Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 558

Количество 355 558

github логотип

GHSA-2vr8-wh6w-3q8m

2 месяца назад

Unauthenticated Debug Service. The /sbin/mtk_dut binary is exposed on TCP port 9000 without authentication, allowing any LAN-based attacker to execute arbitrary UCC commands.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2vr8-6569-m8cp

около 4 лет назад

Inappropriate implementation in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass same origin policy via a crafted HTML page.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2vr7-h5jg-93gq

около 4 лет назад

Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has a composite of Stored XSS and Information Disclosure issues in the attachments feature found in User CP. This can be triggered by any Invision Power Board user and can be used to gain access to moderator/admin accounts. The primary cause is the ability to upload an SVG document with a crafted attribute such an onload; however, full path disclosure is required for exploitation.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2vr7-cm5g-mpcr

около 4 лет назад

The Console in IBM InfoSphere Optim Data Growth for Oracle E-Business Suite 6.x, 7.x, and 9.x before 9.1.0.3 does not provide an encrypted session for transmitting login credentials, which allows remote attackers to obtain sensitive information by sniffing the network.

EPSS: Низкий
github логотип

GHSA-2vr7-94q2-m6j4

около 4 лет назад

Buffer overflow in Drive Control Program (DCP) in EMC AlphaStor 4.0 before build 814 allows remote attackers to execute arbitrary code via vectors involving a new device name.

EPSS: Низкий
github логотип

GHSA-2vr6-j9xc-hjxh

больше 4 лет назад

Multiple vulnerabilities in noweb 2.9 and earlier creates temporary files insecurely, which allows local users to overwrite arbitrary files via multiple vectors including the noroff script.

EPSS: Низкий
github логотип

GHSA-2vr6-hcxv-cf3w

16 дней назад

Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2vr5-fw7q-r93h

около 4 лет назад

WebKit, as used in Apple iOS before 8.3, Apple TV before 7.2, and Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-04-08-1, APPLE-SA-2015-04-08-3, and APPLE-SA-2015-04-08-4.

EPSS: Низкий
github логотип

GHSA-2vr2-r99h-p8hr

3 месяца назад

NVIDIA Flare SDK contains a vulnerability where an Attacker may cause an Improper Input Validation by path traversing. A successful exploit of this vulnerability may lead to information disclosure.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2vr2-94fc-9pcg

около 4 лет назад

Use-after-free vulnerability in the MovieClip object implementation in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via a crafted lineTo method call, a different vulnerability than CVE-2015-8048, CVE-2015-8049, CVE-2015-8050, CVE-2015-8055, CVE-2015-8056, CVE-2015-8057, CVE-2015-8058, CVE-2015-8059, CVE-2015-8061, CVE-2015-8062, CVE-2015-8063, CVE-2015-8064, CVE-2015-8065, CVE-2015-8066, CVE-2015-8067, CVE-2015-8068, CVE-2015-8069, CVE-2015-8070, CVE-2015-8071, CVE-2015-8401, CVE-2015-8402, CVE-2015-8403, CVE-2015-8404, CVE-2015-8405, CVE-2015-8406, CVE-2015-8410, CVE-2015-8411, CVE-2015-8412, CVE-2015-8413, CVE-2015-8414, CVE-2015-8420, CVE-2015-8421, CVE-2015-8422, CVE-2015-8423, CVE-2015-8424, CVE-2015-8425, CVE-2015-8426, CVE-2015-8427, CVE-2015-842...

EPSS: Низкий
github логотип

GHSA-2vqx-vc77-4m8p

10 месяцев назад

SQL injection vulnerability in the cmd component of Base Digitale Group spa product Centrax Open PSIM version 6.1 allows an unauthenticated user to execute arbitrary SQL commands via the sender parameter.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2vqx-5p37-qq4w

около 1 года назад

An issue in Gardyn 4 allows a remote attacker with the corresponding ssh private key can gain remote root access to affected devices

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2vqw-chr2-h9wp

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix an out-of-bounds bug in __snd_usb_parse_audio_interface() There may be a bad USB audio device with a USB ID of (0x04fa, 0x4201) and the number of it's interfaces less than 4, an out-of-bounds read bug occurs when parsing the interface descriptor for this device. Fix this by checking the number of interfaces.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2vqw-3mp8-cgmx

2 месяца назад

Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2vqw-29j2-c787

больше 4 лет назад

The default configuration of Arescom NetDSL 800 does not require authentication, which allows remote attackers to cause a denial of service or reconfigure the router.

EPSS: Низкий
github логотип

GHSA-2vqv-hp3p-fmv8

больше 7 лет назад

Downloads Resources over HTTP in webdriver-launcher

EPSS: Низкий
github логотип

GHSA-2vqv-f5h7-hwv8

около 4 лет назад

RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a crafted length of an MLTI chunk in an IVR file.

EPSS: Низкий
github логотип

GHSA-2vqr-qj95-q9f6

около 4 лет назад

ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated users to obtain user passwords by displaying user information in a Telnet connection.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-2vqr-3j4p-r5j5

около 4 лет назад

IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition 7.2.x allow remote authenticated users to bypass intended access restrictions and send requests to internal services via a callService URL.

EPSS: Низкий
github логотип

GHSA-2vqq-jgxx-fxjc

почти 6 лет назад

Malicious Package in motiv.scss

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2vr8-wh6w-3q8m

Unauthenticated Debug Service. The /sbin/mtk_dut binary is exposed on TCP port 9000 without authentication, allowing any LAN-based attacker to execute arbitrary UCC commands.

CVSS3: 8.8
0%
Низкий
2 месяца назад
github логотип
GHSA-2vr8-6569-m8cp

Inappropriate implementation in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass same origin policy via a crafted HTML page.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2vr7-h5jg-93gq

Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has a composite of Stored XSS and Information Disclosure issues in the attachments feature found in User CP. This can be triggered by any Invision Power Board user and can be used to gain access to moderator/admin accounts. The primary cause is the ability to upload an SVG document with a crafted attribute such an onload; however, full path disclosure is required for exploitation.

CVSS3: 8.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-2vr7-cm5g-mpcr

The Console in IBM InfoSphere Optim Data Growth for Oracle E-Business Suite 6.x, 7.x, and 9.x before 9.1.0.3 does not provide an encrypted session for transmitting login credentials, which allows remote attackers to obtain sensitive information by sniffing the network.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2vr7-94q2-m6j4

Buffer overflow in Drive Control Program (DCP) in EMC AlphaStor 4.0 before build 814 allows remote attackers to execute arbitrary code via vectors involving a new device name.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2vr6-j9xc-hjxh

Multiple vulnerabilities in noweb 2.9 and earlier creates temporary files insecurely, which allows local users to overwrite arbitrary files via multiple vectors including the noroff script.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-2vr6-hcxv-cf3w

Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions.

CVSS3: 5.3
0%
Низкий
16 дней назад
github логотип
GHSA-2vr5-fw7q-r93h

WebKit, as used in Apple iOS before 8.3, Apple TV before 7.2, and Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-04-08-1, APPLE-SA-2015-04-08-3, and APPLE-SA-2015-04-08-4.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2vr2-r99h-p8hr

NVIDIA Flare SDK contains a vulnerability where an Attacker may cause an Improper Input Validation by path traversing. A successful exploit of this vulnerability may lead to information disclosure.

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-2vr2-94fc-9pcg

Use-after-free vulnerability in the MovieClip object implementation in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via a crafted lineTo method call, a different vulnerability than CVE-2015-8048, CVE-2015-8049, CVE-2015-8050, CVE-2015-8055, CVE-2015-8056, CVE-2015-8057, CVE-2015-8058, CVE-2015-8059, CVE-2015-8061, CVE-2015-8062, CVE-2015-8063, CVE-2015-8064, CVE-2015-8065, CVE-2015-8066, CVE-2015-8067, CVE-2015-8068, CVE-2015-8069, CVE-2015-8070, CVE-2015-8071, CVE-2015-8401, CVE-2015-8402, CVE-2015-8403, CVE-2015-8404, CVE-2015-8405, CVE-2015-8406, CVE-2015-8410, CVE-2015-8411, CVE-2015-8412, CVE-2015-8413, CVE-2015-8414, CVE-2015-8420, CVE-2015-8421, CVE-2015-8422, CVE-2015-8423, CVE-2015-8424, CVE-2015-8425, CVE-2015-8426, CVE-2015-8427, CVE-2015-842...

7%
Низкий
около 4 лет назад
github логотип
GHSA-2vqx-vc77-4m8p

SQL injection vulnerability in the cmd component of Base Digitale Group spa product Centrax Open PSIM version 6.1 allows an unauthenticated user to execute arbitrary SQL commands via the sender parameter.

CVSS3: 5.4
0%
Низкий
10 месяцев назад
github логотип
GHSA-2vqx-5p37-qq4w

An issue in Gardyn 4 allows a remote attacker with the corresponding ssh private key can gain remote root access to affected devices

CVSS3: 8.1
около 1 года назад
github логотип
GHSA-2vqw-chr2-h9wp

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix an out-of-bounds bug in __snd_usb_parse_audio_interface() There may be a bad USB audio device with a USB ID of (0x04fa, 0x4201) and the number of it's interfaces less than 4, an out-of-bounds read bug occurs when parsing the interface descriptor for this device. Fix this by checking the number of interfaces.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2vqw-3mp8-cgmx

Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections

CVSS3: 7.5
0%
Низкий
2 месяца назад
github логотип
GHSA-2vqw-29j2-c787

The default configuration of Arescom NetDSL 800 does not require authentication, which allows remote attackers to cause a denial of service or reconfigure the router.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-2vqv-hp3p-fmv8

Downloads Resources over HTTP in webdriver-launcher

2%
Низкий
больше 7 лет назад
github логотип
GHSA-2vqv-f5h7-hwv8

RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a crafted length of an MLTI chunk in an IVR file.

4%
Низкий
около 4 лет назад
github логотип
GHSA-2vqr-qj95-q9f6

ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated users to obtain user passwords by displaying user information in a Telnet connection.

CVSS3: 8.8
13%
Средний
около 4 лет назад
github логотип
GHSA-2vqr-3j4p-r5j5

IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition 7.2.x allow remote authenticated users to bypass intended access restrictions and send requests to internal services via a callService URL.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2vqq-jgxx-fxjc

Malicious Package in motiv.scss

CVSS3: 9.8
почти 6 лет назад

Уязвимостей на страницу