Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 376 080

Количество 376 080

github логотип

GHSA-393c-qgvj-3xph

8 месяцев назад

Gitea does not properly validate repository ownership when deleting Git LFS locks

EPSS: Низкий
github логотип

GHSA-393c-p46r-7c95

6 месяцев назад

Directus: Path Traversal and Broken Access Control in File Management API

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-393c-jhgx-p674

6 месяцев назад

Philips Hue Bridge HomeKit Accessory Protocol Static Nonce Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Philips Hue Bridge. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of the SRP authentication mechanism in the HomeKit Accessory Protocol service, which listens on TCP port 8080 by default. The issue results from the use of a static nonce value. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-28451.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-393c-hwwh-9gm2

больше 4 лет назад

A use-after-free vulnerability can occur when an IndexedDB index is deleted while still in use by JavaScript code that is providing payload values to be stored. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-393c-4g2g-74rm

около 3 лет назад

An issue was discovered in Webmin 2.021. A Cross-site Scripting (XSS) Bypass vulnerability was discovered in the file upload functionality. Normally, the application restricts the upload of certain file types such as .svg, .php, etc., and displays an error message if a prohibited file type is detected. However, by following certain steps, an attacker can bypass these restrictions and inject malicious code.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3939-pwx4-f89g

больше 4 лет назад

Unspecified vulnerability in HP Operations Agent 7.36 and 8.6 on Windows allows remote attackers to execute arbitrary code via unknown vectors.

EPSS: Низкий
github логотип

GHSA-3939-3x7w-37p9

3 месяца назад

Subscriber Arbitrary File Upload in Charity Zone <= 1.1.1 versions.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-3938-vx68-327v

больше 4 лет назад

Improper Input Validation, Cross-site Scripting (XSS) vulnerability in Web GUI of Secomea GateManager allows an attacker to execute arbitrary javascript code. This issue affects: Secomea GateManager all versions prior to 9.4.

EPSS: Низкий
github логотип

GHSA-3938-v8r3-qpfh

больше 4 лет назад

SQL injection vulnerability in helper/popup.php in the ccNewsletter (mod_ccnewsletter) component 1.0.7 through 1.0.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter.

EPSS: Низкий
github логотип

GHSA-3938-2cj5-r45m

больше 2 лет назад

Directory Traversal vulnerability in Kihron ServerRPExposer v.1.0.2 and before allows a remote attacker to execute arbitrary code via the loadServerPack in ServerResourcePackProviderMixin.java.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3937-gxfq-r6h8

больше 4 лет назад

Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the WAdvancedFilter/getDimensionItemsByCode FilterValue parameter.

EPSS: Низкий
github логотип

GHSA-3937-g562-gx7p

больше 4 лет назад

Stack-based buffer overflow in News File Grabber 4.1.0.1 and earlier allows remote attackers to execute arbitrary code via a .nzb file with a long subject field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-3937-c38r-7v8c

больше 4 лет назад

Vulnerability in the Siebel CRM Desktop component of Oracle Siebel CRM (subcomponent: Siebel Business Service Issues). Supported versions that are affected are 16.0 and 17.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Desktop. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Siebel CRM Desktop accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3937-9m84-64gp

больше 4 лет назад

Firefox before 1.0.5 and Mozilla before 1.7.9 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability."

EPSS: Низкий
github логотип

GHSA-3937-3989-hjv5

больше 4 лет назад

Zoho ManageEngine ADManager Plus version 7110 and prior has a Post-Auth OS command injection vulnerability.

EPSS: Средний
github логотип

GHSA-3936-ppm9-g3c2

около 1 года назад

Successful exploitation of the vulnerability could allow an unauthenticated, remote attacker to send Modbus TCP packets to manipulate Digital Outputs, potentially allowing remote control of relay channel which may lead to operational or safety risks.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3936-cmfr-pm3m

7 месяцев назад

Black: Arbitrary file writes from unsanitized user input in cache file name

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3936-9446-hfx7

больше 4 лет назад

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0143 and CVE-2016-0167.

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-3936-5cxx-gxgf

больше 4 лет назад

When GraphicsMagick 1.3.25 processes a DPX image (with metadata indicating a large width) in coders/dpx.c, a denial of service (OOM) can occur in ReadDPXImage().

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-3936-3gx6-49c4

больше 1 года назад

Apache Commons VFS Exposure of Sensitive Information to an Unauthorized Actor

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-393c-qgvj-3xph

Gitea does not properly validate repository ownership when deleting Git LFS locks

0%
Низкий
8 месяцев назад
github логотип
GHSA-393c-p46r-7c95

Directus: Path Traversal and Broken Access Control in File Management API

CVSS3: 8.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-393c-jhgx-p674

Philips Hue Bridge HomeKit Accessory Protocol Static Nonce Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Philips Hue Bridge. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of the SRP authentication mechanism in the HomeKit Accessory Protocol service, which listens on TCP port 8080 by default. The issue results from the use of a static nonce value. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-28451.

CVSS3: 8.1
0%
Низкий
6 месяцев назад
github логотип
GHSA-393c-hwwh-9gm2

A use-after-free vulnerability can occur when an IndexedDB index is deleted while still in use by JavaScript code that is providing payload values to be stored. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-393c-4g2g-74rm

An issue was discovered in Webmin 2.021. A Cross-site Scripting (XSS) Bypass vulnerability was discovered in the file upload functionality. Normally, the application restricts the upload of certain file types such as .svg, .php, etc., and displays an error message if a prohibited file type is detected. However, by following certain steps, an attacker can bypass these restrictions and inject malicious code.

CVSS3: 6.1
1%
Низкий
около 3 лет назад
github логотип
GHSA-3939-pwx4-f89g

Unspecified vulnerability in HP Operations Agent 7.36 and 8.6 on Windows allows remote attackers to execute arbitrary code via unknown vectors.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-3939-3x7w-37p9

Subscriber Arbitrary File Upload in Charity Zone <= 1.1.1 versions.

CVSS3: 9.9
0%
Низкий
3 месяца назад
github логотип
GHSA-3938-vx68-327v

Improper Input Validation, Cross-site Scripting (XSS) vulnerability in Web GUI of Secomea GateManager allows an attacker to execute arbitrary javascript code. This issue affects: Secomea GateManager all versions prior to 9.4.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3938-v8r3-qpfh

SQL injection vulnerability in helper/popup.php in the ccNewsletter (mod_ccnewsletter) component 1.0.7 through 1.0.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3938-2cj5-r45m

Directory Traversal vulnerability in Kihron ServerRPExposer v.1.0.2 and before allows a remote attacker to execute arbitrary code via the loadServerPack in ServerResourcePackProviderMixin.java.

CVSS3: 8.8
2%
Низкий
больше 2 лет назад
github логотип
GHSA-3937-gxfq-r6h8

Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the WAdvancedFilter/getDimensionItemsByCode FilterValue parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3937-g562-gx7p

Stack-based buffer overflow in News File Grabber 4.1.0.1 and earlier allows remote attackers to execute arbitrary code via a .nzb file with a long subject field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-3937-c38r-7v8c

Vulnerability in the Siebel CRM Desktop component of Oracle Siebel CRM (subcomponent: Siebel Business Service Issues). Supported versions that are affected are 16.0 and 17.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Desktop. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Siebel CRM Desktop accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3937-9m84-64gp

Firefox before 1.0.5 and Mozilla before 1.7.9 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability."

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3937-3989-hjv5

Zoho ManageEngine ADManager Plus version 7110 and prior has a Post-Auth OS command injection vulnerability.

10%
Средний
больше 4 лет назад
github логотип
GHSA-3936-ppm9-g3c2

Successful exploitation of the vulnerability could allow an unauthenticated, remote attacker to send Modbus TCP packets to manipulate Digital Outputs, potentially allowing remote control of relay channel which may lead to operational or safety risks.

CVSS3: 8.1
1%
Низкий
около 1 года назад
github логотип
GHSA-3936-cmfr-pm3m

Black: Arbitrary file writes from unsanitized user input in cache file name

CVSS3: 7.5
1%
Низкий
7 месяцев назад
github логотип
GHSA-3936-9446-hfx7

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0143 and CVE-2016-0167.

CVSS3: 7.8
14%
Средний
больше 4 лет назад
github логотип
GHSA-3936-5cxx-gxgf

When GraphicsMagick 1.3.25 processes a DPX image (with metadata indicating a large width) in coders/dpx.c, a denial of service (OOM) can occur in ReadDPXImage().

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3936-3gx6-49c4

Apache Commons VFS Exposure of Sensitive Information to an Unauthorized Actor

1%
Низкий
больше 1 года назад

Уязвимостей на страницу