Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 290

Количество 353 290

github логотип

GHSA-22x5-xjpj-vgh2

около 4 лет назад

novel-plus 3.6.0 suffers from an Arbitrary file reading vulnerability.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-22x4-w9qf-p8qq

около 4 лет назад

A memory corruption issue was addressed with improved state management. This issue is fixed in Boot Camp 6.1.14. A malicious application may be able to elevate privileges.

EPSS: Низкий
github логотип

GHSA-22x4-qh5g-vv78

9 месяцев назад

SQL Anywhere Monitor (Non-GUI) baked credentials into the code,exposing the resources or functionality to unintended users and providing attackers with the possibility of arbitrary code execution.This could cause high impact on confidentiality integrity and availability of the system.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-22x4-mg72-m2h8

около 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Horde Application Framework before 3.0.8 allow remote authenticated users to inject arbitrary web script or HTML via multiple vectors, as demonstrated by (1) the identity field, (2) Category and (3) Label search fields, (4) the Mobile Phone field, and (5) Date and (6) Time fields when importing CSV files, as exploited through modules such as (a) Turba Address Book, (b) Kronolith, (c) Mnemo, and (d) Nag.

EPSS: Низкий
github логотип

GHSA-22x4-j6vj-fmm5

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Fix race between element replace and close() Element replace (with a socket different from the one stored) may race with socket's close() link popping & unlinking. __sock_map_delete() unconditionally unrefs the (wrong) element: // set map[0] = s0 map_update_elem(map, 0, s0) // drop fd of s0 close(s0) sock_map_close() lock_sock(sk) (s0!) sock_map_remove_links(sk) link = sk_psock_link_pop() sock_map_unlink(sk, link) sock_map_delete_from_link // replace map[0] with s1 map_update_elem(map, 0, s1) sock_map_update_elem (s1!) lock_sock(sk) sock_map_update_common psock = sk_psock(sk) ...

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-22x4-5x2c-ghwx

больше 4 лет назад

UnixWare dos7utils allows a local user to gain root privileges by using the STATICMERGE environmental variable to find a script which it executes.

EPSS: Низкий
github логотип

GHSA-22x3-wxh4-7f56

больше 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Photo Gallery Team Photo Gallery by Ays allows Reflected XSS.This issue affects Photo Gallery by Ays: from n/a through 5.5.2.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-22x3-v6j4-627v

больше 2 лет назад

A vulnerability has been found in Nsasoft Product Key Explorer 4.0.9 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Registration Handler. The manipulation of the argument Name/Key leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-251671. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-22x3-74c8-hwpv

почти 3 года назад

Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the rule_info parameter in the formAddMacfilterRule function.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-22x3-2qf6-f5mp

больше 3 лет назад

** UNSUPPORTED WHEN ASSIGNED ** Stored cross-site scripting vulnerability in Wired/Wireless LAN Pan/Tilt Network Camera CS-WMV02G all versions allows a network-adjacent authenticated attacker to inject an arbitrary script. NOTE: This vulnerability only affects products that are no longer supported by the developer.

CVSS3: 5.2
EPSS: Низкий
github логотип

GHSA-22wx-h7xw-m85j

около 4 лет назад

An issue was discovered in TitanHQ WebTitan before 5.18. It has a sudoers file that enables low-privilege users to execute a vast number of commands as root, including mv, chown, and chmod. This can be trivially exploited to gain root privileges by an attacker with access.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-22ww-35pw-64c4

больше 1 года назад

Nagios XI 2024R1.2.2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack through the Favorites component, enabling POST-based Cross-Site Scripting (XSS).

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-22wv-v5wx-cm9x

13 дней назад

SurrealDB versions before 1.1.1 fail to properly validate invocation of custom parameters and functions at root or namespace levels, causing server panic. Authorized clients can invoke these entities at unsupported levels to crash the SurrealDB server, resulting in denial of service.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-22wv-f9f6-xwwm

больше 4 лет назад

FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-22wv-3ghq-5h5v

около 4 лет назад

The Date & Time Pref Pane component in Apple OS X before 10.12 mishandles the .GlobalPreferences file, which allows attackers to discover a user's location via a crafted app.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-22wr-xr3p-42c4

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check phantom_stream before it is used dcn32_enable_phantom_stream can return null, so returned value must be checked before used. This fixes 1 NULL_RETURNS issue reported by Coverity.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-22wq-q86m-83fh

12 месяцев назад

svg-sanitizer Bypasses Attribute Sanitization

EPSS: Низкий
github логотип

GHSA-22wp-7v7w-gjjr

больше 1 года назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-22wm-vgh4-2j44

около 4 лет назад

Yealink phones through 2019-08-04 do not properly check user roles in POST requests. Consequently, the default User account (with a password of user) can make admin requests via HTTP.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-22wm-h2wq-6vm3

около 4 лет назад

A use-after-free vulnerability can occur while editing events in form elements on a page, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.6 and Thunderbird < 52.6.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-22x5-xjpj-vgh2

novel-plus 3.6.0 suffers from an Arbitrary file reading vulnerability.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-22x4-w9qf-p8qq

A memory corruption issue was addressed with improved state management. This issue is fixed in Boot Camp 6.1.14. A malicious application may be able to elevate privileges.

1%
Низкий
около 4 лет назад
github логотип
GHSA-22x4-qh5g-vv78

SQL Anywhere Monitor (Non-GUI) baked credentials into the code,exposing the resources or functionality to unintended users and providing attackers with the possibility of arbitrary code execution.This could cause high impact on confidentiality integrity and availability of the system.

CVSS3: 10
1%
Низкий
9 месяцев назад
github логотип
GHSA-22x4-mg72-m2h8

Multiple cross-site scripting (XSS) vulnerabilities in Horde Application Framework before 3.0.8 allow remote authenticated users to inject arbitrary web script or HTML via multiple vectors, as demonstrated by (1) the identity field, (2) Category and (3) Label search fields, (4) the Mobile Phone field, and (5) Date and (6) Time fields when importing CSV files, as exploited through modules such as (a) Turba Address Book, (b) Kronolith, (c) Mnemo, and (d) Nag.

2%
Низкий
около 4 лет назад
github логотип
GHSA-22x4-j6vj-fmm5

In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Fix race between element replace and close() Element replace (with a socket different from the one stored) may race with socket's close() link popping & unlinking. __sock_map_delete() unconditionally unrefs the (wrong) element: // set map[0] = s0 map_update_elem(map, 0, s0) // drop fd of s0 close(s0) sock_map_close() lock_sock(sk) (s0!) sock_map_remove_links(sk) link = sk_psock_link_pop() sock_map_unlink(sk, link) sock_map_delete_from_link // replace map[0] with s1 map_update_elem(map, 0, s1) sock_map_update_elem (s1!) lock_sock(sk) sock_map_update_common psock = sk_psock(sk) ...

CVSS3: 7
0%
Низкий
больше 1 года назад
github логотип
GHSA-22x4-5x2c-ghwx

UnixWare dos7utils allows a local user to gain root privileges by using the STATICMERGE environmental variable to find a script which it executes.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-22x3-wxh4-7f56

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Photo Gallery Team Photo Gallery by Ays allows Reflected XSS.This issue affects Photo Gallery by Ays: from n/a through 5.5.2.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-22x3-v6j4-627v

A vulnerability has been found in Nsasoft Product Key Explorer 4.0.9 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Registration Handler. The manipulation of the argument Name/Key leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-251671. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-22x3-74c8-hwpv

Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the rule_info parameter in the formAddMacfilterRule function.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-22x3-2qf6-f5mp

** UNSUPPORTED WHEN ASSIGNED ** Stored cross-site scripting vulnerability in Wired/Wireless LAN Pan/Tilt Network Camera CS-WMV02G all versions allows a network-adjacent authenticated attacker to inject an arbitrary script. NOTE: This vulnerability only affects products that are no longer supported by the developer.

CVSS3: 5.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-22wx-h7xw-m85j

An issue was discovered in TitanHQ WebTitan before 5.18. It has a sudoers file that enables low-privilege users to execute a vast number of commands as root, including mv, chown, and chmod. This can be trivially exploited to gain root privileges by an attacker with access.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-22ww-35pw-64c4

Nagios XI 2024R1.2.2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack through the Favorites component, enabling POST-based Cross-Site Scripting (XSS).

CVSS3: 6.1
1%
Низкий
больше 1 года назад
github логотип
GHSA-22wv-v5wx-cm9x

SurrealDB versions before 1.1.1 fail to properly validate invocation of custom parameters and functions at root or namespace levels, causing server panic. Authorized clients can invoke these entities at unsupported levels to crash the SurrealDB server, resulting in denial of service.

CVSS3: 6.5
0%
Низкий
13 дней назад
github логотип
GHSA-22wv-f9f6-xwwm

FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-22wv-3ghq-5h5v

The Date & Time Pref Pane component in Apple OS X before 10.12 mishandles the .GlobalPreferences file, which allows attackers to discover a user's location via a crafted app.

CVSS3: 3.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-22wr-xr3p-42c4

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check phantom_stream before it is used dcn32_enable_phantom_stream can return null, so returned value must be checked before used. This fixes 1 NULL_RETURNS issue reported by Coverity.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-22wq-q86m-83fh

svg-sanitizer Bypasses Attribute Sanitization

0%
Низкий
12 месяцев назад
github логотип
GHSA-22wp-7v7w-gjjr

Rejected reason: Not used

больше 1 года назад
github логотип
GHSA-22wm-vgh4-2j44

Yealink phones through 2019-08-04 do not properly check user roles in POST requests. Consequently, the default User account (with a password of user) can make admin requests via HTTP.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-22wm-h2wq-6vm3

A use-after-free vulnerability can occur while editing events in form elements on a page, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.6 and Thunderbird < 52.6.

CVSS3: 9.8
3%
Низкий
около 4 лет назад

Уязвимостей на страницу