Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 714

Количество 353 714

github логотип

GHSA-2hhc-69mg-j8fr

4 месяца назад

Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-2hhc-539m-8qw5

около 4 лет назад

The WPG parser in ImageMagick before 6.9.4-4 and 7.x before 7.0.1-5, when a memory limit is set, allows remote attackers to have unspecified impact via vectors related to the SetImageExtent return-value check, which trigger (1) a heap-based buffer overflow in the SetPixelIndex function or an invalid write operation in the (2) ScaleCharToQuantum or (3) SetPixelIndex functions.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2hhc-4hqc-4mg8

23 дня назад

gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title without proper escaping. The subtype field sourced from a DEVICES JSON log entry or NMEA PGRMT sentence is written into a generated gnuplot program via a set title statement with only double-quote characters escaped, enabling arbitrary shell command execution as the user running gnuplot when the victim renders the generated plot through the gpsprof and gnuplot workflow.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2hh9-vfrm-8f6w

около 4 лет назад

In ImageMagick before 6.9.7-10, there is a crash (rather than a "width or height exceeds limit" error report) if the image dimensions are too large, as demonstrated by use of the mpc coder.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2hh8-gpv5-pc93

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix racy issue from session lookup and expire Increment the session reference count within the lock for lookup to avoid racy issue with session expire.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2hh7-f3x9-8mgq

около 4 лет назад

An insecure direct object reference in webmail in totemo totemomail 7.0.0 allows an authenticated remote user to read and modify mail folder names of other users via enumeration.

EPSS: Низкий
github логотип

GHSA-2hh7-c75g-qj2r

3 месяца назад

OpenClaw validates Zalo outbound photo URLs through the SSRF guard

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-2hh7-5899-hfpg

11 месяцев назад

ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic WPA2-PSK, which can be easily derived.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2hh6-6xcj-rrfv

около 4 лет назад

IBM Tivoli Endpoint Manager could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 123902.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2hh5-jxwx-3pwr

около 4 лет назад

An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because small IOMMU mappings are unsafely combined into larger ones.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2hh5-254v-jpf4

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix use-after-free of encap entry in neigh update handler Function mlx5e_rep_neigh_update() wasn't updated to accommodate rtnl lock removal from TC filter update path and properly handle concurrent encap entry insertion/deletion which can lead to following use-after-free: [23827.464923] ================================================================== [23827.469446] BUG: KASAN: use-after-free in mlx5e_encap_take+0x72/0x140 [mlx5_core] [23827.470971] Read of size 4 at addr ffff8881d132228c by task kworker/u20:6/21635 [23827.472251] [23827.472615] CPU: 9 PID: 21635 Comm: kworker/u20:6 Not tainted 5.13.0-rc3+ #5 [23827.473788] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014 [23827.475639] Workqueue: mlx5e mlx5e_rep_neigh_update [mlx5_core] [23827.476731] Call Trace: [23827.477260] dump_stack+0xbb/0x107 [23827.477906] print_addre...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2hh4-qfh8-22w2

больше 2 лет назад

Claris FileMaker Server before version 20.3.2 was susceptible to a reflected Cross-Site Scripting vulnerability due to an improperly handled parameter in the FileMaker WebDirect login endpoint. The vulnerability was resolved in FileMaker Server 20.3.2 by escaping the HTML contents of the login error message on the login page.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2hh4-c6pj-8p6j

около 1 года назад

An arbitrary file upload vulnerability in the component /rsc/filemanager.rsc.class.php of Filemanager commit c75b914 v.2.5.0 allows attackers to execute arbitrary code via uploading a crafted SVG file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2hh4-7m9c-h6f2

около 4 лет назад

Heap-based buffer overflow in the eap_server_tls_process_fragment function in eap_server_tls_common.c in the EAP authentication server in hostapd 0.6 through 1.0 allows remote attackers to cause a denial of service (crash or abort) via a small "TLS Message Length" value in an EAP-TLS message with the "More Fragments" flag set.

EPSS: Низкий
github логотип

GHSA-2hh3-q7m3-vf3h

больше 4 лет назад

post.php in x_atrix xGuestBook 1.02 allows remote attackers to obtain sensitive information via a request without the (1) user, (2) mail, (3) p, or (4) url parameter, which reveals the installation path in an error message.

EPSS: Низкий
github логотип

GHSA-2hh3-jmv8-5fmx

около 4 лет назад

Moodle Does Not Escape Characters In Email Headers

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2hh3-6mr4-7gqq

около 4 лет назад

An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded System Passwords that provide shell access.

EPSS: Низкий
github логотип

GHSA-2hh3-2vjw-vgr4

больше 4 лет назад

Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from the content script itself that could lead to controlling Whale Bridge if the rendering process compromises.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2hh2-mfw7-g797

около 3 лет назад

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Surbma Surbma | GDPR Proof Cookie Consent & Notice Bar plugin <= 17.5.3 versions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2hgx-m265-x6jf

около 4 лет назад

IBM Robotic Process Automation with Automation Anywhere 10.0 could allow a remote attacker to execute arbitrary code on the system, caused by improper output encoding in an CSV export. By persuading a victim to download the CSV export, to open it in Microsoft Excel and to confirm the two security questions, an attacker could exploit this vulnerability to run any command or program on the victim's machine. IBM X-Force ID: 142651.

CVSS3: 7.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2hhc-69mg-j8fr

Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.

CVSS3: 7
0%
Низкий
4 месяца назад
github логотип
GHSA-2hhc-539m-8qw5

The WPG parser in ImageMagick before 6.9.4-4 and 7.x before 7.0.1-5, when a memory limit is set, allows remote attackers to have unspecified impact via vectors related to the SetImageExtent return-value check, which trigger (1) a heap-based buffer overflow in the SetPixelIndex function or an invalid write operation in the (2) ScaleCharToQuantum or (3) SetPixelIndex functions.

CVSS3: 8.1
5%
Низкий
около 4 лет назад
github логотип
GHSA-2hhc-4hqc-4mg8

gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title without proper escaping. The subtype field sourced from a DEVICES JSON log entry or NMEA PGRMT sentence is written into a generated gnuplot program via a set title statement with only double-quote characters escaped, enabling arbitrary shell command execution as the user running gnuplot when the victim renders the generated plot through the gpsprof and gnuplot workflow.

CVSS3: 7.8
2%
Низкий
23 дня назад
github логотип
GHSA-2hh9-vfrm-8f6w

In ImageMagick before 6.9.7-10, there is a crash (rather than a "width or height exceeds limit" error report) if the image dimensions are too large, as demonstrated by use of the mpc coder.

CVSS3: 6.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-2hh8-gpv5-pc93

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix racy issue from session lookup and expire Increment the session reference count within the lock for lookup to avoid racy issue with session expire.

CVSS3: 8.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-2hh7-f3x9-8mgq

An insecure direct object reference in webmail in totemo totemomail 7.0.0 allows an authenticated remote user to read and modify mail folder names of other users via enumeration.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2hh7-c75g-qj2r

OpenClaw validates Zalo outbound photo URLs through the SSRF guard

CVSS3: 8.6
0%
Низкий
3 месяца назад
github логотип
GHSA-2hh7-5899-hfpg

ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic WPA2-PSK, which can be easily derived.

CVSS3: 6.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-2hh6-6xcj-rrfv

IBM Tivoli Endpoint Manager could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 123902.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-2hh5-jxwx-3pwr

An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because small IOMMU mappings are unsafely combined into larger ones.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-2hh5-254v-jpf4

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix use-after-free of encap entry in neigh update handler Function mlx5e_rep_neigh_update() wasn't updated to accommodate rtnl lock removal from TC filter update path and properly handle concurrent encap entry insertion/deletion which can lead to following use-after-free: [23827.464923] ================================================================== [23827.469446] BUG: KASAN: use-after-free in mlx5e_encap_take+0x72/0x140 [mlx5_core] [23827.470971] Read of size 4 at addr ffff8881d132228c by task kworker/u20:6/21635 [23827.472251] [23827.472615] CPU: 9 PID: 21635 Comm: kworker/u20:6 Not tainted 5.13.0-rc3+ #5 [23827.473788] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014 [23827.475639] Workqueue: mlx5e mlx5e_rep_neigh_update [mlx5_core] [23827.476731] Call Trace: [23827.477260] dump_stack+0xbb/0x107 [23827.477906] print_addre...

CVSS3: 7.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-2hh4-qfh8-22w2

Claris FileMaker Server before version 20.3.2 was susceptible to a reflected Cross-Site Scripting vulnerability due to an improperly handled parameter in the FileMaker WebDirect login endpoint. The vulnerability was resolved in FileMaker Server 20.3.2 by escaping the HTML contents of the login error message on the login page.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2hh4-c6pj-8p6j

An arbitrary file upload vulnerability in the component /rsc/filemanager.rsc.class.php of Filemanager commit c75b914 v.2.5.0 allows attackers to execute arbitrary code via uploading a crafted SVG file.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2hh4-7m9c-h6f2

Heap-based buffer overflow in the eap_server_tls_process_fragment function in eap_server_tls_common.c in the EAP authentication server in hostapd 0.6 through 1.0 allows remote attackers to cause a denial of service (crash or abort) via a small "TLS Message Length" value in an EAP-TLS message with the "More Fragments" flag set.

4%
Низкий
около 4 лет назад
github логотип
GHSA-2hh3-q7m3-vf3h

post.php in x_atrix xGuestBook 1.02 allows remote attackers to obtain sensitive information via a request without the (1) user, (2) mail, (3) p, or (4) url parameter, which reveals the installation path in an error message.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2hh3-jmv8-5fmx

Moodle Does Not Escape Characters In Email Headers

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-2hh3-6mr4-7gqq

An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded System Passwords that provide shell access.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2hh3-2vjw-vgr4

Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from the content script itself that could lead to controlling Whale Bridge if the rendering process compromises.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2hh2-mfw7-g797

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Surbma Surbma | GDPR Proof Cookie Consent & Notice Bar plugin <= 17.5.3 versions.

CVSS3: 6.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-2hgx-m265-x6jf

IBM Robotic Process Automation with Automation Anywhere 10.0 could allow a remote attacker to execute arbitrary code on the system, caused by improper output encoding in an CSV export. By persuading a victim to download the CSV export, to open it in Microsoft Excel and to confirm the two security questions, an attacker could exploit this vulnerability to run any command or program on the victim's machine. IBM X-Force ID: 142651.

CVSS3: 7.7
2%
Низкий
около 4 лет назад

Уязвимостей на страницу