Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 883

Количество 353 883

github логотип

GHSA-2m66-w9x8-6hfm

больше 4 лет назад

SQL injection vulnerability in army.php in supersmashbrothers (SSB) Army System 2.1.0 for Invision Power Board (IPB) allows remote attackers to execute arbitrary SQL commands via the userstat parameter in an army action to index.php.

EPSS: Низкий
github логотип

GHSA-2m65-xxr3-mhcv

около 1 месяца назад

Insufficient policy enforcement in Web Authentication (Passkeys & Security Keys) in Google Chrome on iOS prior to 150.0.7871.47 allowed an attacker in a privileged network position to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2m65-m65r-c7gq

около 4 лет назад

cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in PostgresAdmin (SEC-313).

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2m65-m22p-9wjw

почти 4 года назад

Duplicate Advisory: .NET Information Disclosure Vulnerability

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2m65-7fpj-78p9

6 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: hwmon: (acpi_power_meter) Fix deadlocks related to acpi_power_meter_notify() The acpi_power_meter driver's .notify() callback function, acpi_power_meter_notify(), calls hwmon_device_unregister() under a lock that is also acquired by callbacks in sysfs attributes of the device being unregistered which is prone to deadlocks between sysfs access and device removal. Address this by moving the hwmon device removal in acpi_power_meter_notify() outside the lock in question, but notice that doing it alone is not sufficient because two concurrent METER_NOTIFY_CONFIG notifications may be attempting to remove the same device at the same time. To prevent that from happening, add a new lock serializing the execution of the switch () statement in acpi_power_meter_notify(). For simplicity, it is a static mutex which should not be a problem from the performance perspective. The new lock also allows the hwmon_device_register_w...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2m64-whjh-g4f5

около 4 лет назад

Advantech WebAccess before 8.4.3 allows unauthenticated remote attackers to execute arbitrary code or cause a denial of service (memory corruption) due to a stack-based buffer overflow when handling IOCTL 70533 RPC messages.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2m64-484g-392f

около 4 лет назад

The Bi-directional driver in IDM 4.5 before 4.0.3.0 could be susceptible to a denial of service attack.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2m63-hj6g-hcv7

около 4 лет назад

Splunk 5.0.3 has an Unquoted Service Path in Windows for Universal Forwarder which can allow an attacker to escalate privileges

EPSS: Низкий
github логотип

GHSA-2m63-3w8x-5q36

больше 4 лет назад

Unspecified vulnerability in passwordserver in Mac OS X Server 10.3.9 and 10.4.3, when creating an Open Directory master server, allows local users to gain privileges via unknown attack vectors.

EPSS: Низкий
github логотип

GHSA-2m62-r3gq-8m9j

около 4 лет назад

The confirm_create_account function in the account-creation feature in token.cgi in Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 does not specify a scalar context for the realname parameter, which allows remote attackers to create accounts with unverified e-mail addresses by sending three realname values with realname=login_name as the second, as demonstrated by selecting an e-mail address with a domain name for which group privileges are automatically granted.

EPSS: Низкий
github логотип

GHSA-2m62-mq6r-h972

8 месяцев назад

Primakon Pi Portal 1.0.18 API endpoints fail to enforce sufficient authorization checks when processing requests. Specifically, a standard user can exploit this flaw by sending direct HTTP requests to administrative endpoints, bypassing the UI restrictions. This allows the attacker to manipulate data outside their assigned scope, including: Unauthorized Account modification, modifying/deleting arbitrary user accounts and changing passwords by sending a direct request to the user management API endpoint; Confidential Data Access, accessing and downloading sensitive organizational documents via a direct request to the document retrieval API; Privilege escalation, This vulnerability can lead to complete compromise of data integrity and confidentiality, and Privilege Escalation by manipulating core system functions.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2m5x-xrc7-mrxp

больше 3 лет назад

Planet eStream before 6.72.10.07 allows unauthenticated upload of arbitrary files: Choose a Video / Related Media or Upload Document. Upload2.ashx can be used, or Ajax.asmx/ProcessUpload2. This leads to remote code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2m5x-r2g7-72x8

больше 2 лет назад

In Splunk Add-on Builder versions below 4.1.4, the app writes sensitive information to internal log files.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-2m5x-jqmf-gr49

около 4 лет назад

In the Linux kernel before 5.3.11, there is an info-leak bug that can be caused by a malicious USB device in the drivers/net/can/usb/peak_usb/pcan_usb_core.c driver, aka CID-f7a1337f0d29.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-2m5x-4wp5-g3mp

11 месяцев назад

In startSpaActivityForApp of SpaActivity.kt, there is a possible cross-user permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2m5w-88gg-379g

больше 3 лет назад

There is a SQL injection vulnerability in ZTE MF286R. Due to insufficient validation of the input parameters of the phonebook interface, an authenticated attacker could use the vulnerability to execute arbitrary SQL injection.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-2m5v-qw26-9cmh

почти 4 года назад

IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e20.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2m5v-p53f-hgfp

около 4 лет назад

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112050983

EPSS: Низкий
github логотип

GHSA-2m5r-g595-364q

9 месяцев назад

A buffer overflow in the UPnP service of Tenda AC8 Hardware v03.03.10.01 allows attackers to cause a Denial of Service (DoS) via supplying a crafted packet.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2m5q-52fx-w72m

около 4 лет назад

The kernel extension in Cisco AnyConnect Secure Mobility Client 4.0(2049) on OS X allows local users to cause a denial of service (panic) via vectors involving contiguous memory locations, aka Bug ID CSCut12255.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2m66-w9x8-6hfm

SQL injection vulnerability in army.php in supersmashbrothers (SSB) Army System 2.1.0 for Invision Power Board (IPB) allows remote attackers to execute arbitrary SQL commands via the userstat parameter in an army action to index.php.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2m65-xxr3-mhcv

Insufficient policy enforcement in Web Authentication (Passkeys & Security Keys) in Google Chrome on iOS prior to 150.0.7871.47 allowed an attacker in a privileged network position to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-2m65-m65r-c7gq

cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in PostgresAdmin (SEC-313).

CVSS3: 7.2
2%
Низкий
около 4 лет назад
github логотип
GHSA-2m65-m22p-9wjw

Duplicate Advisory: .NET Information Disclosure Vulnerability

CVSS3: 5.9
почти 4 года назад
github логотип
GHSA-2m65-7fpj-78p9

In the Linux kernel, the following vulnerability has been resolved: hwmon: (acpi_power_meter) Fix deadlocks related to acpi_power_meter_notify() The acpi_power_meter driver's .notify() callback function, acpi_power_meter_notify(), calls hwmon_device_unregister() under a lock that is also acquired by callbacks in sysfs attributes of the device being unregistered which is prone to deadlocks between sysfs access and device removal. Address this by moving the hwmon device removal in acpi_power_meter_notify() outside the lock in question, but notice that doing it alone is not sufficient because two concurrent METER_NOTIFY_CONFIG notifications may be attempting to remove the same device at the same time. To prevent that from happening, add a new lock serializing the execution of the switch () statement in acpi_power_meter_notify(). For simplicity, it is a static mutex which should not be a problem from the performance perspective. The new lock also allows the hwmon_device_register_w...

CVSS3: 5.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-2m64-whjh-g4f5

Advantech WebAccess before 8.4.3 allows unauthenticated remote attackers to execute arbitrary code or cause a denial of service (memory corruption) due to a stack-based buffer overflow when handling IOCTL 70533 RPC messages.

CVSS3: 9.8
4%
Низкий
около 4 лет назад
github логотип
GHSA-2m64-484g-392f

The Bi-directional driver in IDM 4.5 before 4.0.3.0 could be susceptible to a denial of service attack.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2m63-hj6g-hcv7

Splunk 5.0.3 has an Unquoted Service Path in Windows for Universal Forwarder which can allow an attacker to escalate privileges

0%
Низкий
около 4 лет назад
github логотип
GHSA-2m63-3w8x-5q36

Unspecified vulnerability in passwordserver in Mac OS X Server 10.3.9 and 10.4.3, when creating an Open Directory master server, allows local users to gain privileges via unknown attack vectors.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-2m62-r3gq-8m9j

The confirm_create_account function in the account-creation feature in token.cgi in Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 does not specify a scalar context for the realname parameter, which allows remote attackers to create accounts with unverified e-mail addresses by sending three realname values with realname=login_name as the second, as demonstrated by selecting an e-mail address with a domain name for which group privileges are automatically granted.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2m62-mq6r-h972

Primakon Pi Portal 1.0.18 API endpoints fail to enforce sufficient authorization checks when processing requests. Specifically, a standard user can exploit this flaw by sending direct HTTP requests to administrative endpoints, bypassing the UI restrictions. This allows the attacker to manipulate data outside their assigned scope, including: Unauthorized Account modification, modifying/deleting arbitrary user accounts and changing passwords by sending a direct request to the user management API endpoint; Confidential Data Access, accessing and downloading sensitive organizational documents via a direct request to the document retrieval API; Privilege escalation, This vulnerability can lead to complete compromise of data integrity and confidentiality, and Privilege Escalation by manipulating core system functions.

CVSS3: 5.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-2m5x-xrc7-mrxp

Planet eStream before 6.72.10.07 allows unauthenticated upload of arbitrary files: Choose a Video / Related Media or Upload Document. Upload2.ashx can be used, or Ajax.asmx/ProcessUpload2. This leads to remote code execution.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2m5x-r2g7-72x8

In Splunk Add-on Builder versions below 4.1.4, the app writes sensitive information to internal log files.

CVSS3: 8.2
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2m5x-jqmf-gr49

In the Linux kernel before 5.3.11, there is an info-leak bug that can be caused by a malicious USB device in the drivers/net/can/usb/peak_usb/pcan_usb_core.c driver, aka CID-f7a1337f0d29.

CVSS3: 2.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-2m5x-4wp5-g3mp

In startSpaActivityForApp of SpaActivity.kt, there is a possible cross-user permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-2m5w-88gg-379g

There is a SQL injection vulnerability in ZTE MF286R. Due to insufficient validation of the input parameters of the phonebook interface, an authenticated attacker could use the vulnerability to execute arbitrary SQL injection.

CVSS3: 8.8
27%
Средний
больше 3 лет назад
github логотип
GHSA-2m5v-qw26-9cmh

IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e20.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-2m5v-p53f-hgfp

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112050983

1%
Низкий
около 4 лет назад
github логотип
GHSA-2m5r-g595-364q

A buffer overflow in the UPnP service of Tenda AC8 Hardware v03.03.10.01 allows attackers to cause a Denial of Service (DoS) via supplying a crafted packet.

CVSS3: 7.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-2m5q-52fx-w72m

The kernel extension in Cisco AnyConnect Secure Mobility Client 4.0(2049) on OS X allows local users to cause a denial of service (panic) via vectors involving contiguous memory locations, aka Bug ID CSCut12255.

0%
Низкий
около 4 лет назад

Уязвимостей на страницу