Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-36c4-mfgf-7fg3

больше 4 лет назад

An information disclosure vulnerability exists in Windows Media Player when it fails to properly handle objects in memory, aka 'Windows Media Player Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1481.

EPSS: Низкий
github логотип

GHSA-36c4-c6rg-wqpc

больше 1 года назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-36c4-85vg-5q9w

почти 2 года назад

A vulnerability classified as critical was found in Project Worlds Online Time Table Generator 1.0. Affected by this vulnerability is an unknown functionality of the file /timetable/staff/staffdashboard.php?info=updateprofile. The manipulation of the argument n leads to sql injection. The attack can be launched remotely.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-36c4-6cpg-q42g

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HashThemes Easy Elementor Addons allows DOM-Based XSS. This issue affects Easy Elementor Addons: from n/a through 2.1.5.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-36c4-4r89-6whg

около 6 лет назад

Prototype Pollution in @commercial/subtext

EPSS: Низкий
github логотип

GHSA-36c4-4cpj-pxpr

больше 4 лет назад

A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to access sensitive data about the application. An attacker could exploit this vulnerability to gain information to conduct additional reconnaissance attacks. The vulnerability is due to the HTTP header reply from the Cisco WebEx Meetings Server to the client, which could include internal network information that should be restricted. An attacker could exploit the vulnerability by attempting to use the HTTP protocol and looking at the data in the HTTP responses from the Cisco WebEx Meetings Server. An exploit could allow the attacker to discover sensitive data about the application. Cisco Bug IDs: CSCve65818.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-36c3-vq66-wvcg

больше 4 лет назад

A logic issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0. Processing maliciously crafted web content may lead to universal cross site scripting.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-36c3-jcm2-rm3j

больше 4 лет назад

ChakraCore RCE Vulnerability

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-36c2-gx9g-q34j

около 3 лет назад

A potential security vulnerability has been identified in the Enterprise Server Common Web Administration (ESCWA) component used in Enterprise Server, Enterprise Test Server, Enterprise Developer, Visual COBOL, and COBOL Server. An attacker would need to be authenticated into ESCWA to attempt to exploit this vulnerability. As described in the hardening guide in the product documentation, other mitigations including restricting network access to ESCWA and restricting users’ permissions in the Micro Focus Directory Server also reduce the exposure to this issue. Given the right conditions this vulnerability could be exploited to expose a service account password. The account corresponding to the exposed credentials usually has limited privileges and, in many cases would only be useful for extracting details of other user accounts and similar information.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-369x-mphv-h9f7

больше 4 лет назад

The ignore_section_sym function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, does not validate the output_section pointer in the case of a symtab entry with a "SECTION" type that has a "0" value, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file, as demonstrated by objcopy.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-369x-hwpm-r69p

больше 4 лет назад

The Precision Video Engine component in Cisco Jabber for Windows and Cisco Virtualization Experience Media Engine allows remote attackers to cause a denial of service (process crash and call disconnection) via crafted RTP packets, aka Bug IDs CSCuh60706 and CSCue21117.

EPSS: Низкий
github логотип

GHSA-369w-jch7-c8m6

больше 4 лет назад

Integer underflow in Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote HTTP servers to execute arbitrary code via crafted parameter values in a response, related to error handling, aka "Windows HTTP Services Integer Underflow Vulnerability."

EPSS: Средний
github логотип

GHSA-369w-ch94-45q9

больше 4 лет назад

Multiple "potential" SQL injection vulnerabilities in Utopia News Pro (UNP) 1.1.4 might allow remote attackers to execute arbitrary SQL commands via (1) the newsid parameter in editnews.php, (2) the catid and question parameters in faq.php, (3) the poster parameter in postnews.php, (4) the tempid parameter in templates.php, and (5) the userid and groupid parameters in users.php.

EPSS: Низкий
github логотип

GHSA-369v-xrvc-8m87

больше 4 лет назад

PHP Scripts Mall Naukri Clone Script 3.0.3 has Stored XSS via every profile input field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-369v-6hwx-pj3p

больше 4 лет назад

cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in a Reseller style upload (SEC-314).

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-369v-4h43-wwr9

больше 4 лет назад

An issue was discovered in Espressif ESP-IDF 2.x and 3.x before 3.0.6 and 3.1.x before 3.1.1. Insufficient validation of input data in the 2nd stage bootloader allows a physically proximate attacker to bypass secure boot checks and execute arbitrary code, by crafting an application binary that overwrites a bootloader code segment in process_segment in components/bootloader_support/src/esp_image_format.c. The attack is effective when the flash encryption feature is not enabled, or if the attacker finds a different vulnerability that allows them to write this binary to flash memory.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-369r-wm99-xh2c

больше 1 года назад

Reflected Cross-Site Scripting (XSS) vulnerability in version 1.0 of the Clinic Queuing System. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the page parameter in /patient_side.php.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-369q-m6cp-9fh8

больше 3 лет назад

Windows Kernel Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-369p-wm82-rf8h

больше 4 лет назад

Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1783, CVE-2014-1784, CVE-2014-1786, CVE-2014-1795, CVE-2014-1805, CVE-2014-2758, CVE-2014-2759, CVE-2014-2765, CVE-2014-2766, and CVE-2014-2775.

EPSS: Средний
github логотип

GHSA-369m-2gv6-mw28

больше 4 лет назад

WEBrick RCE Vulnerability

CVSS3: 8.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-36c4-mfgf-7fg3

An information disclosure vulnerability exists in Windows Media Player when it fails to properly handle objects in memory, aka 'Windows Media Player Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1481.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-36c4-c6rg-wqpc

Rejected reason: Not used

больше 1 года назад
github логотип
GHSA-36c4-85vg-5q9w

A vulnerability classified as critical was found in Project Worlds Online Time Table Generator 1.0. Affected by this vulnerability is an unknown functionality of the file /timetable/staff/staffdashboard.php?info=updateprofile. The manipulation of the argument n leads to sql injection. The attack can be launched remotely.

CVSS3: 6.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-36c4-6cpg-q42g

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HashThemes Easy Elementor Addons allows DOM-Based XSS. This issue affects Easy Elementor Addons: from n/a through 2.1.5.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-36c4-4r89-6whg

Prototype Pollution in @commercial/subtext

около 6 лет назад
github логотип
GHSA-36c4-4cpj-pxpr

A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to access sensitive data about the application. An attacker could exploit this vulnerability to gain information to conduct additional reconnaissance attacks. The vulnerability is due to the HTTP header reply from the Cisco WebEx Meetings Server to the client, which could include internal network information that should be restricted. An attacker could exploit the vulnerability by attempting to use the HTTP protocol and looking at the data in the HTTP responses from the Cisco WebEx Meetings Server. An exploit could allow the attacker to discover sensitive data about the application. Cisco Bug IDs: CSCve65818.

CVSS3: 5.3
2%
Низкий
больше 4 лет назад
github логотип
GHSA-36c3-vq66-wvcg

A logic issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0. Processing maliciously crafted web content may lead to universal cross site scripting.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-36c3-jcm2-rm3j

ChakraCore RCE Vulnerability

CVSS3: 7.5
58%
Средний
больше 4 лет назад
github логотип
GHSA-36c2-gx9g-q34j

A potential security vulnerability has been identified in the Enterprise Server Common Web Administration (ESCWA) component used in Enterprise Server, Enterprise Test Server, Enterprise Developer, Visual COBOL, and COBOL Server. An attacker would need to be authenticated into ESCWA to attempt to exploit this vulnerability. As described in the hardening guide in the product documentation, other mitigations including restricting network access to ESCWA and restricting users’ permissions in the Micro Focus Directory Server also reduce the exposure to this issue. Given the right conditions this vulnerability could be exploited to expose a service account password. The account corresponding to the exposed credentials usually has limited privileges and, in many cases would only be useful for extracting details of other user accounts and similar information.

CVSS3: 7.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-369x-mphv-h9f7

The ignore_section_sym function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, does not validate the output_section pointer in the case of a symtab entry with a "SECTION" type that has a "0" value, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file, as demonstrated by objcopy.

CVSS3: 5.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-369x-hwpm-r69p

The Precision Video Engine component in Cisco Jabber for Windows and Cisco Virtualization Experience Media Engine allows remote attackers to cause a denial of service (process crash and call disconnection) via crafted RTP packets, aka Bug IDs CSCuh60706 and CSCue21117.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-369w-jch7-c8m6

Integer underflow in Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote HTTP servers to execute arbitrary code via crafted parameter values in a response, related to error handling, aka "Windows HTTP Services Integer Underflow Vulnerability."

14%
Средний
больше 4 лет назад
github логотип
GHSA-369w-ch94-45q9

Multiple "potential" SQL injection vulnerabilities in Utopia News Pro (UNP) 1.1.4 might allow remote attackers to execute arbitrary SQL commands via (1) the newsid parameter in editnews.php, (2) the catid and question parameters in faq.php, (3) the poster parameter in postnews.php, (4) the tempid parameter in templates.php, and (5) the userid and groupid parameters in users.php.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-369v-xrvc-8m87

PHP Scripts Mall Naukri Clone Script 3.0.3 has Stored XSS via every profile input field.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-369v-6hwx-pj3p

cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in a Reseller style upload (SEC-314).

CVSS3: 7.2
2%
Низкий
больше 4 лет назад
github логотип
GHSA-369v-4h43-wwr9

An issue was discovered in Espressif ESP-IDF 2.x and 3.x before 3.0.6 and 3.1.x before 3.1.1. Insufficient validation of input data in the 2nd stage bootloader allows a physically proximate attacker to bypass secure boot checks and execute arbitrary code, by crafting an application binary that overwrites a bootloader code segment in process_segment in components/bootloader_support/src/esp_image_format.c. The attack is effective when the flash encryption feature is not enabled, or if the attacker finds a different vulnerability that allows them to write this binary to flash memory.

CVSS3: 6.4
0%
Низкий
больше 4 лет назад
github логотип
GHSA-369r-wm99-xh2c

Reflected Cross-Site Scripting (XSS) vulnerability in version 1.0 of the Clinic Queuing System. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the page parameter in /patient_side.php.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-369q-m6cp-9fh8

Windows Kernel Elevation of Privilege Vulnerability

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-369p-wm82-rf8h

Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1783, CVE-2014-1784, CVE-2014-1786, CVE-2014-1795, CVE-2014-1805, CVE-2014-2758, CVE-2014-2759, CVE-2014-2765, CVE-2014-2766, and CVE-2014-2775.

63%
Средний
больше 4 лет назад
github логотип
GHSA-369m-2gv6-mw28

WEBrick RCE Vulnerability

CVSS3: 8.8
16%
Средний
больше 4 лет назад

Уязвимостей на страницу