Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-35x8-g8m5-x5w7

больше 3 лет назад

There are buffer overflow vulnerabilities in multiple underlying operating system processes that could lead to unauthenticated remote code execution by sending specially crafted packets via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-35x7-r658-wx7f

7 месяцев назад

A HTTP Host header attack vulnerability affects WebClient and the WebScheduler web apps of PcVue in version 15.0.0 through 16.3.3 included, allowing a remote attacker to inject harmful payloads that manipulate server-side behavior. This vulnerability only affects the endpoints /Authentication/ExternalLogin, /Authentication/AuthorizationCodeCallback and /Authentication/Logout of the WebClient and WebScheduler web apps.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-35x7-m572-w69v

больше 1 года назад

A vulnerability classified as problematic was found in Open5GS up to 2.7.2. Affected by this vulnerability is the function amf_nsmf_pdusession_handle_update_sm_context of the file src/amf/nsmf-handler.c of the component AMF. The manipulation leads to denial of service. The attack can be launched remotely. This vulnerability allows a single UE to crash the AMF, resulting in the complete loss of mobility and session management services and causing a network-wide outage. All registered UEs will lose connectivity, and new registrations will be blocked until the AMF is restarted, leading to a high availability impact. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-35x6-wg3h-rrv6

больше 4 лет назад

Session fixation vulnerability in SYNO.PhotoStation.Auth in Synology Photo Station before 6.8.7-3481 allows remote attackers to hijack web sessions via the PHPSESSID parameter.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-35x6-cfx8-j8gm

больше 4 лет назад

Stack-based buffer overflow in the Chinagames CGAgent ActiveX control 1.x in CGAgent.dll, as distributed in Chinagames iGame 2009, allows remote attackers to execute arbitrary code via a long argument to the CreateChinagames method, as exploited in the wild in April and May 2009. NOTE: some of these details are obtained from third party information.

EPSS: Средний
github логотип

GHSA-35x5-m3xw-vp7p

больше 4 лет назад

As a result of an observable discrepancy in returned messages, OPSWAT MetaDefender Core (MDCore) before 5.1.2 could allow an authenticated user to enumerate filenames on the server.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-35x5-g32v-j75x

больше 4 лет назад

Buffer overflow in the embedded HTTP server for Cisco Catalyst switches running CatOS 5.4 through 7.3 allows remote attackers to cause a denial of service (reset) via a long HTTP request.

EPSS: Низкий
github логотип

GHSA-35x5-8hjg-m53r

больше 4 лет назад

tftpd in Philippe Jounin Tftpd32 2.74 and earlier, as used in Wyse Simple Imager (WSI) and other products, allows remote attackers to cause a denial of service (daemon crash) via a long filename in a TFTP read (aka RRQ or get) request, a different vulnerability than CVE-2002-2226.

EPSS: Низкий
github логотип

GHSA-35x3-v7hw-gc2g

больше 2 лет назад

std::bad_alloc is mishandled in Precomp 0.4.8. NOTE: this is disputed because it should be categorized as a usability problem.

EPSS: Низкий
github логотип

GHSA-35x3-rj44-584q

больше 4 лет назад

In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-35x2-6j99-3gv6

около 4 лет назад

In Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' flag to be changed after the first scan of the image, leading to an unknown integer-related vulnerability in Stream.cc.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-35wx-v489-5vx6

больше 1 года назад

Missing Authorization vulnerability in Conversios Conversios.io allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Conversios.io: from n/a through 7.2.3.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-35wx-qhfj-hc3p

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in IBM iNotes 8.5.x before 8.5.3 FP4 allows user-assisted remote attackers to inject arbitrary web script or HTML via vectors involving mail, aka SPR JDOE8ZZS9.

EPSS: Низкий
github логотип

GHSA-35ww-qxmq-894v

больше 4 лет назад

WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-04-01-1.

EPSS: Низкий
github логотип

GHSA-35wv-xg96-7j37

больше 4 лет назад

Multiple unspecified vulnerabilities in the Importer in Flip4Mac WMV before 2.2.1 have unknown impact and attack vectors, different vulnerabilities than CVE-2007-6713.

EPSS: Низкий
github логотип

GHSA-35wr-x7v6-9fv2

4 месяца назад

Dalfox Server Mode has an Unauthenticated Arbitrary File Read with Out-of-Band Exfiltration via `custom-payload-file`

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-35wr-c9xh-h9cf

около 4 лет назад

Microsoft Defender for Endpoint Tampering Vulnerability.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-35wp-vg6r-qrm4

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: parisc: Drop WARN_ON_ONCE() from flush_cache_vmap I have observed warning to occassionally trigger.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-35wp-mq65-94rh

больше 4 лет назад

CRLF injection vulnerability in Infoblox Network Automation NetMRI before 7.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the contentType parameter in a login action to config/userAdmin/login.tdf.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-35wm-wmj3-cw44

больше 4 лет назад

SQL injection vulnerability in class/show.php in FaScript FaPersianHack 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to show.php.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-35x8-g8m5-x5w7

There are buffer overflow vulnerabilities in multiple underlying operating system processes that could lead to unauthenticated remote code execution by sending specially crafted packets via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-35x7-r658-wx7f

A HTTP Host header attack vulnerability affects WebClient and the WebScheduler web apps of PcVue in version 15.0.0 through 16.3.3 included, allowing a remote attacker to inject harmful payloads that manipulate server-side behavior. This vulnerability only affects the endpoints /Authentication/ExternalLogin, /Authentication/AuthorizationCodeCallback and /Authentication/Logout of the WebClient and WebScheduler web apps.

CVSS3: 6.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-35x7-m572-w69v

A vulnerability classified as problematic was found in Open5GS up to 2.7.2. Affected by this vulnerability is the function amf_nsmf_pdusession_handle_update_sm_context of the file src/amf/nsmf-handler.c of the component AMF. The manipulation leads to denial of service. The attack can be launched remotely. This vulnerability allows a single UE to crash the AMF, resulting in the complete loss of mobility and session management services and causing a network-wide outage. All registered UEs will lose connectivity, and new registrations will be blocked until the AMF is restarted, leading to a high availability impact. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.

CVSS3: 5.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-35x6-wg3h-rrv6

Session fixation vulnerability in SYNO.PhotoStation.Auth in Synology Photo Station before 6.8.7-3481 allows remote attackers to hijack web sessions via the PHPSESSID parameter.

CVSS3: 6.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-35x6-cfx8-j8gm

Stack-based buffer overflow in the Chinagames CGAgent ActiveX control 1.x in CGAgent.dll, as distributed in Chinagames iGame 2009, allows remote attackers to execute arbitrary code via a long argument to the CreateChinagames method, as exploited in the wild in April and May 2009. NOTE: some of these details are obtained from third party information.

11%
Средний
больше 4 лет назад
github логотип
GHSA-35x5-m3xw-vp7p

As a result of an observable discrepancy in returned messages, OPSWAT MetaDefender Core (MDCore) before 5.1.2 could allow an authenticated user to enumerate filenames on the server.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-35x5-g32v-j75x

Buffer overflow in the embedded HTTP server for Cisco Catalyst switches running CatOS 5.4 through 7.3 allows remote attackers to cause a denial of service (reset) via a long HTTP request.

9%
Низкий
больше 4 лет назад
github логотип
GHSA-35x5-8hjg-m53r

tftpd in Philippe Jounin Tftpd32 2.74 and earlier, as used in Wyse Simple Imager (WSI) and other products, allows remote attackers to cause a denial of service (daemon crash) via a long filename in a TFTP read (aka RRQ or get) request, a different vulnerability than CVE-2002-2226.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-35x3-v7hw-gc2g

std::bad_alloc is mishandled in Precomp 0.4.8. NOTE: this is disputed because it should be categorized as a usability problem.

0%
Низкий
больше 2 лет назад
github логотип
GHSA-35x3-rj44-584q

In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload.

CVSS3: 8.8
7%
Низкий
больше 4 лет назад
github логотип
GHSA-35x2-6j99-3gv6

In Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' flag to be changed after the first scan of the image, leading to an unknown integer-related vulnerability in Stream.cc.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-35wx-v489-5vx6

Missing Authorization vulnerability in Conversios Conversios.io allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Conversios.io: from n/a through 7.2.3.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-35wx-qhfj-hc3p

Cross-site scripting (XSS) vulnerability in IBM iNotes 8.5.x before 8.5.3 FP4 allows user-assisted remote attackers to inject arbitrary web script or HTML via vectors involving mail, aka SPR JDOE8ZZS9.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-35ww-qxmq-894v

WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-04-01-1.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-35wv-xg96-7j37

Multiple unspecified vulnerabilities in the Importer in Flip4Mac WMV before 2.2.1 have unknown impact and attack vectors, different vulnerabilities than CVE-2007-6713.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-35wr-x7v6-9fv2

Dalfox Server Mode has an Unauthenticated Arbitrary File Read with Out-of-Band Exfiltration via `custom-payload-file`

CVSS3: 7.5
0%
Низкий
4 месяца назад
github логотип
GHSA-35wr-c9xh-h9cf

Microsoft Defender for Endpoint Tampering Vulnerability.

CVSS3: 6.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-35wp-vg6r-qrm4

In the Linux kernel, the following vulnerability has been resolved: parisc: Drop WARN_ON_ONCE() from flush_cache_vmap I have observed warning to occassionally trigger.

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-35wp-mq65-94rh

CRLF injection vulnerability in Infoblox Network Automation NetMRI before 7.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the contentType parameter in a login action to config/userAdmin/login.tdf.

CVSS3: 6.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-35wm-wmj3-cw44

SQL injection vulnerability in class/show.php in FaScript FaPersianHack 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to show.php.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу