Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 628

Количество 355 628

github логотип

GHSA-xqjp-6x3w-8653

около 1 года назад

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-xqjm-27pc-rvwm

около 2 месяцев назад

@actual-app/web has CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-xqjj-ffgq-m3mf

около 4 лет назад

WebKit in Apple Safari before 6.0 does not properly handle drag-and-drop events, which allows user-assisted remote attackers to read arbitrary files via a crafted web site.

EPSS: Низкий
github логотип

GHSA-xqjh-g9rv-vg4c

6 месяцев назад

Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xqjh-59ww-r864

больше 1 года назад

A vulnerability, which was classified as critical, was found in PCMan FTP Server 2.0.7. Affected is an unknown function of the component MKDIR Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xqjg-gmg7-72xr

почти 2 года назад

Inappropriate implementation in UI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xqjg-5cv9-m2h7

больше 4 лет назад

The TCP implementation in Sun Solaris 8, 9, and 10 before 20060726 allows remote attackers to cause a denial of service (resource exhaustion) via a TCP packet with an incorrect sequence number, which triggers an ACK storm.

EPSS: Низкий
github логотип

GHSA-xqjg-324c-5xg7

около 4 лет назад

The web services APIs in Eucalyptus 2.0 through 3.4.1 allow remote attackers to cause a denial of service via vectors related to the "network connection clean up code" and (1) Cloud Controller (CLC), (2) Walrus, (3) Storage Controller (SC), and (4) VMware Broker (VB).

EPSS: Низкий
github логотип

GHSA-xqjf-pcpj-x9v7

около 4 лет назад

Insecure method vulnerability in Sina Inc. DLoader Class ActiveX Control allows remote attackers to overwrite arbitrary files via a URL in the first parameter to the DonwloadAndInstall method. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-xqjf-h57w-hh6f

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: mm/slub: Avoid list corruption when removing a slab from the full list Boot with slub_debug=UFPZ. If allocated object failed in alloc_consistency_checks, all objects of the slab will be marked as used, and then the slab will be removed from the partial list. When an object belonging to the slab got freed later, the remove_full() function is called. Because the slab is neither on the partial list nor on the full list, it eventually lead to a list corruption (actually a list poison being detected). So we need to mark and isolate the slab page with metadata corruption, do not put it back in circulation. Because the debug caches avoid all the fastpaths, reusing the frozen bit to mark slab page with metadata corruption seems to be fine. [ 4277.385669] list_del corruption, ffffea00044b3e50->next is LIST_POISON1 (dead000000000100) [ 4277.387023] ------------[ cut here ]------------ [ 4277.387880] kernel BUG at lib/l...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xqjc-xm8j-3445

около 4 лет назад

A vulnerability classified as problematic was found in Solare Solar-Log 2.8.4-56/3.5.2-85. Affected by this vulnerability is an unknown functionality of the component Config Handler. The manipulation leads to information disclosure. The attack can be launched remotely. Upgrading to version 3.5.3-86 is able to address this issue. It is recommended to upgrade the affected component.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xqjc-xc2g-945f

больше 4 лет назад

The FlexGrid ActiveX control in Microsoft Visual Basic 6.0, Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2, Office FrontPage 2002 SP3, and Office Project 2003 SP3 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to corruption of the "system state," aka "FlexGrid Control Memory Corruption Vulnerability."

EPSS: Средний
github логотип

GHSA-xqjc-v8pq-qh2x

больше 4 лет назад

Possible assertion in QOS request due to improper validation when multiple add or update request are received simultaneously in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

EPSS: Низкий
github логотип

GHSA-xqj9-9cw6-3p8v

около 1 года назад

A vulnerability was reported in version 1.0 of the Bluetooth Transmission Alliance protocol adopted by Motorola Smart Connect Android Application that could allow a nearby attacker within the Bluetooth interaction range to intercept files when transferred to a device not paired in Smart Connect.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-xqj8-j5cp-c427

около 4 лет назад

IBM API Connect 5.0.0.0 could allow a user to bypass policy restrictions and create non-compliant passwords which could be intercepted and decrypted using man in the middle techniques. IBM X-Force ID: 127160.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xqj7-j8j5-f2xr

почти 8 лет назад

Bouncy Castle has a flaw in the Low-level interface to RSA key pair generator

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xqj5-x7c8-6f4h

около 4 лет назад

Uncontrolled search path in software installer for Intel(R) PROSet/Wireless WiFi in Windows 10 may allow an authenticated user to potentially enable escalation of privilege via local access.

EPSS: Низкий
github логотип

GHSA-xqj5-wxw2-5ww9

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saturday Drive Ninja Forms allows Stored XSS.This issue affects Ninja Forms: from n/a through 3.8.16.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xqj5-jf43-pwhr

больше 4 лет назад

Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is related to XNewPtr and improper handling of an integer parameter when allocating heap memory in the com.sun.media.sound libraries, which allows remote attackers to execute arbitrary code.

EPSS: Низкий
github логотип

GHSA-xqj5-4q2p-7gm5

больше 3 лет назад

Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability

CVSS3: 7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xqjp-6x3w-8653

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVSS3: 8.4
1%
Низкий
около 1 года назад
github логотип
GHSA-xqjm-27pc-rvwm

@actual-app/web has CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields

CVSS3: 4.2
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xqjj-ffgq-m3mf

WebKit in Apple Safari before 6.0 does not properly handle drag-and-drop events, which allows user-assisted remote attackers to read arbitrary files via a crafted web site.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xqjh-g9rv-vg4c

Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools.

CVSS3: 7.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-xqjh-59ww-r864

A vulnerability, which was classified as critical, was found in PCMan FTP Server 2.0.7. Affected is an unknown function of the component MKDIR Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-xqjg-gmg7-72xr

Inappropriate implementation in UI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 4.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-xqjg-5cv9-m2h7

The TCP implementation in Sun Solaris 8, 9, and 10 before 20060726 allows remote attackers to cause a denial of service (resource exhaustion) via a TCP packet with an incorrect sequence number, which triggers an ACK storm.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xqjg-324c-5xg7

The web services APIs in Eucalyptus 2.0 through 3.4.1 allow remote attackers to cause a denial of service via vectors related to the "network connection clean up code" and (1) Cloud Controller (CLC), (2) Walrus, (3) Storage Controller (SC), and (4) VMware Broker (VB).

1%
Низкий
около 4 лет назад
github логотип
GHSA-xqjf-pcpj-x9v7

Insecure method vulnerability in Sina Inc. DLoader Class ActiveX Control allows remote attackers to overwrite arbitrary files via a URL in the first parameter to the DonwloadAndInstall method. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xqjf-h57w-hh6f

In the Linux kernel, the following vulnerability has been resolved: mm/slub: Avoid list corruption when removing a slab from the full list Boot with slub_debug=UFPZ. If allocated object failed in alloc_consistency_checks, all objects of the slab will be marked as used, and then the slab will be removed from the partial list. When an object belonging to the slab got freed later, the remove_full() function is called. Because the slab is neither on the partial list nor on the full list, it eventually lead to a list corruption (actually a list poison being detected). So we need to mark and isolate the slab page with metadata corruption, do not put it back in circulation. Because the debug caches avoid all the fastpaths, reusing the frozen bit to mark slab page with metadata corruption seems to be fine. [ 4277.385669] list_del corruption, ffffea00044b3e50->next is LIST_POISON1 (dead000000000100) [ 4277.387023] ------------[ cut here ]------------ [ 4277.387880] kernel BUG at lib/l...

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xqjc-xm8j-3445

A vulnerability classified as problematic was found in Solare Solar-Log 2.8.4-56/3.5.2-85. Affected by this vulnerability is an unknown functionality of the component Config Handler. The manipulation leads to information disclosure. The attack can be launched remotely. Upgrading to version 3.5.3-86 is able to address this issue. It is recommended to upgrade the affected component.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xqjc-xc2g-945f

The FlexGrid ActiveX control in Microsoft Visual Basic 6.0, Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2, Office FrontPage 2002 SP3, and Office Project 2003 SP3 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to corruption of the "system state," aka "FlexGrid Control Memory Corruption Vulnerability."

21%
Средний
больше 4 лет назад
github логотип
GHSA-xqjc-v8pq-qh2x

Possible assertion in QOS request due to improper validation when multiple add or update request are received simultaneously in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xqj9-9cw6-3p8v

A vulnerability was reported in version 1.0 of the Bluetooth Transmission Alliance protocol adopted by Motorola Smart Connect Android Application that could allow a nearby attacker within the Bluetooth interaction range to intercept files when transferred to a device not paired in Smart Connect.

CVSS3: 3.5
0%
Низкий
около 1 года назад
github логотип
GHSA-xqj8-j5cp-c427

IBM API Connect 5.0.0.0 could allow a user to bypass policy restrictions and create non-compliant passwords which could be intercepted and decrypted using man in the middle techniques. IBM X-Force ID: 127160.

CVSS3: 5.9
1%
Низкий
около 4 лет назад
github логотип
GHSA-xqj7-j8j5-f2xr

Bouncy Castle has a flaw in the Low-level interface to RSA key pair generator

CVSS3: 7.5
4%
Низкий
почти 8 лет назад
github логотип
GHSA-xqj5-x7c8-6f4h

Uncontrolled search path in software installer for Intel(R) PROSet/Wireless WiFi in Windows 10 may allow an authenticated user to potentially enable escalation of privilege via local access.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xqj5-wxw2-5ww9

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saturday Drive Ninja Forms allows Stored XSS.This issue affects Ninja Forms: from n/a through 3.8.16.

CVSS3: 5.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-xqj5-jf43-pwhr

Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is related to XNewPtr and improper handling of an integer parameter when allocating heap memory in the com.sun.media.sound libraries, which allows remote attackers to execute arbitrary code.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-xqj5-4q2p-7gm5

Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability

CVSS3: 7
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу