Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 714

Количество 353 714

github логотип

GHSA-269w-3qmc-h38f

около 3 лет назад

In Image filter, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-269v-rmv9-mwh8

почти 2 года назад

A security vulnerability in HPE IceWall Agent products could be exploited remotely to cause a Cross-Site Request Forgery (CSRF) in the login flow.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-269v-f6q7-wg8w

больше 4 лет назад

Buffer overflow in (1) wrapping and (2) unwrapping functions of slrn news reader before 0.9.7.0 allows remote attackers to execute arbitrary commands via a long message header.

EPSS: Низкий
github логотип

GHSA-269r-ppxf-6rgm

около 4 лет назад

Buffer overflow in the Player in Remote-Anything 5.60.15 allows remote attackers to execute arbitrary code via a crafted flm file.

EPSS: Низкий
github логотип

GHSA-269r-2rrv-62mq

больше 4 лет назад

Kerio MailServer 5.0 allows remote attackers to cause a denial of service (hang) via SYN packets to the supported network services.

EPSS: Низкий
github логотип

GHSA-269q-phhx-gq68

около 4 лет назад

Unrestricted file upload vulnerability in lazyseo.php in the Lazy SEO plugin 1.1.9 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a PHP file, then accessing it via a direct request to the file in lazy-seo/.

EPSS: Низкий
github логотип

GHSA-269q-hmxg-m83q

около 4 лет назад

Local Information Disclosure Vulnerability in io.netty:netty-codec-http

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-269q-2cg6-vx42

5 месяцев назад

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the webPage parameter to goform/formSetWanPPTP.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-269p-6jw2-x3jp

около 4 лет назад

Stack-based buffer overflow in the suhosin_encrypt_single_cookie function in the transparent cookie-encryption feature in the Suhosin extension before 0.9.33 for PHP, when suhosin.cookie.encrypt and suhosin.multiheader are enabled, might allow remote attackers to execute arbitrary code via a long string that is used in a Set-Cookie HTTP header.

EPSS: Низкий
github логотип

GHSA-269m-c36j-r834

больше 1 года назад

Infinispan vulnerable to Insertion of Sensitive Information into Log File

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-269m-695x-j34p

почти 8 лет назад

Apache Qpid Broker vulnerable to authentication port spoofing

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-269j-rg7r-j5rj

около 4 лет назад

Multiple SQL injection vulnerabilities in Pligg before 1.1.1 allow remote attackers to execute arbitrary SQL commands via the title parameter to (1) storyrss.php or (2) story.php.

EPSS: Низкий
github логотип

GHSA-269j-r79f-hqvp

больше 4 лет назад

Active PHP Bookmarks (APB) 1.1.01 allows remote attackers to execute arbitrary PHP code via (1) head.php, (2) apb_common.php, or (3) apb_view_class.php by modifying the APB_SETTINGS parameter to reference a URL on a remote web server that contains the code.

EPSS: Низкий
github логотип

GHSA-269j-j44g-6c79

больше 4 лет назад

SQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensitive information and gain access via the calendar parameter.

EPSS: Низкий
github логотип

GHSA-269j-j2cg-h6qp

около 4 лет назад

Aruba ClearPass, all versions of 6.6.x prior to 6.6.9 are affected by an authentication bypass vulnerability, an attacker can leverage this vulnerability to gain administrator privileges on the system. The vulnerability is exposed only on ClearPass web interfaces, including administrative, guest captive portal, and API. Customers who do not expose ClearPass web interfaces to untrusted users are impacted to a lesser extent.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-269j-37ww-cmh3

около 1 года назад

Mezzanine CMS vulnerable to Cross-site Scripting

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-269h-v9xg-7fq6

10 месяцев назад

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-269h-pcpx-q5mj

около 4 лет назад

Use after free in Browser UI in Google Chrome on Chrome OS prior to 99.0.4844.74 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-269h-hc79-qjpf

больше 2 лет назад

LOYTEC electronics GmbH LINX-212 firmware 6.2.4 and LINX-151 Firmware 7.2.4 are vulnerable to Incorrect Access Control via registry.xml file. This vulnerability allows remote attackers to disclose sensitive information on LINX configuration.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-269h-2wf7-8247

около 4 лет назад

The license-installation module on the Cisco Nexus 1000V switch 4.2(1)SV1(5.2b) and earlier for VMware vSphere, Cisco Nexus 1000V switch 5.2(1)SM1(5.1) for Microsoft Hyper-V, and Cisco Virtual Security Gateway 4.2(1)VSG1(1) for Nexus 1000V switches allows local users to gain privileges and execute arbitrary commands via crafted "install all iso" arguments, aka Bug ID CSCui21340.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-269w-3qmc-h38f

In Image filter, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.

CVSS3: 4.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-269v-rmv9-mwh8

A security vulnerability in HPE IceWall Agent products could be exploited remotely to cause a Cross-Site Request Forgery (CSRF) in the login flow.

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-269v-f6q7-wg8w

Buffer overflow in (1) wrapping and (2) unwrapping functions of slrn news reader before 0.9.7.0 allows remote attackers to execute arbitrary commands via a long message header.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-269r-ppxf-6rgm

Buffer overflow in the Player in Remote-Anything 5.60.15 allows remote attackers to execute arbitrary code via a crafted flm file.

6%
Низкий
около 4 лет назад
github логотип
GHSA-269r-2rrv-62mq

Kerio MailServer 5.0 allows remote attackers to cause a denial of service (hang) via SYN packets to the supported network services.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-269q-phhx-gq68

Unrestricted file upload vulnerability in lazyseo.php in the Lazy SEO plugin 1.1.9 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a PHP file, then accessing it via a direct request to the file in lazy-seo/.

5%
Низкий
около 4 лет назад
github логотип
GHSA-269q-hmxg-m83q

Local Information Disclosure Vulnerability in io.netty:netty-codec-http

CVSS3: 5.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-269q-2cg6-vx42

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the webPage parameter to goform/formSetWanPPTP.

CVSS3: 7.5
1%
Низкий
5 месяцев назад
github логотип
GHSA-269p-6jw2-x3jp

Stack-based buffer overflow in the suhosin_encrypt_single_cookie function in the transparent cookie-encryption feature in the Suhosin extension before 0.9.33 for PHP, when suhosin.cookie.encrypt and suhosin.multiheader are enabled, might allow remote attackers to execute arbitrary code via a long string that is used in a Set-Cookie HTTP header.

4%
Низкий
около 4 лет назад
github логотип
GHSA-269m-c36j-r834

Infinispan vulnerable to Insertion of Sensitive Information into Log File

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-269m-695x-j34p

Apache Qpid Broker vulnerable to authentication port spoofing

CVSS3: 9.8
6%
Низкий
почти 8 лет назад
github логотип
GHSA-269j-rg7r-j5rj

Multiple SQL injection vulnerabilities in Pligg before 1.1.1 allow remote attackers to execute arbitrary SQL commands via the title parameter to (1) storyrss.php or (2) story.php.

1%
Низкий
около 4 лет назад
github логотип
GHSA-269j-r79f-hqvp

Active PHP Bookmarks (APB) 1.1.01 allows remote attackers to execute arbitrary PHP code via (1) head.php, (2) apb_common.php, or (3) apb_view_class.php by modifying the APB_SETTINGS parameter to reference a URL on a remote web server that contains the code.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-269j-j44g-6c79

SQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensitive information and gain access via the calendar parameter.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-269j-j2cg-h6qp

Aruba ClearPass, all versions of 6.6.x prior to 6.6.9 are affected by an authentication bypass vulnerability, an attacker can leverage this vulnerability to gain administrator privileges on the system. The vulnerability is exposed only on ClearPass web interfaces, including administrative, guest captive portal, and API. Customers who do not expose ClearPass web interfaces to untrusted users are impacted to a lesser extent.

CVSS3: 9.8
4%
Низкий
около 4 лет назад
github логотип
GHSA-269j-37ww-cmh3

Mezzanine CMS vulnerable to Cross-site Scripting

CVSS3: 4.8
1%
Низкий
около 1 года назад
github логотип
GHSA-269h-v9xg-7fq6

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVSS3: 8.4
0%
Низкий
10 месяцев назад
github логотип
GHSA-269h-pcpx-q5mj

Use after free in Browser UI in Google Chrome on Chrome OS prior to 99.0.4844.74 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 9.6
1%
Низкий
около 4 лет назад
github логотип
GHSA-269h-hc79-qjpf

LOYTEC electronics GmbH LINX-212 firmware 6.2.4 and LINX-151 Firmware 7.2.4 are vulnerable to Incorrect Access Control via registry.xml file. This vulnerability allows remote attackers to disclose sensitive information on LINX configuration.

CVSS3: 7.5
2%
Низкий
больше 2 лет назад
github логотип
GHSA-269h-2wf7-8247

The license-installation module on the Cisco Nexus 1000V switch 4.2(1)SV1(5.2b) and earlier for VMware vSphere, Cisco Nexus 1000V switch 5.2(1)SM1(5.1) for Microsoft Hyper-V, and Cisco Virtual Security Gateway 4.2(1)VSG1(1) for Nexus 1000V switches allows local users to gain privileges and execute arbitrary commands via crafted "install all iso" arguments, aka Bug ID CSCui21340.

0%
Низкий
около 4 лет назад

Уязвимостей на страницу