Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-29gf-hgr6-3gvc

около 2 месяцев назад

In multiple functions of DevicePolicyManagerService.java, there is a possible desync from persistence due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-29gc-r2qh-wc5v

7 месяцев назад

A memory initialization issue was addressed with improved memory handling. This issue is fixed in tvOS 26.2, Safari 26.2, watchOS 26.2, visionOS 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2. Processing maliciously crafted web content may disclose internal states of the app.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-29gc-hgfp-33m5

около 4 лет назад

A Blind SQL Injection Vulnerability in Exponent CMS through 2.4.0, with the rerank array parameter, can lead to site database information disclosure and denial of service.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-29g9-qwhc-hg77

около 4 лет назад

Directory traversal vulnerability in Cybozu Garoon 4.2.4 to 4.2.5 allows an attacker to read arbitrary files via Garoon SOAP API "WorkflowHandleApplications".

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-29g9-48v7-9r7c

больше 1 года назад

Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Paid Memberships Pro: from n/a through 3.0.4.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-29g8-xp94-2r42

10 дней назад

Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-29g8-w5j3-pph4

около 4 лет назад

A service which is hosted on port 6998 in HiNet GPON firmware < I040GWR190731 allows an attacker to execute a specific command to read arbitrary files. CVSS 3.0 Base score 9.3. CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L).

EPSS: Низкий
github логотип

GHSA-29g8-6h62-f7vc

около 4 лет назад

Heap-based buffer overflow in Pedro Lineu Orso chetcpasswd 2.3.3 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long REMOTE_ADDR environment variable. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-29g7-m78g-3fx6

больше 4 лет назад

serial_ports administrative program in IRIX 4.x and 5.x trusts the user's PATH environmental variable to find and execute the ls program, which allows local users to gain root privileges via a Trojan horse ls program.

EPSS: Низкий
github логотип

GHSA-29g7-g95p-w4ww

около 4 лет назад

Cross-site scripting (XSS) vulnerability in takeprofedit.php in TBDev.NET DR 11-10-05-BETA-SF1:111005 and earlier allows remote attackers to inject arbitrary web script or HTML via the SRC attribute of a SCRIPT element in the avatar parameter. NOTE: this may be related to the tracker program in the Janitor package. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-29g7-9vcg-g9rm

больше 2 лет назад

Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privileges.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-29g5-m8v7-v564

около 1 года назад

Measured is vulnerable to Path Traversal attacks during class initialization

EPSS: Низкий
github логотип

GHSA-29g4-35pw-347h

больше 2 лет назад

A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 9.5 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as root.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-29g3-4frr-8p4r

около 4 лет назад

Cross-site scripting (XSS) vulnerability in BarracudaDrive Web Server before 3.8 allows remote attackers to inject arbitrary web script or HTML via the URI path in an HTTP GET request, which is activated by administrators viewing log files via the Trace page.

EPSS: Низкий
github логотип

GHSA-29g3-3hqg-cw9q

около 4 лет назад

The H2O Human Harmony Organization (aka com.netpia.ha.theh2o) application 1.6.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-29g3-2vmh-rhvh

10 месяцев назад

Buffer overflow vulnerability in the sensor service. Successful exploitation of this vulnerability may affect availability.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-29g2-mrxj-jw38

около 4 лет назад

In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows before 7.6, multiple memory corruption issues were addressed with improved memory handling.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-29g2-j2qf-h8qw

около 4 лет назад

Out of bounds memory access in the gamepad API in Google Chrome prior to 78.0.3904.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-29g2-g2r5-p4x5

около 4 лет назад

SchedMD Slurm before 17.11.13 and 18.x before 18.08.5 mishandles 32-bit systems.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-29g2-8vj7-7q4q

больше 3 лет назад

A vulnerability classified as critical has been found in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown function of the file recovery.php of the component Password Reset. The manipulation of the argument uname/mobile leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-225360.

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-29gf-hgr6-3gvc

In multiple functions of DevicePolicyManagerService.java, there is a possible desync from persistence due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 5.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-29gc-r2qh-wc5v

A memory initialization issue was addressed with improved memory handling. This issue is fixed in tvOS 26.2, Safari 26.2, watchOS 26.2, visionOS 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2. Processing maliciously crafted web content may disclose internal states of the app.

CVSS3: 4.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-29gc-hgfp-33m5

A Blind SQL Injection Vulnerability in Exponent CMS through 2.4.0, with the rerank array parameter, can lead to site database information disclosure and denial of service.

CVSS3: 9.1
2%
Низкий
около 4 лет назад
github логотип
GHSA-29g9-qwhc-hg77

Directory traversal vulnerability in Cybozu Garoon 4.2.4 to 4.2.5 allows an attacker to read arbitrary files via Garoon SOAP API "WorkflowHandleApplications".

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-29g9-48v7-9r7c

Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Paid Memberships Pro: from n/a through 3.0.4.

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-29g8-xp94-2r42

Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.

CVSS3: 7.5
0%
Низкий
10 дней назад
github логотип
GHSA-29g8-w5j3-pph4

A service which is hosted on port 6998 in HiNet GPON firmware < I040GWR190731 allows an attacker to execute a specific command to read arbitrary files. CVSS 3.0 Base score 9.3. CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L).

1%
Низкий
около 4 лет назад
github логотип
GHSA-29g8-6h62-f7vc

Heap-based buffer overflow in Pedro Lineu Orso chetcpasswd 2.3.3 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long REMOTE_ADDR environment variable. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

0%
Низкий
около 4 лет назад
github логотип
GHSA-29g7-m78g-3fx6

serial_ports administrative program in IRIX 4.x and 5.x trusts the user's PATH environmental variable to find and execute the ls program, which allows local users to gain root privileges via a Trojan horse ls program.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-29g7-g95p-w4ww

Cross-site scripting (XSS) vulnerability in takeprofedit.php in TBDev.NET DR 11-10-05-BETA-SF1:111005 and earlier allows remote attackers to inject arbitrary web script or HTML via the SRC attribute of a SCRIPT element in the avatar parameter. NOTE: this may be related to the tracker program in the Janitor package. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

2%
Низкий
около 4 лет назад
github логотип
GHSA-29g7-9vcg-g9rm

Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privileges.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-29g5-m8v7-v564

Measured is vulnerable to Path Traversal attacks during class initialization

около 1 года назад
github логотип
GHSA-29g4-35pw-347h

A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 9.5 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as root.

CVSS3: 10
2%
Низкий
больше 2 лет назад
github логотип
GHSA-29g3-4frr-8p4r

Cross-site scripting (XSS) vulnerability in BarracudaDrive Web Server before 3.8 allows remote attackers to inject arbitrary web script or HTML via the URI path in an HTTP GET request, which is activated by administrators viewing log files via the Trace page.

4%
Низкий
около 4 лет назад
github логотип
GHSA-29g3-3hqg-cw9q

The H2O Human Harmony Organization (aka com.netpia.ha.theh2o) application 1.6.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
около 4 лет назад
github логотип
GHSA-29g3-2vmh-rhvh

Buffer overflow vulnerability in the sensor service. Successful exploitation of this vulnerability may affect availability.

CVSS3: 5.9
0%
Низкий
10 месяцев назад
github логотип
GHSA-29g2-mrxj-jw38

In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows before 7.6, multiple memory corruption issues were addressed with improved memory handling.

CVSS3: 8.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-29g2-j2qf-h8qw

Out of bounds memory access in the gamepad API in Google Chrome prior to 78.0.3904.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-29g2-g2r5-p4x5

SchedMD Slurm before 17.11.13 and 18.x before 18.08.5 mishandles 32-bit systems.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-29g2-8vj7-7q4q

A vulnerability classified as critical has been found in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown function of the file recovery.php of the component Password Reset. The manipulation of the argument uname/mobile leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-225360.

CVSS3: 9.1
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу