Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 366 653

Количество 366 653

github логотип

GHSA-232c-j76f-6rhp

7 дней назад

Incorrect access control in the getStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain static DHCP reservation rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2328-vc59-64q8

больше 4 лет назад

The key-management component in Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allows remote attackers to trigger unintended content in outbound e-mail messages via a crafted key UID value in an inbound e-mail message, as demonstrated by the outbound Subject header.

EPSS: Низкий
github логотип

GHSA-2328-f5f3-gj25

5 месяцев назад

Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-2328-876m-g2rg

около 3 лет назад

In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2327-x98x-57c5

10 месяцев назад

Inappropriate implementation in Downloads in Google Chrome on Windows prior to 140.0.7339.80 allowed a remote attacker to bypass Mark of the Web via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-2327-m5w2-rg7f

больше 4 лет назад

The icmp_send function in net/ipv4/icmp.c in the Linux kernel before 2.6.25, when configured as a router with a REJECT route, does not properly manage the Protocol Independent Destination Cache (aka DST) in some situations involving transmission of an ICMP Host Unreachable message, which allows remote attackers to cause a denial of service (connectivity outage) by sending a large series of packets to many destination IP addresses within this REJECT route, related to an "rt_cache leak."

EPSS: Низкий
github логотип

GHSA-2326-xfc9-g293

больше 4 лет назад

SQL injection vulnerability in related.php in Milw0rm Clone Script 1.0 allows remote attackers to execute arbitrary SQL commands via the program parameter.

EPSS: Низкий
github логотип

GHSA-2326-pfpj-vx3h

почти 2 года назад

lexical-core has multiple soundness issues

EPSS: Низкий
github логотип

GHSA-2326-jr9x-m329

10 месяцев назад

A SQL injection vulnerability exists in CSZ-CMS <=1.3.0 in the Form Builder view functionality. The vulnerability is located in the field parameter of the form viewing feature, allowing authenticated administrators to execute arbitrary SQL queries.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2326-hx7g-3m9r

около 2 лет назад

Apache MINA SSHD: integrity check bypass

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-2326-85qm-8gr9

больше 4 лет назад

Integer overflow in the rwpng_read_image24_libpng function in rwpng.c in pngquant 2.7.0 allows remote attackers to have unspecified impact via a crafted PNG file, which triggers a buffer overflow.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2325-58pf-r6qj

почти 3 года назад

Incorrect Default Permissions vulnerability due to incomplete fix to address CVE-2020-14496 in Mitsubishi Electric Corporation FA engineering software products allows a malicious local attacker to execute a malicious code, which could result in information disclosure, tampering with and deletion, or a denial-of-service (DoS) condition. However, if the mitigated version described in the advisory for CVE-2020-14496 is used and installed in the default installation folder, this vulnerability does not affect the products.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-2324-wjjf-834r

больше 4 лет назад

The Soccer Blitz (aka soccer.blitz) application 1.06 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-2324-r4hv-6h34

12 месяцев назад

Memory corruption while performing private key encryption in trusted application.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-2323-w4gh-8p33

больше 4 лет назад

BEA AquaLogic Enterprise Security 2.0 through 2.0 SP2, 2.1 through 2.1 SP1, and 2.2 does not properly set the severity level of audit events when the system load is high, which might make it easier for attackers to avoid detection.

EPSS: Низкий
github логотип

GHSA-2322-wmrw-5cf3

больше 4 лет назад

Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3145.

EPSS: Средний
github логотип

GHSA-2322-g7g4-r84v

больше 4 лет назад

Unspecified vulnerability in MyBB (aka MyBulletinBoard) 1.1.4, related has unspecified impact and attack vectors related to "user group manipulation."

EPSS: Низкий
github логотип

GHSA-2322-3mhq-32v4

больше 4 лет назад

Panda Security 3.0 with registry editing disabled allows users to edit the registry and gain privileges by directly executing a .reg file or using other methods.

EPSS: Низкий
github логотип

GHSA-22xx-xg3v-m8g7

2 месяца назад

Pathway through 0.31.1, fixed in commit d09722e, document store applies a caller-supplied glob pattern to indexed document paths using a hand-written recursive matcher that branches two ways on each ** token without memoization, giving exponential worst-case complexity. The filepath_globpattern value is taken from the body of the unauthenticated HTTP endpoints /v1/retrieve, /v1/inputs and /v2/answer and compiled into a filter evaluated once per indexed document, with no length or **-count limit. A remote unauthenticated attacker can submit a short pattern containing many ** tokens to consume CPU for tens of seconds per request, and a small number of requests denies service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-22xx-mmhm-wq6h

21 день назад

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: validate skb length in testmode query In mt7925_tm_query(), the response skb from mt76_mcu_send_and_get_msg() is used in a memcpy without validating its length: memcpy(evt_resp, skb->data + 8, MT7925_EVT_RSP_LEN); where MT7925_EVT_RSP_LEN is 512. If the firmware returns a response shorter than 520 bytes (8 + 512), this reads beyond the skb data buffer. The over-read data is then returned to userspace via nla_put() in mt7925_testmode_dump(). Add a length check before the memcpy to ensure the skb contains sufficient data.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-232c-j76f-6rhp

Incorrect access control in the getStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain static DHCP reservation rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

CVSS3: 4.3
0%
Низкий
7 дней назад
github логотип
GHSA-2328-vc59-64q8

The key-management component in Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allows remote attackers to trigger unintended content in outbound e-mail messages via a crafted key UID value in an inbound e-mail message, as demonstrated by the outbound Subject header.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2328-f5f3-gj25

Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)

CVSS3: 7.4
0%
Низкий
5 месяцев назад
github логотип
GHSA-2328-876m-g2rg

In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges

CVSS3: 5.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-2327-x98x-57c5

Inappropriate implementation in Downloads in Google Chrome on Windows prior to 140.0.7339.80 allowed a remote attacker to bypass Mark of the Web via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 5.4
0%
Низкий
10 месяцев назад
github логотип
GHSA-2327-m5w2-rg7f

The icmp_send function in net/ipv4/icmp.c in the Linux kernel before 2.6.25, when configured as a router with a REJECT route, does not properly manage the Protocol Independent Destination Cache (aka DST) in some situations involving transmission of an ICMP Host Unreachable message, which allows remote attackers to cause a denial of service (connectivity outage) by sending a large series of packets to many destination IP addresses within this REJECT route, related to an "rt_cache leak."

5%
Низкий
больше 4 лет назад
github логотип
GHSA-2326-xfc9-g293

SQL injection vulnerability in related.php in Milw0rm Clone Script 1.0 allows remote attackers to execute arbitrary SQL commands via the program parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-2326-pfpj-vx3h

lexical-core has multiple soundness issues

почти 2 года назад
github логотип
GHSA-2326-jr9x-m329

A SQL injection vulnerability exists in CSZ-CMS <=1.3.0 in the Form Builder view functionality. The vulnerability is located in the field parameter of the form viewing feature, allowing authenticated administrators to execute arbitrary SQL queries.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-2326-hx7g-3m9r

Apache MINA SSHD: integrity check bypass

CVSS3: 5.9
1%
Низкий
около 2 лет назад
github логотип
GHSA-2326-85qm-8gr9

Integer overflow in the rwpng_read_image24_libpng function in rwpng.c in pngquant 2.7.0 allows remote attackers to have unspecified impact via a crafted PNG file, which triggers a buffer overflow.

CVSS3: 7.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-2325-58pf-r6qj

Incorrect Default Permissions vulnerability due to incomplete fix to address CVE-2020-14496 in Mitsubishi Electric Corporation FA engineering software products allows a malicious local attacker to execute a malicious code, which could result in information disclosure, tampering with and deletion, or a denial-of-service (DoS) condition. However, if the mitigated version described in the advisory for CVE-2020-14496 is used and installed in the default installation folder, this vulnerability does not affect the products.

CVSS3: 9.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-2324-wjjf-834r

The Soccer Blitz (aka soccer.blitz) application 1.06 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-2324-r4hv-6h34

Memory corruption while performing private key encryption in trusted application.

CVSS3: 7.8
0%
Низкий
12 месяцев назад
github логотип
GHSA-2323-w4gh-8p33

BEA AquaLogic Enterprise Security 2.0 through 2.0 SP2, 2.1 through 2.1 SP1, and 2.2 does not properly set the severity level of audit events when the system load is high, which might make it easier for attackers to avoid detection.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-2322-wmrw-5cf3

Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3145.

25%
Средний
больше 4 лет назад
github логотип
GHSA-2322-g7g4-r84v

Unspecified vulnerability in MyBB (aka MyBulletinBoard) 1.1.4, related has unspecified impact and attack vectors related to "user group manipulation."

1%
Низкий
больше 4 лет назад
github логотип
GHSA-2322-3mhq-32v4

Panda Security 3.0 with registry editing disabled allows users to edit the registry and gain privileges by directly executing a .reg file or using other methods.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-22xx-xg3v-m8g7

Pathway through 0.31.1, fixed in commit d09722e, document store applies a caller-supplied glob pattern to indexed document paths using a hand-written recursive matcher that branches two ways on each ** token without memoization, giving exponential worst-case complexity. The filepath_globpattern value is taken from the body of the unauthenticated HTTP endpoints /v1/retrieve, /v1/inputs and /v2/answer and compiled into a filter evaluated once per indexed document, with no length or **-count limit. A remote unauthenticated attacker can submit a short pattern containing many ** tokens to consume CPU for tens of seconds per request, and a small number of requests denies service.

CVSS3: 7.5
1%
Низкий
2 месяца назад
github логотип
GHSA-22xx-mmhm-wq6h

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: validate skb length in testmode query In mt7925_tm_query(), the response skb from mt76_mcu_send_and_get_msg() is used in a memcpy without validating its length: memcpy(evt_resp, skb->data + 8, MT7925_EVT_RSP_LEN); where MT7925_EVT_RSP_LEN is 512. If the firmware returns a response shorter than 520 bytes (8 + 512), this reads beyond the skb data buffer. The over-read data is then returned to userspace via nla_put() in mt7925_testmode_dump(). Add a length check before the memcpy to ensure the skb contains sufficient data.

0%
Низкий
21 день назад

Уязвимостей на страницу