Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 453

Количество 375 453

github логотип

GHSA-3725-x3x8-r7jq

больше 4 лет назад

The Platform Service Process (asampsp) in Fan-Out Driver Platform Services for Novell Identity Manager (IDM) 3.5.1 allows remote attackers to cause a denial of service (daemon crash) via unspecified network traffic that triggers a syslog message containing invalid format string specifiers, as demonstrated by a Nessus scan.

EPSS: Низкий
github логотип

GHSA-3724-xmqw-2wwv

больше 4 лет назад

Zulip Server before 2.1.3 allows XSS via the modal_link feature in the Markdown functionality.

EPSS: Низкий
github логотип

GHSA-3724-qc3c-8gr9

больше 4 лет назад

In all Android releases from CAF using the Linux kernel, a kernel driver has an off-by-one buffer over-read vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3724-q3rh-j82p

больше 4 лет назад

A Path Traversal issue was discovered in Advantech WebAccess/SCADA versions prior to V8.2_20170817. An attacker has read access to files within the directory structure of the target device.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3724-jcfq-mvfc

почти 2 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Miguel Peixe WP Feature Box allows Stored XSS.This issue affects WP Feature Box: from n/a through 0.1.3.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3724-4mmc-j59x

почти 5 лет назад

NoMachine Enterprise Desktop is affected by Buffer Overflow. IOCTL Handler 0x22001B in the NoMachine Enterprise Desktop above 4.0.346 and below 7.7.4 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

EPSS: Низкий
github логотип

GHSA-3723-f7xr-2xgj

больше 1 года назад

WeGIA < 3.2.0 is vulnerable to Incorrect Access Control in controle/control.php. The application does not validate the value of the old password, so it is possible to change the password by placing any value in the senha_antiga field.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-36xx-949x-639g

5 дней назад

In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma: Initialize IRQ data before requesting IRQs dw_edma_irq_request() passes struct dw_edma_irq to request_irq() before dw_edma_channel_setup() fills the back pointer. A shared interrupt can therefore enter the handler with dw_irq->dw still NULL, leading to a NULL pointer dereference. Set the back pointer before installing each handler.

EPSS: Низкий
github логотип

GHSA-36xx-7vf6-7mv3

около 3 лет назад

Silverstripe Framework: Members with no password can be created and bypass custom login forms

EPSS: Низкий
github логотип

GHSA-36xw-xp2j-w52g

больше 4 лет назад

Directory traversal vulnerability in index.php in BNCwi 1.04 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the newlanguage parameter.

EPSS: Низкий
github логотип

GHSA-36xw-wj35-w3q4

3 месяца назад

A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-36xw-hgfv-jwm7

около 5 лет назад

Multiple security issues including data race, buffer overflow, and uninitialized memory drop in arr

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-36xw-fx78-c5r4

больше 5 лет назад

containerd-shim API Exposed to Host Network Containers

CVSS3: 5.2
EPSS: Низкий
github логотип

GHSA-36xv-rp4j-w277

больше 4 лет назад

Memory leak in eServ 2.9x allows remote attackers to cause a denial of service (memory exhaustion) via a large number of connections, whose memory is not freed when the connection is terminated.

EPSS: Низкий
github логотип

GHSA-36xv-jgw5-4q75

6 месяцев назад

@nestjs/core Improperly Neutralizes Special Elements in Output Used by a Downstream Component ('Injection')

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-36xv-45pm-m623

больше 4 лет назад

Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, does not properly manage memory allocations for function pointers, which allows user-assisted remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Function Pointer Overwrite Vulnerability."

EPSS: Средний
github логотип

GHSA-36xv-3m2q-wwfm

около 2 месяцев назад

The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'width' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-36xr-hxmp-hqwm

больше 4 лет назад

Mutt mail client allows a remote attacker to execute commands via shell metacharacters.

EPSS: Низкий
github логотип

GHSA-36xr-8q52-r359

около 1 года назад

A vulnerability was found in xujeff tianti 天梯 up to 2.3. It has been rated as problematic. This issue affects the function exportOrder of the file /tianti-module-admin/user/ajax/save of the component com.jeff.tianti.controller. The manipulation leads to csv injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-36xr-52f8-hmpq

больше 4 лет назад

Gadu-Gadu build 155 and earlier allows remote attackers to cause a denial of service (infinite loop) via a message that contains an image whose filename does not start with restricted characters.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3725-x3x8-r7jq

The Platform Service Process (asampsp) in Fan-Out Driver Platform Services for Novell Identity Manager (IDM) 3.5.1 allows remote attackers to cause a denial of service (daemon crash) via unspecified network traffic that triggers a syslog message containing invalid format string specifiers, as demonstrated by a Nessus scan.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-3724-xmqw-2wwv

Zulip Server before 2.1.3 allows XSS via the modal_link feature in the Markdown functionality.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3724-qc3c-8gr9

In all Android releases from CAF using the Linux kernel, a kernel driver has an off-by-one buffer over-read vulnerability.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-3724-q3rh-j82p

A Path Traversal issue was discovered in Advantech WebAccess/SCADA versions prior to V8.2_20170817. An attacker has read access to files within the directory structure of the target device.

CVSS3: 5.3
2%
Низкий
больше 4 лет назад
github логотип
GHSA-3724-jcfq-mvfc

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Miguel Peixe WP Feature Box allows Stored XSS.This issue affects WP Feature Box: from n/a through 0.1.3.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-3724-4mmc-j59x

NoMachine Enterprise Desktop is affected by Buffer Overflow. IOCTL Handler 0x22001B in the NoMachine Enterprise Desktop above 4.0.346 and below 7.7.4 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

0%
Низкий
почти 5 лет назад
github логотип
GHSA-3723-f7xr-2xgj

WeGIA < 3.2.0 is vulnerable to Incorrect Access Control in controle/control.php. The application does not validate the value of the old password, so it is possible to change the password by placing any value in the senha_antiga field.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-36xx-949x-639g

In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma: Initialize IRQ data before requesting IRQs dw_edma_irq_request() passes struct dw_edma_irq to request_irq() before dw_edma_channel_setup() fills the back pointer. A shared interrupt can therefore enter the handler with dw_irq->dw still NULL, leading to a NULL pointer dereference. Set the back pointer before installing each handler.

0%
Низкий
5 дней назад
github логотип
GHSA-36xx-7vf6-7mv3

Silverstripe Framework: Members with no password can be created and bypass custom login forms

около 3 лет назад
github логотип
GHSA-36xw-xp2j-w52g

Directory traversal vulnerability in index.php in BNCwi 1.04 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the newlanguage parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-36xw-wj35-w3q4

A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.

CVSS3: 5.5
0%
Низкий
3 месяца назад
github логотип
GHSA-36xw-hgfv-jwm7

Multiple security issues including data race, buffer overflow, and uninitialized memory drop in arr

CVSS3: 9.8
2%
Низкий
около 5 лет назад
github логотип
GHSA-36xw-fx78-c5r4

containerd-shim API Exposed to Host Network Containers

CVSS3: 5.2
3%
Низкий
больше 5 лет назад
github логотип
GHSA-36xv-rp4j-w277

Memory leak in eServ 2.9x allows remote attackers to cause a denial of service (memory exhaustion) via a large number of connections, whose memory is not freed when the connection is terminated.

8%
Низкий
больше 4 лет назад
github логотип
GHSA-36xv-jgw5-4q75

@nestjs/core Improperly Neutralizes Special Elements in Output Used by a Downstream Component ('Injection')

CVSS3: 6.1
0%
Низкий
6 месяцев назад
github логотип
GHSA-36xv-45pm-m623

Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, does not properly manage memory allocations for function pointers, which allows user-assisted remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Function Pointer Overwrite Vulnerability."

14%
Средний
больше 4 лет назад
github логотип
GHSA-36xv-3m2q-wwfm

The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'width' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-36xr-hxmp-hqwm

Mutt mail client allows a remote attacker to execute commands via shell metacharacters.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-36xr-8q52-r359

A vulnerability was found in xujeff tianti 天梯 up to 2.3. It has been rated as problematic. This issue affects the function exportOrder of the file /tianti-module-admin/user/ajax/save of the component com.jeff.tianti.controller. The manipulation leads to csv injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-36xr-52f8-hmpq

Gadu-Gadu build 155 and earlier allows remote attackers to cause a denial of service (infinite loop) via a message that contains an image whose filename does not start with restricted characters.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу