Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 269

Количество 353 269

github логотип

GHSA-276f-6jm7-647m

около 2 лет назад

An Improper Validation of Integrity Check Value vulnerability in Zscaler Client Connector on MacOS during the upgrade process may allow a Local Execution of Code.This issue affects Client Connector on MacOS: before 3.4.

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-276c-r54j-3fg6

около 4 лет назад

MRcgi/MRProcessIncomingForms.pl in Numara FootPrints 8.1 on Linux allows remote attackers to execute arbitrary code via shell metacharacters in the PROJECTNUM parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-276c-c7gr-r4j6

почти 2 года назад

A denial of service vulnerability exists in the Web Application functionality of LevelOne WBR-6012 R0.40e6. A specially crafted HTTP request can lead to a reboot. An attacker can send an HTTP request to trigger this vulnerability.

CVSS3: 3.7
EPSS: Средний
github логотип

GHSA-276c-3gx4-x9pr

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix buffer overflow when parsing NFS reparse points ReparseDataLength is sum of the InodeType size and DataBuffer size. So to get DataBuffer size it is needed to subtract InodeType's size from ReparseDataLength. Function cifs_strndup_from_utf16() is currentlly accessing buf->DataBuffer at position after the end of the buffer because it does not subtract InodeType size from the length. Fix this problem and correctly subtract variable len. Member InodeType is present only when reparse buffer is large enough. Check for ReparseDataLength before accessing InodeType to prevent another invalid memory access. Major and minor rdev values are present also only when reparse buffer is large enough. Check for reparse buffer size before calling reparse_mkdev().

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-276c-2376-64gp

около 4 лет назад

An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component. Out of bounds memory access during parsing of ARP packets in eARPProcessPacket can be used for information disclosure.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2769-pfcp-47gw

около 4 лет назад

Cross-site scripting (XSS) vulnerability in proxy.asp in Sambar Server 6.3 BETA 2 and possibly earlier versions allows remote attackers to inject arbitrary web script or HTML via the (1) Remote Proxy Server or (2) Proxy Filter IPs field.

EPSS: Низкий
github логотип

GHSA-2769-9cr9-9w7h

около 2 лет назад

J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the getDeptList() function.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2768-c9pp-fhfg

около 4 лет назад

SQL injection vulnerability in index.php in BloofoxCMS 0.3.5 allows remote attackers to execute arbitrary SQL commands via the gender parameter.

EPSS: Низкий
github логотип

GHSA-2768-785q-97pf

около 2 лет назад

Improper restriction of communication channel to intended endpoints issue exists in Ricoh Streamline NX PC Client ver.3.6.x and earlier. If this vulnerability is exploited, arbitrary code may be executed on the PC where the product is installed.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-2768-5wmv-cfff

10 месяцев назад

Magento vulnerable to stored Cross-Site Scripting (XSS)

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-2768-2mfm-w93v

около 4 лет назад

The IBM BladeCenter with Advanced Management Module (AMM) firmware before bpet50g does not properly perform interrupt sharing for USB and iSCSI, which allows remote attackers to cause a denial of service (management module reboot) via TCP packets with malformed application data.

EPSS: Низкий
github логотип

GHSA-2767-v9j6-723w

около 4 лет назад

Untrusted search path vulnerability in Cisco VPN Client 5.0 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka Bug ID CSCua28747.

EPSS: Низкий
github логотип

GHSA-2767-g28h-69jv

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: fgraph: Add READ_ONCE() when accessing fgraph_array[] In __ftrace_return_to_handler(), a loop iterates over the fgraph_array[] elements, which are fgraph_ops. The loop checks if an element is a fgraph_stub to prevent using a fgraph_stub afterward. However, if the compiler reloads fgraph_array[] after this check, it might race with an update to fgraph_array[] that introduces a fgraph_stub. This could result in the stub being processed, but the stub contains a null "func_hash" field, leading to a NULL pointer dereference. To ensure that the gops compared against the fgraph_stub matches the gops processed later, add a READ_ONCE(). A similar patch appears in commit 63a8dfb ("function_graph: Add READ_ONCE() when accessing fgraph_array[]").

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-2767-2q9v-9326

3 месяца назад

OpenClaw: QQBot reply media URL handling could trigger SSRF and re-upload fetched bytes

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-2766-6fw4-8r99

около 4 лет назад

A potential security vulnerability has been identified with HP Integrated Lights-Out 4 (iLO 4) firmware version 2.11 and later, but prior to version 2.30. The vulnerability could be exploited remotely resulting in Denial of Service (DoS). Note this was originally published in 2015 however the CVE entry was added in 2020.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2765-4mww-988c

около 4 лет назад

The provider-edge MPLS NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (device reload) via a malformed SIP packet to UDP port 5060, aka Bug ID CSCti98219.

EPSS: Низкий
github логотип

GHSA-2764-jq98-83vg

больше 3 лет назад

A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Footer field.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-2764-9vrm-2xfc

больше 3 лет назад

PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the StdioOutPutc function in cstdlib/stdio.c when called from ExpressionParseFunctionCall.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2764-97wf-7645

9 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in favethemes Houzez Theme - Functionality houzez-theme-functionality.This issue affects Houzez Theme - Functionality: from n/a through < 4.2.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2764-7h3r-8xg3

около 4 лет назад

A vulnerability in Brocade SANnav versions before v2.1.0 could allow a remote authenticated attacker to conduct an LDAP injection. The vulnerability could allow a remote attacker to bypass the authentication process.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-276f-6jm7-647m

An Improper Validation of Integrity Check Value vulnerability in Zscaler Client Connector on MacOS during the upgrade process may allow a Local Execution of Code.This issue affects Client Connector on MacOS: before 3.4.

CVSS3: 4.2
0%
Низкий
около 2 лет назад
github логотип
GHSA-276c-r54j-3fg6

MRcgi/MRProcessIncomingForms.pl in Numara FootPrints 8.1 on Linux allows remote attackers to execute arbitrary code via shell metacharacters in the PROJECTNUM parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

3%
Низкий
около 4 лет назад
github логотип
GHSA-276c-c7gr-r4j6

A denial of service vulnerability exists in the Web Application functionality of LevelOne WBR-6012 R0.40e6. A specially crafted HTTP request can lead to a reboot. An attacker can send an HTTP request to trigger this vulnerability.

CVSS3: 3.7
11%
Средний
почти 2 года назад
github логотип
GHSA-276c-3gx4-x9pr

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix buffer overflow when parsing NFS reparse points ReparseDataLength is sum of the InodeType size and DataBuffer size. So to get DataBuffer size it is needed to subtract InodeType's size from ReparseDataLength. Function cifs_strndup_from_utf16() is currentlly accessing buf->DataBuffer at position after the end of the buffer because it does not subtract InodeType size from the length. Fix this problem and correctly subtract variable len. Member InodeType is present only when reparse buffer is large enough. Check for ReparseDataLength before accessing InodeType to prevent another invalid memory access. Major and minor rdev values are present also only when reparse buffer is large enough. Check for reparse buffer size before calling reparse_mkdev().

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-276c-2376-64gp

An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component. Out of bounds memory access during parsing of ARP packets in eARPProcessPacket can be used for information disclosure.

CVSS3: 5.9
2%
Низкий
около 4 лет назад
github логотип
GHSA-2769-pfcp-47gw

Cross-site scripting (XSS) vulnerability in proxy.asp in Sambar Server 6.3 BETA 2 and possibly earlier versions allows remote attackers to inject arbitrary web script or HTML via the (1) Remote Proxy Server or (2) Proxy Filter IPs field.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2769-9cr9-9w7h

J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the getDeptList() function.

CVSS3: 9.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-2768-c9pp-fhfg

SQL injection vulnerability in index.php in BloofoxCMS 0.3.5 allows remote attackers to execute arbitrary SQL commands via the gender parameter.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2768-785q-97pf

Improper restriction of communication channel to intended endpoints issue exists in Ricoh Streamline NX PC Client ver.3.6.x and earlier. If this vulnerability is exploited, arbitrary code may be executed on the PC where the product is installed.

CVSS3: 6.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-2768-5wmv-cfff

Magento vulnerable to stored Cross-Site Scripting (XSS)

CVSS3: 8.1
1%
Низкий
10 месяцев назад
github логотип
GHSA-2768-2mfm-w93v

The IBM BladeCenter with Advanced Management Module (AMM) firmware before bpet50g does not properly perform interrupt sharing for USB and iSCSI, which allows remote attackers to cause a denial of service (management module reboot) via TCP packets with malformed application data.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2767-v9j6-723w

Untrusted search path vulnerability in Cisco VPN Client 5.0 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka Bug ID CSCua28747.

0%
Низкий
около 4 лет назад
github логотип
GHSA-2767-g28h-69jv

In the Linux kernel, the following vulnerability has been resolved: fgraph: Add READ_ONCE() when accessing fgraph_array[] In __ftrace_return_to_handler(), a loop iterates over the fgraph_array[] elements, which are fgraph_ops. The loop checks if an element is a fgraph_stub to prevent using a fgraph_stub afterward. However, if the compiler reloads fgraph_array[] after this check, it might race with an update to fgraph_array[] that introduces a fgraph_stub. This could result in the stub being processed, but the stub contains a null "func_hash" field, leading to a NULL pointer dereference. To ensure that the gops compared against the fgraph_stub matches the gops processed later, add a READ_ONCE(). A similar patch appears in commit 63a8dfb ("function_graph: Add READ_ONCE() when accessing fgraph_array[]").

CVSS3: 4.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-2767-2q9v-9326

OpenClaw: QQBot reply media URL handling could trigger SSRF and re-upload fetched bytes

CVSS3: 8.2
0%
Низкий
3 месяца назад
github логотип
GHSA-2766-6fw4-8r99

A potential security vulnerability has been identified with HP Integrated Lights-Out 4 (iLO 4) firmware version 2.11 and later, but prior to version 2.30. The vulnerability could be exploited remotely resulting in Denial of Service (DoS). Note this was originally published in 2015 however the CVE entry was added in 2020.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-2765-4mww-988c

The provider-edge MPLS NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (device reload) via a malformed SIP packet to UDP port 5060, aka Bug ID CSCti98219.

3%
Низкий
около 4 лет назад
github логотип
GHSA-2764-jq98-83vg

A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Footer field.

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2764-9vrm-2xfc

PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the StdioOutPutc function in cstdlib/stdio.c when called from ExpressionParseFunctionCall.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2764-97wf-7645

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in favethemes Houzez Theme - Functionality houzez-theme-functionality.This issue affects Houzez Theme - Functionality: from n/a through < 4.2.0.

CVSS3: 6.5
0%
Низкий
9 месяцев назад
github логотип
GHSA-2764-7h3r-8xg3

A vulnerability in Brocade SANnav versions before v2.1.0 could allow a remote authenticated attacker to conduct an LDAP injection. The vulnerability could allow a remote attacker to bypass the authentication process.

2%
Низкий
около 4 лет назад

Уязвимостей на страницу