Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 269

Количество 353 269

github логотип

GHSA-2ch6-jww2-3r97

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the Web GUI in SAP Web Application Server (WAS) 7.0, Web Dynpro for ABAP (aka WD4A or WDA), and Web Dynpro for BSP allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under bc/gui/sap/its/webgui/.

EPSS: Низкий
github логотип

GHSA-2ch6-g4cg-g5ph

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ByteLabX Pdf Embedder Fay allows DOM-Based XSS.This issue affects Pdf Embedder Fay: from n/a through 1.10.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2ch6-fw6m-3v29

около 2 лет назад

An issue was discovered in Samsung Mobile Processor, Automotive Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 2200, 1280, 1380, 1330, Modem 5123, Modem 5300, and Auto T5123. The baseband software does not properly check format types specified by the NAS (Non-Access-Stratum) module. This can lead to bypass of authentication.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-2ch6-33cf-cx8p

около 4 лет назад

Cross-site scripting (XSS) vulnerability in index.php for Quick.cart 0.3.0 allows remote attackers to inject arbitrary web script or HTML via the sWord parameter.

EPSS: Низкий
github логотип

GHSA-2ch5-gmrh-68h8

больше 3 лет назад

Aver Information Inc PTZApp2 v20.01044.48 allows attackers to access sensitive files via a crafted GET request.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2ch4-vpw2-3h66

больше 4 лет назад

Dell PowerScale OneFS versions 8.2.x - 9.3.0.x contains a denial-of-service vulnerability in SmartConnect. An unprivileged network attacker could potentially exploit this vulnerability, leading to denial-of-service. (of course this is temporary and will need to be adapted/reviewed as we determine the CWE with Srisimha Tummala 's help)

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2ch2-m5qc-grp2

около 4 лет назад

Multiple use-after-free vulnerabilities in the gx_image_enum_begin function in base/gxipixel.c in Ghostscript before ecceafe3abba2714ef9b432035fe0739d9b1a283 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PostScript document.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2ch2-jw27-c5r3

почти 3 года назад

In Bluetooth, there is a possible way for a paired Bluetooth device to access a long term identifier for an Android device due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-2ch2-j7qp-pqm3

4 месяца назад

XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can inject malicious scripts through BB code that are stored and executed when other users view the content.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-2ch2-ch47-wm8m

около 4 лет назад

Integer overflow in the ib_uverbs_poll_cq function in drivers/infiniband/core/uverbs_cmd.c in the Linux kernel before 2.6.37 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a large value of a certain structure member.

EPSS: Низкий
github логотип

GHSA-2cgx-fc69-pwm2

около 4 лет назад

In avrc_ctrl_pars_vendor_rsp of bluetooth avrcp_ctrl, there is a possible out of bounds write on the stack due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-71603410.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2cgw-gvv3-hc6c

больше 2 лет назад

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Om Ak Solutions Slick Popup: Contact Form 7 Popup Plugin plugin <= 1.7.14 versions.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2cgw-c87g-ww8q

около 4 лет назад

OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middle attacker to bypass the certificate authentication by issuing an unrelated server certificate using the same hostname found in the verify-x509-name option in a client configuration.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-2cgv-xp72-gv7r

почти 3 года назад

A use after free in r_reg_set_value function in radare2 5.4.2 and 5.4.0.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2cgv-wgf2-f376

больше 4 лет назад

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. ModifyUser param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2cgv-9p9x-26g8

около 4 лет назад

Possible out of bound access due to lack of validation of page offset before page is inserted in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

EPSS: Низкий
github логотип

GHSA-2cgv-7m8h-63j7

около 4 лет назад

Microsoft Windows Mobile 6.0 on HTC Wiza 200 and HTC MDA 8125 devices does not properly handle the first attempt to establish a Bluetooth connection to a peer with a long name, which allows remote attackers to cause a denial of service (device reboot) by configuring a Bluetooth device with a long hci name and (1) connecting directly to the Windows Mobile system or (2) waiting for the Windows Mobile system to scan for nearby devices.

EPSS: Средний
github логотип

GHSA-2cgv-28vr-rv6j

8 месяцев назад

libcrux incorrectly calculates on aarch64

EPSS: Низкий
github логотип

GHSA-2cgr-rv3r-g9vw

больше 1 года назад

Missing Authorization vulnerability in Genetech Pie Register Premium.This issue affects Pie Register Premium: from n/a before 3.8.3.3.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2cgq-rm2f-x3x7

около 4 лет назад

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Exynos chipsets) software. There is a baseband heap overflow. The Samsung ID is SVE-2018-13187 (February 2019).

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2ch6-jww2-3r97

Cross-site scripting (XSS) vulnerability in the Web GUI in SAP Web Application Server (WAS) 7.0, Web Dynpro for ABAP (aka WD4A or WDA), and Web Dynpro for BSP allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under bc/gui/sap/its/webgui/.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2ch6-g4cg-g5ph

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ByteLabX Pdf Embedder Fay allows DOM-Based XSS.This issue affects Pdf Embedder Fay: from n/a through 1.10.1.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2ch6-fw6m-3v29

An issue was discovered in Samsung Mobile Processor, Automotive Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 2200, 1280, 1380, 1330, Modem 5123, Modem 5300, and Auto T5123. The baseband software does not properly check format types specified by the NAS (Non-Access-Stratum) module. This can lead to bypass of authentication.

CVSS3: 3.7
0%
Низкий
около 2 лет назад
github логотип
GHSA-2ch6-33cf-cx8p

Cross-site scripting (XSS) vulnerability in index.php for Quick.cart 0.3.0 allows remote attackers to inject arbitrary web script or HTML via the sWord parameter.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2ch5-gmrh-68h8

Aver Information Inc PTZApp2 v20.01044.48 allows attackers to access sensitive files via a crafted GET request.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2ch4-vpw2-3h66

Dell PowerScale OneFS versions 8.2.x - 9.3.0.x contains a denial-of-service vulnerability in SmartConnect. An unprivileged network attacker could potentially exploit this vulnerability, leading to denial-of-service. (of course this is temporary and will need to be adapted/reviewed as we determine the CWE with Srisimha Tummala 's help)

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2ch2-m5qc-grp2

Multiple use-after-free vulnerabilities in the gx_image_enum_begin function in base/gxipixel.c in Ghostscript before ecceafe3abba2714ef9b432035fe0739d9b1a283 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PostScript document.

CVSS3: 7.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2ch2-jw27-c5r3

In Bluetooth, there is a possible way for a paired Bluetooth device to access a long term identifier for an Android device due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

CVSS3: 5
0%
Низкий
почти 3 года назад
github логотип
GHSA-2ch2-j7qp-pqm3

XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can inject malicious scripts through BB code that are stored and executed when other users view the content.

CVSS3: 6.4
0%
Низкий
4 месяца назад
github логотип
GHSA-2ch2-ch47-wm8m

Integer overflow in the ib_uverbs_poll_cq function in drivers/infiniband/core/uverbs_cmd.c in the Linux kernel before 2.6.37 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a large value of a certain structure member.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2cgx-fc69-pwm2

In avrc_ctrl_pars_vendor_rsp of bluetooth avrcp_ctrl, there is a possible out of bounds write on the stack due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-71603410.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-2cgw-gvv3-hc6c

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Om Ak Solutions Slick Popup: Contact Form 7 Popup Plugin plugin <= 1.7.14 versions.

CVSS3: 4.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2cgw-c87g-ww8q

OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middle attacker to bypass the certificate authentication by issuing an unrelated server certificate using the same hostname found in the verify-x509-name option in a client configuration.

CVSS3: 7.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-2cgv-xp72-gv7r

A use after free in r_reg_set_value function in radare2 5.4.2 and 5.4.0.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-2cgv-wgf2-f376

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. ModifyUser param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2cgv-9p9x-26g8

Possible out of bound access due to lack of validation of page offset before page is inserted in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

0%
Низкий
около 4 лет назад
github логотип
GHSA-2cgv-7m8h-63j7

Microsoft Windows Mobile 6.0 on HTC Wiza 200 and HTC MDA 8125 devices does not properly handle the first attempt to establish a Bluetooth connection to a peer with a long name, which allows remote attackers to cause a denial of service (device reboot) by configuring a Bluetooth device with a long hci name and (1) connecting directly to the Windows Mobile system or (2) waiting for the Windows Mobile system to scan for nearby devices.

30%
Средний
около 4 лет назад
github логотип
GHSA-2cgv-28vr-rv6j

libcrux incorrectly calculates on aarch64

8 месяцев назад
github логотип
GHSA-2cgr-rv3r-g9vw

Missing Authorization vulnerability in Genetech Pie Register Premium.This issue affects Pie Register Premium: from n/a before 3.8.3.3.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2cgq-rm2f-x3x7

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Exynos chipsets) software. There is a baseband heap overflow. The Samsung ID is SVE-2018-13187 (February 2019).

1%
Низкий
около 4 лет назад

Уязвимостей на страницу