Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 727

Количество 375 727

github логотип

GHSA-38fr-qxq2-m645

около 3 лет назад

In Keysight Geolocation Server v2.4.2 and prior, an attacker could upload a specially crafted malicious file or delete any file or directory with SYSTEM privileges due to an improper path validation, which could result in local privilege escalation or a denial-of-service condition.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-38fr-fpg3-22rf

около 2 месяцев назад

ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of ATEN Unizon. Authentication is not required to exploit this vulnerability. The specific flaw exists within the RpcProvider class. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-29041.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-38fr-2xrg-mwqm

11 месяцев назад

The Reolink Desktop Application 8.18.12 contains hardcoded credentials as the Initialization Vector (IV) in its AES-CFB encryption implementation allowing attackers with access to the application environment to reliably decrypt encrypted configuration data.

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-38fq-h5hc-gwv8

около 3 лет назад

Microsoft Security Advisory CVE-2023-36794: .NET Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-38fq-722f-5mfp

больше 4 лет назад

In the parseURL function of URLStreamHandler, there is improper input validation of the host field. This could lead to a remote elevation of privilege that could enable bypassing user interaction requirements with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68341964.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-38fp-9j49-g4gm

больше 4 лет назад

Attacker is able craft an article with a link to the customer address book with malicious content (JavaScript). When agent opens the link, JavaScript code is executed due to the missing parameter encoding. This issue affects: ((OTRS)) Community Edition: 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-38fm-xc5v-hgc5

почти 4 года назад

This vulnerability happens in the web client versions 15.3.0 to Serv-U 15.3.1. This vulnerability affects the directory creation function.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-38fm-hvrq-g6g6

около 3 лет назад

The Woo Custom Emails for WordPress is vulnerable to Reflected Cross-Site Scripting via the wcemails_edit parameter in versions up to, and including, 2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-38fm-2h4v-3qf4

почти 3 года назад

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-38fj-36m5-783c

2 месяца назад

Duplicate Advisory: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access

EPSS: Низкий
github логотип

GHSA-38fh-px4j-r2wx

больше 4 лет назад

Mantis 1.0.0rc3 and earlier discloses private bugs via public RSS feeds, which allows remote attackers to obtain sensitive information.

EPSS: Низкий
github логотип

GHSA-38fh-mgpv-6gjj

больше 4 лет назад

BadBlue 2.72b and earlier allows remote attackers to obtain sensitive information via an invalid browse parameter, which reveals the installation path in an error message.

EPSS: Низкий
github логотип

GHSA-38fh-7j8c-5f2w

больше 4 лет назад

Unspecified vulnerability in the Oracle OLAP component in Oracle Database Server 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, 11.1.0.7, and 11.2.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.

EPSS: Низкий
github логотип

GHSA-38fh-5rpq-pxq2

больше 4 лет назад

Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

EPSS: Низкий
github логотип

GHSA-38fg-rh2c-fh5c

больше 4 лет назад

Unspecified vulnerability in libpng before 1.6.20, as used in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01, allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 23265085.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-38fc-wpqx-33j7

около 5 лет назад

Uncontrolled Resource Consumption in trim-off-newlines

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-38fc-w9g8-x254

больше 4 лет назад

An issue was discovered in GPAC version 0.8.0. There is a NULL pointer dereference in the function gf_isom_get_media_data_size() in isomedia/isom_read.c.

EPSS: Низкий
github логотип

GHSA-38fc-cmwf-cfvc

больше 4 лет назад

Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability.

EPSS: Средний
github логотип

GHSA-38fc-9xqv-7f7q

больше 7 лет назад

SQLAlchemy is vulnerable to SQL Injection via group_by parameter

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-38f9-m297-6q9g

больше 6 лет назад

DoS via malicious record IDs in WatermelonDB

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-38fr-qxq2-m645

In Keysight Geolocation Server v2.4.2 and prior, an attacker could upload a specially crafted malicious file or delete any file or directory with SYSTEM privileges due to an improper path validation, which could result in local privilege escalation or a denial-of-service condition.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-38fr-fpg3-22rf

ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of ATEN Unizon. Authentication is not required to exploit this vulnerability. The specific flaw exists within the RpcProvider class. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-29041.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-38fr-2xrg-mwqm

The Reolink Desktop Application 8.18.12 contains hardcoded credentials as the Initialization Vector (IV) in its AES-CFB encryption implementation allowing attackers with access to the application environment to reliably decrypt encrypted configuration data.

CVSS3: 5.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-38fq-h5hc-gwv8

Microsoft Security Advisory CVE-2023-36794: .NET Remote Code Execution Vulnerability

CVSS3: 7.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-38fq-722f-5mfp

In the parseURL function of URLStreamHandler, there is improper input validation of the host field. This could lead to a remote elevation of privilege that could enable bypassing user interaction requirements with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68341964.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-38fp-9j49-g4gm

Attacker is able craft an article with a link to the customer address book with malicious content (JavaScript). When agent opens the link, JavaScript code is executed due to the missing parameter encoding. This issue affects: ((OTRS)) Community Edition: 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-38fm-xc5v-hgc5

This vulnerability happens in the web client versions 15.3.0 to Serv-U 15.3.1. This vulnerability affects the directory creation function.

CVSS3: 5.4
1%
Низкий
почти 4 года назад
github логотип
GHSA-38fm-hvrq-g6g6

The Woo Custom Emails for WordPress is vulnerable to Reflected Cross-Site Scripting via the wcemails_edit parameter in versions up to, and including, 2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-38fm-2h4v-3qf4

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

CVSS3: 6.2
1%
Низкий
почти 3 года назад
github логотип
GHSA-38fj-36m5-783c

Duplicate Advisory: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access

2 месяца назад
github логотип
GHSA-38fh-px4j-r2wx

Mantis 1.0.0rc3 and earlier discloses private bugs via public RSS feeds, which allows remote attackers to obtain sensitive information.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-38fh-mgpv-6gjj

BadBlue 2.72b and earlier allows remote attackers to obtain sensitive information via an invalid browse parameter, which reveals the installation path in an error message.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-38fh-7j8c-5f2w

Unspecified vulnerability in the Oracle OLAP component in Oracle Database Server 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, 11.1.0.7, and 11.2.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-38fh-5rpq-pxq2

Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

1%
Низкий
больше 4 лет назад
github логотип
GHSA-38fg-rh2c-fh5c

Unspecified vulnerability in libpng before 1.6.20, as used in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01, allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 23265085.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-38fc-wpqx-33j7

Uncontrolled Resource Consumption in trim-off-newlines

CVSS3: 5.3
2%
Низкий
около 5 лет назад
github логотип
GHSA-38fc-w9g8-x254

An issue was discovered in GPAC version 0.8.0. There is a NULL pointer dereference in the function gf_isom_get_media_data_size() in isomedia/isom_read.c.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-38fc-cmwf-cfvc

Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability.

28%
Средний
больше 4 лет назад
github логотип
GHSA-38fc-9xqv-7f7q

SQLAlchemy is vulnerable to SQL Injection via group_by parameter

CVSS3: 7.8
2%
Низкий
больше 7 лет назад
github логотип
GHSA-38f9-m297-6q9g

DoS via malicious record IDs in WatermelonDB

CVSS3: 5.9
1%
Низкий
больше 6 лет назад

Уязвимостей на страницу