Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 628

Количество 355 628

github логотип

GHSA-2wcm-g247-vx59

около 1 месяца назад

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly. The Websocket server can accept various commands coming from localhost. Many of the commands will take an `index` value that is then used to access various arrays to enter critical sections, perform various actions via function calls, etc. However the `index` value is usually not checked for valid range, and as such it can be used to access multiple arrays out-of-bound. #### setPIP command index-out-of-bound

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-2wcj-qr76-9768

больше 2 лет назад

PaddlePaddle segfault in paddle.put_along_axis

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-2wcj-p2hm-6ff7

около 4 лет назад

Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attackers to execute arbitrary code via a crafted packet, a different vulnerability than CVE-2015-4931, CVE-2015-4933, CVE-2015-4934, and CVE-2015-4935.

EPSS: Низкий
github логотип

GHSA-2wch-wmvj-vcfw

5 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Crown Art crown-art allows PHP Local File Inclusion.This issue affects Crown Art: from n/a through <= 1.2.11.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2wch-qhpr-mqp5

около 4 лет назад

An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input.

EPSS: Средний
github логотип

GHSA-2wch-pp5g-pc57

около 4 лет назад

The process_file function in reader.c in libdoc through 2017-10-23 has a heap-based buffer over-read that allows attackers to cause a denial of service (application crash) via a crafted file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2wch-9pmc-8h8m

около 4 лет назад

In cPanel before 66.0.2, weak log-file permissions can occur after account modification (SEC-289).

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-2wcg-qvrr-vf6j

3 месяца назад

A flaw has been found in dazeb markdown-downloader up to 3d4394b34b6c99d81af817623af55e3384df5a6a. Affected is the function download_markdown/list_downloaded_files/create_subdirectory of the file src/index.ts. Executing a manipulation can lead to path traversal. The attack can be launched remotely. The exploit has been published and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2wcg-7wr3-q72q

2 месяца назад

Use after free in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2wcg-78mh-f9m8

больше 4 лет назад

Netbt.sys in Windows NT 4.0 allows remote malicious DNS servers to cause a denial of service (crash) by returning 0.0.0.0 as the IP address for a DNS host name lookup.

EPSS: Низкий
github логотип

GHSA-2wcf-8w35-jp7x

около 4 лет назад

Microsoft SharePoint Spoofing Vulnerability This CVE ID is unique from CVE-2020-17015, CVE-2020-17060.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-2wcf-7wvx-2jw3

больше 4 лет назад

Foojan PHP Weblog allows remote attackers to obtain sensitive information via (1) a direct request to /daylinks/index.php or (2) a negative value in the daylinkspage parameter to index.php, which reveal the path in an error message.

EPSS: Низкий
github логотип

GHSA-2wcf-273g-9c2w

больше 2 лет назад

A vulnerability has been found in Ruijie RG-UAC up to 20240428 and classified as critical. This vulnerability affects unknown code of the file /view/IPV6/ipv6Addr/ip_addr_edit_commit.php. The manipulation of the argument text_ip_addr/orgprelen/orgname leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-263110 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-2wc9-q6m7-wqrq

около 4 лет назад

Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Text. Successful attacks of this vulnerability can result in takeover of Oracle Text. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

EPSS: Низкий
github логотип

GHSA-2wc9-6hm3-wjmr

около 4 лет назад

Buffer overflow in the HVM graphics console support in Citrix XenServer 6.2 Service Pack 1 and earlier has unspecified impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-2wc8-fx5r-628m

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in Absolute Image Gallery XE 2.x allows remote attackers to inject arbitrary web script or HTML via the text parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-2wc8-2pc2-v659

около 1 года назад

SAP MDM Server ReadString function allows an attacker to send specially crafted packets which could trigger a memory read access violation in the server process that would then fail and exit unexpectedly causing high impact on availability with no impact on confidentiality and integrity of the application.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2wc8-2hmm-w3qm

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the user registration in PBLang 4.65, and possibly earlier versions, allows remote attackers to inject arbitrary web script or PHP via the location field.

EPSS: Низкий
github логотип

GHSA-2wc7-rq3v-m6mj

больше 2 лет назад

The Advanced Local Pickup for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter in versions up to, and including, 1.5.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with admin-level privileges to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2wc7-p52f-xgxm

больше 4 лет назад

Buffer overflow in the RPC preprocessor for Snort 1.8 and 1.9.x before 1.9.1 allows remote attackers to execute arbitrary code via fragmented RPC packets.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2wcm-g247-vx59

GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly. The Websocket server can accept various commands coming from localhost. Many of the commands will take an `index` value that is then used to access various arrays to enter critical sections, perform various actions via function calls, etc. However the `index` value is usually not checked for valid range, and as such it can be used to access multiple arrays out-of-bound. #### setPIP command index-out-of-bound

CVSS3: 8.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-2wcj-qr76-9768

PaddlePaddle segfault in paddle.put_along_axis

CVSS3: 4.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2wcj-p2hm-6ff7

Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12.1 allows remote attackers to execute arbitrary code via a crafted packet, a different vulnerability than CVE-2015-4931, CVE-2015-4933, CVE-2015-4934, and CVE-2015-4935.

9%
Низкий
около 4 лет назад
github логотип
GHSA-2wch-wmvj-vcfw

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Crown Art crown-art allows PHP Local File Inclusion.This issue affects Crown Art: from n/a through <= 1.2.11.

CVSS3: 8.1
1%
Низкий
5 месяцев назад
github логотип
GHSA-2wch-qhpr-mqp5

An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input.

52%
Средний
около 4 лет назад
github логотип
GHSA-2wch-pp5g-pc57

The process_file function in reader.c in libdoc through 2017-10-23 has a heap-based buffer over-read that allows attackers to cause a denial of service (application crash) via a crafted file.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2wch-9pmc-8h8m

In cPanel before 66.0.2, weak log-file permissions can occur after account modification (SEC-289).

CVSS3: 3.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-2wcg-qvrr-vf6j

A flaw has been found in dazeb markdown-downloader up to 3d4394b34b6c99d81af817623af55e3384df5a6a. Affected is the function download_markdown/list_downloaded_files/create_subdirectory of the file src/index.ts. Executing a manipulation can lead to path traversal. The attack can be launched remotely. The exploit has been published and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 6.3
0%
Низкий
3 месяца назад
github логотип
GHSA-2wcg-7wr3-q72q

Use after free in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)

CVSS3: 8.8
0%
Низкий
2 месяца назад
github логотип
GHSA-2wcg-78mh-f9m8

Netbt.sys in Windows NT 4.0 allows remote malicious DNS servers to cause a denial of service (crash) by returning 0.0.0.0 as the IP address for a DNS host name lookup.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-2wcf-8w35-jp7x

Microsoft SharePoint Spoofing Vulnerability This CVE ID is unique from CVE-2020-17015, CVE-2020-17060.

CVSS3: 8
3%
Низкий
около 4 лет назад
github логотип
GHSA-2wcf-7wvx-2jw3

Foojan PHP Weblog allows remote attackers to obtain sensitive information via (1) a direct request to /daylinks/index.php or (2) a negative value in the daylinkspage parameter to index.php, which reveal the path in an error message.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2wcf-273g-9c2w

A vulnerability has been found in Ruijie RG-UAC up to 20240428 and classified as critical. This vulnerability affects unknown code of the file /view/IPV6/ipv6Addr/ip_addr_edit_commit.php. The manipulation of the argument text_ip_addr/orgprelen/orgname leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-263110 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.7
8%
Низкий
больше 2 лет назад
github логотип
GHSA-2wc9-q6m7-wqrq

Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Text. Successful attacks of this vulnerability can result in takeover of Oracle Text. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

2%
Низкий
около 4 лет назад
github логотип
GHSA-2wc9-6hm3-wjmr

Buffer overflow in the HVM graphics console support in Citrix XenServer 6.2 Service Pack 1 and earlier has unspecified impact and attack vectors.

5%
Низкий
около 4 лет назад
github логотип
GHSA-2wc8-fx5r-628m

Cross-site scripting (XSS) vulnerability in Absolute Image Gallery XE 2.x allows remote attackers to inject arbitrary web script or HTML via the text parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2wc8-2pc2-v659

SAP MDM Server ReadString function allows an attacker to send specially crafted packets which could trigger a memory read access violation in the server process that would then fail and exit unexpectedly causing high impact on availability with no impact on confidentiality and integrity of the application.

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2wc8-2hmm-w3qm

Cross-site scripting (XSS) vulnerability in the user registration in PBLang 4.65, and possibly earlier versions, allows remote attackers to inject arbitrary web script or PHP via the location field.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2wc7-rq3v-m6mj

The Advanced Local Pickup for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter in versions up to, and including, 1.5.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with admin-level privileges to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVSS3: 7.2
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2wc7-p52f-xgxm

Buffer overflow in the RPC preprocessor for Snort 1.8 and 1.9.x before 1.9.1 allows remote attackers to execute arbitrary code via fragmented RPC packets.

12%
Средний
больше 4 лет назад

Уязвимостей на страницу