Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 489

Количество 353 489

github логотип

GHSA-25hm-qrp9-f25g

2 месяца назад

IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of symbolic links during archive extraction.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-25hm-6gxf-m348

около 4 лет назад

IBM PureApplication System 2.2.3.0 through 2.2.5.3 could allow an authenticated user with local access to bypass authentication and obtain administrative access. IBM X-Force ID: 159467.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-25hm-2vqm-695w

около 4 лет назад

Possible information exposure and denial of service due to NAS not dropping messages when integrity check fails in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-25hh-rw6j-95ch

около 1 месяца назад

A denial-of-service (DoS) vulnerability has been identified in Tapo C200 v3 in the network packet handling logic due to improper handling of IPv4 fragmented packets.  An unauthenticated adjacent attacker can send crafted packets to cause excessive resource consumption, leading to instability of the device.Successful exploitation can remotely trigger a temporary denial-of-service condition, causing the camera to become unresponsive and resulting in intermittent loss of video monitoring and recording.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-25hh-342h-jw88

около 4 лет назад

A cross-site scripting (XSS) vulnerability in the referer parameter of Dzzoffice 2.02 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

EPSS: Низкий
github логотип

GHSA-25hg-rr9r-5w7v

около 4 лет назад

Certificate Server 7.2 in Red Hat Certificate System (RHCS) does not properly handle new revocations that occur while a Certificate Revocation List (CRL) is being generated, which might prevent certain revoked certificates from appearing on the CRL quickly and allow users with revoked certificates to bypass the intended CRL.

EPSS: Низкий
github логотип

GHSA-25hg-c4gr-f986

около 4 лет назад

Directory traversal vulnerability in attachmentlibrary.php in the XStandard component for Joomla! 1.5.8 and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in the X_CMS_LIBRARY_PATH HTTP header.

EPSS: Низкий
github логотип

GHSA-25hf-x7c8-5f3h

около 4 лет назад

A bug in the standard library ScalarMult implementation of curve P-256 for amd64 architectures in Go before 1.7.6 and 1.8.x before 1.8.2 causes incorrect results to be generated for specific input points. An adaptive attack can be mounted to progressively extract the scalar input to ScalarMult by submitting crafted points and observing failures to the derive correct output. This leads to a full key recovery attack against static ECDH, as used in popular JWT libraries.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-25hf-m67j-23hc

около 4 лет назад

An issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attackers can use slowhttptest tool to send incomplete HTTP request, which could make server keep waiting for the packet to finish the connection, until its resource exhausted. Then the web server is denial-of-service.

EPSS: Низкий
github логотип

GHSA-25hc-qcg6-38wj

около 2 лет назад

socket.io has an unhandled 'error' event

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-25hc-fw6g-7r5g

больше 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Arrow Design Out Of Stock Badge allows Cross Site Request Forgery.This issue affects Out Of Stock Badge: from n/a through 1.3.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-25hc-436f-7p8m

больше 3 лет назад

In MessageQueueBase of MessageQueueBase.h, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-247092734

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-25hc-2p68-qc2g

больше 1 года назад

MongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privileges, when a crafted file is stored in C:\node_modules\. This issue affects MongoDB Compass prior to 1.42.1

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-25h9-m345-xpmx

7 месяцев назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-25h9-28j4-4h3g

около 4 лет назад

Use-after-free vulnerability in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving tables.

EPSS: Низкий
github логотип

GHSA-25h8-g2f4-5mwj

почти 3 года назад

Missing authentication in the SearchStudentsStaff method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student and teacher data by unauthenticated attackers.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-25h8-7qpw-h33r

9 месяцев назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-25h7-w4hq-hgjg

около 4 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the SimpleMeta module 6.x-1.x before 6.x-2.0 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) delete or (2) add a meta tag entry.

EPSS: Низкий
github логотип

GHSA-25h7-qcgx-8445

около 4 лет назад

An elevation of privilege vulnerability exists when the Windows Event Logging Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Event Logging Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1365.

EPSS: Низкий
github логотип

GHSA-25h7-pfq9-p65f

5 месяцев назад

flatted vulnerable to unbounded recursion DoS in parse() revive phase

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-25hm-qrp9-f25g

IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of symbolic links during archive extraction.

CVSS3: 9.8
1%
Низкий
2 месяца назад
github логотип
GHSA-25hm-6gxf-m348

IBM PureApplication System 2.2.3.0 through 2.2.5.3 could allow an authenticated user with local access to bypass authentication and obtain administrative access. IBM X-Force ID: 159467.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-25hm-2vqm-695w

Possible information exposure and denial of service due to NAS not dropping messages when integrity check fails in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVSS3: 9.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-25hh-rw6j-95ch

A denial-of-service (DoS) vulnerability has been identified in Tapo C200 v3 in the network packet handling logic due to improper handling of IPv4 fragmented packets.  An unauthenticated adjacent attacker can send crafted packets to cause excessive resource consumption, leading to instability of the device.Successful exploitation can remotely trigger a temporary denial-of-service condition, causing the camera to become unresponsive and resulting in intermittent loss of video monitoring and recording.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-25hh-342h-jw88

A cross-site scripting (XSS) vulnerability in the referer parameter of Dzzoffice 2.02 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

1%
Низкий
около 4 лет назад
github логотип
GHSA-25hg-rr9r-5w7v

Certificate Server 7.2 in Red Hat Certificate System (RHCS) does not properly handle new revocations that occur while a Certificate Revocation List (CRL) is being generated, which might prevent certain revoked certificates from appearing on the CRL quickly and allow users with revoked certificates to bypass the intended CRL.

1%
Низкий
около 4 лет назад
github логотип
GHSA-25hg-c4gr-f986

Directory traversal vulnerability in attachmentlibrary.php in the XStandard component for Joomla! 1.5.8 and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in the X_CMS_LIBRARY_PATH HTTP header.

7%
Низкий
около 4 лет назад
github логотип
GHSA-25hf-x7c8-5f3h

A bug in the standard library ScalarMult implementation of curve P-256 for amd64 architectures in Go before 1.7.6 and 1.8.x before 1.8.2 causes incorrect results to be generated for specific input points. An adaptive attack can be mounted to progressively extract the scalar input to ScalarMult by submitting crafted points and observing failures to the derive correct output. This leads to a full key recovery attack against static ECDH, as used in popular JWT libraries.

CVSS3: 5.9
2%
Низкий
около 4 лет назад
github логотип
GHSA-25hf-m67j-23hc

An issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attackers can use slowhttptest tool to send incomplete HTTP request, which could make server keep waiting for the packet to finish the connection, until its resource exhausted. Then the web server is denial-of-service.

2%
Низкий
около 4 лет назад
github логотип
GHSA-25hc-qcg6-38wj

socket.io has an unhandled 'error' event

CVSS3: 7.3
1%
Низкий
около 2 лет назад
github логотип
GHSA-25hc-fw6g-7r5g

Cross-Site Request Forgery (CSRF) vulnerability in Arrow Design Out Of Stock Badge allows Cross Site Request Forgery.This issue affects Out Of Stock Badge: from n/a through 1.3.1.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-25hc-436f-7p8m

In MessageQueueBase of MessageQueueBase.h, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-247092734

CVSS3: 6.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-25hc-2p68-qc2g

MongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privileges, when a crafted file is stored in C:\node_modules\. This issue affects MongoDB Compass prior to 1.42.1

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-25h9-m345-xpmx

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

7 месяцев назад
github логотип
GHSA-25h9-28j4-4h3g

Use-after-free vulnerability in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving tables.

3%
Низкий
около 4 лет назад
github логотип
GHSA-25h8-g2f4-5mwj

Missing authentication in the SearchStudentsStaff method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student and teacher data by unauthenticated attackers.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-25h8-7qpw-h33r

Rejected reason: Not used

9 месяцев назад
github логотип
GHSA-25h7-w4hq-hgjg

Multiple cross-site request forgery (CSRF) vulnerabilities in the SimpleMeta module 6.x-1.x before 6.x-2.0 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) delete or (2) add a meta tag entry.

1%
Низкий
около 4 лет назад
github логотип
GHSA-25h7-qcgx-8445

An elevation of privilege vulnerability exists when the Windows Event Logging Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Event Logging Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1365.

1%
Низкий
около 4 лет назад
github логотип
GHSA-25h7-pfq9-p65f

flatted vulnerable to unbounded recursion DoS in parse() revive phase

CVSS3: 7.5
1%
Низкий
5 месяцев назад

Уязвимостей на страницу