Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 269

Количество 353 269

github логотип

GHSA-27r7-3m9x-r533

11 месяцев назад

traQ Allows Insertion of Sensitive Information into Log File

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-27r6-xq24-p9x8

больше 1 года назад

Insufficiently protected credentials in AD/LDAP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send AD/LDAP administrators account passwords to an arbitrary server via HTTP POST request.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-27r6-qw3g-4x74

около 4 лет назад

Use-after-free vulnerability in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving element attributes.

EPSS: Низкий
github логотип

GHSA-27r6-6m95-4c69

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the management interface in Alcatel-Lucent 1830 Photonic Service Switch (PSS) 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the myurl parameter to menu/pop.html.

EPSS: Низкий
github логотип

GHSA-27r5-q87w-8cff

больше 3 лет назад

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-27r4-rp49-685c

около 4 лет назад

The Autoptimize WordPress plugin before 2.7.8 does not check for malicious files such as .html in the archive uploaded via the 'Import Settings' feature. As a result, it is possible for a high privilege user to upload a malicious file containing JavaScript code inside an archive which will execute when a victim visits index.html inside the plugin directory.

EPSS: Низкий
github логотип

GHSA-27r4-945x-jq67

больше 1 года назад

In removeUnsynchronization of ID3.cpp there is a possible resource exhaustion due to improper input validation. This could lead to denial of service with no additional execution privileges needed. User interaction is needed for exploitation.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-27r4-3wxx-xxj6

больше 2 лет назад

A CWE-601:URL Redirection to Untrusted Site (‘Open Redirect’) vulnerability exists that could cause disclosure of information through phishing attempts over HTTP.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-27r3-f3mg-fxp8

около 4 лет назад

Cross-site scripting (XSS) vulnerability in Properties.do in ZOHO ManageEngine OpStor before build 8500 allows remote authenticated users to inject arbitrary web script or HTML via the name parameter, a different vulnerability than CVE-2014-0344.

EPSS: Низкий
github логотип

GHSA-27r3-85x4-pfqv

около 2 лет назад

The contains an IDOR vulnerability that allows a user to comment on a private post by manipulating the ID included in the request

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-27r2-x487-q675

больше 2 лет назад

The system application (com.transsion.kolun.aiservice) component does not perform an authentication check, which allows attackers to perform malicious exploitations and affect system services.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-27r2-6rqh-xrg8

больше 2 лет назад

An authorization bypass vulnerability was discovered in GitLab affecting versions 15.1 prior to 16.7.6, 16.8 prior to 16.8.3, and 16.9 prior to 16.9.1. A developer could bypass CODEOWNERS approvals by creating a merge conflict.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-27qx-rrr4-rx3x

около 4 лет назад

drivers/char/diag/diag_dci.c in the Qualcomm components in Android before 2016-08-05 on Nexus 7 (2013) devices allows attackers to gain privileges via a crafted application that sends short DCI request packets, aka Android internal bug 28767589 and Qualcomm internal bug CR483310.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-27qx-pwhc-4j5g

около 2 лет назад

A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Enterprise Security Manager and ArcSight Platform. The vulnerability could be remotely exploited.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-27qw-rmpj-379q

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: jfs: fix null ptr deref in dtInsertEntry [syzbot reported] general protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] PREEMPT SMP KASAN PTI KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f] CPU: 0 PID: 5061 Comm: syz-executor404 Not tainted 6.8.0-syzkaller-08951-gfe46a7dd189e #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/27/2024 RIP: 0010:dtInsertEntry+0xd0c/0x1780 fs/jfs/jfs_dtree.c:3713 ... [Analyze] In dtInsertEntry(), when the pointer h has the same value as p, after writing name in UniStrncpy_to_le(), p->header.flag will be cleared. This will cause the previously true judgment "p->header.flag & BT-LEAF" to change to no after writing the name operation, this leads to entering an incorrect branch and accessing the uninitialized object ih when judging this condition for the second time. [Fix] After got the page, check fr...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-27qw-pwxv-qq8r

почти 4 года назад

Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function formSetVirtualSer.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-27qw-fff9-qjq8

около 1 года назад

Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-27qw-cxvq-fp97

около 4 лет назад

HPE IPFilter A.11.31.18.21 on HP-UX, when a certain keep-state configuration is enabled, allows remote attackers to cause a denial of service via unspecified UDP packets.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-27qv-mw67-9whg

около 4 лет назад

An issue was discovered in ezXML 0.8.2 through 0.8.6. The function ezxml_str2utf8, while parsing a crafted XML file, performs zero-length reallocation in ezxml.c, leading to returning a NULL pointer (in some compilers). After this, the function ezxml_parse_str does not check whether the s variable is not NULL in ezxml.c, leading to a NULL pointer dereference and crash (segmentation fault).

EPSS: Низкий
github логотип

GHSA-27qv-6m8p-ww7g

3 месяца назад

Illustrator versions 29.8.6, 30.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-27r7-3m9x-r533

traQ Allows Insertion of Sensitive Information into Log File

CVSS3: 5.9
0%
Низкий
11 месяцев назад
github логотип
GHSA-27r6-xq24-p9x8

Insufficiently protected credentials in AD/LDAP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send AD/LDAP administrators account passwords to an arbitrary server via HTTP POST request.

CVSS3: 6.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-27r6-qw3g-4x74

Use-after-free vulnerability in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving element attributes.

6%
Низкий
около 4 лет назад
github логотип
GHSA-27r6-6m95-4c69

Cross-site scripting (XSS) vulnerability in the management interface in Alcatel-Lucent 1830 Photonic Service Switch (PSS) 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the myurl parameter to menu/pop.html.

1%
Низкий
около 4 лет назад
github логотип
GHSA-27r5-q87w-8cff

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

CVSS3: 5.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-27r4-rp49-685c

The Autoptimize WordPress plugin before 2.7.8 does not check for malicious files such as .html in the archive uploaded via the 'Import Settings' feature. As a result, it is possible for a high privilege user to upload a malicious file containing JavaScript code inside an archive which will execute when a victim visits index.html inside the plugin directory.

1%
Низкий
около 4 лет назад
github логотип
GHSA-27r4-945x-jq67

In removeUnsynchronization of ID3.cpp there is a possible resource exhaustion due to improper input validation. This could lead to denial of service with no additional execution privileges needed. User interaction is needed for exploitation.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-27r4-3wxx-xxj6

A CWE-601:URL Redirection to Untrusted Site (‘Open Redirect’) vulnerability exists that could cause disclosure of information through phishing attempts over HTTP.

CVSS3: 8.2
0%
Низкий
больше 2 лет назад
github логотип
GHSA-27r3-f3mg-fxp8

Cross-site scripting (XSS) vulnerability in Properties.do in ZOHO ManageEngine OpStor before build 8500 allows remote authenticated users to inject arbitrary web script or HTML via the name parameter, a different vulnerability than CVE-2014-0344.

2%
Низкий
около 4 лет назад
github логотип
GHSA-27r3-85x4-pfqv

The contains an IDOR vulnerability that allows a user to comment on a private post by manipulating the ID included in the request

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-27r2-x487-q675

The system application (com.transsion.kolun.aiservice) component does not perform an authentication check, which allows attackers to perform malicious exploitations and affect system services.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-27r2-6rqh-xrg8

An authorization bypass vulnerability was discovered in GitLab affecting versions 15.1 prior to 16.7.6, 16.8 prior to 16.8.3, and 16.9 prior to 16.9.1. A developer could bypass CODEOWNERS approvals by creating a merge conflict.

CVSS3: 7.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-27qx-rrr4-rx3x

drivers/char/diag/diag_dci.c in the Qualcomm components in Android before 2016-08-05 on Nexus 7 (2013) devices allows attackers to gain privileges via a crafted application that sends short DCI request packets, aka Android internal bug 28767589 and Qualcomm internal bug CR483310.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-27qx-pwhc-4j5g

A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Enterprise Security Manager and ArcSight Platform. The vulnerability could be remotely exploited.

CVSS3: 8.7
0%
Низкий
около 2 лет назад
github логотип
GHSA-27qw-rmpj-379q

In the Linux kernel, the following vulnerability has been resolved: jfs: fix null ptr deref in dtInsertEntry [syzbot reported] general protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] PREEMPT SMP KASAN PTI KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f] CPU: 0 PID: 5061 Comm: syz-executor404 Not tainted 6.8.0-syzkaller-08951-gfe46a7dd189e #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/27/2024 RIP: 0010:dtInsertEntry+0xd0c/0x1780 fs/jfs/jfs_dtree.c:3713 ... [Analyze] In dtInsertEntry(), when the pointer h has the same value as p, after writing name in UniStrncpy_to_le(), p->header.flag will be cleared. This will cause the previously true judgment "p->header.flag & BT-LEAF" to change to no after writing the name operation, this leads to entering an incorrect branch and accessing the uninitialized object ih when judging this condition for the second time. [Fix] After got the page, check fr...

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-27qw-pwxv-qq8r

Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function formSetVirtualSer.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-27qw-fff9-qjq8

Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-27qw-cxvq-fp97

HPE IPFilter A.11.31.18.21 on HP-UX, when a certain keep-state configuration is enabled, allows remote attackers to cause a denial of service via unspecified UDP packets.

CVSS3: 5.9
2%
Низкий
около 4 лет назад
github логотип
GHSA-27qv-mw67-9whg

An issue was discovered in ezXML 0.8.2 through 0.8.6. The function ezxml_str2utf8, while parsing a crafted XML file, performs zero-length reallocation in ezxml.c, leading to returning a NULL pointer (in some compilers). After this, the function ezxml_parse_str does not check whether the s variable is not NULL in ezxml.c, leading to a NULL pointer dereference and crash (segmentation fault).

1%
Низкий
около 4 лет назад
github логотип
GHSA-27qv-6m8p-ww7g

Illustrator versions 29.8.6, 30.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
3 месяца назад

Уязвимостей на страницу