Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-3rhc-pc7v-fhr7

больше 4 лет назад

Juniper Junos 11.4 before 11.4R12, 12.1X44 before 12.1X44-D32, 12.1X45 before 12.1X45-D25, 12.1X46 before 12.1X46-D20, and 12.1X47 before 12.1X47-D10 on SRX Series devices, when NAT protocol translation from IPv4 to IPv6 is enabled, allows remote attackers to cause a denial of service (flowd hang or crash) via a crafted packet.

EPSS: Низкий
github логотип

GHSA-3rhc-hj98-5mpj

больше 1 года назад

Improper access control in Tor network blocking feature in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the tor blocking feature when the Devolutions hosted endpoint is not reachable.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-3rhc-g969-jjxw

12 месяцев назад

A weakness has been identified in Campcodes Online Learning Management System 1.0. This vulnerability affects unknown code of the file /admin/admin_user.php. Executing manipulation of the argument firstname can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could be exploited.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3rhc-44qf-c226

больше 3 лет назад

A vulnerability has been discovered in Rocket.Chat, where editing messages can change the original timestamp, causing the UI to display messages in an incorrect order.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3rh8-vm3g-5r4x

больше 4 лет назад

TechSmith Snagit 19.1.0.2653 uses Object Linking and Embedding (OLE) which can allow attackers to obfuscate and embed crafted files used to escalate privileges.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3rh8-jx6v-pf36

больше 3 лет назад

Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3rh8-f4gv-8c37

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in vud_term.module in the Vote Up/Down module 6.x-2.x before 6.x-2.8 and 6.x-3.x before 6.x-3.1 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via taxonomy terms.

EPSS: Низкий
github логотип

GHSA-3rh7-vm4x-q2hp

почти 8 лет назад

sqlserver is malware

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3rh7-cg3h-rr3p

3 месяца назад

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3rh7-494q-3mjq

больше 4 лет назад

A use-after-free flaw has been discovered in libcomps before version 0.1.10 in the way ObjMRTrees are merged. An attacker, who is able to make an application read a crafted comps XML file, may be able to crash the application or execute malicious code.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3rh6-vqr9-vpx5

больше 4 лет назад

Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (memory consumption) via a large crontab file because an unlimited number of lines is accepted.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3rh6-mpmf-236w

около 3 лет назад

iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at admincp.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3rh6-4p5j-qqfp

больше 4 лет назад

An issue was discovered in Emote Remote Mouse through 4.0.0.0. Attackers can retrieve recently used and running applications, their icons, and their file paths. This information is sent in cleartext and is not protected by any authentication logic.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3rh5-9p47-7947

больше 4 лет назад

The Device Model in ACRN before 2019w25.5-140000p relies on assert calls in devicemodel/hw/pci/core.c and devicemodel/include/pci_core.h (instead of other mechanisms for propagating error information or diagnostic information), which might allow attackers to cause a denial of service (assertion failure) within pci core.

EPSS: Низкий
github логотип

GHSA-3rh4-hgwg-p5c2

около 4 лет назад

Windows Connected Devices Platform Service Information Disclosure Vulnerability.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-3rh4-gr64-mv89

4 дня назад

Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Demand Signal Repository accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Demand Signal Repository. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3rh4-fv5f-h684

17 дней назад

Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3rh3-x38g-8fjx

больше 4 лет назад

Unspecified vulnerability in the Workspace Manager component in Oracle Database 10.2.0.4 and 11.1.0.6 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2009-0975.

EPSS: Средний
github логотип

GHSA-3rh3-wfr4-76mj

больше 5 лет назад

Regular expression Denial of Service in multiple packages

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3rh3-mwf4-58r4

больше 4 лет назад

In Pulse Secure Pulse Connect Secure (PCS) before 8.1R15.1, 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an authenticated attacker (via the admin web interface) can exploit Directory Traversal to execute arbitrary code on the appliance.

CVSS3: 7.2
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3rhc-pc7v-fhr7

Juniper Junos 11.4 before 11.4R12, 12.1X44 before 12.1X44-D32, 12.1X45 before 12.1X45-D25, 12.1X46 before 12.1X46-D20, and 12.1X47 before 12.1X47-D10 on SRX Series devices, when NAT protocol translation from IPv4 to IPv6 is enabled, allows remote attackers to cause a denial of service (flowd hang or crash) via a crafted packet.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3rhc-hj98-5mpj

Improper access control in Tor network blocking feature in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the tor blocking feature when the Devolutions hosted endpoint is not reachable.

CVSS3: 5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3rhc-g969-jjxw

A weakness has been identified in Campcodes Online Learning Management System 1.0. This vulnerability affects unknown code of the file /admin/admin_user.php. Executing manipulation of the argument firstname can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could be exploited.

CVSS3: 7.3
0%
Низкий
12 месяцев назад
github логотип
GHSA-3rhc-44qf-c226

A vulnerability has been discovered in Rocket.Chat, where editing messages can change the original timestamp, causing the UI to display messages in an incorrect order.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3rh8-vm3g-5r4x

TechSmith Snagit 19.1.0.2653 uses Object Linking and Embedding (OLE) which can allow attackers to obfuscate and embed crafted files used to escalate privileges.

CVSS3: 8.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3rh8-jx6v-pf36

Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3rh8-f4gv-8c37

Cross-site scripting (XSS) vulnerability in vud_term.module in the Vote Up/Down module 6.x-2.x before 6.x-2.8 and 6.x-3.x before 6.x-3.1 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via taxonomy terms.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3rh7-vm4x-q2hp

sqlserver is malware

CVSS3: 7.5
1%
Низкий
почти 8 лет назад
github логотип
GHSA-3rh7-cg3h-rr3p

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
0%
Низкий
3 месяца назад
github логотип
GHSA-3rh7-494q-3mjq

A use-after-free flaw has been discovered in libcomps before version 0.1.10 in the way ObjMRTrees are merged. An attacker, who is able to make an application read a crafted comps XML file, may be able to crash the application or execute malicious code.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3rh6-vqr9-vpx5

Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (memory consumption) via a large crontab file because an unlimited number of lines is accepted.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3rh6-mpmf-236w

iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at admincp.php.

CVSS3: 9.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-3rh6-4p5j-qqfp

An issue was discovered in Emote Remote Mouse through 4.0.0.0. Attackers can retrieve recently used and running applications, their icons, and their file paths. This information is sent in cleartext and is not protected by any authentication logic.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3rh5-9p47-7947

The Device Model in ACRN before 2019w25.5-140000p relies on assert calls in devicemodel/hw/pci/core.c and devicemodel/include/pci_core.h (instead of other mechanisms for propagating error information or diagnostic information), which might allow attackers to cause a denial of service (assertion failure) within pci core.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3rh4-hgwg-p5c2

Windows Connected Devices Platform Service Information Disclosure Vulnerability.

CVSS3: 4.7
0%
Низкий
около 4 лет назад
github логотип
GHSA-3rh4-gr64-mv89

Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Demand Signal Repository accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Demand Signal Repository. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).

CVSS3: 8.1
0%
Низкий
4 дня назад
github логотип
GHSA-3rh4-fv5f-h684

Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*.

CVSS3: 5.9
0%
Низкий
17 дней назад
github логотип
GHSA-3rh3-x38g-8fjx

Unspecified vulnerability in the Workspace Manager component in Oracle Database 10.2.0.4 and 11.1.0.6 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2009-0975.

17%
Средний
больше 4 лет назад
github логотип
GHSA-3rh3-wfr4-76mj

Regular expression Denial of Service in multiple packages

CVSS3: 6.5
2%
Низкий
больше 5 лет назад
github логотип
GHSA-3rh3-mwf4-58r4

In Pulse Secure Pulse Connect Secure (PCS) before 8.1R15.1, 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an authenticated attacker (via the admin web interface) can exploit Directory Traversal to execute arbitrary code on the appliance.

CVSS3: 7.2
15%
Средний
больше 4 лет назад

Уязвимостей на страницу