Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 374 825

Количество 374 825

github логотип

GHSA-34wr-xg9w-2vh7

больше 4 лет назад

An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13003.1007. A specially crafted pixel shader can cause a denial of service. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability can be triggered from VMware guest, affecting VMware host.

EPSS: Низкий
github логотип

GHSA-34wr-w2h3-hr5x

больше 2 лет назад

File Upload vulnerability in unauthenticated session found in OpenText™ iManager 3.2.6.0200. The vulnerability could allow ant attacker to upload a file without authentication.

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-34wr-q9h7-hx52

больше 4 лет назад

ESet NOD32 2.70.0039.0000 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many "Content-type: message/rfc822;" headers, which allows remote attackers to cause a denial of service (stack consumption or other resource consumption) via a large e-mail message, a related issue to CVE-2006-1173.

EPSS: Низкий
github логотип

GHSA-34wr-p98q-h643

17 дней назад

The Solace Extra WordPress plugin before 1.7.0 does not perform any authorization or post-status checks in one of its AJAX actions, allowing unauthenticated visitors to read the content of non-published (draft, pending, private, and trashed) Site Builder parts that WordPress would otherwise not serve.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-34wq-9xgr-wg53

больше 4 лет назад

acFTP 1.5 allows remote authenticated users to cause a denial of service via a crafted argument to the (1) REST or (2) PBSZ command.

EPSS: Низкий
github логотип

GHSA-34wq-4gw5-77mw

больше 4 лет назад

A buffer overflow in WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tga file. Related to Data from Faulting Address may be used as a return value starting at Editor!TMethodImplementationIntercept+0x528a3.

EPSS: Низкий
github логотип

GHSA-34wp-xvvv-gh32

больше 4 лет назад

The Linux Security Auditing Tool (LSAT) allows local users to overwrite arbitrary files via a symlink attack on temporary files, as demonstrated using /tmp/lsat1.lsat.

EPSS: Низкий
github логотип

GHSA-34wm-j673-236g

больше 2 лет назад

When a virtual server is enabled with VLAN group and SNAT listener is configured, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-34wm-6458-9xcj

больше 4 лет назад

SonicWall Pro running firmware 6.4.0.1 allows remote attackers to cause a denial of service (device reset) via a long HTTP POST to the internal interface, possibly due to a buffer overflow.

EPSS: Низкий
github логотип

GHSA-34wm-4hw7-qfjv

9 месяцев назад

Feast vulnerable to Deserialization of Untrusted Data

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-34wj-p97g-p5hh

больше 4 лет назад

libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer overflow in the ReadImage function in input-bmp.c:337:25.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-34wj-p5jm-2p96

больше 4 лет назад

Improper Restriction of XML External Entity Reference in python-docx

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-34wj-ch2p-7g5r

больше 4 лет назад

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.4. A non-privileged user may be able to modify restricted settings.

EPSS: Низкий
github логотип

GHSA-34wh-mx6f-wwpc

больше 4 лет назад

A memory corruption vulnerability exists in the DMG File Format Handler functionality of PowerISO 7.9. A specially crafted DMG file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability. The vendor fixed it in a bug-release of the current version.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-34wh-7j35-vw3w

больше 4 лет назад

FreeType commit 22a0cccb4d9d002f33c1ba7a4b36812c7d4f46b5 was discovered to contain a segmentation violation via the function FT_Request_Size.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-34wg-xv5v-xgh8

больше 4 лет назад

IBM Security Guardium 10.5, 10.6, and 11.1 could disclose sensitive information on the login page that could aid in further attacks against the system. IBM X-Force ID: 174804.

EPSS: Низкий
github логотип

GHSA-34wg-h67q-gqwf

около 1 месяца назад

A security flaw has been discovered in Open Asset Import Library Assimp 17c12da. Impacted is the function Assimp::Compression::decompressBlock of the file code/Common/Compression.cpp of the component File Parser. Performing a manipulation results in heap-based buffer overflow. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-34wg-h45c-wrjc

больше 4 лет назад

The IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.2S, 3.5.xS before 3.5.1S, and 3.2.xSG before 3.2.2SG allows remote attackers to cause a denial of service (device reload) by sending IKE UDP packets over (1) IPv4 or (2) IPv6, aka Bug ID CSCts38429.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-34wg-2frf-2rx3

больше 4 лет назад

The EncodeImage function in coders/pict.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PICT file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-34wf-vr8w-7xh4

больше 4 лет назад

A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run an arbitrary shell command. Such a URL could be generated by a malicious server, by a malicious user committing to a honest server (to attack another user of that server's repositories), or by a proxy server. The vulnerability affects all clients, including those that use file://, http://, and plain (untunneled) svn://.

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-34wr-xg9w-2vh7

An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13003.1007. A specially crafted pixel shader can cause a denial of service. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability can be triggered from VMware guest, affecting VMware host.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-34wr-w2h3-hr5x

File Upload vulnerability in unauthenticated session found in OpenText™ iManager 3.2.6.0200. The vulnerability could allow ant attacker to upload a file without authentication.

CVSS3: 5.6
0%
Низкий
больше 2 лет назад
github логотип
GHSA-34wr-q9h7-hx52

ESet NOD32 2.70.0039.0000 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many "Content-type: message/rfc822;" headers, which allows remote attackers to cause a denial of service (stack consumption or other resource consumption) via a large e-mail message, a related issue to CVE-2006-1173.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-34wr-p98q-h643

The Solace Extra WordPress plugin before 1.7.0 does not perform any authorization or post-status checks in one of its AJAX actions, allowing unauthenticated visitors to read the content of non-published (draft, pending, private, and trashed) Site Builder parts that WordPress would otherwise not serve.

CVSS3: 5.3
0%
Низкий
17 дней назад
github логотип
GHSA-34wq-9xgr-wg53

acFTP 1.5 allows remote authenticated users to cause a denial of service via a crafted argument to the (1) REST or (2) PBSZ command.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-34wq-4gw5-77mw

A buffer overflow in WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tga file. Related to Data from Faulting Address may be used as a return value starting at Editor!TMethodImplementationIntercept+0x528a3.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-34wp-xvvv-gh32

The Linux Security Auditing Tool (LSAT) allows local users to overwrite arbitrary files via a symlink attack on temporary files, as demonstrated using /tmp/lsat1.lsat.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-34wm-j673-236g

When a virtual server is enabled with VLAN group and SNAT listener is configured, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-34wm-6458-9xcj

SonicWall Pro running firmware 6.4.0.1 allows remote attackers to cause a denial of service (device reset) via a long HTTP POST to the internal interface, possibly due to a buffer overflow.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-34wm-4hw7-qfjv

Feast vulnerable to Deserialization of Untrusted Data

CVSS3: 7.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-34wj-p97g-p5hh

libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer overflow in the ReadImage function in input-bmp.c:337:25.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-34wj-p5jm-2p96

Improper Restriction of XML External Entity Reference in python-docx

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-34wj-ch2p-7g5r

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.4. A non-privileged user may be able to modify restricted settings.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-34wh-mx6f-wwpc

A memory corruption vulnerability exists in the DMG File Format Handler functionality of PowerISO 7.9. A specially crafted DMG file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability. The vendor fixed it in a bug-release of the current version.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-34wh-7j35-vw3w

FreeType commit 22a0cccb4d9d002f33c1ba7a4b36812c7d4f46b5 was discovered to contain a segmentation violation via the function FT_Request_Size.

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-34wg-xv5v-xgh8

IBM Security Guardium 10.5, 10.6, and 11.1 could disclose sensitive information on the login page that could aid in further attacks against the system. IBM X-Force ID: 174804.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-34wg-h67q-gqwf

A security flaw has been discovered in Open Asset Import Library Assimp 17c12da. Impacted is the function Assimp::Compression::decompressBlock of the file code/Common/Compression.cpp of the component File Parser. Performing a manipulation results in heap-based buffer overflow. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 6.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-34wg-h45c-wrjc

The IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.2S, 3.5.xS before 3.5.1S, and 3.2.xSG before 3.2.2SG allows remote attackers to cause a denial of service (device reload) by sending IKE UDP packets over (1) IPv4 or (2) IPv6, aka Bug ID CSCts38429.

CVSS3: 7.5
4%
Низкий
больше 4 лет назад
github логотип
GHSA-34wg-2frf-2rx3

The EncodeImage function in coders/pict.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PICT file.

CVSS3: 6.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-34wf-vr8w-7xh4

A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run an arbitrary shell command. Such a URL could be generated by a malicious server, by a malicious user committing to a honest server (to attack another user of that server's repositories), or by a proxy server. The vulnerability affects all clients, including those that use file://, http://, and plain (untunneled) svn://.

CVSS3: 9.8
19%
Средний
больше 4 лет назад

Уязвимостей на страницу