Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 374 825

Количество 374 825

github логотип

GHSA-24cv-mgp7-4xjv

больше 4 лет назад

FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-24cr-vx4r-gqr6

16 дней назад

AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the EPG parser that allows authenticated uploaders to fetch arbitrary internal URLs. An attacker can supply an internal URL via the epg_link parameter during video upload, which is validated only for syntax and later fetched server-side during EPG generation without SSRF protection checks.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-24cr-7gmf-xxwh

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921: fix kernel panic due to null pointer dereference Address a kernel panic caused by a null pointer dereference in the `mt792x_rx_get_wcid` function. The issue arises because the `deflink` structure is not properly initialized with the `sta` context. This patch ensures that the `deflink` structure is correctly linked to the `sta` context, preventing the null pointer dereference. BUG: kernel NULL pointer dereference, address: 0000000000000400 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page PGD 0 P4D 0 Oops: Oops: 0000 [#1] PREEMPT SMP NOPTI CPU: 0 UID: 0 PID: 470 Comm: mt76-usb-rx phy Not tainted 6.12.13-gentoo-dist #1 Hardware name: /AMD HUDSON-M1, BIOS 4.6.4 11/15/2011 RIP: 0010:mt792x_rx_get_wcid+0x48/0x140 [mt792x_lib] RSP: 0018:ffffa147c055fd98 EFLAGS: 00010202 RAX: 0000000000000000 RBX: ffff8e9ecb652000 RCX: 0000000000000000 RDX: 000000000000...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-24cr-56gf-fx38

около 3 лет назад

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-24cq-x4xw-49mr

больше 4 лет назад

Skybox Manager Client Application prior to 8.5.501 is prone to an arbitrary file upload vulnerability due to insufficient input validation of user-supplied files path when uploading files via the application. During a debugger-pause state, a local authenticated attacker can upload an arbitrary file and overwrite existing files within the scope of the affected application.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-24cq-pjqj-w96x

больше 2 лет назад

An issue in Otakara lapis totuka mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-24cq-5jcg-gqj5

около 3 лет назад

A path traversal vulnerability in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-24cp-rv65-qm42

больше 4 лет назад

File Deletion vulnerability in Halo 0.4.3 via delBackup.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-24cp-26gx-3pp4

больше 4 лет назад

The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka "ImageTragick."

CVSS3: 8.4
EPSS: Критический
github логотип

GHSA-24cm-p92g-3mhv

больше 4 лет назад

Unspecified vulnerability in Oracle Java SE 7u85 and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality via unknown vectors related to 2D.

EPSS: Низкий
github логотип

GHSA-24cm-983f-gmgx

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CantonBolo WordPress 淘宝客插件 allows Reflected XSS. This issue affects WordPress 淘宝客插件: from n/a through 1.1.2.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-24cj-jcg7-v9g9

больше 4 лет назад

SQL injection vulnerability in include.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

EPSS: Низкий
github логотип

GHSA-24ch-w38v-xmh8

около 1 года назад

Juju zip slip vulnerability via authenticated endpoint

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-24ch-r26p-7c3f

больше 4 лет назад

Unspecified vulnerability in Oracle Java SE 7u45 and JavaFX 2.2.45 allows remote attackers to affect availability via unknown vectors related to JavaFX.

EPSS: Низкий
github логотип

GHSA-24cg-f7cp-3vmv

больше 4 лет назад

Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-24cf-848g-762c

больше 1 года назад

ShopXO Vulnerable to Server-Side Request Forgery (SSRF) and Cross-Site Scripting (XSS)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-24cc-98rp-8qhg

больше 4 лет назад

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 10.1.3.37598. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D objects embedded in PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-13574.

EPSS: Низкий
github логотип

GHSA-24cc-5mgg-6xch

больше 4 лет назад

SQL injection vulnerability in include/functions_trackbacks.inc.php in Serendipity 1.6.2 allows remote attackers to execute arbitrary SQL commands via the url parameter to comment.php.

EPSS: Низкий
github логотип

GHSA-24c9-h3qq-j27f

5 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in __ksmbd_close_fd() via durable scavenger When a durable file handle survives session disconnect (TCP close without SMB2_LOGOFF), session_fd_check() sets fp->conn = NULL to preserve the handle for later reconnection. However, it did not clean up the byte-range locks on fp->lock_list. Later, when the durable scavenger thread times out and calls __ksmbd_close_fd(NULL, fp), the lock cleanup loop did: spin_lock(&fp->conn->llist_lock); This caused a slab use-after-free because fp->conn was NULL and the original connection object had already been freed by ksmbd_tcp_disconnect(). The root cause is asymmetric cleanup: lock entries (smb_lock->clist) were left dangling on the freed conn->lock_list while fp->conn was nulled out. To fix this issue properly, we need to handle the lifetime of smb_lock->clist across three paths: - Safely skip clist deletion when list is empty and fp->conn is...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-24c9-7g9h-vmm8

больше 4 лет назад

Multiple stack-based buffer overflows in EpicDJSoftware EpicVJ 1.2.8.0 and 1.3.1.2 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a (1) .m3u or (2) .mpl playlist file.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-24cv-mgp7-4xjv

FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.

CVSS3: 9.8
29%
Средний
больше 4 лет назад
github логотип
GHSA-24cr-vx4r-gqr6

AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the EPG parser that allows authenticated uploaders to fetch arbitrary internal URLs. An attacker can supply an internal URL via the epg_link parameter during video upload, which is validated only for syntax and later fetched server-side during EPG generation without SSRF protection checks.

CVSS3: 6.5
0%
Низкий
16 дней назад
github логотип
GHSA-24cr-7gmf-xxwh

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921: fix kernel panic due to null pointer dereference Address a kernel panic caused by a null pointer dereference in the `mt792x_rx_get_wcid` function. The issue arises because the `deflink` structure is not properly initialized with the `sta` context. This patch ensures that the `deflink` structure is correctly linked to the `sta` context, preventing the null pointer dereference. BUG: kernel NULL pointer dereference, address: 0000000000000400 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page PGD 0 P4D 0 Oops: Oops: 0000 [#1] PREEMPT SMP NOPTI CPU: 0 UID: 0 PID: 470 Comm: mt76-usb-rx phy Not tainted 6.12.13-gentoo-dist #1 Hardware name: /AMD HUDSON-M1, BIOS 4.6.4 11/15/2011 RIP: 0010:mt792x_rx_get_wcid+0x48/0x140 [mt792x_lib] RSP: 0018:ffffa147c055fd98 EFLAGS: 00010202 RAX: 0000000000000000 RBX: ffff8e9ecb652000 RCX: 0000000000000000 RDX: 000000000000...

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-24cr-56gf-fx38

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

CVSS3: 8.2
1%
Низкий
около 3 лет назад
github логотип
GHSA-24cq-x4xw-49mr

Skybox Manager Client Application prior to 8.5.501 is prone to an arbitrary file upload vulnerability due to insufficient input validation of user-supplied files path when uploading files via the application. During a debugger-pause state, a local authenticated attacker can upload an arbitrary file and overwrite existing files within the scope of the affected application.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-24cq-pjqj-w96x

An issue in Otakara lapis totuka mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-24cq-5jcg-gqj5

A path traversal vulnerability in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-24cp-rv65-qm42

File Deletion vulnerability in Halo 0.4.3 via delBackup.

CVSS3: 9.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-24cp-26gx-3pp4

The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka "ImageTragick."

CVSS3: 8.4
97%
Критический
больше 4 лет назад
github логотип
GHSA-24cm-p92g-3mhv

Unspecified vulnerability in Oracle Java SE 7u85 and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality via unknown vectors related to 2D.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-24cm-983f-gmgx

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CantonBolo WordPress 淘宝客插件 allows Reflected XSS. This issue affects WordPress 淘宝客插件: from n/a through 1.1.2.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-24cj-jcg7-v9g9

SQL injection vulnerability in include.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-24ch-w38v-xmh8

Juju zip slip vulnerability via authenticated endpoint

CVSS3: 8.8
1%
Низкий
около 1 года назад
github логотип
GHSA-24ch-r26p-7c3f

Unspecified vulnerability in Oracle Java SE 7u45 and JavaFX 2.2.45 allows remote attackers to affect availability via unknown vectors related to JavaFX.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-24cg-f7cp-3vmv

Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

CVSS3: 7.8
14%
Средний
больше 4 лет назад
github логотип
GHSA-24cf-848g-762c

ShopXO Vulnerable to Server-Side Request Forgery (SSRF) and Cross-Site Scripting (XSS)

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-24cc-98rp-8qhg

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 10.1.3.37598. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of U3D objects embedded in PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-13574.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-24cc-5mgg-6xch

SQL injection vulnerability in include/functions_trackbacks.inc.php in Serendipity 1.6.2 allows remote attackers to execute arbitrary SQL commands via the url parameter to comment.php.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-24c9-h3qq-j27f

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in __ksmbd_close_fd() via durable scavenger When a durable file handle survives session disconnect (TCP close without SMB2_LOGOFF), session_fd_check() sets fp->conn = NULL to preserve the handle for later reconnection. However, it did not clean up the byte-range locks on fp->lock_list. Later, when the durable scavenger thread times out and calls __ksmbd_close_fd(NULL, fp), the lock cleanup loop did: spin_lock(&fp->conn->llist_lock); This caused a slab use-after-free because fp->conn was NULL and the original connection object had already been freed by ksmbd_tcp_disconnect(). The root cause is asymmetric cleanup: lock entries (smb_lock->clist) were left dangling on the freed conn->lock_list while fp->conn was nulled out. To fix this issue properly, we need to handle the lifetime of smb_lock->clist across three paths: - Safely skip clist deletion when list is empty and fp->conn is...

CVSS3: 9.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-24c9-7g9h-vmm8

Multiple stack-based buffer overflows in EpicDJSoftware EpicVJ 1.2.8.0 and 1.3.1.2 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a (1) .m3u or (2) .mpl playlist file.

6%
Низкий
больше 4 лет назад

Уязвимостей на страницу