Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-2cjm-p78p-rjpj

больше 4 лет назад

Adobe Animate version 21.0.9 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious .psd file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2cjm-j72p-vj2q

больше 2 лет назад

Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2cjm-f4h6-vv39

4 месяца назад

Out-of-bounds Write vulnerability in WujekFoliarz DualSenseY-v2.This issue affects DualSenseY-v2: before 54.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2cjm-cj9v-8j23

около 4 лет назад

Cross-site scripting (XSS) vulnerability in index.php in phpLinks 2.1.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the term parameter.

EPSS: Низкий
github логотип

GHSA-2cjm-39g8-5fv8

около 4 лет назад

In Shanda MapleStory Online V160, the SdoKeyCrypt.sys driver allows privilege escalation to NT AUTHORITY\SYSTEM because of not validating the IOCtl 0x8000c01c input value, leading to an integer signedness error and a heap-based buffer underflow.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2cjm-2gwv-m892

5 месяцев назад

Parse Server's OAuth2 adapter shares mutable state across providers via singleton instance

EPSS: Низкий
github логотип

GHSA-2cjj-vh62-f62h

около 4 лет назад

IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 through 6.0.6) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 145509.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2cjj-7rx5-5hhq

около 4 лет назад

STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "Read Access Violation on Control Flow starting at Unknown Symbol @ 0x0000000003aa7cef called from Unknown Symbol @ 0x0000000004aa024d."

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2cjh-75gp-34gc

больше 2 лет назад

livewire Cross-Site Request Forgery vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2cjg-pfcc-g8hr

около 4 лет назад

In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related dissectors could crash. This was addressed in epan/dissectors/packet-ber.c by preventing a buffer overflow associated with excessive digits in time values.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2cjg-6xm9-4wh6

около 4 лет назад

IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 could allow remote attackers to bypass authentication via a direct request or forced browsing to a page other than URL intended. IBM X-Force ID: 142561.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2cjg-466r-p8w4

5 месяцев назад

A vulnerability has been found in Ettercap 0.8.4-Garofalo. Affected by this vulnerability is the function add_data_segment of the file src/ettercap/utils/etterfilter/ef_output.c of the component etterfilter. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-2cjf-w7c4-fhf6

больше 4 лет назад

Cross-site Scripting in Beanstalk console

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2cjf-q722-7gc5

около 4 лет назад

SQL injection vulnerability in search_results.php in ABK-Soft AbleDating 2.4 allows remote attackers to execute arbitrary SQL commands via the keyword parameter.

EPSS: Низкий
github логотип

GHSA-2cjf-4qjm-hh7v

больше 3 лет назад

An issue was discovered in Open Ticket Request System (OTRS) 6.0.x before 6.0.12. An attacker could send an e-mail message with a malicious link to an OTRS system or an agent. If a logged-in agent opens this link, it could cause the execution of JavaScript in the context of OTRS.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2cjc-rgmp-x649

около 4 лет назад

Traefik Missing Authentication

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2cjc-6xrh-7w5q

больше 1 года назад

Missing Authorization vulnerability in ThemeSupport Hide Category by User Role for WooCommerce.This issue affects Hide Category by User Role for WooCommerce: from n/a through 2.1.1.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2cjc-543p-gpj8

около 4 лет назад

admin/default.php in PHPMyWind v5.5 has XSS via an HTTP Host header.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2cj9-wjmr-5w57

больше 2 лет назад

An off-by-one error flaw was found in the udevListInterfacesByStatus() function in libvirt when the number of interfaces exceeds the size of the `names` array. This issue can be reproduced by sending specially crafted data to the libvirt daemon, allowing an unprivileged client to perform a denial of service attack by causing the libvirt daemon to crash.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2cj9-r6h5-6jwg

около 4 лет назад

ServerDocs Server in Apple OS X Server before 5.2 supports the RC4 cipher, which might allow remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2cjm-p78p-rjpj

Adobe Animate version 21.0.9 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious .psd file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.

CVSS3: 7.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-2cjm-j72p-vj2q

Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
2%
Низкий
больше 2 лет назад
github логотип
GHSA-2cjm-f4h6-vv39

Out-of-bounds Write vulnerability in WujekFoliarz DualSenseY-v2.This issue affects DualSenseY-v2: before 54.

CVSS3: 7.8
0%
Низкий
4 месяца назад
github логотип
GHSA-2cjm-cj9v-8j23

Cross-site scripting (XSS) vulnerability in index.php in phpLinks 2.1.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the term parameter.

2%
Низкий
около 4 лет назад
github логотип
GHSA-2cjm-39g8-5fv8

In Shanda MapleStory Online V160, the SdoKeyCrypt.sys driver allows privilege escalation to NT AUTHORITY\SYSTEM because of not validating the IOCtl 0x8000c01c input value, leading to an integer signedness error and a heap-based buffer underflow.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2cjm-2gwv-m892

Parse Server's OAuth2 adapter shares mutable state across providers via singleton instance

0%
Низкий
5 месяцев назад
github логотип
GHSA-2cjj-vh62-f62h

IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 through 6.0.6) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 145509.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-2cjj-7rx5-5hhq

STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "Read Access Violation on Control Flow starting at Unknown Symbol @ 0x0000000003aa7cef called from Unknown Symbol @ 0x0000000004aa024d."

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-2cjh-75gp-34gc

livewire Cross-Site Request Forgery vulnerability

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2cjg-pfcc-g8hr

In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related dissectors could crash. This was addressed in epan/dissectors/packet-ber.c by preventing a buffer overflow associated with excessive digits in time values.

CVSS3: 5.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2cjg-6xm9-4wh6

IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 could allow remote attackers to bypass authentication via a direct request or forced browsing to a page other than URL intended. IBM X-Force ID: 142561.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2cjg-466r-p8w4

A vulnerability has been found in Ettercap 0.8.4-Garofalo. Affected by this vulnerability is the function add_data_segment of the file src/ettercap/utils/etterfilter/ef_output.c of the component etterfilter. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 3.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-2cjf-w7c4-fhf6

Cross-site Scripting in Beanstalk console

CVSS3: 6.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2cjf-q722-7gc5

SQL injection vulnerability in search_results.php in ABK-Soft AbleDating 2.4 allows remote attackers to execute arbitrary SQL commands via the keyword parameter.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2cjf-4qjm-hh7v

An issue was discovered in Open Ticket Request System (OTRS) 6.0.x before 6.0.12. An attacker could send an e-mail message with a malicious link to an OTRS system or an agent. If a logged-in agent opens this link, it could cause the execution of JavaScript in the context of OTRS.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2cjc-rgmp-x649

Traefik Missing Authentication

CVSS3: 7.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-2cjc-6xrh-7w5q

Missing Authorization vulnerability in ThemeSupport Hide Category by User Role for WooCommerce.This issue affects Hide Category by User Role for WooCommerce: from n/a through 2.1.1.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-2cjc-543p-gpj8

admin/default.php in PHPMyWind v5.5 has XSS via an HTTP Host header.

CVSS3: 4.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2cj9-wjmr-5w57

An off-by-one error flaw was found in the udevListInterfacesByStatus() function in libvirt when the number of interfaces exceeds the size of the `names` array. This issue can be reproduced by sending specially crafted data to the libvirt daemon, allowing an unprivileged client to perform a denial of service attack by causing the libvirt daemon to crash.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2cj9-r6h5-6jwg

ServerDocs Server in Apple OS X Server before 5.2 supports the RC4 cipher, which might allow remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.

CVSS3: 7.5
2%
Низкий
около 4 лет назад

Уязвимостей на страницу