Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 376 080

Количество 376 080

github логотип

GHSA-3mf7-7q28-hchw

больше 3 лет назад

In wlan driver, there is a race condition. This could lead to local denial of service in wlan services.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-3mf7-49vm-cgqm

больше 4 лет назад

Unspecified vulnerability in the Transparent Data Encryption (TDE) Wallet component of Oracle Database server 10.2.0.1 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB27. NOTE: Oracle has not disputed a reliable researcher report that TDA stores the master key without encryption, which allows local users to obtain the key via the SGA.

EPSS: Низкий
github логотип

GHSA-3mf6-hp9h-pxf7

больше 4 лет назад

Adding method ACLs in remap.config can cause a segfault when the user makes a carefully crafted request. This affects versions Apache Traffic Server (ATS) 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x should upgrade to 6.2.3 or later versions and 7.x users should upgrade to 7.1.4 or later versions.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3mf6-cpxv-733m

больше 4 лет назад

EMC Unisphere for VMAX Virtual Appliance (vApp) versions prior to 8.4.0.15, EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.15, EMC VASA Virtual Appliance versions prior to 8.4.0.512, and EMC VMAX Embedded Management (eManagement) versions prior to and including 1.4 (Enginuity Release 5977.1125.1125 and earlier) contain an authentication bypass vulnerability that may potentially be exploited by malicious users to compromise the affected system.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3mf6-3q6q-vqgr

8 месяцев назад

Missing Authorization vulnerability in e-plugins Institutions Directory institutions-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Institutions Directory: from n/a through <= 1.3.4.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3mf5-r4hg-hfx9

больше 1 года назад

mavo DOM Clobbering vulnerability

EPSS: Низкий
github логотип

GHSA-3mf5-jc6x-rp7q

больше 4 лет назад

The copy_shmid_to_user function in ipc/shm.c in the Linux kernel before 2.6.37-rc1 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via vectors related to the shmctl system call and the "old shm interface."

EPSS: Низкий
github логотип

GHSA-3mf5-g7fj-qj4f

больше 4 лет назад

HP ElitePad 900 PCs with BIOS F.0x before F.01 Update 1.0.0.8 do not enable the Secure Boot feature, which allows local users to bypass intended BIOS restrictions and boot unintended operating systems via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3mf4-m8w3-fw93

почти 3 года назад

Use of implicit intent for sensitive communication vulnerability in startMandatoryCheckActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3mf4-grcw-4c92

больше 4 лет назад

The ExecuteExe method in the DVBSExeCall Control ActiveX control 1.0.0.1 in DVBSExeCall.ocx in DATEV Base System (aka Grundpaket Basis) allows remote attackers to execute arbitrary commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3mf4-g44r-xcvg

28 дней назад

Improper neutralization of path traversal sequences in TeamViewer Desktop Clients prior Version 15.81.5 allows an authenticated remote session participant to write files to unintended locations on the local file system via file transfer or virtual file clipboard mechanisms. An attacker can leverage this behavior to achieve arbitrary file write and potentially execute code with the privileges of the affected user.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3mf4-86mx-6m36

больше 4 лет назад

Buffer overflows in CTRLServer in XMail allows attackers to execute arbitrary commands via the cfgfileget or domaindel functions.

EPSS: Низкий
github логотип

GHSA-3mf3-c5hx-g6jm

7 дней назад

Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-3mf3-33v4-jcj2

больше 4 лет назад

ChaiVM EZloader for HP color LaserJet 4500 and 4550 and HP LaserJet 4100 and 8150 does not properly verify JAR signatures for new services, which allows local users to load unauthorized Chai services.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3mf3-2gv9-h39j

около 5 лет назад

Uninitialized buffer use in marc

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3mf2-x699-cxr9

больше 4 лет назад

rcore6/main/addcookie.jsp in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows remote attackers to create or modify cookies via the query string.

EPSS: Низкий
github логотип

GHSA-3mf2-j3p3-w43q

больше 4 лет назад

The console in Puppet Enterprise 2015.x and 2016.x prior to 2016.4.0 includes unsafe string reads that potentially allows for remote code execution on the console node.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3mf2-h46x-xfpw

больше 4 лет назад

IBM Security Access Manager for Web is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3mcx-xjfh-fh99

больше 4 лет назад

During listener modified response processing, a buffer overrun occurs due to lack of buffer size verification when updating message buffer with physical address information in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909W, MSM8917, MSM8953, MSM8996AU, Nicobar, QCM2150, QCS405, QCS605, QM215, Rennell, SA6155P, Saipan, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM632, SDM670, SDM710, SDM845, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130

EPSS: Низкий
github логотип

GHSA-3mcx-q4cv-hcc6

больше 4 лет назад

An issue was discovered in CipherMail Community Gateway Virtual Appliances and Professional/Enterprise Gateway Virtual Appliances versions 1.0.1 through 4.7.1-0 and CipherMail Webmail Messenger Virtual Appliances 1.1.1 through 3.1.1-0. A Diffie-Hellman parameter of insufficient size could allow man-in-the-middle compromise of communications between CipherMail products and external SMTP clients.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3mf7-7q28-hchw

In wlan driver, there is a race condition. This could lead to local denial of service in wlan services.

CVSS3: 4.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mf7-49vm-cgqm

Unspecified vulnerability in the Transparent Data Encryption (TDE) Wallet component of Oracle Database server 10.2.0.1 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB27. NOTE: Oracle has not disputed a reliable researcher report that TDA stores the master key without encryption, which allows local users to obtain the key via the SGA.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-3mf6-hp9h-pxf7

Adding method ACLs in remap.config can cause a segfault when the user makes a carefully crafted request. This affects versions Apache Traffic Server (ATS) 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x should upgrade to 6.2.3 or later versions and 7.x users should upgrade to 7.1.4 or later versions.

CVSS3: 7.5
8%
Низкий
больше 4 лет назад
github логотип
GHSA-3mf6-cpxv-733m

EMC Unisphere for VMAX Virtual Appliance (vApp) versions prior to 8.4.0.15, EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.15, EMC VASA Virtual Appliance versions prior to 8.4.0.512, and EMC VMAX Embedded Management (eManagement) versions prior to and including 1.4 (Enginuity Release 5977.1125.1125 and earlier) contain an authentication bypass vulnerability that may potentially be exploited by malicious users to compromise the affected system.

CVSS3: 9.8
5%
Низкий
больше 4 лет назад
github логотип
GHSA-3mf6-3q6q-vqgr

Missing Authorization vulnerability in e-plugins Institutions Directory institutions-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Institutions Directory: from n/a through <= 1.3.4.

CVSS3: 7.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-3mf5-r4hg-hfx9

mavo DOM Clobbering vulnerability

1%
Низкий
больше 1 года назад
github логотип
GHSA-3mf5-jc6x-rp7q

The copy_shmid_to_user function in ipc/shm.c in the Linux kernel before 2.6.37-rc1 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via vectors related to the shmctl system call and the "old shm interface."

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3mf5-g7fj-qj4f

HP ElitePad 900 PCs with BIOS F.0x before F.01 Update 1.0.0.8 do not enable the Secure Boot feature, which allows local users to bypass intended BIOS restrictions and boot unintended operating systems via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mf4-m8w3-fw93

Use of implicit intent for sensitive communication vulnerability in startMandatoryCheckActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with Samsung Account privilege.

CVSS3: 6.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-3mf4-grcw-4c92

The ExecuteExe method in the DVBSExeCall Control ActiveX control 1.0.0.1 in DVBSExeCall.ocx in DATEV Base System (aka Grundpaket Basis) allows remote attackers to execute arbitrary commands via unspecified vectors.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-3mf4-g44r-xcvg

Improper neutralization of path traversal sequences in TeamViewer Desktop Clients prior Version 15.81.5 allows an authenticated remote session participant to write files to unintended locations on the local file system via file transfer or virtual file clipboard mechanisms. An attacker can leverage this behavior to achieve arbitrary file write and potentially execute code with the privileges of the affected user.

CVSS3: 7.5
0%
Низкий
28 дней назад
github логотип
GHSA-3mf4-86mx-6m36

Buffer overflows in CTRLServer in XMail allows attackers to execute arbitrary commands via the cfgfileget or domaindel functions.

8%
Низкий
больше 4 лет назад
github логотип
GHSA-3mf3-c5hx-g6jm

Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

CVSS3: 10
1%
Низкий
7 дней назад
github логотип
GHSA-3mf3-33v4-jcj2

ChaiVM EZloader for HP color LaserJet 4500 and 4550 and HP LaserJet 4100 and 8150 does not properly verify JAR signatures for new services, which allows local users to load unauthorized Chai services.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3mf3-2gv9-h39j

Uninitialized buffer use in marc

CVSS3: 7.5
1%
Низкий
около 5 лет назад
github логотип
GHSA-3mf2-x699-cxr9

rcore6/main/addcookie.jsp in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows remote attackers to create or modify cookies via the query string.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-3mf2-j3p3-w43q

The console in Puppet Enterprise 2015.x and 2016.x prior to 2016.4.0 includes unsafe string reads that potentially allows for remote code execution on the console node.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3mf2-h46x-xfpw

IBM Security Access Manager for Web is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mcx-xjfh-fh99

During listener modified response processing, a buffer overrun occurs due to lack of buffer size verification when updating message buffer with physical address information in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909W, MSM8917, MSM8953, MSM8996AU, Nicobar, QCM2150, QCS405, QCS605, QM215, Rennell, SA6155P, Saipan, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM632, SDM670, SDM710, SDM845, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3mcx-q4cv-hcc6

An issue was discovered in CipherMail Community Gateway Virtual Appliances and Professional/Enterprise Gateway Virtual Appliances versions 1.0.1 through 4.7.1-0 and CipherMail Webmail Messenger Virtual Appliances 1.1.1 through 3.1.1-0. A Diffie-Hellman parameter of insufficient size could allow man-in-the-middle compromise of communications between CipherMail products and external SMTP clients.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу