Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 727

Количество 375 727

github логотип

GHSA-3863-q6pp-rrcg

больше 1 года назад

All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.9.19 are vulnerable to cross-site request forgery (CSRF). An external attacker with no access to the device can force the end user into submitting a "setconf" method request, not requiring any CSRF token, which can lead into denial of service on the device.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-3863-h4xw-2xv3

больше 4 лет назад

An issue was discovered in Pure-FTPd 1.0.49. An out-of-bounds (OOB) read has been detected in the pure_strcmp function in utils.c.

EPSS: Низкий
github логотип

GHSA-3863-8rfp-v9rw

7 дней назад

A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. Affected is the function urllib.request.urlopen of the file integrations/aws-strands/python/src/ag_ui_strands/utils.py of the component Multimodal Content. The manipulation of the argument Value results in server-side request forgery. The attack can be executed remotely. The patch is identified as bf0c34df34cbb4b1992bc37c9bfffe6dd54bb189. It is advisable to implement a patch to correct this issue.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3863-2447-669p

почти 3 года назад

transformers has a Deserialization of Untrusted Data vulnerability

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-3862-v28r-vqw4

больше 4 лет назад

seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-3862-j6jr-jg22

больше 4 лет назад

Multiple buffer overflows in the torrent parsing implementation in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allow remote attackers to execute arbitrary code via (1) a long file name within a torrent file, (2) a long tracker URL in a torrent file, or (3) a long comment in a torrent file.

EPSS: Средний
github логотип

GHSA-3862-fmr3-4f3h

больше 3 лет назад

Broadleaf vulnerable to Cross-site Scripting

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3862-f8g9-4ffc

почти 2 года назад

Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Featured Post Creative allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Featured Post Creative: from n/a through 1.2.7.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3862-c622-v4fp

больше 3 лет назад

Cross-site Scripting in Backdrop CMS

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-3862-5qvv-3rvv

около 2 лет назад

The Floating Social Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the floating_social_buttons_option() function. This makes it possible for unauthenticated attackers to update the plugins settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-385x-88c3-c379

больше 4 лет назад

Azure Sphere Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-41375, CVE-2021-41376.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-385w-hjpp-r4cx

больше 3 лет назад

Exposure of resource to wrong sphere in Zoom for Windows and Zoom for MacOS clients before 5.14.10 may allow an authenticated user to potentially enable information disclosure via network access.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-385w-3r67-h9rr

почти 2 года назад

Missing Authorization vulnerability in appsbd Mini Cart Drawer For WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mini Cart Drawer For WooCommerce: from n/a through 4.0.0.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-385r-vgx4-4g7p

больше 4 лет назад

Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0964, CVE-2016-0965, CVE-2016-0966, CVE-2016-0967, CVE-2016-0968, CVE-2016-0969, CVE-2016-0970, CVE-2016-0976, CVE-2016-0977, CVE-2016-0978, CVE-2016-0979, CVE-2016-0980, and CVE-2016-0981.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-385r-j2f8-hqw6

около 1 месяца назад

In the Linux kernel, the following vulnerability has been resolved: mptcp: fix stale skb->sk reference on subflow close The backlog list is updated by mptcp_data_ready() under mptcp_data_lock(). The cleanup of backlog references to a closing subflow, however, was performed in mptcp_close_ssk(), before __mptcp_close_ssk() acquires the ssk lock, and while holding neither the ssk lock nor mptcp_data_lock(). Because that traversal ran without mptcp_data_lock(), concurrent softirq RX processing on another CPU (subflow_data_ready() -> mptcp_data_ready() -> __mptcp_add_backlog(), under mptcp_data_lock()) could add a backlog entry referencing the ssk while the cleanup loop was in progress. Such an entry could be missed by the cleanup, or the concurrent list update could corrupt the traversal, leaving skb->sk pointing at the ssk after it is freed. A later mptcp_backlog_purge() then dereferences the stale pointer, triggering a warning in inet_sock_destruct() (ssk->sk_rmem_alloc != 0) foll...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-385r-ghm4-jjf9

больше 4 лет назад

Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial of service (crash) via (1) creating an ASP program that uses Scripting.FileSystemObject to open a file with an MS-DOS device name, or (2) remotely injecting the device name into ASP programs that internally use Scripting.FileSystemObject.

EPSS: Высокий
github логотип

GHSA-385q-xgw2-6c6x

больше 4 лет назад

Kerio MailServer before 6.1.3 Patch 1 allows remote attackers to cause a denial of service (application crash) via a crafted IMAP LOGIN command.

EPSS: Низкий
github логотип

GHSA-385q-2f2c-f3c9

около 2 лет назад

A code injection vulnerability that allows a low-privileged user with REST API access granted to remotely upload arbitrary files to the VSPC server using REST API, leading to remote code execution on VSPC server.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-385m-wxfc-gc76

больше 4 лет назад

Heap-based buffer overflow in ColorSync in Apple Mac OS X 10.4.11 and 10.5 before 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted image containing an embedded ColorSync profile.

EPSS: Низкий
github логотип

GHSA-385m-q9q4-536h

больше 4 лет назад

An issue was discovered in Zammad before 4.1.1. An Agent account can modify account data, and gain admin access, via a crafted request.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3863-q6pp-rrcg

All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.9.19 are vulnerable to cross-site request forgery (CSRF). An external attacker with no access to the device can force the end user into submitting a "setconf" method request, not requiring any CSRF token, which can lead into denial of service on the device.

CVSS3: 7.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-3863-h4xw-2xv3

An issue was discovered in Pure-FTPd 1.0.49. An out-of-bounds (OOB) read has been detected in the pure_strcmp function in utils.c.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-3863-8rfp-v9rw

A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. Affected is the function urllib.request.urlopen of the file integrations/aws-strands/python/src/ag_ui_strands/utils.py of the component Multimodal Content. The manipulation of the argument Value results in server-side request forgery. The attack can be executed remotely. The patch is identified as bf0c34df34cbb4b1992bc37c9bfffe6dd54bb189. It is advisable to implement a patch to correct this issue.

CVSS3: 6.3
0%
Низкий
7 дней назад
github логотип
GHSA-3863-2447-669p

transformers has a Deserialization of Untrusted Data vulnerability

CVSS3: 9
1%
Низкий
почти 3 года назад
github логотип
GHSA-3862-v28r-vqw4

seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3862-j6jr-jg22

Multiple buffer overflows in the torrent parsing implementation in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allow remote attackers to execute arbitrary code via (1) a long file name within a torrent file, (2) a long tracker URL in a torrent file, or (3) a long comment in a torrent file.

28%
Средний
больше 4 лет назад
github логотип
GHSA-3862-fmr3-4f3h

Broadleaf vulnerable to Cross-site Scripting

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3862-f8g9-4ffc

Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Featured Post Creative allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Featured Post Creative: from n/a through 1.2.7.

CVSS3: 5.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-3862-c622-v4fp

Cross-site Scripting in Backdrop CMS

CVSS3: 4.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3862-5qvv-3rvv

The Floating Social Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the floating_social_buttons_option() function. This makes it possible for unauthenticated attackers to update the plugins settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 6.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-385x-88c3-c379

Azure Sphere Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-41375, CVE-2021-41376.

CVSS3: 6.7
1%
Низкий
больше 4 лет назад
github логотип
GHSA-385w-hjpp-r4cx

Exposure of resource to wrong sphere in Zoom for Windows and Zoom for MacOS clients before 5.14.10 may allow an authenticated user to potentially enable information disclosure via network access.

CVSS3: 7.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-385w-3r67-h9rr

Missing Authorization vulnerability in appsbd Mini Cart Drawer For WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mini Cart Drawer For WooCommerce: from n/a through 4.0.0.

CVSS3: 5.4
0%
Низкий
почти 2 года назад
github логотип
GHSA-385r-vgx4-4g7p

Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0964, CVE-2016-0965, CVE-2016-0966, CVE-2016-0967, CVE-2016-0968, CVE-2016-0969, CVE-2016-0970, CVE-2016-0976, CVE-2016-0977, CVE-2016-0978, CVE-2016-0979, CVE-2016-0980, and CVE-2016-0981.

CVSS3: 9.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-385r-j2f8-hqw6

In the Linux kernel, the following vulnerability has been resolved: mptcp: fix stale skb->sk reference on subflow close The backlog list is updated by mptcp_data_ready() under mptcp_data_lock(). The cleanup of backlog references to a closing subflow, however, was performed in mptcp_close_ssk(), before __mptcp_close_ssk() acquires the ssk lock, and while holding neither the ssk lock nor mptcp_data_lock(). Because that traversal ran without mptcp_data_lock(), concurrent softirq RX processing on another CPU (subflow_data_ready() -> mptcp_data_ready() -> __mptcp_add_backlog(), under mptcp_data_lock()) could add a backlog entry referencing the ssk while the cleanup loop was in progress. Such an entry could be missed by the cleanup, or the concurrent list update could corrupt the traversal, leaving skb->sk pointing at the ssk after it is freed. A later mptcp_backlog_purge() then dereferences the stale pointer, triggering a warning in inet_sock_destruct() (ssk->sk_rmem_alloc != 0) foll...

CVSS3: 9.8
1%
Низкий
около 1 месяца назад
github логотип
GHSA-385r-ghm4-jjf9

Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial of service (crash) via (1) creating an ASP program that uses Scripting.FileSystemObject to open a file with an MS-DOS device name, or (2) remotely injecting the device name into ASP programs that internally use Scripting.FileSystemObject.

71%
Высокий
больше 4 лет назад
github логотип
GHSA-385q-xgw2-6c6x

Kerio MailServer before 6.1.3 Patch 1 allows remote attackers to cause a denial of service (application crash) via a crafted IMAP LOGIN command.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-385q-2f2c-f3c9

A code injection vulnerability that allows a low-privileged user with REST API access granted to remotely upload arbitrary files to the VSPC server using REST API, leading to remote code execution on VSPC server.

CVSS3: 8.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-385m-wxfc-gc76

Heap-based buffer overflow in ColorSync in Apple Mac OS X 10.4.11 and 10.5 before 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted image containing an embedded ColorSync profile.

8%
Низкий
больше 4 лет назад
github логотип
GHSA-385m-q9q4-536h

An issue was discovered in Zammad before 4.1.1. An Agent account can modify account data, and gain admin access, via a crafted request.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу