Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 357 271

Количество 357 271

github логотип

GHSA-33vg-9h99-96pc

около 4 лет назад

A denial of service issue was addressed with improved input validation.

EPSS: Низкий
github логотип

GHSA-33vf-v7x5-68hh

около 4 лет назад

Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 77.0.3865.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

EPSS: Низкий
github логотип

GHSA-33vf-chjh-98j4

больше 4 лет назад

Buffer overflow in the RTSP protocol parser for the View Source plug-in (vsrcplin.so or vsrcplin3260.dll) for RealNetworks Helix Universal Server 9 and RealSystem Server 8, 7 and RealServer G2 allows remote attackers to execute arbitrary code.

EPSS: Средний
github логотип

GHSA-33vf-9722-2226

около 4 лет назад

softmagic.c in file before 5.17 and libmagic allows context-dependent attackers to cause a denial of service (out-of-bounds memory access and crash) via crafted offsets in the softmagic of a PE executable.

EPSS: Низкий
github логотип

GHSA-33vf-4xgg-9r58

больше 6 лет назад

HTTP Response Splitting (Early Hints) in Puma

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-33vc-wfww-vjfv

11 месяцев назад

jsondiffpatch is vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeBegin

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-33vc-mr28-327x

больше 4 лет назад

In GraphicsMagick 1.4 snapshot-20181209 Q8, there is a heap-based buffer overflow in the WriteTGAImage function of tga.c, which allows attackers to cause a denial of service via a crafted image file, because the number of rows or columns can exceed the pixel-dimension restrictions of the TGA specification.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-33vc-jm33-3f35

больше 1 года назад

Zammad before 6.4.1 places sensitive data (such as auth_microsoft_office365_credentials and application_secret) in log files.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-33v9-rqhp-2p82

около 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in register.php in Piwigo 2.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) login and (2) mail_address parameters.

EPSS: Низкий
github логотип

GHSA-33v9-jfq7-pmxc

23 дня назад

Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-33v9-9rxf-3675

около 4 лет назад

On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, and 13.1.x before 13.1.4, when JSON content profiles are configured for URLs as part of an F5 Advanced Web Application Firewall (WAF)/BIG-IP ASM security policy and applied to a virtual server, undisclosed requests may cause the BIG-IP ASM bd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

EPSS: Низкий
github логотип

GHSA-33v9-7cpf-3wr4

5 месяцев назад

Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-33v8-g7j5-qg76

5 месяцев назад

OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary OS command may be executed on the products.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-33v7-x483-jjjx

около 4 лет назад

An out-of-bounds read exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service and read sensitive memory.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-33v7-h6gx-6h2h

около 4 лет назад

In getAppSize of InstalldNativeService.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-220733817

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-33v7-2ghp-xqch

около 4 лет назад

Improper buffer restrictions in firmware for Intel(R) NUC may allow an authenticated user to potentially enable escalation of privilege via local access. The list of affected products is provided in intel-sa-00343: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00343.html

EPSS: Низкий
github логотип

GHSA-33v5-vv3q-q64q

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in EditModule.aspx for DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to inject arbitrary web script or HTML.

EPSS: Низкий
github логотип

GHSA-33v5-9rfm-w3f4

около 2 лет назад

The WP QuickLaTeX WordPress plugin before 3.8.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-33v5-6gf6-m6w4

больше 4 лет назад

Multiple stack-based buffer overflows in the CPLI_ReadTag_OGG function in CPI_PlaylistItem.c in CoolPlayer 217 and earlier allow user-assisted remote attackers to execute arbitrary code via a long (1) cTag or (2) cValue field in an OGG Vorbis file.

EPSS: Низкий
github логотип

GHSA-33v4-rh3c-mhcg

почти 4 года назад

A local file disclosure vulnerability in /appConfig/userDB.json of Telos Alliance Omnia MPX Node through 1.5.0+r1 allows attackers to escalate privileges to root and execute arbitrary commands.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-33vg-9h99-96pc

A denial of service issue was addressed with improved input validation.

2%
Низкий
около 4 лет назад
github логотип
GHSA-33vf-v7x5-68hh

Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 77.0.3865.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

1%
Низкий
около 4 лет назад
github логотип
GHSA-33vf-chjh-98j4

Buffer overflow in the RTSP protocol parser for the View Source plug-in (vsrcplin.so or vsrcplin3260.dll) for RealNetworks Helix Universal Server 9 and RealSystem Server 8, 7 and RealServer G2 allows remote attackers to execute arbitrary code.

49%
Средний
больше 4 лет назад
github логотип
GHSA-33vf-9722-2226

softmagic.c in file before 5.17 and libmagic allows context-dependent attackers to cause a denial of service (out-of-bounds memory access and crash) via crafted offsets in the softmagic of a PE executable.

4%
Низкий
около 4 лет назад
github логотип
GHSA-33vf-4xgg-9r58

HTTP Response Splitting (Early Hints) in Puma

CVSS3: 6.5
2%
Низкий
больше 6 лет назад
github логотип
GHSA-33vc-wfww-vjfv

jsondiffpatch is vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeBegin

CVSS3: 4.7
0%
Низкий
11 месяцев назад
github логотип
GHSA-33vc-mr28-327x

In GraphicsMagick 1.4 snapshot-20181209 Q8, there is a heap-based buffer overflow in the WriteTGAImage function of tga.c, which allows attackers to cause a denial of service via a crafted image file, because the number of rows or columns can exceed the pixel-dimension restrictions of the TGA specification.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-33vc-jm33-3f35

Zammad before 6.4.1 places sensitive data (such as auth_microsoft_office365_credentials and application_secret) in log files.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-33v9-rqhp-2p82

Multiple cross-site scripting (XSS) vulnerabilities in register.php in Piwigo 2.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) login and (2) mail_address parameters.

1%
Низкий
около 4 лет назад
github логотип
GHSA-33v9-jfq7-pmxc

Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153.

CVSS3: 6.5
0%
Низкий
23 дня назад
github логотип
GHSA-33v9-9rxf-3675

On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, and 13.1.x before 13.1.4, when JSON content profiles are configured for URLs as part of an F5 Advanced Web Application Firewall (WAF)/BIG-IP ASM security policy and applied to a virtual server, undisclosed requests may cause the BIG-IP ASM bd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

1%
Низкий
около 4 лет назад
github логотип
GHSA-33v9-7cpf-3wr4

Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally.

CVSS3: 5.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-33v8-g7j5-qg76

OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary OS command may be executed on the products.

CVSS3: 8.8
1%
Низкий
5 месяцев назад
github логотип
GHSA-33v7-x483-jjjx

An out-of-bounds read exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service and read sensitive memory.

CVSS3: 9.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-33v7-h6gx-6h2h

In getAppSize of InstalldNativeService.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-220733817

CVSS3: 6.7
0%
Низкий
около 4 лет назад
github логотип
GHSA-33v7-2ghp-xqch

Improper buffer restrictions in firmware for Intel(R) NUC may allow an authenticated user to potentially enable escalation of privilege via local access. The list of affected products is provided in intel-sa-00343: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00343.html

0%
Низкий
около 4 лет назад
github логотип
GHSA-33v5-vv3q-q64q

Cross-site scripting (XSS) vulnerability in EditModule.aspx for DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to inject arbitrary web script or HTML.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-33v5-9rfm-w3f4

The WP QuickLaTeX WordPress plugin before 3.8.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVSS3: 7.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-33v5-6gf6-m6w4

Multiple stack-based buffer overflows in the CPLI_ReadTag_OGG function in CPI_PlaylistItem.c in CoolPlayer 217 and earlier allow user-assisted remote attackers to execute arbitrary code via a long (1) cTag or (2) cValue field in an OGG Vorbis file.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-33v4-rh3c-mhcg

A local file disclosure vulnerability in /appConfig/userDB.json of Telos Alliance Omnia MPX Node through 1.5.0+r1 allows attackers to escalate privileges to root and execute arbitrary commands.

CVSS3: 9.8
10%
Низкий
почти 4 года назад

Уязвимостей на страницу