Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 883

Количество 353 883

github логотип

GHSA-2mg9-59xm-chrg

около 1 года назад

The `/etc/passwd` and `/etc/shadow` files reveal hard-coded password hashes for the operating system "root" user. The credentials are shipped with the update files. There is no option for deleting or changing their passwords for an enduser. An attacker can use the credentials to log into the device. Authentication can be performed via SSH backdoor or likely via physical access (UART shell).

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-2mg8-v7rr-mpqj

8 месяцев назад

NVIDIA DGX Spark GB10 contains a vulnerability in OSROOT firmware, where an attacker could cause an invalid memory read. A successful exploit of this vulnerability might lead to denial of service.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-2mg8-pqjg-f272

больше 4 лет назад

Buffer overflow in Labtam ProFTP 2.9 allows remote FTP servers to cause a denial of service (application crash) or execute arbitrary code via a long 220 reply (aka connection greeting or welcome message).

EPSS: Средний
github логотип

GHSA-2mg8-jrmg-qq5v

около 4 лет назад

The simple-add-pages-or-posts plugin before 1.7 for WordPress has CSRF for deleting users.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2mg8-8fqw-hq49

около 4 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the Our Team Showcase (our-team-enhanced) plugin before 1.3 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change plugin settings via unspecified vectors or (2) conduct cross-site scripting (XSS) attacks via the sc_our_team_member_count parameter in the sc_team_settings page to wp-admin/edit.php.

EPSS: Низкий
github логотип

GHSA-2mg8-3gq9-25w2

больше 4 лет назад

The useredit_account.wdm module in Alt-N WebAdmin 3.2.5 running with MDaemon 9.0.6, and possibly earlier versions, allows remote authenticated domain administrators to gain privileges and obtain access to the system mail queue by modifying the mailbox of the MDaemon user account to use the mailbox of another account.

EPSS: Низкий
github логотип

GHSA-2mg7-w9r8-29mw

4 месяца назад

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Wikimedia Foundation Mediawiki - Cargo Extension allows Stored XSS.This issue affects Mediawiki - Cargo Extension: before 3.8.7.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2mg7-924f-g32v

около 4 лет назад

The srtp_add_address function in epan/dissectors/packet-rtp.c in the RTP dissector in Wireshark 1.10.x before 1.10.7 does not properly update SRTP conversation data, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

EPSS: Низкий
github логотип

GHSA-2mg6-cgrh-mg4j

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Fix double free in error path If the uvc_status_init() function fails to allocate the int_urb, it will free the dev->status pointer but doesn't reset the pointer to NULL. This results in the kfree() call in uvc_status_cleanup() trying to double-free the memory. Fix it by resetting the dev->status pointer to NULL after freeing it. Reviewed by: Ricardo Ribalda <ribalda@chromium.org>

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2mg5-34rx-c3p8

10 месяцев назад

ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could result in arbitrary code being executed within the browsers of ServiceNow users who click on a specially crafted link. ServiceNow has addressed this vulnerability by deploying a relevant security update to the majority of hosted instances. Relevant security updates also have been provided to ServiceNow self-hosted customers, partners, and hosted customers with unique configurations. Further, the vulnerability is addressed in the listed patches and hot fixes. We recommend customers promptly apply appropriate updates or upgrade if they have not already done so.

EPSS: Низкий
github логотип

GHSA-2mg5-26r6-fpmg

больше 4 лет назад

Stack-based buffer overflow in the SymSpamHelper ActiveX component (symspam.dll) in Norton AntiSpam 2004, as used in Norton Internet Security 2004, allows remote attackers to execute arbitrary code via a long parameter to the LaunchCustomRuleWizard method.

EPSS: Средний
github логотип

GHSA-2mg4-pfgx-64cf

4 месяца назад

AVideo's WebSocket Token Never Expires Due to Commented-Out Timeout Validation in verifyTokenSocket()

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2mg4-fmh8-qqh3

9 месяцев назад

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2mg4-7347-xp3j

больше 4 лет назад

** DISPUTED ** 3Com TippingPoint IPS allows remote attackers to cause a denial of service (device hang) via a flood of packets on TCP port 80 with sequentially increasing source ports, related to a "badly written loop." NOTE: the vendor disputes this issue, stating that the product has "performed as expected with no DoS emerging."

EPSS: Низкий
github логотип

GHSA-2mg4-3x37-m4wx

больше 1 года назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-2mg3-gq68-7gq2

около 4 лет назад

An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. An arbitrary command execution vulnerability allows a malicious VRP user to execute commands with root privilege within the VRP virtual machine, related to resiliency plans and custom script functionality.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2mg3-562w-27qp

почти 3 года назад

A vulnerability in the ERS API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an affected device. To exploit this vulnerability, an attacker must have valid Administrator-level privileges on the affected device. This vulnerability is due to improper privilege management in the ERS API. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to elevate their privileges beyond the sphere of their intended access level, which would allow them to obtain sensitive information from the underlying operating system. Note: The ERS is not enabled by default. To verify the status of the ERS API in the Admin GUI, choose Administration > Settings > API Settings > API Service Settings.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-2mg2-p7r7-g27f

27 дней назад

Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2mg2-8p2q-47h9

больше 4 лет назад

Novell NetWare 5.0 allows remote attackers to cause a denial of service by flooding port 40193 with random data.

EPSS: Низкий
github логотип

GHSA-2mfx-wqj9-m26w

около 4 лет назад

IBM Security AppScan Enterprise 8.x before 8.8 sends a cleartext AppScan Source database password in a response, which allows remote authenticated users to obtain sensitive information, and subsequently conduct man-in-the-middle attacks, by examining the response content.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2mg9-59xm-chrg

The `/etc/passwd` and `/etc/shadow` files reveal hard-coded password hashes for the operating system "root" user. The credentials are shipped with the update files. There is no option for deleting or changing their passwords for an enduser. An attacker can use the credentials to log into the device. Authentication can be performed via SSH backdoor or likely via physical access (UART shell).

CVSS3: 7.7
0%
Низкий
около 1 года назад
github логотип
GHSA-2mg8-v7rr-mpqj

NVIDIA DGX Spark GB10 contains a vulnerability in OSROOT firmware, where an attacker could cause an invalid memory read. A successful exploit of this vulnerability might lead to denial of service.

CVSS3: 5.7
0%
Низкий
8 месяцев назад
github логотип
GHSA-2mg8-pqjg-f272

Buffer overflow in Labtam ProFTP 2.9 allows remote FTP servers to cause a denial of service (application crash) or execute arbitrary code via a long 220 reply (aka connection greeting or welcome message).

28%
Средний
больше 4 лет назад
github логотип
GHSA-2mg8-jrmg-qq5v

The simple-add-pages-or-posts plugin before 1.7 for WordPress has CSRF for deleting users.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2mg8-8fqw-hq49

Multiple cross-site request forgery (CSRF) vulnerabilities in the Our Team Showcase (our-team-enhanced) plugin before 1.3 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change plugin settings via unspecified vectors or (2) conduct cross-site scripting (XSS) attacks via the sc_our_team_member_count parameter in the sc_team_settings page to wp-admin/edit.php.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2mg8-3gq9-25w2

The useredit_account.wdm module in Alt-N WebAdmin 3.2.5 running with MDaemon 9.0.6, and possibly earlier versions, allows remote authenticated domain administrators to gain privileges and obtain access to the system mail queue by modifying the mailbox of the MDaemon user account to use the mailbox of another account.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2mg7-w9r8-29mw

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Wikimedia Foundation Mediawiki - Cargo Extension allows Stored XSS.This issue affects Mediawiki - Cargo Extension: before 3.8.7.

CVSS3: 6.1
0%
Низкий
4 месяца назад
github логотип
GHSA-2mg7-924f-g32v

The srtp_add_address function in epan/dissectors/packet-rtp.c in the RTP dissector in Wireshark 1.10.x before 1.10.7 does not properly update SRTP conversation data, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2mg6-cgrh-mg4j

In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Fix double free in error path If the uvc_status_init() function fails to allocate the int_urb, it will free the dev->status pointer but doesn't reset the pointer to NULL. This results in the kfree() call in uvc_status_cleanup() trying to double-free the memory. Fix it by resetting the dev->status pointer to NULL after freeing it. Reviewed by: Ricardo Ribalda <ribalda@chromium.org>

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2mg5-34rx-c3p8

ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could result in arbitrary code being executed within the browsers of ServiceNow users who click on a specially crafted link. ServiceNow has addressed this vulnerability by deploying a relevant security update to the majority of hosted instances. Relevant security updates also have been provided to ServiceNow self-hosted customers, partners, and hosted customers with unique configurations. Further, the vulnerability is addressed in the listed patches and hot fixes. We recommend customers promptly apply appropriate updates or upgrade if they have not already done so.

0%
Низкий
10 месяцев назад
github логотип
GHSA-2mg5-26r6-fpmg

Stack-based buffer overflow in the SymSpamHelper ActiveX component (symspam.dll) in Norton AntiSpam 2004, as used in Norton Internet Security 2004, allows remote attackers to execute arbitrary code via a long parameter to the LaunchCustomRuleWizard method.

67%
Средний
больше 4 лет назад
github логотип
GHSA-2mg4-pfgx-64cf

AVideo's WebSocket Token Never Expires Due to Commented-Out Timeout Validation in verifyTokenSocket()

CVSS3: 5.4
0%
Низкий
4 месяца назад
github логотип
GHSA-2mg4-fmh8-qqh3

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

CVSS3: 4.3
1%
Низкий
9 месяцев назад
github логотип
GHSA-2mg4-7347-xp3j

** DISPUTED ** 3Com TippingPoint IPS allows remote attackers to cause a denial of service (device hang) via a flood of packets on TCP port 80 with sequentially increasing source ports, related to a "badly written loop." NOTE: the vendor disputes this issue, stating that the product has "performed as expected with no DoS emerging."

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2mg4-3x37-m4wx

Rejected reason: Not used

больше 1 года назад
github логотип
GHSA-2mg3-gq68-7gq2

An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. An arbitrary command execution vulnerability allows a malicious VRP user to execute commands with root privilege within the VRP virtual machine, related to resiliency plans and custom script functionality.

CVSS3: 7.2
4%
Низкий
около 4 лет назад
github логотип
GHSA-2mg3-562w-27qp

A vulnerability in the ERS API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an affected device. To exploit this vulnerability, an attacker must have valid Administrator-level privileges on the affected device. This vulnerability is due to improper privilege management in the ERS API. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to elevate their privileges beyond the sphere of their intended access level, which would allow them to obtain sensitive information from the underlying operating system. Note: The ERS is not enabled by default. To verify the status of the ERS API in the Admin GUI, choose Administration > Settings > API Settings > API Service Settings.

CVSS3: 4.9
1%
Низкий
почти 3 года назад
github логотип
GHSA-2mg2-p7r7-g27f

Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service

CVSS3: 6.5
0%
Низкий
27 дней назад
github логотип
GHSA-2mg2-8p2q-47h9

Novell NetWare 5.0 allows remote attackers to cause a denial of service by flooding port 40193 with random data.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-2mfx-wqj9-m26w

IBM Security AppScan Enterprise 8.x before 8.8 sends a cleartext AppScan Source database password in a response, which allows remote authenticated users to obtain sensitive information, and subsequently conduct man-in-the-middle attacks, by examining the response content.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу