Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 883

Количество 353 883

github логотип

GHSA-2m76-hphm-wxpc

почти 3 года назад

Windows GDI Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2m75-q268-c73v

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in index.php in Clansys (aka Clanpage System) 1.0 and 1.1 allows remote attackers to inject arbitrary web script or HTML via the func parameter in a search function.

EPSS: Низкий
github логотип

GHSA-2m75-32f4-6fhr

около 4 лет назад

There is an Uninitialized variable vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause transmission of invalid data.

EPSS: Низкий
github логотип

GHSA-2m74-x26c-g7xc

около 4 лет назад

Missing permission checks in Mac Plugin

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2m74-3p45-9q47

больше 1 года назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий
github логотип

GHSA-2m74-3m4w-28q3

около 4 лет назад

Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-2m73-2hpg-2q56

больше 3 лет назад

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information. In some cases, it is also possible to cause a temporary availability impact to portions of the FMC Dashboard.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2m72-x5wj-734p

около 4 лет назад

The instruction decoder in arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel before 3.18-rc2 does not properly handle invalid instructions, which allows guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) via a crafted application that triggers (1) an improperly fetched instruction or (2) an instruction that occupies too many bytes. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-8480.

EPSS: Низкий
github логотип

GHSA-2m72-p55q-qgr7

около 4 лет назад

ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a file inclusion vulnerability. Successful exploitation could lead to arbitrary code execution of files located in the webroot or its subdirectory.

EPSS: Низкий
github логотип

GHSA-2m72-m5cw-3g9h

около 4 лет назад

Missing permission check in Moodle

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2m72-4x6w-fqpx

около 4 лет назад

A sandbox escape issue was discovered in VyOS 1.1.8. It provides a restricted management shell for operator users to administer the device. By issuing various shell special characters with certain commands, an authenticated operator user can break out of the management shell and gain access to the underlying Linux shell. The user can then run arbitrary operating system commands with the privileges afforded by their account.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-2m6x-j88f-83rx

около 4 лет назад

IBM Sterling File Gateway does not properly restrict user requests based on permission level. This allows for users to update data related to other users, by manipulating the parameters passed in the POST request. IBM X-Force ID: 126060.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2m6w-7qwv-3jcx

2 месяца назад

FlexRIC v2.0.0 contains reachable assert(0) calls in stub message handlers for whitelisted but unimplemented E2AP message types in the near-RT RIC. A remote unauthenticated attacker can send a decodable E2AP PDU of such a type (e.g., E2nodeConfigurationUpdate) to crash the near-RT RIC process (port 36421) via SIGABRT. The message passes whitelist validation but triggers an unconditional assertion in the handler.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2m6w-285w-23qv

около 4 лет назад

A crafted NTFS image can cause an out-of-bounds read in ntfs_ie_lookup in NTFS-3G < 2021.8.22.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2m6v-xpgq-6gwv

около 4 лет назад

Edimax BR-6208AC V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. They forward ARP requests, which are sent as broadcast packets, between the host and the guest networks. To use this leakage as a direct covert channel, the sender can trivially issue an ARP request to an arbitrary computer on the network. (In general, some routers restrict ARP forwarding only to requests destined for the network's subnet mask, but these routers did not restrict this traffic in any way. Depending on this factor, one must use either the lower 8 bits of the IP address, or the entire 32 bits, as the data payload.)

EPSS: Низкий
github логотип

GHSA-2m6v-mggf-5f9g

около 4 лет назад

Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2m6v-8g4p-879p

12 дней назад

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise CS Campus Community accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2m6r-pj86-q7hh

около 1 года назад

Improper input validation in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2m6q-rj94-6952

около 3 лет назад

An issue has been discovered in GitLab CE/EE affecting all versions from 8.6 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. File integrity may be compromised when source code or installation packages are pulled from a tag or from a release containing a ref to another commit.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-2m6q-934x-xjrf

больше 4 лет назад

Multiple issues were addressed by updating to curl version 7.79.1. This issue is fixed in macOS Monterey 12.3. Multiple issues in curl.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2m76-hphm-wxpc

Windows GDI Elevation of Privilege Vulnerability

CVSS3: 7.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-2m75-q268-c73v

Cross-site scripting (XSS) vulnerability in index.php in Clansys (aka Clanpage System) 1.0 and 1.1 allows remote attackers to inject arbitrary web script or HTML via the func parameter in a search function.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2m75-32f4-6fhr

There is an Uninitialized variable vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause transmission of invalid data.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2m74-x26c-g7xc

Missing permission checks in Mac Plugin

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-2m74-3p45-9q47

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

больше 1 года назад
github логотип
GHSA-2m74-3m4w-28q3

Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."

CVSS3: 8.8
26%
Средний
около 4 лет назад
github логотип
GHSA-2m73-2hpg-2q56

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit these vulnerabilities by inserting crafted input into various data fields in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface, or access sensitive, browser-based information. In some cases, it is also possible to cause a temporary availability impact to portions of the FMC Dashboard.

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2m72-x5wj-734p

The instruction decoder in arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel before 3.18-rc2 does not properly handle invalid instructions, which allows guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) via a crafted application that triggers (1) an improperly fetched instruction or (2) an instruction that occupies too many bytes. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-8480.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2m72-p55q-qgr7

ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a file inclusion vulnerability. Successful exploitation could lead to arbitrary code execution of files located in the webroot or its subdirectory.

7%
Низкий
около 4 лет назад
github логотип
GHSA-2m72-m5cw-3g9h

Missing permission check in Moodle

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-2m72-4x6w-fqpx

A sandbox escape issue was discovered in VyOS 1.1.8. It provides a restricted management shell for operator users to administer the device. By issuing various shell special characters with certain commands, an authenticated operator user can break out of the management shell and gain access to the underlying Linux shell. The user can then run arbitrary operating system commands with the privileges afforded by their account.

CVSS3: 9.9
2%
Низкий
около 4 лет назад
github логотип
GHSA-2m6x-j88f-83rx

IBM Sterling File Gateway does not properly restrict user requests based on permission level. This allows for users to update data related to other users, by manipulating the parameters passed in the POST request. IBM X-Force ID: 126060.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-2m6w-7qwv-3jcx

FlexRIC v2.0.0 contains reachable assert(0) calls in stub message handlers for whitelisted but unimplemented E2AP message types in the near-RT RIC. A remote unauthenticated attacker can send a decodable E2AP PDU of such a type (e.g., E2nodeConfigurationUpdate) to crash the near-RT RIC process (port 36421) via SIGABRT. The message passes whitelist validation but triggers an unconditional assertion in the handler.

CVSS3: 7.5
0%
Низкий
2 месяца назад
github логотип
GHSA-2m6w-285w-23qv

A crafted NTFS image can cause an out-of-bounds read in ntfs_ie_lookup in NTFS-3G < 2021.8.22.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-2m6v-xpgq-6gwv

Edimax BR-6208AC V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. They forward ARP requests, which are sent as broadcast packets, between the host and the guest networks. To use this leakage as a direct covert channel, the sender can trivially issue an ARP request to an arbitrary computer on the network. (In general, some routers restrict ARP forwarding only to requests destined for the network's subnet mask, but these routers did not restrict this traffic in any way. Depending on this factor, one must use either the lower 8 bits of the IP address, or the entire 32 bits, as the data payload.)

1%
Низкий
около 4 лет назад
github логотип
GHSA-2m6v-mggf-5f9g

Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2m6v-8g4p-879p

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise CS Campus Community accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVSS3: 5.3
0%
Низкий
12 дней назад
github логотип
GHSA-2m6r-pj86-q7hh

Improper input validation in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-2m6q-rj94-6952

An issue has been discovered in GitLab CE/EE affecting all versions from 8.6 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. File integrity may be compromised when source code or installation packages are pulled from a tag or from a release containing a ref to another commit.

CVSS3: 5.7
1%
Низкий
около 3 лет назад
github логотип
GHSA-2m6q-934x-xjrf

Multiple issues were addressed by updating to curl version 7.79.1. This issue is fixed in macOS Monterey 12.3. Multiple issues in curl.

CVSS3: 9.8
больше 4 лет назад

Уязвимостей на страницу