Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 269

Количество 353 269

github логотип

GHSA-28f3-55mq-pp68

около 1 месяца назад

A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS).

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-28f2-gw74-5cpj

около 4 лет назад

The setpermissions function in the auto-updater in Arq before 5.9.7 for Mac allows local users to gain root privileges via a symlink attack on the updater binary itself.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-28cx-j4v5-m5fv

почти 2 года назад

Pluck CMS 4.7.18 does not restrict failed login attempts, allowing attackers to execute a brute force attack.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-28cx-hxv4-g5q7

около 4 лет назад

Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/vehicles/manage_vehicle.php?id=.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-28cx-5f85-hrh4

почти 2 года назад

FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/edit/10.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-28cw-rx3r-6f3c

около 4 лет назад

Palo Alto Networks Traps ESM Console before 3.4.4 allows attackers to cause a denial of service by leveraging improper validation of requests to revoke a Traps agent license.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-28cw-rpqc-wqqj

около 2 месяцев назад

LiamBindle MQTT-C through version 1.1.6 contains a heap-based out-of-bounds read and integer underflow in the mqtt_unpack_publish_response() function in src/mqtt.c that allows a remote unauthenticated attacker controlling an MQTT broker - or able to inject MQTT traffic into an unencrypted session - to crash a subscribed MQTT-C client and potentially disclose adjacent heap memory by sending a single crafted PUBLISH packet. The function validates only that the fixed-header remaining_length is at least 4, then reads the 16-bit topic_name_size field from the broker-controlled packet and advances the parse pointer by that value without verifying that topic_name_size plus the surrounding overhead fits within remaining_length; it subsequently computes application_message_size as remaining_length - topic_name_size - 2 (QoS 0) or - 4 (QoS greater than 0) in unsigned arithmetic, producing an integer underflow that is then passed to memmove(). A PUBLISH packet with topic_name_size = 0xFFFF and...

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-28cw-qr46-rx46

около 4 лет назад

The php_zip_make_relative_path function in php_zip.c in PHP 5.2.x before 5.2.9 allows context-dependent attackers to cause a denial of service (crash) via a ZIP file that contains filenames with relative paths, which is not properly handled during extraction.

EPSS: Низкий
github логотип

GHSA-28cw-qjjv-g5g8

больше 3 лет назад

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to a Log Injection attack by constructing URLs from user-controlled data. This could enable attackers to make arbitrary requests to the internal network or to the local file system. IBM X-Force ID: 240266.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-28cw-3j6f-3fv3

около 4 лет назад

A vulnerability exists that could allow the execution of operating system commands on systems running MiPlatform 2019.05.16 and earlier. An attacker could execute arbitrary remote command by sending parameters to WinExec function in ExtCommandApi.dll module of MiPlatform.

EPSS: Низкий
github логотип

GHSA-28cv-g234-w9cx

больше 3 лет назад

A vulnerability has been identified in Polarion ALM (All versions < V2304.0). The application contains a XML External Entity Injection (XXE) vulnerability. This could allow an attacker to view files on the application server filesystem.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-28cv-7xwr-65c6

10 месяцев назад

VitaraCharts 5.3.5 is vulnerable to Server-Side Request Forgery in fileLoader.jsp.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-28cv-45w7-c3g7

больше 2 лет назад

Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-28cr-jmcx-rqcp

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: arm64: dts: qcom: msm8998: Fix CPU/L2 idle state latency and residency The entry/exit latency and minimum residency in state for the idle states of MSM8998 were ..bad: first of all, for all of them the timings were written for CPU sleep but the min-residency-us param was miscalculated (supposedly, while porting this from downstream); Then, the power collapse states are setting PC on both the CPU cluster *and* the L2 cache, which have different timings: in the specific case of L2 the times are higher so these ones should be taken into account instead of the CPU ones. This parameter misconfiguration was not giving particular issues because on MSM8998 there was no CPU scaling at all, so cluster/L2 power collapse was rarely (if ever) hit. When CPU scaling is enabled, though, the wrong timings will produce SoC unstability shown to the user as random, apparently error-less, sudden reboots and/or lockups. This set of p...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-28cr-g9xf-2wgh

2 месяца назад

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. A malicious app may be able to gain root privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-28cr-3625-x6c5

около 4 лет назад

Exponent CMS before 2.6.0 has improper input validation in fileController.php.

EPSS: Низкий
github логотип

GHSA-28cq-wr2x-53v2

около 4 лет назад

Cross-site scripting (XSS) vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-28cq-rjgp-gc9m

около 4 лет назад

GleamTech FileVista before 6.1 allows remote authenticated users to create arbitrary files and possibly execute arbitrary code via a crafted path in a zip archive, which is not properly handled during extraction.

EPSS: Низкий
github логотип

GHSA-28cq-6rmx-pjq4

около 4 лет назад

Improper Authentication in Apache Tomcat

EPSS: Средний
github логотип

GHSA-28cp-rjg9-r8c3

8 месяцев назад

The AI Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'aife_post_meta' shortcode in all versions up to, and including, 1.0.22 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-28f3-55mq-pp68

A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS).

CVSS3: 4.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-28f2-gw74-5cpj

The setpermissions function in the auto-updater in Arq before 5.9.7 for Mac allows local users to gain root privileges via a symlink attack on the updater binary itself.

CVSS3: 7.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-28cx-j4v5-m5fv

Pluck CMS 4.7.18 does not restrict failed login attempts, allowing attackers to execute a brute force attack.

CVSS3: 9.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-28cx-hxv4-g5q7

Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/vehicles/manage_vehicle.php?id=.

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-28cx-5f85-hrh4

FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/edit/10.

CVSS3: 5.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-28cw-rx3r-6f3c

Palo Alto Networks Traps ESM Console before 3.4.4 allows attackers to cause a denial of service by leveraging improper validation of requests to revoke a Traps agent license.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-28cw-rpqc-wqqj

LiamBindle MQTT-C through version 1.1.6 contains a heap-based out-of-bounds read and integer underflow in the mqtt_unpack_publish_response() function in src/mqtt.c that allows a remote unauthenticated attacker controlling an MQTT broker - or able to inject MQTT traffic into an unencrypted session - to crash a subscribed MQTT-C client and potentially disclose adjacent heap memory by sending a single crafted PUBLISH packet. The function validates only that the fixed-header remaining_length is at least 4, then reads the 16-bit topic_name_size field from the broker-controlled packet and advances the parse pointer by that value without verifying that topic_name_size plus the surrounding overhead fits within remaining_length; it subsequently computes application_message_size as remaining_length - topic_name_size - 2 (QoS 0) or - 4 (QoS greater than 0) in unsigned arithmetic, producing an integer underflow that is then passed to memmove(). A PUBLISH packet with topic_name_size = 0xFFFF and...

CVSS3: 8.2
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-28cw-qr46-rx46

The php_zip_make_relative_path function in php_zip.c in PHP 5.2.x before 5.2.9 allows context-dependent attackers to cause a denial of service (crash) via a ZIP file that contains filenames with relative paths, which is not properly handled during extraction.

2%
Низкий
около 4 лет назад
github логотип
GHSA-28cw-qjjv-g5g8

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to a Log Injection attack by constructing URLs from user-controlled data. This could enable attackers to make arbitrary requests to the internal network or to the local file system. IBM X-Force ID: 240266.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-28cw-3j6f-3fv3

A vulnerability exists that could allow the execution of operating system commands on systems running MiPlatform 2019.05.16 and earlier. An attacker could execute arbitrary remote command by sending parameters to WinExec function in ExtCommandApi.dll module of MiPlatform.

2%
Низкий
около 4 лет назад
github логотип
GHSA-28cv-g234-w9cx

A vulnerability has been identified in Polarion ALM (All versions < V2304.0). The application contains a XML External Entity Injection (XXE) vulnerability. This could allow an attacker to view files on the application server filesystem.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-28cv-7xwr-65c6

VitaraCharts 5.3.5 is vulnerable to Server-Side Request Forgery in fileLoader.jsp.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-28cv-45w7-c3g7

Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-28cr-jmcx-rqcp

In the Linux kernel, the following vulnerability has been resolved: arm64: dts: qcom: msm8998: Fix CPU/L2 idle state latency and residency The entry/exit latency and minimum residency in state for the idle states of MSM8998 were ..bad: first of all, for all of them the timings were written for CPU sleep but the min-residency-us param was miscalculated (supposedly, while porting this from downstream); Then, the power collapse states are setting PC on both the CPU cluster *and* the L2 cache, which have different timings: in the specific case of L2 the times are higher so these ones should be taken into account instead of the CPU ones. This parameter misconfiguration was not giving particular issues because on MSM8998 there was no CPU scaling at all, so cluster/L2 power collapse was rarely (if ever) hit. When CPU scaling is enabled, though, the wrong timings will produce SoC unstability shown to the user as random, apparently error-less, sudden reboots and/or lockups. This set of p...

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-28cr-g9xf-2wgh

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. A malicious app may be able to gain root privileges.

CVSS3: 7.8
0%
Низкий
2 месяца назад
github логотип
GHSA-28cr-3625-x6c5

Exponent CMS before 2.6.0 has improper input validation in fileController.php.

1%
Низкий
около 4 лет назад
github логотип
GHSA-28cq-wr2x-53v2

Cross-site scripting (XSS) vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

3%
Низкий
около 4 лет назад
github логотип
GHSA-28cq-rjgp-gc9m

GleamTech FileVista before 6.1 allows remote authenticated users to create arbitrary files and possibly execute arbitrary code via a crafted path in a zip archive, which is not properly handled during extraction.

3%
Низкий
около 4 лет назад
github логотип
GHSA-28cq-6rmx-pjq4

Improper Authentication in Apache Tomcat

12%
Средний
около 4 лет назад
github логотип
GHSA-28cp-rjg9-r8c3

The AI Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'aife_post_meta' shortcode in all versions up to, and including, 1.0.22 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
8 месяцев назад

Уязвимостей на страницу