Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 354 924

Количество 354 924

github логотип

GHSA-2rcp-jj9q-pcqp

около 4 лет назад

Unspecified vulnerability in the ATRC codec in RealNetworks RealPlayer before 15.0.0 and Mac RealPlayer before 12.0.0.1703 allows remote attackers to execute arbitrary code via unknown vectors.

EPSS: Низкий
github логотип

GHSA-2rcm-phc9-3945

почти 8 лет назад

Pyopenssl Incorrect Memory Management

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2rcm-mm94-fj4v

больше 4 лет назад

Null pointer dereference vulnerability in parser_infe function of libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds read by remote attackers.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-2rcm-fq84-jjch

больше 1 года назад

Telesquare TLR-2005KSH 1.1.4 is affected by an unauthorized command execution vulnerability when requesting the admin.cgi parameter with setAutorest.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2rcm-9pw5-qh2h

больше 2 лет назад

Inductive Automation Ignition OPC UA Quick Client Permissive Cross-domain Policy Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the configuration of the web server. The issue results from the lack of appropriate Content Security Policy headers. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of SYSTEM. Was ZDI-CAN-20539.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2rcm-7f2m-m5qc

больше 4 лет назад

ifdhcpc-done script for configuring DHCP on Red Hat Linux 5 allows local users to append text to arbitrary files via a symlink attack on the dhcplog file.

EPSS: Низкий
github логотип

GHSA-2rcj-xx33-m8j8

больше 4 лет назад

The SOAP interface to the eMBox module in Novell eDirectory 8.7.3.9 and earlier, and 8.8.x before 8.8.2, relies on client-side authentication, which allows remote attackers to bypass authentication via requests for /SOAP URIs, and cause a denial of service (daemon shutdown) or read arbitrary files. NOTE: it was later reported that 8.7.3.10 (aka 8.7.3 SP10) is also affected.

EPSS: Средний
github логотип

GHSA-2rcj-xpff-488p

больше 4 лет назад

Cross-site scripting vulnerability in TransWARE Active! mail 1.422 and 2.0 allows remote attackers to execute arbitrary code via a certain e-mail header, which is not properly filtered.

EPSS: Низкий
github логотип

GHSA-2rcj-jvwv-8rhr

больше 3 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in RegistrationMagic plugin <= 5.1.9.2 versions.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2rcj-9v96-9vwg

около 4 лет назад

Yamaha RTX, RT, SRT, RTV, RTW, and RTA series routers with firmware 6.x through 10.x, and NEC IP38X series routers with firmware 6.x through 10.x, do not properly handle IP header options, which allows remote attackers to cause a denial of service (device reboot) via a crafted option that triggers access to an invalid memory location.

EPSS: Низкий
github логотип

GHSA-2rcj-3wpj-27f2

больше 2 лет назад

The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to an attacker being able to control the values passed to an include, and subsequently leverage that to achieve remote code execution. This makes it possible for unauthenticated attackers to easily execute code on the server.

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-2rcg-mm5h-xchx

около 2 месяцев назад

PraisonAI: Arbitrary File Read via `@file:` Mention Path Traversal

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2rcg-mhmv-j368

около 4 лет назад

nps/servlet/webacc in iManager in the Administration Console server in NetIQ Access Manager (NAM) 4.x before 4.0.1 HF3 allows remote authenticated novlwww users to read arbitrary files via a query parameter containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

EPSS: Низкий
github логотип

GHSA-2rcg-6729-3c5c

больше 4 лет назад

Unspecified vulnerability in usermod in HP-UX B.11.00, B.11.11, and B.11.23, when run with certain options that involve a new home directory, might cause usermod to change the ownership of all directories and files under the new directory, which might result in less secure permissions than intended.

EPSS: Низкий
github логотип

GHSA-2rcf-hgr2-55mc

около 4 лет назад

The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services via CSRF can result in an unauthorized change of username or password of the administrator of the portal.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2rcf-f7rp-mvx7

около 4 лет назад

OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly verify whether a request made to the application was intentionally made by the user, allowing for cross-site request forgery attacks on all user functions.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2rcf-99h2-99hm

6 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: slimbus: core: fix device reference leak on report present Slimbus devices can be allocated dynamically upon reception of report-present messages. Make sure to drop the reference taken when looking up already registered devices. Note that this requires taking an extra reference in case the device has not yet been registered and has to be allocated.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2rcf-2963-c47m

больше 3 лет назад

Insufficient policy enforcement in Resource Timing in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to obtain potentially sensitive information from API via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2rcc-vrwm-m429

больше 4 лет назад

The default configuration in MySQL 3.20.32 through 3.23.52, when running on Windows, does not have logging enabled, which could allow remote attackers to conduct activities without detection.

EPSS: Низкий
github логотип

GHSA-2rcc-q9cg-9v38

больше 3 лет назад

Improper Authorization of Index Containing Sensitive Information in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2rcp-jj9q-pcqp

Unspecified vulnerability in the ATRC codec in RealNetworks RealPlayer before 15.0.0 and Mac RealPlayer before 12.0.0.1703 allows remote attackers to execute arbitrary code via unknown vectors.

4%
Низкий
около 4 лет назад
github логотип
GHSA-2rcm-phc9-3945

Pyopenssl Incorrect Memory Management

CVSS3: 5.9
2%
Низкий
почти 8 лет назад
github логотип
GHSA-2rcm-mm94-fj4v

Null pointer dereference vulnerability in parser_infe function of libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds read by remote attackers.

CVSS3: 9.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2rcm-fq84-jjch

Telesquare TLR-2005KSH 1.1.4 is affected by an unauthorized command execution vulnerability when requesting the admin.cgi parameter with setAutorest.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-2rcm-9pw5-qh2h

Inductive Automation Ignition OPC UA Quick Client Permissive Cross-domain Policy Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the configuration of the web server. The issue results from the lack of appropriate Content Security Policy headers. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of SYSTEM. Was ZDI-CAN-20539.

CVSS3: 7.2
2%
Низкий
больше 2 лет назад
github логотип
GHSA-2rcm-7f2m-m5qc

ifdhcpc-done script for configuring DHCP on Red Hat Linux 5 allows local users to append text to arbitrary files via a symlink attack on the dhcplog file.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-2rcj-xx33-m8j8

The SOAP interface to the eMBox module in Novell eDirectory 8.7.3.9 and earlier, and 8.8.x before 8.8.2, relies on client-side authentication, which allows remote attackers to bypass authentication via requests for /SOAP URIs, and cause a denial of service (daemon shutdown) or read arbitrary files. NOTE: it was later reported that 8.7.3.10 (aka 8.7.3 SP10) is also affected.

58%
Средний
больше 4 лет назад
github логотип
GHSA-2rcj-xpff-488p

Cross-site scripting vulnerability in TransWARE Active! mail 1.422 and 2.0 allows remote attackers to execute arbitrary code via a certain e-mail header, which is not properly filtered.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-2rcj-jvwv-8rhr

Cross-Site Request Forgery (CSRF) vulnerability in RegistrationMagic plugin <= 5.1.9.2 versions.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rcj-9v96-9vwg

Yamaha RTX, RT, SRT, RTV, RTW, and RTA series routers with firmware 6.x through 10.x, and NEC IP38X series routers with firmware 6.x through 10.x, do not properly handle IP header options, which allows remote attackers to cause a denial of service (device reboot) via a crafted option that triggers access to an invalid memory location.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2rcj-3wpj-27f2

The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to an attacker being able to control the values passed to an include, and subsequently leverage that to achieve remote code execution. This makes it possible for unauthenticated attackers to easily execute code on the server.

CVSS3: 9.8
98%
Критический
больше 2 лет назад
github логотип
GHSA-2rcg-mm5h-xchx

PraisonAI: Arbitrary File Read via `@file:` Mention Path Traversal

CVSS3: 7.5
около 2 месяцев назад
github логотип
GHSA-2rcg-mhmv-j368

nps/servlet/webacc in iManager in the Administration Console server in NetIQ Access Manager (NAM) 4.x before 4.0.1 HF3 allows remote authenticated novlwww users to read arbitrary files via a query parameter containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2rcg-6729-3c5c

Unspecified vulnerability in usermod in HP-UX B.11.00, B.11.11, and B.11.23, when run with certain options that involve a new home directory, might cause usermod to change the ownership of all directories and files under the new directory, which might result in less secure permissions than intended.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-2rcf-hgr2-55mc

The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services via CSRF can result in an unauthorized change of username or password of the administrator of the portal.

CVSS3: 8.8
7%
Низкий
около 4 лет назад
github логотип
GHSA-2rcf-f7rp-mvx7

OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly verify whether a request made to the application was intentionally made by the user, allowing for cross-site request forgery attacks on all user functions.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2rcf-99h2-99hm

In the Linux kernel, the following vulnerability has been resolved: slimbus: core: fix device reference leak on report present Slimbus devices can be allocated dynamically upon reception of report-present messages. Make sure to drop the reference taken when looking up already registered devices. Note that this requires taking an extra reference in case the device has not yet been registered and has to be allocated.

CVSS3: 5.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-2rcf-2963-c47m

Insufficient policy enforcement in Resource Timing in Google Chrome prior to 111.0.5563.64 allowed a remote attacker to obtain potentially sensitive information from API via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2rcc-vrwm-m429

The default configuration in MySQL 3.20.32 through 3.23.52, when running on Windows, does not have logging enabled, which could allow remote attackers to conduct activities without detection.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-2rcc-q9cg-9v38

Improper Authorization of Index Containing Sensitive Information in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу