Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-3v83-p792-64c4

больше 4 лет назад

Apple Remote Desktop before 3.7 does not properly use server authentication-type information during decisions about whether to present an unencrypted-connection warning message, which allows remote attackers to obtain sensitive information in opportunistic circumstances by sniffing the network during an unintended cleartext VNC session.

EPSS: Низкий
github логотип

GHSA-3v83-f4h7-w2mj

около 4 лет назад

Improper restriction of broadcasting Intent in ConfirmConnectActivity of?NFC prior to SMR Aug-2022 Release 1 leaks MAC address of the connected Bluetooth device.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-3v83-crv9-cf9p

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: gtp: fix use-after-free and null-ptr-deref in gtp_newlink() The gtp_link_ops operations structure for the subsystem must be registered after registering the gtp_net_ops pernet operations structure. Syzkaller hit 'general protection fault in gtp_genl_dump_pdp' bug: [ 1010.702740] gtp: GTP module unloaded [ 1010.715877] general protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] SMP KASAN NOPTI [ 1010.715888] KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f] [ 1010.715895] CPU: 1 PID: 128616 Comm: a.out Not tainted 6.8.0-rc6-std-def-alt1 #1 [ 1010.715899] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.0-alt1 04/01/2014 [ 1010.715908] RIP: 0010:gtp_newlink+0x4d7/0x9c0 [gtp] [ 1010.715915] Code: 80 3c 02 00 0f 85 41 04 00 00 48 8b bb d8 05 00 00 e8 ed f6 ff ff 48 89 c2 48 89 c5 48 b8 00 00 00 00 00 fc ff df 48 c1 ea 03 <80> 3c 02 00 0f 85 4f 04 00 00...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3v82-hq57-c7xh

больше 4 лет назад

Invision Community (aka IPS Community Suite) before 4.6.0 allows eval-based PHP code injection by a moderator because the IPS\cms\modules\front\pages\_builder::previewBlock method interacts unsafely with the IPS\_Theme::runProcessFunction method.

EPSS: Средний
github логотип

GHSA-3v82-5w89-j5ww

больше 4 лет назад

An exploitable vulnerability exists in the smart cameras RTSP configuration of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The device incorrectly handles spaces in the URL field, leading to an arbitrary operating system command injection. An attacker can send a series of HTTP requests to trigger this vulnerability.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-3v7w-vw6x-qr3j

больше 1 года назад

A vulnerability was found in Yonyou UFIDA ERP-NC 5.0. It has been classified as problematic. Affected is an unknown function of the file /help/systop.jsp. The manipulation of the argument langcode leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3v7v-w4cq-gmpp

почти 2 года назад

Missing Authorization vulnerability in Survey Maker team Survey Maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Survey Maker: from n/a through 3.2.0.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3v7v-j7vf-jhpq

10 месяцев назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-3v7v-cgjc-xh4g

6 месяцев назад

PCHelpWareV2 1.0.0.5 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Group field. Attackers can paste a buffer overflow payload into the Group property field and click Ok to trigger an application crash.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3v7v-46v6-pjjr

почти 4 года назад

This issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. An app may be able to access user-sensitive data.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3v7r-r3pj-33fx

больше 4 лет назад

A vulnerability in Siemens SICAM PAS (all versions before V8.09) could allow a remote attacker to upload, download, or delete files in certain parts of the file system by sending specially crafted packets to port 19235/TCP.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3v7r-5qj8-2v68

больше 4 лет назад

redhat-certification does not properly sanitize paths in rhcertStore.py:__saveResultsFile. A remote attacker could use this flaw to overwrite any file, potentially gaining remote code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3v7q-6w55-588c

больше 4 лет назад

lisp/gnus/gnus-fun.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on the /tmp/gnus.face.ppm temporary file.

EPSS: Низкий
github логотип

GHSA-3v7p-mx8w-xf2h

почти 3 года назад

Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'id' parameter of the partner_preference.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3v7p-hjjf-gqp8

около 1 месяца назад

UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the user substitution logic within parse_artifact.sh where usernames and home directories from /etc/passwd are substituted directly into command strings without escaping before execution via eval. Attackers can inject shell metacharacters such as command substitution syntax or semicolons through crafted usernames or home directory paths in /etc/passwd entries to execute arbitrary commands on the analyst's host system.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3v7p-2jr8-qj72

11 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: x86/speculation: Fill RSB on vmexit for IBRS Prevent RSB underflow/poisoning attacks with RSB. While at it, add a bunch of comments to attempt to document the current state of tribal knowledge about RSB attacks and what exactly is being mitigated.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3v7m-rv2r-mcp9

почти 4 года назад

A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to cause a Denial of Service by Rebooting the router through " /mgm_dev_reboot.asp."

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3v7m-qg4x-58h9

6 месяцев назад

AVideo: Unauthenticated Access to Payment Order Data via BlockonomicsYPT check.php

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-3v7m-2jrh-vc93

больше 3 лет назад

Froxlor vulnerable to Argument Injection

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3v7g-82fr-x624

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in KnowledgeTree Open Source 3.4 and 3.4.1 allows remote attackers to inject arbitrary web script or HTML via the login field on the login page, and other unspecified vectors.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3v83-p792-64c4

Apple Remote Desktop before 3.7 does not properly use server authentication-type information during decisions about whether to present an unencrypted-connection warning message, which allows remote attackers to obtain sensitive information in opportunistic circumstances by sniffing the network during an unintended cleartext VNC session.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3v83-f4h7-w2mj

Improper restriction of broadcasting Intent in ConfirmConnectActivity of?NFC prior to SMR Aug-2022 Release 1 leaks MAC address of the connected Bluetooth device.

CVSS3: 3.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-3v83-crv9-cf9p

In the Linux kernel, the following vulnerability has been resolved: gtp: fix use-after-free and null-ptr-deref in gtp_newlink() The gtp_link_ops operations structure for the subsystem must be registered after registering the gtp_net_ops pernet operations structure. Syzkaller hit 'general protection fault in gtp_genl_dump_pdp' bug: [ 1010.702740] gtp: GTP module unloaded [ 1010.715877] general protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] SMP KASAN NOPTI [ 1010.715888] KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f] [ 1010.715895] CPU: 1 PID: 128616 Comm: a.out Not tainted 6.8.0-rc6-std-def-alt1 #1 [ 1010.715899] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.0-alt1 04/01/2014 [ 1010.715908] RIP: 0010:gtp_newlink+0x4d7/0x9c0 [gtp] [ 1010.715915] Code: 80 3c 02 00 0f 85 41 04 00 00 48 8b bb d8 05 00 00 e8 ed f6 ff ff 48 89 c2 48 89 c5 48 b8 00 00 00 00 00 fc ff df 48 c1 ea 03 <80> 3c 02 00 0f 85 4f 04 00 00...

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3v82-hq57-c7xh

Invision Community (aka IPS Community Suite) before 4.6.0 allows eval-based PHP code injection by a moderator because the IPS\cms\modules\front\pages\_builder::previewBlock method interacts unsafely with the IPS\_Theme::runProcessFunction method.

20%
Средний
больше 4 лет назад
github логотип
GHSA-3v82-5w89-j5ww

An exploitable vulnerability exists in the smart cameras RTSP configuration of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The device incorrectly handles spaces in the URL field, leading to an arbitrary operating system command injection. An attacker can send a series of HTTP requests to trigger this vulnerability.

CVSS3: 9.9
3%
Низкий
больше 4 лет назад
github логотип
GHSA-3v7w-vw6x-qr3j

A vulnerability was found in Yonyou UFIDA ERP-NC 5.0. It has been classified as problematic. Affected is an unknown function of the file /help/systop.jsp. The manipulation of the argument langcode leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-3v7v-w4cq-gmpp

Missing Authorization vulnerability in Survey Maker team Survey Maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Survey Maker: from n/a through 3.2.0.

CVSS3: 5.3
1%
Низкий
почти 2 года назад
github логотип
GHSA-3v7v-j7vf-jhpq

Rejected reason: Not used

10 месяцев назад
github логотип
GHSA-3v7v-cgjc-xh4g

PCHelpWareV2 1.0.0.5 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Group field. Attackers can paste a buffer overflow payload into the Group property field and click Ok to trigger an application crash.

CVSS3: 5.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-3v7v-46v6-pjjr

This issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. An app may be able to access user-sensitive data.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-3v7r-r3pj-33fx

A vulnerability in Siemens SICAM PAS (all versions before V8.09) could allow a remote attacker to upload, download, or delete files in certain parts of the file system by sending specially crafted packets to port 19235/TCP.

CVSS3: 7.3
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3v7r-5qj8-2v68

redhat-certification does not properly sanitize paths in rhcertStore.py:__saveResultsFile. A remote attacker could use this flaw to overwrite any file, potentially gaining remote code execution.

CVSS3: 9.8
6%
Низкий
больше 4 лет назад
github логотип
GHSA-3v7q-6w55-588c

lisp/gnus/gnus-fun.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on the /tmp/gnus.face.ppm temporary file.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3v7p-mx8w-xf2h

Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'id' parameter of the partner_preference.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-3v7p-hjjf-gqp8

UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the user substitution logic within parse_artifact.sh where usernames and home directories from /etc/passwd are substituted directly into command strings without escaping before execution via eval. Attackers can inject shell metacharacters such as command substitution syntax or semicolons through crafted usernames or home directory paths in /etc/passwd entries to execute arbitrary commands on the analyst's host system.

CVSS3: 7.8
1%
Низкий
около 1 месяца назад
github логотип
GHSA-3v7p-2jr8-qj72

In the Linux kernel, the following vulnerability has been resolved: x86/speculation: Fill RSB on vmexit for IBRS Prevent RSB underflow/poisoning attacks with RSB. While at it, add a bunch of comments to attempt to document the current state of tribal knowledge about RSB attacks and what exactly is being mitigated.

CVSS3: 5.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-3v7m-rv2r-mcp9

A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to cause a Denial of Service by Rebooting the router through " /mgm_dev_reboot.asp."

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-3v7m-qg4x-58h9

AVideo: Unauthenticated Access to Payment Order Data via BlockonomicsYPT check.php

CVSS3: 3.7
0%
Низкий
6 месяцев назад
github логотип
GHSA-3v7m-2jrh-vc93

Froxlor vulnerable to Argument Injection

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3v7g-82fr-x624

Cross-site scripting (XSS) vulnerability in KnowledgeTree Open Source 3.4 and 3.4.1 allows remote attackers to inject arbitrary web script or HTML via the login field on the login page, and other unspecified vectors.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу