Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 364 463

Количество 364 463

github логотип

GHSA-22cc-j8pf-c532

больше 4 лет назад

Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect integrity via unknown vectors related to AX/HI Web UI.

EPSS: Низкий
github логотип

GHSA-22cc-5v95-5pqq

больше 4 лет назад

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have a security bypass vulnerability. Successful exploitation could lead to privilege escalation.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-22c9-qjc2-9748

больше 4 лет назад

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-22c9-2rqw-7g84

8 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: scsi: aic94xx: fix use-after-free in device removal path The asd_pci_remove() function fails to synchronize with pending tasklets before freeing the asd_ha structure, leading to a potential use-after-free vulnerability. When a device removal is triggered (via hot-unplug or module unload), race condition can occur. The fix adds tasklet_kill() before freeing the asd_ha structure, ensuring all scheduled tasklets complete before cleanup proceeds.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-22c8-wr9r-qr3j

больше 4 лет назад

Heap-based buffer overflow in the utf16_to_isolatin1 function in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allows remote attackers to execute arbitrary code via vectors that trigger a character-set conversion failure.

EPSS: Низкий
github логотип

GHSA-22c8-79jr-rvwg

почти 2 года назад

D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command injection vulnerabilities via the ExternalPort, InternalPort, ProtocolNumber, and LocalIPAddress parameters in the SetVirtualServerSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-22c7-f2c3-8h35

больше 4 лет назад

A lack of CORS checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak limited cross-origin data via a crafted HTML page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-22c7-cppf-fmqm

больше 4 лет назад

Internet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when opening it, which allows remote attackers to cause a denial of service (crash) by triggering a heap-based buffer overflow using invalid length codes during decompression, aka "Malformed PNG Image File Failure."

EPSS: Средний
github логотип

GHSA-22c7-32gx-23fj

больше 4 лет назад

Linear eMerge E3-Series devices have Cleartext Credentials in a Database.

EPSS: Низкий
github логотип

GHSA-22c6-pmf5-543m

больше 4 лет назад

CRLF injection vulnerability in Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a MIME header.

EPSS: Низкий
github логотип

GHSA-22c6-jwp4-wc87

больше 4 лет назад

Integer overflow in modules/MSADPCM.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-22c6-3h88-26m3

больше 4 лет назад

Ignite Realtime Openfire allows Cross-site Scripting

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-22c5-cpvr-cfvq

больше 1 года назад

Withdrawn Advisory: undertow: information leakage via HTTP/2 request header reuse

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-22c4-4rv3-jj9h

больше 4 лет назад

Stack-based buffer overflow in the demux_nsf_send_chunk function in src/demuxers/demux_nsf.c in xine-lib 1.1.12 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long NSF title.

EPSS: Средний
github логотип

GHSA-22c3-whjv-hrfm

около 3 лет назад

Jenkins Folders Plugin cross-site request forgery vulnerability

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-22c3-jmcx-576g

больше 4 лет назад

SQL injection vulnerability in login.asp for Cool Cafe (Cool Café) Chat 1.2.1 allows remote attackers to execute arbitrary SQL commands via the password.

EPSS: Низкий
github логотип

GHSA-22c2-9gwg-mj59

больше 1 года назад

Langroid has a Code Injection vulnerability in LanceDocChatAgent through vector_store

EPSS: Низкий
github логотип

GHSA-22c2-92rp-fgpf

3 месяца назад

A Cross Site Scripting vulnerability exists in the Kimi AI v1.0 web interface's 'Preview' feature. The application fails to properly sanitize or encode HTML/JavaScript payloads generated by the AI model. When a user switches to the 'Preview' tab to view AI-generated code, the malicious payload is rendered directly into the DOM, leading to arbitrary JavaScript execution in the victim's browser session.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-229x-w52j-6f5m

8 месяцев назад

A flaw has been found in Open5GS up to 2.7.5. This affects the function decode_ipv6_header/ogs_pfcp_pdr_rule_find_by_packet of the file lib/pfcp/rule-match.c of the component PFCP Session Establishment Request Handler. Executing manipulation can lead to reachable assertion. It is possible to launch the attack remotely. The exploit has been published and may be used. This patch is called b72d8349980076e2c033c8324f07747a86eea4f8. Applying a patch is advised to resolve this issue.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-229x-cgvj-5q56

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in apps/user_webdavauth/settings.php in ownCloud 4.5.x before 4.5.2 allows remote attackers to inject arbitrary web script or HTML via arbitrary POST parameters.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-22cc-j8pf-c532

Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect integrity via unknown vectors related to AX/HI Web UI.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-22cc-5v95-5pqq

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have a security bypass vulnerability. Successful exploitation could lead to privilege escalation.

CVSS3: 8.8
6%
Низкий
больше 4 лет назад
github логотип
GHSA-22c9-qjc2-9748

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-22c9-2rqw-7g84

In the Linux kernel, the following vulnerability has been resolved: scsi: aic94xx: fix use-after-free in device removal path The asd_pci_remove() function fails to synchronize with pending tasklets before freeing the asd_ha structure, leading to a potential use-after-free vulnerability. When a device removal is triggered (via hot-unplug or module unload), race condition can occur. The fix adds tasklet_kill() before freeing the asd_ha structure, ensuring all scheduled tasklets complete before cleanup proceeds.

CVSS3: 7.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-22c8-wr9r-qr3j

Heap-based buffer overflow in the utf16_to_isolatin1 function in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allows remote attackers to execute arbitrary code via vectors that trigger a character-set conversion failure.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-22c8-79jr-rvwg

D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command injection vulnerabilities via the ExternalPort, InternalPort, ProtocolNumber, and LocalIPAddress parameters in the SetVirtualServerSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.

CVSS3: 8
2%
Низкий
почти 2 года назад
github логотип
GHSA-22c7-f2c3-8h35

A lack of CORS checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak limited cross-origin data via a crafted HTML page.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-22c7-cppf-fmqm

Internet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when opening it, which allows remote attackers to cause a denial of service (crash) by triggering a heap-based buffer overflow using invalid length codes during decompression, aka "Malformed PNG Image File Failure."

21%
Средний
больше 4 лет назад
github логотип
GHSA-22c7-32gx-23fj

Linear eMerge E3-Series devices have Cleartext Credentials in a Database.

7%
Низкий
больше 4 лет назад
github логотип
GHSA-22c6-pmf5-543m

CRLF injection vulnerability in Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a MIME header.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-22c6-jwp4-wc87

Integer overflow in modules/MSADPCM.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file.

CVSS3: 5.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-22c6-3h88-26m3

Ignite Realtime Openfire allows Cross-site Scripting

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-22c5-cpvr-cfvq

Withdrawn Advisory: undertow: information leakage via HTTP/2 request header reuse

CVSS3: 7.5
больше 1 года назад
github логотип
GHSA-22c4-4rv3-jj9h

Stack-based buffer overflow in the demux_nsf_send_chunk function in src/demuxers/demux_nsf.c in xine-lib 1.1.12 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long NSF title.

15%
Средний
больше 4 лет назад
github логотип
GHSA-22c3-whjv-hrfm

Jenkins Folders Plugin cross-site request forgery vulnerability

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-22c3-jmcx-576g

SQL injection vulnerability in login.asp for Cool Cafe (Cool Café) Chat 1.2.1 allows remote attackers to execute arbitrary SQL commands via the password.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-22c2-9gwg-mj59

Langroid has a Code Injection vulnerability in LanceDocChatAgent through vector_store

1%
Низкий
больше 1 года назад
github логотип
GHSA-22c2-92rp-fgpf

A Cross Site Scripting vulnerability exists in the Kimi AI v1.0 web interface's 'Preview' feature. The application fails to properly sanitize or encode HTML/JavaScript payloads generated by the AI model. When a user switches to the 'Preview' tab to view AI-generated code, the malicious payload is rendered directly into the DOM, leading to arbitrary JavaScript execution in the victim's browser session.

CVSS3: 6.3
0%
Низкий
3 месяца назад
github логотип
GHSA-229x-w52j-6f5m

A flaw has been found in Open5GS up to 2.7.5. This affects the function decode_ipv6_header/ogs_pfcp_pdr_rule_find_by_packet of the file lib/pfcp/rule-match.c of the component PFCP Session Establishment Request Handler. Executing manipulation can lead to reachable assertion. It is possible to launch the attack remotely. The exploit has been published and may be used. This patch is called b72d8349980076e2c033c8324f07747a86eea4f8. Applying a patch is advised to resolve this issue.

CVSS3: 5.3
1%
Низкий
8 месяцев назад
github логотип
GHSA-229x-cgvj-5q56

Cross-site scripting (XSS) vulnerability in apps/user_webdavauth/settings.php in ownCloud 4.5.x before 4.5.2 allows remote attackers to inject arbitrary web script or HTML via arbitrary POST parameters.

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу