Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 376 080

Количество 376 080

github логотип

GHSA-3mch-7p5f-mw9j

больше 4 лет назад

Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host crash) via vectors involving an asynchronous abort while at EL2.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3mch-6gw4-qf68

больше 3 лет назад

Improper restriction of operations within the bounds of a memory buffer in some Intel(R) i915 Graphics drivers for linux before kernel version 6.2.10 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3mcg-4jhc-4p5f

больше 4 лет назад

phpwcms 1.8.9 allows remote attackers to discover the installation path via an invalid csrf_token_value field.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3mcf-r5g4-57jg

больше 4 лет назад

Buffer overflow in mikmod 3.1.6 and earlier allows remote attackers to execute arbitrary code via an archive file that contains a file with a long filename.

EPSS: Низкий
github логотип

GHSA-3mcf-jx37-9qjf

больше 4 лет назад

Microsoft Access 2007 SP3, 2010 SP1 and SP2, and 2013 in Microsoft Office allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Access file, aka "Access File Format Memory Corruption Vulnerability."

EPSS: Средний
github логотип

GHSA-3mcf-6wx8-8w5c

около 2 месяцев назад

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the Telnet configuration interface to inject malicious commands and obtain root privileges on the underlying system.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3mcf-4rgf-4fx9

больше 2 лет назад

HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5HG_read in H5HG.c (called from H5VL__native_blob_get in H5VLnative_blob.c), resulting in the corruption of the instruction pointer.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3mcc-r9wq-f9g6

7 месяцев назад

A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream API. This vulnerability allows exposure of sensitive client credentials and internal infrastructure headers via the test_headers field when an event stream is in test mode. The possible outcome includes leakage of internal infrastructure details, accidental disclosure of user or system credentials, privilege escalation if high-value tokens are exposed, and persistent sensitive data exposure to all users with read access on the event stream.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3mcc-2cg8-vvjx

больше 4 лет назад

pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition when an LDAP directory server responds with a PasswordPolicyResponse control response, which causes the pam_authenticate function to return a success code even if authentication has failed, as originally reported for xscreensaver.

EPSS: Низкий
github логотип

GHSA-3mcc-24f2-h4fr

больше 4 лет назад

Multiple SQL injection vulnerabilities in CMScout 2.06 allow remote authenticated users to execute arbitrary SQL commands via the id parameter to (1) index.php in a mythings page (mythings.php) and (2) the users page in admin.php.

EPSS: Низкий
github логотип

GHSA-3mc9-cqff-fcp8

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in Rainboard before 2.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-3mc9-3c2c-xqg4

почти 3 года назад

Windows Graphics Component Elevation of Privilege Vulnerability

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-3mc8-x7c9-wfw9

9 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: tcp: use dst_dev_rcu() in tcp_fastopen_active_disable_ofo_check() Use RCU to avoid a pair of atomic operations and a potential UAF on dst_dev()->flags.

EPSS: Низкий
github логотип

GHSA-3mc8-g687-m3cf

больше 4 лет назад

A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0787, CVE-2019-1290, CVE-2019-1291.

EPSS: Средний
github логотип

GHSA-3mc8-8xr7-cw36

больше 4 лет назад

Unspecified vulnerability in HP StorageWorks Command View Advanced Edition for XP before 5.6.0-01, XP Replication Monitor before 5.6.0-01, and XP Tiered Storage Manager before 5.5.0-02 allows local users to access other accounts via unspecified vectors during registration or addition of new users.

EPSS: Низкий
github логотип

GHSA-3mc7-mrgm-m6rp

больше 4 лет назад

The ReadSGIImage function in sgi.c in ImageMagick 7.0.5-4 allows remote attackers to consume an amount of available memory via a crafted file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3mc7-4q67-w48m

около 4 лет назад

Uncontrolled Resource Consumption in snakeyaml

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3mc6-qj9j-9v96

7 месяцев назад

Glory RBG-100 recycler systems using the ISPK-08 software component contain hard-coded operating system credentials that allow remote authentication to the underlying Linux system. Multiple local user accounts, including accounts with administrative privileges, were found to have fixed, embedded passwords. An attacker with network access to exposed services such as SSH may authenticate using these credentials and gain unauthorized access to the system. Successful exploitation allows remote access with elevated privileges and may result in full system compromise.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3mc6-pq7x-jqgv

2 месяца назад

A vulnerability was identified in zevorn rt-claw up to 0.2.0. This affects the function claw_net_get/claw_net_post of the file claw/tools/tool_net.c of the component http_request. Such manipulation of the argument url leads to server-side request forgery. The attack may be performed from remote. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-3mc5-w7jh-66fj

больше 4 лет назад

BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier, and 7.0 SP5 and earlier, when fullyDelegatedAuthorization is enabled for a servlet, does not cause servlet deployment to fail when failures occur in authorization or role providers, which might prevent the servlet from being "fully protected."

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3mch-7p5f-mw9j

Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host crash) via vectors involving an asynchronous abort while at EL2.

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3mch-6gw4-qf68

Improper restriction of operations within the bounds of a memory buffer in some Intel(R) i915 Graphics drivers for linux before kernel version 6.2.10 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3mcg-4jhc-4p5f

phpwcms 1.8.9 allows remote attackers to discover the installation path via an invalid csrf_token_value field.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mcf-r5g4-57jg

Buffer overflow in mikmod 3.1.6 and earlier allows remote attackers to execute arbitrary code via an archive file that contains a file with a long filename.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3mcf-jx37-9qjf

Microsoft Access 2007 SP3, 2010 SP1 and SP2, and 2013 in Microsoft Office allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Access file, aka "Access File Format Memory Corruption Vulnerability."

20%
Средний
больше 4 лет назад
github логотип
GHSA-3mcf-6wx8-8w5c

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the Telnet configuration interface to inject malicious commands and obtain root privileges on the underlying system.

CVSS3: 9.8
1%
Низкий
около 2 месяцев назад
github логотип
GHSA-3mcf-4rgf-4fx9

HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5HG_read in H5HG.c (called from H5VL__native_blob_get in H5VLnative_blob.c), resulting in the corruption of the instruction pointer.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3mcc-r9wq-f9g6

A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream API. This vulnerability allows exposure of sensitive client credentials and internal infrastructure headers via the test_headers field when an event stream is in test mode. The possible outcome includes leakage of internal infrastructure details, accidental disclosure of user or system credentials, privilege escalation if high-value tokens are exposed, and persistent sensitive data exposure to all users with read access on the event stream.

CVSS3: 6.7
0%
Низкий
7 месяцев назад
github логотип
GHSA-3mcc-2cg8-vvjx

pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition when an LDAP directory server responds with a PasswordPolicyResponse control response, which causes the pam_authenticate function to return a success code even if authentication has failed, as originally reported for xscreensaver.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-3mcc-24f2-h4fr

Multiple SQL injection vulnerabilities in CMScout 2.06 allow remote authenticated users to execute arbitrary SQL commands via the id parameter to (1) index.php in a mythings page (mythings.php) and (2) the users page in admin.php.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3mc9-cqff-fcp8

Cross-site scripting (XSS) vulnerability in Rainboard before 2.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3mc9-3c2c-xqg4

Windows Graphics Component Elevation of Privilege Vulnerability

CVSS3: 7
6%
Низкий
почти 3 года назад
github логотип
GHSA-3mc8-x7c9-wfw9

In the Linux kernel, the following vulnerability has been resolved: tcp: use dst_dev_rcu() in tcp_fastopen_active_disable_ofo_check() Use RCU to avoid a pair of atomic operations and a potential UAF on dst_dev()->flags.

0%
Низкий
9 месяцев назад
github логотип
GHSA-3mc8-g687-m3cf

A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0787, CVE-2019-1290, CVE-2019-1291.

12%
Средний
больше 4 лет назад
github логотип
GHSA-3mc8-8xr7-cw36

Unspecified vulnerability in HP StorageWorks Command View Advanced Edition for XP before 5.6.0-01, XP Replication Monitor before 5.6.0-01, and XP Tiered Storage Manager before 5.5.0-02 allows local users to access other accounts via unspecified vectors during registration or addition of new users.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-3mc7-mrgm-m6rp

The ReadSGIImage function in sgi.c in ImageMagick 7.0.5-4 allows remote attackers to consume an amount of available memory via a crafted file.

CVSS3: 6.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-3mc7-4q67-w48m

Uncontrolled Resource Consumption in snakeyaml

CVSS3: 7.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-3mc6-qj9j-9v96

Glory RBG-100 recycler systems using the ISPK-08 software component contain hard-coded operating system credentials that allow remote authentication to the underlying Linux system. Multiple local user accounts, including accounts with administrative privileges, were found to have fixed, embedded passwords. An attacker with network access to exposed services such as SSH may authenticate using these credentials and gain unauthorized access to the system. Successful exploitation allows remote access with elevated privileges and may result in full system compromise.

CVSS3: 9.8
1%
Низкий
7 месяцев назад
github логотип
GHSA-3mc6-pq7x-jqgv

A vulnerability was identified in zevorn rt-claw up to 0.2.0. This affects the function claw_net_get/claw_net_post of the file claw/tools/tool_net.c of the component http_request. Such manipulation of the argument url leads to server-side request forgery. The attack may be performed from remote. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 7.3
0%
Низкий
2 месяца назад
github логотип
GHSA-3mc5-w7jh-66fj

BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier, and 7.0 SP5 and earlier, when fullyDelegatedAuthorization is enabled for a servlet, does not cause servlet deployment to fail when failures occur in authorization or role providers, which might prevent the servlet from being "fully protected."

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу