Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 269

Количество 353 269

github логотип

GHSA-28ff-x3xj-mx7q

около 4 лет назад

An information disclosure vulnerability in libstagefright in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Android ID: A-31091777.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-28fc-gvjg-5f4h

около 4 лет назад

** UNSUPPORTED WHEN ASSIGNED ** The unofficial vscode-sass-lint (aka Sass Lint) extension through 1.0.7 for Visual Studio Code allows attackers to execute arbitrary binaries if the user opens a crafted workspace. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-28f9-43w8-v45c

около 4 лет назад

Buffer overflow in the ILASM assembler in the Microsoft .NET 1.0 and 1.1 Framework might allow user-assisted attackers to execute arbitrary code via a .il file that calls a function with a long name.

EPSS: Низкий
github логотип

GHSA-28f8-hqmc-7ph8

почти 6 лет назад

Malicious Package in ember-power-timepicker

EPSS: Низкий
github логотип

GHSA-28f7-mc45-4x8m

почти 2 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gordon Böhme, Antonio Leutsch Structured Content allows Stored XSS.This issue affects Structured Content: from n/a through 1.6.2.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-28f7-g5r5-mpx5

около 3 лет назад

In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-28f6-9xpw-pwcr

около 4 лет назад

Cross-site scripting (XSS) vulnerability in core/summary_api.php in MantisBT before 1.2.3 allows remote attackers to inject arbitrary web script or HTML via the Summary field, a different vector than CVE-2010-3303.

EPSS: Низкий
github логотип

GHSA-28f6-647f-xq87

около 4 лет назад

Buffer overflow in SonicWall SMA100 allows an authenticated user to execute arbitrary code in DEARegister CGI script. This vulnerability impacted SMA100 version 9.0.0.3 and earlier.

EPSS: Низкий
github логотип

GHSA-28f5-mg2c-r34c

около 4 лет назад

Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScript API execution via unspecified vectors, a different vulnerability than CVE-2015-3060, CVE-2015-3061, CVE-2015-3062, CVE-2015-3063, CVE-2015-3064, CVE-2015-3065, CVE-2015-3066, CVE-2015-3067, CVE-2015-3068, CVE-2015-3069, CVE-2015-3071, CVE-2015-3072, and CVE-2015-3074.

EPSS: Средний
github логотип

GHSA-28f5-j5p5-xmmw

22 дня назад

The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-28f5-cgmh-4pfj

27 дней назад

Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-28f5-7mw6-mfmc

около 4 лет назад

In AccountManager, there is a possible bypass of a permissions check due to a confused deputy. This could lead to local information disclosure, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-123700107

EPSS: Низкий
github логотип

GHSA-28f5-7fwx-xrf3

около 4 лет назад

When SWFTools 0.9.2 processes a crafted file in png2swf, it can lead to a Segmentation Violation in the png_load() function in lib/png.c.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-28f5-3rf2-gpm8

около 4 лет назад

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.

EPSS: Низкий
github логотип

GHSA-28f5-38xr-jh2w

3 дня назад

java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-28f4-mjfq-qrvf

почти 6 лет назад

Malicious Package in buffes-xor

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-28f4-f5wq-36wr

больше 2 лет назад

The WooCommerce POS plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 1.4.11. This is due to the plugin not properly verifying the authentication and authorization of the current user This makes it possible for authenticated attackers, with customer-level access and above, to view potentially sensitive information about other users by leveraging their order id

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-28f4-9qfp-6f7v

около 4 лет назад

An issue was discovered in Xpdf 4.01.01. There is an FPE in the function ImageStream::ImageStream at Stream.cc for nBits.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-28f3-rf96-2vvg

больше 2 лет назад

Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'txtPass' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-28f3-c95g-f4g3

около 4 лет назад

In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the IxVeriWave file parser could crash. This was addressed in wiretap/vwr.c by correcting the signature timestamp bounds checks.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-28ff-x3xj-mx7q

An information disclosure vulnerability in libstagefright in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Android ID: A-31091777.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-28fc-gvjg-5f4h

** UNSUPPORTED WHEN ASSIGNED ** The unofficial vscode-sass-lint (aka Sass Lint) extension through 1.0.7 for Visual Studio Code allows attackers to execute arbitrary binaries if the user opens a crafted workspace. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-28f9-43w8-v45c

Buffer overflow in the ILASM assembler in the Microsoft .NET 1.0 and 1.1 Framework might allow user-assisted attackers to execute arbitrary code via a .il file that calls a function with a long name.

8%
Низкий
около 4 лет назад
github логотип
GHSA-28f8-hqmc-7ph8

Malicious Package in ember-power-timepicker

почти 6 лет назад
github логотип
GHSA-28f7-mc45-4x8m

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gordon Böhme, Antonio Leutsch Structured Content allows Stored XSS.This issue affects Structured Content: from n/a through 1.6.2.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-28f7-g5r5-mpx5

In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-28f6-9xpw-pwcr

Cross-site scripting (XSS) vulnerability in core/summary_api.php in MantisBT before 1.2.3 allows remote attackers to inject arbitrary web script or HTML via the Summary field, a different vector than CVE-2010-3303.

2%
Низкий
около 4 лет назад
github логотип
GHSA-28f6-647f-xq87

Buffer overflow in SonicWall SMA100 allows an authenticated user to execute arbitrary code in DEARegister CGI script. This vulnerability impacted SMA100 version 9.0.0.3 and earlier.

2%
Низкий
около 4 лет назад
github логотип
GHSA-28f5-mg2c-r34c

Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScript API execution via unspecified vectors, a different vulnerability than CVE-2015-3060, CVE-2015-3061, CVE-2015-3062, CVE-2015-3063, CVE-2015-3064, CVE-2015-3065, CVE-2015-3066, CVE-2015-3067, CVE-2015-3068, CVE-2015-3069, CVE-2015-3071, CVE-2015-3072, and CVE-2015-3074.

25%
Средний
около 4 лет назад
github логотип
GHSA-28f5-j5p5-xmmw

The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

CVSS3: 9.8
76%
Высокий
22 дня назад
github логотип
GHSA-28f5-cgmh-4pfj

Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS3: 8.3
0%
Низкий
27 дней назад
github логотип
GHSA-28f5-7mw6-mfmc

In AccountManager, there is a possible bypass of a permissions check due to a confused deputy. This could lead to local information disclosure, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-123700107

0%
Низкий
около 4 лет назад
github логотип
GHSA-28f5-7fwx-xrf3

When SWFTools 0.9.2 processes a crafted file in png2swf, it can lead to a Segmentation Violation in the png_load() function in lib/png.c.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-28f5-3rf2-gpm8

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.

1%
Низкий
около 4 лет назад
github логотип
GHSA-28f5-38xr-jh2w

java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor

CVSS3: 8.2
3 дня назад
github логотип
GHSA-28f4-mjfq-qrvf

Malicious Package in buffes-xor

CVSS3: 9.8
почти 6 лет назад
github логотип
GHSA-28f4-f5wq-36wr

The WooCommerce POS plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 1.4.11. This is due to the plugin not properly verifying the authentication and authorization of the current user This makes it possible for authenticated attackers, with customer-level access and above, to view potentially sensitive information about other users by leveraging their order id

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-28f4-9qfp-6f7v

An issue was discovered in Xpdf 4.01.01. There is an FPE in the function ImageStream::ImageStream at Stream.cc for nBits.

CVSS3: 5.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-28f3-rf96-2vvg

Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'txtPass' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
больше 2 лет назад
github логотип
GHSA-28f3-c95g-f4g3

In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the IxVeriWave file parser could crash. This was addressed in wiretap/vwr.c by correcting the signature timestamp bounds checks.

CVSS3: 6.5
2%
Низкий
около 4 лет назад

Уязвимостей на страницу