Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 374 825

Количество 374 825

github логотип

GHSA-3pgj-h3jv-hj48

9 месяцев назад

AVideo versions prior to 20.0 are vulnerable to an open redirect flaw due to missing validation of the cancelUri parameter during user login. An attacker can craft a link to redirect users to arbitrary external sites, enabling phishing attacks.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3pgh-mfvh-3jch

больше 4 лет назад

The sell function of a smart contract implementation for Internet Node Token (INT), a tradable Ethereum ERC20 token, allows a potential trap that could be used to cause financial damage to the seller, because of overflow of the multiplication of its argument amount and a manipulable variable sellPrice, aka the "tradeTrap" issue.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3pgh-gc83-p85w

больше 4 лет назад

A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3pgh-f8f3-268r

больше 4 лет назад

The AnimationThread function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 uses an incorrect argument to the sscanf function, which might allow remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via unknown vectors.

EPSS: Низкий
github логотип

GHSA-3pgg-hvfr-3phx

больше 4 лет назад

An issue was discovered in Squiz Matrix from 5.3 through to 5.3.6.1 and 5.4.1.3. An information disclosure caused by a Path Traversal issue in the 'File Bridge' plugin allowed the existence of files outside of the bridged path to be confirmed.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3pgg-fxm7-xv3p

больше 2 лет назад

NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the logging location to an arbitrary file. If this file exists, logs are appended to the file. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

CVSS3: 9
EPSS: Средний
github логотип

GHSA-3pgg-7mmh-564c

больше 4 лет назад

An Open Redirect vulnerability was discovered in Revive Adserver version < 5.0.5 and reported by HackerOne user hoangn144. A remote attacker could trick logged-in users to open a specifically crafted link and have them redirected to any destination.The CSRF protection of the “/www/admin/*-modify.php” could be skipped if no meaningful parameter was sent. No action was performed, but the user was still redirected to the target page, specified via the “returnurl” GET parameter.

EPSS: Высокий
github логотип

GHSA-3pgc-xqg9-cfr6

4 месяца назад

FacturaScripts Vulnerable to Remote Code Execution (RCE) via Zip Slip in Plugin Upload Mechanism

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-3pgc-7jf3-5x5g

больше 4 лет назад

Magento 2 Community Edition IDOR Vulnerability

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3pg9-qqg9-8485

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the web interface in ClearCase RWP server in IBM Rational ClearCase 7.0.0 before 7.0.0.4, and 7.0.1.1-RATL-RCC-IFIX02 and possibly other 7.0.1 versions before 7.0.1.3, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO of a URI associated with a VOB page.

EPSS: Низкий
github логотип

GHSA-3pg9-mr9f-v7qm

около 4 лет назад

HiCOS’ client-side citizen certificate component has a double free vulnerability. An unauthenticated physical attacker can exploit this vulnerability to corrupt memory and execute arbitrary code, manipulate system data or terminate service.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-3pg9-h6fh-rxcr

больше 4 лет назад

SQL injection vulnerability in catagorie.php in Werner Hilversum FAQ Manager 1.2 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

EPSS: Низкий
github логотип

GHSA-3pg9-h44j-gvg9

больше 4 лет назад

Unquoted Windows search path vulnerability in the guest service in Unisys s-Par before 4.4.20 allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory, as demonstrated by program.exe.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3pg9-gwgr-fmmw

3 месяца назад

A security flaw has been discovered in Investintech SlimPDFReader up to 2.0.14. Affected by this issue is the function SlimPDFReader!Investintech::PCV::TeighaDo+0x25cde0 of the file SlimPDFReader.exe of the component PDF File Handler. Performing a manipulation results in out-of-bounds read. It is possible to initiate the attack remotely. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3pg9-fj7q-9h7m

больше 3 лет назад

Multiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. An attacker should send an authenticated HTTP request to trigger this vulnerability. In cmd s_b, at 0x9d016578, the value for the `val` key is copied using `strcpy` to the buffer at `$sp+0x2b0`.This buffer is 32 bytes large, sending anything longer will cause a buffer overflow.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3pg9-8r34-25v2

почти 3 года назад

Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Page Specific Metadata and Smarty data parameters in the Content Manager Menu component.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3pg9-3f6q-hjf5

больше 4 лет назад

Blink, as used in Google Chrome before 43.0.2357.130, does not properly restrict the creation context during creation of a DOM wrapper, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code that uses a Blink public API, related to WebArrayBufferConverter.cpp, WebBlob.cpp, WebDOMError.cpp, and WebDOMFileSystem.cpp.

EPSS: Низкий
github логотип

GHSA-3pg8-c473-w6rr

больше 4 лет назад

Stored Cross-site Scripting in showdoc

CVSS3: 6.9
EPSS: Низкий
github логотип

GHSA-3pg8-5qjj-jmqc

больше 4 лет назад

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where improper access controls allow a regular user to write a part of the registry intended for privileged users only, leading to escalation of privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3pg8-3336-w32h

больше 4 лет назад

Directory traversal vulnerability in UploadServlet in the Remote Management component in Novell ZENworks Configuration Management (ZCM) 10 before 10.3 allows remote attackers to execute arbitrary code via a crafted WAR pathname in the filename parameter in conjunction with WAR content in the POST data, a different vulnerability than CVE-2010-5324.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3pgj-h3jv-hj48

AVideo versions prior to 20.0 are vulnerable to an open redirect flaw due to missing validation of the cancelUri parameter during user login. An attacker can craft a link to redirect users to arbitrary external sites, enabling phishing attacks.

CVSS3: 6.1
0%
Низкий
9 месяцев назад
github логотип
GHSA-3pgh-mfvh-3jch

The sell function of a smart contract implementation for Internet Node Token (INT), a tradable Ethereum ERC20 token, allows a potential trap that could be used to cause financial damage to the seller, because of overflow of the multiplication of its argument amount and a manipulable variable sellPrice, aka the "tradeTrap" issue.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3pgh-gc83-p85w

A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.

CVSS3: 8.8
9%
Низкий
больше 4 лет назад
github логотип
GHSA-3pgh-f8f3-268r

The AnimationThread function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 uses an incorrect argument to the sscanf function, which might allow remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via unknown vectors.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-3pgg-hvfr-3phx

An issue was discovered in Squiz Matrix from 5.3 through to 5.3.6.1 and 5.4.1.3. An information disclosure caused by a Path Traversal issue in the 'File Bridge' plugin allowed the existence of files outside of the bridged path to be confirmed.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3pgg-fxm7-xv3p

NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the logging location to an arbitrary file. If this file exists, logs are appended to the file. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

CVSS3: 9
20%
Средний
больше 2 лет назад
github логотип
GHSA-3pgg-7mmh-564c

An Open Redirect vulnerability was discovered in Revive Adserver version < 5.0.5 and reported by HackerOne user hoangn144. A remote attacker could trick logged-in users to open a specifically crafted link and have them redirected to any destination.The CSRF protection of the “/www/admin/*-modify.php” could be skipped if no meaningful parameter was sent. No action was performed, but the user was still redirected to the target page, specified via the “returnurl” GET parameter.

70%
Высокий
больше 4 лет назад
github логотип
GHSA-3pgc-xqg9-cfr6

FacturaScripts Vulnerable to Remote Code Execution (RCE) via Zip Slip in Plugin Upload Mechanism

CVSS3: 7.2
1%
Низкий
4 месяца назад
github логотип
GHSA-3pgc-7jf3-5x5g

Magento 2 Community Edition IDOR Vulnerability

CVSS3: 7.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3pg9-qqg9-8485

Multiple cross-site scripting (XSS) vulnerabilities in the web interface in ClearCase RWP server in IBM Rational ClearCase 7.0.0 before 7.0.0.4, and 7.0.1.1-RATL-RCC-IFIX02 and possibly other 7.0.1 versions before 7.0.1.3, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO of a URI associated with a VOB page.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3pg9-mr9f-v7qm

HiCOS’ client-side citizen certificate component has a double free vulnerability. An unauthenticated physical attacker can exploit this vulnerability to corrupt memory and execute arbitrary code, manipulate system data or terminate service.

CVSS3: 6.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-3pg9-h6fh-rxcr

SQL injection vulnerability in catagorie.php in Werner Hilversum FAQ Manager 1.2 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3pg9-h44j-gvg9

Unquoted Windows search path vulnerability in the guest service in Unisys s-Par before 4.4.20 allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory, as demonstrated by program.exe.

CVSS3: 6.7
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3pg9-gwgr-fmmw

A security flaw has been discovered in Investintech SlimPDFReader up to 2.0.14. Affected by this issue is the function SlimPDFReader!Investintech::PCV::TeighaDo+0x25cde0 of the file SlimPDFReader.exe of the component PDF File Handler. Performing a manipulation results in out-of-bounds read. It is possible to initiate the attack remotely. This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 4.3
1%
Низкий
3 месяца назад
github логотип
GHSA-3pg9-fj7q-9h7m

Multiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. An attacker should send an authenticated HTTP request to trigger this vulnerability. In cmd s_b, at 0x9d016578, the value for the `val` key is copied using `strcpy` to the buffer at `$sp+0x2b0`.This buffer is 32 bytes large, sending anything longer will cause a buffer overflow.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3pg9-8r34-25v2

Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Page Specific Metadata and Smarty data parameters in the Content Manager Menu component.

CVSS3: 5.4
0%
Низкий
почти 3 года назад
github логотип
GHSA-3pg9-3f6q-hjf5

Blink, as used in Google Chrome before 43.0.2357.130, does not properly restrict the creation context during creation of a DOM wrapper, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code that uses a Blink public API, related to WebArrayBufferConverter.cpp, WebBlob.cpp, WebDOMError.cpp, and WebDOMFileSystem.cpp.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3pg8-c473-w6rr

Stored Cross-site Scripting in showdoc

CVSS3: 6.9
3%
Низкий
больше 4 лет назад
github логотип
GHSA-3pg8-5qjj-jmqc

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where improper access controls allow a regular user to write a part of the registry intended for privileged users only, leading to escalation of privileges.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3pg8-3336-w32h

Directory traversal vulnerability in UploadServlet in the Remote Management component in Novell ZENworks Configuration Management (ZCM) 10 before 10.3 allows remote attackers to execute arbitrary code via a crafted WAR pathname in the filename parameter in conjunction with WAR content in the POST data, a different vulnerability than CVE-2010-5324.

14%
Средний
больше 4 лет назад

Уязвимостей на страницу