Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-35h7-q377-hpqq

больше 4 лет назад

NVIDIA libnvomx contains a possible out of bounds write due to a improper input validation which could lead to local escalation of privilege. This issue is rated as high. Product: Android. Version: N/A. Android: A-66969318. Reference: N-CVE-2017-6281.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-35h7-49rx-p783

больше 2 лет назад

HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_scaleoffset, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-35h6-j94c-7hrg

около 2 лет назад

A BOLA vulnerability in GET, PUT, DELETE /webhooks/{webhookId} allows a low privileged user to fetch, modify or delete a webhook of any user (including admin). This results in unauthorized access and unauthorized data manipulation.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-35h6-9g28-r76q

больше 4 лет назад

Alzip 10.76.0.0 and earlier is vulnerable to a stack overflow caused by improper bounds checking. By persuading a victim to open a specially-crafted LZH archive file, a attacker could execute arbitrary code execution.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-35h6-3hm3-w4f8

больше 4 лет назад

An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_process in sdp.c has a NULL pointer dereference.

EPSS: Низкий
github логотип

GHSA-35h4-gw83-rq54

больше 4 лет назад

SQL injection vulnerability in the Paid Memberships versions prior to 2.3.3 allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-35h4-862v-c795

больше 4 лет назад

Zoho ManageEngine Applications Manager before 13620 allows a remote unauthenticated SQL injection via the SyncEventServlet eventid parameter to the SyncEventServlet.java doGet function.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-35h4-3q56-pc46

больше 4 лет назад

In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in GNSS when performing a scan after bootup.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-35h3-x337-gr6p

почти 3 года назад

In ProtocolMiscCarrierConfigSimInfoIndAdapter of protocolmiscadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-35h3-7v37-r8cx

6 месяцев назад

A weakness has been identified in itsourcecode Online Enrollment System 1.0. This issue affects some unknown processing of the file /sms/login.php. This manipulation of the argument user_email causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-35gx-vxvr-hvjq

почти 3 года назад

Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-35gw-c9g7-fphf

больше 4 лет назад

Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-6940, CVE-2016-6941, CVE-2016-6942, CVE-2016-6943, CVE-2016-6947, CVE-2016-6948, CVE-2016-6950, CVE-2016-6951, CVE-2016-6954, CVE-2016-6955, CVE-2016-6956, CVE-2016-6960, CVE-2016-6966, CVE-2016-6970, CVE-2016-6972, CVE-2016-6973, CVE-2016-6974, CVE-2016-6975, CVE-2016-6976, CVE-2016-6977, CVE-2016-6978, CVE-2016-6995, CVE-2016-6996, CVE-2016-6997, CVE-2016-6998, CVE-2016-7000, CVE-2016-7001, CVE-2016-7002, CVE-2016-7003, CVE-2016-7004, CVE-2016-7005, CVE-2016-7006, CVE-2016-7007, CVE-2016-7008, CVE-2016-7009, CVE-2016-7010, CVE-2016-7011, CVE-2016-7012, CVE-2016-7013, CVE-2016-7014, CVE-2016-7015, CVE-2016-7016, CVE-2016-7017, CVE-2016-7018, and C...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-35gv-g55r-237w

больше 4 лет назад

Double free in i18n/zonemeta.cpp in International Components for Unicode (ICU) for C/C++ through 59.1 allows remote attackers to execute arbitrary code via a crafted string, aka a "redundant UVector entry clean up function call" issue.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-35gr-6j23-m9wg

8 месяцев назад

Statistics Database System developed by Gotac has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-35gq-cvrm-xf94

больше 1 года назад

Apache NiFi: Potential Insertion of MongoDB Password in Provenance Record

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-35gq-9q5j-jcc9

больше 4 лет назад

Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6149.

EPSS: Средний
github логотип

GHSA-35gq-67f6-phh5

больше 2 лет назад

Missing Authorization vulnerability in ThimPress WP Hotel Booking.This issue affects WP Hotel Booking: from n/a through 2.0.9.2.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-35gp-jxw8-xw6h

больше 4 лет назад

Codiad CSRF Vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-35gp-6hvq-gx74

больше 4 лет назад

Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect integrity via unknown vectors related to pkg.depotd.

EPSS: Низкий
github логотип

GHSA-35gp-5q9f-g9pq

около 2 лет назад

In ensureSetPipAspectRatioQuotaTracker of ActivityClientController.java, there is a possible way to generate unmovable and undeletable pip windows due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-35h7-q377-hpqq

NVIDIA libnvomx contains a possible out of bounds write due to a improper input validation which could lead to local escalation of privilege. This issue is rated as high. Product: Android. Version: N/A. Android: A-66969318. Reference: N-CVE-2017-6281.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-35h7-49rx-p783

HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_scaleoffset, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-35h6-j94c-7hrg

A BOLA vulnerability in GET, PUT, DELETE /webhooks/{webhookId} allows a low privileged user to fetch, modify or delete a webhook of any user (including admin). This results in unauthorized access and unauthorized data manipulation.

CVSS3: 9.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-35h6-9g28-r76q

Alzip 10.76.0.0 and earlier is vulnerable to a stack overflow caused by improper bounds checking. By persuading a victim to open a specially-crafted LZH archive file, a attacker could execute arbitrary code execution.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-35h6-3hm3-w4f8

An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_process in sdp.c has a NULL pointer dereference.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-35h4-gw83-rq54

SQL injection vulnerability in the Paid Memberships versions prior to 2.3.3 allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-35h4-862v-c795

Zoho ManageEngine Applications Manager before 13620 allows a remote unauthenticated SQL injection via the SyncEventServlet eventid parameter to the SyncEventServlet.java doGet function.

CVSS3: 9.8
10%
Низкий
больше 4 лет назад
github логотип
GHSA-35h4-3q56-pc46

In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in GNSS when performing a scan after bootup.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-35h3-x337-gr6p

In ProtocolMiscCarrierConfigSimInfoIndAdapter of protocolmiscadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-35h3-7v37-r8cx

A weakness has been identified in itsourcecode Online Enrollment System 1.0. This issue affects some unknown processing of the file /sms/login.php. This manipulation of the argument user_email causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.

CVSS3: 7.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-35gx-vxvr-hvjq

Adobe Experience Manager versions 6.5.18 and earlier are affected by a Cross-site Scripting (DOM-based XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

CVSS3: 5.4
1%
Низкий
почти 3 года назад
github логотип
GHSA-35gw-c9g7-fphf

Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-6940, CVE-2016-6941, CVE-2016-6942, CVE-2016-6943, CVE-2016-6947, CVE-2016-6948, CVE-2016-6950, CVE-2016-6951, CVE-2016-6954, CVE-2016-6955, CVE-2016-6956, CVE-2016-6960, CVE-2016-6966, CVE-2016-6970, CVE-2016-6972, CVE-2016-6973, CVE-2016-6974, CVE-2016-6975, CVE-2016-6976, CVE-2016-6977, CVE-2016-6978, CVE-2016-6995, CVE-2016-6996, CVE-2016-6997, CVE-2016-6998, CVE-2016-7000, CVE-2016-7001, CVE-2016-7002, CVE-2016-7003, CVE-2016-7004, CVE-2016-7005, CVE-2016-7006, CVE-2016-7007, CVE-2016-7008, CVE-2016-7009, CVE-2016-7010, CVE-2016-7011, CVE-2016-7012, CVE-2016-7013, CVE-2016-7014, CVE-2016-7015, CVE-2016-7016, CVE-2016-7017, CVE-2016-7018, and C...

CVSS3: 9.8
5%
Низкий
больше 4 лет назад
github логотип
GHSA-35gv-g55r-237w

Double free in i18n/zonemeta.cpp in International Components for Unicode (ICU) for C/C++ through 59.1 allows remote attackers to execute arbitrary code via a crafted string, aka a "redundant UVector entry clean up function call" issue.

CVSS3: 9.8
5%
Низкий
больше 4 лет назад
github логотип
GHSA-35gr-6j23-m9wg

Statistics Database System developed by Gotac has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files.

CVSS3: 7.5
1%
Низкий
8 месяцев назад
github логотип
GHSA-35gq-cvrm-xf94

Apache NiFi: Potential Insertion of MongoDB Password in Provenance Record

CVSS3: 6.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-35gq-9q5j-jcc9

Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6149.

18%
Средний
больше 4 лет назад
github логотип
GHSA-35gq-67f6-phh5

Missing Authorization vulnerability in ThimPress WP Hotel Booking.This issue affects WP Hotel Booking: from n/a through 2.0.9.2.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-35gp-jxw8-xw6h

Codiad CSRF Vulnerability

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-35gp-6hvq-gx74

Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect integrity via unknown vectors related to pkg.depotd.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-35gp-5q9f-g9pq

In ensureSetPipAspectRatioQuotaTracker of ActivityClientController.java, there is a possible way to generate unmovable and undeletable pip windows due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.7
0%
Низкий
около 2 лет назад

Уязвимостей на страницу