Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-2c88-v3f4-r6jr

около 4 лет назад

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.6. A local user may be able to cause unexpected system termination or read kernel memory.

EPSS: Низкий
github логотип

GHSA-2c88-8r97-2vcx

около 1 года назад

Substance3D - Stager versions 3.1.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2c86-c788-7r54

около 4 лет назад

Multiple heap-based buffer overflows in xine-lib 1.1.12, and other versions before 1.1.15, allow remote attackers to execute arbitrary code via vectors related to (1) a crafted metadata atom size processed by the parse_moov_atom function in demux_qt.c and (2) frame reading in the id3v23_interp_frame function in id3.c. NOTE: as of 20081122, it is possible that vector 1 has not been fixed in 1.1.15.

EPSS: Низкий
github логотип

GHSA-2c85-rfcc-g74j

около 1 месяца назад

Karate Mock Server RCE via embedded expression evaluation of request-derived data

EPSS: Низкий
github логотип

GHSA-2c85-r6w7-qf97

около 4 лет назад

SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on the GroupSummaryCounts related table.

EPSS: Низкий
github логотип

GHSA-2c85-mrfp-x4x7

около 4 лет назад

A vulnerability in the web UI of Cisco SD-WAN Solution vManage software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists because the web UI improperly validates SQL values. An attacker could exploit this vulnerability by authenticating to the application and sending malicious SQL queries to an affected system. A successful exploit could allow the attacker to modify values on, or return values from, the underlying database as well as the operating system.

CVSS3: 8.1
EPSS: Средний
github логотип

GHSA-2c84-35rv-6q3f

около 4 лет назад

Stored XSS vulnerability in ClearCase Release Plugin

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-2c83-wfv3-q25f

почти 5 лет назад

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in ZMarkdown

EPSS: Низкий
github логотип

GHSA-2c83-rhjj-cjg4

больше 2 лет назад

The Online-Ausweis-Funktion eID scheme in the German National Identity card through 2024-02-15 allows authentication bypass by spoofing. A man-in-the-middle attacker can assume a victim's identify for access to government, medical, and financial resources, and can also extract personal data from the card, aka the "sPACE (Spoofing Password Authenticated Connection Establishment)" issue. This occurs because of a combination of factors, such as insecure PIN entry (for basic readers) and eid:// deeplinking. The victim must be using a modified eID kernel, which may occur if the victim is tricked into installing a fake version of an official app. NOTE: the BSI position is "ensuring a secure operational environment at the client side is an obligation of the ID card owner."

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-2c82-pcxm-wpqf

больше 4 лет назад

The License Manager (mathlm) for Mathematica 4.0 and 4.1 allows remote attackers to cause a denial of service (resource exhaustion) by connecting to port 16286 and not disconnecting, which prevents users from making license requests.

EPSS: Низкий
github логотип

GHSA-2c82-m7qw-rh64

больше 1 года назад

SunGrow WiNet-S V200.001.00.P025 and earlier versions is missing integrity checks for firmware upgrades. Sending a specific MQTT message allows an update to an inverter or a WiNet connectivity dongle with a bogus firmware file that is located on attacker-controlled server.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2c82-jh24-wvh5

4 месяца назад

The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.12 via the syncedData function. This makes it possible for unauthenticated attackers to extract sensitive data including user names, emails, phone numbers, addresses.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2c82-gggj-55f4

около 4 лет назад

Buffer overflow in the CGM image converter in the graphics filters in Microsoft Office XP SP3, Office 2003 SP3, and Office Converter Pack allows remote attackers to execute arbitrary code via a crafted CGM image in an Office document, aka "CGM Image Converter Buffer Overrun Vulnerability."

EPSS: Средний
github логотип

GHSA-2c82-fg6w-rjhp

больше 2 лет назад

A vulnerability was found in Jspxcms 10.2.0 and classified as problematic. This issue affects some unknown processing of the file /ext/collect/filter_text.do. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252995.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-2c82-59ww-vx6g

больше 1 года назад

Path Traversal vulnerability in NotFound ARForms allows Path Traversal.This issue affects ARForms: from n/a through 6.4.1.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-2c7x-w3mx-h7p6

больше 2 лет назад

Microweber file upload vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2c7x-f37h-c5qh

около 4 лет назад

The BBC Knowledge Magazine (aka com.magzter.bbcknowledge) application 3.01 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-2c7w-v459-cwgf

больше 4 лет назад

MotionEye allows attackers to access sensitive information

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2c7w-qmwm-xgjp

больше 4 лет назад

There is a memory leak vulnerability in CloudEngine 12800 V200R019C00SPC800, CloudEngine 5800 V200R019C00SPC800, CloudEngine 6800 V200R019C00SPC800 and CloudEngine 7800 V200R019C00SPC800. The software does not sufficiently track and release allocated memory while parse a series of crafted binary messages, which could consume remaining memory. Successful exploit could cause memory exhaust.

EPSS: Низкий
github логотип

GHSA-2c7v-qcjp-4mg2

больше 3 лет назад

.NET Remote Code Execution Vulnerability

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2c88-v3f4-r6jr

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.6. A local user may be able to cause unexpected system termination or read kernel memory.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2c88-8r97-2vcx

Substance3D - Stager versions 3.1.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-2c86-c788-7r54

Multiple heap-based buffer overflows in xine-lib 1.1.12, and other versions before 1.1.15, allow remote attackers to execute arbitrary code via vectors related to (1) a crafted metadata atom size processed by the parse_moov_atom function in demux_qt.c and (2) frame reading in the id3v23_interp_frame function in id3.c. NOTE: as of 20081122, it is possible that vector 1 has not been fixed in 1.1.15.

6%
Низкий
около 4 лет назад
github логотип
GHSA-2c85-rfcc-g74j

Karate Mock Server RCE via embedded expression evaluation of request-derived data

около 1 месяца назад
github логотип
GHSA-2c85-r6w7-qf97

SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on the GroupSummaryCounts related table.

5%
Низкий
около 4 лет назад
github логотип
GHSA-2c85-mrfp-x4x7

A vulnerability in the web UI of Cisco SD-WAN Solution vManage software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists because the web UI improperly validates SQL values. An attacker could exploit this vulnerability by authenticating to the application and sending malicious SQL queries to an affected system. A successful exploit could allow the attacker to modify values on, or return values from, the underlying database as well as the operating system.

CVSS3: 8.1
54%
Средний
около 4 лет назад
github логотип
GHSA-2c84-35rv-6q3f

Stored XSS vulnerability in ClearCase Release Plugin

CVSS3: 8
1%
Низкий
около 4 лет назад
github логотип
GHSA-2c83-wfv3-q25f

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in ZMarkdown

почти 5 лет назад
github логотип
GHSA-2c83-rhjj-cjg4

The Online-Ausweis-Funktion eID scheme in the German National Identity card through 2024-02-15 allows authentication bypass by spoofing. A man-in-the-middle attacker can assume a victim's identify for access to government, medical, and financial resources, and can also extract personal data from the card, aka the "sPACE (Spoofing Password Authenticated Connection Establishment)" issue. This occurs because of a combination of factors, such as insecure PIN entry (for basic readers) and eid:// deeplinking. The victim must be using a modified eID kernel, which may occur if the victim is tricked into installing a fake version of an official app. NOTE: the BSI position is "ensuring a secure operational environment at the client side is an obligation of the ID card owner."

CVSS3: 9.6
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2c82-pcxm-wpqf

The License Manager (mathlm) for Mathematica 4.0 and 4.1 allows remote attackers to cause a denial of service (resource exhaustion) by connecting to port 16286 and not disconnecting, which prevents users from making license requests.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2c82-m7qw-rh64

SunGrow WiNet-S V200.001.00.P025 and earlier versions is missing integrity checks for firmware upgrades. Sending a specific MQTT message allows an update to an inverter or a WiNet connectivity dongle with a bogus firmware file that is located on attacker-controlled server.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2c82-jh24-wvh5

The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.12 via the syncedData function. This makes it possible for unauthenticated attackers to extract sensitive data including user names, emails, phone numbers, addresses.

CVSS3: 5.3
0%
Низкий
4 месяца назад
github логотип
GHSA-2c82-gggj-55f4

Buffer overflow in the CGM image converter in the graphics filters in Microsoft Office XP SP3, Office 2003 SP3, and Office Converter Pack allows remote attackers to execute arbitrary code via a crafted CGM image in an Office document, aka "CGM Image Converter Buffer Overrun Vulnerability."

25%
Средний
около 4 лет назад
github логотип
GHSA-2c82-fg6w-rjhp

A vulnerability was found in Jspxcms 10.2.0 and classified as problematic. This issue affects some unknown processing of the file /ext/collect/filter_text.do. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252995.

CVSS3: 3.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-2c82-59ww-vx6g

Path Traversal vulnerability in NotFound ARForms allows Path Traversal.This issue affects ARForms: from n/a through 6.4.1.

CVSS3: 7.7
1%
Низкий
больше 1 года назад
github логотип
GHSA-2c7x-w3mx-h7p6

Microweber file upload vulnerability

CVSS3: 8.8
2%
Низкий
больше 2 лет назад
github логотип
GHSA-2c7x-f37h-c5qh

The BBC Knowledge Magazine (aka com.magzter.bbcknowledge) application 3.01 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2c7w-v459-cwgf

MotionEye allows attackers to access sensitive information

CVSS3: 7.5
7%
Низкий
больше 4 лет назад
github логотип
GHSA-2c7w-qmwm-xgjp

There is a memory leak vulnerability in CloudEngine 12800 V200R019C00SPC800, CloudEngine 5800 V200R019C00SPC800, CloudEngine 6800 V200R019C00SPC800 and CloudEngine 7800 V200R019C00SPC800. The software does not sufficiently track and release allocated memory while parse a series of crafted binary messages, which could consume remaining memory. Successful exploit could cause memory exhaust.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2c7v-qcjp-4mg2

.NET Remote Code Execution Vulnerability

CVSS3: 8.8
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу