Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 972

Количество 353 972

github логотип

GHSA-2mp2-8rhv-p755

около 4 лет назад

IBM Cloud Pak System 2.3 and 2.3.0.1 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server. IBM X-Force ID: 158280.

EPSS: Низкий
github логотип

GHSA-2mmx-jx99-8cmf

9 месяцев назад

HP ThinPro 8.1 System management application failed to verify user's true id. HP has released HP ThinPro 8.1 SP8, which includes updates to mitigate potential vulnerabilities.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2mmx-5mfh-2536

около 4 лет назад

An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It mishandles IP-based rate limiting.

EPSS: Низкий
github логотип

GHSA-2mmx-452m-3qmq

около 4 лет назад

Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.5 allows an attacker to inject arbitrary web script or HTML via "Rich text" function of the application "Memo".

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2mmw-g99r-5x3v

больше 2 лет назад

Internet Shortcut Files Security Feature Bypass Vulnerability

CVSS3: 8.1
EPSS: Критический
github логотип

GHSA-2mmv-7rrp-g8xh

7 месяцев назад

Weblate command-line client susceptible to SSL verification skip

CVSS3: 2.5
EPSS: Низкий
github логотип

GHSA-2mmr-w2qp-r5qp

8 месяцев назад

A cross-site request forgery (csrf) vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted HTTP request can lead to unauthorized access. An attacker can stage a malicious webpage to trigger this vulnerability.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2mmr-f4v7-mvfx

3 месяца назад

The WP Maps WordPress plugin before 4.9.3 does not properly sanitize a parameter before using it in a file path, allowing authenticated users to perform Local File Inclusion attacks.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2mmr-5x9x-4m97

около 4 лет назад

Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to require a user gesture for powerful download operations, which allowed a remote attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted HTML page.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2mmr-2hq6-5c3v

около 4 лет назад

The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the relay_send_end_cell_from_edge_ function via a malformed BEGIN cell.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2mmq-prpj-ww9q

8 месяцев назад

Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2 on multiple platforms allows a remote unauthenticated attacker to cause a denial-of-service by sending a crafted ClientHello message containing duplicate KeyShareEntry values for the same supported group, leading to excessive CPU and memory consumption during ClientHello processing.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2mmq-f6mj-fwfx

больше 3 лет назад

In several functions of SettingsState.java, there is a possible system crash loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-239415861

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2mmp-4p76-vmrq

около 4 лет назад

In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112663886

EPSS: Низкий
github логотип

GHSA-2mmm-qjp3-8j87

почти 3 года назад

e-Excellence U-Office Force has a path traversal vulnerability within its file uploading and downloading functions. An unauthenticated remote attacker can exploit this vulnerability to read arbitrary system files, but can’t control system or disrupt service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2mmj-hgqm-x284

около 4 лет назад

Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by a token spoofing vulnerability. Each payment terminal has a session token (called X-Terminal-Token) to access the marketplace. This allows the store to identify the terminal and make available the applications distributed by its reseller. By intercepting HTTPS traffic from the application store, it is possible to collect the request responsible for assigning the X-Terminal-Token to the terminal, which makes it possible to craft an X-Terminal-Token pretending to be another device. An attacker can use this behavior to authenticate its own payment terminal in the application store through token impersonation.

EPSS: Низкий
github логотип

GHSA-2mmg-vhx9-xmqq

больше 4 лет назад

An unspecified version of youtube-php-mirroring is affected by a Cross Site Scripting (XSS) vulnerability in file ytproxy/index.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2mmg-r5qc-hhcj

больше 4 лет назад

archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assisted remote attackers to cause a denial of service (infinite loop) via (1) an end-of-file condition within a pax extension header or (2) a malformed pax extension header in an (a) PAX or a (b) TAR archive.

EPSS: Низкий
github логотип

GHSA-2mmf-rqvr-m9qr

больше 2 лет назад

Microsoft On-Prem Data Gateway Security Feature Bypass Vulnerability

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-2mmf-r54m-7994

около 4 лет назад

mwlib 0.13 through 0.13.4 has a denial of service vulnerability when parsing #iferror magic functions

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2mmf-p5r8-wc5g

11 месяцев назад

The MongoDB Windows installation MSI may leave ACLs unset on custom installation directories allowing a local attacker to introduce executable code to MongoDB's process via DLL hijacking. This issue affects MongoDB Server v6.0 version prior to 6.0.25, MongoDB Server v7.0 version prior to 7.0.21 and MongoDB Server v8.0 version prior to 8.0.5

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2mp2-8rhv-p755

IBM Cloud Pak System 2.3 and 2.3.0.1 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server. IBM X-Force ID: 158280.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2mmx-jx99-8cmf

HP ThinPro 8.1 System management application failed to verify user's true id. HP has released HP ThinPro 8.1 SP8, which includes updates to mitigate potential vulnerabilities.

CVSS3: 9.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-2mmx-5mfh-2536

An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It mishandles IP-based rate limiting.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2mmx-452m-3qmq

Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.5 allows an attacker to inject arbitrary web script or HTML via "Rich text" function of the application "Memo".

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-2mmw-g99r-5x3v

Internet Shortcut Files Security Feature Bypass Vulnerability

CVSS3: 8.1
95%
Критический
больше 2 лет назад
github логотип
GHSA-2mmv-7rrp-g8xh

Weblate command-line client susceptible to SSL verification skip

CVSS3: 2.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-2mmr-w2qp-r5qp

A cross-site request forgery (csrf) vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted HTTP request can lead to unauthorized access. An attacker can stage a malicious webpage to trigger this vulnerability.

CVSS3: 7.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-2mmr-f4v7-mvfx

The WP Maps WordPress plugin before 4.9.3 does not properly sanitize a parameter before using it in a file path, allowing authenticated users to perform Local File Inclusion attacks.

CVSS3: 7.5
0%
Низкий
3 месяца назад
github логотип
GHSA-2mmr-5x9x-4m97

Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to require a user gesture for powerful download operations, which allowed a remote attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted HTML page.

CVSS3: 6.1
2%
Низкий
около 4 лет назад
github логотип
GHSA-2mmr-2hq6-5c3v

The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the relay_send_end_cell_from_edge_ function via a malformed BEGIN cell.

CVSS3: 7.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-2mmq-prpj-ww9q

Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2 on multiple platforms allows a remote unauthenticated attacker to cause a denial-of-service by sending a crafted ClientHello message containing duplicate KeyShareEntry values for the same supported group, leading to excessive CPU and memory consumption during ClientHello processing.

CVSS3: 5.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-2mmq-f6mj-fwfx

In several functions of SettingsState.java, there is a possible system crash loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-239415861

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2mmp-4p76-vmrq

In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112663886

1%
Низкий
около 4 лет назад
github логотип
GHSA-2mmm-qjp3-8j87

e-Excellence U-Office Force has a path traversal vulnerability within its file uploading and downloading functions. An unauthenticated remote attacker can exploit this vulnerability to read arbitrary system files, but can’t control system or disrupt service.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-2mmj-hgqm-x284

Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by a token spoofing vulnerability. Each payment terminal has a session token (called X-Terminal-Token) to access the marketplace. This allows the store to identify the terminal and make available the applications distributed by its reseller. By intercepting HTTPS traffic from the application store, it is possible to collect the request responsible for assigning the X-Terminal-Token to the terminal, which makes it possible to craft an X-Terminal-Token pretending to be another device. An attacker can use this behavior to authenticate its own payment terminal in the application store through token impersonation.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2mmg-vhx9-xmqq

An unspecified version of youtube-php-mirroring is affected by a Cross Site Scripting (XSS) vulnerability in file ytproxy/index.php.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2mmg-r5qc-hhcj

archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assisted remote attackers to cause a denial of service (infinite loop) via (1) an end-of-file condition within a pax extension header or (2) a malformed pax extension header in an (a) PAX or a (b) TAR archive.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-2mmf-rqvr-m9qr

Microsoft On-Prem Data Gateway Security Feature Bypass Vulnerability

CVSS3: 8
2%
Низкий
больше 2 лет назад
github логотип
GHSA-2mmf-r54m-7994

mwlib 0.13 through 0.13.4 has a denial of service vulnerability when parsing #iferror magic functions

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-2mmf-p5r8-wc5g

The MongoDB Windows installation MSI may leave ACLs unset on custom installation directories allowing a local attacker to introduce executable code to MongoDB's process via DLL hijacking. This issue affects MongoDB Server v6.0 version prior to 6.0.25, MongoDB Server v7.0 version prior to 7.0.21 and MongoDB Server v8.0 version prior to 8.0.5

CVSS3: 7.8
0%
Низкий
11 месяцев назад

Уязвимостей на страницу