Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 453

Количество 375 453

github логотип

GHSA-37j4-mqr6-6m6x

больше 1 года назад

HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack, due to a potentially weak validation of an API parameter.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-37j4-jj4f-rgwh

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in index.php in NewsPHP allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter. NOTE: this issue might overlap vector 3 in CVE-2006-3358.

EPSS: Низкий
github логотип

GHSA-37j4-88rp-2f6h

5 месяцев назад

Electerm's full process.env exposed to renderer via window.pre.env

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-37j4-5858-49mq

4 месяца назад

A vulnerability was found in j3k0 mcp-google-workspace up to 831790e7d5c2663325733d9f5579cc339a267c4c. This issue affects the function saveToDisk of the file src/tools/gmail.ts of the component MCP Gmail Tool. Performing a manipulation results in improper access controls. It is possible to initiate the attack remotely. The exploit has been made public and could be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The patch is named 89c091ecf8b9f9c7291d1af0b1966e271f86551c. It is suggested to install a patch to address this issue.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-37j3-8x65-gx72

больше 4 лет назад

Stack-based buffer overflow in ndiiop.exe in the DIIOP implementation in the server in IBM Lotus Domino before 8.5.3 allows remote attackers to execute arbitrary code via a GIOP getEnvironmentString request, related to the local variable cache.

EPSS: Низкий
github логотип

GHSA-37j2-wpv7-2cfq

3 месяца назад

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-37j2-h4x2-rp3v

больше 2 лет назад

Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted requests.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-37j2-87p9-cj66

больше 4 лет назад

Vulnerability in the Oracle Integrated Lights Out Manager (ILOM) component of Oracle Sun Systems Products Suite (subcomponent: System Management). The supported version that is affected is Prior to 3.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Integrated Lights Out Manager (ILOM). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Integrated Lights Out Manager (ILOM) accessible data as well as unauthorized read access to a subset of Oracle Integrated Lights Out Manager (ILOM) accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Integrated Lights Out Manager (ILOM). CVSS 3.0 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-37j2-4mf7-p7r4

больше 4 лет назад

Unspecified vulnerability on the La Fonera+ router with firmware before 1.7.0.1 allows remote attackers to cause a denial of service via unknown vectors.

EPSS: Низкий
github логотип

GHSA-37j2-3vv8-cf24

4 месяца назад

Mattermost doesn't validate the TIFF IFD offset in the image header before allocating memory

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-37hx-vm8w-5g3h

7 месяцев назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

EPSS: Низкий
github логотип

GHSA-37hx-9chj-hc3m

около 1 месяца назад

A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This script gains access to sensitive credentials, such as GitHub access tokens and registry passwords, used in the build environment. A remote attacker could exploit this vulnerability to inject malicious code, leading to unauthorized access to build resources and potential compromise of the resulting operator bundle.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-37hx-4mcq-wc3h

почти 5 лет назад

Weak Password Recovery Mechanism for Forgotten Password in Strapi

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-37hw-m3rc-6ww4

больше 4 лет назад

A memory leak in the unittest_data_add() function in drivers/of/unittest.c in the Linux kernel before 5.3.10 allows attackers to cause a denial of service (memory consumption) by triggering of_fdt_unflatten_tree() failures, aka CID-e13de8fe0d6a.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-37hw-37wh-562h

больше 4 лет назад

In Snowtide PDFxStream before 3.7.1 (for Java), a crafted PDF file can trigger an extremely long running computation because of page-tree mishandling.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-37hv-5w7w-hhjw

больше 4 лет назад

A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest and may result in a crash of QEMU or cause undefined behavior due to the access of an uninitialized pointer. The highest threat from this vulnerability is to system availability.

CVSS3: 6
EPSS: Низкий
github логотип

GHSA-37hv-4cjv-mxqq

больше 4 лет назад

Windows Kernel Memory Information Disclosure Vulnerability

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-37hr-rhw9-q43g

больше 4 лет назад

Format string vulnerability in TrACESroute 6.0 GOLD (aka NANOG traceroute) allows local users to execute arbitrary code via the -T (terminator) command line argument.

EPSS: Низкий
github логотип

GHSA-37hr-r96j-6hcx

около 3 лет назад

A vulnerability, which was classified as problematic, was found in Creativeitem Ekushey Project Manager CRM 5.0. Affected is an unknown function of the file /index.php/client/message/message_read/xxxxxxxx[random-msg-hash]. The manipulation of the argument message leads to cross site scripting. It is possible to launch the attack remotely. VDB-234426 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-37hr-898c-hc2f

больше 4 лет назад

A vulnerability has been identified in SiNVR 3 Central Control Server (CCS) (all versions), SiNVR 3 Video Server (all versions). The streaming service (default port 5410/tcp) of the SiNVR 3 Video Server contains a path traversal vulnerability, that could allow an unauthenticated remote attacker to access and download arbitrary files from the server.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-37j4-mqr6-6m6x

HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack, due to a potentially weak validation of an API parameter.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-37j4-jj4f-rgwh

Cross-site scripting (XSS) vulnerability in index.php in NewsPHP allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter. NOTE: this issue might overlap vector 3 in CVE-2006-3358.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-37j4-88rp-2f6h

Electerm's full process.env exposed to renderer via window.pre.env

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-37j4-5858-49mq

A vulnerability was found in j3k0 mcp-google-workspace up to 831790e7d5c2663325733d9f5579cc339a267c4c. This issue affects the function saveToDisk of the file src/tools/gmail.ts of the component MCP Gmail Tool. Performing a manipulation results in improper access controls. It is possible to initiate the attack remotely. The exploit has been made public and could be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The patch is named 89c091ecf8b9f9c7291d1af0b1966e271f86551c. It is suggested to install a patch to address this issue.

CVSS3: 6.3
0%
Низкий
4 месяца назад
github логотип
GHSA-37j3-8x65-gx72

Stack-based buffer overflow in ndiiop.exe in the DIIOP implementation in the server in IBM Lotus Domino before 8.5.3 allows remote attackers to execute arbitrary code via a GIOP getEnvironmentString request, related to the local variable cache.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-37j2-wpv7-2cfq

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 9.8
0%
Низкий
3 месяца назад
github логотип
GHSA-37j2-h4x2-rp3v

Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted requests.

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-37j2-87p9-cj66

Vulnerability in the Oracle Integrated Lights Out Manager (ILOM) component of Oracle Sun Systems Products Suite (subcomponent: System Management). The supported version that is affected is Prior to 3.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Integrated Lights Out Manager (ILOM). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Integrated Lights Out Manager (ILOM) accessible data as well as unauthorized read access to a subset of Oracle Integrated Lights Out Manager (ILOM) accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Integrated Lights Out Manager (ILOM). CVSS 3.0 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).

CVSS3: 7.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-37j2-4mf7-p7r4

Unspecified vulnerability on the La Fonera+ router with firmware before 1.7.0.1 allows remote attackers to cause a denial of service via unknown vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-37j2-3vv8-cf24

Mattermost doesn't validate the TIFF IFD offset in the image header before allocating memory

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-37hx-vm8w-5g3h

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

7 месяцев назад
github логотип
GHSA-37hx-9chj-hc3m

A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This script gains access to sensitive credentials, such as GitHub access tokens and registry passwords, used in the build environment. A remote attacker could exploit this vulnerability to inject malicious code, leading to unauthorized access to build resources and potential compromise of the resulting operator bundle.

CVSS3: 8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-37hx-4mcq-wc3h

Weak Password Recovery Mechanism for Forgotten Password in Strapi

CVSS3: 8.1
1%
Низкий
почти 5 лет назад
github логотип
GHSA-37hw-m3rc-6ww4

A memory leak in the unittest_data_add() function in drivers/of/unittest.c in the Linux kernel before 5.3.10 allows attackers to cause a denial of service (memory consumption) by triggering of_fdt_unflatten_tree() failures, aka CID-e13de8fe0d6a.

CVSS3: 7.5
4%
Низкий
больше 4 лет назад
github логотип
GHSA-37hw-37wh-562h

In Snowtide PDFxStream before 3.7.1 (for Java), a crafted PDF file can trigger an extremely long running computation because of page-tree mishandling.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-37hv-5w7w-hhjw

A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest and may result in a crash of QEMU or cause undefined behavior due to the access of an uninitialized pointer. The highest threat from this vulnerability is to system availability.

CVSS3: 6
0%
Низкий
больше 4 лет назад
github логотип
GHSA-37hv-4cjv-mxqq

Windows Kernel Memory Information Disclosure Vulnerability

CVSS3: 6.3
3%
Низкий
больше 4 лет назад
github логотип
GHSA-37hr-rhw9-q43g

Format string vulnerability in TrACESroute 6.0 GOLD (aka NANOG traceroute) allows local users to execute arbitrary code via the -T (terminator) command line argument.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-37hr-r96j-6hcx

A vulnerability, which was classified as problematic, was found in Creativeitem Ekushey Project Manager CRM 5.0. Affected is an unknown function of the file /index.php/client/message/message_read/xxxxxxxx[random-msg-hash]. The manipulation of the argument message leads to cross site scripting. It is possible to launch the attack remotely. VDB-234426 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-37hr-898c-hc2f

A vulnerability has been identified in SiNVR 3 Central Control Server (CCS) (all versions), SiNVR 3 Video Server (all versions). The streaming service (default port 5410/tcp) of the SiNVR 3 Video Server contains a path traversal vulnerability, that could allow an unauthenticated remote attacker to access and download arbitrary files from the server.

CVSS3: 7.5
3%
Низкий
больше 4 лет назад

Уязвимостей на страницу