Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-2j3p-vpp9-9f53

больше 1 года назад

An unbounded resource search path in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-2j3p-gqw5-g59j

5 месяцев назад

theshit's Improper Privilege Dropping Allows Local Privilege Escalation via Command Re-execution

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-2j3m-rxqm-r548

около 4 лет назад

Microsoft Windows Media Player 11 does not properly perform colorspace conversion, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .AVI file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Средний
github логотип

GHSA-2j3m-gwxg-45rx

больше 3 лет назад

Improper restriction of XML external entity reference (XXE) vulnerability exists in OMRON CX-Motion Pro 1.4.6.013 and earlier. If a user opens a specially crafted project file created by an attacker, sensitive information in the file system where CX-Motion Pro is installed may be disclosed.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2j3j-g2v5-fh5c

около 4 лет назад

A vulnerability has been identified in Mendix Applications using Mendix 8 (All versions < V8.18.13), Mendix Applications using Mendix 9 (All versions < V9.6.2). Applications built with affected versions of Mendix Studio Pro do not properly control read access for certain client actions. This could allow authenticated attackers to retrieve the changedDate attribute of arbitrary objects, even when they don't have read access to them.

EPSS: Низкий
github логотип

GHSA-2j3h-j2q3-wxp3

больше 2 лет назад

Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2j3h-78mv-5phm

больше 2 лет назад

Cleartext Storage of Sensitive Information in Gambio 4.9.2.0 allows attackers to obtain sensitive information via error-handler.log.json and legacy-error-handler.log.txt under the webroot.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-2j3h-74w8-wpxm

около 4 лет назад

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave. A malicious application may be able to access restricted files.

EPSS: Низкий
github логотип

GHSA-2j3h-55rq-rj48

около 4 лет назад

The URI.decode_www_form_component method in Ruby before 1.9.2-p330 allows remote attackers to cause a denial of service (catastrophic regular expression backtracking, resource consumption, or application crash) via a crafted string.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2j3g-rxwp-8rq5

около 4 лет назад

LuaUPnP in Vera Edge Home Controller 1.7.4452 allows remote unauthenticated users to execute arbitrary OS commands via the code parameter to /port_3480/data_request because the "No unsafe lua allowed" code block is skipped.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2j3g-pf25-9mr9

около 2 лет назад

Kofax Power PDF PNG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PNG files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-20458.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2j3g-p2x2-c94q

почти 3 года назад

The Import XML and RSS Feeds WordPress plugin before 2.1.5 contains a web shell, allowing unauthenticated attackers to perform RCE. The plugin/vendor was not compromised and the files are the result of running a PoC for a previously reported issue (https://wpscan.com/vulnerability/d4220025-2272-4d5f-9703-4b2ac4a51c42) and not deleting the created files when releasing the new version.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-2j3g-mmqf-22pf

около 4 лет назад

vos in OpenAFS before 1.6.13, when updating VLDB entries, allows remote attackers to obtain stack data by sniffing the network.

EPSS: Низкий
github логотип

GHSA-2j3g-j6qj-x9q2

6 месяцев назад

An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.

CVSS3: 8.6
EPSS: Высокий
github логотип

GHSA-2j3g-cq99-w5x4

около 4 лет назад

** DISPUTED ** PHP remote file inclusion vulnerability in upgrader.php in Vanilla CMS 1.0.1 and earlier, when /conf/old_settings.php exists, allows remote attackers to execute arbitrary PHP code via a URL in the RootDirectory parameter. NOTE: this issue has been disputed by a third party who states that the RootDirectory parameter is initialized before being used, for version 1.0. CVE analysis concurs with the dispute, but it is unclear whether older versions are affected.

EPSS: Низкий
github логотип

GHSA-2j3g-9pf6-phh4

около 3 лет назад

Delta Electronics' CNCSoft-B DOPSoft versions 1.0.0.4 and prior are vulnerable to heap-based buffer overflow, which could allow an attacker to execute arbitrary code.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2j3g-5jhm-r285

5 месяцев назад

A security vulnerability has been detected in Tenda A21 1.0.0.0. This vulnerability affects the function set_device_name of the file /goform/setBlackRule of the component MAC Filtering Configuration Endpoint. Such manipulation of the argument devName/mac leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2j3f-mgwg-2gjh

около 4 лет назад

SQL injection vulnerability in the administrative web interface in Cisco Unified Communications Manager 11.0(0.98000.225) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug IDs CSCut33447 and CSCut33608.

EPSS: Низкий
github логотип

GHSA-2j3f-gh3p-94vc

больше 4 лет назад

Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure.

EPSS: Средний
github логотип

GHSA-2j3f-972q-6fv5

около 4 лет назад

The _pcre32_xclass function in pcre_xclass.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (invalid memory read) via a crafted file.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2j3p-vpp9-9f53

An unbounded resource search path in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

CVSS3: 7.2
3%
Низкий
больше 1 года назад
github логотип
GHSA-2j3p-gqw5-g59j

theshit's Improper Privilege Dropping Allows Local Privilege Escalation via Command Re-execution

CVSS3: 8.4
0%
Низкий
5 месяцев назад
github логотип
GHSA-2j3m-rxqm-r548

Microsoft Windows Media Player 11 does not properly perform colorspace conversion, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .AVI file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

10%
Средний
около 4 лет назад
github логотип
GHSA-2j3m-gwxg-45rx

Improper restriction of XML external entity reference (XXE) vulnerability exists in OMRON CX-Motion Pro 1.4.6.013 and earlier. If a user opens a specially crafted project file created by an attacker, sensitive information in the file system where CX-Motion Pro is installed may be disclosed.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2j3j-g2v5-fh5c

A vulnerability has been identified in Mendix Applications using Mendix 8 (All versions < V8.18.13), Mendix Applications using Mendix 9 (All versions < V9.6.2). Applications built with affected versions of Mendix Studio Pro do not properly control read access for certain client actions. This could allow authenticated attackers to retrieve the changedDate attribute of arbitrary objects, even when they don't have read access to them.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2j3h-j2q3-wxp3

Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.

CVSS3: 6.5
2%
Низкий
больше 2 лет назад
github логотип
GHSA-2j3h-78mv-5phm

Cleartext Storage of Sensitive Information in Gambio 4.9.2.0 allows attackers to obtain sensitive information via error-handler.log.json and legacy-error-handler.log.txt under the webroot.

CVSS3: 2.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2j3h-74w8-wpxm

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave. A malicious application may be able to access restricted files.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2j3h-55rq-rj48

The URI.decode_www_form_component method in Ruby before 1.9.2-p330 allows remote attackers to cause a denial of service (catastrophic regular expression backtracking, resource consumption, or application crash) via a crafted string.

CVSS3: 7.5
4%
Низкий
около 4 лет назад
github логотип
GHSA-2j3g-rxwp-8rq5

LuaUPnP in Vera Edge Home Controller 1.7.4452 allows remote unauthenticated users to execute arbitrary OS commands via the code parameter to /port_3480/data_request because the "No unsafe lua allowed" code block is skipped.

CVSS3: 9.8
4%
Низкий
около 4 лет назад
github логотип
GHSA-2j3g-pf25-9mr9

Kofax Power PDF PNG File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PNG files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-20458.

CVSS3: 7.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-2j3g-p2x2-c94q

The Import XML and RSS Feeds WordPress plugin before 2.1.5 contains a web shell, allowing unauthenticated attackers to perform RCE. The plugin/vendor was not compromised and the files are the result of running a PoC for a previously reported issue (https://wpscan.com/vulnerability/d4220025-2272-4d5f-9703-4b2ac4a51c42) and not deleting the created files when releasing the new version.

CVSS3: 9.8
39%
Средний
почти 3 года назад
github логотип
GHSA-2j3g-mmqf-22pf

vos in OpenAFS before 1.6.13, when updating VLDB entries, allows remote attackers to obtain stack data by sniffing the network.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2j3g-j6qj-x9q2

An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.

CVSS3: 8.6
81%
Высокий
6 месяцев назад
github логотип
GHSA-2j3g-cq99-w5x4

** DISPUTED ** PHP remote file inclusion vulnerability in upgrader.php in Vanilla CMS 1.0.1 and earlier, when /conf/old_settings.php exists, allows remote attackers to execute arbitrary PHP code via a URL in the RootDirectory parameter. NOTE: this issue has been disputed by a third party who states that the RootDirectory parameter is initialized before being used, for version 1.0. CVE analysis concurs with the dispute, but it is unclear whether older versions are affected.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2j3g-9pf6-phh4

Delta Electronics' CNCSoft-B DOPSoft versions 1.0.0.4 and prior are vulnerable to heap-based buffer overflow, which could allow an attacker to execute arbitrary code.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-2j3g-5jhm-r285

A security vulnerability has been detected in Tenda A21 1.0.0.0. This vulnerability affects the function set_device_name of the file /goform/setBlackRule of the component MAC Filtering Configuration Endpoint. Such manipulation of the argument devName/mac leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.

CVSS3: 8.8
1%
Низкий
5 месяцев назад
github логотип
GHSA-2j3f-mgwg-2gjh

SQL injection vulnerability in the administrative web interface in Cisco Unified Communications Manager 11.0(0.98000.225) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug IDs CSCut33447 and CSCut33608.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2j3f-gh3p-94vc

Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure.

23%
Средний
больше 4 лет назад
github логотип
GHSA-2j3f-972q-6fv5

The _pcre32_xclass function in pcre_xclass.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (invalid memory read) via a crafted file.

CVSS3: 5.5
2%
Низкий
около 4 лет назад

Уязвимостей на страницу