Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-2cgq-5ww9-3c6v

почти 3 года назад

XNSoft Nconvert 7.136 has an Exception Handler Chain Corrupted via a crafted image file. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2cgp-x82p-v5h2

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in ninotheme Nino Social Connect allows Stored XSS. This issue affects Nino Social Connect: from n/a through 2.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2cgp-p7jr-3hv7

около 3 лет назад

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. An app may be able to break out of its sandbox

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-2cgp-j8vp-ww2f

около 2 лет назад

In ensureFileColumns of MediaProvider.java, there is a possible disclosure of files owned by another user due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-2cgp-h7jq-hhwj

больше 3 лет назад

A missing authentication for a critical function vulnerability in Fortinet FortiSOAR 6.4.0 - 6.4.4 and 7.0.0 - 7.0.3 and 7.2.0 allows an attacker to disclose information via logging into the database using a privileged account without a password.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2cgp-5g8f-36f9

около 4 лет назад

The RealServer RealSubscriber on Cisco devices running Application and Content Networking System (ACNS) 5.1 allow remote attackers to cause a denial of service (CPU consumption) via malformed packets.

EPSS: Низкий
github логотип

GHSA-2cgm-vmgv-mqwg

10 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SAPO SAPO Feed allows Stored XSS. This issue affects SAPO Feed: from n/a through 2.4.2.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2cgm-r77w-c7r9

около 4 лет назад

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "CoreText" component. It allows remote attackers to cause a denial of service (application crash) via a crafted file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2cgm-qw4f-q8cr

больше 4 лет назад

TuziCMS v2.0.6 was discovered to contain a SQL injection vulnerability via the component App\Manage\Controller\ZhuantiController.class.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2cgm-mxqq-wprv

больше 4 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in FuseTalk 2.0 allows remote attackers to create arbitrary accounts via a link to adduser.cfm.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2cgh-v7qq-5hw9

около 4 лет назад

Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 20061110 allow remote attackers to execute arbitrary PHP code via a URL in the g_documentRoot parameter to (1) bugreporter/thankyou.php and (2) feedback/thankyou.php in implementation/management/priv/.

EPSS: Низкий
github логотип

GHSA-2cgh-f33f-2mv2

больше 1 года назад

A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2cgh-c72w-rfjm

около 21 часа назад

An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the CheckUils.php file

EPSS: Низкий
github логотип

GHSA-2cgh-c2fq-mxqp

4 месяца назад

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2cgh-57h5-g49r

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Teplitsa. Technologies for Social Good ShMapper by Teplitsa allows Stored XSS. This issue affects ShMapper by Teplitsa: from n/a through 1.5.0.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2cgf-9596-49ff

около 4 лет назад

A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0851, CVE-2020-0852, CVE-2020-0855, CVE-2020-0892.

EPSS: Низкий
github логотип

GHSA-2cg9-g249-7mf2

около 4 лет назад

The Rust Programming Language Standard Library version 1.29.0, 1.28.0, 1.27.2, 1.27.1, 127.0, 126.2, 126.1, 126.0 contains a CWE-680: Integer Overflow to Buffer Overflow vulnerability in standard library that can result in buffer overflow. This attack appear to be exploitable via str::repeat, passed a large number, can overflow an internal buffer. This vulnerability appears to have been fixed in 1.29.1.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2cg8-626m-7pjv

около 4 лет назад

Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2cg8-29w5-5m74

10 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: mt76: mt7915: Fix PCI device refcount leak in mt7915_pci_init_hif2() As comment of pci_get_device() says, it returns a pci_device with its refcount increased. We need to call pci_dev_put() to decrease the refcount. Save the return value of pci_get_device() and call pci_dev_put() to decrease the refcount.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2cg7-x3pg-q7xf

8 месяцев назад

Out-of-bounds write in cdfs_open_cue_track in libretro libretro-common latest on all platforms allows remote attackers to execute arbitrary code via a crafted .cue file with a file path exceeding PATH_MAX_LENGTH that is copied using memcpy into a fixed-size buffer.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2cgq-5ww9-3c6v

XNSoft Nconvert 7.136 has an Exception Handler Chain Corrupted via a crafted image file. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution.

CVSS3: 7.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-2cgp-x82p-v5h2

Cross-Site Request Forgery (CSRF) vulnerability in ninotheme Nino Social Connect allows Stored XSS. This issue affects Nino Social Connect: from n/a through 2.0.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-2cgp-p7jr-3hv7

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. An app may be able to break out of its sandbox

CVSS3: 8.6
0%
Низкий
около 3 лет назад
github логотип
GHSA-2cgp-j8vp-ww2f

In ensureFileColumns of MediaProvider.java, there is a possible disclosure of files owned by another user due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 6.2
0%
Низкий
около 2 лет назад
github логотип
GHSA-2cgp-h7jq-hhwj

A missing authentication for a critical function vulnerability in Fortinet FortiSOAR 6.4.0 - 6.4.4 and 7.0.0 - 7.0.3 and 7.2.0 allows an attacker to disclose information via logging into the database using a privileged account without a password.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2cgp-5g8f-36f9

The RealServer RealSubscriber on Cisco devices running Application and Content Networking System (ACNS) 5.1 allow remote attackers to cause a denial of service (CPU consumption) via malformed packets.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2cgm-vmgv-mqwg

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SAPO SAPO Feed allows Stored XSS. This issue affects SAPO Feed: from n/a through 2.4.2.

CVSS3: 5.9
0%
Низкий
10 месяцев назад
github логотип
GHSA-2cgm-r77w-c7r9

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "CoreText" component. It allows remote attackers to cause a denial of service (application crash) via a crafted file.

CVSS3: 5.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2cgm-qw4f-q8cr

TuziCMS v2.0.6 was discovered to contain a SQL injection vulnerability via the component App\Manage\Controller\ZhuantiController.class.php.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-2cgm-mxqq-wprv

Cross-Site Request Forgery (CSRF) vulnerability in FuseTalk 2.0 allows remote attackers to create arbitrary accounts via a link to adduser.cfm.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-2cgh-v7qq-5hw9

Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 20061110 allow remote attackers to execute arbitrary PHP code via a URL in the g_documentRoot parameter to (1) bugreporter/thankyou.php and (2) feedback/thankyou.php in implementation/management/priv/.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2cgh-f33f-2mv2

A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-2cgh-c72w-rfjm

An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the CheckUils.php file

около 21 часа назад
github логотип
GHSA-2cgh-c2fq-mxqp

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
0%
Низкий
4 месяца назад
github логотип
GHSA-2cgh-57h5-g49r

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Teplitsa. Technologies for Social Good ShMapper by Teplitsa allows Stored XSS. This issue affects ShMapper by Teplitsa: from n/a through 1.5.0.

CVSS3: 5.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-2cgf-9596-49ff

A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0851, CVE-2020-0852, CVE-2020-0855, CVE-2020-0892.

9%
Низкий
около 4 лет назад
github логотип
GHSA-2cg9-g249-7mf2

The Rust Programming Language Standard Library version 1.29.0, 1.28.0, 1.27.2, 1.27.1, 127.0, 126.2, 126.1, 126.0 contains a CWE-680: Integer Overflow to Buffer Overflow vulnerability in standard library that can result in buffer overflow. This attack appear to be exploitable via str::repeat, passed a large number, can overflow an internal buffer. This vulnerability appears to have been fixed in 1.29.1.

CVSS3: 9.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-2cg8-626m-7pjv

Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 7.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-2cg8-29w5-5m74

In the Linux kernel, the following vulnerability has been resolved: mt76: mt7915: Fix PCI device refcount leak in mt7915_pci_init_hif2() As comment of pci_get_device() says, it returns a pci_device with its refcount increased. We need to call pci_dev_put() to decrease the refcount. Save the return value of pci_get_device() and call pci_dev_put() to decrease the refcount.

CVSS3: 5.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-2cg7-x3pg-q7xf

Out-of-bounds write in cdfs_open_cue_track in libretro libretro-common latest on all platforms allows remote attackers to execute arbitrary code via a crafted .cue file with a file path exceeding PATH_MAX_LENGTH that is copied using memcpy into a fixed-size buffer.

CVSS3: 9.8
0%
Низкий
8 месяцев назад

Уязвимостей на страницу