Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 558

Количество 355 558

github логотип

GHSA-2vvq-j8xq-hwrq

около 4 лет назад

The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulnerability due to the way memory addresses are handled, aka "Windows Kernel Information Disclosure Vulnerability". This CVE is unique from CVE-2018-0811, CVE-2018-0813, CVE-2018-0814, CVE-2018-0894, CVE-2018-0895, CVE-2018-0896, CVE-2018-0898, CVE-2018-0899, CVE-2018-0900, CVE-2018-0901 and CVE-2018-0926.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-2vvp-wxcw-3455

около 2 месяцев назад

Unauthenticated Cross Site Scripting (XSS) in Enfold <= 7.1.4 versions.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2vvp-rqvq-vxv2

около 3 лет назад

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-2vvp-c6qg-7x3r

больше 4 лет назад

Cross-site scripting vulnerability in E-Blah Platinum 9.7 allows remote attackers to inject arbitrary web script or HTML via the referer (HTTP_REFERER), which is not sanitized when the log file is viewed by the administrator using "Click Log".

EPSS: Низкий
github логотип

GHSA-2vvp-3qrq-jvpm

почти 4 года назад

Clinic's Patient Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via patients.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2vvm-g2m7-36wx

около 4 лет назад

The management GUI in the web framework in IronPort AsyncOS on Cisco Web Security Appliance devices before 7.1.3-013, 7.5 before 7.5.0-838, and 7.7 before 7.7.0-602; Email Security Appliance devices before 7.1.5-106 and 7.3, 7.5, and 7.6 before 7.6.3-019; and Content Security Management Appliance devices before 7.9.1-102 and 8.0 before 8.0.0-404 allows remote attackers to cause a denial of service (system hang) via a series of (1) HTTP or (2) HTTPS requests to a management interface, aka Bug IDs CSCzv58669, CSCzv63329, and CSCzv78669.

EPSS: Низкий
github логотип

GHSA-2vvm-3hqv-2c4h

больше 4 лет назад

Multiple PHP remote file inclusion vulnerabilities in adminprint.php in PicturesPro Photo Cart 3.9 allow remote attackers to execute arbitrary PHP code via a URL in the (1) admin_folder and (2) path parameters.

EPSS: Низкий
github логотип

GHSA-2vvj-x2x5-ghqg

около 4 лет назад

An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They replace secure and protected directory permissions (set as default by the underlying operating system) with highly insecure read, write, and execute directory permissions for all users. By default, /usr/local and all of its subdirectories should have permissions set to only allow non-privileged users to read and execute from the tree structure, and to deny users from creating or editing files in this location. The ENTTEC firmware startup script permits all users to read, write, and execute (rwxrwxrwx) from the /usr, /usr/local, /usr/local/dmxis, and /usr/local/bin/ directories.

EPSS: Низкий
github логотип

GHSA-2vvj-hm96-cr7r

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: hv_netvsc: Register VF in netvsc_probe if NET_DEVICE_REGISTER missed If hv_netvsc driver is unloaded and reloaded, the NET_DEVICE_REGISTER handler cannot perform VF register successfully as the register call is received before netvsc_probe is finished. This is because we register register_netdevice_notifier() very early( even before vmbus_driver_register()). To fix this, we try to register each such matching VF( if it is visible as a netdevice) at the end of netvsc_probe.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2vvj-8q22-v822

около 4 лет назад

The Search component in IBM WebSphere Commerce 7.0 FP4 through FP6, in certain search-term association configurations, allows remote attackers to cause a denial of service via a crafted query.

EPSS: Низкий
github логотип

GHSA-2vvg-qw4w-m46v

больше 1 года назад

In onPrimaryClipChanged of ClipboardListener.java, there is a possible way to partially bypass lock screen. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2vvg-j984-hh8p

около 1 года назад

loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.

CVSS3: 4.3
EPSS: Средний
github логотип

GHSA-2vvf-m6gh-56m4

около 4 лет назад

Cisco IOS XR 5.x through 5.2.5 on NCS 6000 devices allows remote attackers to cause a denial of service (timer consumption and Route Processor reload) via crafted SSH traffic, aka Bug ID CSCux76819.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2vvf-4m7q-pvpx

9 месяцев назад

A denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality of Entr&#39;ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a denial of service. An attacker can send a malformed SAML response to trigger this vulnerability.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-2vvf-4m7g-gc7w

около 4 лет назад

Buffer overflow in the DAS server in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 might allow attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors, a different vulnerability than CVE-2007-3676 and CVE-2008-3853.

EPSS: Низкий
github логотип

GHSA-2vvc-952f-f8xg

около 4 лет назад

The m_sasl module in InspIRCd before 2.0.23, when used with a service that supports SASL_EXTERNAL authentication, allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted SASL message.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2vv9-3gf2-vjx5

больше 2 лет назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Utarit Information Technologies SoliPay Mobile App allows SQL Injection.This issue affects SoliPay Mobile App: before 5.0.8.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2vv7-7crh-jr74

около 4 лет назад

The snd_ctl_elem_add function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not properly maintain the user_ctl_count value, which allows local users to cause a denial of service (integer overflow and limit bypass) by leveraging /dev/snd/controlCX access for a large number of SNDRV_CTL_IOCTL_ELEM_REPLACE ioctl calls.

EPSS: Низкий
github логотип

GHSA-2vv6-fvmm-g8r3

25 дней назад

Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorized attacker to disclose information locally.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2vv5-w39x-64g7

около 4 лет назад

An issue was discovered on the D-Link DWR-932B router. qmiweb allows directory listing with ../ traversal.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2vvq-j8xq-hwrq

The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulnerability due to the way memory addresses are handled, aka "Windows Kernel Information Disclosure Vulnerability". This CVE is unique from CVE-2018-0811, CVE-2018-0813, CVE-2018-0814, CVE-2018-0894, CVE-2018-0895, CVE-2018-0896, CVE-2018-0898, CVE-2018-0899, CVE-2018-0900, CVE-2018-0901 and CVE-2018-0926.

CVSS3: 4.7
2%
Низкий
около 4 лет назад
github логотип
GHSA-2vvp-wxcw-3455

Unauthenticated Cross Site Scripting (XSS) in Enfold <= 7.1.4 versions.

CVSS3: 7.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2vvp-rqvq-vxv2

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVSS3: 8.2
1%
Низкий
около 3 лет назад
github логотип
GHSA-2vvp-c6qg-7x3r

Cross-site scripting vulnerability in E-Blah Platinum 9.7 allows remote attackers to inject arbitrary web script or HTML via the referer (HTTP_REFERER), which is not sanitized when the log file is viewed by the administrator using "Click Log".

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2vvp-3qrq-jvpm

Clinic's Patient Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via patients.php.

CVSS3: 6.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-2vvm-g2m7-36wx

The management GUI in the web framework in IronPort AsyncOS on Cisco Web Security Appliance devices before 7.1.3-013, 7.5 before 7.5.0-838, and 7.7 before 7.7.0-602; Email Security Appliance devices before 7.1.5-106 and 7.3, 7.5, and 7.6 before 7.6.3-019; and Content Security Management Appliance devices before 7.9.1-102 and 8.0 before 8.0.0-404 allows remote attackers to cause a denial of service (system hang) via a series of (1) HTTP or (2) HTTPS requests to a management interface, aka Bug IDs CSCzv58669, CSCzv63329, and CSCzv78669.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2vvm-3hqv-2c4h

Multiple PHP remote file inclusion vulnerabilities in adminprint.php in PicturesPro Photo Cart 3.9 allow remote attackers to execute arbitrary PHP code via a URL in the (1) admin_folder and (2) path parameters.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-2vvj-x2x5-ghqg

An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They replace secure and protected directory permissions (set as default by the underlying operating system) with highly insecure read, write, and execute directory permissions for all users. By default, /usr/local and all of its subdirectories should have permissions set to only allow non-privileged users to read and execute from the tree structure, and to deny users from creating or editing files in this location. The ENTTEC firmware startup script permits all users to read, write, and execute (rwxrwxrwx) from the /usr, /usr/local, /usr/local/dmxis, and /usr/local/bin/ directories.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2vvj-hm96-cr7r

In the Linux kernel, the following vulnerability has been resolved: hv_netvsc: Register VF in netvsc_probe if NET_DEVICE_REGISTER missed If hv_netvsc driver is unloaded and reloaded, the NET_DEVICE_REGISTER handler cannot perform VF register successfully as the register call is received before netvsc_probe is finished. This is because we register register_netdevice_notifier() very early( even before vmbus_driver_register()). To fix this, we try to register each such matching VF( if it is visible as a netdevice) at the end of netvsc_probe.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2vvj-8q22-v822

The Search component in IBM WebSphere Commerce 7.0 FP4 through FP6, in certain search-term association configurations, allows remote attackers to cause a denial of service via a crafted query.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2vvg-qw4w-m46v

In onPrimaryClipChanged of ClipboardListener.java, there is a possible way to partially bypass lock screen. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2vvg-j984-hh8p

loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.

CVSS3: 4.3
59%
Средний
около 1 года назад
github логотип
GHSA-2vvf-m6gh-56m4

Cisco IOS XR 5.x through 5.2.5 on NCS 6000 devices allows remote attackers to cause a denial of service (timer consumption and Route Processor reload) via crafted SSH traffic, aka Bug ID CSCux76819.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-2vvf-4m7q-pvpx

A denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality of Entr&#39;ouvert Lasso 2.5.1. A specially crafted SAML response can lead to a denial of service. An attacker can send a malformed SAML response to trigger this vulnerability.

CVSS3: 9.6
0%
Низкий
9 месяцев назад
github логотип
GHSA-2vvf-4m7g-gc7w

Buffer overflow in the DAS server in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 might allow attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors, a different vulnerability than CVE-2007-3676 and CVE-2008-3853.

4%
Низкий
около 4 лет назад
github логотип
GHSA-2vvc-952f-f8xg

The m_sasl module in InspIRCd before 2.0.23, when used with a service that supports SASL_EXTERNAL authentication, allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted SASL message.

CVSS3: 5.9
1%
Низкий
около 4 лет назад
github логотип
GHSA-2vv9-3gf2-vjx5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Utarit Information Technologies SoliPay Mobile App allows SQL Injection.This issue affects SoliPay Mobile App: before 5.0.8.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2vv7-7crh-jr74

The snd_ctl_elem_add function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not properly maintain the user_ctl_count value, which allows local users to cause a denial of service (integer overflow and limit bypass) by leveraging /dev/snd/controlCX access for a large number of SNDRV_CTL_IOCTL_ELEM_REPLACE ioctl calls.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2vv6-fvmm-g8r3

Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorized attacker to disclose information locally.

CVSS3: 5.5
0%
Низкий
25 дней назад
github логотип
GHSA-2vv5-w39x-64g7

An issue was discovered on the D-Link DWR-932B router. qmiweb allows directory listing with ../ traversal.

CVSS3: 7.5
6%
Низкий
около 4 лет назад

Уязвимостей на страницу