Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 727

Количество 375 727

github логотип

GHSA-389r-v5pg-54r7

больше 4 лет назад

Microsoft SharePoint Enterprise Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an attacker to exploit a cross-site scripting (XSS) vulnerability by sending a specially crafted request to an affected SharePoint server, due to how SharePoint Server sanitizes web requests, aka "Microsoft Office SharePoint XSS Vulnerability". This CVE ID is unique from CVE-2017-11775 and CVE-2017-11777.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-389r-rccm-h3h5

7 месяцев назад

eml_parser: Path Traversal in Official Example Script Leads to Arbitrary File Write

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-389r-gv7p-r3rp

4 месяца назад

go-git's improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git

EPSS: Низкий
github логотип

GHSA-389q-wq7j-hp78

около 3 лет назад

Aruba AirWave before 8.0.7 allows XSS attacks agsinat an administrator.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-389q-94h9-f6qm

больше 2 лет назад

SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in PowerSYSTEM Center.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-389q-8mv3-6hx2

больше 4 лет назад

In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a buffer overread is observed in __wlan_hdd_cfg80211_set_pmksa when user space application sends PMKID of size less than WLAN_PMKID_LEN bytes.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-389p-g792-49fp

21 день назад

Baserow 2.3.3 contains a SQL injection vulnerability in the index() formula function. A low-privileged authenticated user who can create or modify formula fields can provide an undocumented fourth argument that is treated as a SQL template and interpolated directly into a PostgreSQL expression. The vulnerable expression is executed when Baserow recalculates formula field values. Because the generated SQL runs through Baserow's database connection, the injected SQL executes with the privileges of the Baserow PostgreSQL role rather than the permissions of the authenticated application user. This issue affects Baserow: 2.3.3.

EPSS: Низкий
github логотип

GHSA-389p-g5q7-wj2f

больше 4 лет назад

Cacti before 0.6.8 stores a MySQL username and password in plaintext in config.php, which has world-readable permissions, which allows local users to modify databases as the Cacti user and possibly gain privileges.

EPSS: Низкий
github логотип

GHSA-389p-fchr-q2mg

больше 4 лет назад

Path Traversal in ImpressCMS

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-389p-6whp-pg38

больше 4 лет назад

Huawei X6800 and XH620 V3 servers with software before V100R003C00SPC606, RH1288 V3 servers with software before V100R003C00SPC613, RH2288 V3 servers with software before V100R003C00SPC617, CH140 V3 and CH226 V3 servers with software before V100R001C00SPC122, CH220 V3 servers with software before V100R001C00SPC201, and CH121 V3 and CH222 V3 servers with software before V100R001C00SPC202 might allow remote attackers to decrypt encrypted data and consequently obtain sensitive information by leveraging selection of an insecure SSH encryption algorithm.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-389m-px3j-rcmc

15 дней назад

Stack-based buffer overflow in Windows Fast FAT Driver allows an authorized attacker to elevate privileges over a network.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-389m-cgpc-f2xq

больше 4 лет назад

Session fixation vulnerability in TIBCO Spotfire Server 3.0.x before 3.0.2, 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.1, and Spotfire Analytics Server before 10.1.1, allows remote attackers to hijack web sessions via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-389m-9g22-rcpx

больше 4 лет назад

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, and Office Web Apps Server 2013 SP1 allow remote attackers to obtain sensitive information from process memory via a crafted Office document, aka "Microsoft Office Information Disclosure Vulnerability."

CVSS3: 5.5
EPSS: Средний
github логотип

GHSA-389j-qw4x-m76h

больше 4 лет назад

Multiple SQL injection vulnerabilities in the get_record function in datalib.php in Moodle 1.5.2 allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) category.php and (2) info.php.

EPSS: Низкий
github логотип

GHSA-389j-cw3h-6fc8

больше 4 лет назад

During installation or upgrade to Software House C•CURE 9000 v2.70 and American Dynamics victor Video Management System v5.2, the credentials of the user used to perform the installation or upgrade are logged in a file. The install log file persists after the installation.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-389h-r2q6-jqgm

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in phpBB 2.0.6d and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) postdays parameter to viewtopic.php or (2) topicdays parameter to viewforum.php.

EPSS: Низкий
github логотип

GHSA-389h-737c-f3fq

больше 4 лет назад

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-30139, CVE-2022-30141, CVE-2022-30143, CVE-2022-30149, CVE-2022-30153, CVE-2022-30161.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-389h-6rjg-wxc9

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: xhci: handle isoc Babble and Buffer Overrun events properly xHCI 4.9 explicitly forbids assuming that the xHC has released its ownership of a multi-TRB TD when it reports an error on one of the early TRBs. Yet the driver makes such assumption and releases the TD, allowing the remaining TRBs to be freed or overwritten by new TDs. The xHC should also report completion of the final TRB due to its IOC flag being set by us, regardless of prior errors. This event cannot be recognized if the TD has already been freed earlier, resulting in "Transfer event TRB DMA ptr not part of current TD" error message. Fix this by reusing the logic for processing isoc Transaction Errors. This also handles hosts which fail to report the final completion. Fix transfer length reporting on Babble errors. They may be caused by device malfunction, no guarantee that the buffer has been filled.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-389g-v72q-8rrr

больше 4 лет назад

Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2012-1766, CVE-2012-1769, CVE-2012-1770, CVE-2012-1771, CVE-2012-1772, CVE-2012-1773, CVE-2012-3106, CVE-2012-3107, CVE-2012-3108, and CVE-2012-3110.

EPSS: Низкий
github логотип

GHSA-389c-f9cf-c585

около 1 месяца назад

OriginLab Origin Viewer OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of OPJ files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29336.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-389r-v5pg-54r7

Microsoft SharePoint Enterprise Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an attacker to exploit a cross-site scripting (XSS) vulnerability by sending a specially crafted request to an affected SharePoint server, due to how SharePoint Server sanitizes web requests, aka "Microsoft Office SharePoint XSS Vulnerability". This CVE ID is unique from CVE-2017-11775 and CVE-2017-11777.

CVSS3: 5.4
3%
Низкий
больше 4 лет назад
github логотип
GHSA-389r-rccm-h3h5

eml_parser: Path Traversal in Official Example Script Leads to Arbitrary File Write

CVSS3: 5.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-389r-gv7p-r3rp

go-git's improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git

0%
Низкий
4 месяца назад
github логотип
GHSA-389q-wq7j-hp78

Aruba AirWave before 8.0.7 allows XSS attacks agsinat an administrator.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-389q-94h9-f6qm

SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in PowerSYSTEM Center.

CVSS3: 8.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-389q-8mv3-6hx2

In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a buffer overread is observed in __wlan_hdd_cfg80211_set_pmksa when user space application sends PMKID of size less than WLAN_PMKID_LEN bytes.

CVSS3: 7.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-389p-g792-49fp

Baserow 2.3.3 contains a SQL injection vulnerability in the index() formula function. A low-privileged authenticated user who can create or modify formula fields can provide an undocumented fourth argument that is treated as a SQL template and interpolated directly into a PostgreSQL expression. The vulnerable expression is executed when Baserow recalculates formula field values. Because the generated SQL runs through Baserow's database connection, the injected SQL executes with the privileges of the Baserow PostgreSQL role rather than the permissions of the authenticated application user. This issue affects Baserow: 2.3.3.

0%
Низкий
21 день назад
github логотип
GHSA-389p-g5q7-wj2f

Cacti before 0.6.8 stores a MySQL username and password in plaintext in config.php, which has world-readable permissions, which allows local users to modify databases as the Cacti user and possibly gain privileges.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-389p-fchr-q2mg

Path Traversal in ImpressCMS

CVSS3: 9.8
6%
Низкий
больше 4 лет назад
github логотип
GHSA-389p-6whp-pg38

Huawei X6800 and XH620 V3 servers with software before V100R003C00SPC606, RH1288 V3 servers with software before V100R003C00SPC613, RH2288 V3 servers with software before V100R003C00SPC617, CH140 V3 and CH226 V3 servers with software before V100R001C00SPC122, CH220 V3 servers with software before V100R001C00SPC201, and CH121 V3 and CH222 V3 servers with software before V100R001C00SPC202 might allow remote attackers to decrypt encrypted data and consequently obtain sensitive information by leveraging selection of an insecure SSH encryption algorithm.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-389m-px3j-rcmc

Stack-based buffer overflow in Windows Fast FAT Driver allows an authorized attacker to elevate privileges over a network.

CVSS3: 8
1%
Низкий
15 дней назад
github логотип
GHSA-389m-cgpc-f2xq

Session fixation vulnerability in TIBCO Spotfire Server 3.0.x before 3.0.2, 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.1, and Spotfire Analytics Server before 10.1.1, allows remote attackers to hijack web sessions via unspecified vectors.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-389m-9g22-rcpx

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, and Office Web Apps Server 2013 SP1 allow remote attackers to obtain sensitive information from process memory via a crafted Office document, aka "Microsoft Office Information Disclosure Vulnerability."

CVSS3: 5.5
16%
Средний
больше 4 лет назад
github логотип
GHSA-389j-qw4x-m76h

Multiple SQL injection vulnerabilities in the get_record function in datalib.php in Moodle 1.5.2 allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) category.php and (2) info.php.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-389j-cw3h-6fc8

During installation or upgrade to Software House C•CURE 9000 v2.70 and American Dynamics victor Video Management System v5.2, the credentials of the user used to perform the installation or upgrade are logged in a file. The install log file persists after the installation.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-389h-r2q6-jqgm

Cross-site scripting (XSS) vulnerability in phpBB 2.0.6d and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) postdays parameter to viewtopic.php or (2) topicdays parameter to viewforum.php.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-389h-737c-f3fq

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-30139, CVE-2022-30141, CVE-2022-30143, CVE-2022-30149, CVE-2022-30153, CVE-2022-30161.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-389h-6rjg-wxc9

In the Linux kernel, the following vulnerability has been resolved: xhci: handle isoc Babble and Buffer Overrun events properly xHCI 4.9 explicitly forbids assuming that the xHC has released its ownership of a multi-TRB TD when it reports an error on one of the early TRBs. Yet the driver makes such assumption and releases the TD, allowing the remaining TRBs to be freed or overwritten by new TDs. The xHC should also report completion of the final TRB due to its IOC flag being set by us, regardless of prior errors. This event cannot be recognized if the TD has already been freed earlier, resulting in "Transfer event TRB DMA ptr not part of current TD" error message. Fix this by reusing the logic for processing isoc Transaction Errors. This also handles hosts which fail to report the final completion. Fix transfer length reporting on Babble errors. They may be caused by device malfunction, no guarantee that the buffer has been filled.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-389g-v72q-8rrr

Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2012-1766, CVE-2012-1769, CVE-2012-1770, CVE-2012-1771, CVE-2012-1772, CVE-2012-1773, CVE-2012-3106, CVE-2012-3107, CVE-2012-3108, and CVE-2012-3110.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-389c-f9cf-c585

OriginLab Origin Viewer OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of OPJ files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29336.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу