Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 268

Количество 375 268

github логотип

GHSA-255v-hc9m-54wv

9 месяцев назад

Missing Authorization vulnerability in merkulove Laser laser allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Laser: from n/a through <= 1.1.1.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-255v-grg6-24pg

около 3 лет назад

MotoCMS Version 3.4.3 Store Category Template was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the keyword parameter.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-255v-ffqg-5w87

почти 4 года назад

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/?page=appointments/view_appointment.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-255v-3pqf-6g77

около 1 месяца назад

Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-255r-pghp-r5wh

около 6 лет назад

Malicious Package in hdeky

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-255r-gqmx-m2jm

около 2 месяцев назад

A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through deep alias nesting, can lead to corruption of internal program data. This corruption could potentially enable a local attacker to execute arbitrary code if the host application then unsafely processes the altered data.

CVSS3: 2.5
EPSS: Низкий
github логотип

GHSA-255r-f4p7-p9r5

больше 4 лет назад

Hacksoft The Hacker 6.3.1.2.174 and possibly 6.3.0.9.081, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.

EPSS: Низкий
github логотип

GHSA-255r-96jc-w7r6

3 месяца назад

DVP80ES300T with Improper Validation of Array Index Vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-255r-3prx-mf99

больше 3 лет назад

`rmp-serde` `Raw` and `RawRef` may crash when receiving invalid UTF-8

EPSS: Низкий
github логотип

GHSA-255q-f9p7-jxj6

около 3 лет назад

Microsoft SharePoint Server Spoofing Vulnerability

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-255p-hfwr-9qm4

почти 4 года назад

This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.4. An app with root privileges may be able to access private information.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-255p-hfc6-whjx

больше 4 лет назад

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14021.

EPSS: Низкий
github логотип

GHSA-255m-x7w5-9w65

больше 1 года назад

Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB MATRIX Series.This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-255m-v9ff-ggrc

больше 4 лет назад

The doPayouts() function of the smart contract implementation for MegaCryptoPolis, an Ethereum game, has a Denial of Service vulnerability. If a smart contract that has a fallback function always causing exceptions buys a land, users cannot buy lands near that contract's land, because those purchase attempts will not be completed unless the doPayouts() function successfully sends Ether to certain neighbors.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-255m-r5v7-p5hq

больше 4 лет назад

A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An attacker could exploit this vulnerability by sending a user a malicious ARF or WRF file via a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit could allow the attacker to execute arbitrary code on the affected system.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-255m-8v4r-mcgr

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: tls: stop recv() if initial process_rx_list gave us non-DATA If we have a non-DATA record on the rx_list and another record of the same type still on the queue, we will end up merging them: - process_rx_list copies the non-DATA record - we start the loop and process the first available record since it's of the same type - we break out of the loop since the record was not DATA Just check the record type and jump to the end in case process_rx_list did some work.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-255j-qw47-wjh5

9 месяцев назад

Craft CMS vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior

EPSS: Низкий
github логотип

GHSA-255j-gp8h-r5hh

больше 4 лет назад

The documents application in ownCloud Server 6.x before 6.0.6 and 7.x before 7.0.3 allows remote authenticated users to obtain all valid session IDs via an unspecified API method.

EPSS: Низкий
github логотип

GHSA-255j-5m9h-c8jh

около 4 лет назад

The OpenBook Book Data WordPress plugin through 3.5.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping as well

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-255j-56mh-hp3w

больше 4 лет назад

IBM UrbanCode Deploy (UCD) 6.1 and 6.2 could allow an authenticated user to edit objects that they should not have access to due to improper access controls. IBM X-Force ID: 128691.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-255v-hc9m-54wv

Missing Authorization vulnerability in merkulove Laser laser allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Laser: from n/a through <= 1.1.1.

CVSS3: 5.4
0%
Низкий
9 месяцев назад
github логотип
GHSA-255v-grg6-24pg

MotoCMS Version 3.4.3 Store Category Template was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the keyword parameter.

CVSS3: 9.8
31%
Средний
около 3 лет назад
github логотип
GHSA-255v-ffqg-5w87

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/?page=appointments/view_appointment.

CVSS3: 8.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-255v-3pqf-6g77

Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-255r-pghp-r5wh

Malicious Package in hdeky

CVSS3: 9.1
около 6 лет назад
github логотип
GHSA-255r-gqmx-m2jm

A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through deep alias nesting, can lead to corruption of internal program data. This corruption could potentially enable a local attacker to execute arbitrary code if the host application then unsafely processes the altered data.

CVSS3: 2.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-255r-f4p7-p9r5

Hacksoft The Hacker 6.3.1.2.174 and possibly 6.3.0.9.081, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-255r-96jc-w7r6

DVP80ES300T with Improper Validation of Array Index Vulnerability

CVSS3: 7.5
0%
Низкий
3 месяца назад
github логотип
GHSA-255r-3prx-mf99

`rmp-serde` `Raw` and `RawRef` may crash when receiving invalid UTF-8

больше 3 лет назад
github логотип
GHSA-255q-f9p7-jxj6

Microsoft SharePoint Server Spoofing Vulnerability

CVSS3: 8
2%
Низкий
около 3 лет назад
github логотип
GHSA-255p-hfwr-9qm4

This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.4. An app with root privileges may be able to access private information.

CVSS3: 4.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-255p-hfc6-whjx

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14021.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-255m-x7w5-9w65

Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB MATRIX Series.This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-255m-v9ff-ggrc

The doPayouts() function of the smart contract implementation for MegaCryptoPolis, an Ethereum game, has a Denial of Service vulnerability. If a smart contract that has a fallback function always causing exceptions buys a land, users cannot buy lands near that contract's land, because those purchase attempts will not be completed unless the doPayouts() function successfully sends Ether to certain neighbors.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-255m-r5v7-p5hq

A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An attacker could exploit this vulnerability by sending a user a malicious ARF or WRF file via a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit could allow the attacker to execute arbitrary code on the affected system.

CVSS3: 7.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-255m-8v4r-mcgr

In the Linux kernel, the following vulnerability has been resolved: tls: stop recv() if initial process_rx_list gave us non-DATA If we have a non-DATA record on the rx_list and another record of the same type still on the queue, we will end up merging them: - process_rx_list copies the non-DATA record - we start the loop and process the first available record since it's of the same type - we break out of the loop since the record was not DATA Just check the record type and jump to the end in case process_rx_list did some work.

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-255j-qw47-wjh5

Craft CMS vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior

1%
Низкий
9 месяцев назад
github логотип
GHSA-255j-gp8h-r5hh

The documents application in ownCloud Server 6.x before 6.0.6 and 7.x before 7.0.3 allows remote authenticated users to obtain all valid session IDs via an unspecified API method.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-255j-5m9h-c8jh

The OpenBook Book Data WordPress plugin through 3.5.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping as well

CVSS3: 4.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-255j-56mh-hp3w

IBM UrbanCode Deploy (UCD) 6.1 and 6.2 could allow an authenticated user to edit objects that they should not have access to due to improper access controls. IBM X-Force ID: 128691.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу