Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 628

Количество 355 628

github логотип

GHSA-2wc7-jrqh-277g

около 2 лет назад

Transient DOS when NAS receives ODAC criteria of length 1 and type 1 in registration accept OTA.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2wc6-h889-742q

около 4 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-2wc6-2rcj-8v76

почти 5 лет назад

scalarmult() vulnerable to degenerate public keys

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2wc3-pwm6-wv9g

около 4 лет назад

SAP Sybase Adaptive Server Enterprise (ASE) 15.0.3 before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows remote authenticated users to gain privileges via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2wc3-pmh3-j9cq

больше 4 лет назад

PHP remote file inclusion vulnerability in index.php in SkaDate Dating allows remote attackers to execute arbitrary PHP code via a URL in the language_id parameter. NOTE: this can also be leveraged to include and execute arbitrary local files via directory traversal sequences.

EPSS: Низкий
github логотип

GHSA-2wc3-h48p-9gpq

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ncm: Fix UAF ncm object at re-bind after usb ep transport error When ncm function is working and then stop usb0 interface for link down, eth_stop() is called. At this piont, accidentally if usb transport error should happen in usb_ep_enable(), 'in_ep' and/or 'out_ep' may not be enabled. After that, ncm_disable() is called to disable for ncm unbind but gether_disconnect() is never called since 'in_ep' is not enabled. As the result, ncm object is released in ncm unbind but 'dev->port_usb' associated to 'ncm->port' is not NULL. And when ncm bind again to recover netdev, ncm object is reallocated but usb0 interface is already associated to previous released ncm object. Therefore, once usb0 interface is up and eth_start_xmit() is called, released ncm object is dereferrenced and it might cause use-after-free memory. [function unlink via configfs] usb0: eth_stop dev->port_usb=ffffff9b179c3200 --> ...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2wc3-9w3j-8phw

около 4 лет назад

Zyxel WRE6505 devices have a default TELNET password of 1234 for the root and admin accounts, which makes it easier for remote attackers to conduct DNS hijacking attacks by reconfiguring the built-in dnshijacker process.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-2wc2-w32v-v8wr

около 4 лет назад

The iTriage Health (aka com.healthagen.iTriage) application 5.29 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-2wc2-fm75-p42x

около 1 месяца назад

Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2wc2-8hhf-wr42

около 4 лет назад

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Nighthawk R7800. Authentication is not required to exploit this vulnerability The specific flaw exists within handling of firmware updates. The issue results from a fallback to a insecure protocol to deliver updates. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-12308.

EPSS: Низкий
github логотип

GHSA-2wc2-77r7-4pm8

больше 3 лет назад

An issue was discovered in ksmbd in the Linux kernel before 5.19.2. fs/ksmbd/smb2pdu.c omits a kfree call in certain smb2_handle_negotiate error conditions, aka a memory leak.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2wc2-3qx9-3828

больше 4 лет назад

SafeHTML before 1.3.5 does not properly filter script in UTF-7 and CSS comments, which allows remote attackers to conduct cross-site scripting (XSS) attacks in vulnerable applications that use SafeHTML.

EPSS: Низкий
github логотип

GHSA-2w9x-qwqq-9qpw

больше 4 лет назад

Heap-based buffer overflow in Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SIP firmware might allow remote SIP servers to execute arbitrary code via a crafted challenge/response message.

EPSS: Низкий
github логотип

GHSA-2w9x-8fmc-q598

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the "Monitor browsers' feature in Browscap before 5.x-1.1 and 6.x-1.1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.

EPSS: Низкий
github логотип

GHSA-2w9x-58hj-96v8

больше 2 лет назад

A buffer overflow vulnerability has been discovered in the C++ components of ROS2 Galactic Geochelone ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows attackers to execute arbitrary code or cause a denial of service (DoS) via improper handling of arrays or strings.

EPSS: Низкий
github логотип

GHSA-2w9w-m6x3-g9c8

больше 4 лет назад

In onCreate of SetupLayoutActivity.java, there is a possible way to setup a work profile bypassing user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-209611539

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2w9w-fgq6-2vmc

9 месяцев назад

Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability affects Firefox < 145.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2w9w-5m28-9576

больше 4 лет назад

Buffer overflow in FTP server in QPC Software's QVT/Term Plus versions 4.2d and 4.3 and QVT/Net 4.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long (1) user name or (2) password.

EPSS: Средний
github логотип

GHSA-2w9w-5h27-2qqm

около 4 лет назад

Jason2605 AdminPanel 4.0 allows SQL Injection via the editPlayer.php hidden parameter.

EPSS: Низкий
github логотип

GHSA-2w9w-448q-4hqv

около 4 лет назад

A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An attacker could exploit this vulnerability by sending a user a malicious ARF or WRF file via a link or an email attachment and persuading the user to open the file by using the affected software. A successful exploit could allow the attacker to execute arbitrary code on the affected system.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2wc7-jrqh-277g

Transient DOS when NAS receives ODAC criteria of length 1 and type 1 in registration accept OTA.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-2wc6-h889-742q

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
2%
Низкий
около 4 лет назад
github логотип
GHSA-2wc6-2rcj-8v76

scalarmult() vulnerable to degenerate public keys

CVSS3: 6.5
1%
Низкий
почти 5 лет назад
github логотип
GHSA-2wc3-pwm6-wv9g

SAP Sybase Adaptive Server Enterprise (ASE) 15.0.3 before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows remote authenticated users to gain privileges via unspecified vectors.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2wc3-pmh3-j9cq

PHP remote file inclusion vulnerability in index.php in SkaDate Dating allows remote attackers to execute arbitrary PHP code via a URL in the language_id parameter. NOTE: this can also be leveraged to include and execute arbitrary local files via directory traversal sequences.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2wc3-h48p-9gpq

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ncm: Fix UAF ncm object at re-bind after usb ep transport error When ncm function is working and then stop usb0 interface for link down, eth_stop() is called. At this piont, accidentally if usb transport error should happen in usb_ep_enable(), 'in_ep' and/or 'out_ep' may not be enabled. After that, ncm_disable() is called to disable for ncm unbind but gether_disconnect() is never called since 'in_ep' is not enabled. As the result, ncm object is released in ncm unbind but 'dev->port_usb' associated to 'ncm->port' is not NULL. And when ncm bind again to recover netdev, ncm object is reallocated but usb0 interface is already associated to previous released ncm object. Therefore, once usb0 interface is up and eth_start_xmit() is called, released ncm object is dereferrenced and it might cause use-after-free memory. [function unlink via configfs] usb0: eth_stop dev->port_usb=ffffff9b179c3200 --> ...

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2wc3-9w3j-8phw

Zyxel WRE6505 devices have a default TELNET password of 1234 for the root and admin accounts, which makes it easier for remote attackers to conduct DNS hijacking attacks by reconfiguring the built-in dnshijacker process.

CVSS3: 10
2%
Низкий
около 4 лет назад
github логотип
GHSA-2wc2-w32v-v8wr

The iTriage Health (aka com.healthagen.iTriage) application 5.29 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2wc2-fm75-p42x

Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists

CVSS3: 7.5
1%
Низкий
около 1 месяца назад
github логотип
GHSA-2wc2-8hhf-wr42

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Nighthawk R7800. Authentication is not required to exploit this vulnerability The specific flaw exists within handling of firmware updates. The issue results from a fallback to a insecure protocol to deliver updates. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-12308.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2wc2-77r7-4pm8

An issue was discovered in ksmbd in the Linux kernel before 5.19.2. fs/ksmbd/smb2pdu.c omits a kfree call in certain smb2_handle_negotiate error conditions, aka a memory leak.

CVSS3: 7.5
5%
Низкий
больше 3 лет назад
github логотип
GHSA-2wc2-3qx9-3828

SafeHTML before 1.3.5 does not properly filter script in UTF-7 and CSS comments, which allows remote attackers to conduct cross-site scripting (XSS) attacks in vulnerable applications that use SafeHTML.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2w9x-qwqq-9qpw

Heap-based buffer overflow in Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SIP firmware might allow remote SIP servers to execute arbitrary code via a crafted challenge/response message.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-2w9x-8fmc-q598

Cross-site scripting (XSS) vulnerability in the "Monitor browsers' feature in Browscap before 5.x-1.1 and 6.x-1.1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2w9x-58hj-96v8

A buffer overflow vulnerability has been discovered in the C++ components of ROS2 Galactic Geochelone ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows attackers to execute arbitrary code or cause a denial of service (DoS) via improper handling of arrays or strings.

больше 2 лет назад
github логотип
GHSA-2w9w-m6x3-g9c8

In onCreate of SetupLayoutActivity.java, there is a possible way to setup a work profile bypassing user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-209611539

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2w9w-fgq6-2vmc

Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability affects Firefox < 145.

CVSS3: 9.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-2w9w-5m28-9576

Buffer overflow in FTP server in QPC Software's QVT/Term Plus versions 4.2d and 4.3 and QVT/Net 4.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long (1) user name or (2) password.

12%
Средний
больше 4 лет назад
github логотип
GHSA-2w9w-5h27-2qqm

Jason2605 AdminPanel 4.0 allows SQL Injection via the editPlayer.php hidden parameter.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2w9w-448q-4hqv

A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An attacker could exploit this vulnerability by sending a user a malicious ARF or WRF file via a link or an email attachment and persuading the user to open the file by using the affected software. A successful exploit could allow the attacker to execute arbitrary code on the affected system.

CVSS3: 7.8
2%
Низкий
около 4 лет назад

Уязвимостей на страницу