Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 354 225

Количество 354 225

github логотип

GHSA-2pr3-qrhm-jm7j

около 4 лет назад

PoDoFo::Impose::PdfTranslator::setSource() in pdftranslator.cpp in PoDoFo 0.9.6 has a NULL pointer dereference that can (for example) be triggered by sending a crafted PDF file to the podofoimpose binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2pr3-956j-4qvg

около 4 лет назад

Software Integrity Attacks vulnerability in Intel Security Anti-Virus Engine (AVE) 5200 through 5800 allows local users to bypass local security protection via a crafted input file.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2pr3-6gwh-9gvq

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in PostNuke 0.71 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) name parameter in modules.php and (2) catid parameter in index.php.

EPSS: Низкий
github логотип

GHSA-2pr3-45mh-ph8r

около 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in PHPDug 2.0.0 allow remote attackers to inject arbitrary web script or HTML via (1) the story_url parameter to add_story.php, (2) the email parameter to editprofile.php, (3) the title parameter to adm/content_add.php, or (4) the username parameter to adm/admin_edit.php.

EPSS: Низкий
github логотип

GHSA-2pr2-hcv6-7gwv

4 месяца назад

OpenClaw's device removal and token revocation do not terminate active WebSocket sessions

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2pr2-cxfq-398w

около 4 лет назад

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "SQLite" component. A use-after-free vulnerability allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted SQL statement.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2pqx-426g-hrmc

около 4 лет назад

The (1) bin/invscoutClient_VPD_Survey and (2) sbin/invscout_lsvpd programs in invscout.rte before 2.2.0.19 on IBM AIX 7.1, 6.1, 5.3, and earlier allow local users to delete arbitrary files, or trigger inventory scout operations on arbitrary files, via a symlink attack on an unspecified file.

EPSS: Низкий
github логотип

GHSA-2pqv-gjx5-j94f

около 4 лет назад

A potential vulnerability has been identified in HP Remote Graphics Software’s certificate authentication process version 7.5.0 and earlier.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-2pqr-cp8m-m5vw

около 4 лет назад

An issue was discovered in the pam_p11 component 0.2.0 and 0.3.0 for OpenSC. If a smart card creates a signature with a length longer than 256 bytes, this triggers a buffer overflow. This may be the case for RSA keys with 4096 bits depending on the signature scheme.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2pqr-5864-6fgw

11 месяцев назад

In App Widget, there is a possible Information Disclosure due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2pqq-4jjp-fmr3

больше 1 года назад

The Subpage List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'subpages' shortcode in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2pqp-x768-f3m2

около 4 лет назад

An information disclosure vulnerability in upload.php of PopojiCMS 1.2 leads to physical path disclosure of the host when 'name = "file" is deleted during file uploads.

EPSS: Низкий
github логотип

GHSA-2pqp-qqmg-62w8

около 4 лет назад

NDrive(1.2.2).sys in Naver Cloud Explorer has a stack-based buffer overflow, which allows attackers to cause a denial of service when reading data from IOCTL handle.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2pqm-v28p-x679

около 4 лет назад

eramba c2.8.1 and Enterprise before e2.19.3 allows XSS via a crafted filename for a file attached to an object. For example, the filename has a complete XSS payload followed by the .png extension.

EPSS: Низкий
github логотип

GHSA-2pqm-qhp5-fh45

больше 2 лет назад

Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in the svc_topstats utility. An authenticated attacker could potentially exploit this vulnerability, leading to the ability to overwrite arbitrary files on the file system with root privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2pqm-q853-jfvf

около 4 лет назад

An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g., by using ANSI control codes to hide additional files being transferred. This affects refresh_progress_meter() in progressmeter.c.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-2pqj-vff5-fgh2

около 4 лет назад

Cross-site scripting (XSS) vulnerability in Sijio Community Software allows remote authenticated users to inject arbitrary web script or HTML via the title parameter when adding a new blog, related to edit_blog/index.php. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-2pqj-h3vj-pqgw

почти 6 лет назад

Cross-Site Scripting in jquery

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2pqg-9xqc-m3rw

больше 4 лет назад

D-LINK DWL-2000AP+ firmware 2.11 allows remote attackers to cause (1) a denial of service (device reset) via a flood of ARP replies on the wired or wireless (radio) link and (2) a denial of service (device crash) via a flood of ARP requests on the wireless link.

EPSS: Низкий
github логотип

GHSA-2pqf-pg56-pwcv

около 4 лет назад

The ZEROF Expert pro/2.0 application for mobile devices allows SQL Injection via the Authorization header to the /v2/devices/add endpoint.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2pr3-qrhm-jm7j

PoDoFo::Impose::PdfTranslator::setSource() in pdftranslator.cpp in PoDoFo 0.9.6 has a NULL pointer dereference that can (for example) be triggered by sending a crafted PDF file to the podofoimpose binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.

CVSS3: 8.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-2pr3-956j-4qvg

Software Integrity Attacks vulnerability in Intel Security Anti-Virus Engine (AVE) 5200 through 5800 allows local users to bypass local security protection via a crafted input file.

CVSS3: 7.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-2pr3-6gwh-9gvq

Cross-site scripting (XSS) vulnerability in PostNuke 0.71 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) name parameter in modules.php and (2) catid parameter in index.php.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2pr3-45mh-ph8r

Multiple cross-site scripting (XSS) vulnerabilities in PHPDug 2.0.0 allow remote attackers to inject arbitrary web script or HTML via (1) the story_url parameter to add_story.php, (2) the email parameter to editprofile.php, (3) the title parameter to adm/content_add.php, or (4) the username parameter to adm/admin_edit.php.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2pr2-hcv6-7gwv

OpenClaw's device removal and token revocation do not terminate active WebSocket sessions

CVSS3: 7.5
0%
Низкий
4 месяца назад
github логотип
GHSA-2pr2-cxfq-398w

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "SQLite" component. A use-after-free vulnerability allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted SQL statement.

CVSS3: 9.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-2pqx-426g-hrmc

The (1) bin/invscoutClient_VPD_Survey and (2) sbin/invscout_lsvpd programs in invscout.rte before 2.2.0.19 on IBM AIX 7.1, 6.1, 5.3, and earlier allow local users to delete arbitrary files, or trigger inventory scout operations on arbitrary files, via a symlink attack on an unspecified file.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2pqv-gjx5-j94f

A potential vulnerability has been identified in HP Remote Graphics Software’s certificate authentication process version 7.5.0 and earlier.

CVSS3: 9.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-2pqr-cp8m-m5vw

An issue was discovered in the pam_p11 component 0.2.0 and 0.3.0 for OpenSC. If a smart card creates a signature with a length longer than 256 bytes, this triggers a buffer overflow. This may be the case for RSA keys with 4096 bits depending on the signature scheme.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-2pqr-5864-6fgw

In App Widget, there is a possible Information Disclosure due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 5.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-2pqq-4jjp-fmr3

The Subpage List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'subpages' shortcode in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-2pqp-x768-f3m2

An information disclosure vulnerability in upload.php of PopojiCMS 1.2 leads to physical path disclosure of the host when 'name = "file" is deleted during file uploads.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2pqp-qqmg-62w8

NDrive(1.2.2).sys in Naver Cloud Explorer has a stack-based buffer overflow, which allows attackers to cause a denial of service when reading data from IOCTL handle.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2pqm-v28p-x679

eramba c2.8.1 and Enterprise before e2.19.3 allows XSS via a crafted filename for a file attached to an object. For example, the filename has a complete XSS payload followed by the .png extension.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2pqm-qhp5-fh45

Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in the svc_topstats utility. An authenticated attacker could potentially exploit this vulnerability, leading to the ability to overwrite arbitrary files on the file system with root privileges.

CVSS3: 7.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2pqm-q853-jfvf

An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g., by using ANSI control codes to hide additional files being transferred. This affects refresh_progress_meter() in progressmeter.c.

CVSS3: 6.8
4%
Низкий
около 4 лет назад
github логотип
GHSA-2pqj-vff5-fgh2

Cross-site scripting (XSS) vulnerability in Sijio Community Software allows remote authenticated users to inject arbitrary web script or HTML via the title parameter when adding a new blog, related to edit_blog/index.php. NOTE: some of these details are obtained from third party information.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2pqj-h3vj-pqgw

Cross-Site Scripting in jquery

CVSS3: 6.1
9%
Низкий
почти 6 лет назад
github логотип
GHSA-2pqg-9xqc-m3rw

D-LINK DWL-2000AP+ firmware 2.11 allows remote attackers to cause (1) a denial of service (device reset) via a flood of ARP replies on the wired or wireless (radio) link and (2) a denial of service (device crash) via a flood of ARP requests on the wireless link.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-2pqf-pg56-pwcv

The ZEROF Expert pro/2.0 application for mobile devices allows SQL Injection via the Authorization header to the /v2/devices/add endpoint.

29%
Средний
около 4 лет назад

Уязвимостей на страницу