Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 453

Количество 375 453

github логотип

GHSA-37fm-8p76-8ch8

больше 4 лет назад

SQL injection vulnerability in BasiliX Webmail 1.10 allows remote attackers to obtain sensitive information or possibly modify data via the id variable.

EPSS: Низкий
github логотип

GHSA-37fm-24w3-h7fh

больше 4 лет назад

The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An unauthenticated attacker can exploit the vulnerabilities to gain root privileges by sending some messages with malicious commands.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-37fj-53xc-q7rr

около 3 лет назад

In vowifi service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-37fj-538x-3px9

2 месяца назад

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-37fh-v665-q95p

больше 4 лет назад

2z project 0.9.6.1 allows attackers to change the password without supplying the old password.

EPSS: Низкий
github логотип

GHSA-37fh-f35c-r73m

4 месяца назад

DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags. DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from untrusted sources. The format_event method (used by the event method) does not validate the content of the tags, which may contain commas (allowing tags to be injected) or newlines, pipes and colons that allow metric injections. (There is an ineffective s/|//g to remove pipes, but because the pipe is not escaped, it is interpreted as a regular expression metacharacter and has no effect.)

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-37ff-x2xh-cxcr

больше 4 лет назад

Presence of a .htaccess file could leak information in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before SP2.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-37ff-whmf-mj2q

около 3 лет назад

A vulnerability was found in SourceCodester Contact Manager App 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file add.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-239353 was assigned to this vulnerability.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-37ff-c5mh-pmpm

больше 4 лет назад

A logic issue in the firmware of the Intel(R) Ethernet 700 Series Controllers may allow a privileged user to potentially enable escalation of privilege and/or denial of service via local access.

EPSS: Низкий
github логотип

GHSA-37fc-xjq7-ff6p

около 3 лет назад

The setMediaSource function on the amzn.thin.pl service does not sanitize the "source" parameter allowing for arbitrary javascript code to be run This issue affects: Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5. Insignia TV with FireOS versions prior to 7.6.3.3.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-37fc-f69r-mp86

9 месяцев назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-37fc-9fm9-7mh2

больше 2 лет назад

Weak access control in OpenText PVCS Version Manager allows potential bypassing of authentication and uploading of files.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-37fc-4qqv-26w3

больше 4 лет назад

CRLF injection vulnerability in Yealink VoIP Phones with firmware 28.72.0.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the model parameter to servlet.

EPSS: Низкий
github логотип

GHSA-37fc-3j87-m624

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: jffs2: check that raw node were preallocated before writing summary Syzkaller detected a kernel bug in jffs2_link_node_ref, caused by fault injection in jffs2_prealloc_raw_node_refs. jffs2_sum_write_sumnode doesn't check return value of jffs2_prealloc_raw_node_refs and simply lets any error propagate into jffs2_sum_write_data, which eventually calls jffs2_link_node_ref in order to link the summary to an expectedly allocated node. kernel BUG at fs/jffs2/nodelist.c:592! invalid opcode: 0000 [#1] PREEMPT SMP KASAN NOPTI CPU: 1 PID: 31277 Comm: syz-executor.7 Not tainted 6.1.128-syzkaller-00139-ge10f83ca10a1 #0 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1 04/01/2014 RIP: 0010:jffs2_link_node_ref+0x570/0x690 fs/jffs2/nodelist.c:592 Call Trace: <TASK> jffs2_sum_write_data fs/jffs2/summary.c:841 [inline] jffs2_sum_write_sumnode+0xd1a/0x1da0 fs/jffs2/summary.c:874 jffs2_do_reserve_space+0xa18/...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-37f8-3cvh-9hjg

больше 4 лет назад

Multiple SQL injection vulnerabilities in index.php in Katalog Plyt Audio 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) fraza and (2) litera parameters, different vectors than CVE-2007-1612. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-37f7-6x64-w46m

около 1 месяца назад

In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: reacquire gw address after skb realloc The pskb_may_pull() called by batadv_bla_is_backbone_gw() could reallocate the buffer behind the skb. Variables which were pointing to the old buffer need to be reassigned to avoid an use-after-free.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-37f6-vjg7-8c6c

больше 1 года назад

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-37f6-m354-672c

больше 4 лет назад

The UsersWP WordPress plugin before 1.2.3.1 is missing access controls when updating a user avatar, and does not make sure file names for user avatars are unique, allowing a logged in user to overwrite another users avatar.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-37f6-2x94-2r9p

больше 4 лет назад

Format string vulnerability in VMware Workstation 4.5.2 build-8848, if running with elevated privileges, might allow local users to execute arbitrary code via format string specifiers in command line arguments. NOTE: it is not clear if there are any default or typical circumstances under which VMware would be running with privileges beyond those already available to the attackers, so this might not be a vulnerability.

EPSS: Низкий
github логотип

GHSA-37f5-m753-pjhv

больше 4 лет назад

Heap-based buffer overflow in SuiteLink server while processing commands 0x05/0x06

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-37fm-8p76-8ch8

SQL injection vulnerability in BasiliX Webmail 1.10 allows remote attackers to obtain sensitive information or possibly modify data via the id variable.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-37fm-24w3-h7fh

The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An unauthenticated attacker can exploit the vulnerabilities to gain root privileges by sending some messages with malicious commands.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-37fj-53xc-q7rr

In vowifi service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges

CVSS3: 5.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-37fj-538x-3px9

ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.

CVSS3: 6.8
0%
Низкий
2 месяца назад
github логотип
GHSA-37fh-v665-q95p

2z project 0.9.6.1 allows attackers to change the password without supplying the old password.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-37fh-f35c-r73m

DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags. DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from untrusted sources. The format_event method (used by the event method) does not validate the content of the tags, which may contain commas (allowing tags to be injected) or newlines, pipes and colons that allow metric injections. (There is an ineffective s/|//g to remove pipes, but because the pipe is not escaped, it is interpreted as a regular expression metacharacter and has no effect.)

CVSS3: 9.8
0%
Низкий
4 месяца назад
github логотип
GHSA-37ff-x2xh-cxcr

Presence of a .htaccess file could leak information in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before SP2.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-37ff-whmf-mj2q

A vulnerability was found in SourceCodester Contact Manager App 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file add.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-239353 was assigned to this vulnerability.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-37ff-c5mh-pmpm

A logic issue in the firmware of the Intel(R) Ethernet 700 Series Controllers may allow a privileged user to potentially enable escalation of privilege and/or denial of service via local access.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-37fc-xjq7-ff6p

The setMediaSource function on the amzn.thin.pl service does not sanitize the "source" parameter allowing for arbitrary javascript code to be run This issue affects: Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5. Insignia TV with FireOS versions prior to 7.6.3.3.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-37fc-f69r-mp86

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

9 месяцев назад
github логотип
GHSA-37fc-9fm9-7mh2

Weak access control in OpenText PVCS Version Manager allows potential bypassing of authentication and uploading of files.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-37fc-4qqv-26w3

CRLF injection vulnerability in Yealink VoIP Phones with firmware 28.72.0.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the model parameter to servlet.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-37fc-3j87-m624

In the Linux kernel, the following vulnerability has been resolved: jffs2: check that raw node were preallocated before writing summary Syzkaller detected a kernel bug in jffs2_link_node_ref, caused by fault injection in jffs2_prealloc_raw_node_refs. jffs2_sum_write_sumnode doesn't check return value of jffs2_prealloc_raw_node_refs and simply lets any error propagate into jffs2_sum_write_data, which eventually calls jffs2_link_node_ref in order to link the summary to an expectedly allocated node. kernel BUG at fs/jffs2/nodelist.c:592! invalid opcode: 0000 [#1] PREEMPT SMP KASAN NOPTI CPU: 1 PID: 31277 Comm: syz-executor.7 Not tainted 6.1.128-syzkaller-00139-ge10f83ca10a1 #0 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1 04/01/2014 RIP: 0010:jffs2_link_node_ref+0x570/0x690 fs/jffs2/nodelist.c:592 Call Trace: <TASK> jffs2_sum_write_data fs/jffs2/summary.c:841 [inline] jffs2_sum_write_sumnode+0xd1a/0x1da0 fs/jffs2/summary.c:874 jffs2_do_reserve_space+0xa18/...

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-37f8-3cvh-9hjg

Multiple SQL injection vulnerabilities in index.php in Katalog Plyt Audio 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) fraza and (2) litera parameters, different vectors than CVE-2007-1612. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-37f7-6x64-w46m

In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: reacquire gw address after skb realloc The pskb_may_pull() called by batadv_bla_is_backbone_gw() could reallocate the buffer behind the skb. Variables which were pointing to the old buffer need to be reassigned to avoid an use-after-free.

CVSS3: 8.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-37f6-vjg7-8c6c

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process.

CVSS3: 7.1
2%
Низкий
больше 1 года назад
github логотип
GHSA-37f6-m354-672c

The UsersWP WordPress plugin before 1.2.3.1 is missing access controls when updating a user avatar, and does not make sure file names for user avatars are unique, allowing a logged in user to overwrite another users avatar.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-37f6-2x94-2r9p

Format string vulnerability in VMware Workstation 4.5.2 build-8848, if running with elevated privileges, might allow local users to execute arbitrary code via format string specifiers in command line arguments. NOTE: it is not clear if there are any default or typical circumstances under which VMware would be running with privileges beyond those already available to the attackers, so this might not be a vulnerability.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-37f5-m753-pjhv

Heap-based buffer overflow in SuiteLink server while processing commands 0x05/0x06

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу