Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 373 892

Количество 373 892

github логотип

GHSA-3p42-w5ch-gg42

3 месяца назад

TYPO3 CMS has an Open Redirect Vulnerability via Core Utilities

EPSS: Низкий
github логотип

GHSA-3p42-c2wq-v9gc

около 3 лет назад

A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary JavaScript code via a vulnerable delete_file parameter.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3p42-8gxw-6cw4

больше 4 лет назад

Stack-based buffer overflow in gen_jumpex.dll in Winamp before 5.64 Build 3418 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a package with a long Skin directory name. NOTE: a second buffer overflow involving a long GUI Search field to ml_local.dll was also reported. However, since it is only exploitable by the user of the application, this issue would not cross privilege boundaries unless Winamp is running under a highly restricted environment such as a kiosk.

EPSS: Средний
github логотип

GHSA-3p42-7grr-wj6x

больше 4 лет назад

HPE Universal CMDB 10.0 through 10.21, Universal CMDB Configuration Manager 10.0 through 10.21, and Universal Discovery 10.0 through 10.21 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3p3x-vg38-6g9q

около 3 лет назад

Issue summary: Checking excessively long DH keys or parameters may be very slow. Impact summary: Applications that use the functions DH_check(), DH_check_ex() or EVP_PKEY_param_check() to check a DH key or DH parameters may experience long delays. Where the key or parameters that are being checked have been obtained from an untrusted source this may lead to a Denial of Service. The function DH_check() performs various checks on DH parameters. One of those checks confirms that the modulus ('p' parameter) is not too large. Trying to use a very large modulus is slow and OpenSSL will not normally use a modulus which is over 10,000 bits in length. However the DH_check() function checks numerous aspects of the key or parameters that have been supplied. Some of those checks use the supplied modulus value even if it has already been found to be too large. An application that calls DH_check() and supplies a key or parameters obtained from an untrusted source could be vulernable to a Deni...

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3p3x-8v96-cq98

11 месяцев назад

A vulnerability was found in Campcodes Online Apartment Visitor Management System 1.0. Impacted is an unknown function of the file /admin-profile.php. Performing manipulation of the argument mobilenumber results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-3p3w-92gc-7p27

больше 4 лет назад

Buffer overflow in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor 4000 & 5000 Series Processors may allow an authenticated user to potentially enable elevation of privilege or denial of service via adjacent access.

EPSS: Низкий
github логотип

GHSA-3p3w-8fvr-q4gw

больше 4 лет назад

Multiple unspecified vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31 and earlier allow remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

EPSS: Низкий
github логотип

GHSA-3p3v-qhpw-qrgr

5 месяцев назад

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stun-user parameter to /cgi-bin/cstecgi.cgi.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3p3r-fjqw-f7g3

больше 4 лет назад

A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.3 and iPadOS 13.3, watchOS 6.1.1, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, tvOS 13.3. An application may be able to execute arbitrary code with kernel privileges.

EPSS: Низкий
github логотип

GHSA-3p3q-w36v-m4vj

больше 4 лет назад

Buffer overflow in the Multimedia PC Client in Nortel Multimedia Communication Server (MCS) before Maintenance Release 3.5.8.3 and 4.0.25.3 allows remote attackers to cause a denial of service (crash) via a flood of "extraneous" messages, as demonstrated by the Nessus "Generic flood" denial of service plugin.

EPSS: Низкий
github логотип

GHSA-3p3q-5gjp-wvmc

больше 1 года назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

EPSS: Низкий
github логотип

GHSA-3p3p-qg5g-j2p5

больше 4 лет назад

SQL injection vulnerability in view.php in Butterfly Organizer 2.0.1 allows remote attackers to execute arbitrary SQL commands via the mytable parameter. NOTE: the id vector is covered by another CVE name.

EPSS: Низкий
github логотип

GHSA-3p3p-pvm7-cggr

больше 4 лет назад

Winston 1.5.4 devices are vulnerable to command injection via the API.

EPSS: Низкий
github логотип

GHSA-3p3p-cgj7-vgw3

больше 2 лет назад

RSSHub vulnerable to Server-Side Request Forgery

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3p3m-mqcr-8mfw

около 3 лет назад

Inappropriate implementation in Cast UI in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to spoof browser UI via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3p3m-h26v-9r73

около 4 лет назад

The Quectel RG502Q-EA modem before 2022-02-23 allow OS Command Injection.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3p3m-4x7c-p4pw

4 месяца назад

unsafe parameter handing in `wsrep_notify_cmd`

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-3p3h-qghp-hvh2

больше 5 лет назад

Open Redirect in werkzeug

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3p3h-j9q4-q239

почти 2 года назад

Incorrect access control in the firmware update and download processes of IVY Smart v4.5.0 allows attackers to access sensitive information by analyzing the code and data within the APK file.

CVSS3: 8.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3p42-w5ch-gg42

TYPO3 CMS has an Open Redirect Vulnerability via Core Utilities

0%
Низкий
3 месяца назад
github логотип
GHSA-3p42-c2wq-v9gc

A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary JavaScript code via a vulnerable delete_file parameter.

CVSS3: 5.4
1%
Низкий
около 3 лет назад
github логотип
GHSA-3p42-8gxw-6cw4

Stack-based buffer overflow in gen_jumpex.dll in Winamp before 5.64 Build 3418 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a package with a long Skin directory name. NOTE: a second buffer overflow involving a long GUI Search field to ml_local.dll was also reported. However, since it is only exploitable by the user of the application, this issue would not cross privilege boundaries unless Winamp is running under a highly restricted environment such as a kiosk.

17%
Средний
больше 4 лет назад
github логотип
GHSA-3p42-7grr-wj6x

HPE Universal CMDB 10.0 through 10.21, Universal CMDB Configuration Manager 10.0 through 10.21, and Universal Discovery 10.0 through 10.21 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

CVSS3: 9.8
5%
Низкий
больше 4 лет назад
github логотип
GHSA-3p3x-vg38-6g9q

Issue summary: Checking excessively long DH keys or parameters may be very slow. Impact summary: Applications that use the functions DH_check(), DH_check_ex() or EVP_PKEY_param_check() to check a DH key or DH parameters may experience long delays. Where the key or parameters that are being checked have been obtained from an untrusted source this may lead to a Denial of Service. The function DH_check() performs various checks on DH parameters. One of those checks confirms that the modulus ('p' parameter) is not too large. Trying to use a very large modulus is slow and OpenSSL will not normally use a modulus which is over 10,000 bits in length. However the DH_check() function checks numerous aspects of the key or parameters that have been supplied. Some of those checks use the supplied modulus value even if it has already been found to be too large. An application that calls DH_check() and supplies a key or parameters obtained from an untrusted source could be vulernable to a Deni...

CVSS3: 5.3
7%
Низкий
около 3 лет назад
github логотип
GHSA-3p3x-8v96-cq98

A vulnerability was found in Campcodes Online Apartment Visitor Management System 1.0. Impacted is an unknown function of the file /admin-profile.php. Performing manipulation of the argument mobilenumber results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.

CVSS3: 4.7
0%
Низкий
11 месяцев назад
github логотип
GHSA-3p3w-92gc-7p27

Buffer overflow in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor 4000 & 5000 Series Processors may allow an authenticated user to potentially enable elevation of privilege or denial of service via adjacent access.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3p3w-8fvr-q4gw

Multiple unspecified vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31 and earlier allow remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-3p3v-qhpw-qrgr

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stun-user parameter to /cgi-bin/cstecgi.cgi.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-3p3r-fjqw-f7g3

A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.3 and iPadOS 13.3, watchOS 6.1.1, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, tvOS 13.3. An application may be able to execute arbitrary code with kernel privileges.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3p3q-w36v-m4vj

Buffer overflow in the Multimedia PC Client in Nortel Multimedia Communication Server (MCS) before Maintenance Release 3.5.8.3 and 4.0.25.3 allows remote attackers to cause a denial of service (crash) via a flood of "extraneous" messages, as demonstrated by the Nessus "Generic flood" denial of service plugin.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3p3q-5gjp-wvmc

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

больше 1 года назад
github логотип
GHSA-3p3p-qg5g-j2p5

SQL injection vulnerability in view.php in Butterfly Organizer 2.0.1 allows remote attackers to execute arbitrary SQL commands via the mytable parameter. NOTE: the id vector is covered by another CVE name.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3p3p-pvm7-cggr

Winston 1.5.4 devices are vulnerable to command injection via the API.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-3p3p-cgj7-vgw3

RSSHub vulnerable to Server-Side Request Forgery

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3p3m-mqcr-8mfw

Inappropriate implementation in Cast UI in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to spoof browser UI via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 4.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-3p3m-h26v-9r73

The Quectel RG502Q-EA modem before 2022-02-23 allow OS Command Injection.

CVSS3: 9.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-3p3m-4x7c-p4pw

unsafe parameter handing in `wsrep_notify_cmd`

CVSS3: 10
2%
Низкий
4 месяца назад
github логотип
GHSA-3p3h-qghp-hvh2

Open Redirect in werkzeug

CVSS3: 6.1
2%
Низкий
больше 5 лет назад
github логотип
GHSA-3p3h-j9q4-q239

Incorrect access control in the firmware update and download processes of IVY Smart v4.5.0 allows attackers to access sensitive information by analyzing the code and data within the APK file.

CVSS3: 8.4
0%
Низкий
почти 2 года назад

Уязвимостей на страницу