Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 453

Количество 375 453

github логотип

GHSA-37h2-23m8-m8pm

больше 4 лет назад

An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute code via a crafted WMF file with a manipulated WMF header size, possibly involving an integer overflow, a different vulnerability than CVE-2005-4560, and aka "WMF Image Parsing Memory Corruption Vulnerability."

EPSS: Средний
github логотип

GHSA-37gx-xxp4-5rgx

5 месяцев назад

Microsoft Security Advisory CVE-2026-33116 – .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-37gx-w2pf-9hpp

26 дней назад

When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads, concurrent requests on the same FluxMessageChannel subscription have their reply headers (replyChannel, errorChannel, correlationId, any propagated security/tenant headers) copied from whichever message was most recently consumed upstream. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 Spring Integration 5.5.21 and earlier

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-37gx-jqx9-fwmg

больше 2 лет назад

Improper Certificate Validation in Apache DolphinScheduler

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-37gx-37xg-963j

почти 2 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in HK Digital Agency LLC TAX SERVICE Electronic HDM allows SQL Injection.This issue affects TAX SERVICE Electronic HDM: from n/a through 1.1.2.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-37gw-25xx-74f7

больше 2 лет назад

Windows Kerberos Security Feature Bypass Vulnerability

CVSS3: 9
EPSS: Средний
github логотип

GHSA-37gv-w6h3-7hm7

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: Fix MAC comparison to be constant-time To prevent timing attacks, MACs need to be compared in constant time. Use the appropriate helper function for this.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-37gv-mrx7-gfqg

больше 4 лет назад

The LAN-side Web-Configuration Interface has Stack-based Buffer Overflow vulnerability in the D-Link Wi-Fi router firmware DIR-890L DIR890LA1_FW107b09.bin and previous versions. The function created at 0x17958 of /htdocs/cgibin will call sprintf without checking the length of strings in parameters given by HTTP header and can be controlled by users easily. The attackers can exploit the vulnerability to carry out arbitrary code by means of sending a specially constructed payload to port 49152.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-37gv-9q37-8946

почти 3 года назад

An out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32_fpu function of libr/arch/p/nds32/nds32-dis.h.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-37gr-95fp-3q54

больше 4 лет назад

Kerio Personal Firewall 4.0 (KPF4) allows local users with administrative privileges to bypass the Application Security feature and execute arbitrary processes by directly writing to \device\physicalmemory to restore the running kernel's SDT ServiceTable.

EPSS: Низкий
github логотип

GHSA-37gr-7cxx-ccpq

почти 3 года назад

Docker Desktop before 4.23.0 allows Access Token theft via a crafted extension icon URL. This issue affects Docker Desktop: before 4.23.0.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-37gq-89mf-f5ph

больше 4 лет назад

Stack-based buffer overflow in a certain ActiveX control in GLChat.ocx 2.5.1.32 in GlobalLink 2.7.0.8, as used in Ourgame GLWorld and possibly other products, allows remote attackers to execute arbitrary code via a long first argument to the ConnectAndEnterRoom method, possibly involving the GLCHAT.GLChatCtrl.1 control, as originally exploited in the wild in October 2007. NOTE: some of these details are obtained from third party information. NOTE: this was originally reported as a heap-based issue by some sources.

EPSS: Средний
github логотип

GHSA-37gq-4hg5-cxqj

почти 3 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Arul Prasad J Publish Confirm Message plugin <= 1.3.1 versions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-37gp-666w-35h8

больше 4 лет назад

Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a remote attacker with network-operator privileges to conduct a cross-site scripting (XSS) attack or a reflected file download (RFD) attack against a user of the interface. For more information about these vulnerabilities, see the Details section of this advisory.

EPSS: Низкий
github логотип

GHSA-37gm-h5wr-pf25

почти 2 года назад

Path traversal in redaxo

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-37gm-gwpm-x7vh

больше 4 лет назад

Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to view arbitrary files that contain the "{" character via script containing the cssText property of the stylesheet object, aka "Local Information Disclosure through HTML Object" vulnerability.

EPSS: Средний
github логотип

GHSA-37gj-jhr2-v5wv

больше 4 лет назад

IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to External Service Interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-side DNS lookups or HTTP requests to arbitrary domain names. By submitting suitable payloads, an attacker can cause the application server to attack other systems that it can interact with. IBM X-Force ID: 119516.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-37gh-rp4q-r94c

13 дней назад

UI misrepresentation in UrlFormatting in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof address bar via a crafted domain name. (Chromium security severity: Medium)

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-37gh-h6xp-rvc2

8 месяцев назад

A flaw has been found in D-Link DWR-M921 1.1.50. This affects the function sub_419920 of the file /boafrm/formLtefotaUpgradeQuectel. This manipulation of the argument fota_url causes command injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-37gh-342p-m59x

почти 3 года назад

Free broadcast vulnerability in the running management module. Successful exploitation of this vulnerability may affect service confidentiality.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-37h2-23m8-m8pm

An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute code via a crafted WMF file with a manipulated WMF header size, possibly involving an integer overflow, a different vulnerability than CVE-2005-4560, and aka "WMF Image Parsing Memory Corruption Vulnerability."

19%
Средний
больше 4 лет назад
github логотип
GHSA-37gx-xxp4-5rgx

Microsoft Security Advisory CVE-2026-33116 – .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability

CVSS3: 7.5
2%
Низкий
5 месяцев назад
github логотип
GHSA-37gx-w2pf-9hpp

When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads, concurrent requests on the same FluxMessageChannel subscription have their reply headers (replyChannel, errorChannel, correlationId, any propagated security/tenant headers) copied from whichever message was most recently consumed upstream. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 Spring Integration 5.5.21 and earlier

CVSS3: 8.2
0%
Низкий
26 дней назад
github логотип
GHSA-37gx-jqx9-fwmg

Improper Certificate Validation in Apache DolphinScheduler

CVSS3: 7.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-37gx-37xg-963j

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in HK Digital Agency LLC TAX SERVICE Electronic HDM allows SQL Injection.This issue affects TAX SERVICE Electronic HDM: from n/a through 1.1.2.

CVSS3: 10
1%
Низкий
почти 2 года назад
github логотип
GHSA-37gw-25xx-74f7

Windows Kerberos Security Feature Bypass Vulnerability

CVSS3: 9
17%
Средний
больше 2 лет назад
github логотип
GHSA-37gv-w6h3-7hm7

In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: Fix MAC comparison to be constant-time To prevent timing attacks, MACs need to be compared in constant time. Use the appropriate helper function for this.

CVSS3: 7
0%
Низкий
около 1 года назад
github логотип
GHSA-37gv-mrx7-gfqg

The LAN-side Web-Configuration Interface has Stack-based Buffer Overflow vulnerability in the D-Link Wi-Fi router firmware DIR-890L DIR890LA1_FW107b09.bin and previous versions. The function created at 0x17958 of /htdocs/cgibin will call sprintf without checking the length of strings in parameters given by HTTP header and can be controlled by users easily. The attackers can exploit the vulnerability to carry out arbitrary code by means of sending a specially constructed payload to port 49152.

CVSS3: 9.8
15%
Средний
больше 4 лет назад
github логотип
GHSA-37gv-9q37-8946

An out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32_fpu function of libr/arch/p/nds32/nds32-dis.h.

CVSS3: 9.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-37gr-95fp-3q54

Kerio Personal Firewall 4.0 (KPF4) allows local users with administrative privileges to bypass the Application Security feature and execute arbitrary processes by directly writing to \device\physicalmemory to restore the running kernel's SDT ServiceTable.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-37gr-7cxx-ccpq

Docker Desktop before 4.23.0 allows Access Token theft via a crafted extension icon URL. This issue affects Docker Desktop: before 4.23.0.

CVSS3: 8
1%
Низкий
почти 3 года назад
github логотип
GHSA-37gq-89mf-f5ph

Stack-based buffer overflow in a certain ActiveX control in GLChat.ocx 2.5.1.32 in GlobalLink 2.7.0.8, as used in Ourgame GLWorld and possibly other products, allows remote attackers to execute arbitrary code via a long first argument to the ConnectAndEnterRoom method, possibly involving the GLCHAT.GLChatCtrl.1 control, as originally exploited in the wild in October 2007. NOTE: some of these details are obtained from third party information. NOTE: this was originally reported as a heap-based issue by some sources.

12%
Средний
больше 4 лет назад
github логотип
GHSA-37gq-4hg5-cxqj

Cross-Site Request Forgery (CSRF) vulnerability in Arul Prasad J Publish Confirm Message plugin <= 1.3.1 versions.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-37gp-666w-35h8

Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a remote attacker with network-operator privileges to conduct a cross-site scripting (XSS) attack or a reflected file download (RFD) attack against a user of the interface. For more information about these vulnerabilities, see the Details section of this advisory.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-37gm-h5wr-pf25

Path traversal in redaxo

CVSS3: 4.9
1%
Низкий
почти 2 года назад
github логотип
GHSA-37gm-gwpm-x7vh

Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to view arbitrary files that contain the "{" character via script containing the cssText property of the stylesheet object, aka "Local Information Disclosure through HTML Object" vulnerability.

29%
Средний
больше 4 лет назад
github логотип
GHSA-37gj-jhr2-v5wv

IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to External Service Interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-side DNS lookups or HTTP requests to arbitrary domain names. By submitting suitable payloads, an attacker can cause the application server to attack other systems that it can interact with. IBM X-Force ID: 119516.

CVSS3: 8.6
2%
Низкий
больше 4 лет назад
github логотип
GHSA-37gh-rp4q-r94c

UI misrepresentation in UrlFormatting in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof address bar via a crafted domain name. (Chromium security severity: Medium)

CVSS3: 4.3
0%
Низкий
13 дней назад
github логотип
GHSA-37gh-h6xp-rvc2

A flaw has been found in D-Link DWR-M921 1.1.50. This affects the function sub_419920 of the file /boafrm/formLtefotaUpgradeQuectel. This manipulation of the argument fota_url causes command injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.

CVSS3: 6.3
3%
Низкий
8 месяцев назад
github логотип
GHSA-37gh-342p-m59x

Free broadcast vulnerability in the running management module. Successful exploitation of this vulnerability may affect service confidentiality.

CVSS3: 7.5
0%
Низкий
почти 3 года назад

Уязвимостей на страницу