Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 453

Количество 375 453

github логотип

GHSA-3783-6pmv-w66f

больше 4 лет назад

The Dollar Bank Mobile app 2.6.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3783-62vc-jr7x

больше 2 лет назад

ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-3782-4pq4-qwj2

больше 4 лет назад

The WebFOCUS Reporting Server and WebFOCUS Client components of TIBCO Software Inc.'s TIBCO WebFOCUS Client, TIBCO WebFOCUS Installer, and TIBCO WebFOCUS Reporting Server contain easily exploitable Stored and Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker to social engineer a legitimate user with network access to execute scripts targeting the affected system or the victim's local system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO WebFOCUS Client: versions 8207.27.0 and below, TIBCO WebFOCUS Installer: versions 8207.27.0 and below, and TIBCO WebFOCUS Reporting Server: versions 8207.27.0 and below.

EPSS: Низкий
github логотип

GHSA-3782-325c-2w47

больше 4 лет назад

VMware Horizon DaaS (7.x before 8.0.0) contains a broken authentication vulnerability that may allow an attacker to bypass two-factor authentication. Note: In order to exploit this issue, an attacker must have a legitimate account on Horizon DaaS.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-377x-v3vm-mq5h

почти 3 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Pascal Casier bbPress Toolkit plugin <= 1.0.12 versions.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-377x-pw2p-2hm3

больше 2 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in BMI Adult & Kid Calculator allows Stored XSS.This issue affects BMI Adult & Kid Calculator: from n/a through 1.2.1.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-377x-m9rv-682v

больше 4 лет назад

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where multiple pointers are used without checking for NULL, leading to denial of service or potential escalation of privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-377x-f57q-cjmg

больше 4 лет назад

vim (aka gvim) allows local users to modify files being edited by other users via a symlink attack on the backup and swap files, when the victim is editing the file in a world writable directory.

EPSS: Низкий
github логотип

GHSA-377x-9h5g-pgr9

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in misc.php in MyBB (aka MyBulletinBoard) before 1.6.12 allows remote attackers to inject arbitrary web script or HTML via the editor parameter in a smilie list popup.

EPSS: Низкий
github логотип

GHSA-377x-8q3w-wmvj

больше 4 лет назад

The ColorChanger::GetColorFromStack function in colorchanger.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-377x-3gqm-h467

больше 4 лет назад

Multiple SQL injection vulnerabilities in the Call Logging feature in FrontRange HEAT 8.01 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

EPSS: Низкий
github логотип

GHSA-377x-2gvv-ch83

больше 4 лет назад

Multiple PHP remote file inclusion vulnerabilities in eFiction 3.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path_to_smf parameter to (1) bridges/SMF/logout.php or (2) get_session_vars.php.

EPSS: Низкий
github логотип

GHSA-377v-hq7x-6pmr

больше 4 лет назад

cPanel before 82.0.18 allows attackers to conduct arbitrary chown operations as root during log processing (SEC-532).

EPSS: Низкий
github логотип

GHSA-377v-9whx-fp3q

почти 3 года назад

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Image vertical reel scroll slideshow plugin <= 9.0 versions.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-377v-8637-6vq6

больше 4 лет назад

TYPO3 femanager extension allows remote frontend users to modify or delete records of other frontend users

EPSS: Низкий
github логотип

GHSA-377v-3m99-jhrj

больше 4 лет назад

Wavlink WN575A4 and WN579X3 devices through 2020-05-15 allow unauthenticated remote users to inject commands via the key parameter in a login request.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-377r-p949-gf93

18 дней назад

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: use check_add_overflow for shader size+offset bound vmw_shader_define() validates the user-supplied shader window against its backing buffer with (u64)buffer->tbo.base.size < (u64)size + (u64)offset drm_vmw_shader_create_arg::offset is __u64 in the uapi; when it is near U64_MAX the unsigned addition wraps and the resulting tiny value passes the check. The unbounded offset is then stored in res->guest_memory_offset and forwarded to host SVGA shader-create commands. Use check_add_overflow() to detect the wrap and compare the resulting endpoint against the buffer size.

EPSS: Низкий
github логотип

GHSA-377r-5qpp-cqqx

больше 4 лет назад

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. A malicious application may be able to execute arbitrary code with system privileges.

EPSS: Низкий
github логотип

GHSA-377r-32g5-6qvm

больше 4 лет назад

The shmem_nopage function in shmem.c for the tmpfs driver in Linux kernel 2.6 does not properly verify the address argument, which allows local users to cause a denial of service (kernel crash) via an invalid address.

EPSS: Низкий
github логотип

GHSA-377q-pqm6-wg2h

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the WebKit JavaScript bindings in Apple iOS before 9.3.3 and Safari before 9.1.2 allows remote attackers to inject arbitrary web script or HTML via a crafted HTTP/0.9 response, related to a "cross-protocol cross-site scripting (XPXSS)" vulnerability.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3783-6pmv-w66f

The Dollar Bank Mobile app 2.6.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVSS3: 5.9
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3783-62vc-jr7x

ConsoleMe has an Arbitrary File Read Vulnerability via Limited Git command

CVSS3: 9.6
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3782-4pq4-qwj2

The WebFOCUS Reporting Server and WebFOCUS Client components of TIBCO Software Inc.'s TIBCO WebFOCUS Client, TIBCO WebFOCUS Installer, and TIBCO WebFOCUS Reporting Server contain easily exploitable Stored and Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker to social engineer a legitimate user with network access to execute scripts targeting the affected system or the victim's local system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO WebFOCUS Client: versions 8207.27.0 and below, TIBCO WebFOCUS Installer: versions 8207.27.0 and below, and TIBCO WebFOCUS Reporting Server: versions 8207.27.0 and below.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3782-325c-2w47

VMware Horizon DaaS (7.x before 8.0.0) contains a broken authentication vulnerability that may allow an attacker to bypass two-factor authentication. Note: In order to exploit this issue, an attacker must have a legitimate account on Horizon DaaS.

CVSS3: 8.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-377x-v3vm-mq5h

Cross-Site Request Forgery (CSRF) vulnerability in Pascal Casier bbPress Toolkit plugin <= 1.0.12 versions.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-377x-pw2p-2hm3

Cross-Site Request Forgery (CSRF) vulnerability in BMI Adult & Kid Calculator allows Stored XSS.This issue affects BMI Adult & Kid Calculator: from n/a through 1.2.1.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-377x-m9rv-682v

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where multiple pointers are used without checking for NULL, leading to denial of service or potential escalation of privileges.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-377x-f57q-cjmg

vim (aka gvim) allows local users to modify files being edited by other users via a symlink attack on the backup and swap files, when the victim is editing the file in a world writable directory.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-377x-9h5g-pgr9

Cross-site scripting (XSS) vulnerability in misc.php in MyBB (aka MyBulletinBoard) before 1.6.12 allows remote attackers to inject arbitrary web script or HTML via the editor parameter in a smilie list popup.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-377x-8q3w-wmvj

The ColorChanger::GetColorFromStack function in colorchanger.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-377x-3gqm-h467

Multiple SQL injection vulnerabilities in the Call Logging feature in FrontRange HEAT 8.01 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-377x-2gvv-ch83

Multiple PHP remote file inclusion vulnerabilities in eFiction 3.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path_to_smf parameter to (1) bridges/SMF/logout.php or (2) get_session_vars.php.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-377v-hq7x-6pmr

cPanel before 82.0.18 allows attackers to conduct arbitrary chown operations as root during log processing (SEC-532).

0%
Низкий
больше 4 лет назад
github логотип
GHSA-377v-9whx-fp3q

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Image vertical reel scroll slideshow plugin <= 9.0 versions.

CVSS3: 5.9
0%
Низкий
почти 3 года назад
github логотип
GHSA-377v-8637-6vq6

TYPO3 femanager extension allows remote frontend users to modify or delete records of other frontend users

1%
Низкий
больше 4 лет назад
github логотип
GHSA-377v-3m99-jhrj

Wavlink WN575A4 and WN579X3 devices through 2020-05-15 allow unauthenticated remote users to inject commands via the key parameter in a login request.

CVSS3: 9.8
69%
Средний
больше 4 лет назад
github логотип
GHSA-377r-p949-gf93

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: use check_add_overflow for shader size+offset bound vmw_shader_define() validates the user-supplied shader window against its backing buffer with (u64)buffer->tbo.base.size < (u64)size + (u64)offset drm_vmw_shader_create_arg::offset is __u64 in the uapi; when it is near U64_MAX the unsigned addition wraps and the resulting tiny value passes the check. The unbounded offset is then stored in res->guest_memory_offset and forwarded to host SVGA shader-create commands. Use check_add_overflow() to detect the wrap and compare the resulting endpoint against the buffer size.

0%
Низкий
18 дней назад
github логотип
GHSA-377r-5qpp-cqqx

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. A malicious application may be able to execute arbitrary code with system privileges.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-377r-32g5-6qvm

The shmem_nopage function in shmem.c for the tmpfs driver in Linux kernel 2.6 does not properly verify the address argument, which allows local users to cause a denial of service (kernel crash) via an invalid address.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-377q-pqm6-wg2h

Cross-site scripting (XSS) vulnerability in the WebKit JavaScript bindings in Apple iOS before 9.3.3 and Safari before 9.1.2 allows remote attackers to inject arbitrary web script or HTML via a crafted HTTP/0.9 response, related to a "cross-protocol cross-site scripting (XPXSS)" vulnerability.

CVSS3: 6.1
2%
Низкий
больше 4 лет назад

Уязвимостей на страницу