Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 883

Количество 353 883

github логотип

GHSA-2mfx-gf42-jf89

больше 4 лет назад

SQL injection vulnerability in directory.php in Prozilla Hosting Index, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.

EPSS: Низкий
github логотип

GHSA-2mfw-qmh9-qc8p

около 4 лет назад

SQL injection vulnerability in d4d/statusFilter.php in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.2 allows remote authenticated users to execute arbitrary SQL commands via the q parameter.

EPSS: Средний
github логотип

GHSA-2mfw-8h6x-jgc4

больше 2 лет назад

Command Injection vulnerability in D-Link Dir 816 with firmware version DIR-816_A2_v1.10CNB04 allows attackers to run arbitrary commands via the urlAdd parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2mfv-hhmv-9rh8

около 4 лет назад

An issue was discovered in Open-iSCSI through 2.0.875. A local attacker can cause the iscsiuio server to abort or potentially execute code by sending messages with incorrect lengths, which (due to lack of checking) can lead to buffer overflows, and result in aborts (with overflow checking enabled) or code execution. The process_iscsid_broadcast function in iscsiuio/src/unix/iscsid_ipc.c does not validate the payload length before a write operation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2mfv-2f5w-p9fq

больше 4 лет назад

pearweb < 1.32 is suffers from a Weak Password Recovery Mechanism via include/users/passwordmanage.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2mfr-qhwc-4wp2

около 3 лет назад

In affected versions of Octopus Deploy it is possible for a low privileged guest user to interact with extension endpoints.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2mfq-w3fm-wxm3

около 4 лет назад

Emby Server is a personal media server with apps on many devices. In Emby Server on Windows there is a set of arbitrary file read vulnerabilities. This vulnerability is known to exist in version 4.6.4.0 and may not be patched in later versions. Known vulnerable routes are /Videos/Id/hls/PlaylistId/SegmentId.SegmentContainer, /Images/Ratings/theme/name and /Images/MediaInfo/theme/name. For more details including proof of concept code, refer to the referenced GHSL-2021-051. This issue may lead to unauthorized access to the system especially when Emby Server is configured to be accessible from the Internet.

EPSS: Низкий
github логотип

GHSA-2mfp-xhwj-f686

больше 1 года назад

Substance3D - Painter versions 10.1.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2mfp-vqrw-7p7v

около 2 месяцев назад

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2mfm-m7q3-xch8

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix READDIR buffer overflow If a client sends a READDIR count argument that is too small (say, zero), then the buffer size calculation in the new init_dirlist helper functions results in an underflow, allowing the XDR stream functions to write beyond the actual buffer. This calculation has always been suspect. NFSD has never sanity- checked the READDIR count argument, but the old entry encoders managed the problem correctly. With the commits below, entry encoding changed, exposing the underflow to the pointer arithmetic in xdr_reserve_space(). Modern NFS clients attempt to retrieve as much data as possible for each READDIR request. Also, we have no unit tests that exercise the behavior of READDIR at the lower bound of @count values. Thus this case was missed during testing.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2mfj-xm96-46wm

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: ice: Fix improper handling of refcount in ice_sriov_set_msix_vec_count() This patch addresses an issue with improper reference count handling in the ice_sriov_set_msix_vec_count() function. First, the function calls ice_get_vf_by_id(), which increments the reference count of the vf pointer. If the subsequent call to ice_get_vf_vsi() fails, the function currently returns an error without decrementing the reference count of the vf pointer, leading to a reference count leak. The correct behavior, as implemented in this patch, is to decrement the reference count using ice_put_vf(vf) before returning an error when vsi is NULL. Second, the function calls ice_sriov_get_irqs(), which sets vf->first_vector_idx. If this call returns a negative value, indicating an error, the function returns an error without decrementing the reference count of the vf pointer, resulting in another reference count leak. The patch addresses ...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2mfj-w9xr-gff7

почти 4 года назад

EC-CUBE plugin 'Product Image Bulk Upload Plugin' 1.0.0 and 4.1.0 contains an insufficient verification vulnerability when uploading files. Exploiting this vulnerability allows a remote unauthenticated attacker to upload arbitrary files other than image files. If a user with an administrative privilege of EC-CUBE where the vulnerable plugin is installed is led to upload a specially crafted file, an arbitrary script may be executed on the system.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2mfj-vmvj-q937

около 4 лет назад

x86 pv: Race condition in typeref acquisition Xen maintains a type reference count for pages, in addition to a regular reference count. This scheme is used to maintain invariants required for Xen's safety, e.g. PV guests may not have direct writeable access to pagetables; updates need auditing by Xen. Unfortunately, the logic for acquiring a type reference has a race condition, whereby a safely TLB flush is issued too early and creates a window where the guest can re-establish the read/write mapping before writeability is prohibited.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2mfj-r695-5h9r

4 месяца назад

Dolibarr Core Discloses Sensitive Data via Authenticated Local File Inclusion in selectobject.php

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2mfj-g9qp-83p8

почти 2 года назад

Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-2mfj-6r2j-3g4m

почти 4 года назад

A logic issue was addressed with improved state management. This issue is fixed in Safari 15.6, macOS Monterey 12.5. A user may be tracked through their IP address.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2mfh-qqrx-9f28

больше 4 лет назад

Cisco IOS after 12.3(14)T, 12.3(8)YC1, 12.3(8)YG, and 12.4, with voice support and without Session Initiated Protocol (SIP) configured, allows remote attackers to cause a denial of service (crash) by sending a crafted packet to port 5060/UDP.

EPSS: Низкий
github логотип

GHSA-2mfh-jhf2-vx33

около 4 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14529.

EPSS: Средний
github логотип

GHSA-2mfh-952f-g7hg

больше 4 лет назад

Unspecified vulnerability in Open System Services (OSS) Name Server on HP NonStop G06.27, G06.28, G06.29, G06.30, H06.06, H06.07, H06.08, and J06.03 allows remote attackers to obtain sensitive information via unknown vectors.

EPSS: Низкий
github логотип

GHSA-2mfh-8q3p-3q36

около 4 лет назад

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to arbitrary delete a directory caused by improper validation of user-supplied input. IBM X-Force ID: 175026.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2mfx-gf42-jf89

SQL injection vulnerability in directory.php in Prozilla Hosting Index, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2mfw-qmh9-qc8p

SQL injection vulnerability in d4d/statusFilter.php in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.2 allows remote authenticated users to execute arbitrary SQL commands via the q parameter.

67%
Средний
около 4 лет назад
github логотип
GHSA-2mfw-8h6x-jgc4

Command Injection vulnerability in D-Link Dir 816 with firmware version DIR-816_A2_v1.10CNB04 allows attackers to run arbitrary commands via the urlAdd parameter.

CVSS3: 9.8
2%
Низкий
больше 2 лет назад
github логотип
GHSA-2mfv-hhmv-9rh8

An issue was discovered in Open-iSCSI through 2.0.875. A local attacker can cause the iscsiuio server to abort or potentially execute code by sending messages with incorrect lengths, which (due to lack of checking) can lead to buffer overflows, and result in aborts (with overflow checking enabled) or code execution. The process_iscsid_broadcast function in iscsiuio/src/unix/iscsid_ipc.c does not validate the payload length before a write operation.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-2mfv-2f5w-p9fq

pearweb < 1.32 is suffers from a Weak Password Recovery Mechanism via include/users/passwordmanage.php.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2mfr-qhwc-4wp2

In affected versions of Octopus Deploy it is possible for a low privileged guest user to interact with extension endpoints.

CVSS3: 5.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-2mfq-w3fm-wxm3

Emby Server is a personal media server with apps on many devices. In Emby Server on Windows there is a set of arbitrary file read vulnerabilities. This vulnerability is known to exist in version 4.6.4.0 and may not be patched in later versions. Known vulnerable routes are /Videos/Id/hls/PlaylistId/SegmentId.SegmentContainer, /Images/Ratings/theme/name and /Images/MediaInfo/theme/name. For more details including proof of concept code, refer to the referenced GHSL-2021-051. This issue may lead to unauthorized access to the system especially when Emby Server is configured to be accessible from the Internet.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2mfp-xhwj-f686

Substance3D - Painter versions 10.1.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2mfp-vqrw-7p7v

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2mfm-m7q3-xch8

In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix READDIR buffer overflow If a client sends a READDIR count argument that is too small (say, zero), then the buffer size calculation in the new init_dirlist helper functions results in an underflow, allowing the XDR stream functions to write beyond the actual buffer. This calculation has always been suspect. NFSD has never sanity- checked the READDIR count argument, but the old entry encoders managed the problem correctly. With the commits below, entry encoding changed, exposing the underflow to the pointer arithmetic in xdr_reserve_space(). Modern NFS clients attempt to retrieve as much data as possible for each READDIR request. Also, we have no unit tests that exercise the behavior of READDIR at the lower bound of @count values. Thus this case was missed during testing.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2mfj-xm96-46wm

In the Linux kernel, the following vulnerability has been resolved: ice: Fix improper handling of refcount in ice_sriov_set_msix_vec_count() This patch addresses an issue with improper reference count handling in the ice_sriov_set_msix_vec_count() function. First, the function calls ice_get_vf_by_id(), which increments the reference count of the vf pointer. If the subsequent call to ice_get_vf_vsi() fails, the function currently returns an error without decrementing the reference count of the vf pointer, leading to a reference count leak. The correct behavior, as implemented in this patch, is to decrement the reference count using ice_put_vf(vf) before returning an error when vsi is NULL. Second, the function calls ice_sriov_get_irqs(), which sets vf->first_vector_idx. If this call returns a negative value, indicating an error, the function returns an error without decrementing the reference count of the vf pointer, resulting in another reference count leak. The patch addresses ...

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-2mfj-w9xr-gff7

EC-CUBE plugin 'Product Image Bulk Upload Plugin' 1.0.0 and 4.1.0 contains an insufficient verification vulnerability when uploading files. Exploiting this vulnerability allows a remote unauthenticated attacker to upload arbitrary files other than image files. If a user with an administrative privilege of EC-CUBE where the vulnerable plugin is installed is led to upload a specially crafted file, an arbitrary script may be executed on the system.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-2mfj-vmvj-q937

x86 pv: Race condition in typeref acquisition Xen maintains a type reference count for pages, in addition to a regular reference count. This scheme is used to maintain invariants required for Xen's safety, e.g. PV guests may not have direct writeable access to pagetables; updates need auditing by Xen. Unfortunately, the logic for acquiring a type reference has a race condition, whereby a safely TLB flush is issued too early and creates a window where the guest can re-establish the read/write mapping before writeability is prohibited.

CVSS3: 6.4
0%
Низкий
около 4 лет назад
github логотип
GHSA-2mfj-r695-5h9r

Dolibarr Core Discloses Sensitive Data via Authenticated Local File Inclusion in selectobject.php

CVSS3: 6.5
1%
Низкий
4 месяца назад
github логотип
GHSA-2mfj-g9qp-83p8

Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information.

CVSS3: 7.5
47%
Средний
почти 2 года назад
github логотип
GHSA-2mfj-6r2j-3g4m

A logic issue was addressed with improved state management. This issue is fixed in Safari 15.6, macOS Monterey 12.5. A user may be tracked through their IP address.

CVSS3: 5.3
1%
Низкий
почти 4 года назад
github логотип
GHSA-2mfh-qqrx-9f28

Cisco IOS after 12.3(14)T, 12.3(8)YC1, 12.3(8)YG, and 12.4, with voice support and without Session Initiated Protocol (SIP) configured, allows remote attackers to cause a denial of service (crash) by sending a crafted packet to port 5060/UDP.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-2mfh-jhf2-vx33

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14529.

38%
Средний
около 4 лет назад
github логотип
GHSA-2mfh-952f-g7hg

Unspecified vulnerability in Open System Services (OSS) Name Server on HP NonStop G06.27, G06.28, G06.29, G06.30, H06.06, H06.07, H06.08, and J06.03 allows remote attackers to obtain sensitive information via unknown vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2mfh-8q3p-3q36

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to arbitrary delete a directory caused by improper validation of user-supplied input. IBM X-Force ID: 175026.

2%
Низкий
около 4 лет назад

Уязвимостей на страницу