Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 370 227

Количество 370 227

github логотип

GHSA-23v2-6gx7-7pp6

5 месяцев назад

SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in packet data processing of sx_smpd. Processing a crafted packet may cause a temporary denial-of-service (DoS) condition.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-23rx-x963-qprq

больше 4 лет назад

The ResourceDownloadRewriteRule class in Crowd before version 4.0.4, and from version 4.1.0 before 4.1.2 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.

EPSS: Низкий
github логотип

GHSA-23rx-gwwc-2hq5

больше 4 лет назад

In Arial Campaign Enterprise before 11.0.551, multiple pages are accessible without authentication or authorization.

EPSS: Низкий
github логотип

GHSA-23rx-f2xv-5pg9

больше 4 лет назад

Out of bound memory access can happen while parsing ADSP message due to lack of check of size of payload received from userspace in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8096AU, IPQ4019, IPQ6018, IPQ8064, IPQ8074, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, QCN7605, QCS605, SC8180X, SDM710, SDX24, SDX55, SM8150, SM8250, SXR2130

EPSS: Низкий
github логотип

GHSA-23rx-c3g5-hv9w

больше 2 лет назад

Deno permission escalation vulnerability via open of privileged files with missing `--deny` flag

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-23rx-79r7-6cpx

больше 2 лет назад

Duplicate Advisory: Sandbox escape in Artemis Java Test Sandbox

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-23rw-h3j3-5576

больше 4 лет назад

Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for attackers to update settings.

EPSS: Низкий
github логотип

GHSA-23rw-79p3-xgcm

больше 2 лет назад

Type confusion in ANGLE in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-23rv-9x82-j4fq

8 месяцев назад

A vulnerability has been found in Yonyou KSOA 9.0. Affected by this issue is some unknown functionality of the file /worksheet/work_edit.jsp. Such manipulation of the argument Report leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-23rr-vcw7-54r8

больше 4 лет назад

An Unrestricted Upload of File with Dangerous Type vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows remote attackers to upload any files to the /tmp directory of the device through the webpage API. This can result in critical files being overwritten.

EPSS: Низкий
github логотип

GHSA-23rr-99j6-vcfq

6 месяцев назад

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formdumpeasysetup.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-23rr-8ff7-qf8m

5 месяцев назад

A vulnerability was detected in MaxSite CMS up to 109.3. This affects an unknown part of the component Redirect Plugin. The manipulation of the argument f_all/f_all404 results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be used. Upgrading to version 109.4 is able to mitigate this issue. The patch is identified as 8a3946bd0a54bfb72a4d57179fcd253f2c550cd7. You should upgrade the affected component. The vendor was informed early about this issue. They classify it as a "Self-XSS". They deployed a countermeasure: "Nevertheless, we consider this a violation of secure coding standards. The lack of filtering via `htmlspecialchars()` has already been fixed in the latest patch to prevent incorrect data display."

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-23rr-6phq-5p65

около 3 лет назад

Jenkins mabl Plugin missing permission check

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-23rq-jcxh-rmv6

больше 4 лет назад

AOL 9.0 Security Edition revision 4184.2340, and probably other versions, uses insecure permissions (Everyone/Full Control) for the "America Online 9.0" directory, which allows local users to gain privileges by replacing critical files.

EPSS: Низкий
github логотип

GHSA-23rp-qg5j-5vm7

больше 2 лет назад

Missing Authorization vulnerability in sirv.Com Sirv.This issue affects Sirv: from n/a through 7.1.2.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-23rp-cxj2-cgcm

больше 3 лет назад

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is stored XSS on the issue details screen.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-23rh-xw42-fq82

2 дня назад

Pimcore: SQL Injection in Custom Reports via Malicious Report Configuration

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-23rg-jpw2-p6r8

около 3 лет назад

A vulnerability, which was classified as problematic, has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This issue affects some unknown processing of the file \Service\FileHandler.ashx. The manipulation of the argument FileDirectory leads to absolute path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-236207.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-23rg-j4mh-2pmr

больше 4 лет назад

Safari 1.x allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability, a different vulnerability than CVE-2004-1122.

EPSS: Низкий
github логотип

GHSA-23rg-hpwq-h786

больше 4 лет назад

Multiple stack-based buffer overflows in HP OpenView Network Node Manager (OV NNM) 6.41, 7.01, and 7.51 allow remote attackers to execute arbitrary code via unspecified long arguments to (1) ovlogin.exe, (2) OpenView5.exe, (3) snmpviewer.exe, and (4) webappmon.exe, as demonstrated via a long Action parameter to OpenView5.exe.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-23v2-6gx7-7pp6

SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in packet data processing of sx_smpd. Processing a crafted packet may cause a temporary denial-of-service (DoS) condition.

CVSS3: 5.3
1%
Низкий
5 месяцев назад
github логотип
GHSA-23rx-x963-qprq

The ResourceDownloadRewriteRule class in Crowd before version 4.0.4, and from version 4.1.0 before 4.1.2 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-23rx-gwwc-2hq5

In Arial Campaign Enterprise before 11.0.551, multiple pages are accessible without authentication or authorization.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-23rx-f2xv-5pg9

Out of bound memory access can happen while parsing ADSP message due to lack of check of size of payload received from userspace in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8096AU, IPQ4019, IPQ6018, IPQ8064, IPQ8074, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, QCN7605, QCS605, SC8180X, SDM710, SDX24, SDX55, SM8150, SM8250, SXR2130

1%
Низкий
больше 4 лет назад
github логотип
GHSA-23rx-c3g5-hv9w

Deno permission escalation vulnerability via open of privileged files with missing `--deny` flag

CVSS3: 8.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-23rx-79r7-6cpx

Duplicate Advisory: Sandbox escape in Artemis Java Test Sandbox

CVSS3: 8.2
больше 2 лет назад
github логотип
GHSA-23rw-h3j3-5576

Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for attackers to update settings.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-23rw-79p3-xgcm

Type confusion in ANGLE in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

CVSS3: 8.8
9%
Низкий
больше 2 лет назад
github логотип
GHSA-23rv-9x82-j4fq

A vulnerability has been found in Yonyou KSOA 9.0. Affected by this issue is some unknown functionality of the file /worksheet/work_edit.jsp. Such manipulation of the argument Report leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-23rr-vcw7-54r8

An Unrestricted Upload of File with Dangerous Type vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows remote attackers to upload any files to the /tmp directory of the device through the webpage API. This can result in critical files being overwritten.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-23rr-99j6-vcfq

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formdumpeasysetup.

CVSS3: 7.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-23rr-8ff7-qf8m

A vulnerability was detected in MaxSite CMS up to 109.3. This affects an unknown part of the component Redirect Plugin. The manipulation of the argument f_all/f_all404 results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be used. Upgrading to version 109.4 is able to mitigate this issue. The patch is identified as 8a3946bd0a54bfb72a4d57179fcd253f2c550cd7. You should upgrade the affected component. The vendor was informed early about this issue. They classify it as a "Self-XSS". They deployed a countermeasure: "Nevertheless, we consider this a violation of secure coding standards. The lack of filtering via `htmlspecialchars()` has already been fixed in the latest patch to prevent incorrect data display."

CVSS3: 2.4
0%
Низкий
5 месяцев назад
github логотип
GHSA-23rr-6phq-5p65

Jenkins mabl Plugin missing permission check

CVSS3: 4.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-23rq-jcxh-rmv6

AOL 9.0 Security Edition revision 4184.2340, and probably other versions, uses insecure permissions (Everyone/Full Control) for the "America Online 9.0" directory, which allows local users to gain privileges by replacing critical files.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-23rp-qg5j-5vm7

Missing Authorization vulnerability in sirv.Com Sirv.This issue affects Sirv: from n/a through 7.1.2.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-23rp-cxj2-cgcm

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is stored XSS on the issue details screen.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-23rh-xw42-fq82

Pimcore: SQL Injection in Custom Reports via Malicious Report Configuration

CVSS3: 8.8
2 дня назад
github логотип
GHSA-23rg-jpw2-p6r8

A vulnerability, which was classified as problematic, has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This issue affects some unknown processing of the file \Service\FileHandler.ashx. The manipulation of the argument FileDirectory leads to absolute path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-236207.

CVSS3: 4.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-23rg-j4mh-2pmr

Safari 1.x allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability, a different vulnerability than CVE-2004-1122.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-23rg-hpwq-h786

Multiple stack-based buffer overflows in HP OpenView Network Node Manager (OV NNM) 6.41, 7.01, and 7.51 allow remote attackers to execute arbitrary code via unspecified long arguments to (1) ovlogin.exe, (2) OpenView5.exe, (3) snmpviewer.exe, and (4) webappmon.exe, as demonstrated via a long Action parameter to OpenView5.exe.

70%
Средний
больше 4 лет назад

Уязвимостей на страницу