Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-28wf-jx5m-6fhg

почти 3 года назад

An issue was discovered in kdmserver service in LeEco LeTV X43 version V2401RCN02C080080B04121S, allows attackers to execute arbitrary code, escalate privileges, and cause a denial of service (DoS).

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-28wf-973p-g3gx

больше 4 лет назад

In JetBrains TeamCity before 2021.2.1, the Agent Push feature allowed selection of any private key on the server.

EPSS: Низкий
github логотип

GHSA-28wc-7mwv-p5h3

около 4 лет назад

In Piwigo 11.5.0, there exists a persistent cross-site scripting in the single mode function through /admin.php?page=batch_manager&mode=unit.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-28w9-vf5c-mw9p

около 4 лет назад

E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when successfully exploited could allow a remote attacker to discover system configuration and application information which may aid in crafting more complex attacks.

EPSS: Низкий
github логотип

GHSA-28w9-qhgf-j4rh

12 месяцев назад

Heap buffer overflow in libaom in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to potentially exploit heap corruption via a curated set of gestures. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-28w9-f394-mqfw

около 4 лет назад

Double free vulnerability in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to cause a denial of service (system shutdown) or execute arbitrary code via crafted IPV6 packets.

EPSS: Низкий
github логотип

GHSA-28w9-2v4x-592r

около 1 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kron Technologies Kron PAM allows Stored XSS.This issue affects Kron PAM: before 3.7.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-28w7-pjc6-7h5m

около 4 лет назад

SQL injection vulnerability in index.php in BoonEx Barracuda 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) link_dir_target and (2) link_id_target parameter, possibly involving the link_edit functionality.

EPSS: Низкий
github логотип

GHSA-28w7-9227-5wcm

9 месяцев назад

GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.3, and 18.5 before 18.5.1 that under certain conditions could have allowed authenticated users to gain unauthorized project access by exploiting the access request approval workflow.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-28w7-5v3f-jc8j

около 4 лет назад

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c does not leave room for quote characters, leading to a stack-based buffer overflow.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-28w6-v9pv-jfvr

около 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in BLOG:CMS 4.2.1b allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) admin.php or (2) index.php in photo/.

EPSS: Низкий
github логотип

GHSA-28w5-j8xj-2xwc

почти 5 лет назад

Cross-site Scripting in the yoast_seo TYPO3 extension

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-28w5-8wm6-h27m

больше 3 лет назад

An open redirect in GitLab CE/EE affecting all versions from 10.1 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick users into visiting a trustworthy URL and being redirected to arbitrary content.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-28w4-whch-hx99

17 дней назад

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-28w4-h56g-grg7

почти 4 года назад

Cross-site Scripting in Jenkins Job Configuration History Plugin

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-28w3-wp3w-h9m8

около 4 лет назад

Out of bounds read can happen in diag event set mask command handler when user provided length in the command request is less than expected length in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8096, APQ8096AU, APQ8098, Kamorta, MDM9150, MDM9205, MDM9206, MDM9607, MDM9625, MDM9635M, MDM9640, MDM9650, MDM9655, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCM2150, QCN7605, QCS404, QCS405, QCS605, QM215, Rennell, SA415M, Saipan, SC7180, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX24, SDX55, SM6150, SM7150, SM8150, SXR1130

EPSS: Низкий
github логотип

GHSA-28w3-q8xh-2jcc

больше 1 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Caio Web Dev CWD – Stealth Links allows SQL Injection. This issue affects CWD – Stealth Links: from n/a through 1.3.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-28w3-fc52-f4vq

больше 3 лет назад

A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.264), Parasolid V34.0 (All versions < V34.0.252), Parasolid V34.1 (All versions < V34.1.242), Parasolid V35.0 (All versions < V35.0.170). The affected applications contain an out of bounds write past the end of an allocated structure while parsing specially crafted X_B files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-19079)

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-28w3-f2rh-76x2

около 4 лет назад

Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked addition arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-28w3-5p7x-2j47

около 4 лет назад

Possible out of bound read due to improper validation of packet length while handling data transfer in VR service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-28wf-jx5m-6fhg

An issue was discovered in kdmserver service in LeEco LeTV X43 version V2401RCN02C080080B04121S, allows attackers to execute arbitrary code, escalate privileges, and cause a denial of service (DoS).

CVSS3: 9.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-28wf-973p-g3gx

In JetBrains TeamCity before 2021.2.1, the Agent Push feature allowed selection of any private key on the server.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-28wc-7mwv-p5h3

In Piwigo 11.5.0, there exists a persistent cross-site scripting in the single mode function through /admin.php?page=batch_manager&mode=unit.

CVSS3: 5.4
0%
Низкий
около 4 лет назад
github логотип
GHSA-28w9-vf5c-mw9p

E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when successfully exploited could allow a remote attacker to discover system configuration and application information which may aid in crafting more complex attacks.

1%
Низкий
около 4 лет назад
github логотип
GHSA-28w9-qhgf-j4rh

Heap buffer overflow in libaom in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to potentially exploit heap corruption via a curated set of gestures. (Chromium security severity: High)

CVSS3: 8.8
0%
Низкий
12 месяцев назад
github логотип
GHSA-28w9-f394-mqfw

Double free vulnerability in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to cause a denial of service (system shutdown) or execute arbitrary code via crafted IPV6 packets.

7%
Низкий
около 4 лет назад
github логотип
GHSA-28w9-2v4x-592r

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kron Technologies Kron PAM allows Stored XSS.This issue affects Kron PAM: before 3.7.

CVSS3: 6.1
0%
Низкий
около 1 года назад
github логотип
GHSA-28w7-pjc6-7h5m

SQL injection vulnerability in index.php in BoonEx Barracuda 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) link_dir_target and (2) link_id_target parameter, possibly involving the link_edit functionality.

1%
Низкий
около 4 лет назад
github логотип
GHSA-28w7-9227-5wcm

GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.3, and 18.5 before 18.5.1 that under certain conditions could have allowed authenticated users to gain unauthorized project access by exploiting the access request approval workflow.

CVSS3: 2.7
0%
Низкий
9 месяцев назад
github логотип
GHSA-28w7-5v3f-jc8j

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap_quote_string in imap/util.c does not leave room for quote characters, leading to a stack-based buffer overflow.

CVSS3: 9.8
4%
Низкий
около 4 лет назад
github логотип
GHSA-28w6-v9pv-jfvr

Multiple cross-site scripting (XSS) vulnerabilities in BLOG:CMS 4.2.1b allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) admin.php or (2) index.php in photo/.

2%
Низкий
около 4 лет назад
github логотип
GHSA-28w5-j8xj-2xwc

Cross-site Scripting in the yoast_seo TYPO3 extension

CVSS3: 5.4
0%
Низкий
почти 5 лет назад
github логотип
GHSA-28w5-8wm6-h27m

An open redirect in GitLab CE/EE affecting all versions from 10.1 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick users into visiting a trustworthy URL and being redirected to arbitrary content.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-28w4-whch-hx99

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.

CVSS3: 6.2
0%
Низкий
17 дней назад
github логотип
GHSA-28w4-h56g-grg7

Cross-site Scripting in Jenkins Job Configuration History Plugin

CVSS3: 5.4
1%
Низкий
почти 4 года назад
github логотип
GHSA-28w3-wp3w-h9m8

Out of bounds read can happen in diag event set mask command handler when user provided length in the command request is less than expected length in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8096, APQ8096AU, APQ8098, Kamorta, MDM9150, MDM9205, MDM9206, MDM9607, MDM9625, MDM9635M, MDM9640, MDM9650, MDM9655, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCM2150, QCN7605, QCS404, QCS405, QCS605, QM215, Rennell, SA415M, Saipan, SC7180, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX24, SDX55, SM6150, SM7150, SM8150, SXR1130

0%
Низкий
около 4 лет назад
github логотип
GHSA-28w3-q8xh-2jcc

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Caio Web Dev CWD – Stealth Links allows SQL Injection. This issue affects CWD – Stealth Links: from n/a through 1.3.

CVSS3: 9.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-28w3-fc52-f4vq

A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.264), Parasolid V34.0 (All versions < V34.0.252), Parasolid V34.1 (All versions < V34.1.242), Parasolid V35.0 (All versions < V35.0.170). The affected applications contain an out of bounds write past the end of an allocated structure while parsing specially crafted X_B files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-19079)

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-28w3-f2rh-76x2

Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked addition arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-28w3-5p7x-2j47

Possible out of bound read due to improper validation of packet length while handling data transfer in VR service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables

0%
Низкий
около 4 лет назад

Уязвимостей на страницу