Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 558

Количество 355 558

github логотип

GHSA-xr2p-8p3f-gvvg

около 4 лет назад

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

EPSS: Низкий
github логотип

GHSA-xr2p-42gc-m46q

около 4 лет назад

** DISPUTED ** On ShapeShift KeepKey devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For example, a hardware implant in the USB cable might be able to leverage this behavior to recover secret data shown on the display. In other words, the side channel is relevant only if the attacker has enough control over the device's USB connection to make power-consumption measurements at a time when secret data is displayed. The side channel is not relevant in other circumstances, such as a stolen device that is not currently displaying secret data. NOTE: the vendor's position is that there is "insignificant risk."

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-xr2m-m75v-cg43

больше 4 лет назад

cPanel does not automatically synchronize the PHP open_basedir configuration directive between the main server and virtual hosts that share physical directories, which might allow a local user to bypass open_basedir restrictions and access other virtual hosts via a PHP script that uses a main server URL (such as ~username) that is blocked by the user's own open_basedir directive, but not the main server's open_basedir directive.

EPSS: Низкий
github логотип

GHSA-xr2m-8rhq-x323

около 4 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows an administrator to embed JavaScript code when configuring the name of a database to be monitored. This would be triggered when any authorized user logs into the DBSec interface and opens the properties configuration page for this database.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xr2j-xr37-3jm3

около 4 лет назад

Directory traversal vulnerability in the iNetLanka Multiple Map (com_multimap) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

EPSS: Средний
github логотип

GHSA-xr2j-w2jp-cp5m

больше 4 лет назад

Integer overflow in the JBIG2 decoding feature in Poppler before 0.10.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to CairoOutputDev (CairoOutputDev.cc).

EPSS: Низкий
github логотип

GHSA-xr2h-wg3w-vrcr

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Meeting Room Booking System (MRBS) 1.2.6 allow remote attackers to inject arbitrary web script or HTML via the area parameter to (1) day.php, (2) week.php, (3) month.php, (4) search.php, (5) report.php, and (6) help.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-xr2g-wg2c-hrx6

больше 4 лет назад

Possible assertion due to improper validation of TCI configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xr2g-57fm-4f25

2 месяца назад

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xr2f-69jg-7g6f

больше 1 года назад

Improper access control in some Intel(R) Granulate(TM) software before version 4.30.1 may allow a authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-xr2c-mwcx-4xmj

больше 4 лет назад

Buffer overflow in NIS+, in Sun's rpc.nisd program.

EPSS: Низкий
github логотип

GHSA-xr2c-mghr-gmr2

почти 4 года назад

Missing protection mechanism for alternate hardware interface in SmaCam CS-QR10 all versions and SmaCam Night Vision CS-QR20 all versions allows an attacker to execute an arbitrary OS command by having the product connect to the product's specific serial connection

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-xr2c-6hv6-xcw7

3 дня назад

Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.

EPSS: Низкий
github логотип

GHSA-xr2c-5w89-63pv

больше 4 лет назад

Poetry before v1.1.9 contains Untrusted Search Path

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xr2c-56qc-4ffh

больше 4 лет назад

A CWE-200: Information Exposure vulnerability exists which could allow a session hijack when the door panel is communicating with the door. Affected Product: Ritto Wiser Door (All versions)

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-xr2c-4prw-6479

около 4 лет назад

PHP Scripts Mall advanced-real-estate-script 4.0.9 has CSRF via edit-profile.php.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-xr29-6gg3-jq8m

больше 4 лет назад

SQL injection vulnerability in Page.asp in Baseline CMS 1.95 and earlier allows remote attackers to execute arbitrary SQL commands via the SiteNodeID parameter.

EPSS: Низкий
github логотип

GHSA-xr29-4f97-vhvq

5 месяцев назад

A vulnerability was found in code-projects Student Web Portal 1.0. Affected is an unknown function of the file profile.php. The manipulation of the argument User results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xr28-hrcf-5jw6

почти 2 года назад

Local active protection service settings manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows, macOS) before build 38565.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-xr28-f4wv-gfp3

около 4 лет назад

An issue was discovered in PHP Scripts Mall Investment MLM Software 2.0.2. Stored XSS was found in the the My Profile Section. This is due to lack of sanitization in the Edit Name section.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xr2p-8p3f-gvvg

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.28 and prior to 6.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

1%
Низкий
около 4 лет назад
github логотип
GHSA-xr2p-42gc-m46q

** DISPUTED ** On ShapeShift KeepKey devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For example, a hardware implant in the USB cable might be able to leverage this behavior to recover secret data shown on the display. In other words, the side channel is relevant only if the attacker has enough control over the device's USB connection to make power-consumption measurements at a time when secret data is displayed. The side channel is not relevant in other circumstances, such as a stolen device that is not currently displaying secret data. NOTE: the vendor's position is that there is "insignificant risk."

CVSS3: 2.4
0%
Низкий
около 4 лет назад
github логотип
GHSA-xr2m-m75v-cg43

cPanel does not automatically synchronize the PHP open_basedir configuration directive between the main server and virtual hosts that share physical directories, which might allow a local user to bypass open_basedir restrictions and access other virtual hosts via a PHP script that uses a main server URL (such as ~username) that is blocked by the user's own open_basedir directive, but not the main server's open_basedir directive.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xr2m-8rhq-x323

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows an administrator to embed JavaScript code when configuring the name of a database to be monitored. This would be triggered when any authorized user logs into the DBSec interface and opens the properties configuration page for this database.

CVSS3: 4.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xr2j-xr37-3jm3

Directory traversal vulnerability in the iNetLanka Multiple Map (com_multimap) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

16%
Средний
около 4 лет назад
github логотип
GHSA-xr2j-w2jp-cp5m

Integer overflow in the JBIG2 decoding feature in Poppler before 0.10.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to CairoOutputDev (CairoOutputDev.cc).

7%
Низкий
больше 4 лет назад
github логотип
GHSA-xr2h-wg3w-vrcr

Multiple cross-site scripting (XSS) vulnerabilities in Meeting Room Booking System (MRBS) 1.2.6 allow remote attackers to inject arbitrary web script or HTML via the area parameter to (1) day.php, (2) week.php, (3) month.php, (4) search.php, (5) report.php, and (6) help.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xr2g-wg2c-hrx6

Possible assertion due to improper validation of TCI configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xr2g-57fm-4f25

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 5.5
0%
Низкий
2 месяца назад
github логотип
GHSA-xr2f-69jg-7g6f

Improper access control in some Intel(R) Granulate(TM) software before version 4.30.1 may allow a authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 4.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-xr2c-mwcx-4xmj

Buffer overflow in NIS+, in Sun's rpc.nisd program.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-xr2c-mghr-gmr2

Missing protection mechanism for alternate hardware interface in SmaCam CS-QR10 all versions and SmaCam Night Vision CS-QR20 all versions allows an attacker to execute an arbitrary OS command by having the product connect to the product's specific serial connection

CVSS3: 6.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xr2c-6hv6-xcw7

Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.

3 дня назад
github логотип
GHSA-xr2c-5w89-63pv

Poetry before v1.1.9 contains Untrusted Search Path

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xr2c-56qc-4ffh

A CWE-200: Information Exposure vulnerability exists which could allow a session hijack when the door panel is communicating with the door. Affected Product: Ritto Wiser Door (All versions)

CVSS3: 7.6
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xr2c-4prw-6479

PHP Scripts Mall advanced-real-estate-script 4.0.9 has CSRF via edit-profile.php.

CVSS3: 8
0%
Низкий
около 4 лет назад
github логотип
GHSA-xr29-6gg3-jq8m

SQL injection vulnerability in Page.asp in Baseline CMS 1.95 and earlier allows remote attackers to execute arbitrary SQL commands via the SiteNodeID parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xr29-4f97-vhvq

A vulnerability was found in code-projects Student Web Portal 1.0. Affected is an unknown function of the file profile.php. The manipulation of the argument User results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.

CVSS3: 6.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-xr28-hrcf-5jw6

Local active protection service settings manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows, macOS) before build 38565.

CVSS3: 4.7
0%
Низкий
почти 2 года назад
github логотип
GHSA-xr28-f4wv-gfp3

An issue was discovered in PHP Scripts Mall Investment MLM Software 2.0.2. Stored XSS was found in the the My Profile Section. This is due to lack of sanitization in the Edit Name section.

CVSS3: 5.4
1%
Низкий
около 4 лет назад

Уязвимостей на страницу