Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 269

Количество 353 269

github логотип

GHSA-23qf-p445-3vhr

около 4 лет назад

An inclusion of sensitive information in log files vulnerability is present in Hickory Smart for Android mobile devices from Belwith Products, LLC. Communications to the internet API services and direct connections to the lock via Bluetooth Low Energy (BLE) from the mobile application are logged in a debug log on the Android device at HickorySmartLog/Logs/SRDeviceLog.txt. This information was found stored in the Android device's default USB or SDcard storage paths and is accessible without rooting the device. This issue affects Hickory Smart for Android, version 01.01.43 and prior versions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-23qf-mx2g-p3gq

больше 2 лет назад

An information disclosure vulnerability exists in the challenge functionality of instipod DuoUniversalKeycloakAuthenticator 1.0.7 plugin. A specially crafted HTTP request can lead to a disclosure of sensitive information. An user login to Keycloak using DuoUniversalKeycloakAuthenticator plugin triggers this vulnerability.

CVSS3: 4.5
EPSS: Низкий
github логотип

GHSA-23qf-cvxj-h26r

7 месяцев назад

An insecure authentication mechanism in the safe_exec.sh startup script of Blurams Flare Camera version 24.1114.151.929 and earlier allows an attacker with physical access to the device to execute arbitrary commands with root privileges, if file /opt/images/public_key.der is not present in the file system. The vulnerability can be triggered by providing a maliciously crafted auth.ini file on the device's SD card.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-23qf-8c5g-2ccx

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryo Arkhe Blocks allows Stored XSS. This issue affects Arkhe Blocks: from n/a through 2.27.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-23qf-3jf9-h3q9

почти 3 года назад

Apache NiFi Insufficient Property Validation vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-23qc-j7fh-79jg

около 4 лет назад

IBM Security Verify Access Docker 10.0.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID:198918

EPSS: Низкий
github логотип

GHSA-23qc-j55g-qfm7

около 4 лет назад

The (1) SAPDatabase and (2) SAPInstance scripts in OCF Resource Agents (aka resource-agents or cluster-agents) 1.0.3 in Linux-HA place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

EPSS: Низкий
github логотип

GHSA-23qc-7hjx-vwmv

почти 2 года назад

A lack of code signature verification in Parallels Desktop for Mac v19.3.0 and below allows attackers to escalate privileges via a crafted macOS installer, because Parallels Service is setuid root.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-23q9-v5c2-xg7m

около 4 лет назад

PHP remote file inclusion vulnerability in content.php in phpGreetz 0.99 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the content parameter.

EPSS: Низкий
github логотип

GHSA-23q7-9vq5-jc43

почти 2 года назад

Heap-based Buffer Overflow vulnerability in Samsung Open Source Escargot JavaScript engine allows Overflow Buffers.This issue affects Escargot: 4.0.0.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-23q7-59jj-2pj4

около 4 лет назад

SEOmatic for CraftCMS allows Server-Side Template Injection

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-23q7-3w4q-p4fg

около 4 лет назад

The wikifaces package in PyPI v1.0 included a code execution backdoor inserted by a third party.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-23q6-wpc7-6vv9

около 2 лет назад

Cross-site scripting vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script on the web browser of the user who is logging in to the product.

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-23q6-mcrh-4x5m

около 4 лет назад

An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "8 of 9. Out of Bounds read and write."

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-23q6-8qm4-482q

около 4 лет назад

Digital Guardian Management Console 7.1.2.0015 has an XXE issue.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-23q5-m4p6-fg53

больше 3 лет назад

In cs40l2x_cp_trigger_queue_show of cs40l2x.c, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-224000736References: N/A

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-23q5-hv3c-8qvj

больше 3 лет назад

Improper input validation in BIOS firmware for some Intel(R) NUC Boards, Intel(R) NUC Kits before version TY0070 may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-23q5-53ph-6386

около 4 лет назад

Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 do not properly iterate through the characters in a text run, which allows remote attackers to execute arbitrary code via a crafted document.

EPSS: Низкий
github логотип

GHSA-23q4-mv34-qff2

почти 4 года назад

A privilege escalation vulnerability was discovered in Avaya IP Office Admin Lite and USB Creator that may potentially allow a local user to escalate privileges. This issue affects Admin Lite and USB Creator 11.1 Feature Pack 2 Service Pack 1 and earlier versions.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-23q4-7p25-c68g

около 4 лет назад

Use after free issue in kernel while accessing freed mdlog session info and its attributes after closing the session in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS405, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 636, SD 675, SD 730, SD 820, SD 820A, SD 835, SD 855, SDA660, SDM630, SDM660, SDX20, SDX24

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-23qf-p445-3vhr

An inclusion of sensitive information in log files vulnerability is present in Hickory Smart for Android mobile devices from Belwith Products, LLC. Communications to the internet API services and direct connections to the lock via Bluetooth Low Energy (BLE) from the mobile application are logged in a debug log on the Android device at HickorySmartLog/Logs/SRDeviceLog.txt. This information was found stored in the Android device's default USB or SDcard storage paths and is accessible without rooting the device. This issue affects Hickory Smart for Android, version 01.01.43 and prior versions.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-23qf-mx2g-p3gq

An information disclosure vulnerability exists in the challenge functionality of instipod DuoUniversalKeycloakAuthenticator 1.0.7 plugin. A specially crafted HTTP request can lead to a disclosure of sensitive information. An user login to Keycloak using DuoUniversalKeycloakAuthenticator plugin triggers this vulnerability.

CVSS3: 4.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-23qf-cvxj-h26r

An insecure authentication mechanism in the safe_exec.sh startup script of Blurams Flare Camera version 24.1114.151.929 and earlier allows an attacker with physical access to the device to execute arbitrary commands with root privileges, if file /opt/images/public_key.der is not present in the file system. The vulnerability can be triggered by providing a maliciously crafted auth.ini file on the device's SD card.

CVSS3: 8.4
0%
Низкий
7 месяцев назад
github логотип
GHSA-23qf-8c5g-2ccx

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryo Arkhe Blocks allows Stored XSS. This issue affects Arkhe Blocks: from n/a through 2.27.1.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-23qf-3jf9-h3q9

Apache NiFi Insufficient Property Validation vulnerability

CVSS3: 6.5
2%
Низкий
почти 3 года назад
github логотип
GHSA-23qc-j7fh-79jg

IBM Security Verify Access Docker 10.0.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID:198918

1%
Низкий
около 4 лет назад
github логотип
GHSA-23qc-j55g-qfm7

The (1) SAPDatabase and (2) SAPInstance scripts in OCF Resource Agents (aka resource-agents or cluster-agents) 1.0.3 in Linux-HA place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

0%
Низкий
около 4 лет назад
github логотип
GHSA-23qc-7hjx-vwmv

A lack of code signature verification in Parallels Desktop for Mac v19.3.0 and below allows attackers to escalate privileges via a crafted macOS installer, because Parallels Service is setuid root.

CVSS3: 9.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-23q9-v5c2-xg7m

PHP remote file inclusion vulnerability in content.php in phpGreetz 0.99 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the content parameter.

3%
Низкий
около 4 лет назад
github логотип
GHSA-23q7-9vq5-jc43

Heap-based Buffer Overflow vulnerability in Samsung Open Source Escargot JavaScript engine allows Overflow Buffers.This issue affects Escargot: 4.0.0.

CVSS3: 9.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-23q7-59jj-2pj4

SEOmatic for CraftCMS allows Server-Side Template Injection

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-23q7-3w4q-p4fg

The wikifaces package in PyPI v1.0 included a code execution backdoor inserted by a third party.

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-23q6-wpc7-6vv9

Cross-site scripting vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script on the web browser of the user who is logging in to the product.

CVSS3: 9
1%
Низкий
около 2 лет назад
github логотип
GHSA-23q6-mcrh-4x5m

An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "8 of 9. Out of Bounds read and write."

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-23q6-8qm4-482q

Digital Guardian Management Console 7.1.2.0015 has an XXE issue.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-23q5-m4p6-fg53

In cs40l2x_cp_trigger_queue_show of cs40l2x.c, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-224000736References: N/A

CVSS3: 6.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-23q5-hv3c-8qvj

Improper input validation in BIOS firmware for some Intel(R) NUC Boards, Intel(R) NUC Kits before version TY0070 may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS3: 6.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-23q5-53ph-6386

Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 do not properly iterate through the characters in a text run, which allows remote attackers to execute arbitrary code via a crafted document.

5%
Низкий
около 4 лет назад
github логотип
GHSA-23q4-mv34-qff2

A privilege escalation vulnerability was discovered in Avaya IP Office Admin Lite and USB Creator that may potentially allow a local user to escalate privileges. This issue affects Admin Lite and USB Creator 11.1 Feature Pack 2 Service Pack 1 and earlier versions.

CVSS3: 7.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-23q4-7p25-c68g

Use after free issue in kernel while accessing freed mdlog session info and its attributes after closing the session in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS405, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 636, SD 675, SD 730, SD 820, SD 820A, SD 835, SD 855, SDA660, SDM630, SDM660, SDX20, SDX24

1%
Низкий
около 4 лет назад

Уязвимостей на страницу