Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 373 892

Количество 373 892

github логотип

GHSA-3ph2-m9qq-8gwp

около 1 года назад

IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26119.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3ph2-3pv3-wjv3

больше 4 лет назад

Microsoft NetMeeting with Remote Desktop Sharing enabled allows remote attackers to cause a denial of service (CPU utilization) via a sequence of null bytes to the NetMeeting port, aka the "NetMeeting Desktop Sharing" vulnerability.

EPSS: Средний
github логотип

GHSA-3pgx-69pv-46wx

больше 1 года назад

A race condition could have led to private browsing tabs being opened in normal browsing windows. This could have resulted in a potential privacy leak. This vulnerability affects Firefox < 135, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3pgx-5h9r-2mg2

больше 4 лет назад

SAP Enable Now, before version 1911, leaks information about network configuration in the server error messages, leading to Information Disclosure.

EPSS: Низкий
github логотип

GHSA-3pgx-46rx-xc9j

больше 4 лет назад

hawtio before version 1.5.5 is vulnerable to remote code execution via file upload. An attacker could use this vulnerability to upload a crafted file which could be executed on a target machine where hawtio is deployed.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3pgw-qmv2-hv8m

6 месяцев назад

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, then issue or receive OCPP commands as a legitimate charger. Given that no authentication is required, this can lead to privilege escalation, unauthorized control of charging infrastructure, and corruption of charging network data reported to the backend.

CVSS3: 9.4
EPSS: Низкий
github логотип

GHSA-3pgw-pp6m-pgh6

больше 3 лет назад

In multiple functions of AdapterService.java, there is a possible way to manipulate Bluetooth state due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-240301753

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3pgw-hvj7-xwg9

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in data/hybrid/i_hybrid.php in Open Constructor 3.12.0 allows remote authenticated users to inject arbitrary web script or HTML via the header parameter.

EPSS: Низкий
github логотип

GHSA-3pgv-pw29-xppm

больше 4 лет назад

Netwide Assembler (NASM) 2.13.02rc2 has a stack-based buffer under-read in the function ieee_shr in asm/float.c via a large shift value.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3pgv-hwxj-pq2c

больше 4 лет назад

Multiple format string vulnerabilities in Scorched 3D 39.1 (bf) and earlier allow remote attackers to execute arbitrary code via various (1) GLConsole::addLine, (2) ServerCommon::sendString, (3) ServerCommon::serverLog functions, and possibly other unspecified vectors.

EPSS: Средний
github логотип

GHSA-3pgp-22cc-4c6r

9 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartcms Advance Seat Reservation Management for WooCommerce scw-seat-reservation allows SQL Injection.This issue affects Advance Seat Reservation Management for WooCommerce: from n/a through <= 3.1.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-3pgm-m73m-qrj2

больше 1 года назад

SSRF vulnerability in the RSS feed parser in Zimbra Collaboration 9.0.0 before Patch 43, 10.0.x before 10.0.12, and 10.1.x before 10.1.4 allows unauthorized redirection to internal network endpoints.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3pgm-jg3q-f445

около 1 года назад

A Reflected XSS vulnerability in DJ-Reviews component 1.0-1.3.6 for Joomla was discovered.

EPSS: Низкий
github логотип

GHSA-3pgm-8wwj-gjwc

больше 3 лет назад

McAfee Total Protection prior to 16.0.50 may allow an adversary (with full administrative access) to modify a McAfee specific Component Object Model (COM) in the Windows Registry. This can result in the loading of a malicious payload.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3pgm-5jc2-x2rx

больше 4 лет назад

Incorrect security UI in Omnibox in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3pgj-pg6c-r5p7

около 4 лет назад

OAuthLib vulnerable to DoS when attacker provides malicious IPV6 URI

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-3pgj-h3jv-hj48

9 месяцев назад

AVideo versions prior to 20.0 are vulnerable to an open redirect flaw due to missing validation of the cancelUri parameter during user login. An attacker can craft a link to redirect users to arbitrary external sites, enabling phishing attacks.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3pgh-mfvh-3jch

больше 4 лет назад

The sell function of a smart contract implementation for Internet Node Token (INT), a tradable Ethereum ERC20 token, allows a potential trap that could be used to cause financial damage to the seller, because of overflow of the multiplication of its argument amount and a manipulable variable sellPrice, aka the "tradeTrap" issue.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3pgh-gc83-p85w

больше 4 лет назад

A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3pgh-f8f3-268r

больше 4 лет назад

The AnimationThread function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 uses an incorrect argument to the sscanf function, which might allow remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via unknown vectors.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3ph2-m9qq-8gwp

IrfanView CADImage Plugin DXF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DXF files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26119.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-3ph2-3pv3-wjv3

Microsoft NetMeeting with Remote Desktop Sharing enabled allows remote attackers to cause a denial of service (CPU utilization) via a sequence of null bytes to the NetMeeting port, aka the "NetMeeting Desktop Sharing" vulnerability.

21%
Средний
больше 4 лет назад
github логотип
GHSA-3pgx-69pv-46wx

A race condition could have led to private browsing tabs being opened in normal browsing windows. This could have resulted in a potential privacy leak. This vulnerability affects Firefox < 135, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-3pgx-5h9r-2mg2

SAP Enable Now, before version 1911, leaks information about network configuration in the server error messages, leading to Information Disclosure.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3pgx-46rx-xc9j

hawtio before version 1.5.5 is vulnerable to remote code execution via file upload. An attacker could use this vulnerability to upload a crafted file which could be executed on a target machine where hawtio is deployed.

CVSS3: 7.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3pgw-qmv2-hv8m

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, then issue or receive OCPP commands as a legitimate charger. Given that no authentication is required, this can lead to privilege escalation, unauthorized control of charging infrastructure, and corruption of charging network data reported to the backend.

CVSS3: 9.4
0%
Низкий
6 месяцев назад
github логотип
GHSA-3pgw-pp6m-pgh6

In multiple functions of AdapterService.java, there is a possible way to manipulate Bluetooth state due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-240301753

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3pgw-hvj7-xwg9

Cross-site scripting (XSS) vulnerability in data/hybrid/i_hybrid.php in Open Constructor 3.12.0 allows remote authenticated users to inject arbitrary web script or HTML via the header parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3pgv-pw29-xppm

Netwide Assembler (NASM) 2.13.02rc2 has a stack-based buffer under-read in the function ieee_shr in asm/float.c via a large shift value.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3pgv-hwxj-pq2c

Multiple format string vulnerabilities in Scorched 3D 39.1 (bf) and earlier allow remote attackers to execute arbitrary code via various (1) GLConsole::addLine, (2) ServerCommon::sendString, (3) ServerCommon::serverLog functions, and possibly other unspecified vectors.

11%
Средний
больше 4 лет назад
github логотип
GHSA-3pgp-22cc-4c6r

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartcms Advance Seat Reservation Management for WooCommerce scw-seat-reservation allows SQL Injection.This issue affects Advance Seat Reservation Management for WooCommerce: from n/a through <= 3.1.

CVSS3: 9.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-3pgm-m73m-qrj2

SSRF vulnerability in the RSS feed parser in Zimbra Collaboration 9.0.0 before Patch 43, 10.0.x before 10.0.12, and 10.1.x before 10.1.4 allows unauthorized redirection to internal network endpoints.

CVSS3: 5.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-3pgm-jg3q-f445

A Reflected XSS vulnerability in DJ-Reviews component 1.0-1.3.6 for Joomla was discovered.

0%
Низкий
около 1 года назад
github логотип
GHSA-3pgm-8wwj-gjwc

McAfee Total Protection prior to 16.0.50 may allow an adversary (with full administrative access) to modify a McAfee specific Component Object Model (COM) in the Windows Registry. This can result in the loading of a malicious payload.

CVSS3: 6.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3pgm-5jc2-x2rx

Incorrect security UI in Omnibox in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3pgj-pg6c-r5p7

OAuthLib vulnerable to DoS when attacker provides malicious IPV6 URI

CVSS3: 5.7
2%
Низкий
около 4 лет назад
github логотип
GHSA-3pgj-h3jv-hj48

AVideo versions prior to 20.0 are vulnerable to an open redirect flaw due to missing validation of the cancelUri parameter during user login. An attacker can craft a link to redirect users to arbitrary external sites, enabling phishing attacks.

CVSS3: 6.1
0%
Низкий
9 месяцев назад
github логотип
GHSA-3pgh-mfvh-3jch

The sell function of a smart contract implementation for Internet Node Token (INT), a tradable Ethereum ERC20 token, allows a potential trap that could be used to cause financial damage to the seller, because of overflow of the multiplication of its argument amount and a manipulable variable sellPrice, aka the "tradeTrap" issue.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3pgh-gc83-p85w

A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVSS3: 8.8
9%
Низкий
больше 4 лет назад
github логотип
GHSA-3pgh-f8f3-268r

The AnimationThread function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 uses an incorrect argument to the sscanf function, which might allow remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via unknown vectors.

4%
Низкий
больше 4 лет назад

Уязвимостей на страницу