Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 972

Количество 353 972

github логотип

GHSA-2mxf-cwcv-jcx7

около 4 лет назад

listmp3.c in libming 0.4.7 allows remote attackers to unspecified impact via a crafted mp3 file, which triggers an invalid left shift.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2mxc-m4c3-wqhq

почти 6 лет назад

Malicious Package in ruffer-xor

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2mxc-jxw2-pf5c

около 4 лет назад

Possible integer overflow due to improper length check while updating grace period and count record in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking

EPSS: Низкий
github логотип

GHSA-2mxc-fm8x-qgcp

10 месяцев назад

In Artifex Ghostscript through 10.05.1, ocr_begin_page in devices/gdevpdfocr.c has an integer overflow that leads to a heap-based buffer overflow in ocr_line8.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2mx9-wcpw-c6gq

около 3 лет назад

The RegistrationMagic plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.2.1.0. This is due to insufficient verification on the user being supplied during a Google social login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2mx9-p3v6-mw46

около 4 лет назад

Cross-site scripting vulnerability in Aterm WG2600HP firmware Ver1.0.2 and earlier, and Aterm WG2600HP2 firmware Ver1.0.2 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-2mx9-mg2h-r94x

5 месяцев назад

A security vulnerability has been detected in YiFang CMS 2.0.5. The affected element is the function update of the file app/db/admin/D_friendLink.php. Such manipulation of the argument linkName leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-2mx9-jpq3-jxj6

около 4 лет назад

Firejail before 0.9.44.6 and 0.9.38.x LTS before 0.9.38.10 LTS does not comprehensively address dotfile cases during its attempt to prevent accessing user files with an euid of zero, which allows local users to conduct sandbox-escape attacks via vectors involving a symlink and the --private option. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-5180.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2mx9-8h8x-39hv

около 4 лет назад

Vulnerability in the Oracle Retail Invoice Matching component of Oracle Retail Applications (subcomponent: Security). Supported versions that are affected are 12.0 and 13.0. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Invoice Matching. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Retail Invoice Matching accessible data as well as unauthorized update, insert or delete access to some of Oracle Retail Invoice Matching accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Retail Invoice Matching. CVSS 3.0 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L).

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-2mx8-3jpw-29fq

около 4 лет назад

Affected versions of Atlassian Jira Service Desk Server and Data Center allow remote attackers authenticated as a non-administrator user to view Project Request-Types and Descriptions, via an Information Disclosure vulnerability in the editform request-type-fields resource. The affected versions are before version 4.12.0.

EPSS: Низкий
github логотип

GHSA-2mx7-xvfg-fg53

больше 2 лет назад

Liferay Portal's account lockout does not invalidate existing user sessions

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2mx7-9ww8-vf6w

больше 4 лет назад

browse.asp in Hosting Controller allows remote attackers to view arbitrary directories by specifying the target pathname in the FilePath parameter.

EPSS: Низкий
github логотип

GHSA-2mx7-93rf-q2qj

около 4 лет назад

XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at IMM32!ImmLockImeDpi+0x0000000000000050."

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2mx7-6jw4-m4gw

больше 4 лет назад

Sendmail before 8.12.1, without the RestrictQueueRun option enabled, allows local users to obtain potentially sensitive information about the mail queue by setting debugging flags to enable debug mode.

EPSS: Низкий
github логотип

GHSA-2mx6-fq24-g2mh

10 месяцев назад

ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal

EPSS: Низкий
github логотип

GHSA-2mx6-9mw9-88cc

около 4 лет назад

dxgkrnl.sys in the DirectX Graphics kernel subsystem in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Microsoft DirectX Graphics Kernel Subsystem Elevation of Privilege Vulnerability."

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2mx6-6v5m-wj8m

около 4 лет назад

Certain NETGEAR devices are affected by stored XSS. This affects RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.

EPSS: Низкий
github логотип

GHSA-2mx5-rvwp-q23x

около 2 лет назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in TemeGUM Gum Elementor Addon allows Stored XSS.This issue affects Gum Elementor Addon: from n/a through 1.3.5.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2mx5-492m-xqp6

почти 4 года назад

H3C H200 H200V100R004 was discovered to contain a stack overflow via the function EnableIpv6.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2mx5-42xw-7586

24 дня назад

R-SOFT DMS stores superadmin credentials using a non-salted nested MD5 hash. This allows an attacker who obtain password hash to decode superadmin credentials. Critically, this password cannot be changed except by modifying the configuration file. This issue was fixed in version v3.17-2000.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2mxf-cwcv-jcx7

listmp3.c in libming 0.4.7 allows remote attackers to unspecified impact via a crafted mp3 file, which triggers an invalid left shift.

CVSS3: 6.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-2mxc-m4c3-wqhq

Malicious Package in ruffer-xor

CVSS3: 9.8
почти 6 лет назад
github логотип
GHSA-2mxc-jxw2-pf5c

Possible integer overflow due to improper length check while updating grace period and count record in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking

0%
Низкий
около 4 лет назад
github логотип
GHSA-2mxc-fm8x-qgcp

In Artifex Ghostscript through 10.05.1, ocr_begin_page in devices/gdevpdfocr.c has an integer overflow that leads to a heap-based buffer overflow in ocr_line8.

CVSS3: 4.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-2mx9-wcpw-c6gq

The RegistrationMagic plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.2.1.0. This is due to insufficient verification on the user being supplied during a Google social login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.

CVSS3: 9.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-2mx9-p3v6-mw46

Cross-site scripting vulnerability in Aterm WG2600HP firmware Ver1.0.2 and earlier, and Aterm WG2600HP2 firmware Ver1.0.2 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2mx9-mg2h-r94x

A security vulnerability has been detected in YiFang CMS 2.0.5. The affected element is the function update of the file app/db/admin/D_friendLink.php. Such manipulation of the argument linkName leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-2mx9-jpq3-jxj6

Firejail before 0.9.44.6 and 0.9.38.x LTS before 0.9.38.10 LTS does not comprehensively address dotfile cases during its attempt to prevent accessing user files with an euid of zero, which allows local users to conduct sandbox-escape attacks via vectors involving a symlink and the --private option. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-5180.

CVSS3: 8.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-2mx9-8h8x-39hv

Vulnerability in the Oracle Retail Invoice Matching component of Oracle Retail Applications (subcomponent: Security). Supported versions that are affected are 12.0 and 13.0. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Invoice Matching. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Retail Invoice Matching accessible data as well as unauthorized update, insert or delete access to some of Oracle Retail Invoice Matching accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Retail Invoice Matching. CVSS 3.0 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L).

CVSS3: 7.6
1%
Низкий
около 4 лет назад
github логотип
GHSA-2mx8-3jpw-29fq

Affected versions of Atlassian Jira Service Desk Server and Data Center allow remote attackers authenticated as a non-administrator user to view Project Request-Types and Descriptions, via an Information Disclosure vulnerability in the editform request-type-fields resource. The affected versions are before version 4.12.0.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2mx7-xvfg-fg53

Liferay Portal's account lockout does not invalidate existing user sessions

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2mx7-9ww8-vf6w

browse.asp in Hosting Controller allows remote attackers to view arbitrary directories by specifying the target pathname in the FilePath parameter.

8%
Низкий
больше 4 лет назад
github логотип
GHSA-2mx7-93rf-q2qj

XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at IMM32!ImmLockImeDpi+0x0000000000000050."

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-2mx7-6jw4-m4gw

Sendmail before 8.12.1, without the RestrictQueueRun option enabled, allows local users to obtain potentially sensitive information about the mail queue by setting debugging flags to enable debug mode.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-2mx6-fq24-g2mh

ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal

10 месяцев назад
github логотип
GHSA-2mx6-9mw9-88cc

dxgkrnl.sys in the DirectX Graphics kernel subsystem in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Microsoft DirectX Graphics Kernel Subsystem Elevation of Privilege Vulnerability."

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2mx6-6v5m-wj8m

Certain NETGEAR devices are affected by stored XSS. This affects RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2mx5-rvwp-q23x

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in TemeGUM Gum Elementor Addon allows Stored XSS.This issue affects Gum Elementor Addon: from n/a through 1.3.5.

CVSS3: 5.9
0%
Низкий
около 2 лет назад
github логотип
GHSA-2mx5-492m-xqp6

H3C H200 H200V100R004 was discovered to contain a stack overflow via the function EnableIpv6.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-2mx5-42xw-7586

R-SOFT DMS stores superadmin credentials using a non-salted nested MD5 hash. This allows an attacker who obtain password hash to decode superadmin credentials. Critically, this password cannot be changed except by modifying the configuration file. This issue was fixed in version v3.17-2000.

0%
Низкий
24 дня назад

Уязвимостей на страницу