Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 453

Количество 375 453

github логотип

GHSA-375m-5fvv-xq23

больше 5 лет назад

VVE-2021-0002: Incorrect `returndatasize` when using simple forwarder proxies deployed prior to EIP-1167 adoption

EPSS: Низкий
github логотип

GHSA-375j-whc9-8r32

около 1 месяца назад

Improper buffer restrictions for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 0: Kernel may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via adjacent access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (high) impacts.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-375j-vf5x-r3gh

около 2 лет назад

Inappropriate implementation in Picture in Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-375h-xc5m-fwff

больше 2 лет назад

Missing Authorization vulnerability in WP Swings Points and Rewards for WooCommerce.This issue affects Points and Rewards for WooCommerce: from n/a through 1.5.0.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-375h-4wr8-m676

больше 4 лет назад

An elevation of privilege vulnerability exists when the Windows fails to properly handle objects in memory, aka 'Microsoft Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1010, CVE-2020-1068.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-375h-2mv6-2f8m

больше 4 лет назад

An Out-of-bounds Write issue was discovered in Delta Electronics Delta Industrial Automation Screen Editor, Version 2.00.23.00 or prior. Specially crafted .dpb files may cause the system to write outside the intended buffer area.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-375g-qwp7-p447

2 месяца назад

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Net). Supported versions that are affected are 9.7.0-9.7.1. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. While the vulnerability is in MySQL Connectors, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-375g-qj2r-88m9

больше 2 лет назад

in OpenHarmony v3.2.4 and prior versions allow an adjacent attacker arbitrary code execution through out-of-bounds write.

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-375g-mf6c-ppr8

около 4 лет назад

Foxit PDF Reader before 11.2.2 and PDF Editor before 11.2.2, and PhantomPDF before 10.1.8, mishandle cross-reference information during compressed-object parsing within signed documents. This leads to delivery of incorrect signature information via an Incremental Saving Attack and a Shadow Attack.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-375g-cvgg-5crp

около 2 лет назад

The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘media_url’ parameter in all versions up to, and including, 11.9.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-375g-39jq-vq7m

больше 2 лет назад

Potential buffer overflow in CBOR2 decoder

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-375f-qm2g-pw3c

больше 4 лет назад

VirusBlokAda Vba32 AntiVirus 3.12.2 uses weak permissions (Everyone:Write) for its installation directory, which allows local users to gain privileges by replacing application programs, as demonstrated by replacing vba32ldr.exe.

EPSS: Низкий
github логотип

GHSA-375f-cc53-h7vh

около 4 лет назад

Benjamin BALET Jorani v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Comment parameter at application/controllers/Leaves.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-375f-4r2h-f99j

5 месяцев назад

Bandit trusts client-supplied URI scheme on plaintext connections

EPSS: Низкий
github логотип

GHSA-375c-626v-c7m7

больше 4 лет назад

A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD files. A specially crafted USDC file format path jumps decompression heap overflow in a way path jumps are processed. To trigger this vulnerability, the victim needs to open an attacker-provided malformed file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3759-qv8m-9cv6

10 месяцев назад

An Incorrect Authorization vulnerability [CWE-863] in FortiPortal 7.4.0 through 7.4.5 may allow an authenticated attacker to reboot a shared FortiGate device via crafted HTTP requests.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-3759-mwvf-f7q3

3 месяца назад

Missing Authorization vulnerability in Sparkle WP MetroStore metrostore allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MetroStore: from n/a through 1.3.2.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3759-4226-vq4q

около 1 года назад

Out-of-bounds read in some Intel(R) TDX module software before version TDX_1.5.07.00.774 may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-3758-4r5f-9x5h

больше 4 лет назад

The clean-login plugin before 1.5.1 for WordPress has reflected XSS.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3757-wwff-jr3w

больше 4 лет назад

An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.1. There was a heap-based buffer overflow in the function excluded_channels() in libfaad/syntax.c.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-375m-5fvv-xq23

VVE-2021-0002: Incorrect `returndatasize` when using simple forwarder proxies deployed prior to EIP-1167 adoption

больше 5 лет назад
github логотип
GHSA-375j-whc9-8r32

Improper buffer restrictions for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 0: Kernel may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via adjacent access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (high) impacts.

CVSS3: 7.4
0%
Низкий
около 1 месяца назад
github логотип
GHSA-375j-vf5x-r3gh

Inappropriate implementation in Picture in Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-375h-xc5m-fwff

Missing Authorization vulnerability in WP Swings Points and Rewards for WooCommerce.This issue affects Points and Rewards for WooCommerce: from n/a through 1.5.0.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-375h-4wr8-m676

An elevation of privilege vulnerability exists when the Windows fails to properly handle objects in memory, aka 'Microsoft Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1010, CVE-2020-1068.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-375h-2mv6-2f8m

An Out-of-bounds Write issue was discovered in Delta Electronics Delta Industrial Automation Screen Editor, Version 2.00.23.00 or prior. Specially crafted .dpb files may cause the system to write outside the intended buffer area.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-375g-qwp7-p447

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Net). Supported versions that are affected are 9.7.0-9.7.1. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. While the vulnerability is in MySQL Connectors, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).

CVSS3: 8.5
0%
Низкий
2 месяца назад
github логотип
GHSA-375g-qj2r-88m9

in OpenHarmony v3.2.4 and prior versions allow an adjacent attacker arbitrary code execution through out-of-bounds write.

CVSS3: 4.2
0%
Низкий
больше 2 лет назад
github логотип
GHSA-375g-mf6c-ppr8

Foxit PDF Reader before 11.2.2 and PDF Editor before 11.2.2, and PhantomPDF before 10.1.8, mishandle cross-reference information during compressed-object parsing within signed documents. This leads to delivery of incorrect signature information via an Incremental Saving Attack and a Shadow Attack.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-375g-cvgg-5crp

The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘media_url’ parameter in all versions up to, and including, 11.9.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.4
0%
Низкий
около 2 лет назад
github логотип
GHSA-375g-39jq-vq7m

Potential buffer overflow in CBOR2 decoder

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-375f-qm2g-pw3c

VirusBlokAda Vba32 AntiVirus 3.12.2 uses weak permissions (Everyone:Write) for its installation directory, which allows local users to gain privileges by replacing application programs, as demonstrated by replacing vba32ldr.exe.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-375f-cc53-h7vh

Benjamin BALET Jorani v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Comment parameter at application/controllers/Leaves.php.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-375f-4r2h-f99j

Bandit trusts client-supplied URI scheme on plaintext connections

0%
Низкий
5 месяцев назад
github логотип
GHSA-375c-626v-c7m7

A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD files. A specially crafted USDC file format path jumps decompression heap overflow in a way path jumps are processed. To trigger this vulnerability, the victim needs to open an attacker-provided malformed file.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3759-qv8m-9cv6

An Incorrect Authorization vulnerability [CWE-863] in FortiPortal 7.4.0 through 7.4.5 may allow an authenticated attacker to reboot a shared FortiGate device via crafted HTTP requests.

CVSS3: 6.8
0%
Низкий
10 месяцев назад
github логотип
GHSA-3759-mwvf-f7q3

Missing Authorization vulnerability in Sparkle WP MetroStore metrostore allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MetroStore: from n/a through 1.3.2.

CVSS3: 4.3
0%
Низкий
3 месяца назад
github логотип
GHSA-3759-4226-vq4q

Out-of-bounds read in some Intel(R) TDX module software before version TDX_1.5.07.00.774 may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 5.6
0%
Низкий
около 1 года назад
github логотип
GHSA-3758-4r5f-9x5h

The clean-login plugin before 1.5.1 for WordPress has reflected XSS.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3757-wwff-jr3w

An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.1. There was a heap-based buffer overflow in the function excluded_channels() in libfaad/syntax.c.

CVSS3: 7.8
2%
Низкий
больше 4 лет назад

Уязвимостей на страницу