Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 704

Количество 355 704

github логотип

GHSA-xq75-p9cv-wvw7

больше 2 лет назад

Transient DOS in WLAN Firmware while parsing no-inherit IES.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xq75-p73c-3q2p

больше 4 лет назад

Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denial of service or execute arbitrary code via ZIP files containing entries with long filenames, including (1) Microsoft Windows 98 with Plus! Pack, (2) Windows XP, (3) Windows ME, (4) Lotus Notes R4 through R6 (pre-gold), (5) Verity KeyView, and (6) Stuffit Expander before 7.0.

EPSS: Средний
github логотип

GHSA-xq75-f8hh-4vh3

почти 2 года назад

Incorrect use of privileged API in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to knox without proper license.

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-xq75-f84r-j89w

больше 4 лет назад

Multiple buffer overflows in Google Picasa have unspecified attack vectors and impact. NOTE: this information is based upon a vague pre-advisory.

EPSS: Низкий
github логотип

GHSA-xq74-7v9v-c3c9

около 4 лет назад

Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary files via a (1) .. (dot dot) in the file parameter to a webmail/client/skins/default/css/css.php page or .../. (dot dot dot slash dot) in the (2) script or (3) style parameter to webmail/old/calendar/minimizer/index.php.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-xq73-fvmr-jvmm

около 1 месяца назад

OpenAM Authentication Bypass via MSISDN LDAP Injection

EPSS: Низкий
github логотип

GHSA-xq72-m3h5-wf3q

почти 2 года назад

Mecha CMS 3.0.0 is vulnerable to Directory Traversal. An attacker can construct cookies and URIs that bypass user identity checks. Parameters can then be passed through the POST method, resulting in the Deletion of Arbitrary Files or Website Takeover.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xq72-hmvw-v63g

около 4 лет назад

In the Android kernel in Bluetooth there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-xq72-8gp2-7gp9

около 4 лет назад

A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability is different from those described in CVE-2017-0010, CVE-2017-0015, CVE-2017-0032, CVE-2017-0035, CVE-2017-0067, CVE-2017-0070, CVE-2017-0071, CVE-2017-0094, CVE-2017-0132, CVE-2017-0133, CVE-2017-0134, CVE-2017-0136, CVE-2017-0137, CVE-2017-0138, CVE-2017-0141, CVE-2017-0150, and CVE-2017-01...

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-xq72-5mqw-j6rc

больше 2 лет назад

An issue was discovered in the Archibus app 4.0.3 for iOS. There is an XSS vulnerability in the create work request feature of the maintenance module, via the description field. This allows an attacker to perform an action on behalf of the user, exfiltrate data, and so on.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xq72-25v6-8f77

7 месяцев назад

A local privilege escalation vulnerability exists during the installation of Epic Games Store via the Microsoft Store. A low-privilege user can replace a DLL file during the installation process, which may result in unintended elevation of privileges.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xq6x-xxj4-mwgq

около 3 лет назад

The SolarWinds Platform was susceptible to the Incorrect Behavior Order Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with NETWORK SERVICE privileges.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-xq6x-pg98-qjx9

больше 3 лет назад

Cross Site Scripting vulnerability found in Ehuacui BBS allows attackers to cause a denial of service via a crafted payload in the login parameter.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-xq6x-jrcx-94fj

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AlphaEfficiencyTeam Custom Login and Registration allows Stored XSS.This issue affects Custom Login and Registration: from n/a through 1.0.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xq6v-x2f5-r47x

3 месяца назад

Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xq6v-wx5r-87h6

почти 2 года назад

A vulnerability, which was classified as critical, was found in SourceCodester Car Driving School Management System 1.0. This affects the function delete_users of the file User.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xq6v-6r3h-fhg4

около 1 года назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in serpednet SERPed.net allows PHP Local File Inclusion. This issue affects SERPed.net: from n/a through 4.6.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xq6v-3fpg-crf4

около 2 месяцев назад

In EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logic and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xq6r-vj6w-ghh7

5 месяцев назад

In multiple functions of KeyguardViewMediator.java, there is a possible lockscreen bypass due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-xq6q-7cp7-7pv2

около 4 лет назад

CA Automic Automation 12.2 and 12.3 contain an insufficient input validation vulnerability in the Automic agent that could allow a remote attacker to potentially execute arbitrary code.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xq75-p9cv-wvw7

Transient DOS in WLAN Firmware while parsing no-inherit IES.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xq75-p73c-3q2p

Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denial of service or execute arbitrary code via ZIP files containing entries with long filenames, including (1) Microsoft Windows 98 with Plus! Pack, (2) Windows XP, (3) Windows ME, (4) Lotus Notes R4 through R6 (pre-gold), (5) Verity KeyView, and (6) Stuffit Expander before 7.0.

43%
Средний
больше 4 лет назад
github логотип
GHSA-xq75-f8hh-4vh3

Incorrect use of privileged API in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to knox without proper license.

CVSS3: 4
0%
Низкий
почти 2 года назад
github логотип
GHSA-xq75-f84r-j89w

Multiple buffer overflows in Google Picasa have unspecified attack vectors and impact. NOTE: this information is based upon a vague pre-advisory.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xq74-7v9v-c3c9

Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary files via a (1) .. (dot dot) in the file parameter to a webmail/client/skins/default/css/css.php page or .../. (dot dot dot slash dot) in the (2) script or (3) style parameter to webmail/old/calendar/minimizer/index.php.

CVSS3: 7.5
58%
Средний
около 4 лет назад
github логотип
GHSA-xq73-fvmr-jvmm

OpenAM Authentication Bypass via MSISDN LDAP Injection

около 1 месяца назад
github логотип
GHSA-xq72-m3h5-wf3q

Mecha CMS 3.0.0 is vulnerable to Directory Traversal. An attacker can construct cookies and URIs that bypass user identity checks. Parameters can then be passed through the POST method, resulting in the Deletion of Arbitrary Files or Website Takeover.

CVSS3: 9.1
1%
Низкий
почти 2 года назад
github логотип
GHSA-xq72-hmvw-v63g

In the Android kernel in Bluetooth there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 6.7
0%
Низкий
около 4 лет назад
github логотип
GHSA-xq72-8gp2-7gp9

A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability is different from those described in CVE-2017-0010, CVE-2017-0015, CVE-2017-0032, CVE-2017-0035, CVE-2017-0067, CVE-2017-0070, CVE-2017-0071, CVE-2017-0094, CVE-2017-0132, CVE-2017-0133, CVE-2017-0134, CVE-2017-0136, CVE-2017-0137, CVE-2017-0138, CVE-2017-0141, CVE-2017-0150, and CVE-2017-01...

CVSS3: 7.5
15%
Средний
около 4 лет назад
github логотип
GHSA-xq72-5mqw-j6rc

An issue was discovered in the Archibus app 4.0.3 for iOS. There is an XSS vulnerability in the create work request feature of the maintenance module, via the description field. This allows an attacker to perform an action on behalf of the user, exfiltrate data, and so on.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xq72-25v6-8f77

A local privilege escalation vulnerability exists during the installation of Epic Games Store via the Microsoft Store. A low-privilege user can replace a DLL file during the installation process, which may result in unintended elevation of privileges.

CVSS3: 8.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-xq6x-xxj4-mwgq

The SolarWinds Platform was susceptible to the Incorrect Behavior Order Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with NETWORK SERVICE privileges.

CVSS3: 6.8
3%
Низкий
около 3 лет назад
github логотип
GHSA-xq6x-pg98-qjx9

Cross Site Scripting vulnerability found in Ehuacui BBS allows attackers to cause a denial of service via a crafted payload in the login parameter.

CVSS3: 8.2
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xq6x-jrcx-94fj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AlphaEfficiencyTeam Custom Login and Registration allows Stored XSS.This issue affects Custom Login and Registration: from n/a through 1.0.0.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xq6v-x2f5-r47x

Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
3 месяца назад
github логотип
GHSA-xq6v-wx5r-87h6

A vulnerability, which was classified as critical, was found in SourceCodester Car Driving School Management System 1.0. This affects the function delete_users of the file User.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
1%
Низкий
почти 2 года назад
github логотип
GHSA-xq6v-6r3h-fhg4

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in serpednet SERPed.net allows PHP Local File Inclusion. This issue affects SERPed.net: from n/a through 4.6.

CVSS3: 8.1
1%
Низкий
около 1 года назад
github логотип
GHSA-xq6v-3fpg-crf4

In EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logic and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed.

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xq6r-vj6w-ghh7

In multiple functions of KeyguardViewMediator.java, there is a possible lockscreen bypass due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.4
0%
Низкий
5 месяцев назад
github логотип
GHSA-xq6q-7cp7-7pv2

CA Automic Automation 12.2 and 12.3 contain an insufficient input validation vulnerability in the Automic agent that could allow a remote attacker to potentially execute arbitrary code.

CVSS3: 9.8
2%
Низкий
около 4 лет назад

Уязвимостей на страницу