Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 376 080

Количество 376 080

github логотип

GHSA-38wv-xxqw-6v4w

около 1 года назад

When Network Access is configured on a BIG-IP APM virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-38wv-wfx6-3cx2

8 месяцев назад

YetiShare File Hosting Script 5.1.0 contains a server-side request forgery vulnerability that allows attackers to read local system files through the remote file upload feature. Attackers can exploit the url parameter in the url_upload_handler endpoint to access sensitive files like /etc/passwd by using file:/// protocol.

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-38wv-982m-4q6p

больше 4 лет назад

Improper authentication vulnerability in SCT-40CM01SR and AT-40CM01SR allows an attacker to bypass access restriction and execute an arbitrary command via telnet.

EPSS: Низкий
github логотип

GHSA-38wr-vpc7-2mp4

2 месяца назад

dd-trace-dotnet: Improper parsing of W3C baggage headers may lead to DoS

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-38wr-pjxc-vgf7

больше 3 лет назад

Knot Resolver before 5.6.0 enables attackers to consume its resources, launching amplification attacks and potentially causing a denial of service. Specifically, a single client query may lead to a hundred TCP connection attempts if a DNS server closes connections without providing a response.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-38wr-g9xc-v3j7

больше 4 лет назад

** DISPUTED ** PatrolAgent.exe in BMC Performance Manager does not require authentication for requests to modify configuration files, which allows remote attackers to execute arbitrary code via a request on TCP port 3181 for modification of the masterAgentName and masterAgentStartLine SNMP parameters. NOTE: the vendor disputes this vulnerability, stating that it does not exist when the system is properly configured.

EPSS: Низкий
github логотип

GHSA-38wr-8jpj-263v

больше 4 лет назад

Stack-based buffer overflow in the Anti-Virus engine before content update 30.6 in multiple CA (formerly Computer Associates) products allows remote attackers to execute arbitrary code via a large invalid value of the coffFiles field in a .CAB file.

EPSS: Средний
github логотип

GHSA-38wq-r4mv-7p28

больше 1 года назад

Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

EPSS: Низкий
github логотип

GHSA-38wq-hqmp-4jj6

около 2 месяцев назад

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] With the introduction of Grant Table v2 came the requirement to be able to switch between versions. Switching from v1 to v2 reduces the number of valid grant references, as a bigger shared entry structure is then needed while the shared table doesn't change size. Switching from v2 back to v1 the status frames, which are separate in v2, go away. Code holding, but intermediately dropping and then re-acquiring the grant table lock, sometimes wrongly assumes that said properties wouldn't change across the window in time where the lock is not being held. The v1 -> v2 issue is CVE-2026-62435. The v2 -> v1 issue is CVE-2026-62436.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-38wq-6q2w-hcf9

7 месяцев назад

Rucio WebUI has Username Enumeration via Login Error Message

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-38wp-738r-69jh

8 месяцев назад

A vulnerability was found in WeKan up to 8.20. This affects an unknown function of the file models/attachments.js of the component Attachment Storage. The manipulation results in improper access controls. The attack may be launched remotely. Upgrading to version 8.21 mitigates this issue. The patch is identified as c413a7e860bc4d93fe2adcf82516228570bf382d. Upgrading the affected component is advised.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-38wm-mhwf-wxxg

больше 4 лет назад

A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Win32k Graphics Remote Code Execution Vulnerability'.

EPSS: Средний
github логотип

GHSA-38wm-547c-5mmg

больше 1 года назад

Uncontrolled search path for some EPCT software before version 1.42.8.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-38wj-vw4m-m5hg

больше 4 лет назад

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16.6, RBK852 before 3.2.16.6, RBR850 before 3.2.16.6, and RBS850 before 3.2.16.6.

EPSS: Низкий
github логотип

GHSA-38wj-mm25-rhw6

больше 4 лет назад

Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity via vectors related to Console, a different vulnerability than CVE-2016-0700.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-38wj-jq62-7fx7

около 1 года назад

Permission bypass vulnerability in the calendar storage module Impact: Successful exploitation of this vulnerability may affect the schedule reminder function of head units.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-38wh-jw2h-h2f5

больше 4 лет назад

Bastet module of some Huawei smartphones with Versions earlier than Emily-AL00A 9.0.0.182(C00E82R1P21), Versions earlier than Emily-TL00B 9.0.0.182(C01E82R1P21), Versions earlier than Emily-L09C 9.0.0.203(C432E7R1P11), Versions earlier than Emily-L29C 9.0.0.203(C432E7R1P11), Versions earlier than Emily-L29C 9.0.0.202(C185E2R1P12) have a double free vulnerability. An attacker tricks the user into installing a malicious application, which frees on the same memory address twice. Successful exploit could result in malicious code execution.

EPSS: Низкий
github логотип

GHSA-38wf-gvg7-rrvw

почти 2 года назад

Missing Authorization vulnerability in Harmonic Design HD Quiz – Save Results Light allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HD Quiz – Save Results Light: from n/a through 0.5.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-38wf-932f-qv6q

около 3 лет назад

In multiple functions of mem_protect.c, there is a possible way to access hypervisor memory due to a memory access check in the wrong place. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-38wc-m42p-9wqf

22 дня назад

A remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system, leading to complete compromise of the HPE Networking Fabric Composer host.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-38wv-xxqw-6v4w

When Network Access is configured on a BIG-IP APM virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS3: 7.5
0%
Низкий
около 1 года назад
github логотип
GHSA-38wv-wfx6-3cx2

YetiShare File Hosting Script 5.1.0 contains a server-side request forgery vulnerability that allows attackers to read local system files through the remote file upload feature. Attackers can exploit the url parameter in the url_upload_handler endpoint to access sensitive files like /etc/passwd by using file:/// protocol.

CVSS3: 4
0%
Низкий
8 месяцев назад
github логотип
GHSA-38wv-982m-4q6p

Improper authentication vulnerability in SCT-40CM01SR and AT-40CM01SR allows an attacker to bypass access restriction and execute an arbitrary command via telnet.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-38wr-vpc7-2mp4

dd-trace-dotnet: Improper parsing of W3C baggage headers may lead to DoS

CVSS3: 7.5
1%
Низкий
2 месяца назад
github логотип
GHSA-38wr-pjxc-vgf7

Knot Resolver before 5.6.0 enables attackers to consume its resources, launching amplification attacks and potentially causing a denial of service. Specifically, a single client query may lead to a hundred TCP connection attempts if a DNS server closes connections without providing a response.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-38wr-g9xc-v3j7

** DISPUTED ** PatrolAgent.exe in BMC Performance Manager does not require authentication for requests to modify configuration files, which allows remote attackers to execute arbitrary code via a request on TCP port 3181 for modification of the masterAgentName and masterAgentStartLine SNMP parameters. NOTE: the vendor disputes this vulnerability, stating that it does not exist when the system is properly configured.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-38wr-8jpj-263v

Stack-based buffer overflow in the Anti-Virus engine before content update 30.6 in multiple CA (formerly Computer Associates) products allows remote attackers to execute arbitrary code via a large invalid value of the coffFiles field in a .CAB file.

50%
Средний
больше 4 лет назад
github логотип
GHSA-38wq-r4mv-7p28

Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.

больше 1 года назад
github логотип
GHSA-38wq-hqmp-4jj6

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] With the introduction of Grant Table v2 came the requirement to be able to switch between versions. Switching from v1 to v2 reduces the number of valid grant references, as a bigger shared entry structure is then needed while the shared table doesn't change size. Switching from v2 back to v1 the status frames, which are separate in v2, go away. Code holding, but intermediately dropping and then re-acquiring the grant table lock, sometimes wrongly assumes that said properties wouldn't change across the window in time where the lock is not being held. The v1 -> v2 issue is CVE-2026-62435. The v2 -> v1 issue is CVE-2026-62436.

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-38wq-6q2w-hcf9

Rucio WebUI has Username Enumeration via Login Error Message

CVSS3: 5.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-38wp-738r-69jh

A vulnerability was found in WeKan up to 8.20. This affects an unknown function of the file models/attachments.js of the component Attachment Storage. The manipulation results in improper access controls. The attack may be launched remotely. Upgrading to version 8.21 mitigates this issue. The patch is identified as c413a7e860bc4d93fe2adcf82516228570bf382d. Upgrading the affected component is advised.

CVSS3: 6.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-38wm-mhwf-wxxg

A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Win32k Graphics Remote Code Execution Vulnerability'.

17%
Средний
больше 4 лет назад
github логотип
GHSA-38wm-547c-5mmg

Uncontrolled search path for some EPCT software before version 1.42.8.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 6.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-38wj-vw4m-m5hg

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16.6, RBK852 before 3.2.16.6, RBR850 before 3.2.16.6, and RBS850 before 3.2.16.6.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-38wj-mm25-rhw6

Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity via vectors related to Console, a different vulnerability than CVE-2016-0700.

CVSS3: 6.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-38wj-jq62-7fx7

Permission bypass vulnerability in the calendar storage module Impact: Successful exploitation of this vulnerability may affect the schedule reminder function of head units.

CVSS3: 4.8
0%
Низкий
около 1 года назад
github логотип
GHSA-38wh-jw2h-h2f5

Bastet module of some Huawei smartphones with Versions earlier than Emily-AL00A 9.0.0.182(C00E82R1P21), Versions earlier than Emily-TL00B 9.0.0.182(C01E82R1P21), Versions earlier than Emily-L09C 9.0.0.203(C432E7R1P11), Versions earlier than Emily-L29C 9.0.0.203(C432E7R1P11), Versions earlier than Emily-L29C 9.0.0.202(C185E2R1P12) have a double free vulnerability. An attacker tricks the user into installing a malicious application, which frees on the same memory address twice. Successful exploit could result in malicious code execution.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-38wf-gvg7-rrvw

Missing Authorization vulnerability in Harmonic Design HD Quiz – Save Results Light allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HD Quiz – Save Results Light: from n/a through 0.5.

CVSS3: 5.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-38wf-932f-qv6q

In multiple functions of mem_protect.c, there is a possible way to access hypervisor memory due to a memory access check in the wrong place. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 6.7
0%
Низкий
около 3 лет назад
github логотип
GHSA-38wc-m42p-9wqf

A remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system, leading to complete compromise of the HPE Networking Fabric Composer host.

CVSS3: 7.5
0%
Низкий
22 дня назад

Уязвимостей на страницу