Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 357 271

Количество 357 271

github логотип

GHSA-33r3-cpxm-4xg2

около 2 месяцев назад

Capgo before 12.128.2 contains an authentication bypass vulnerability in the /build/upload/:jobId/* endpoint that allows unauthenticated attackers to trigger consistent 500 errors. Remote attackers can send OPTIONS requests to bypass authentication middleware and invoke tusProxy logic with invalid credentials, enabling trivial request flooding and denial of service.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-33r3-58hj-pwmx

около 2 лет назад

Improper Restriction of XML External Entity Reference vulnerability in PruvaSoft Informatics Apinizer Management Console allows Data Serialization External Entities Blowup.This issue affects Apinizer Management Console: before 2024.05.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-33r3-4whc-44c2

4 месяца назад

Path traversal in vite-plus/binding downloadPackageManager() writes outside VP_HOME

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-33r2-r6fv-8948

около 4 лет назад

A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing maliciously crafted web content may lead to arbitrary code execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-33r2-hfpx-fx7h

6 месяцев назад

A flaw has been found in libvips up to 8.18.0. The affected element is the function vips_foreign_load_matrix_file_is_a/vips_foreign_load_matrix_header of the file libvips/foreign/matrixload.c. Executing a manipulation can lead to memory corruption. The attack needs to be launched locally. This patch is called d4ce337c76bff1b278d7085c3c4f4725e3aa6ece. A patch should be applied to remediate this issue.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-33r2-8g93-5hm2

больше 2 лет назад

The console may experience a service interruption when processing file names with invalid characters.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-33r2-7prf-93fv

около 4 лет назад

The getlong function in numutils.c in libdoc through 2017-10-23 has a heap-based buffer over-read that allows attackers to cause a denial of service (application crash) via a crafted file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-33qx-rqvh-638r

больше 4 лет назад

MIT Kerberos 5 (krb5) 1.3 through 1.4.1 Key Distribution Center (KDC) allows remote attackers to cause a denial of service (application crash) via a certain valid TCP connection that causes a free of unallocated memory.

EPSS: Низкий
github логотип

GHSA-33qx-4qqq-fc86

больше 2 лет назад

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. Note: This vulnerability applies to Windows hosts only. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-33qw-xh9j-v5v3

около 4 лет назад

Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Table Name field to /dashboard/table-list.php.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-33qw-wpjx-355w

около 4 лет назад

libyara/grammar.y in YARA 3.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted rule that is mishandled in the yr_compiler_destroy function.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-33qv-c5qm-799v

2 месяца назад

hermes-agent has an Injection issue

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-33qv-5f33-pv7h

больше 4 лет назад

Microsoft Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code by causing Internet Explorer to access an uninitialized or deleted object, related to prototype variables and table cells, aka "Uninitialized Memory Corruption Vulnerability."

EPSS: Средний
github логотип

GHSA-33qr-xp8v-vv64

8 месяцев назад

In ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images allows attackers to embed malicious JavaScript. The payload executes when an administrator clicks the image link to view the avatar, resulting in stored cross-site scripting (XSS). Successful exploitation may lead to account takeover, privilege escalation, or full compromise of the affected ERPNext instance.

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-33qr-m49q-rxfx

больше 1 года назад

Compromised xrpl.js versions 4.2.1, 4.2.2, 4.2.3, 4.2.4, and 2.14.2

EPSS: Низкий
github логотип

GHSA-33qr-2xwr-95pw

больше 2 лет назад

Before Go 1.20, the RSA based TLS key exchanges used the math/big library, which is not constant time. RSA blinding was applied to prevent timing attacks, but analysis shows this may not have been fully effective. In particular it appears as if the removal of PKCS#1 padding may leak timing information, which in turn could be used to recover session key bits. In Go 1.20, the crypto/tls library switched to a fully constant time RSA implementation, which we do not believe exhibits any timing side channels.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-33qr-2f3g-3c52

около 4 лет назад

A SQL Injection issue was discovered in Ecava IntegraXor v 6.1.1030.1 and prior. The SQL Injection vulnerability has been identified, which an attacker can leverage to disclose sensitive information from the database.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-33qq-wfvm-3749

около 4 лет назад

VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability in Cortado ThinPrint component (EMR STRETCHDIBITS parser). A malicious actor with normal access to a virtual machine may be able to exploit these issues to create a partial denial-of-service condition or to leak memory from TPView process running on the system where Workstation or Horizon Client for Windows is installed.

EPSS: Низкий
github логотип

GHSA-33qq-vjrc-8xw3

больше 4 лет назад

Unspecified vulnerability in the XML component in IBM Runtimes for Java Technology 5.0.0 before SR10 has unknown impact and attack vectors, related to the "updated version of XML4J 4.4.17."

EPSS: Низкий
github логотип

GHSA-33qq-qr49-7phx

больше 4 лет назад

Unknown vulnerability in F-Secure Anti-Virus (FSAV) 4.52 for Linux before Hotfix 3 allows the Sober.D worm to bypass FASV.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-33r3-cpxm-4xg2

Capgo before 12.128.2 contains an authentication bypass vulnerability in the /build/upload/:jobId/* endpoint that allows unauthenticated attackers to trigger consistent 500 errors. Remote attackers can send OPTIONS requests to bypass authentication middleware and invoke tusProxy logic with invalid credentials, enabling trivial request flooding and denial of service.

CVSS3: 5.3
1%
Низкий
около 2 месяцев назад
github логотип
GHSA-33r3-58hj-pwmx

Improper Restriction of XML External Entity Reference vulnerability in PruvaSoft Informatics Apinizer Management Console allows Data Serialization External Entities Blowup.This issue affects Apinizer Management Console: before 2024.05.1.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-33r3-4whc-44c2

Path traversal in vite-plus/binding downloadPackageManager() writes outside VP_HOME

CVSS3: 10
0%
Низкий
4 месяца назад
github логотип
GHSA-33r2-r6fv-8948

A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing maliciously crafted web content may lead to arbitrary code execution.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-33r2-hfpx-fx7h

A flaw has been found in libvips up to 8.18.0. The affected element is the function vips_foreign_load_matrix_file_is_a/vips_foreign_load_matrix_header of the file libvips/foreign/matrixload.c. Executing a manipulation can lead to memory corruption. The attack needs to be launched locally. This patch is called d4ce337c76bff1b278d7085c3c4f4725e3aa6ece. A patch should be applied to remediate this issue.

CVSS3: 5.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-33r2-8g93-5hm2

The console may experience a service interruption when processing file names with invalid characters.

CVSS3: 3.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-33r2-7prf-93fv

The getlong function in numutils.c in libdoc through 2017-10-23 has a heap-based buffer over-read that allows attackers to cause a denial of service (application crash) via a crafted file.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-33qx-rqvh-638r

MIT Kerberos 5 (krb5) 1.3 through 1.4.1 Key Distribution Center (KDC) allows remote attackers to cause a denial of service (application crash) via a certain valid TCP connection that causes a free of unallocated memory.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-33qx-4qqq-fc86

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. Note: This vulnerability applies to Windows hosts only. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 6.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-33qw-xh9j-v5v3

Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Table Name field to /dashboard/table-list.php.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-33qw-wpjx-355w

libyara/grammar.y in YARA 3.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted rule that is mishandled in the yr_compiler_destroy function.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-33qv-c5qm-799v

hermes-agent has an Injection issue

CVSS3: 6.3
0%
Низкий
2 месяца назад
github логотип
GHSA-33qv-5f33-pv7h

Microsoft Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code by causing Internet Explorer to access an uninitialized or deleted object, related to prototype variables and table cells, aka "Uninitialized Memory Corruption Vulnerability."

61%
Средний
больше 4 лет назад
github логотип
GHSA-33qr-xp8v-vv64

In ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images allows attackers to embed malicious JavaScript. The payload executes when an administrator clicks the image link to view the avatar, resulting in stored cross-site scripting (XSS). Successful exploitation may lead to account takeover, privilege escalation, or full compromise of the affected ERPNext instance.

CVSS3: 9
0%
Низкий
8 месяцев назад
github логотип
GHSA-33qr-m49q-rxfx

Compromised xrpl.js versions 4.2.1, 4.2.2, 4.2.3, 4.2.4, and 2.14.2

1%
Низкий
больше 1 года назад
github логотип
GHSA-33qr-2xwr-95pw

Before Go 1.20, the RSA based TLS key exchanges used the math/big library, which is not constant time. RSA blinding was applied to prevent timing attacks, but analysis shows this may not have been fully effective. In particular it appears as if the removal of PKCS#1 padding may leak timing information, which in turn could be used to recover session key bits. In Go 1.20, the crypto/tls library switched to a fully constant time RSA implementation, which we do not believe exhibits any timing side channels.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-33qr-2f3g-3c52

A SQL Injection issue was discovered in Ecava IntegraXor v 6.1.1030.1 and prior. The SQL Injection vulnerability has been identified, which an attacker can leverage to disclose sensitive information from the database.

CVSS3: 5.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-33qq-wfvm-3749

VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability in Cortado ThinPrint component (EMR STRETCHDIBITS parser). A malicious actor with normal access to a virtual machine may be able to exploit these issues to create a partial denial-of-service condition or to leak memory from TPView process running on the system where Workstation or Horizon Client for Windows is installed.

0%
Низкий
около 4 лет назад
github логотип
GHSA-33qq-vjrc-8xw3

Unspecified vulnerability in the XML component in IBM Runtimes for Java Technology 5.0.0 before SR10 has unknown impact and attack vectors, related to the "updated version of XML4J 4.4.17."

2%
Низкий
больше 4 лет назад
github логотип
GHSA-33qq-qr49-7phx

Unknown vulnerability in F-Secure Anti-Virus (FSAV) 4.52 for Linux before Hotfix 3 allows the Sober.D worm to bypass FASV.

3%
Низкий
больше 4 лет назад

Уязвимостей на страницу