Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-3644-q5cj-c5c7

4 месяца назад

LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-3644-5f4r-32pc

9 месяцев назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-3644-5935-56h9

больше 4 лет назад

In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCTL 0x00222088.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3643-w49m-fvvm

больше 4 лет назад

Race condition in the __find_get_block_slow function in the ISO9660 filesystem in Linux 2.6.18 and possibly other versions allows local users to cause a denial of service (infinite loop) by mounting a crafted ISO9660 filesystem containing malformed data structures.

EPSS: Низкий
github логотип

GHSA-3643-vfjq-qr3j

больше 4 лет назад

The aupair service (aupair.exe) in Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 allows remote attackers to execute arbitrary code or corrupt memory via crafted packets that trigger a memory allocation failure and lead to a buffer overflow.

EPSS: Низкий
github логотип

GHSA-3643-7v76-5cj2

4 месяца назад

PraisonAI knowledge-store backends interpolate unvalidated collection names into SQL and CQL queries

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-3642-x49m-7rpc

больше 4 лет назад

Multiple buffer overflows in freeSSHd 1.2.1 allow remote authenticated users to cause a denial of service (crash) and execute arbitrary code via a long (1) open, (2) unlink, (3) mkdir, (4) rmdir, or (5) stat SFTP command.

EPSS: Низкий
github логотип

GHSA-363x-qxhw-jjx9

больше 4 лет назад

Aptdaemon 0.43 and earlier in Ubuntu 11.04, 11.10, and 12.04 LTS does not authenticate packages when the transaction is not simulated, which allows remote attackers to install arbitrary packages via a man-in-the-middle attack.

EPSS: Низкий
github логотип

GHSA-363x-93mm-c7qx

больше 4 лет назад

Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0, 12.3.0, 12.4.0, 14.0.0 and 14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle FLEXCUBE Universal Banking, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle FLEXCUBE Universal Banking accessible data as well as unauthorized read access to a subset of Oracle FLEXCUBE Universal Banking accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L...

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-363x-8vq8-rhv3

больше 4 лет назад

Google Chrome through 32.0.1700.23 on Android allows remote attackers to spoof the address bar via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-363w-hvwh-w7m6

4 месяца назад

Budibase: CouchDB Reduce Injection via Unsanitized Calculation Parameter in V1 Views API

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-363w-c2r8-4qv2

около 2 лет назад

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2. This is due to the plugin utilizing Symfony and leaving display_errors on within test files. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-363w-4gjr-hxxf

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: fix fault at system suspend if device was already runtime suspended If the device was already runtime suspended then during system suspend we cannot access the device registers else it will crash. Also we cannot access any registers after dwc3_core_exit() on some platforms so move the dwc3_enable_susphy() call to the top.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-363v-wf7v-f7x9

больше 4 лет назад

Windows IKE Extension Denial of Service Vulnerability. This CVE ID is unique from CVE-2022-21848, CVE-2022-21883, CVE-2022-21889, CVE-2022-21890.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-363v-vmrh-fj2f

больше 4 лет назад

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-79883568

EPSS: Низкий
github логотип

GHSA-363v-qrh4-66cf

больше 4 лет назад

Unspecified vulnerability in the Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.5.2 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Outside In Filters, a different vulnerability than CVE-2016-3574, CVE-2016-3575, CVE-2016-3576, CVE-2016-3577, CVE-2016-3578, CVE-2016-3579, CVE-2016-3580, CVE-2016-3581, CVE-2016-3582, CVE-2016-3583, CVE-2016-3590, CVE-2016-3591, CVE-2016-3592, CVE-2016-3593, CVE-2016-3595, and CVE-2016-3596.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-363v-5rh8-23wg

6 месяцев назад

AVideo has Plaintext Video Password Storage

EPSS: Низкий
github логотип

GHSA-363r-mxx2-44jc

больше 4 лет назад

The SDDisk2k.sys driver of WinMagic SecureDoc v8.5 and earlier allows local users to read or write to physical disc sectors via a \\.\SecureDocDevice handle. Exploiting this vulnerability results in privileged code execution.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-363r-m8r4-6rjq

больше 4 лет назад

Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) is affected by a heap-based buffer overflow vulnerability due to insecure handling of a crafted .pdf file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted .pdf file

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-363q-xrjc-rqpj

3 месяца назад

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neutralization of special Elements used in an OS command ('OS command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to execution of arbitrary OS commands.

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3644-q5cj-c5c7

LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning

CVSS3: 7.1
0%
Низкий
4 месяца назад
github логотип
GHSA-3644-5f4r-32pc

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

9 месяцев назад
github логотип
GHSA-3644-5935-56h9

In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCTL 0x00222088.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3643-w49m-fvvm

Race condition in the __find_get_block_slow function in the ISO9660 filesystem in Linux 2.6.18 and possibly other versions allows local users to cause a denial of service (infinite loop) by mounting a crafted ISO9660 filesystem containing malformed data structures.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-3643-vfjq-qr3j

The aupair service (aupair.exe) in Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 allows remote attackers to execute arbitrary code or corrupt memory via crafted packets that trigger a memory allocation failure and lead to a buffer overflow.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-3643-7v76-5cj2

PraisonAI knowledge-store backends interpolate unvalidated collection names into SQL and CQL queries

CVSS3: 6.3
0%
Низкий
4 месяца назад
github логотип
GHSA-3642-x49m-7rpc

Multiple buffer overflows in freeSSHd 1.2.1 allow remote authenticated users to cause a denial of service (crash) and execute arbitrary code via a long (1) open, (2) unlink, (3) mkdir, (4) rmdir, or (5) stat SFTP command.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-363x-qxhw-jjx9

Aptdaemon 0.43 and earlier in Ubuntu 11.04, 11.10, and 12.04 LTS does not authenticate packages when the transaction is not simulated, which allows remote attackers to install arbitrary packages via a man-in-the-middle attack.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-363x-93mm-c7qx

Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0, 12.3.0, 12.4.0, 14.0.0 and 14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle FLEXCUBE Universal Banking, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle FLEXCUBE Universal Banking accessible data as well as unauthorized read access to a subset of Oracle FLEXCUBE Universal Banking accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L...

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-363x-8vq8-rhv3

Google Chrome through 32.0.1700.23 on Android allows remote attackers to spoof the address bar via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-363w-hvwh-w7m6

Budibase: CouchDB Reduce Injection via Unsanitized Calculation Parameter in V1 Views API

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-363w-c2r8-4qv2

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2. This is due to the plugin utilizing Symfony and leaving display_errors on within test files. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.

CVSS3: 5.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-363w-4gjr-hxxf

In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: fix fault at system suspend if device was already runtime suspended If the device was already runtime suspended then during system suspend we cannot access the device registers else it will crash. Also we cannot access any registers after dwc3_core_exit() on some platforms so move the dwc3_enable_susphy() call to the top.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-363v-wf7v-f7x9

Windows IKE Extension Denial of Service Vulnerability. This CVE ID is unique from CVE-2022-21848, CVE-2022-21883, CVE-2022-21889, CVE-2022-21890.

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-363v-vmrh-fj2f

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-79883568

0%
Низкий
больше 4 лет назад
github логотип
GHSA-363v-qrh4-66cf

Unspecified vulnerability in the Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.5.2 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Outside In Filters, a different vulnerability than CVE-2016-3574, CVE-2016-3575, CVE-2016-3576, CVE-2016-3577, CVE-2016-3578, CVE-2016-3579, CVE-2016-3580, CVE-2016-3581, CVE-2016-3582, CVE-2016-3583, CVE-2016-3590, CVE-2016-3591, CVE-2016-3592, CVE-2016-3593, CVE-2016-3595, and CVE-2016-3596.

CVSS3: 8.6
4%
Низкий
больше 4 лет назад
github логотип
GHSA-363v-5rh8-23wg

AVideo has Plaintext Video Password Storage

0%
Низкий
6 месяцев назад
github логотип
GHSA-363r-mxx2-44jc

The SDDisk2k.sys driver of WinMagic SecureDoc v8.5 and earlier allows local users to read or write to physical disc sectors via a \\.\SecureDocDevice handle. Exploiting this vulnerability results in privileged code execution.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-363r-m8r4-6rjq

Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) is affected by a heap-based buffer overflow vulnerability due to insecure handling of a crafted .pdf file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted .pdf file

CVSS3: 7.8
5%
Низкий
больше 4 лет назад
github логотип
GHSA-363q-xrjc-rqpj

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neutralization of special Elements used in an OS command ('OS command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to execution of arbitrary OS commands.

CVSS3: 7.2
2%
Низкий
3 месяца назад

Уязвимостей на страницу