Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 373 892

Количество 373 892

github логотип

GHSA-3pcr-4vgr-x46g

около 3 лет назад

Affected versions of Trend Micro Mobile Security (Enterprise) 9.8 SP5 contain some widgets that would allow a remote user to bypass authentication and potentially chain with other vulnerabilities. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit these vulnerabilities. This is similar to, but not identical to CVE-2023-32524.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3pcr-4982-548m

больше 5 лет назад

Exposure of .env if project root is configured as web root in shopware/production

EPSS: Низкий
github логотип

GHSA-3pcq-f86j-jh8q

больше 4 лет назад

An issue was discovered in tnef before 1.4.13. Four type confusions have been identified in the file_add_mapi_attrs() function. These might lead to invalid read and write operations, controlled by an attacker.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3pcq-5mc6-8j3p

больше 4 лет назад

In Tuxera NTFS-3G versions < 2021.8.22, a stack buffer overflow can occur when correcting differences in the MFT and MFTMirror allowing for code execution or escalation of privileges when setuid-root.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3pcq-34w5-p4g2

почти 5 лет назад

modern-async's `forEachSeries` and `forEachLimit` functions do not limit the number of requests

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3pcq-2643-8rg5

больше 4 лет назад

In exif_data_load_data_content of exif-data.c, there is a possible UBSAN abort due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-146428941

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3pcp-j82c-wg8v

больше 3 лет назад

In _ufdt_output_node_to_fdt of ufdt_convert.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-248085351

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-3pcj-vqw8-47jm

около 2 месяцев назад

GNU Bison improperly handles grammar‑defined output paths. Grammar directives such as %output and %header allow specifying file paths, which are accepted without restriction and override caller‑supplied output options. When processing attacker-supplied grammar, this behavior allows directing generated files to arbitrary writable locations on the filesystem, potentially overwriting existing files accessible to the Bison process. Maintainers of this project were notified about this vulnerability, and fixed the issue in commit 8d101c19d4d9aaedf83a448c925513742d4efcf0. However, they did not provide vulnerable version range. Version 3.8.2 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3pcj-r585-2782

10 дней назад

Exposed Dangerous Method or Function in ASUS Armoury Crate allow a local user to cause a brief system stall by bypassing driver authentication and sending requests to trigger system management interrupts (SMIs). Repeatedly triggering SMI may lead to a denial-of-service (DoS) condition.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.

EPSS: Низкий
github логотип

GHSA-3pcg-mr9h-79cf

около 1 года назад

ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to SQL injections which could allow an attacker to leak arbitrary information and insert arbitrary SQL syntax into SQL queries.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-3pcg-3m3w-7636

около 2 лет назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dinesh Karki WP Armour Extended.This issue affects WP Armour Extended: from n/a through 1.26.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3pcg-2h4x-7rx6

около 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Schiocco Support Board allows Reflected XSS. This issue affects Support Board: from n/a through 3.8.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3pc9-28mv-95h3

больше 4 лет назад

Multiple cross-site scripting vulnerabilities in Webmin versions prior to 1.830 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3pc8-q9qj-vmvc

около 1 года назад

Classic buffer overflow in certain Zoom Clients for Windows may allow an authorized user to conduct a denial of service via network access.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3pc8-hwcr-cqrw

почти 2 года назад

An out-of-bounds write in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformed Mach-O file to crash the application during file processing.

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-3pc8-5mmp-rgj7

больше 4 лет назад

Microsoft Outlook 2000 and 2003, when configured to use Microsoft Word 2000 or 2003 as the e-mail editor and when forwarding e-mail, does not properly handle an opening OBJECT tag that does not have a closing OBJECT tag, which causes Outlook to automatically download the URI in the data property of the OBJECT tag and might allow remote attackers to execute arbitrary code.

EPSS: Средний
github логотип

GHSA-3pc7-c3mc-73r6

почти 2 года назад

By default, dedicated folders of CRYHOD for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of CRYHOD has to be modified to prevent this vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3pc6-5vx3-vf24

9 дней назад

Tanium addressed an improper access controls vulnerability in Comply.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3pc5-rvw8-v64m

около 1 года назад

The Honeywell Experion PKS and OneWireless WDM contains Sensitive Information in Resource vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit this vulnerability, leading to a Communication Channel Manipulation, which could result in buffer reuse which may cause incorrect system behavior. Honeywell also recommends updating to the most recent version of Honeywell Experion PKS:520.2 TCU9 HF1 and 530.1 TCU3 HF1 and OneWireless: 322.5 and 331.1.  The affected Experion PKS products are C300, FIM4, FIM8, UOC, CN100, HCA, C300PM, and C200E. The Experion PKS versions affected are 520.1 before 520.2 TCU9 HF1 and 530 before 530 TCU3. The OneWireless WDM affected versions are 322.1 through 322.4 and 330.1 through 330.3.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3pc4-w649-6gv6

больше 4 лет назад

System Server in Android 6.0 before 2015-12-01 allows attackers to obtain sensitive information and consequently gain privileges via a crafted application, aka internal bug 23936840.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3pcr-4vgr-x46g

Affected versions of Trend Micro Mobile Security (Enterprise) 9.8 SP5 contain some widgets that would allow a remote user to bypass authentication and potentially chain with other vulnerabilities. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit these vulnerabilities. This is similar to, but not identical to CVE-2023-32524.

CVSS3: 8.8
3%
Низкий
около 3 лет назад
github логотип
GHSA-3pcr-4982-548m

Exposure of .env if project root is configured as web root in shopware/production

больше 5 лет назад
github логотип
GHSA-3pcq-f86j-jh8q

An issue was discovered in tnef before 1.4.13. Four type confusions have been identified in the file_add_mapi_attrs() function. These might lead to invalid read and write operations, controlled by an attacker.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3pcq-5mc6-8j3p

In Tuxera NTFS-3G versions < 2021.8.22, a stack buffer overflow can occur when correcting differences in the MFT and MFTMirror allowing for code execution or escalation of privileges when setuid-root.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3pcq-34w5-p4g2

modern-async's `forEachSeries` and `forEachLimit` functions do not limit the number of requests

CVSS3: 7.5
2%
Низкий
почти 5 лет назад
github логотип
GHSA-3pcq-2643-8rg5

In exif_data_load_data_content of exif-data.c, there is a possible UBSAN abort due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-146428941

CVSS3: 7.5
4%
Низкий
больше 4 лет назад
github логотип
GHSA-3pcp-j82c-wg8v

In _ufdt_output_node_to_fdt of ufdt_convert.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-248085351

CVSS3: 4.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3pcj-vqw8-47jm

GNU Bison improperly handles grammar‑defined output paths. Grammar directives such as %output and %header allow specifying file paths, which are accepted without restriction and override caller‑supplied output options. When processing attacker-supplied grammar, this behavior allows directing generated files to arbitrary writable locations on the filesystem, potentially overwriting existing files accessible to the Bison process. Maintainers of this project were notified about this vulnerability, and fixed the issue in commit 8d101c19d4d9aaedf83a448c925513742d4efcf0. However, they did not provide vulnerable version range. Version 3.8.2 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.

CVSS3: 6.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3pcj-r585-2782

Exposed Dangerous Method or Function in ASUS Armoury Crate allow a local user to cause a brief system stall by bypassing driver authentication and sending requests to trigger system management interrupts (SMIs). Repeatedly triggering SMI may lead to a denial-of-service (DoS) condition.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.

0%
Низкий
10 дней назад
github логотип
GHSA-3pcg-mr9h-79cf

ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to SQL injections which could allow an attacker to leak arbitrary information and insert arbitrary SQL syntax into SQL queries.

CVSS3: 9.1
0%
Низкий
около 1 года назад
github логотип
GHSA-3pcg-3m3w-7636

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dinesh Karki WP Armour Extended.This issue affects WP Armour Extended: from n/a through 1.26.

CVSS3: 7.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-3pcg-2h4x-7rx6

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Schiocco Support Board allows Reflected XSS. This issue affects Support Board: from n/a through 3.8.0.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-3pc9-28mv-95h3

Multiple cross-site scripting vulnerabilities in Webmin versions prior to 1.830 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 6.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3pc8-q9qj-vmvc

Classic buffer overflow in certain Zoom Clients for Windows may allow an authorized user to conduct a denial of service via network access.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-3pc8-hwcr-cqrw

An out-of-bounds write in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformed Mach-O file to crash the application during file processing.

CVSS3: 5.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-3pc8-5mmp-rgj7

Microsoft Outlook 2000 and 2003, when configured to use Microsoft Word 2000 or 2003 as the e-mail editor and when forwarding e-mail, does not properly handle an opening OBJECT tag that does not have a closing OBJECT tag, which causes Outlook to automatically download the URI in the data property of the OBJECT tag and might allow remote attackers to execute arbitrary code.

13%
Средний
больше 4 лет назад
github логотип
GHSA-3pc7-c3mc-73r6

By default, dedicated folders of CRYHOD for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of CRYHOD has to be modified to prevent this vulnerability.

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-3pc6-5vx3-vf24

Tanium addressed an improper access controls vulnerability in Comply.

CVSS3: 6.3
0%
Низкий
9 дней назад
github логотип
GHSA-3pc5-rvw8-v64m

The Honeywell Experion PKS and OneWireless WDM contains Sensitive Information in Resource vulnerability in the component Control Data Access (CDA). An attacker could potentially exploit this vulnerability, leading to a Communication Channel Manipulation, which could result in buffer reuse which may cause incorrect system behavior. Honeywell also recommends updating to the most recent version of Honeywell Experion PKS:520.2 TCU9 HF1 and 530.1 TCU3 HF1 and OneWireless: 322.5 and 331.1.  The affected Experion PKS products are C300, FIM4, FIM8, UOC, CN100, HCA, C300PM, and C200E. The Experion PKS versions affected are 520.1 before 520.2 TCU9 HF1 and 530 before 530 TCU3. The OneWireless WDM affected versions are 322.1 through 322.4 and 330.1 through 330.3.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-3pc4-w649-6gv6

System Server in Android 6.0 before 2015-12-01 allows attackers to obtain sensitive information and consequently gain privileges via a crafted application, aka internal bug 23936840.

0%
Низкий
больше 4 лет назад

Уязвимостей на страницу