Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 354 225

Количество 354 225

github логотип

GHSA-2q3w-j9mq-c9c9

больше 4 лет назад

Buffer overflow in Microsoft Windows Media Player 9 and 11.0.5721.5145 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted .mpg file.

EPSS: Низкий
github логотип

GHSA-2q3w-h8mm-q9v3

больше 4 лет назад

shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-2q3v-wwm5-c8hw

22 дня назад

Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2q3v-8m45-45jg

почти 2 года назад

The Chatbot with ChatGPT WordPress plugin before 2.4.6 does not have proper authorization in one of its REST endpoint, allowing unauthenticated users to retrieve the encoded key and then decode it, thereby leaking the OpenAI API key

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2q3v-57hj-r275

около 4 лет назад

Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user to access protected dashboard data via improper access control in the user interface.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-2q3r-vrpv-mqjv

около 4 лет назад

Adobe Media Encoder version 15.2 (and earlier) is affected by a memory corruption vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2q3r-gf9c-fhv3

больше 4 лет назад

The tqsl_verifyDataBlock function in openssl_cert.cpp in American Radio Relay League (ARRL) tqsllib 2.0 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.

EPSS: Низкий
github логотип

GHSA-2q3r-568x-rqmv

около 4 лет назад

A cryptographic issue in Nextcloud Server 19.0.1 allowed an attacker to downgrade the encryption scheme and break the integrity of encrypted files.

CVSS3: 4.1
EPSS: Низкий
github логотип

GHSA-2q3r-44vj-r6qr

11 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Russell Jamieson AuthorSure allows Stored XSS. This issue affects AuthorSure: from n/a through 2.3.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2q3q-wgvc-2m5p

около 3 лет назад

In registerReceiverWithFeature of ActivityManagerService.java, there is a possible way for isolated processes to register a broadcast receiver due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-263358101

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2q3q-5qjv-rrf3

почти 4 года назад

SEMCMS SHOP v 1.1 is vulnerable to Cross Site Scripting (XSS) via Ant_M_Coup.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2q3p-j7r5-v28g

около 4 лет назад

User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of the Yandex Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects the Yandex Browser version 20.8.3 and prior versions, and was fixed in version 20.8.4 released October 1, 2020.

EPSS: Низкий
github логотип

GHSA-2q3p-f6j6-9qhj

9 месяцев назад

Use-after-free in the WebRTC: Audio/Video component. This vulnerability affects Firefox < 145 and Firefox ESR < 140.5.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2q3p-cfj5-9f8c

больше 3 лет назад

A vulnerability, which was classified as problematic, has been found in WBCE CMS. Affected by this issue is the function increase_attempts of the file wbce/framework/class.login.php of the component Header Handler. The manipulation of the argument X-Forwarded-For leads to improper restriction of excessive authentication attempts. The attack may be launched remotely. The name of the patch is d394ba39a7bfeb31eda797b6195fd90ef74b2e75. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-213716.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2q3j-wj77-9934

6 месяцев назад

A Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to upload unauthorized content to another user’s repository migration export due to a missing authorization check in the repository migration upload endpoint. By supplying the migration identifier, an attacker could overwrite or replace a victim’s migration archive, potentially causing victims to download attacker-controlled repository data during migration restores or automated imports. An attacker would require authentication to the victim's GitHub Enterprise Server instance. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.20 and was fixed in versions 3.19.2, 3.18.5, 3.17.11, 3.16.14, 3.15.18, 3.14.23. This vulnerability was reported via the GitHub Bug Bounty program.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2q3j-j52p-fq9p

около 4 лет назад

Unspecified vulnerability in Oracle Solaris 10 and OpenSolaris allows local users to affect availability via unknown vectors related to InfiniBand.

EPSS: Низкий
github логотип

GHSA-2q3j-fpjf-8xrm

почти 2 года назад

Wuhan Tianyu Information Industry Co., Ltd Tianyu CPE Router CommonCPExCPETS_v3.2.468.11.04_P4 was discovered to contain a command injection vulnerability via the component at_command.asp.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2q3j-722m-fm66

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rccoder wp_amaps allows Stored XSS.This issue affects wp_amaps: from n/a through 1.7.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2q3h-pxc2-8gqg

больше 1 года назад

A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6.4.13 and 6.2.0 through 6.2.7 and 6.0.0 through 6.0.7 allows attacker to execute unauthorized code or commands via crafted requests.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2q3h-8fv3-88f4

около 4 лет назад

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the getLinks method. By performing actions in JavaScript, an attacker can trigger a type confusion condition. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-6017.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2q3w-j9mq-c9c9

Buffer overflow in Microsoft Windows Media Player 9 and 11.0.5721.5145 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted .mpg file.

9%
Низкий
больше 4 лет назад
github логотип
GHSA-2q3w-h8mm-q9v3

shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees

CVSS3: 4.7
0%
Низкий
больше 4 лет назад
github логотип
GHSA-2q3v-wwm5-c8hw

Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.

CVSS3: 5.5
0%
Низкий
22 дня назад
github логотип
GHSA-2q3v-8m45-45jg

The Chatbot with ChatGPT WordPress plugin before 2.4.6 does not have proper authorization in one of its REST endpoint, allowing unauthenticated users to retrieve the encoded key and then decode it, thereby leaking the OpenAI API key

CVSS3: 5.3
1%
Низкий
почти 2 года назад
github логотип
GHSA-2q3v-57hj-r275

Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user to access protected dashboard data via improper access control in the user interface.

CVSS3: 5.7
0%
Низкий
около 4 лет назад
github логотип
GHSA-2q3r-vrpv-mqjv

Adobe Media Encoder version 15.2 (and earlier) is affected by a memory corruption vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-2q3r-gf9c-fhv3

The tqsl_verifyDataBlock function in openssl_cert.cpp in American Radio Relay League (ARRL) tqsllib 2.0 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2q3r-568x-rqmv

A cryptographic issue in Nextcloud Server 19.0.1 allowed an attacker to downgrade the encryption scheme and break the integrity of encrypted files.

CVSS3: 4.1
0%
Низкий
около 4 лет назад
github логотип
GHSA-2q3r-44vj-r6qr

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Russell Jamieson AuthorSure allows Stored XSS. This issue affects AuthorSure: from n/a through 2.3.

CVSS3: 5.9
0%
Низкий
11 месяцев назад
github логотип
GHSA-2q3q-wgvc-2m5p

In registerReceiverWithFeature of ActivityManagerService.java, there is a possible way for isolated processes to register a broadcast receiver due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-263358101

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-2q3q-5qjv-rrf3

SEMCMS SHOP v 1.1 is vulnerable to Cross Site Scripting (XSS) via Ant_M_Coup.php.

CVSS3: 6.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-2q3p-j7r5-v28g

User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of the Yandex Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects the Yandex Browser version 20.8.3 and prior versions, and was fixed in version 20.8.4 released October 1, 2020.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2q3p-f6j6-9qhj

Use-after-free in the WebRTC: Audio/Video component. This vulnerability affects Firefox < 145 and Firefox ESR < 140.5.

CVSS3: 8.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-2q3p-cfj5-9f8c

A vulnerability, which was classified as problematic, has been found in WBCE CMS. Affected by this issue is the function increase_attempts of the file wbce/framework/class.login.php of the component Header Handler. The manipulation of the argument X-Forwarded-For leads to improper restriction of excessive authentication attempts. The attack may be launched remotely. The name of the patch is d394ba39a7bfeb31eda797b6195fd90ef74b2e75. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-213716.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2q3j-wj77-9934

A Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to upload unauthorized content to another user’s repository migration export due to a missing authorization check in the repository migration upload endpoint. By supplying the migration identifier, an attacker could overwrite or replace a victim’s migration archive, potentially causing victims to download attacker-controlled repository data during migration restores or automated imports. An attacker would require authentication to the victim's GitHub Enterprise Server instance. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.20 and was fixed in versions 3.19.2, 3.18.5, 3.17.11, 3.16.14, 3.15.18, 3.14.23. This vulnerability was reported via the GitHub Bug Bounty program.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-2q3j-j52p-fq9p

Unspecified vulnerability in Oracle Solaris 10 and OpenSolaris allows local users to affect availability via unknown vectors related to InfiniBand.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2q3j-fpjf-8xrm

Wuhan Tianyu Information Industry Co., Ltd Tianyu CPE Router CommonCPExCPETS_v3.2.468.11.04_P4 was discovered to contain a command injection vulnerability via the component at_command.asp.

CVSS3: 8.8
2%
Низкий
почти 2 года назад
github логотип
GHSA-2q3j-722m-fm66

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rccoder wp_amaps allows Stored XSS.This issue affects wp_amaps: from n/a through 1.7.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2q3h-pxc2-8gqg

A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6.4.13 and 6.2.0 through 6.2.7 and 6.0.0 through 6.0.7 allows attacker to execute unauthorized code or commands via crafted requests.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-2q3h-8fv3-88f4

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the getLinks method. By performing actions in JavaScript, an attacker can trigger a type confusion condition. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-6017.

CVSS3: 8.8
3%
Низкий
около 4 лет назад

Уязвимостей на страницу