Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-35mh-4fxp-w6v9

больше 4 лет назад

FarLinX X25 Gateway through 2014-09-25 allows attackers to write arbitrary data to fsUI.xyz via fsSaveUIPersistence.php.

EPSS: Низкий
github логотип

GHSA-35mh-362p-8hhw

больше 4 лет назад

The pdf-print plugin before 1.9.4 for WordPress has multiple XSS issues.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-35mg-p597-mvg8

больше 4 лет назад

The List Users API of Piwigo 2.9.2 is vulnerable to SQL Injection via the /admin/user_list_backend.php sSortDir_0 parameter. An attacker can exploit this to gain access to the data in a connected MySQL database.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-35mg-4h75-f9m6

больше 4 лет назад

Xen 4.4.x, when running on an ARM system and "handling an unknown system register access from 64-bit userspace," returns to an instruction of the trap handler for kernel space faults instead of an instruction that is associated with faults in 64-bit userspace, which allows local guest users to cause a denial of service (crash) and possibly gain privileges via a crafted process.

EPSS: Низкий
github логотип

GHSA-35mf-vj2p-cr8q

больше 4 лет назад

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0313, CVE-2015-0315, and CVE-2015-0322.

EPSS: Низкий
github логотип

GHSA-35mf-hw36-wj5c

больше 4 лет назад

Integer signedness error in the DIRAPI module in Adobe Shockwave Player before 11.5.8.612 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a count value associated with an "undocumented structure" and the tSAC chunk in a Director movie.

EPSS: Средний
github логотип

GHSA-35mf-f26v-97c5

больше 4 лет назад

Microsoft Dataverse Information Disclosure Vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-35mf-cxwv-h9xm

больше 4 лет назад

wbook_addworksheet in workbook.c in libexcel.a in libexcel 0.01 allows attackers to cause a denial of service (SEGV) via a long name. NOTE: this is not a Microsoft product.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-35m9-r2q7-2ggv

3 месяца назад

Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-35m9-hm95-j6w7

больше 4 лет назад

The Visual Form Builder WordPress plugin before 3.0.8 does not enforce nonce checks which could allow attackers to make a logged in admin or editor delete and restore arbitrary form entries via CSRF attacks

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-35m9-g697-gr77

больше 4 лет назад

Lack of buffer length check before copying in WLAN function while processing FIPS event, can lead to a buffer overflow in Snapdragon Mobile in version SD 845.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-35m7-qv6j-fhf2

около 1 года назад

Ashlar-Vellum Cobalt XE File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of XE files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26236.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-35m7-pw2x-j9f6

больше 4 лет назад

fs/ext4/namei.c in the Linux kernel before 3.7 allows physically proximate attackers to cause a denial of service (system crash) via a crafted no-journal filesystem, a related issue to CVE-2013-2015.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-35m7-cqfx-w4jw

около 2 лет назад

Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.23, 21.3-21.14 and 23.4. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java VM. CVSS 3.1 Base Score 3.1 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-35m7-4c94-48cp

больше 4 лет назад

The Bond Trading (aka com.appmakr.app613309) application 197705 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-35m6-rf3v-8cxx

больше 2 лет назад

A Denial of Service (Dos) vulnerability in Nozomi Networks Guardian, caused by improper input validation in certain fields used in the Radius parsing functionality of our IDS, allows an unauthenticated attacker sending specially crafted malformed network packets to cause the IDS module to stop updating nodes, links, and assets. Network traffic may not be analyzed until the IDS module is restarted.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-35m5-pgqp-r25w

больше 3 лет назад

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий
github логотип

GHSA-35m5-8cvj-8783

почти 5 лет назад

Improper hashing in enrocrypt

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-35m5-388q-jrx8

больше 4 лет назад

websendmail in Webgais 1.0 allows a remote user to access arbitrary files and execute arbitrary code via the receiver parameter ($VAR_receiver variable).

EPSS: Средний
github логотип

GHSA-35m5-23fr-x9rq

около 1 года назад

A vulnerability in the Software SMI handler (SwSmiInputValue 0xB2) allows a local attacker to control the RBX register, which is used to derive pointers (OcHeader, OcData) passed into power and thermal configuration logic. These buffers are not validated before performing multiple structured memory writes based on OcSetup NVRAM values, enabling arbitrary SMRAM corruption and potential SMM privilege escalation.

CVSS3: 8.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-35mh-4fxp-w6v9

FarLinX X25 Gateway through 2014-09-25 allows attackers to write arbitrary data to fsUI.xyz via fsSaveUIPersistence.php.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-35mh-362p-8hhw

The pdf-print plugin before 1.9.4 for WordPress has multiple XSS issues.

CVSS3: 6.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-35mg-p597-mvg8

The List Users API of Piwigo 2.9.2 is vulnerable to SQL Injection via the /admin/user_list_backend.php sSortDir_0 parameter. An attacker can exploit this to gain access to the data in a connected MySQL database.

CVSS3: 4.9
1%
Низкий
больше 4 лет назад
github логотип
GHSA-35mg-4h75-f9m6

Xen 4.4.x, when running on an ARM system and "handling an unknown system register access from 64-bit userspace," returns to an instruction of the trap handler for kernel space faults instead of an instruction that is associated with faults in 64-bit userspace, which allows local guest users to cause a denial of service (crash) and possibly gain privileges via a crafted process.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-35mf-vj2p-cr8q

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0313, CVE-2015-0315, and CVE-2015-0322.

10%
Низкий
больше 4 лет назад
github логотип
GHSA-35mf-hw36-wj5c

Integer signedness error in the DIRAPI module in Adobe Shockwave Player before 11.5.8.612 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a count value associated with an "undocumented structure" and the tSAC chunk in a Director movie.

13%
Средний
больше 4 лет назад
github логотип
GHSA-35mf-f26v-97c5

Microsoft Dataverse Information Disclosure Vulnerability

CVSS3: 6.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-35mf-cxwv-h9xm

wbook_addworksheet in workbook.c in libexcel.a in libexcel 0.01 allows attackers to cause a denial of service (SEGV) via a long name. NOTE: this is not a Microsoft product.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-35m9-r2q7-2ggv

Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
0%
Низкий
3 месяца назад
github логотип
GHSA-35m9-hm95-j6w7

The Visual Form Builder WordPress plugin before 3.0.8 does not enforce nonce checks which could allow attackers to make a logged in admin or editor delete and restore arbitrary form entries via CSRF attacks

CVSS3: 8.1
0%
Низкий
больше 4 лет назад
github логотип
GHSA-35m9-g697-gr77

Lack of buffer length check before copying in WLAN function while processing FIPS event, can lead to a buffer overflow in Snapdragon Mobile in version SD 845.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-35m7-qv6j-fhf2

Ashlar-Vellum Cobalt XE File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of XE files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26236.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-35m7-pw2x-j9f6

fs/ext4/namei.c in the Linux kernel before 3.7 allows physically proximate attackers to cause a denial of service (system crash) via a crafted no-journal filesystem, a related issue to CVE-2013-2015.

CVSS3: 4.4
0%
Низкий
больше 4 лет назад
github логотип
GHSA-35m7-cqfx-w4jw

Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.23, 21.3-21.14 and 23.4. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java VM. CVSS 3.1 Base Score 3.1 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).

CVSS3: 3.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-35m7-4c94-48cp

The Bond Trading (aka com.appmakr.app613309) application 197705 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-35m6-rf3v-8cxx

A Denial of Service (Dos) vulnerability in Nozomi Networks Guardian, caused by improper input validation in certain fields used in the Radius parsing functionality of our IDS, allows an unauthenticated attacker sending specially crafted malformed network packets to cause the IDS module to stop updating nodes, links, and assets. Network traffic may not be analyzed until the IDS module is restarted.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-35m5-pgqp-r25w

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

больше 3 лет назад
github логотип
GHSA-35m5-8cvj-8783

Improper hashing in enrocrypt

CVSS3: 7.5
1%
Низкий
почти 5 лет назад
github логотип
GHSA-35m5-388q-jrx8

websendmail in Webgais 1.0 allows a remote user to access arbitrary files and execute arbitrary code via the receiver parameter ($VAR_receiver variable).

13%
Средний
больше 4 лет назад
github логотип
GHSA-35m5-23fr-x9rq

A vulnerability in the Software SMI handler (SwSmiInputValue 0xB2) allows a local attacker to control the RBX register, which is used to derive pointers (OcHeader, OcData) passed into power and thermal configuration logic. These buffers are not validated before performing multiple structured memory writes based on OcSetup NVRAM values, enabling arbitrary SMRAM corruption and potential SMM privilege escalation.

CVSS3: 8.2
0%
Низкий
около 1 года назад

Уязвимостей на страницу