Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 883

Количество 353 883

github логотип

GHSA-2mgr-rf47-4329

больше 1 года назад

An attacker authenticated as an administrator can use an exposed webservice to upload or download a custom PDF font file on the system server. Using the upload functionality to copy an internal file into a font file and subsequently using the download functionality to retrieve that file allows the attacker to read any file on the server with no effect on integrity or availability

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-2mgq-r8qg-4f9c

около 4 лет назад

Vulnerability in the Oracle Retail Xstore Payment component of Oracle Retail Applications (subcomponent: Security). The supported version that is affected is 3.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Payment. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Retail Xstore Payment accessible data as well as unauthorized update, insert or delete access to some of Oracle Retail Xstore Payment accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Retail Xstore Payment. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-2mgp-xj4h-v78w

больше 4 лет назад

Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.10.2 have unknown impact and attack vectors related to (a) Advanced Pricing, aka (1) APP01 and (2) APP10; and (b) Applications Framework, aka (3) APP05.

EPSS: Низкий
github логотип

GHSA-2mgp-rv5h-ggjm

около 4 лет назад

WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1268 and CVE-2014-1269.

EPSS: Низкий
github логотип

GHSA-2mgp-6265-vwf6

около 4 лет назад

A use-after-free vulnerability can occur while playing a sound notification in Thunderbird. The memory storing the sound data is immediately freed, although the sound is still being played asynchronously, leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 60.5.

EPSS: Низкий
github логотип

GHSA-2mgm-x4fm-vrg8

больше 4 лет назад

The Batch::BatchRun module 1.03 for Perl does not properly handle temporary files.

EPSS: Низкий
github логотип

GHSA-2mgm-8w3p-2gr4

около 4 лет назад

Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

EPSS: Низкий
github логотип

GHSA-2mgm-7frw-wmjm

больше 4 лет назад

Argument injection vulnerability involving Microsoft Outlook and Outlook Express, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in an unspecified URI, which are inserted into the command line when invoking the handling process, a similar issue to CVE-2007-3670.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-2mgm-5g5q-v3cw

больше 4 лет назад

NetMaster 12.2 Network Management for TCP/IP and NetMaster File Transfer Management contain a XSS (Cross-Site Scripting) vulnerability in ReportCenter UI due to insufficient input validation that could potentially allow an attacker to execute code on the affected machine.

EPSS: Низкий
github логотип

GHSA-2mgj-rr5x-hxrj

больше 2 лет назад

Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the doc_number parameter at his_admin_view_single_employee.php.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-2mgj-mwvf-mpg5

больше 4 лет назад

Missing permission checks in Jenkins Proxmox Plugin

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2mgh-x98w-w25p

около 4 лет назад

The Dr. Sheikh Adnan Ibrahim (aka com.amitaff.adnanIbrahim) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-2mgg-5ppq-j685

9 месяцев назад

A stack-based buffer overflow vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in the guestSsid parameter of the /goform/WifiGuestSet interface. Remote attackers can exploit this vulnerability by sending oversized data to the guestSsid parameter, leading to denial of service (device crash) or potential remote code execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2mgf-58rr-j7mr

около 4 лет назад

An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is heap-based buffer overflow in the function ReadGF_IPMPX_WatermarkingInit() in odf/ipmpx_code.c.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2mgc-vc9w-hfw7

около 4 лет назад

The Mobile and Remote Access (MRA) endpoint-validation feature in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 improperly validates the phone line used for registration, which allows remote authenticated users to conduct impersonation attacks via a crafted registration, aka Bug ID CSCuv40396.

EPSS: Низкий
github логотип

GHSA-2mgc-grxm-67g2

больше 4 лет назад

Untrusted search path vulnerability in CMake before 2.2.0-r1 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build directory, which is part of the RUNPATH.

EPSS: Низкий
github логотип

GHSA-2mg9-hv69-897x

около 4 лет назад

Moodle Ability to delete glossary entries that belong to another glossary

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2mg9-gqjh-3ggm

больше 4 лет назад

ColdFusion Administrator for ColdFusion 4.5.1 and earlier allows remote attackers to cause a denial of service via a long login password.

EPSS: Низкий
github логотип

GHSA-2mg9-fx6r-2g48

больше 3 лет назад

Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.0.2.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2mg9-fchf-m4w9

7 месяцев назад

Cyberfox Web Browser 52.9.1 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the search bar with excessive data. Attackers can generate a 9,000,000 byte payload and paste it into the search bar to trigger an application crash.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2mgr-rf47-4329

An attacker authenticated as an administrator can use an exposed webservice to upload or download a custom PDF font file on the system server. Using the upload functionality to copy an internal file into a font file and subsequently using the download functionality to retrieve that file allows the attacker to read any file on the server with no effect on integrity or availability

CVSS3: 6.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-2mgq-r8qg-4f9c

Vulnerability in the Oracle Retail Xstore Payment component of Oracle Retail Applications (subcomponent: Security). The supported version that is affected is 3.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Payment. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Retail Xstore Payment accessible data as well as unauthorized update, insert or delete access to some of Oracle Retail Xstore Payment accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Retail Xstore Payment. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).

CVSS3: 8.6
2%
Низкий
около 4 лет назад
github логотип
GHSA-2mgp-xj4h-v78w

Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.10.2 have unknown impact and attack vectors related to (a) Advanced Pricing, aka (1) APP01 and (2) APP10; and (b) Applications Framework, aka (3) APP05.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2mgp-rv5h-ggjm

WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1268 and CVE-2014-1269.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2mgp-6265-vwf6

A use-after-free vulnerability can occur while playing a sound notification in Thunderbird. The memory storing the sound data is immediately freed, although the sound is still being played asynchronously, leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 60.5.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2mgm-x4fm-vrg8

The Batch::BatchRun module 1.03 for Perl does not properly handle temporary files.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2mgm-8w3p-2gr4

Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

3%
Низкий
около 4 лет назад
github логотип
GHSA-2mgm-7frw-wmjm

Argument injection vulnerability involving Microsoft Outlook and Outlook Express, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in an unspecified URI, which are inserted into the command line when invoking the handling process, a similar issue to CVE-2007-3670.

CVSS3: 8.8
13%
Средний
больше 4 лет назад
github логотип
GHSA-2mgm-5g5q-v3cw

NetMaster 12.2 Network Management for TCP/IP and NetMaster File Transfer Management contain a XSS (Cross-Site Scripting) vulnerability in ReportCenter UI due to insufficient input validation that could potentially allow an attacker to execute code on the affected machine.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2mgj-rr5x-hxrj

Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the doc_number parameter at his_admin_view_single_employee.php.

CVSS3: 2.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2mgj-mwvf-mpg5

Missing permission checks in Jenkins Proxmox Plugin

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2mgh-x98w-w25p

The Dr. Sheikh Adnan Ibrahim (aka com.amitaff.adnanIbrahim) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2mgg-5ppq-j685

A stack-based buffer overflow vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in the guestSsid parameter of the /goform/WifiGuestSet interface. Remote attackers can exploit this vulnerability by sending oversized data to the guestSsid parameter, leading to denial of service (device crash) or potential remote code execution.

CVSS3: 8.8
1%
Низкий
9 месяцев назад
github логотип
GHSA-2mgf-58rr-j7mr

An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is heap-based buffer overflow in the function ReadGF_IPMPX_WatermarkingInit() in odf/ipmpx_code.c.

CVSS3: 5.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2mgc-vc9w-hfw7

The Mobile and Remote Access (MRA) endpoint-validation feature in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 improperly validates the phone line used for registration, which allows remote authenticated users to conduct impersonation attacks via a crafted registration, aka Bug ID CSCuv40396.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2mgc-grxm-67g2

Untrusted search path vulnerability in CMake before 2.2.0-r1 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build directory, which is part of the RUNPATH.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2mg9-hv69-897x

Moodle Ability to delete glossary entries that belong to another glossary

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-2mg9-gqjh-3ggm

ColdFusion Administrator for ColdFusion 4.5.1 and earlier allows remote attackers to cause a denial of service via a long login password.

8%
Низкий
больше 4 лет назад
github логотип
GHSA-2mg9-fx6r-2g48

Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.0.2.

CVSS3: 4.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2mg9-fchf-m4w9

Cyberfox Web Browser 52.9.1 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the search bar with excessive data. Attackers can generate a 9,000,000 byte payload and paste it into the search bar to trigger an application crash.

CVSS3: 7.5
0%
Низкий
7 месяцев назад

Уязвимостей на страницу