Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 704

Количество 355 704

github логотип

GHSA-2wx9-x824-p464

около 4 лет назад

A vulnerability in the FTP inspection engine of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability exists because the affected software fails to release spinlocks when a device is running low on system memory, if the software is configured to apply FTP inspection and an access control rule to transit traffic, and the access control rule is associated with an FTP file policy. An attacker could exploit this vulnerability by sending a high rate of transit traffic through an affected device to cause a low-memory condition on the device. A successful exploit could allow the attacker to cause a software panic on the affected device, which could cause the device to reload and result in a temporary DoS condition.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-2wx9-w67p-qcqq

около 4 лет назад

Unspecified vulnerability in the Hyperion Essbase component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote attackers to affect availability via unknown vectors related to Agent.

EPSS: Низкий
github логотип

GHSA-2wx9-j8x2-r9vm

больше 4 лет назад

An improper access control in LiveWallpaperService prior to versions 3.0.9.0 allows to create a specific named system directory without a proper permission.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2wx9-243g-7hm9

около 4 лет назад

An out of bounds read in the function d2ulaw_array() in ulaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or information disclosure, related to mishandling of the NAN and INFINITY floating-point values.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2wx8-vvfc-5r8w

больше 2 лет назад

Parallels Desktop Updater Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target host system in order to exploit this vulnerability. The specific flaw exists within the Updater service. By creating a symbolic link, an attacker can abuse the service to execute a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root. Was ZDI-CAN-18150.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2wx8-q5hg-8h5m

около 4 лет назад

Ming (aka libming) 0.4.8 has z NULL pointer dereference in the function decompileGETURL2() in decompile.c.

EPSS: Низкий
github логотип

GHSA-2wx8-6jj8-chhc

около 4 лет назад

Format string vulnerability in the logMess function in TFTP Server MT 1.65 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format string sequences in a TFTP error packet.

EPSS: Низкий
github логотип

GHSA-2wx7-j39g-4p6g

больше 1 года назад

A vulnerability in the handling of specific packets that are punted from a line card to a route processor in Cisco IOS XR Software Release 7.9.2 could allow an unauthenticated, adjacent attacker to cause control plane traffic to stop working on multiple Cisco IOS XR platforms.  This vulnerability is due to incorrect handling of packets that are punted to the route processor. An attacker could exploit this vulnerability by sending traffic, which must be handled by the Linux stack on the route processor, to an affected device. A successful exploit could allow the attacker to cause control plane traffic to stop working, resulting in a denial of service (DoS) condition.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-2wx7-cf6v-q9v8

около 4 лет назад

A SQL Injection issue was discovered in Sentrifugo 3.2 via the deptid parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2wx7-3qvr-gm34

около 4 лет назад

A vulnerability in the web-based management interface of Cisco Mobility Express Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected device. An attacker could exploit this vulnerability by persuading a user with an active session on an affected device to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions, including modifying the configuration, with the privilege level of the user.

EPSS: Низкий
github логотип

GHSA-2wx6-wc87-rmjm

больше 6 лет назад

GitHub personal access token leaking into temporary EasyBuild (debug) logs

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-2wx6-gjr5-cw6x

больше 4 лет назад

PHP remote file inclusion vulnerability in phpthumb.php in Jetbox CMS allows remote attackers to execute arbitrary PHP code via a URL in the includes_path parameter. NOTE: The relative_script_path vector is already covered by CVE-2006-2270.

EPSS: Низкий
github логотип

GHSA-2wx5-xx7r-5pp4

больше 3 лет назад

A stored cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3, allows remote attackers to inject arbitrary web script or HTML via input fields. These input fields are located in the "Title" Input Field in EventEditor.php.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2wx5-x3v9-h4fr

больше 3 лет назад

72crm v9 was discovered to contain an arbitrary file upload vulnerability via the avatar upload function. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-2wx5-pg32-77vx

около 4 лет назад

Multiple HTC Android devices including Desire HD FRG83D and GRI40, Glacier FRG83, Droid Incredible FRF91, Thunderbolt 4G FRG83D, Sensation Z710e GRI40, Sensation 4G GRI40, Desire S GRI40, EVO 3D GRI40, and EVO 4G GRI40 allow remote attackers to obtain 802.1X Wi-Fi credentials and SSID via a crafted application that uses the android.permission.ACCESS_WIFI_STATE permission to call the toString method on the WifiConfiguration class.

EPSS: Низкий
github логотип

GHSA-2wx5-jfx2-287m

6 месяцев назад

A security flaw has been discovered in Tenda AC21 1.1.1.1/1.dmzip/16.03.08.16. The impacted element is the function mDMZSetCfg of the file /goform/mDMZSetCfg. The manipulation of the argument dmzIp results in command injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2wx4-jmwh-g7cc

почти 3 года назад

Dell SmartFabric Storage Software v1.4 (and earlier) contains an improper access control vulnerability in the CLI. A local possibly unauthenticated attacker could potentially exploit this vulnerability, leading to ability to execute arbritrary shell commands.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-2wx4-c69c-72wc

около 4 лет назад

IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1998887.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2wx3-wgwm-8jh9

больше 2 лет назад

Due to improper error handling, a REST API resource could expose a server side error containing an internal WSO2 specific package name in the HTTP response.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2wx3-jm7x-4xg5

около 2 лет назад

The One Click Order Re-Order plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ced_ocor_save_general_setting' function in all versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change the plugin settings, including adding stored cross-site scripting.

CVSS3: 6.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2wx9-x824-p464

A vulnerability in the FTP inspection engine of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability exists because the affected software fails to release spinlocks when a device is running low on system memory, if the software is configured to apply FTP inspection and an access control rule to transit traffic, and the access control rule is associated with an FTP file policy. An attacker could exploit this vulnerability by sending a high rate of transit traffic through an affected device to cause a low-memory condition on the device. A successful exploit could allow the attacker to cause a software panic on the affected device, which could cause the device to reload and result in a temporary DoS condition.

CVSS3: 6.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2wx9-w67p-qcqq

Unspecified vulnerability in the Hyperion Essbase component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote attackers to affect availability via unknown vectors related to Agent.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2wx9-j8x2-r9vm

An improper access control in LiveWallpaperService prior to versions 3.0.9.0 allows to create a specific named system directory without a proper permission.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2wx9-243g-7hm9

An out of bounds read in the function d2ulaw_array() in ulaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or information disclosure, related to mishandling of the NAN and INFINITY floating-point values.

CVSS3: 8.1
2%
Низкий
около 4 лет назад
github логотип
GHSA-2wx8-vvfc-5r8w

Parallels Desktop Updater Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target host system in order to exploit this vulnerability. The specific flaw exists within the Updater service. By creating a symbolic link, an attacker can abuse the service to execute a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root. Was ZDI-CAN-18150.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2wx8-q5hg-8h5m

Ming (aka libming) 0.4.8 has z NULL pointer dereference in the function decompileGETURL2() in decompile.c.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2wx8-6jj8-chhc

Format string vulnerability in the logMess function in TFTP Server MT 1.65 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format string sequences in a TFTP error packet.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2wx7-j39g-4p6g

A vulnerability in the handling of specific packets that are punted from a line card to a route processor in Cisco IOS XR Software Release 7.9.2 could allow an unauthenticated, adjacent attacker to cause control plane traffic to stop working on multiple Cisco IOS XR platforms.  This vulnerability is due to incorrect handling of packets that are punted to the route processor. An attacker could exploit this vulnerability by sending traffic, which must be handled by the Linux stack on the route processor, to an affected device. A successful exploit could allow the attacker to cause control plane traffic to stop working, resulting in a denial of service (DoS) condition.

CVSS3: 7.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-2wx7-cf6v-q9v8

A SQL Injection issue was discovered in Sentrifugo 3.2 via the deptid parameter.

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2wx7-3qvr-gm34

A vulnerability in the web-based management interface of Cisco Mobility Express Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected device. An attacker could exploit this vulnerability by persuading a user with an active session on an affected device to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions, including modifying the configuration, with the privilege level of the user.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2wx6-wc87-rmjm

GitHub personal access token leaking into temporary EasyBuild (debug) logs

CVSS3: 7.7
1%
Низкий
больше 6 лет назад
github логотип
GHSA-2wx6-gjr5-cw6x

PHP remote file inclusion vulnerability in phpthumb.php in Jetbox CMS allows remote attackers to execute arbitrary PHP code via a URL in the includes_path parameter. NOTE: The relative_script_path vector is already covered by CVE-2006-2270.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2wx5-xx7r-5pp4

A stored cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3, allows remote attackers to inject arbitrary web script or HTML via input fields. These input fields are located in the "Title" Input Field in EventEditor.php.

CVSS3: 5.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2wx5-x3v9-h4fr

72crm v9 was discovered to contain an arbitrary file upload vulnerability via the avatar upload function. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

CVSS3: 8.8
18%
Средний
больше 3 лет назад
github логотип
GHSA-2wx5-pg32-77vx

Multiple HTC Android devices including Desire HD FRG83D and GRI40, Glacier FRG83, Droid Incredible FRF91, Thunderbolt 4G FRG83D, Sensation Z710e GRI40, Sensation 4G GRI40, Desire S GRI40, EVO 3D GRI40, and EVO 4G GRI40 allow remote attackers to obtain 802.1X Wi-Fi credentials and SSID via a crafted application that uses the android.permission.ACCESS_WIFI_STATE permission to call the toString method on the WifiConfiguration class.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2wx5-jfx2-287m

A security flaw has been discovered in Tenda AC21 1.1.1.1/1.dmzip/16.03.08.16. The impacted element is the function mDMZSetCfg of the file /goform/mDMZSetCfg. The manipulation of the argument dmzIp results in command injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

CVSS3: 6.3
2%
Низкий
6 месяцев назад
github логотип
GHSA-2wx4-jmwh-g7cc

Dell SmartFabric Storage Software v1.4 (and earlier) contains an improper access control vulnerability in the CLI. A local possibly unauthenticated attacker could potentially exploit this vulnerability, leading to ability to execute arbritrary shell commands.

CVSS3: 4.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-2wx4-c69c-72wc

IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1998887.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-2wx3-wgwm-8jh9

Due to improper error handling, a REST API resource could expose a server side error containing an internal WSO2 specific package name in the HTTP response.

CVSS3: 5.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2wx3-jm7x-4xg5

The One Click Order Re-Order plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ced_ocor_save_general_setting' function in all versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change the plugin settings, including adding stored cross-site scripting.

CVSS3: 6.4
0%
Низкий
около 2 лет назад

Уязвимостей на страницу