Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 558

Количество 355 558

github логотип

GHSA-xqv4-fgx7-jfv3

больше 3 лет назад

Multiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. An attacker should send an authenticated HTTP request to trigger this vulnerability. In cmd s_sonos, at 0x9d01d068, the value for the `g_group` key is copied using `strcpy` to the buffer at `$sp+0x2b0`.This buffer is 32 bytes large, sending anything longer will cause a buffer overflow.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-xqv2-3vvq-qg6r

почти 4 года назад

Hashicorp Boundary vulnerable to clickjacking

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xqrw-v83c-fjpf

5 месяцев назад

Insufficient Session Expiration in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstation to escalate their privileges via disclosure of local admin password.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xqrw-qq76-h9pm

около 4 лет назад

html/parser/XSSAuditor.cpp in WebCore in WebKit, as used in Google Chrome through 22 and Safari 5.1.7, does not consider all possible output contexts of reflected data, which makes it easier for remote attackers to bypass a cross-site scripting (XSS) protection mechanism via a crafted string, aka rdar problem 12019108.

EPSS: Низкий
github логотип

GHSA-xqrw-f62h-4ff2

почти 4 года назад

Reflected cross-site scripting (XSS) vulnerabilities in WithSecure through 2022-08-10) exists within the F-Secure Policy Manager due to an unvalidated parameter in the endpoint, which allows remote attackers to provide a malicious input.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xqrw-3c79-7qc7

около 2 месяцев назад

OS Command Injection vulnerability in the process_string action of Rapid7 InsightConnect AWK Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text or expression parameters due to unsafe shell command construction in the processing pipeline.

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-xqrv-vpmx-2rm7

около 4 лет назад

Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.0 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Maintenance. NOTE: the original disclosure of this issue erroneously mapped it to CVE-2013-3624.

EPSS: Низкий
github логотип

GHSA-xqrv-hxv4-28ph

больше 4 лет назад

PHP remote file include vulnerability in acceptDecline.php in Sugar Suite Open Source Customer Relationship Management (SugarCRM) 4.0 beta and earlier allows remote attackers to execute arbitrary PHP code via a URL in the beanFiles array parameter.

EPSS: Низкий
github логотип

GHSA-xqrr-554w-8mch

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in STAGGS Staggs Product Configurator for WooCommerce allows Reflected XSS.This issue affects Staggs Product Configurator for WooCommerce: from n/a through 2.0.0.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xqrq-qgmp-x7x4

около 4 лет назад

Revive Adserver before 5.1.0 is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the publicly accessible afr.php delivery script. While this issue was previously addressed in modern browsers as CVE-2020-8115, some older browsers (e.g., IE10) that do not automatically URL encode parameters were still vulnerable.

EPSS: Низкий
github логотип

GHSA-xqrq-q336-f78g

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: arp: Prevent overflow in arp_req_get(). syzkaller reported an overflown write in arp_req_get(). [0] When ioctl(SIOCGARP) is issued, arp_req_get() looks up an neighbour entry and copies neigh->ha to struct arpreq.arp_ha.sa_data. The arp_ha here is struct sockaddr, not struct sockaddr_storage, so the sa_data buffer is just 14 bytes. In the splat below, 2 bytes are overflown to the next int field, arp_flags. We initialise the field just after the memcpy(), so it's not a problem. However, when dev->addr_len is greater than 22 (e.g. MAX_ADDR_LEN), arp_netmask is overwritten, which could be set as htonl(0xFFFFFFFFUL) in arp_ioctl() before calling arp_req_get(). To avoid the overflow, let's limit the max length of memcpy(). Note that commit b5f0de6df6dc ("net: dev: Convert sa_data to flexible array in struct sockaddr") just silenced syzkaller. [0]: memcpy: detected field-spanning write (size 16) of single field "...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xqrq-4mgf-ff32

12 месяцев назад

Withdrawn Advisory: Python-Future Module Arbitrary Code Execution via Unintended Import of test.py

EPSS: Низкий
github логотип

GHSA-xqrp-qvcf-85hm

около 4 лет назад

Insecure permissions in OneBlog v2.3.4 allows low-level administrators to reset the passwords of high-level administrators who hold greater privileges.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xqrp-5pxm-3qxh

около 4 лет назад

Server-Side request forgery (SSRF) vulnerability in task management component in Synology Download Station before 3.8.15-3563 allows remote authenticated users to read arbitrary files via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xqrm-r7vv-r3fq

около 4 лет назад

myfactory.FMS before 7.1-912 allows XSS via the UID parameter.

EPSS: Низкий
github логотип

GHSA-xqrh-rfw4-5q55

около 4 лет назад

IBM DataPower Gateway 10.0.1.0 through 10.0.1.4 and 2018.4.1.0 through 2018.4.1.17 could allow a remote user to cause a temporary denial of service by sending invalid HTTP requests. IBM X-Force ID: 192906.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xqrh-mp77-29j5

около 4 лет назад

The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via an arbitrary parameter name or value that is mishandled in a success.php echo statement.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xqrh-6pmp-4rgf

около 4 лет назад

Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allow local users to obtain sensitive information via an HTML document that loads a shortcut (aka .lnk) file for display within an IFRAME element, as demonstrated by a network share implemented by (1) Microsoft Windows or (2) Samba.

EPSS: Низкий
github логотип

GHSA-xqrh-6c7q-6xm3

около 4 лет назад

The sell function of a smart contract implementation for R Time Token v3 (RS) (Contract Name: RTokenMain), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xqrg-hj9q-p9jx

около 4 лет назад

The Melodigram (aka com.minusdegree.melodigramandroid) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xqv4-fgx7-jfv3

Multiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. An attacker should send an authenticated HTTP request to trigger this vulnerability. In cmd s_sonos, at 0x9d01d068, the value for the `g_group` key is copied using `strcpy` to the buffer at `$sp+0x2b0`.This buffer is 32 bytes large, sending anything longer will cause a buffer overflow.

CVSS3: 9.9
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xqv2-3vvq-qg6r

Hashicorp Boundary vulnerable to clickjacking

CVSS3: 6.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-xqrw-v83c-fjpf

Insufficient Session Expiration in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstation to escalate their privileges via disclosure of local admin password.

CVSS3: 7.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-xqrw-qq76-h9pm

html/parser/XSSAuditor.cpp in WebCore in WebKit, as used in Google Chrome through 22 and Safari 5.1.7, does not consider all possible output contexts of reflected data, which makes it easier for remote attackers to bypass a cross-site scripting (XSS) protection mechanism via a crafted string, aka rdar problem 12019108.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xqrw-f62h-4ff2

Reflected cross-site scripting (XSS) vulnerabilities in WithSecure through 2022-08-10) exists within the F-Secure Policy Manager due to an unvalidated parameter in the endpoint, which allows remote attackers to provide a malicious input.

CVSS3: 6.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-xqrw-3c79-7qc7

OS Command Injection vulnerability in the process_string action of Rapid7 InsightConnect AWK Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text or expression parameters due to unsafe shell command construction in the processing pipeline.

CVSS3: 7.7
1%
Низкий
около 2 месяцев назад
github логотип
GHSA-xqrv-vpmx-2rm7

Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.0 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Maintenance. NOTE: the original disclosure of this issue erroneously mapped it to CVE-2013-3624.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xqrv-hxv4-28ph

PHP remote file include vulnerability in acceptDecline.php in Sugar Suite Open Source Customer Relationship Management (SugarCRM) 4.0 beta and earlier allows remote attackers to execute arbitrary PHP code via a URL in the beanFiles array parameter.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-xqrr-554w-8mch

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in STAGGS Staggs Product Configurator for WooCommerce allows Reflected XSS.This issue affects Staggs Product Configurator for WooCommerce: from n/a through 2.0.0.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-xqrq-qgmp-x7x4

Revive Adserver before 5.1.0 is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the publicly accessible afr.php delivery script. While this issue was previously addressed in modern browsers as CVE-2020-8115, some older browsers (e.g., IE10) that do not automatically URL encode parameters were still vulnerable.

3%
Низкий
около 4 лет назад
github логотип
GHSA-xqrq-q336-f78g

In the Linux kernel, the following vulnerability has been resolved: arp: Prevent overflow in arp_req_get(). syzkaller reported an overflown write in arp_req_get(). [0] When ioctl(SIOCGARP) is issued, arp_req_get() looks up an neighbour entry and copies neigh->ha to struct arpreq.arp_ha.sa_data. The arp_ha here is struct sockaddr, not struct sockaddr_storage, so the sa_data buffer is just 14 bytes. In the splat below, 2 bytes are overflown to the next int field, arp_flags. We initialise the field just after the memcpy(), so it's not a problem. However, when dev->addr_len is greater than 22 (e.g. MAX_ADDR_LEN), arp_netmask is overwritten, which could be set as htonl(0xFFFFFFFFUL) in arp_ioctl() before calling arp_req_get(). To avoid the overflow, let's limit the max length of memcpy(). Note that commit b5f0de6df6dc ("net: dev: Convert sa_data to flexible array in struct sockaddr") just silenced syzkaller. [0]: memcpy: detected field-spanning write (size 16) of single field "...

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xqrq-4mgf-ff32

Withdrawn Advisory: Python-Future Module Arbitrary Code Execution via Unintended Import of test.py

0%
Низкий
12 месяцев назад
github логотип
GHSA-xqrp-qvcf-85hm

Insecure permissions in OneBlog v2.3.4 allows low-level administrators to reset the passwords of high-level administrators who hold greater privileges.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xqrp-5pxm-3qxh

Server-Side request forgery (SSRF) vulnerability in task management component in Synology Download Station before 3.8.15-3563 allows remote authenticated users to read arbitrary files via unspecified vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xqrm-r7vv-r3fq

myfactory.FMS before 7.1-912 allows XSS via the UID parameter.

6%
Низкий
около 4 лет назад
github логотип
GHSA-xqrh-rfw4-5q55

IBM DataPower Gateway 10.0.1.0 through 10.0.1.4 and 2018.4.1.0 through 2018.4.1.17 could allow a remote user to cause a temporary denial of service by sending invalid HTTP requests. IBM X-Force ID: 192906.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xqrh-mp77-29j5

The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via an arbitrary parameter name or value that is mishandled in a success.php echo statement.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-xqrh-6pmp-4rgf

Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allow local users to obtain sensitive information via an HTML document that loads a shortcut (aka .lnk) file for display within an IFRAME element, as demonstrated by a network share implemented by (1) Microsoft Windows or (2) Samba.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xqrh-6c7q-6xm3

The sell function of a smart contract implementation for R Time Token v3 (RS) (Contract Name: RTokenMain), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xqrg-hj9q-p9jx

The Melodigram (aka com.minusdegree.melodigramandroid) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
около 4 лет назад

Уязвимостей на страницу