Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 558

Количество 355 558

github логотип

GHSA-2vq7-c2r9-jgpf

около 4 лет назад

Windows Fast FAT File System Driver Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-38662.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2vq7-8vvf-w66v

больше 2 лет назад

Exim libspf2 Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Exim libspf2. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parsing of SPF macros. When parsing SPF macros, the process does not properly validate user-supplied data, which can result in an integer underflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-17578.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-2vq7-33x9-h9x9

2 месяца назад

InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2vq6-f897-g2gx

около 4 лет назад

Stack-based buffer overflow in the main function in util/lpci_main.c in Csound before 5.17.2, when converting a file, allows user-assisted remote attackers to execute arbitrary code via a crafted file.

EPSS: Низкий
github логотип

GHSA-2vq6-7g93-mrhp

около 4 лет назад

The Register Plus plugin 3.5.1 and earlier for WordPress allows remote attackers to obtain sensitive information via a direct request to (1) dash_widget.php and (2) register-plus.php, which reveals the installation path in an error message.

EPSS: Низкий
github логотип

GHSA-2vq4-854f-5c72

4 месяца назад

Vikunja vulnerable to Privilege Escalation via Project Reparenting

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-2vq4-6g9q-2xjq

около 4 лет назад

The Eat Spray Love mobile app for both iOS and Android contains logic that allows users to bypass authentication and retrieve or modify information that they would not normally have access to.

EPSS: Низкий
github логотип

GHSA-2vq4-4j9c-v3v4

3 месяца назад

A vulnerability was determined in liyupi yu-picture up to a053632c41340152bf75b66b3c543d129123d8ec. This impacts the function PageRequest of the file yu-picture-backend/src/main/java/com/yupi/yupicturebackend/service/impl/PictureServiceImpl.java of the component MyBatis-Plus. Executing a manipulation of the argument sortField can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. Applying a patch is advised to resolve this issue. The project was informed of the problem early through a pull request but has not reacted yet.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2vq3-r375-cjhg

больше 1 года назад

Use after free in WebAudio in Google Chrome prior to 136.0.7103.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2vq3-9f5g-9jr5

больше 2 лет назад

Substance3D - Designer versions 13.1.0 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2vq3-7wqx-v4r2

больше 4 лет назад

Unspecified vulnerability in the SMB component in Apple Mac OS X 10.4.11 and 10.5.6 allows remote SMB servers to cause a denial of service (memory exhaustion and system shutdown) via a crafted file system name.

EPSS: Низкий
github логотип

GHSA-2vq2-xc55-3j5m

почти 4 года назад

libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2vq2-p76v-j88p

больше 4 лет назад

Format string vulnerability in ypserv in Mandrake Linux 7.1 and earlier, and possibly other Linux operating systems, allows an attacker to gain root privileges when ypserv is built without a vsyslog() function.

EPSS: Низкий
github логотип

GHSA-2vq2-77wm-755c

больше 4 лет назад

Computer Associates (CA) InoculateIT 6.0, eTrust Antivirus r6.0 through r7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content Manager, eTrust Intrusion Detection, EZ-Armor 2.0 through 2.4, and EZ-Antivirus 6.1 through 6.3 allow remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.

EPSS: Средний
github логотип

GHSA-2vpx-p529-jx74

около 4 лет назад

Use-after-free vulnerability in the SVG implementation in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

EPSS: Низкий
github логотип

GHSA-2vpx-j6gq-83g2

7 месяцев назад

Multiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data buffers. Due to insufficient validation of maximum buffer size values, the process may attempt to read beyond the intended memory region. Under specific conditions, this can result in a crash of the affected process and a potential denial-of-service of the compromised process.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2vpx-cqm4-rqhq

около 4 лет назад

An issue was discovered in Joomla! 3.0.0 through 3.9.27. Inadequate escaping in the rules field of the JForm API leads to a XSS vulnerability.

EPSS: Низкий
github логотип

GHSA-2vpw-vxmx-p733

почти 3 года назад

Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on certain sensitive ones allowing media exploitation from a malicious mattermost server

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-2vpw-mvv7-vfx4

больше 1 года назад

Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/SystemSettings.php?f=update_settings. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2vpw-h4q9-62fp

больше 4 лет назад

Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c.

EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2vq7-c2r9-jgpf

Windows Fast FAT File System Driver Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-38662.

CVSS3: 5.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2vq7-8vvf-w66v

Exim libspf2 Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Exim libspf2. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parsing of SPF macros. When parsing SPF macros, the process does not properly validate user-supplied data, which can result in an integer underflow before writing to memory. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-17578.

CVSS3: 7.5
52%
Средний
больше 2 лет назад
github логотип
GHSA-2vq7-33x9-h9x9

InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
2 месяца назад
github логотип
GHSA-2vq6-f897-g2gx

Stack-based buffer overflow in the main function in util/lpci_main.c in Csound before 5.17.2, when converting a file, allows user-assisted remote attackers to execute arbitrary code via a crafted file.

7%
Низкий
около 4 лет назад
github логотип
GHSA-2vq6-7g93-mrhp

The Register Plus plugin 3.5.1 and earlier for WordPress allows remote attackers to obtain sensitive information via a direct request to (1) dash_widget.php and (2) register-plus.php, which reveals the installation path in an error message.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2vq4-854f-5c72

Vikunja vulnerable to Privilege Escalation via Project Reparenting

CVSS3: 8.3
0%
Низкий
4 месяца назад
github логотип
GHSA-2vq4-6g9q-2xjq

The Eat Spray Love mobile app for both iOS and Android contains logic that allows users to bypass authentication and retrieve or modify information that they would not normally have access to.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2vq4-4j9c-v3v4

A vulnerability was determined in liyupi yu-picture up to a053632c41340152bf75b66b3c543d129123d8ec. This impacts the function PageRequest of the file yu-picture-backend/src/main/java/com/yupi/yupicturebackend/service/impl/PictureServiceImpl.java of the component MyBatis-Plus. Executing a manipulation of the argument sortField can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. Applying a patch is advised to resolve this issue. The project was informed of the problem early through a pull request but has not reacted yet.

CVSS3: 7.3
0%
Низкий
3 месяца назад
github логотип
GHSA-2vq3-r375-cjhg

Use after free in WebAudio in Google Chrome prior to 136.0.7103.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 8.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2vq3-9f5g-9jr5

Substance3D - Designer versions 13.1.0 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2vq3-7wqx-v4r2

Unspecified vulnerability in the SMB component in Apple Mac OS X 10.4.11 and 10.5.6 allows remote SMB servers to cause a denial of service (memory exhaustion and system shutdown) via a crafted file system name.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2vq2-xc55-3j5m

libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.

CVSS3: 9.8
2%
Низкий
почти 4 года назад
github логотип
GHSA-2vq2-p76v-j88p

Format string vulnerability in ypserv in Mandrake Linux 7.1 and earlier, and possibly other Linux operating systems, allows an attacker to gain root privileges when ypserv is built without a vsyslog() function.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2vq2-77wm-755c

Computer Associates (CA) InoculateIT 6.0, eTrust Antivirus r6.0 through r7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content Manager, eTrust Intrusion Detection, EZ-Armor 2.0 through 2.4, and EZ-Antivirus 6.1 through 6.3 allow remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.

21%
Средний
больше 4 лет назад
github логотип
GHSA-2vpx-p529-jx74

Use-after-free vulnerability in the SVG implementation in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2vpx-j6gq-83g2

Multiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data buffers. Due to insufficient validation of maximum buffer size values, the process may attempt to read beyond the intended memory region. Under specific conditions, this can result in a crash of the affected process and a potential denial-of-service of the compromised process.

CVSS3: 5.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-2vpx-cqm4-rqhq

An issue was discovered in Joomla! 3.0.0 through 3.9.27. Inadequate escaping in the rules field of the JForm API leads to a XSS vulnerability.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2vpw-vxmx-p733

Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on certain sensitive ones allowing media exploitation from a malicious mattermost server

CVSS3: 3.7
0%
Низкий
почти 3 года назад
github логотип
GHSA-2vpw-mvv7-vfx4

Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/SystemSettings.php?f=update_settings. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-2vpw-h4q9-62fp

Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c.

72%
Высокий
больше 4 лет назад

Уязвимостей на страницу