Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-25c8-fq6j-8vvf

9 месяцев назад

Memory corruption while processing MFC channel configuration during music playback.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-25c8-fmh2-q3pg

больше 4 лет назад

IBM WebSphere Message Broker 6.1.x before 6.1.0.2 writes a database connection password to the Event Log and System Log during exception handling for a JDBC error, which allows local users to obtain sensitive information by reading these logs.

EPSS: Низкий
github логотип

GHSA-25c8-fc6x-9x37

5 месяцев назад

Insecure deserialization of untrusted input in StellarGroup HPX 1.11.0 under certain conditions may allow attackers to execute arbitrary code or other unspecified impacts.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-25c7-67gf-gc43

больше 4 лет назад

A URL redirection to untrusted site vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow URL redirection to untrusted site.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-25c7-5442-g7pq

больше 4 лет назад

Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.1.10111, does not properly restrict access to memory associated with unmanaged objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, (3) a crafted .NET Framework application, or (4) a crafted Silverlight application, aka ".NET Framework Unmanaged Objects Vulnerability."

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-25c7-47pw-x5cf

больше 1 года назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

EPSS: Низкий
github логотип

GHSA-25c5-9pxc-899f

больше 4 лет назад

index.php in WebMplayer before 0.6.1-Alpha allows remote attackers to execute arbitrary code via shell metacharacters in an exec function call. NOTE: some sources have referred to this as eval injection in the param parameter, but CVE source inspection suggests that this is erroneous.

EPSS: Низкий
github логотип

GHSA-25c5-5c5w-53xq

больше 4 лет назад

Sophos Anti-Virus before 4.02, 4.5.x before 4.5.9, 4.6.x before 4.6.9, and 5.x before 5.1.4 allow remote attackers to hide arbitrary files and data via crafted ARJ archives, which are not properly scanned.

EPSS: Низкий
github логотип

GHSA-25c5-58xw-hw5q

больше 4 лет назад

Jenkins allows Remote Users to Build Arbitrary Jobs

EPSS: Низкий
github логотип

GHSA-25c3-h67j-g2qq

почти 4 года назад

Insufficient data validation in Directory in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass file system restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-25c3-7fvj-v45j

больше 3 лет назад

phpMyFAQ Stored Cross-site Scripting vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-25c3-4v7x-3hrp

больше 2 лет назад

A vulnerability, which was classified as critical, was found in openBI up to 6.0.3. Affected is the function addxinzhi of the file application/controllers/User.php of the component Phar Handler. The manipulation of the argument outimgurl leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252696.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-25c3-3rg2-gf39

больше 4 лет назад

In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the WSubStr function (provided by the scripting engine) allows an attacker to cause a denial of service by crashing the application.

EPSS: Низкий
github логотип

GHSA-259x-xg45-mf97

6 месяцев назад

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/incoming.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-259x-wgj2-g49m

больше 4 лет назад

Unspecified vulnerability in Sun Java System Application Server 7 2004Q2 before Update 6, Web Server 6.1 before SP8, and Web Server 7.0 before Update 1 allows remote attackers to obtain source code of JSP files via unknown vectors.

EPSS: Низкий
github логотип

GHSA-259x-v826-2fcj

больше 4 лет назад

IBM SPSS Modeler 16.0 before 16.0.0.1 on UNIX does not properly drop group privileges, which allows local users to bypass intended file-access restrictions by leveraging (1) gid 0 or (2) root's group memberships.

EPSS: Низкий
github логотип

GHSA-259w-fqv8-xvgh

больше 4 лет назад

Acronis True Image prior to 2021 Update 4 for Windows allowed local privilege escalation due to improper soft link handling (issue 1 of 2).

EPSS: Низкий
github логотип

GHSA-259w-8hf6-59c2

больше 3 лет назад

OCI image importer memory exhaustion in github.com/containerd/containerd

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-259w-3jff-442h

11 месяцев назад

The PixelYourSite WordPress plugin before 11.1.2 does not validate some URL parameters before using them to generate paths passed to function/s, allowing any admins to perform LFI attacks

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-259v-xm34-p7fr

больше 2 лет назад

Typo3 Cross-Site Scripting in Language Pack Handling

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-25c8-fq6j-8vvf

Memory corruption while processing MFC channel configuration during music playback.

CVSS3: 7.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-25c8-fmh2-q3pg

IBM WebSphere Message Broker 6.1.x before 6.1.0.2 writes a database connection password to the Event Log and System Log during exception handling for a JDBC error, which allows local users to obtain sensitive information by reading these logs.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-25c8-fc6x-9x37

Insecure deserialization of untrusted input in StellarGroup HPX 1.11.0 under certain conditions may allow attackers to execute arbitrary code or other unspecified impacts.

CVSS3: 9.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-25c7-67gf-gc43

A URL redirection to untrusted site vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow URL redirection to untrusted site.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-25c7-5442-g7pq

Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.1.10111, does not properly restrict access to memory associated with unmanaged objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, (3) a crafted .NET Framework application, or (4) a crafted Silverlight application, aka ".NET Framework Unmanaged Objects Vulnerability."

CVSS3: 7.8
28%
Средний
больше 4 лет назад
github логотип
GHSA-25c7-47pw-x5cf

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

больше 1 года назад
github логотип
GHSA-25c5-9pxc-899f

index.php in WebMplayer before 0.6.1-Alpha allows remote attackers to execute arbitrary code via shell metacharacters in an exec function call. NOTE: some sources have referred to this as eval injection in the param parameter, but CVE source inspection suggests that this is erroneous.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-25c5-5c5w-53xq

Sophos Anti-Virus before 4.02, 4.5.x before 4.5.9, 4.6.x before 4.6.9, and 5.x before 5.1.4 allow remote attackers to hide arbitrary files and data via crafted ARJ archives, which are not properly scanned.

8%
Низкий
больше 4 лет назад
github логотип
GHSA-25c5-58xw-hw5q

Jenkins allows Remote Users to Build Arbitrary Jobs

2%
Низкий
больше 4 лет назад
github логотип
GHSA-25c3-h67j-g2qq

Insufficient data validation in Directory in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass file system restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 8.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-25c3-7fvj-v45j

phpMyFAQ Stored Cross-site Scripting vulnerability

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-25c3-4v7x-3hrp

A vulnerability, which was classified as critical, was found in openBI up to 6.0.3. Affected is the function addxinzhi of the file application/controllers/User.php of the component Phar Handler. The manipulation of the argument outimgurl leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252696.

CVSS3: 6.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-25c3-3rg2-gf39

In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the WSubStr function (provided by the scripting engine) allows an attacker to cause a denial of service by crashing the application.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-259x-xg45-mf97

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/incoming.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.

CVSS3: 6.4
0%
Низкий
6 месяцев назад
github логотип
GHSA-259x-wgj2-g49m

Unspecified vulnerability in Sun Java System Application Server 7 2004Q2 before Update 6, Web Server 6.1 before SP8, and Web Server 7.0 before Update 1 allows remote attackers to obtain source code of JSP files via unknown vectors.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-259x-v826-2fcj

IBM SPSS Modeler 16.0 before 16.0.0.1 on UNIX does not properly drop group privileges, which allows local users to bypass intended file-access restrictions by leveraging (1) gid 0 or (2) root's group memberships.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-259w-fqv8-xvgh

Acronis True Image prior to 2021 Update 4 for Windows allowed local privilege escalation due to improper soft link handling (issue 1 of 2).

0%
Низкий
больше 4 лет назад
github логотип
GHSA-259w-8hf6-59c2

OCI image importer memory exhaustion in github.com/containerd/containerd

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-259w-3jff-442h

The PixelYourSite WordPress plugin before 11.1.2 does not validate some URL parameters before using them to generate paths passed to function/s, allowing any admins to perform LFI attacks

CVSS3: 2.7
0%
Низкий
11 месяцев назад
github логотип
GHSA-259v-xm34-p7fr

Typo3 Cross-Site Scripting in Language Pack Handling

больше 2 лет назад

Уязвимостей на страницу