Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 357 271

Количество 357 271

github логотип

GHSA-33gm-hf2j-r258

больше 4 лет назад

Multiple PHP remote file inclusion vulnerabilities in ZebraFeeds 1.0, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the zf_path parameter to (1) aggregator.php and (2) controller.php in newsfeeds/includes/.

EPSS: Низкий
github логотип

GHSA-33gj-cgfq-5j2j

больше 2 лет назад

Authorization Bypass Through User-Controlled Key vulnerability in Blaz K. Rate my Post – WP Rating System.This issue affects Rate my Post – WP Rating System: from n/a through 3.4.1.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-33gh-f3xq-j9hx

около 4 лет назад

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-33gg-5m74-52cv

около 4 лет назад

A DOMParser XSS issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-33gg-4g7f-39f7

около 1 месяца назад

Capgo before 12.128.2 contains unauthenticated security definer RPC functions get_user_id and get_org_perm_for_apikey that expose API key validity oracles and user UUID disclosure. Unauthenticated attackers using the public API key can validate leaked keys, enumerate users and apps, and determine permission levels, significantly increasing the actionability of compromised credentials.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-33gg-2298-wmfp

около 4 лет назад

Adobe InDesign version 16.0 (and earlier) is affected by an Out-of-bounds Write vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to achieve remote code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

EPSS: Низкий
github логотип

GHSA-33gf-mr65-87rw

почти 2 года назад

Unrestricted Upload of File with Dangerous Type vulnerability in Ajar Productions Ajar in5 Embed allows Upload a Web Shell to a Web Server.This issue affects Ajar in5 Embed: from n/a through 3.1.3.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-33gc-wq56-g94m

около 4 лет назад

In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the Memcpy function (provided by the scripting engine) allows an attacker to overwrite arbitrary memory, which could lead to code execution.

EPSS: Низкий
github логотип

GHSA-33gc-vmgr-56fc

больше 3 лет назад

A vulnerability in the Spectrum Scale 5.0.5.0 through 5.1.6.1 core component could allow unauthorized access to user data or injection of arbitrary data in the communication protocol. IBM X-Force ID: 191695.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-33gc-p3fc-rqq7

около 4 лет назад

Cross-site scripting (XSS) vulnerability in OneOrZero AIMS 2.8.0 Trial Edition build231211 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.

EPSS: Низкий
github логотип

GHSA-33gc-f8v9-v8hm

почти 6 лет назад

Malicious Package in ladder-text-js

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-33gc-6cw9-w3g4

больше 4 лет назад

Deserialization of Untrusted Data in topthink/framework

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-33g9-x8rg-2pmj

9 месяцев назад

An ACAP configuration file has improper permissions, which could allow command injection and potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-33g8-ghxc-wjh9

около 4 лет назад

Cisco ASR 5500 System Architecture Evolution (SAE) Gateway devices allow remote attackers to cause a denial of service (CPU consumption and SNMP outage) via malformed SNMP packets, aka Bug ID CSCur13393.

EPSS: Низкий
github логотип

GHSA-33g6-495w-v8j2

больше 1 года назад

Snowflake JDBC uses insecure temporary credential cache file permissions

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-33g5-vw3f-w92q

около 4 лет назад

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

EPSS: Низкий
github логотип

GHSA-33g5-pmx8-956p

больше 1 года назад

Missing Authorization vulnerability in matthewrubin Local Magic allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Local Magic: from n/a through 2.6.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-33g5-gx8w-x4p5

около 4 лет назад

go7007_snd_init in drivers/media/usb/go7007/snd-go7007.c in the Linux kernel before 5.6 does not call snd_card_free for a failure path, which causes a memory leak, aka CID-9453264ef586.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-33g4-8f6m-m4gq

больше 1 года назад

Tungsten Automation Power PDF PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Tungsten Automation Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-24479.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-33g4-646g-qwmm

около 2 месяцев назад

Snipe-IT has Multi-Tenancy Bypass via Bulk Asset Update

CVSS3: 6.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-33gm-hf2j-r258

Multiple PHP remote file inclusion vulnerabilities in ZebraFeeds 1.0, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the zf_path parameter to (1) aggregator.php and (2) controller.php in newsfeeds/includes/.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-33gj-cgfq-5j2j

Authorization Bypass Through User-Controlled Key vulnerability in Blaz K. Rate my Post – WP Rating System.This issue affects Rate my Post – WP Rating System: from n/a through 3.4.1.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-33gh-f3xq-j9hx

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

CVSS3: 7.8
4%
Низкий
около 4 лет назад
github логотип
GHSA-33gg-5m74-52cv

A DOMParser XSS issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-33gg-4g7f-39f7

Capgo before 12.128.2 contains unauthenticated security definer RPC functions get_user_id and get_org_perm_for_apikey that expose API key validity oracles and user UUID disclosure. Unauthenticated attackers using the public API key can validate leaked keys, enumerate users and apps, and determine permission levels, significantly increasing the actionability of compromised credentials.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-33gg-2298-wmfp

Adobe InDesign version 16.0 (and earlier) is affected by an Out-of-bounds Write vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to achieve remote code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

6%
Низкий
около 4 лет назад
github логотип
GHSA-33gf-mr65-87rw

Unrestricted Upload of File with Dangerous Type vulnerability in Ajar Productions Ajar in5 Embed allows Upload a Web Shell to a Web Server.This issue affects Ajar in5 Embed: from n/a through 3.1.3.

CVSS3: 10
1%
Низкий
почти 2 года назад
github логотип
GHSA-33gc-wq56-g94m

In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the Memcpy function (provided by the scripting engine) allows an attacker to overwrite arbitrary memory, which could lead to code execution.

2%
Низкий
около 4 лет назад
github логотип
GHSA-33gc-vmgr-56fc

A vulnerability in the Spectrum Scale 5.0.5.0 through 5.1.6.1 core component could allow unauthorized access to user data or injection of arbitrary data in the communication protocol. IBM X-Force ID: 191695.

CVSS3: 8.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-33gc-p3fc-rqq7

Cross-site scripting (XSS) vulnerability in OneOrZero AIMS 2.8.0 Trial Edition build231211 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.

2%
Низкий
около 4 лет назад
github логотип
GHSA-33gc-f8v9-v8hm

Malicious Package in ladder-text-js

CVSS3: 9.8
почти 6 лет назад
github логотип
GHSA-33gc-6cw9-w3g4

Deserialization of Untrusted Data in topthink/framework

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-33g9-x8rg-2pmj

An ACAP configuration file has improper permissions, which could allow command injection and potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.

CVSS3: 6.7
1%
Низкий
9 месяцев назад
github логотип
GHSA-33g8-ghxc-wjh9

Cisco ASR 5500 System Architecture Evolution (SAE) Gateway devices allow remote attackers to cause a denial of service (CPU consumption and SNMP outage) via malformed SNMP packets, aka Bug ID CSCur13393.

2%
Низкий
около 4 лет назад
github логотип
GHSA-33g6-495w-v8j2

Snowflake JDBC uses insecure temporary credential cache file permissions

CVSS3: 4.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-33g5-vw3f-w92q

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PCX file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

1%
Низкий
около 4 лет назад
github логотип
GHSA-33g5-pmx8-956p

Missing Authorization vulnerability in matthewrubin Local Magic allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Local Magic: from n/a through 2.6.0.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-33g5-gx8w-x4p5

go7007_snd_init in drivers/media/usb/go7007/snd-go7007.c in the Linux kernel before 5.6 does not call snd_card_free for a failure path, which causes a memory leak, aka CID-9453264ef586.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-33g4-8f6m-m4gq

Tungsten Automation Power PDF PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Tungsten Automation Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-24479.

CVSS3: 3.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-33g4-646g-qwmm

Snipe-IT has Multi-Tenancy Bypass via Bulk Asset Update

CVSS3: 6.3
около 2 месяцев назад

Уязвимостей на страницу