Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 374 825

Количество 374 825

github логотип

GHSA-3qrw-968g-4hqv

около 1 месяца назад

The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attackers to write a file into any existing directory on the server, inside or outside the web root, overwriting whatever occupies the target name. On Apache, the same flaw overwrites the site's .htaccess files, which breaks the site and can strip hardening rules that other security measures rely on.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-3qrv-r8v8-pmw7

больше 2 лет назад

A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed before the rename operation, the temporary file will not be removed and may fill the filesystem when invoked multiple times, resulting in a filesystem out of free inodes or blocks.

CVSS3: 3.2
EPSS: Низкий
github логотип

GHSA-3qrv-qpqp-72x5

больше 4 лет назад

LokwaBB 1.2.2 allows remote attackers to read arbitrary messages by modifying the pmid parameter to pm.php.

EPSS: Низкий
github логотип

GHSA-3qrv-qff5-f7w7

около 1 года назад

NVIDIA Triton Inference Server contains a vulnerability in the HTTP server, where an attacker could start a reverse shell by sending a specially crafted HTTP request. A successful exploit of this vulnerability might lead to remote code execution, denial of service, data tampering, or information disclosure.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-3qrr-xcc2-m7cg

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: NFSD: prevent underflow in nfssvc_decode_writeargs() Smatch complains: fs/nfsd/nfsxdr.c:341 nfssvc_decode_writeargs() warn: no lower bound on 'args->len' Change the type to unsigned to prevent this issue.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3qrr-qcj3-vmhr

больше 4 лет назад

An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory, aka 'Microsoft Graphics Component Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0921.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3qrr-m24q-j9qm

больше 4 лет назад

Arm Mbed TLS before 2.6.15 allows attackers to obtain sensitive information (an RSA private key) by measuring cache usage during an import.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3qrq-r688-vvh4

больше 4 лет назад

Multiple valid tokens for password reset in Shopware

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-3qrq-p37g-j4wm

больше 4 лет назад

An issue was discovered in HCC embedded InterNiche 4.0.1. A potential heap buffer overflow exists in the code that parses the HTTP POST request, due to lack of size validation. This vulnerability requires the attacker to send a crafted HTTP POST request with a URI longer than 50 bytes. This leads to a heap overflow in wbs_post() via an strcpy() call.

EPSS: Низкий
github логотип

GHSA-3qrq-jf59-7wp6

больше 4 лет назад

An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in work_stuff_copy_to_from when called from iterate_demangle_function.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3qrp-f55m-c6cw

3 месяца назад

A vulnerability was determined in itsourcecode Online Hotel Management System 1.0. This affects an unknown part of the file /admin/mod_users/controller.php?action=edit of the component POST Request Handler. This manipulation of the argument Name causes cross site scripting. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3qrp-9m7h-qrvr

больше 4 лет назад

Unknown vulnerability in WesMo phpEventCalendar 1.1 allows remote attackers to execute arbitrary commands via unknown attack vectors.

EPSS: Низкий
github логотип

GHSA-3qrp-9gcp-6h2f

больше 4 лет назад

Unspecified vulnerability in the PeopleSoft Enterprise FMS - GL component in Oracle PeopleSoft and JDEdwards Suite 8.9 Bundle #38, 9.0 Bundle #31, and 9.1 Bundle #6 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2010-3539.

EPSS: Низкий
github логотип

GHSA-3qrj-m7m5-v2mm

10 месяцев назад

PHPGurukul Small CRM 3.0 is vulnerable to Cross Site Scripting (XSS) via the aremark parameter in manage-tickets.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3qrj-m697-ww2v

около 4 лет назад

Flooding SNS firewall 3.7.0 to 3.7.26 with udp or icmp randomizing the source through an internal to internal or external to internal interfaces will lead the firewall to overwork. It will consume 100% CPU, 100 RAM and won't be available and can crash.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3qrh-x7rc-6p32

больше 4 лет назад

Directory traversal vulnerability in SafeNet Sentinel Protection Server 7.0.0 through 7.4.0 and possibly earlier versions, and Sentinel Keys Server 1.0.3 and possibly earlier versions, allows remote attackers to read arbitrary files via a .. (dot dot) in the query string.

EPSS: Средний
github логотип

GHSA-3qrh-q76v-gc9c

около 2 месяцев назад

The Brizy WordPress plugin before 2.8.19 does not properly restrict who can modify its site-global design data and does not sanitise part of that data before outputting it, allowing authenticated users with Author-level access and above to store arbitrary JavaScript that is then served unsanitised on the site's front-end pages and executes in the browser of every visitor, including administrators.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-3qrh-88fr-gvx6

больше 4 лет назад

An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device has a custom telnet daemon as a part of the busybox and retrieves the password from the shadow file using the function getspnam at address 0x00053894. Then performs a crypt operation on the password retrieved from the user at address 0x000538E0 and performs a strcmp at address 0x00053908 to check if the password is correct or incorrect. However, the /etc/shadow file is a part of CRAM-FS filesystem which means that the user cannot change the password and hence a hardcoded hash in /etc/shadow is used to match the credentials provided by the user. This is a salted hash of the string "admin" and hence it acts as a password to the device which cannot be changed as the whole filesystem is read only.

EPSS: Низкий
github логотип

GHSA-3qrg-2wxx-492r

больше 4 лет назад

In BIG-IP PEM versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.2.7, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, when processing Capabilities-Exchange-Answer (CEA) packets with certain attributes from the Policy and Charging Rules Function (PCRF) server, the Traffic Management Microkernel (TMM) may generate a core file and restart.

EPSS: Низкий
github логотип

GHSA-3qrf-m4j2-pcrr

около 3 лет назад

Security issue with external entity loading in XML without enabling it

CVSS3: 8.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3qrw-968g-4hqv

The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attackers to write a file into any existing directory on the server, inside or outside the web root, overwriting whatever occupies the target name. On Apache, the same flaw overwrites the site's .htaccess files, which breaks the site and can strip hardening rules that other security measures rely on.

CVSS3: 10
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3qrv-r8v8-pmw7

A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed before the rename operation, the temporary file will not be removed and may fill the filesystem when invoked multiple times, resulting in a filesystem out of free inodes or blocks.

CVSS3: 3.2
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3qrv-qpqp-72x5

LokwaBB 1.2.2 allows remote attackers to read arbitrary messages by modifying the pmid parameter to pm.php.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3qrv-qff5-f7w7

NVIDIA Triton Inference Server contains a vulnerability in the HTTP server, where an attacker could start a reverse shell by sending a specially crafted HTTP request. A successful exploit of this vulnerability might lead to remote code execution, denial of service, data tampering, or information disclosure.

CVSS3: 9.1
2%
Низкий
около 1 года назад
github логотип
GHSA-3qrr-xcc2-m7cg

In the Linux kernel, the following vulnerability has been resolved: NFSD: prevent underflow in nfssvc_decode_writeargs() Smatch complains: fs/nfsd/nfsxdr.c:341 nfssvc_decode_writeargs() warn: no lower bound on 'args->len' Change the type to unsigned to prevent this issue.

CVSS3: 5.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-3qrr-qcj3-vmhr

An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory, aka 'Microsoft Graphics Component Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0921.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3qrr-m24q-j9qm

Arm Mbed TLS before 2.6.15 allows attackers to obtain sensitive information (an RSA private key) by measuring cache usage during an import.

CVSS3: 5.9
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3qrq-r688-vvh4

Multiple valid tokens for password reset in Shopware

CVSS3: 6.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3qrq-p37g-j4wm

An issue was discovered in HCC embedded InterNiche 4.0.1. A potential heap buffer overflow exists in the code that parses the HTTP POST request, due to lack of size validation. This vulnerability requires the attacker to send a crafted HTTP POST request with a URI longer than 50 bytes. This leads to a heap overflow in wbs_post() via an strcpy() call.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3qrq-jf59-7wp6

An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in work_stuff_copy_to_from when called from iterate_demangle_function.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3qrp-f55m-c6cw

A vulnerability was determined in itsourcecode Online Hotel Management System 1.0. This affects an unknown part of the file /admin/mod_users/controller.php?action=edit of the component POST Request Handler. This manipulation of the argument Name causes cross site scripting. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.

CVSS3: 4.3
0%
Низкий
3 месяца назад
github логотип
GHSA-3qrp-9m7h-qrvr

Unknown vulnerability in WesMo phpEventCalendar 1.1 allows remote attackers to execute arbitrary commands via unknown attack vectors.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3qrp-9gcp-6h2f

Unspecified vulnerability in the PeopleSoft Enterprise FMS - GL component in Oracle PeopleSoft and JDEdwards Suite 8.9 Bundle #38, 9.0 Bundle #31, and 9.1 Bundle #6 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2010-3539.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3qrj-m7m5-v2mm

PHPGurukul Small CRM 3.0 is vulnerable to Cross Site Scripting (XSS) via the aremark parameter in manage-tickets.php.

CVSS3: 6.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-3qrj-m697-ww2v

Flooding SNS firewall 3.7.0 to 3.7.26 with udp or icmp randomizing the source through an internal to internal or external to internal interfaces will lead the firewall to overwork. It will consume 100% CPU, 100 RAM and won't be available and can crash.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-3qrh-x7rc-6p32

Directory traversal vulnerability in SafeNet Sentinel Protection Server 7.0.0 through 7.4.0 and possibly earlier versions, and Sentinel Keys Server 1.0.3 and possibly earlier versions, allows remote attackers to read arbitrary files via a .. (dot dot) in the query string.

10%
Средний
больше 4 лет назад
github логотип
GHSA-3qrh-q76v-gc9c

The Brizy WordPress plugin before 2.8.19 does not properly restrict who can modify its site-global design data and does not sanitise part of that data before outputting it, allowing authenticated users with Author-level access and above to store arbitrary JavaScript that is then served unsanitised on the site's front-end pages and executes in the browser of every visitor, including administrators.

CVSS3: 3.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3qrh-88fr-gvx6

An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device has a custom telnet daemon as a part of the busybox and retrieves the password from the shadow file using the function getspnam at address 0x00053894. Then performs a crypt operation on the password retrieved from the user at address 0x000538E0 and performs a strcmp at address 0x00053908 to check if the password is correct or incorrect. However, the /etc/shadow file is a part of CRAM-FS filesystem which means that the user cannot change the password and hence a hardcoded hash in /etc/shadow is used to match the credentials provided by the user. This is a salted hash of the string "admin" and hence it acts as a password to the device which cannot be changed as the whole filesystem is read only.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-3qrg-2wxx-492r

In BIG-IP PEM versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.2.7, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, when processing Capabilities-Exchange-Answer (CEA) packets with certain attributes from the Policy and Charging Rules Function (PCRF) server, the Traffic Management Microkernel (TMM) may generate a core file and restart.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3qrf-m4j2-pcrr

Security issue with external entity loading in XML without enabling it

CVSS3: 8.6
2%
Низкий
около 3 лет назад

Уязвимостей на страницу