Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-363q-pcwj-5wxw

больше 4 лет назад

The issue navigation and search view in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before version 8.13.4, and from version 8.14.0 before version 8.15.1 allows remote attackers to inject arbitrary HTML or JavaScript via a DOM Cross-Site Scripting (XSS) vulnerability caused by parameter pollution.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-363q-mrhx-5q4w

больше 1 года назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-363q-j92x-7543

больше 3 лет назад

Snipe-IT vulnerable to Cross Site Scripting for View Assigned Assets

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-363q-g58w-9xvh

больше 4 лет назад

IBM Rational DOORS Next Generation 5.0 and 6.0 discloses sensitive information in error response messages that could be used for further attacks against the system.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-363q-54cj-prgf

больше 4 лет назад

Pacemaker before 1.1.6 configure script creates temporary files insecurely

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-363q-22g7-fmmm

около 1 месяца назад

Improper buffer restrictions for the Intel(R) NPU Driver for all versions within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-363p-mgpx-cphf

больше 4 лет назад

nslookup.exe in Microsoft Windows XP SP2 allows user-assisted remote attackers to execute arbitrary code, as demonstrated by an attempted DNS zone transfer, and as exploited in the wild in August 2008.

EPSS: Средний
github логотип

GHSA-363p-gjpv-2pxq

2 месяца назад

MediaCMS 8.2.0 contains an information disclosure vulnerability that allows authenticated users to expose private media metadata belonging to other users by adding arbitrary media tokens to their own playlist without access control checks. Attackers can issue a PUT request to the playlist API endpoint with a known media token to bypass state and ownership validation, then retrieve the playlist to read private media fields including title, description, view count, like count, file size, author username, and encoding status through the unfiltered playlist owner branch in the playlist detail view.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-363m-v2j8-gf6w

больше 4 лет назад

Multiple unspecified vulnerabilities in FFmpeg 0.4.x through 0.6.x, as used in MPlayer 1.0 and other products, in Mandriva Linux 2009.0, 2010.0, and 2010.1; Corporate Server 4.0 (aka CS4.0); and Mandriva Enterprise Server 5 (aka MES5) have unknown impact and attack vectors, related to issues "originally discovered by Google Chrome developers."

EPSS: Низкий
github логотип

GHSA-363m-j8q4-hfrx

больше 4 лет назад

Unspecified vulnerability in Oracle Secure Backup 10.3.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.

EPSS: Низкий
github логотип

GHSA-363m-f7wv-qpfm

больше 1 года назад

Flatnotes <v5.3.1 is vulnerable to denial of service through the upload image function.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-363m-9h8j-6gw4

больше 4 лет назад

Cisco IOS 9.1 and earlier does not properly handle extended IP access lists when the IP route cache is enabled and the "established" keyword is set, which could allow attackers to bypass filters.

EPSS: Низкий
github логотип

GHSA-363m-3jp4-qg24

больше 2 лет назад

Themify WordPress plugin before 1.4.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-363j-w49v-cj57

больше 4 лет назад

Directory traversal vulnerability in the File Manager component in DevExpress ASPxFileManager Control for ASP.NET WebForms and MVC before 13.1.10 and 13.2.x before 13.2.9 allows remote authenticated users to read or write arbitrary files via a .. (dot dot) in the __EVENTARGUMENT parameter.

EPSS: Низкий
github логотип

GHSA-363j-9xx8-29r4

больше 4 лет назад

Use after free in audio in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

EPSS: Низкий
github логотип

GHSA-363j-7w3w-3w9g

больше 4 лет назад

A vulnerability in the web portal of the Cisco Prime Collaboration Provisioning Tool could allow an unauthenticated, remote attacker to create a denial of service (DoS) condition for individual users. The vulnerability is due to weak login controls. An attacker could exploit this vulnerability by using a brute-force attack (Repeated Bad Login Attempts). A successful exploit could allow the attacker to restrict user access. Manual administrative intervention is required to restore access. Cisco Bug IDs: CSCvd07264.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-363j-27mr-4whg

больше 4 лет назад

Multiple memory leaks in the DataGrid control implementation in Microsoft Silverlight 4 before 4.0.60310.0 allow remote attackers to cause a denial of service (memory consumption) via an application involving (1) subscriptions to an INotifyDataErrorInfo.ErrorsChanged event or (2) a TextBlock or TextBox element.

EPSS: Средний
github логотип

GHSA-363h-vj6q-3cmj

около 6 лет назад

Rosetta-Flash JSONP Vulnerability in hapi

EPSS: Средний
github логотип

GHSA-363h-22w6-hcrm

около 1 года назад

Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.31. For ESG 5.1 a fix has been released in 5.1.20. For ESG 5.2 a fix has been released in 5.2.31. For ESG 5.4 a fix has been released in 5.4.8. For ESG 5.5. a fix has been released in 5.5.7.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-363g-vch7-x5j4

больше 4 лет назад

In lsx_aiffstartread in aiff.c in Sound eXchange (SoX) 14.4.2, there is a Use-After-Free vulnerability triggered by supplying a malformed AIFF file.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-363q-pcwj-5wxw

The issue navigation and search view in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before version 8.13.4, and from version 8.14.0 before version 8.15.1 allows remote attackers to inject arbitrary HTML or JavaScript via a DOM Cross-Site Scripting (XSS) vulnerability caused by parameter pollution.

CVSS3: 6.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-363q-mrhx-5q4w

Rejected reason: Not used

больше 1 года назад
github логотип
GHSA-363q-j92x-7543

Snipe-IT vulnerable to Cross Site Scripting for View Assigned Assets

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-363q-g58w-9xvh

IBM Rational DOORS Next Generation 5.0 and 6.0 discloses sensitive information in error response messages that could be used for further attacks against the system.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-363q-54cj-prgf

Pacemaker before 1.1.6 configure script creates temporary files insecurely

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-363q-22g7-fmmm

Improper buffer restrictions for the Intel(R) NPU Driver for all versions within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS3: 6.1
0%
Низкий
около 1 месяца назад
github логотип
GHSA-363p-mgpx-cphf

nslookup.exe in Microsoft Windows XP SP2 allows user-assisted remote attackers to execute arbitrary code, as demonstrated by an attempted DNS zone transfer, and as exploited in the wild in August 2008.

22%
Средний
больше 4 лет назад
github логотип
GHSA-363p-gjpv-2pxq

MediaCMS 8.2.0 contains an information disclosure vulnerability that allows authenticated users to expose private media metadata belonging to other users by adding arbitrary media tokens to their own playlist without access control checks. Attackers can issue a PUT request to the playlist API endpoint with a known media token to bypass state and ownership validation, then retrieve the playlist to read private media fields including title, description, view count, like count, file size, author username, and encoding status through the unfiltered playlist owner branch in the playlist detail view.

CVSS3: 3.1
0%
Низкий
2 месяца назад
github логотип
GHSA-363m-v2j8-gf6w

Multiple unspecified vulnerabilities in FFmpeg 0.4.x through 0.6.x, as used in MPlayer 1.0 and other products, in Mandriva Linux 2009.0, 2010.0, and 2010.1; Corporate Server 4.0 (aka CS4.0); and Mandriva Enterprise Server 5 (aka MES5) have unknown impact and attack vectors, related to issues "originally discovered by Google Chrome developers."

2%
Низкий
больше 4 лет назад
github логотип
GHSA-363m-j8q4-hfrx

Unspecified vulnerability in Oracle Secure Backup 10.3.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-363m-f7wv-qpfm

Flatnotes <v5.3.1 is vulnerable to denial of service through the upload image function.

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-363m-9h8j-6gw4

Cisco IOS 9.1 and earlier does not properly handle extended IP access lists when the IP route cache is enabled and the "established" keyword is set, which could allow attackers to bypass filters.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-363m-3jp4-qg24

Themify WordPress plugin before 1.4.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVSS3: 4.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-363j-w49v-cj57

Directory traversal vulnerability in the File Manager component in DevExpress ASPxFileManager Control for ASP.NET WebForms and MVC before 13.1.10 and 13.2.x before 13.2.9 allows remote authenticated users to read or write arbitrary files via a .. (dot dot) in the __EVENTARGUMENT parameter.

9%
Низкий
больше 4 лет назад
github логотип
GHSA-363j-9xx8-29r4

Use after free in audio in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-363j-7w3w-3w9g

A vulnerability in the web portal of the Cisco Prime Collaboration Provisioning Tool could allow an unauthenticated, remote attacker to create a denial of service (DoS) condition for individual users. The vulnerability is due to weak login controls. An attacker could exploit this vulnerability by using a brute-force attack (Repeated Bad Login Attempts). A successful exploit could allow the attacker to restrict user access. Manual administrative intervention is required to restore access. Cisco Bug IDs: CSCvd07264.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-363j-27mr-4whg

Multiple memory leaks in the DataGrid control implementation in Microsoft Silverlight 4 before 4.0.60310.0 allow remote attackers to cause a denial of service (memory consumption) via an application involving (1) subscriptions to an INotifyDataErrorInfo.ErrorsChanged event or (2) a TextBlock or TextBox element.

12%
Средний
больше 4 лет назад
github логотип
GHSA-363h-vj6q-3cmj

Rosetta-Flash JSONP Vulnerability in hapi

23%
Средний
около 6 лет назад
github логотип
GHSA-363h-22w6-hcrm

Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.31. For ESG 5.1 a fix has been released in 5.1.20. For ESG 5.2 a fix has been released in 5.2.31. For ESG 5.4 a fix has been released in 5.4.8. For ESG 5.5. a fix has been released in 5.5.7.

CVSS3: 6.1
2%
Низкий
около 1 года назад
github логотип
GHSA-363g-vch7-x5j4

In lsx_aiffstartread in aiff.c in Sound eXchange (SoX) 14.4.2, there is a Use-After-Free vulnerability triggered by supplying a malformed AIFF file.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу