Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-35mv-96c3-9q8w

больше 4 лет назад

Baby Care System 1.0 is affected by a cross-site scripting (XSS) vulnerability in the Edit Page tab through the Post title parameter.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-35mv-64rp-pmf8

больше 4 лет назад

Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to cause a denial of service (process crash) via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-35mr-9r8x-gpfr

больше 4 лет назад

The get_filter_list function in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0006 does not properly perform certain sub filter parsing, which allows remote authenticated users to cause a denial of service (infinite loop) via a malformed search filter.

EPSS: Низкий
github логотип

GHSA-35mr-3g6g-qqwc

больше 4 лет назад

courier/1000@/api_error_email.html (aka "error reporting page") in Accellion File Transfer Appliance FTA_7_0_178, and possibly other versions before FTA_7_0_189, allows remote attackers to send spam e-mail via modified description and client_email parameters.

EPSS: Низкий
github логотип

GHSA-35mq-hwv5-23m7

18 дней назад

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-35mq-8mc3-vcm8

больше 4 лет назад

OpenSSH before 2.9.9, while using keypairs and multiple keys of different types in the ~/.ssh/authorized_keys2 file, may not properly handle the "from" option associated with a key, which could allow remote attackers to login from unauthorized IP addresses.

EPSS: Низкий
github логотип

GHSA-35mm-cc6r-8fjp

больше 5 лет назад

Cross-site scripting in actionpack

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-35mm-49c2-78fg

больше 4 лет назад

The "mxcsr P4" vulnerability in the Linux kernel before 2.2.17-14, when running on certain Intel CPUs, allows local users to cause a denial of service (system halt).

EPSS: Низкий
github логотип

GHSA-35mj-pjqh-8j57

больше 4 лет назад

The Cisco ATA 187 Analog Telephone Adaptor with firmware 9.2.1.0 and 9.2.3.1 before ES build 4 does not properly implement access control, which allows remote attackers to execute operating-system commands via vectors involving a session on TCP port 7870, aka Bug ID CSCtz67038.

EPSS: Низкий
github логотип

GHSA-35mj-p5wm-c7vw

больше 4 лет назад

Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a Memory corruption vulnerability when parsing a specially crafted PDF file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-35mj-mc7c-rc4m

больше 4 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14270.

EPSS: Средний
github логотип

GHSA-35mj-6q95-hqwx

24 дня назад

The SOCK_STREAM receive path in the unix socket implementation failed to fully detach control messages from the socket buffer before processing them. Some error paths would free those messages, leaving freed data mbufs in the receive socket buffer. An unprivileged local user can exploit this use-after-free to escalate privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-35mj-3pg9-j9v7

больше 4 лет назад

Stack-based buffer overflow in net80211/ieee80211_wireless.c in MadWifi before 0.9.2.1 allows remote attackers to execute arbitrary code via unspecified vectors, related to the encode_ie and giwscan_cb functions.

EPSS: Средний
github логотип

GHSA-35mj-225p-fxvg

почти 4 года назад

Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the schedStartTime parameter in the setSchedWifi function.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-35mh-v24c-mjw6

11 месяцев назад

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted LSA Update packet.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-35mh-m2vc-vgv8

около 1 месяца назад

Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-35mh-jj82-w9jm

около 1 месяца назад

Unauthenticated Broken Access Control in Legal Text Connector of the IT-Recht Kanzlei <= 1.0.13 versions.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-35mh-hxcm-w9xp

11 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in appscreo Hello Followers hellofollowers allows Reflected XSS.This issue affects Hello Followers: from n/a through <= 2.5.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-35mh-f6p8-pj2c

больше 4 лет назад

WPGlobus plugin Stored XSS & CSRF security vulnerability

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-35mh-7m7p-jcq9

больше 1 года назад

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-35mv-96c3-9q8w

Baby Care System 1.0 is affected by a cross-site scripting (XSS) vulnerability in the Edit Page tab through the Post title parameter.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-35mv-64rp-pmf8

Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to cause a denial of service (process crash) via unspecified vectors.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-35mr-9r8x-gpfr

The get_filter_list function in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0006 does not properly perform certain sub filter parsing, which allows remote authenticated users to cause a denial of service (infinite loop) via a malformed search filter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-35mr-3g6g-qqwc

courier/1000@/api_error_email.html (aka "error reporting page") in Accellion File Transfer Appliance FTA_7_0_178, and possibly other versions before FTA_7_0_189, allows remote attackers to send spam e-mail via modified description and client_email parameters.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-35mq-hwv5-23m7

NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

CVSS3: 7.8
0%
Низкий
18 дней назад
github логотип
GHSA-35mq-8mc3-vcm8

OpenSSH before 2.9.9, while using keypairs and multiple keys of different types in the ~/.ssh/authorized_keys2 file, may not properly handle the "from" option associated with a key, which could allow remote attackers to login from unauthorized IP addresses.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-35mm-cc6r-8fjp

Cross-site scripting in actionpack

CVSS3: 6.1
67%
Средний
больше 5 лет назад
github логотип
GHSA-35mm-49c2-78fg

The "mxcsr P4" vulnerability in the Linux kernel before 2.2.17-14, when running on certain Intel CPUs, allows local users to cause a denial of service (system halt).

0%
Низкий
больше 4 лет назад
github логотип
GHSA-35mj-pjqh-8j57

The Cisco ATA 187 Analog Telephone Adaptor with firmware 9.2.1.0 and 9.2.3.1 before ES build 4 does not properly implement access control, which allows remote attackers to execute operating-system commands via vectors involving a session on TCP port 7870, aka Bug ID CSCtz67038.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-35mj-p5wm-c7vw

Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a Memory corruption vulnerability when parsing a specially crafted PDF file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-35mj-mc7c-rc4m

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14270.

62%
Средний
больше 4 лет назад
github логотип
GHSA-35mj-6q95-hqwx

The SOCK_STREAM receive path in the unix socket implementation failed to fully detach control messages from the socket buffer before processing them. Some error paths would free those messages, leaving freed data mbufs in the receive socket buffer. An unprivileged local user can exploit this use-after-free to escalate privileges.

CVSS3: 7.8
0%
Низкий
24 дня назад
github логотип
GHSA-35mj-3pg9-j9v7

Stack-based buffer overflow in net80211/ieee80211_wireless.c in MadWifi before 0.9.2.1 allows remote attackers to execute arbitrary code via unspecified vectors, related to the encode_ie and giwscan_cb functions.

20%
Средний
больше 4 лет назад
github логотип
GHSA-35mj-225p-fxvg

Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the schedStartTime parameter in the setSchedWifi function.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-35mh-v24c-mjw6

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted LSA Update packet.

CVSS3: 7.5
1%
Низкий
11 месяцев назад
github логотип
GHSA-35mh-m2vc-vgv8

Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-35mh-jj82-w9jm

Unauthenticated Broken Access Control in Legal Text Connector of the IT-Recht Kanzlei <= 1.0.13 versions.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-35mh-hxcm-w9xp

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in appscreo Hello Followers hellofollowers allows Reflected XSS.This issue affects Hello Followers: from n/a through <= 2.5.

CVSS3: 7.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-35mh-f6p8-pj2c

WPGlobus plugin Stored XSS & CSRF security vulnerability

CVSS3: 4.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-35mh-7m7p-jcq9

Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
больше 1 года назад

Уязвимостей на страницу