Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 380

Количество 355 380

github логотип

GHSA-2rxq-q8qw-7pgp

9 дней назад

The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.4 does not perform a capability or nonce check before deleting a site's custom-uploaded icon font packs, allowing unauthenticated attackers to permanently delete all of a site's custom icon fonts with a single request.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2rxq-9xvm-3j68

больше 1 года назад

Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2rxp-v6pw-ch6m

почти 2 года назад

REXML ReDoS vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2rxp-jvfw-cj2r

больше 3 лет назад

In Dataiku DSS 11.2.1, an attacker can download other Dataiku files that were uploaded to the myfiles section by specifying the target username in a download request.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2rxp-43p2-54mp

около 4 лет назад

In MicroWorld eScan Internet Security Suite (ISS) for Business 14.0.1400.2029, the driver econceal.sys allows a non-privileged user to send a 0x830020E0 IOCTL request to \\.\econceal to cause a denial of service (BSOD).

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2rxp-2ccg-vg6g

больше 4 лет назад

An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause a call to $Extract to force an signed integer holding the size of a buffer to take on a large negative number, which is then used as the length of a memcpy call that occurs on the stack, causing a buffer overflow.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2rxm-39cm-27mj

около 4 лет назад

Due to a new NDP proxy feature for EVPN leaf nodes introduced in Junos OS 17.4, crafted NDPv6 packets could transit a Junos device configured as a Broadband Network Gateway (BNG) and reach the EVPN leaf node, causing a stale MAC address entry. This could cause legitimate traffic to be discarded, leading to a Denial of Service (DoS) condition. This issue only affects Junos OS 17.4 and later releases. Prior releases do not support this feature and are unaffected by this vulnerability. This issue only affects IPv6. IPv4 ARP proxy is unaffected by this vulnerability. This issue affects Juniper Networks Junos OS: 17.4 versions prior to 17.4R2-S9, 17.4R3 on MX Series; 18.1 versions prior to 18.1R3-S9 on MX Series; 18.2 versions prior to 18.2R2-S7, 18.2R3-S3 on MX Series; 18.2X75 versions prior to 18.2X75-D33, 18.2X75-D411, 18.2X75-D420, 18.2X75-D60 on MX Series; 18.3 versions prior to 18.3R1-S7, 18.3R2-S3, 18.3R3 on MX Series; 18.4 versions prior to 18.4R1-S5, 18.4R2-S2, 18.4R3 on MX Seri...

EPSS: Низкий
github логотип

GHSA-2rxj-vwp2-v63v

около 3 лет назад

Integer underflow in grub_net_recv_ip4_packets; A malicious crafted IP packet can lead to an integer underflow in grub_net_recv_ip4_packets() function on rsm->total_len value. Under certain circumstances the total_len value may end up wrapping around to a small integer number which will be used in memory allocation. If the attack succeeds in such way, subsequent operations can write past the end of the buffer.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2rxj-7r53-f46w

около 4 лет назад

IceWarp Email Server 12.3.0.1 has Incorrect Access Control for user accounts.

EPSS: Низкий
github логотип

GHSA-2rxj-58vc-g6vw

больше 4 лет назад

Buffer overflow in listmanager earlier than 2.105.1 allows local users to gain additional privileges.

EPSS: Низкий
github логотип

GHSA-2rxh-h6h9-qrqc

около 6 лет назад

Class destructors causing side-effects when being unserialized in TYPO3 CMS

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-2rxh-g7fp-j3f7

больше 4 лет назад

WinAce allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.

EPSS: Низкий
github логотип

GHSA-2rxh-4vr2-w87x

8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: ASoC: da7219: Fix an error handling path in da7219_register_dai_clks() If clk_hw_register() fails, the corresponding clk should not be unregistered. To handle errors from loops, clean up partial iterations before doing the goto. So add a clk_hw_unregister(). Then use a while (--i >= 0) loop in the unwind section.

EPSS: Низкий
github логотип

GHSA-2rxg-f4r2-fm3c

около 4 лет назад

Sensitive passwords used in deployment and configuration of oVirt Metrics, all versions. were found to be insufficiently protected. Passwords could be disclosed in log files (if playbooks are run with -v) or in playbooks stored on Metrics or Bastion hosts.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2rxc-gjrp-vjhx

больше 1 года назад

Unsoundness in anstream

EPSS: Низкий
github логотип

GHSA-2rxc-97gh-gwr2

почти 4 года назад

pycdc commit 44a730f3a889503014fec94ae6e62d8401cb75e5 was discovered to contain a stack overflow via the component __sanitizer::StackDepotBase<__sanitizer::StackDepotNode.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2rxc-8f9w-fjq8

больше 4 лет назад

Window may read from uninitialized memory locations in rdiff

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2rxc-55rq-5r4c

больше 4 лет назад

Directory traversal vulnerability in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8, when using "flat" addons, allows remote attackers to read arbitrary Javascript, image, and stylesheet files via the chrome: URI scheme, as demonstrated by stealing session information from sessionstore.js.

EPSS: Низкий
github логотип

GHSA-2rx9-c484-mx43

5 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in stmcan NaturaLife Extensions naturalife-extensions allows Reflected XSS.This issue affects NaturaLife Extensions: from n/a through <= 2.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2rx9-6m9m-h79v

около 4 лет назад

Insufficient session authentication in web server for Intel(R) Data Center Manager SDK before version 5.0.2 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2rxq-q8qw-7pgp

The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.4 does not perform a capability or nonce check before deleting a site's custom-uploaded icon font packs, allowing unauthenticated attackers to permanently delete all of a site's custom icon fonts with a single request.

CVSS3: 6.5
0%
Низкий
9 дней назад
github логотип
GHSA-2rxq-9xvm-3j68

Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2rxp-v6pw-ch6m

REXML ReDoS vulnerability

CVSS3: 7.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-2rxp-jvfw-cj2r

In Dataiku DSS 11.2.1, an attacker can download other Dataiku files that were uploaded to the myfiles section by specifying the target username in a download request.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2rxp-43p2-54mp

In MicroWorld eScan Internet Security Suite (ISS) for Business 14.0.1400.2029, the driver econceal.sys allows a non-privileged user to send a 0x830020E0 IOCTL request to \\.\econceal to cause a denial of service (BSOD).

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-2rxp-2ccg-vg6g

An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause a call to $Extract to force an signed integer holding the size of a buffer to take on a large negative number, which is then used as the length of a memcpy call that occurs on the stack, causing a buffer overflow.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-2rxm-39cm-27mj

Due to a new NDP proxy feature for EVPN leaf nodes introduced in Junos OS 17.4, crafted NDPv6 packets could transit a Junos device configured as a Broadband Network Gateway (BNG) and reach the EVPN leaf node, causing a stale MAC address entry. This could cause legitimate traffic to be discarded, leading to a Denial of Service (DoS) condition. This issue only affects Junos OS 17.4 and later releases. Prior releases do not support this feature and are unaffected by this vulnerability. This issue only affects IPv6. IPv4 ARP proxy is unaffected by this vulnerability. This issue affects Juniper Networks Junos OS: 17.4 versions prior to 17.4R2-S9, 17.4R3 on MX Series; 18.1 versions prior to 18.1R3-S9 on MX Series; 18.2 versions prior to 18.2R2-S7, 18.2R3-S3 on MX Series; 18.2X75 versions prior to 18.2X75-D33, 18.2X75-D411, 18.2X75-D420, 18.2X75-D60 on MX Series; 18.3 versions prior to 18.3R1-S7, 18.3R2-S3, 18.3R3 on MX Series; 18.4 versions prior to 18.4R1-S5, 18.4R2-S2, 18.4R3 on MX Seri...

1%
Низкий
около 4 лет назад
github логотип
GHSA-2rxj-vwp2-v63v

Integer underflow in grub_net_recv_ip4_packets; A malicious crafted IP packet can lead to an integer underflow in grub_net_recv_ip4_packets() function on rsm->total_len value. Under certain circumstances the total_len value may end up wrapping around to a small integer number which will be used in memory allocation. If the attack succeeds in such way, subsequent operations can write past the end of the buffer.

CVSS3: 8.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-2rxj-7r53-f46w

IceWarp Email Server 12.3.0.1 has Incorrect Access Control for user accounts.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2rxj-58vc-g6vw

Buffer overflow in listmanager earlier than 2.105.1 allows local users to gain additional privileges.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-2rxh-h6h9-qrqc

Class destructors causing side-effects when being unserialized in TYPO3 CMS

CVSS3: 8.7
1%
Низкий
около 6 лет назад
github логотип
GHSA-2rxh-g7fp-j3f7

WinAce allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-2rxh-4vr2-w87x

In the Linux kernel, the following vulnerability has been resolved: ASoC: da7219: Fix an error handling path in da7219_register_dai_clks() If clk_hw_register() fails, the corresponding clk should not be unregistered. To handle errors from loops, clean up partial iterations before doing the goto. So add a clk_hw_unregister(). Then use a while (--i >= 0) loop in the unwind section.

0%
Низкий
8 месяцев назад
github логотип
GHSA-2rxg-f4r2-fm3c

Sensitive passwords used in deployment and configuration of oVirt Metrics, all versions. were found to be insufficiently protected. Passwords could be disclosed in log files (if playbooks are run with -v) or in playbooks stored on Metrics or Bastion hosts.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-2rxc-gjrp-vjhx

Unsoundness in anstream

больше 1 года назад
github логотип
GHSA-2rxc-97gh-gwr2

pycdc commit 44a730f3a889503014fec94ae6e62d8401cb75e5 was discovered to contain a stack overflow via the component __sanitizer::StackDepotBase<__sanitizer::StackDepotNode.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-2rxc-8f9w-fjq8

Window may read from uninitialized memory locations in rdiff

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2rxc-55rq-5r4c

Directory traversal vulnerability in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8, when using "flat" addons, allows remote attackers to read arbitrary Javascript, image, and stylesheet files via the chrome: URI scheme, as demonstrated by stealing session information from sessionstore.js.

9%
Низкий
больше 4 лет назад
github логотип
GHSA-2rx9-c484-mx43

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in stmcan NaturaLife Extensions naturalife-extensions allows Reflected XSS.This issue affects NaturaLife Extensions: from n/a through <= 2.1.

CVSS3: 7.1
0%
Низкий
5 месяцев назад
github логотип
GHSA-2rx9-6m9m-h79v

Insufficient session authentication in web server for Intel(R) Data Center Manager SDK before version 5.0.2 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

CVSS3: 8.8
1%
Низкий
около 4 лет назад

Уязвимостей на страницу