Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 354 225

Количество 354 225

github логотип

GHSA-2pj2-8f73-8vw2

около 1 месяца назад

Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2pj2-82cm-7r39

около 4 лет назад

PicoC 2.1 has a heap-based buffer overflow in StringStrcpy in cstdlib/string.c when called from ExpressionParseFunctionCall in expression.c.

EPSS: Низкий
github логотип

GHSA-2phx-w35g-x9vm

около 4 лет назад

Moodle Weak Password Recovery Mechanism for Forgotten Password

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2phx-jm8v-c5v7

около 4 лет назад

A vulnerability in the Guest Shell of Cisco IOS XE Software could allow an authenticated, local attacker to perform directory traversal on the base Linux operating system of Cisco IOS XE Software. The vulnerability is due to incomplete validation of certain commands. An attacker could exploit this vulnerability by first accessing the Guest Shell and then entering specific commands. A successful exploit could allow the attacker to execute arbitrary code on the base Linux operating system.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-2phx-frhf-xr55

6 месяцев назад

Mattermost Plugin Zoom allows any logged-in user to change Zoom meeting restrictions for arbitrary channels

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2phw-rgr7-5pvh

больше 3 лет назад

Information Cards Module vulnerable to Cross-site Scripting

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2phw-mm8g-9jp8

почти 3 года назад

OPNsense before 23.7 was discovered to contain insecure permissions in the directory /tmp.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2phw-fwxh-2fw8

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script or HTML via the (1) words, (2) id, (3) cat_id, and (4) tim parameters, which are not sanitized before being returned in an error page. NOTE: it is possible that some of these vectors are resultant from an SQL injection issue.

EPSS: Низкий
github логотип

GHSA-2phv-qp8w-5cv7

больше 4 лет назад

Directory traversal vulnerability in Enceladus Server Suite 3.9 allows remote attackers to list arbitrary directories and possibly cause a denial of service via "@" (at) characters in a CD (CWD) command, such as (1) "@/....\", (2) "@@@/..c:\", or (3) "@/..@/..".

EPSS: Низкий
github логотип

GHSA-2phv-j68v-wwqx

7 месяцев назад

pnpm vulnerable to Command Injection via environment variable substitution

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2phr-4qpj-wc46

около 4 лет назад

Multiple unspecified vulnerabilities in SPIP before 1.9.2.o, 2.0.x before 2.0.18, and 2.1.x before 2.1.13 have unknown impact and attack vectors that are not related to cross-site scripting (XSS), different vulnerabilities than CVE-2012-2151.

EPSS: Низкий
github логотип

GHSA-2phr-482w-4ppv

больше 3 лет назад

Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the startIp parameter in the formSetPPTPServer function.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2phq-x5jx-m4c3

около 4 лет назад

A flaw was found in ImageMagick in MagickCore/resample.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2phq-jg7h-ghf4

больше 4 лет назад

Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire Intrusion Sensor; allows remote attackers to execute arbitrary code via crafted SMB traffic.

EPSS: Высокий
github логотип

GHSA-2phq-ghf8-6586

больше 4 лет назад

Jenkins Snow Commander Plugin prior to 2.0 vulnerable to Missing Authorization

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2php-v593-f386

10 месяцев назад

Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP requests can lead to stack-based buffer overflow. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This buffer overflow is related to the `ipaddr` request parameter for composing the `"ping -c <counts> <ipaddr> 2>&1 > %s &"` string.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2php-rv2v-c3w8

больше 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Gangolf Custom post type templates for Elementor allows Stored XSS.This issue affects Custom post type templates for Elementor: from n/a through 1.10.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2php-mg3p-mcqg

больше 3 лет назад

The GigPress WordPress plugin through 2.3.28 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated users, such as subscriber to perform SQL Injection attacks

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2php-gcq2-fxqp

больше 1 года назад

Improper processing of some parameters of installed_emanual_list.html leads to a path traversal vulnerability. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2php-7prq-766p

больше 4 лет назад

A Null Pointer Dereference vulnerability exits in ffjpeg d5cfd49 (2021-12-06) in bmp_load(). When the size information in metadata of the bmp is out of range, it returns without assign memory buffer to `pb->pdata` and did not exit the program. So the program crashes when it tries to access the pb->data, in jfif_encode() at jfif.c:763. This is due to the incomplete patch for CVE-2020-13438.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2pj2-8f73-8vw2

Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-2pj2-82cm-7r39

PicoC 2.1 has a heap-based buffer overflow in StringStrcpy in cstdlib/string.c when called from ExpressionParseFunctionCall in expression.c.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2phx-w35g-x9vm

Moodle Weak Password Recovery Mechanism for Forgotten Password

CVSS3: 7.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-2phx-jm8v-c5v7

A vulnerability in the Guest Shell of Cisco IOS XE Software could allow an authenticated, local attacker to perform directory traversal on the base Linux operating system of Cisco IOS XE Software. The vulnerability is due to incomplete validation of certain commands. An attacker could exploit this vulnerability by first accessing the Guest Shell and then entering specific commands. A successful exploit could allow the attacker to execute arbitrary code on the base Linux operating system.

CVSS3: 6.7
1%
Низкий
около 4 лет назад
github логотип
GHSA-2phx-frhf-xr55

Mattermost Plugin Zoom allows any logged-in user to change Zoom meeting restrictions for arbitrary channels

CVSS3: 4.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-2phw-rgr7-5pvh

Information Cards Module vulnerable to Cross-site Scripting

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2phw-mm8g-9jp8

OPNsense before 23.7 was discovered to contain insecure permissions in the directory /tmp.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-2phw-fwxh-2fw8

Multiple cross-site scripting (XSS) vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script or HTML via the (1) words, (2) id, (3) cat_id, and (4) tim parameters, which are not sanitized before being returned in an error page. NOTE: it is possible that some of these vectors are resultant from an SQL injection issue.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2phv-qp8w-5cv7

Directory traversal vulnerability in Enceladus Server Suite 3.9 allows remote attackers to list arbitrary directories and possibly cause a denial of service via "@" (at) characters in a CD (CWD) command, such as (1) "@/....\", (2) "@@@/..c:\", or (3) "@/..@/..".

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2phv-j68v-wwqx

pnpm vulnerable to Command Injection via environment variable substitution

CVSS3: 7.5
1%
Низкий
7 месяцев назад
github логотип
GHSA-2phr-4qpj-wc46

Multiple unspecified vulnerabilities in SPIP before 1.9.2.o, 2.0.x before 2.0.18, and 2.1.x before 2.1.13 have unknown impact and attack vectors that are not related to cross-site scripting (XSS), different vulnerabilities than CVE-2012-2151.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2phr-482w-4ppv

Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the startIp parameter in the formSetPPTPServer function.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2phq-x5jx-m4c3

A flaw was found in ImageMagick in MagickCore/resample.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.

CVSS3: 5.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2phq-jg7h-ghf4

Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire Intrusion Sensor; allows remote attackers to execute arbitrary code via crafted SMB traffic.

79%
Высокий
больше 4 лет назад
github логотип
GHSA-2phq-ghf8-6586

Jenkins Snow Commander Plugin prior to 2.0 vulnerable to Missing Authorization

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2php-v593-f386

Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP requests can lead to stack-based buffer overflow. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This buffer overflow is related to the `ipaddr` request parameter for composing the `"ping -c <counts> <ipaddr> 2>&1 > %s &"` string.

CVSS3: 8.8
1%
Низкий
10 месяцев назад
github логотип
GHSA-2php-rv2v-c3w8

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Gangolf Custom post type templates for Elementor allows Stored XSS.This issue affects Custom post type templates for Elementor: from n/a through 1.10.1.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2php-mg3p-mcqg

The GigPress WordPress plugin through 2.3.28 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated users, such as subscriber to perform SQL Injection attacks

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2php-gcq2-fxqp

Improper processing of some parameters of installed_emanual_list.html leads to a path traversal vulnerability. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

CVSS3: 7.5
6%
Низкий
больше 1 года назад
github логотип
GHSA-2php-7prq-766p

A Null Pointer Dereference vulnerability exits in ffjpeg d5cfd49 (2021-12-06) in bmp_load(). When the size information in metadata of the bmp is out of range, it returns without assign memory buffer to `pb->pdata` and did not exit the program. So the program crashes when it tries to access the pb->data, in jfif_encode() at jfif.c:763. This is due to the incomplete patch for CVE-2020-13438.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу