Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 290

Количество 353 290

github логотип

GHSA-2797-x8w7-6c4p

около 3 лет назад

Active Directory Federation Service Security Feature Bypass Vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2797-h4gc-wv56

больше 3 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.034. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DXF files. Crafted data in a DXF file can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16341.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2797-9p2f-vf5j

16 дней назад

CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-2797-489c-67fq

около 4 лет назад

Imgix through 2019-06-19 allows remote attackers to cause a denial of service (resource consumption) by manipulating a small JPEG file to specify dimensions of 64250x64250 pixels, which is mishandled during an attempt to load the 'whole image' into memory.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2796-xm8f-wrr7

больше 4 лет назад

An issue (5 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications. These TCP services can be exploited due to deserialization behavior that is inherent to the .NET Remoting service. A malicious attacker can exploit both TCP remoting services and local IPC services on the Enterprise Vault Server. This vulnerability is mitigated by properly configuring the servers and firewall as described in the vendor's security alert for this vulnerability (VTS21-003, ZDI-CAN-14080).

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2795-x35v-6hgh

около 4 лет назад

A cross-site scripting (XSS) vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to tamper with the web interface of the product.

EPSS: Низкий
github логотип

GHSA-2795-wfr2-m5v3

10 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Avoid fcport pointer dereference Klocwork reported warning of NULL pointer may be dereferenced. The routine exits when sa_ctl is NULL and fcport is allocated after the exit call thus causing NULL fcport pointer to dereference at the time of exit. To avoid fcport pointer dereference, exit the routine when sa_ctl is NULL.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2795-vvmf-mqf8

9 дней назад

Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Quality. While the vulnerability is in Oracle Quality, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Quality accessible data as well as unauthorized update, insert or delete access to some of Oracle Quality accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Quality. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:L).

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-2795-pjw4-5495

больше 1 года назад

A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0) allows the OpenSSL configuration file to load from a non-existent directory. An unauthorized, locally authenticated user with low privileges can potentially create the directory and load a specially crafted openssl.conf file leading to the execution of a malicious DLL (Dynamic-Link Library) with elevated privileges.

EPSS: Низкий
github логотип

GHSA-2795-hprj-q9m8

около 4 лет назад

Multiple vulnerabilities in the web UI of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against users on an affected system. The vulnerabilities are due to insufficient validation of user-supplied input that is processed by the web UI. An attacker could exploit these vulnerabilities by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information on an affected system.

EPSS: Низкий
github логотип

GHSA-2795-85x7-cp8v

около 4 лет назад

QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the server via command injection in the servicestart parameter.

EPSS: Средний
github логотип

GHSA-2794-c693-53gf

больше 1 года назад

A vulnerability classified as problematic has been found in FabulaTech USB over Network 6.0.6.1. Affected is the function 0x22040C in the library ftusbbus2.sys of the component IOCT Handler. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2794-6m94-77f7

больше 1 года назад

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-2793-r34m-9rvh

около 4 лет назад

libxml2 in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2016-4614, CVE-2016-4616, and CVE-2016-4619.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2793-qrcg-qwq3

почти 3 года назад

Windows Error Reporting Service Elevation of Privilege Vulnerability

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-2793-7v75-7pw5

около 4 лет назад

A remote sql injection authentication bypass in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2793-3243-f8xx

почти 4 года назад

Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain a cross-site scripting (XSS) vulnerability.

CVSS3: 5.4
EPSS: Средний
github логотип

GHSA-2792-x8v5-77wp

почти 3 года назад

Integer overflow vulnerability in tool_operate.c in curl 7.65.2 via crafted value as the retry delay.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-278x-ph66-x5gw

больше 3 лет назад

Memory corruption due to access of uninitialized pointer in Bluetooth HOST while processing the AVRCP packet.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-278x-ggmc-78v9

около 4 лет назад

IBM QRadar Network Security 5.4.0 and 5.5.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 174340.

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2797-x8w7-6c4p

Active Directory Federation Service Security Feature Bypass Vulnerability

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-2797-h4gc-wv56

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.034. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DXF files. Crafted data in a DXF file can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16341.

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2797-9p2f-vf5j

CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.

CVSS3: 6.2
0%
Низкий
16 дней назад
github логотип
GHSA-2797-489c-67fq

Imgix through 2019-06-19 allows remote attackers to cause a denial of service (resource consumption) by manipulating a small JPEG file to specify dimensions of 64250x64250 pixels, which is mishandled during an attempt to load the 'whole image' into memory.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-2796-xm8f-wrr7

An issue (5 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault application starts several services that listen on random .NET Remoting TCP ports for possible commands from client applications. These TCP services can be exploited due to deserialization behavior that is inherent to the .NET Remoting service. A malicious attacker can exploit both TCP remoting services and local IPC services on the Enterprise Vault Server. This vulnerability is mitigated by properly configuring the servers and firewall as described in the vendor's security alert for this vulnerability (VTS21-003, ZDI-CAN-14080).

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-2795-x35v-6hgh

A cross-site scripting (XSS) vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to tamper with the web interface of the product.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2795-wfr2-m5v3

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Avoid fcport pointer dereference Klocwork reported warning of NULL pointer may be dereferenced. The routine exits when sa_ctl is NULL and fcport is allocated after the exit call thus causing NULL fcport pointer to dereference at the time of exit. To avoid fcport pointer dereference, exit the routine when sa_ctl is NULL.

CVSS3: 5.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-2795-vvmf-mqf8

Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Quality. While the vulnerability is in Oracle Quality, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Quality accessible data as well as unauthorized update, insert or delete access to some of Oracle Quality accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Quality. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:L).

CVSS3: 8.2
0%
Низкий
9 дней назад
github логотип
GHSA-2795-pjw4-5495

A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0) allows the OpenSSL configuration file to load from a non-existent directory. An unauthorized, locally authenticated user with low privileges can potentially create the directory and load a specially crafted openssl.conf file leading to the execution of a malicious DLL (Dynamic-Link Library) with elevated privileges.

0%
Низкий
больше 1 года назад
github логотип
GHSA-2795-hprj-q9m8

Multiple vulnerabilities in the web UI of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against users on an affected system. The vulnerabilities are due to insufficient validation of user-supplied input that is processed by the web UI. An attacker could exploit these vulnerabilities by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information on an affected system.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2795-85x7-cp8v

QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the server via command injection in the servicestart parameter.

18%
Средний
около 4 лет назад
github логотип
GHSA-2794-c693-53gf

A vulnerability classified as problematic has been found in FabulaTech USB over Network 6.0.6.1. Affected is the function 0x22040C in the library ftusbbus2.sys of the component IOCT Handler. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-2794-6m94-77f7

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service.

CVSS3: 4.9
1%
Низкий
больше 1 года назад
github логотип
GHSA-2793-r34m-9rvh

libxml2 in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2016-4614, CVE-2016-4616, and CVE-2016-4619.

CVSS3: 9.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-2793-qrcg-qwq3

Windows Error Reporting Service Elevation of Privilege Vulnerability

CVSS3: 7
0%
Низкий
почти 3 года назад
github логотип
GHSA-2793-7v75-7pw5

A remote sql injection authentication bypass in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found.

CVSS3: 9.8
9%
Низкий
около 4 лет назад
github логотип
GHSA-2793-3243-f8xx

Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain a cross-site scripting (XSS) vulnerability.

CVSS3: 5.4
42%
Средний
почти 4 года назад
github логотип
GHSA-2792-x8v5-77wp

Integer overflow vulnerability in tool_operate.c in curl 7.65.2 via crafted value as the retry delay.

CVSS3: 9.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-278x-ph66-x5gw

Memory corruption due to access of uninitialized pointer in Bluetooth HOST while processing the AVRCP packet.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-278x-ggmc-78v9

IBM QRadar Network Security 5.4.0 and 5.5.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 174340.

CVSS3: 5.9
1%
Низкий
около 4 лет назад

Уязвимостей на страницу