Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 628

Количество 355 628

github логотип

GHSA-xqf3-q69c-jc7c

больше 1 года назад

Silicon Labs Z-Wave Series 500 v6.84.0 was discovered to contain insecure permissions.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-xqf3-q2jh-qp3h

больше 3 лет назад

Uncontrolled search path element in the Intel(R) FPGA Add-on for Intel(R) oneAPI Base Toolkit before version 2022.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xqf2-wg33-4hp8

19 дней назад

Data::DisjointSet::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in dsu.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable). O_NOFOLLOW is absent, so a symlink planted at the path is followed, and O_EXCL is absent, so the open silently uses a pre-planted file instead of failing. A "Shared" segment naturally lives in a shared directory such as /tmp or /dev/shm, where any local user can read the IPC payloads stored in the world-readable segment, and a pre-planted file or symlink at the path lets a local attacker win a pre-creation race or redirect the open.

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-xqcx-wqc2-rjfv

больше 4 лет назад

SQL injection vulnerability in index.php in Eclectic Designs CascadianFAQ 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the qid parameter, a different vector than CVE-2007-0631. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-xqcx-6mm2-fv2j

больше 2 лет назад

In Abbott ID NOW before 7.1, settings can be modified via physical access to an internal serial port.

CVSS3: 5.2
EPSS: Низкий
github логотип

GHSA-xqcw-gm88-2753

около 4 лет назад

Unrestricted file upload vulnerability in Micro Focus ArcSight Logger, version 6.7.0 and later. This vulnerability could allow Unrestricted Upload of File with Dangerous type.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xqcv-p45j-c72q

почти 3 года назад

A remote unprivileged attacker can sent multiple packages to the LMS5xx to disrupt its availability through a TCP SYN-based denial-of-service (DDoS) attack. By exploiting this vulnerability, an attacker can flood the targeted LMS5xx with a high volume of TCP SYN requests, overwhelming its resources and causing it to become unresponsive or unavailable for legitimate users.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xqcv-fgfh-v26g

около 4 лет назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

EPSS: Низкий
github логотип

GHSA-xqcr-vmvx-c673

около 4 лет назад

SolarWinds Serv-U FTP server before 15.2.1 allows remote command execution.

EPSS: Низкий
github логотип

GHSA-xqcr-r97c-wq7p

8 месяцев назад

Textpattern CMS 4.8.8 contains a stored cross-site scripting vulnerability in the article excerpt field that allows authenticated users to inject malicious scripts. Attackers can insert JavaScript payloads into the excerpt, which will execute when the article is viewed by other users.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-xqcq-xphx-4p87

около 4 лет назад

Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xqcq-j8w9-3pxv

около 3 лет назад

Jettison parser crash by stackoverflow

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xqcp-x2j9-xj7c

около 4 лет назад

XML external entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect CloudHub, GovCloud, Runtime Fabric, Pivotal Cloud Foundry, Private Cloud Edition, and on-premise customers.

EPSS: Низкий
github логотип

GHSA-xqcp-jqmf-35jv

около 4 лет назад

A remote information disclosure vulnerability in HPE Matrix Operating Environment version v7.6 was found.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xqcp-9p67-2j64

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix memory leak when using fscache If we hit the 'index == next_cached' case, we leak a refcount on the struct page. Fix this by using readahead_folio() which takes care of the refcount for you.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xqcp-4jqv-37rh

больше 2 лет назад

The unauthenticated attacker in NetWeaver AS Java Logon application - version 7.50, can brute force the login functionality to identify the legitimate user ids. This will have an impact on confidentiality but there is no other impact on integrity or availability.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xqcm-xjf8-jp3p

около 4 лет назад

Multiple buffer overflows in the Pdf Printer Preferences ActiveX Control in pdfxctrl.dll in Tracker Software PDF-XChange 3.60.0128 allow remote attackers to execute arbitrary code via a long string in the (1) sub_path parameter to the StoreInRegistry function or (2) sub_key parameter to the InitFromRegistry function.

EPSS: Низкий
github логотип

GHSA-xqcm-jrw9-wq72

6 месяцев назад

A flaw was found in Dropbear. When running in multi-user mode and authenticating users, the dropbear ssh server does the socket forwardings requested by the remote client as root, only switching to the logged-in user upon spawning a shell or performing some operations like reading the user's files. With the recent ability of also using unix domain sockets as the forwarding destination any user able to log in via ssh can connect to any unix socket with the root's credentials, bypassing both file system restrictions and any SO_PEERCRED / SO_PASSCRED checks performed by the peer.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xqcm-7p74-m69m

около 1 года назад

The Restrict File Access plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the 'restrict-file-access' page. This makes it possible for unauthenticated attackers to to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php), via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xqcj-wpcf-8vvg

около 4 лет назад

CoreText in Apple iOS before 9.1, OS X before 10.11.1, and iTunes before 12.3.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6992 and CVE-2015-7017.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xqf3-q69c-jc7c

Silicon Labs Z-Wave Series 500 v6.84.0 was discovered to contain insecure permissions.

CVSS3: 4.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-xqf3-q2jh-qp3h

Uncontrolled search path element in the Intel(R) FPGA Add-on for Intel(R) oneAPI Base Toolkit before version 2022.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 7.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xqf2-wg33-4hp8

Data::DisjointSet::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in dsu.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created mode 0644 (world-readable). O_NOFOLLOW is absent, so a symlink planted at the path is followed, and O_EXCL is absent, so the open silently uses a pre-planted file instead of failing. A "Shared" segment naturally lives in a shared directory such as /tmp or /dev/shm, where any local user can read the IPC payloads stored in the world-readable segment, and a pre-planted file or symlink at the path lets a local attacker win a pre-creation race or redirect the open.

CVSS3: 4
0%
Низкий
19 дней назад
github логотип
GHSA-xqcx-wqc2-rjfv

SQL injection vulnerability in index.php in Eclectic Designs CascadianFAQ 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the qid parameter, a different vector than CVE-2007-0631. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xqcx-6mm2-fv2j

In Abbott ID NOW before 7.1, settings can be modified via physical access to an internal serial port.

CVSS3: 5.2
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xqcw-gm88-2753

Unrestricted file upload vulnerability in Micro Focus ArcSight Logger, version 6.7.0 and later. This vulnerability could allow Unrestricted Upload of File with Dangerous type.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-xqcv-p45j-c72q

A remote unprivileged attacker can sent multiple packages to the LMS5xx to disrupt its availability through a TCP SYN-based denial-of-service (DDoS) attack. By exploiting this vulnerability, an attacker can flood the targeted LMS5xx with a high volume of TCP SYN requests, overwhelming its resources and causing it to become unresponsive or unavailable for legitimate users.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-xqcv-fgfh-v26g

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

2%
Низкий
около 4 лет назад
github логотип
GHSA-xqcr-vmvx-c673

SolarWinds Serv-U FTP server before 15.2.1 allows remote command execution.

7%
Низкий
около 4 лет назад
github логотип
GHSA-xqcr-r97c-wq7p

Textpattern CMS 4.8.8 contains a stored cross-site scripting vulnerability in the article excerpt field that allows authenticated users to inject malicious scripts. Attackers can insert JavaScript payloads into the excerpt, which will execute when the article is viewed by other users.

CVSS3: 4.6
0%
Низкий
8 месяцев назад
github логотип
GHSA-xqcq-xphx-4p87

Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.

CVSS3: 6.1
2%
Низкий
около 4 лет назад
github логотип
GHSA-xqcq-j8w9-3pxv

Jettison parser crash by stackoverflow

CVSS3: 6.5
около 3 лет назад
github логотип
GHSA-xqcp-x2j9-xj7c

XML external entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect CloudHub, GovCloud, Runtime Fabric, Pivotal Cloud Foundry, Private Cloud Edition, and on-premise customers.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xqcp-jqmf-35jv

A remote information disclosure vulnerability in HPE Matrix Operating Environment version v7.6 was found.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xqcp-9p67-2j64

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix memory leak when using fscache If we hit the 'index == next_cached' case, we leak a refcount on the struct page. Fix this by using readahead_folio() which takes care of the refcount for you.

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-xqcp-4jqv-37rh

The unauthenticated attacker in NetWeaver AS Java Logon application - version 7.50, can brute force the login functionality to identify the legitimate user ids. This will have an impact on confidentiality but there is no other impact on integrity or availability.

CVSS3: 5.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xqcm-xjf8-jp3p

Multiple buffer overflows in the Pdf Printer Preferences ActiveX Control in pdfxctrl.dll in Tracker Software PDF-XChange 3.60.0128 allow remote attackers to execute arbitrary code via a long string in the (1) sub_path parameter to the StoreInRegistry function or (2) sub_key parameter to the InitFromRegistry function.

6%
Низкий
около 4 лет назад
github логотип
GHSA-xqcm-jrw9-wq72

A flaw was found in Dropbear. When running in multi-user mode and authenticating users, the dropbear ssh server does the socket forwardings requested by the remote client as root, only switching to the logged-in user upon spawning a shell or performing some operations like reading the user's files. With the recent ability of also using unix domain sockets as the forwarding destination any user able to log in via ssh can connect to any unix socket with the root's credentials, bypassing both file system restrictions and any SO_PEERCRED / SO_PASSCRED checks performed by the peer.

CVSS3: 5.4
0%
Низкий
6 месяцев назад
github логотип
GHSA-xqcm-7p74-m69m

The Restrict File Access plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the 'restrict-file-access' page. This makes it possible for unauthenticated attackers to to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php), via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 8.1
0%
Низкий
около 1 года назад
github логотип
GHSA-xqcj-wpcf-8vvg

CoreText in Apple iOS before 9.1, OS X before 10.11.1, and iTunes before 12.3.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6992 and CVE-2015-7017.

4%
Низкий
около 4 лет назад

Уязвимостей на страницу