Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 628

Количество 355 628

github логотип

GHSA-xq9m-84rg-77f9

около 4 лет назад

Apt 0.8.16~exp5ubuntu13.x before 0.8.16~exp5ubuntu13.6, 0.8.16~exp12ubuntu10.x before 0.8.16~exp12ubuntu10.7, and 0.9.7.5ubuntu5.x before 0.9.7.5ubuntu5.2, as used in Ubuntu, uses world-readable permissions for /var/log/apt/term.log, which allows local users to obtain sensitive shell information by reading the log file.

EPSS: Низкий
github логотип

GHSA-xq9j-rj57-v855

около 4 лет назад

Research Artisan Lite before 1.18 does not ensure that a user has authenticated, which allows remote attackers to perform unspecified actions via unknown vectors.

EPSS: Низкий
github логотип

GHSA-xq9j-r58r-r55p

5 дней назад

A weakness has been identified in Systerel S2OPC up to 1.7.3. This affects the function LockedStaMac_ProcessMsg_DeleteMonitoredItemsResponse of the file src/ClientServer/frontend/client_wrapper/internal/state_machine.c of the component DeleteMonitoredItemsRequest Handler. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-xq9j-g4hv-hg56

около 4 лет назад

Storage Spaces Direct Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-35762, CVE-2022-35763, CVE-2022-35765, CVE-2022-35792.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xq9j-995w-vvw2

больше 4 лет назад

A flaw was found in OpenEXR's Multipart input file functionality. A crafted multi-part input file with no actual parts can trigger a NULL pointer dereference. The highest threat from this vulnerability is to system availability.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xq9h-8fc9-wr6w

больше 4 лет назад

TUTOS 1.3 does not restrict access to php/admin/cmd.php, which allows remote attackers to execute arbitrary shell commands via the cmd parameter in a direct request.

EPSS: Низкий
github логотип

GHSA-xq9g-w4mx-cv7w

5 месяцев назад

Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xq9g-p9vj-39jw

около 4 лет назад

HPE System Management Homepage before 7.5.4 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xq9g-9hx4-3c38

около 4 лет назад

A buffer overflow vulnerability exists in the Microsoft SQL Server that could allow remote code execution on an affected system, aka "Microsoft SQL Server Remote Code Execution Vulnerability." This affects Microsoft SQL Server.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xq9g-8773-5hrq

больше 2 лет назад

D-Link DIR-2640 HNAP LoginPassword Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-2640 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web management interface, which listens on TCP port 80 by default. A specially crafted login request can cause authentication to succeed without providing proper credentials. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-19549.

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-xq9f-gqc7-9v8j

больше 3 лет назад

A vulnerability was found in SourceCodester Online Flight Booking Management System. It has been rated as critical. Affected by this issue is some unknown functionality of the file judge_panel.php. The manipulation of the argument subevent_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-218276.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xq9f-7hxc-qrqx

около 4 лет назад

The “Teacher Edit” function of ShinHer StudyOnline System does not perform authority control. After logging in with user’s privilege, remote attackers can access and edit other users’ credential and personal information by crafting URL parameters.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xq9f-582r-p2j7

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in simple-upload-53.php in CityPost Simple PHP Upload 5.3 allows remote attackers to inject arbitrary web script or HTML via the message parameter.

EPSS: Низкий
github логотип

GHSA-xq9c-7q38-2j2j

больше 4 лет назад

Buffer overflow in Novell NetWare Client 4.80 through 4.83 allows local users to cause a denial of service (crash) by using ping, traceroute, or a similar utility to force the client to resolve a large hostname.

EPSS: Низкий
github логотип

GHSA-xq99-q5xg-8fq7

почти 3 года назад

A vulnerability, which was classified as problematic, has been found in CodeAstro Internet Banking System 1.0. This issue affects some unknown processing of the file pages_view_client.php. The manipulation of the argument acc_name with the input Johnnie Reyes'"()&%<zzz><ScRiPt >alert(5646)</ScRiPt> leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-243137 was assigned to this vulnerability.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-xq99-f7r4-hp52

около 4 лет назад

Tiki before 18.2, 15.7 and 12.14 has XSS via link attributes, related to lib/core/WikiParser/OutputLink.php and lib/parser/parserlib.php.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xq98-x84m-6479

больше 4 лет назад

The setsockopt call in the KAME Project IPv6 implementation, as used in FreeBSD 5.2, does not properly handle certain IPv6 socket options, which could allow attackers to read kernel memory and cause a system panic.

EPSS: Низкий
github логотип

GHSA-xq98-75xh-x359

около 4 лет назад

A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xq98-5rcf-5wqh

около 8 лет назад

Directory Traversal in badjs-sourcemap-server

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xq97-wjxv-m4j7

около 4 лет назад

A password storage vulnerability exists in the operating system functionality of Moxa EDR-810 V4.1 build 17030317. An attacker with shell access could extract passwords in clear text from the device.

CVSS3: 6.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xq9m-84rg-77f9

Apt 0.8.16~exp5ubuntu13.x before 0.8.16~exp5ubuntu13.6, 0.8.16~exp12ubuntu10.x before 0.8.16~exp12ubuntu10.7, and 0.9.7.5ubuntu5.x before 0.9.7.5ubuntu5.2, as used in Ubuntu, uses world-readable permissions for /var/log/apt/term.log, which allows local users to obtain sensitive shell information by reading the log file.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xq9j-rj57-v855

Research Artisan Lite before 1.18 does not ensure that a user has authenticated, which allows remote attackers to perform unspecified actions via unknown vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xq9j-r58r-r55p

A weakness has been identified in Systerel S2OPC up to 1.7.3. This affects the function LockedStaMac_ProcessMsg_DeleteMonitoredItemsResponse of the file src/ClientServer/frontend/client_wrapper/internal/state_machine.c of the component DeleteMonitoredItemsRequest Handler. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.3
0%
Низкий
5 дней назад
github логотип
GHSA-xq9j-g4hv-hg56

Storage Spaces Direct Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-35762, CVE-2022-35763, CVE-2022-35765, CVE-2022-35792.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-xq9j-995w-vvw2

A flaw was found in OpenEXR's Multipart input file functionality. A crafted multi-part input file with no actual parts can trigger a NULL pointer dereference. The highest threat from this vulnerability is to system availability.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xq9h-8fc9-wr6w

TUTOS 1.3 does not restrict access to php/admin/cmd.php, which allows remote attackers to execute arbitrary shell commands via the cmd parameter in a direct request.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-xq9g-w4mx-cv7w

Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-xq9g-p9vj-39jw

HPE System Management Homepage before 7.5.4 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.

CVSS3: 8.1
2%
Низкий
около 4 лет назад
github логотип
GHSA-xq9g-9hx4-3c38

A buffer overflow vulnerability exists in the Microsoft SQL Server that could allow remote code execution on an affected system, aka "Microsoft SQL Server Remote Code Execution Vulnerability." This affects Microsoft SQL Server.

CVSS3: 9.8
29%
Средний
около 4 лет назад
github логотип
GHSA-xq9g-8773-5hrq

D-Link DIR-2640 HNAP LoginPassword Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-2640 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web management interface, which listens on TCP port 80 by default. A specially crafted login request can cause authentication to succeed without providing proper credentials. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-19549.

CVSS3: 6.5
29%
Средний
больше 2 лет назад
github логотип
GHSA-xq9f-gqc7-9v8j

A vulnerability was found in SourceCodester Online Flight Booking Management System. It has been rated as critical. Affected by this issue is some unknown functionality of the file judge_panel.php. The manipulation of the argument subevent_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-218276.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xq9f-7hxc-qrqx

The “Teacher Edit” function of ShinHer StudyOnline System does not perform authority control. After logging in with user’s privilege, remote attackers can access and edit other users’ credential and personal information by crafting URL parameters.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xq9f-582r-p2j7

Cross-site scripting (XSS) vulnerability in simple-upload-53.php in CityPost Simple PHP Upload 5.3 allows remote attackers to inject arbitrary web script or HTML via the message parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xq9c-7q38-2j2j

Buffer overflow in Novell NetWare Client 4.80 through 4.83 allows local users to cause a denial of service (crash) by using ping, traceroute, or a similar utility to force the client to resolve a large hostname.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xq99-q5xg-8fq7

A vulnerability, which was classified as problematic, has been found in CodeAstro Internet Banking System 1.0. This issue affects some unknown processing of the file pages_view_client.php. The manipulation of the argument acc_name with the input Johnnie Reyes'"()&%<zzz><ScRiPt >alert(5646)</ScRiPt> leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-243137 was assigned to this vulnerability.

CVSS3: 3.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-xq99-f7r4-hp52

Tiki before 18.2, 15.7 and 12.14 has XSS via link attributes, related to lib/core/WikiParser/OutputLink.php and lib/parser/parserlib.php.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-xq98-x84m-6479

The setsockopt call in the KAME Project IPv6 implementation, as used in FreeBSD 5.2, does not properly handle certain IPv6 socket options, which could allow attackers to read kernel memory and cause a system panic.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xq98-75xh-x359

A SQL injection code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-xq98-5rcf-5wqh

Directory Traversal in badjs-sourcemap-server

CVSS3: 7.5
2%
Низкий
около 8 лет назад
github логотип
GHSA-xq97-wjxv-m4j7

A password storage vulnerability exists in the operating system functionality of Moxa EDR-810 V4.1 build 17030317. An attacker with shell access could extract passwords in clear text from the device.

CVSS3: 6.7
0%
Низкий
около 4 лет назад

Уязвимостей на страницу