Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 628

Количество 355 628

github логотип

GHSA-2w9v-j4mv-6g6v

около 4 лет назад

In JetBrains TeamCity before 2022.04 potential XSS via Referrer header was possible

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2w9v-97wx-v5mj

больше 4 лет назад

Unspecified vulnerability in rsync before 3.0.0pre6, when running a writable rsync daemon, allows remote attackers to bypass exclude, exclude_from, and filter and read or write hidden files via (1) symlink, (2) partial-dir, (3) backup-dir, and unspecified (4) dest options.

EPSS: Низкий
github логотип

GHSA-2w9v-578w-mf3c

больше 4 лет назад

The Sun Cluster Global File System in Sun Cluster 3.1 on Sun Solaris 8 through 10, when an underlying ufs filesystem is used, might allow local users to read data from arbitrary deleted files, or corrupt files in global filesystems, via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2w9r-mr74-qj9p

больше 4 лет назад

Tiny ASN.1 Library (libtasn1) before 0.2.18, as used by (1) GnuTLS 1.2.x before 1.2.10 and 1.3.x before 1.3.4, and (2) GNU Shishi, allows attackers to crash the DER decoder and possibly execute arbitrary code via "out-of-bounds access" caused by invalid input, as demonstrated by the ProtoVer SSL test suite.

EPSS: Низкий
github логотип

GHSA-2w9r-f5h3-xwfx

около 4 лет назад

IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may terminate abnormally when executing specially crafted SQL statements by an authenticated user. IBM X-Force ID: 2219740.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2w9q-2gq5-vqqj

больше 4 лет назад

The RgSecurity form in the HTTP server for the Thomson TCW690 cable modem running firmware 2.1 and software ST42.03.0a does not properly validate the password before performing changes, which allows remote attackers on the LAN to gain access via a direct POST request.

EPSS: Низкий
github логотип

GHSA-2w9p-xxqr-h253

около 2 лет назад

eZ Platform Object Injection in SiteAccessMatchListener

EPSS: Низкий
github логотип

GHSA-2w9p-xf5h-qwj3

больше 3 лет назад

Duplicate Advisory: pullit Command Injection vulnerability

EPSS: Низкий
github логотип

GHSA-2w9p-mqx6-cvqc

почти 3 года назад

A insufficient session expiration in Fortinet FortiEDR version 5.0.0 through 5.0.1 allows attacker to execute unauthorized code or commands via api request

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2w9p-mj8f-374x

почти 3 года назад

Mattermost Mobile fails to limit the maximum number of Markdown elements in a post allowing an attacker to send a post with hundreds of emojis to a channel and freeze the mobile app of users when viewing that particular channel. 

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2w9p-8x38-7x8f

11 дней назад

The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-2w9p-3jw9-6hcv

около 4 лет назад

Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2774, CVE-2014-2820, CVE-2014-2826, and CVE-2014-2827.

EPSS: Средний
github логотип

GHSA-2w9p-35fw-8hfr

около 3 лет назад

The issue was addressed with improved memory handling. This issue is fixed in iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. An app may be able to execute arbitrary code with kernel privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2w9j-55xj-gcp3

около 4 лет назад

This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Link DAP-2020 1.01rc001 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the getpage parameter provided to the webproc endpoint. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose information in the context of root. Was ZDI-CAN-12103.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2w9g-759j-gvh6

около 4 лет назад

PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002T-4G VZW through 2.05.3, TC ROUTER 3002T-4G ATT through 2.05.3, TC CLOUD CLIENT 1002-4G through 2.03.17, and TC CLOUD CLIENT 1002-TXTX through 1.03.17 devices allow authenticated users to inject system commands through a modified POST request to a specific URL.

EPSS: Низкий
github логотип

GHSA-2w9g-5cc4-cm66

около 1 года назад

A vulnerability was found in code-projects Library System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /student-issue-book.php. The manipulation of the argument reg leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2w9g-53qp-p3g5

3 дня назад

Heap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2w9f-2xp2-w98x

2 месяца назад

Missing authorization vulnerability in AddOns functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitive information via unspecified vectors.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-2w9c-93f4-c2p4

больше 4 лет назад

Buffer overflow in marbles 1.0.2 and earlier allows local users to gain privileges via a long HOME environment variable.

EPSS: Низкий
github логотип

GHSA-2w9c-67cj-fxpp

почти 3 года назад

IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 262174.

CVSS3: 6.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2w9v-j4mv-6g6v

In JetBrains TeamCity before 2022.04 potential XSS via Referrer header was possible

CVSS3: 6.1
0%
Низкий
около 4 лет назад
github логотип
GHSA-2w9v-97wx-v5mj

Unspecified vulnerability in rsync before 3.0.0pre6, when running a writable rsync daemon, allows remote attackers to bypass exclude, exclude_from, and filter and read or write hidden files via (1) symlink, (2) partial-dir, (3) backup-dir, and unspecified (4) dest options.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-2w9v-578w-mf3c

The Sun Cluster Global File System in Sun Cluster 3.1 on Sun Solaris 8 through 10, when an underlying ufs filesystem is used, might allow local users to read data from arbitrary deleted files, or corrupt files in global filesystems, via unspecified vectors.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-2w9r-mr74-qj9p

Tiny ASN.1 Library (libtasn1) before 0.2.18, as used by (1) GnuTLS 1.2.x before 1.2.10 and 1.3.x before 1.3.4, and (2) GNU Shishi, allows attackers to crash the DER decoder and possibly execute arbitrary code via "out-of-bounds access" caused by invalid input, as demonstrated by the ProtoVer SSL test suite.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-2w9r-f5h3-xwfx

IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may terminate abnormally when executing specially crafted SQL statements by an authenticated user. IBM X-Force ID: 2219740.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2w9q-2gq5-vqqj

The RgSecurity form in the HTTP server for the Thomson TCW690 cable modem running firmware 2.1 and software ST42.03.0a does not properly validate the password before performing changes, which allows remote attackers on the LAN to gain access via a direct POST request.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-2w9p-xxqr-h253

eZ Platform Object Injection in SiteAccessMatchListener

около 2 лет назад
github логотип
GHSA-2w9p-xf5h-qwj3

Duplicate Advisory: pullit Command Injection vulnerability

больше 3 лет назад
github логотип
GHSA-2w9p-mqx6-cvqc

A insufficient session expiration in Fortinet FortiEDR version 5.0.0 through 5.0.1 allows attacker to execute unauthorized code or commands via api request

CVSS3: 8.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-2w9p-mj8f-374x

Mattermost Mobile fails to limit the maximum number of Markdown elements in a post allowing an attacker to send a post with hundreds of emojis to a channel and freeze the mobile app of users when viewing that particular channel. 

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-2w9p-8x38-7x8f

The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVSS3: 10
0%
Низкий
11 дней назад
github логотип
GHSA-2w9p-3jw9-6hcv

Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2774, CVE-2014-2820, CVE-2014-2826, and CVE-2014-2827.

23%
Средний
около 4 лет назад
github логотип
GHSA-2w9p-35fw-8hfr

The issue was addressed with improved memory handling. This issue is fixed in iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. An app may be able to execute arbitrary code with kernel privileges.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-2w9j-55xj-gcp3

This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Link DAP-2020 1.01rc001 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the getpage parameter provided to the webproc endpoint. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose information in the context of root. Was ZDI-CAN-12103.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2w9g-759j-gvh6

PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002T-4G VZW through 2.05.3, TC ROUTER 3002T-4G ATT through 2.05.3, TC CLOUD CLIENT 1002-4G through 2.03.17, and TC CLOUD CLIENT 1002-TXTX through 1.03.17 devices allow authenticated users to inject system commands through a modified POST request to a specific URL.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2w9g-5cc4-cm66

A vulnerability was found in code-projects Library System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /student-issue-book.php. The manipulation of the argument reg leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
около 1 года назад
github логотип
GHSA-2w9g-53qp-p3g5

Heap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)

CVSS3: 7.5
0%
Низкий
3 дня назад
github логотип
GHSA-2w9f-2xp2-w98x

Missing authorization vulnerability in AddOns functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to obtain sensitive information via unspecified vectors.

CVSS3: 4.9
0%
Низкий
2 месяца назад
github логотип
GHSA-2w9c-93f4-c2p4

Buffer overflow in marbles 1.0.2 and earlier allows local users to gain privileges via a long HOME environment variable.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2w9c-67cj-fxpp

IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 262174.

CVSS3: 6.4
0%
Низкий
почти 3 года назад

Уязвимостей на страницу