overflow in an API in GDI in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows context-dependent attackers to cause a denial of service or execute arbitrary code via a WMF file with a malformed file-size parameter, which would not be properly handled by a third-party application that uses this API for a copy operation, aka "GDI Heap Overflow Vulnerability."

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-26m8-33mx-qgcj

больше 2 лет назад

Stupid Simple CMS v1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /save_settings.php

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-26m8-335m-qj22

больше 1 года назад

HCL SX does not set the secure attribute on authorization tokens or session cookies. Attackers may potentially be able to obtain access to the cookie values via a Cross-Site-Forgery-Request (CSRF).

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-26m7-x2xv-cj76

около 4 лет назад

Possible denial of service scenario due to improper input validation of received NAS OTA message in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

EPSS: Низкий
github логотип

GHSA-26m7-wv2f-g2rw

около 4 лет назад

The bcm_char_ioctl function in drivers/staging/bcm/Bcmchar.c in the Linux kernel before 3.12 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory via an IOCTL_BCM_GET_DEVICE_DRIVER_INFO ioctl call.

EPSS: Низкий
github логотип

GHSA-26m7-h3mc-j98r

больше 4 лет назад

SQL injection vulnerability in offers_buy.php in Alibaba Clone 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

EPSS: Низкий
github логотип

GHSA-26m6-xq66-wqvc

около 2 лет назад

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm-all-packages' shortcode in all versions up to, and including, 3.2.90 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-26m6-rw98-f5xx

больше 4 лет назад

The WriteBlob function in MagickCore/blob.c in ImageMagick before 6.9.8-10 and 7.x before 7.6.0-0 allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-26m6-4q8m-5vcm

около 4 лет назад

core/rendering/compositing/RenderLayerCompositor.cpp in Blink, as used in Google Chrome before 38.0.2125.102 on Android, does not properly handle a certain IFRAME overflow condition, which allows remote attackers to spoof content via a crafted web site that interferes with the scrollbar.

EPSS: Низкий
github логотип

GHSA-26m5-cv5f-4mwg

больше 1 года назад

Cross Site Scripting vulnerabilities where found providing a potential for malicious scripts to be injected into a client browser.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-26m4-qjp9-xmc6

почти 4 года назад

Apache InLong vulnerable to Deserialization of Untrusted Data

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-26m3-w3qj-hwgj

около 4 лет назад

GE Communicator, all versions prior to 4.0.517, has a service running with system privileges that may allow an unprivileged user to perform certain administrative actions, which may allow the execution of scheduled scripts with system administrator privileges. This service is inaccessible to attackers if Windows default firewall settings are used by the end user.

EPSS: Низкий
github логотип

GHSA-26m3-ccwr-9974

больше 4 лет назад

The Notes Remote Procedure Call (NRPC) protocol in IBM Lotus Notes Domino before 6.5.5 FP2 and 7.x before 7.0.2 does not require authentication to perform user lookups, which allows remote attackers to obtain the user ID file.

EPSS: Средний
github логотип

GHSA-26m2-9g2q-v45q

около 2 месяцев назад

In Spring Cloud Sleuth, it is possible for a user to provide specially crafted calls that may cause a denial-of-service (DoS) condition. The application is vulnerable when it uses a vulnerable version of org.springframework.cloud:spring-cloud-sleuth-instrumentation and Spring TX instrumentation is not disabled. Affected versions: Spring Cloud Sleuth 3.1.0 through 3.1.13.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-26m2-987p-rmm4

больше 4 лет назад

Improper boundary check in UWB firmware prior to SMR Apr-2022 Release 1 allows arbitrary memory write.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-26m2-7wh6-pcq6

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in the pathname in an FTP URI.

EPSS: Средний
github логотип

GHSA-26m2-3jc9-5rqh

около 4 лет назад

IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.16 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 192737.

EPSS: Низкий
github логотип

GHSA-26jx-q9vr-x6rw

10 месяцев назад

The Course Redirects for Learndash plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.4. This is due to missing nonce validation when processing form submissions on the settings page. This makes it possible for unauthenticated attackers to modify plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-26mc-6xx6-g2q4

** DISPUTED ** The libfsntfs_reparse_point_values_read_data function in libfsntfs_reparse_point_values.c in libfsntfs through 2018-04-20 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted ntfs file. NOTE: the vendor has disputed this as described in libyal/libfsntfs issue 8 on GitHub.

CVSS3: 5.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-26m9-9qmg-7c26

eBrigade before 5.0 has evenement_ical.php evenement SQL Injection.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-26m8-fjr7-qf85

Heap-based buffer overflow in an API in GDI in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows context-dependent attackers to cause a denial of service or execute arbitrary code via a WMF file with a malformed file-size parameter, which would not be properly handled by a third-party application that uses this API for a copy operation, aka "GDI Heap Overflow Vulnerability."

CVSS3: 9.8
14%
Средний
больше 4 лет назад
github логотип
GHSA-26m8-33mx-qgcj

Stupid Simple CMS v1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /save_settings.php

CVSS3: 6.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-26m8-335m-qj22

HCL SX does not set the secure attribute on authorization tokens or session cookies. Attackers may potentially be able to obtain access to the cookie values via a Cross-Site-Forgery-Request (CSRF).

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-26m7-x2xv-cj76

Possible denial of service scenario due to improper input validation of received NAS OTA message in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

1%
Низкий
около 4 лет назад
github логотип
GHSA-26m7-wv2f-g2rw

The bcm_char_ioctl function in drivers/staging/bcm/Bcmchar.c in the Linux kernel before 3.12 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory via an IOCTL_BCM_GET_DEVICE_DRIVER_INFO ioctl call.

0%
Низкий
около 4 лет назад
github логотип
GHSA-26m7-h3mc-j98r

SQL injection vulnerability in offers_buy.php in Alibaba Clone 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-26m6-xq66-wqvc

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm-all-packages' shortcode in all versions up to, and including, 3.2.90 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-26m6-rw98-f5xx

The WriteBlob function in MagickCore/blob.c in ImageMagick before 6.9.8-10 and 7.x before 7.6.0-0 allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted file.

CVSS3: 6.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-26m6-4q8m-5vcm

core/rendering/compositing/RenderLayerCompositor.cpp in Blink, as used in Google Chrome before 38.0.2125.102 on Android, does not properly handle a certain IFRAME overflow condition, which allows remote attackers to spoof content via a crafted web site that interferes with the scrollbar.

1%
Низкий
около 4 лет назад
github логотип
GHSA-26m5-cv5f-4mwg

Cross Site Scripting vulnerabilities where found providing a potential for malicious scripts to be injected into a client browser.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

CVSS3: 9
1%
Низкий
больше 1 года назад
github логотип
GHSA-26m4-qjp9-xmc6

Apache InLong vulnerable to Deserialization of Untrusted Data

CVSS3: 8.8
2%
Низкий
почти 4 года назад
github логотип
GHSA-26m3-w3qj-hwgj

GE Communicator, all versions prior to 4.0.517, has a service running with system privileges that may allow an unprivileged user to perform certain administrative actions, which may allow the execution of scheduled scripts with system administrator privileges. This service is inaccessible to attackers if Windows default firewall settings are used by the end user.

1%
Низкий
около 4 лет назад
github логотип
GHSA-26m3-ccwr-9974

The Notes Remote Procedure Call (NRPC) protocol in IBM Lotus Notes Domino before 6.5.5 FP2 and 7.x before 7.0.2 does not require authentication to perform user lookups, which allows remote attackers to obtain the user ID file.

13%
Средний
больше 4 лет назад
github логотип
GHSA-26m2-9g2q-v45q

In Spring Cloud Sleuth, it is possible for a user to provide specially crafted calls that may cause a denial-of-service (DoS) condition. The application is vulnerable when it uses a vulnerable version of org.springframework.cloud:spring-cloud-sleuth-instrumentation and Spring TX instrumentation is not disabled. Affected versions: Spring Cloud Sleuth 3.1.0 through 3.1.13.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-26m2-987p-rmm4

Improper boundary check in UWB firmware prior to SMR Apr-2022 Release 1 allows arbitrary memory write.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-26m2-7wh6-pcq6

Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in the pathname in an FTP URI.

39%
Средний
больше 4 лет назад
github логотип
GHSA-26m2-3jc9-5rqh

IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.16 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 192737.

0%
Низкий
около 4 лет назад
github логотип
GHSA-26jx-q9vr-x6rw

The Course Redirects for Learndash plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.4. This is due to missing nonce validation when processing form submissions on the settings page. This makes it possible for unauthenticated attackers to modify plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
10 месяцев назад

Уязвимостей на страницу