Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 972

Количество 353 972

github логотип

GHSA-2p49-45hj-7mc9

6 месяцев назад

@backstage/cli-common has a possible `resolveSafeChildPath` Symlink Chain Bypass

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2p48-prhc-qmgx

больше 4 лет назад

The connection_state_machine function (connections.c) in lighttpd 1.4.19 and earlier, and 1.5.x before 1.5.0, allows remote attackers to cause a denial of service (active SSL connection loss) by triggering an SSL error, such as disconnecting before a download has finished, which causes all active SSL connections to be lost.

EPSS: Низкий
github логотип

GHSA-2p48-mg67-hr6x

около 4 лет назад

General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to obtain sensitive cleartext account information via unspecified vectors.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2p47-xxcr-5mcp

больше 4 лет назад

mmap function in BSD allows local attackers in the kmem group to modify memory through devices.

EPSS: Низкий
github логотип

GHSA-2p47-m3g8-8549

около 4 лет назад

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to arbitrary code execution.

EPSS: Низкий
github логотип

GHSA-2p46-76mg-wxvh

больше 2 лет назад

Information exposure vulnerability in Planet IGS-4215-16T2S, affecting firmware version 1.305b210528. This vulnerability could allow a remote attacker to access some administrative resources due to lack of proper management of the Switch web interface.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-2p45-q6vq-5r25

около 4 лет назад

Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dReadPsr, Jt3dReadPsr modules in KeyShot Versions v10.1 and prior lack proper validation of user-supplied data when parsing STP files. This could result in a stack-based buffer overflow. An attacker could leverage this vulnerability to execute code in the context of the current process.

EPSS: Низкий
github логотип

GHSA-2p45-j2vr-jcrg

около 4 лет назад

Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1735, CVE-2015-1740, CVE-2015-1744, and CVE-2015-1745.

EPSS: Средний
github логотип

GHSA-2p45-cjpq-qrf9

около 4 лет назад

There is an out of bounds write vulnerability in Huawei Smartphone HUAWEI P30 versions 9.1.0.131(C00E130R1P21) when processing a message. An unauthenticated attacker can exploit this vulnerability by sending specific message to the target device. Due to insufficient validation of the input parameter, successful exploit can cause the process and the service to be abnormal.

EPSS: Низкий
github логотип

GHSA-2p45-c9hc-p9hf

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the Hierarchical Select module 5.x before 5.x-3.2 and 6.x before 6.x-3.2 for Drupal allows remote authenticated users, with administer taxonomy permissions, to inject arbitrary web script or HTML via unspecified vectors in the hierarchical_select form.

EPSS: Низкий
github логотип

GHSA-2p45-2j99-9x4w

около 4 лет назад

Directory traversal vulnerability in the Percha Gallery (com_perchagallery) component 1.6 Beta for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

EPSS: Средний
github логотип

GHSA-2p44-rc6w-2rvw

около 2 лет назад

The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 is not properly filtering which file extensions are allowed to be imported on the server, allowing the uploading of malicious code within zip files

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2p42-xc4w-2gjf

около 4 лет назад

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK40 before 2.5.1.16, RBR40 before 2.5.1.16, RBS40 before 2.5.1.16, RBK20 before 2.5.1.16, RBR20 before 2.5.1.16, RBS20 before 2.5.1.16, RBK50 before 2.5.1.16, RBR50 before 2.5.1.16, RBS50 before 2.5.1.16, and RBS50Y before 2.6.1.40.

EPSS: Низкий
github логотип

GHSA-2p42-7732-942h

около 4 лет назад

iBall WRB303N devices allow CSRF attacks, as demonstrated by enabling remote management, enabling DHCP, or modifying the subnet range for IP addresses.

EPSS: Низкий
github логотип

GHSA-2p3x-w5wm-64vh

больше 4 лет назад

Multiple SQL injection vulnerabilities in Cybozu Garoon 2.1.0 for Windows allow remote authenticated users to execute arbitrary SQL commands via the (1) tid parameter in the (a) todo/view (aka TODO List View), (b) todo/modify (aka TODO List Modify), or (c) todo/delete functionality; the (2) pid parameter in the (d) workflow/view or (e) workflow/print functionality; the (3) uid parameter in the (f) schedule/user_view, (g) phonemessage/add, (h) phonemessage/history, or (i) schedule/view functionality; the (4) cid parameter in (j) todo/index; the (5) iid parameter in the (k) memo/view or (l) memo/print functionality; or the (6) event parameter in the (m) schedule/view functionality.

EPSS: Низкий
github логотип

GHSA-2p3x-qw9c-25hh

больше 5 лет назад

XStream can cause a Denial of Service.

CVSS3: 7.5
EPSS: Высокий
github логотип

GHSA-2p3x-jr4h-q264

9 месяцев назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-2p3w-xr34-xpgc

больше 4 лет назад

Unspecified vulnerability in the Cluster Ready Services component in Oracle Database 10.1.0.5 allows remote attackers to affect availability via unknown vectors.

EPSS: Низкий
github логотип

GHSA-2p3w-949q-3qpx

около 4 лет назад

Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1767 and CVE-2015-2401.

EPSS: Средний
github логотип

GHSA-2p3w-6745-g5pp

11 месяцев назад

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2. An app may be able to record the screen without an indicator.

CVSS3: 3.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2p49-45hj-7mc9

@backstage/cli-common has a possible `resolveSafeChildPath` Symlink Chain Bypass

CVSS3: 6.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-2p48-prhc-qmgx

The connection_state_machine function (connections.c) in lighttpd 1.4.19 and earlier, and 1.5.x before 1.5.0, allows remote attackers to cause a denial of service (active SSL connection loss) by triggering an SSL error, such as disconnecting before a download has finished, which causes all active SSL connections to be lost.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-2p48-mg67-hr6x

General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to obtain sensitive cleartext account information via unspecified vectors.

CVSS3: 6.5
10%
Низкий
около 4 лет назад
github логотип
GHSA-2p47-xxcr-5mcp

mmap function in BSD allows local attackers in the kmem group to modify memory through devices.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-2p47-m3g8-8549

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to arbitrary code execution.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2p46-76mg-wxvh

Information exposure vulnerability in Planet IGS-4215-16T2S, affecting firmware version 1.305b210528. This vulnerability could allow a remote attacker to access some administrative resources due to lack of proper management of the Switch web interface.

CVSS3: 7.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2p45-q6vq-5r25

Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dReadPsr, Jt3dReadPsr modules in KeyShot Versions v10.1 and prior lack proper validation of user-supplied data when parsing STP files. This could result in a stack-based buffer overflow. An attacker could leverage this vulnerability to execute code in the context of the current process.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2p45-j2vr-jcrg

Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1735, CVE-2015-1740, CVE-2015-1744, and CVE-2015-1745.

16%
Средний
около 4 лет назад
github логотип
GHSA-2p45-cjpq-qrf9

There is an out of bounds write vulnerability in Huawei Smartphone HUAWEI P30 versions 9.1.0.131(C00E130R1P21) when processing a message. An unauthenticated attacker can exploit this vulnerability by sending specific message to the target device. Due to insufficient validation of the input parameter, successful exploit can cause the process and the service to be abnormal.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2p45-c9hc-p9hf

Cross-site scripting (XSS) vulnerability in the Hierarchical Select module 5.x before 5.x-3.2 and 6.x before 6.x-3.2 for Drupal allows remote authenticated users, with administer taxonomy permissions, to inject arbitrary web script or HTML via unspecified vectors in the hierarchical_select form.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2p45-2j99-9x4w

Directory traversal vulnerability in the Percha Gallery (com_perchagallery) component 1.6 Beta for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

16%
Средний
около 4 лет назад
github логотип
GHSA-2p44-rc6w-2rvw

The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 is not properly filtering which file extensions are allowed to be imported on the server, allowing the uploading of malicious code within zip files

CVSS3: 5.4
1%
Низкий
около 2 лет назад
github логотип
GHSA-2p42-xc4w-2gjf

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK40 before 2.5.1.16, RBR40 before 2.5.1.16, RBS40 before 2.5.1.16, RBK20 before 2.5.1.16, RBR20 before 2.5.1.16, RBS20 before 2.5.1.16, RBK50 before 2.5.1.16, RBR50 before 2.5.1.16, RBS50 before 2.5.1.16, and RBS50Y before 2.6.1.40.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2p42-7732-942h

iBall WRB303N devices allow CSRF attacks, as demonstrated by enabling remote management, enabling DHCP, or modifying the subnet range for IP addresses.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2p3x-w5wm-64vh

Multiple SQL injection vulnerabilities in Cybozu Garoon 2.1.0 for Windows allow remote authenticated users to execute arbitrary SQL commands via the (1) tid parameter in the (a) todo/view (aka TODO List View), (b) todo/modify (aka TODO List Modify), or (c) todo/delete functionality; the (2) pid parameter in the (d) workflow/view or (e) workflow/print functionality; the (3) uid parameter in the (f) schedule/user_view, (g) phonemessage/add, (h) phonemessage/history, or (i) schedule/view functionality; the (4) cid parameter in (j) todo/index; the (5) iid parameter in the (k) memo/view or (l) memo/print functionality; or the (6) event parameter in the (m) schedule/view functionality.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-2p3x-qw9c-25hh

XStream can cause a Denial of Service.

CVSS3: 7.5
78%
Высокий
больше 5 лет назад
github логотип
GHSA-2p3x-jr4h-q264

Rejected reason: Not used

9 месяцев назад
github логотип
GHSA-2p3w-xr34-xpgc

Unspecified vulnerability in the Cluster Ready Services component in Oracle Database 10.1.0.5 allows remote attackers to affect availability via unknown vectors.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-2p3w-949q-3qpx

Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1767 and CVE-2015-2401.

21%
Средний
около 4 лет назад
github логотип
GHSA-2p3w-6745-g5pp

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2. An app may be able to record the screen without an indicator.

CVSS3: 3.3
0%
Низкий
11 месяцев назад

Уязвимостей на страницу