Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 369 608

Количество 369 608

github логотип

GHSA-248v-fmcv-3gc5

29 дней назад

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-248v-73qf-wh7x

больше 4 лет назад

A Stack-based buffer overflow in the SonicOS SessionID HTTP response header allows a remote authenticated attacker to cause Denial of Service (DoS) and potentially results in code execution in the firewall. This vulnerability affected SonicOS Gen 5, Gen 6 and Gen 7 firmware versions.

EPSS: Низкий
github логотип

GHSA-248v-346w-9cwc

около 2 лет назад

Certifi removes GLOBALTRUST root certificate

EPSS: Низкий
github логотип

GHSA-248r-f975-ppfj

больше 4 лет назад

Processing a maliciously crafted font may result in the disclosure of process memory. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5, iOS 14.6 and iPadOS 14.6. An out-of-bounds read was addressed with improved input validation.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-248r-c6gj-jwpq

10 месяцев назад

Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose the server's Active Directory (AD) or LDAP authentication token to an authenticated user. Exposure of the server’s AD/LDAP token could allow domain-wide authentication misuse, escalation of privileges, or further compromise of network-integrated systems.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-248r-7h7q-cr24

4 месяца назад

vm2 Has a Sandbox Breakout Using Async Generator

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-248r-745f-7p46

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the themes_links function in template.php in the Amadou theme module 6.x-1.x before 6.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors related to class attributes in a list of links.

EPSS: Низкий
github логотип

GHSA-248r-2g9q-v634

больше 4 лет назад

win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1 and Server 2008 R2 SP1 does not properly consider thread-owned objects during the processing of window handles, which allows local users to gain privileges via a crafted application, aka "Win32k Window Handle Vulnerability."

EPSS: Низкий
github логотип

GHSA-248q-w8jq-jxj9

около 1 месяца назад

The logic to handle periodic Viridian STIMERs performs a division with an unchecked user-controlled divisor value, that can be set to zero to cause a #DE fault.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-248q-qwj4-9945

больше 4 лет назад

D-Link DWL-G700AP with firmware 2.00 and 2.01 allows remote attackers to cause a denial of service (CAMEO HTTP service crash) via a request composed of "GET" followed by a space and two newlines, possibly triggering the crash due to missing arguments.

EPSS: Низкий
github логотип

GHSA-248q-88c9-6cq3

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in Opera before 9.63 allows remote attackers to inject arbitrary web script or HTML via built-in XSLT templates.

EPSS: Низкий
github логотип

GHSA-248p-qmc2-qc97

около 2 лет назад

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Magarsus Consultancy SSO (Single Sign On) allows Manipulating Hidden Fields.This issue affects SSO (Single Sign On): from 1.0 before 1.1.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-248p-gq7w-24rp

больше 4 лет назад

Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-0209, CVE-2010-2213, and CVE-2010-2214.

EPSS: Низкий
github логотип

GHSA-248m-82v9-q6g6

3 месяца назад

pypdf: Possible long runtimes for zero-only width values in cross-reference streamsuntimes for zero-only width values in cross-reference streams

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-248j-xg68-6w85

больше 3 лет назад

The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. A remote user may be able to cause kernel code execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-248j-q36m-hvq3

больше 4 лет назад

imcat 4.4 allows remote attackers to obtain potentially sensitive configuration information via the root/tools/adbug/check.php URI.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-248j-6c4g-f66m

больше 4 лет назад

server/notification/NotificationManagerService.java in the Notification Manager Service in Android 6.x before 2016-09-01 and 7.0 before 2016-09-01 lacks uid checks, which allows attackers to bypass intended restrictions on method calls via a crafted application, aka internal bug 29421441.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-248h-xgcm-3q77

больше 4 лет назад

In Wireshark 3.2.0 to 3.2.2, 3.0.0 to 3.0.9, and 2.6.0 to 2.6.15, the BACapp dissector could crash. This was addressed in epan/dissectors/packet-bacapp.c by limiting the amount of recursion.

EPSS: Низкий
github логотип

GHSA-248h-mpmp-3vwh

4 месяца назад

Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Smart Coupons for WooCommerce: from n/a before 2.3.0.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-248h-974q-xrc2

4 месяца назад

axonflow-sdk-java: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verification

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-248v-fmcv-3gc5

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

CVSS3: 6.5
1%
Низкий
29 дней назад
github логотип
GHSA-248v-73qf-wh7x

A Stack-based buffer overflow in the SonicOS SessionID HTTP response header allows a remote authenticated attacker to cause Denial of Service (DoS) and potentially results in code execution in the firewall. This vulnerability affected SonicOS Gen 5, Gen 6 and Gen 7 firmware versions.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-248v-346w-9cwc

Certifi removes GLOBALTRUST root certificate

1%
Низкий
около 2 лет назад
github логотип
GHSA-248r-f975-ppfj

Processing a maliciously crafted font may result in the disclosure of process memory. This issue is fixed in macOS Big Sur 11.4, tvOS 14.6, watchOS 7.5, iOS 14.6 and iPadOS 14.6. An out-of-bounds read was addressed with improved input validation.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-248r-c6gj-jwpq

Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose the server's Active Directory (AD) or LDAP authentication token to an authenticated user. Exposure of the server’s AD/LDAP token could allow domain-wide authentication misuse, escalation of privileges, or further compromise of network-integrated systems.

CVSS3: 9.8
2%
Низкий
10 месяцев назад
github логотип
GHSA-248r-7h7q-cr24

vm2 Has a Sandbox Breakout Using Async Generator

CVSS3: 9.8
1%
Низкий
4 месяца назад
github логотип
GHSA-248r-745f-7p46

Cross-site scripting (XSS) vulnerability in the themes_links function in template.php in the Amadou theme module 6.x-1.x before 6.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors related to class attributes in a list of links.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-248r-2g9q-v634

win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1 and Server 2008 R2 SP1 does not properly consider thread-owned objects during the processing of window handles, which allows local users to gain privileges via a crafted application, aka "Win32k Window Handle Vulnerability."

2%
Низкий
больше 4 лет назад
github логотип
GHSA-248q-w8jq-jxj9

The logic to handle periodic Viridian STIMERs performs a division with an unchecked user-controlled divisor value, that can be set to zero to cause a #DE fault.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-248q-qwj4-9945

D-Link DWL-G700AP with firmware 2.00 and 2.01 allows remote attackers to cause a denial of service (CAMEO HTTP service crash) via a request composed of "GET" followed by a space and two newlines, possibly triggering the crash due to missing arguments.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-248q-88c9-6cq3

Cross-site scripting (XSS) vulnerability in Opera before 9.63 allows remote attackers to inject arbitrary web script or HTML via built-in XSLT templates.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-248p-qmc2-qc97

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Magarsus Consultancy SSO (Single Sign On) allows Manipulating Hidden Fields.This issue affects SSO (Single Sign On): from 1.0 before 1.1.

CVSS3: 6.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-248p-gq7w-24rp

Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-0209, CVE-2010-2213, and CVE-2010-2214.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-248m-82v9-q6g6

pypdf: Possible long runtimes for zero-only width values in cross-reference streamsuntimes for zero-only width values in cross-reference streams

CVSS3: 3.3
0%
Низкий
3 месяца назад
github логотип
GHSA-248j-xg68-6w85

The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. A remote user may be able to cause kernel code execution.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-248j-q36m-hvq3

imcat 4.4 allows remote attackers to obtain potentially sensitive configuration information via the root/tools/adbug/check.php URI.

CVSS3: 5.3
3%
Низкий
больше 4 лет назад
github логотип
GHSA-248j-6c4g-f66m

server/notification/NotificationManagerService.java in the Notification Manager Service in Android 6.x before 2016-09-01 and 7.0 before 2016-09-01 lacks uid checks, which allows attackers to bypass intended restrictions on method calls via a crafted application, aka internal bug 29421441.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-248h-xgcm-3q77

In Wireshark 3.2.0 to 3.2.2, 3.0.0 to 3.0.9, and 2.6.0 to 2.6.15, the BACapp dissector could crash. This was addressed in epan/dissectors/packet-bacapp.c by limiting the amount of recursion.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-248h-mpmp-3vwh

Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Smart Coupons for WooCommerce: from n/a before 2.3.0.

CVSS3: 7.5
0%
Низкий
4 месяца назад
github логотип
GHSA-248h-974q-xrc2

axonflow-sdk-java: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verification

CVSS3: 5.9
4 месяца назад

Уязвимостей на страницу