Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 704

Количество 355 704

github логотип

GHSA-xq45-h54c-3xfp

4 месяца назад

Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xq44-wcjx-g3w9

больше 1 года назад

Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM Framework. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM Framework accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xq44-w95m-vr58

больше 4 лет назад

Google Chrome before 1.0.154.53 displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which allows man-in-the-middle attackers to spoof an arbitrary https site by letting a browser obtain a valid certificate from this site during one request, and then sending the browser a crafted 502 response page upon a subsequent request.

EPSS: Низкий
github логотип

GHSA-xq44-vpm8-w66c

больше 3 лет назад

IBM Cloud Pak for Data 4.5 and 4.6 could allow a privileged user to upload malicious files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 232034.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xq44-9xmj-g9xr

больше 4 лет назад

Multiple race conditions in certain system call wrappers in Generic Software Wrappers Toolkit (GSWTK) allow local users to defeat system call interposition and possibly gain privileges or bypass auditing.

EPSS: Низкий
github логотип

GHSA-xq44-64rg-8g3h

5 месяцев назад

Free5GC AMF is vulnerable to DoS through its HandleRegistrationComplete function

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xq43-hwmx-8g8w

почти 3 года назад

Path Traversal in create template function in EasyUse MailHunter Ultimate 2023 and earlier allow remote authenticated users to extract files into arbitrary directories via a crafted ZIP archive.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xq43-hqr9-phrp

около 4 лет назад

Dashlane might allow local users to gain privileges by placing a Trojan horse WINHTTP.dll in the %APPDATA%\Dashlane directory.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xq42-vpp4-76jp

больше 4 лет назад

The default configuration of SQL-Ledger 2.8.24 allows remote attackers to perform unspecified administrative operations by providing an arbitrary password to the admin interface.

EPSS: Низкий
github логотип

GHSA-xq42-m8jp-gxh3

больше 1 года назад

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xq42-73v3-g528

около 4 лет назад

An issue was discoverered in in function edit_save_f in framework/admin/tpl_control.php in qinggan phpok 5.1, allows attackers to write arbitrary files or get a shell.

EPSS: Низкий
github логотип

GHSA-xq42-24vv-4rxr

почти 3 года назад

In Sim, there is a possible way to evade mobile preference restrictions due to a permission bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xq3x-grrj-fj6x

больше 3 лет назад

sjqzhang go-fastdfs vulnerable to path traversal

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xq3x-fm54-p4gq

около 4 лет назад

A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Creator property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xq3x-7w9j-26jf

около 4 лет назад

com/wavemaker/studio/StudioService.java in WaveMaker Studio 6.6 mishandles the studioService.download?method=getContent&inUrl= value, leading to disclosure of local files and SSRF.

CVSS3: 9.6
EPSS: Средний
github логотип

GHSA-xq3w-v528-46rv

больше 1 года назад

Denial of Service attack on windows app using netty

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xq3w-mm28-x95x

около 4 лет назад

Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xq3w-4qf4-4638

около 4 лет назад

Unspecified vulnerability in the Oracle Warehouse Builder component in Oracle Database Server 10.2.0.5 (OWB) and 11.1.0.7 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Dimensional Data Modeling.

EPSS: Низкий
github логотип

GHSA-xq3v-xj62-r99v

9 дней назад

FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large declared body length to force excessive memory allocation on the server.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xq3v-rpgq-hxm8

около 4 лет назад

The Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, does not perform authentication for certain functionality, which allows remote attackers to obtain sensitive information and access restricted functionality via (1) the certificate installation utility, (2) unspecified scripts in the objects folder, (3) an "unnecessary default application," (4) unspecified scripts in the states folder, (5) an unspecified "default application" that lists server configuration, and (6) "full system help."

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xq45-h54c-3xfp

Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

CVSS3: 8.1
1%
Низкий
4 месяца назад
github логотип
GHSA-xq44-wcjx-g3w9

Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM Framework. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM Framework accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-xq44-w95m-vr58

Google Chrome before 1.0.154.53 displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which allows man-in-the-middle attackers to spoof an arbitrary https site by letting a browser obtain a valid certificate from this site during one request, and then sending the browser a crafted 502 response page upon a subsequent request.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xq44-vpm8-w66c

IBM Cloud Pak for Data 4.5 and 4.6 could allow a privileged user to upload malicious files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 232034.

CVSS3: 7.2
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xq44-9xmj-g9xr

Multiple race conditions in certain system call wrappers in Generic Software Wrappers Toolkit (GSWTK) allow local users to defeat system call interposition and possibly gain privileges or bypass auditing.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xq44-64rg-8g3h

Free5GC AMF is vulnerable to DoS through its HandleRegistrationComplete function

CVSS3: 5.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-xq43-hwmx-8g8w

Path Traversal in create template function in EasyUse MailHunter Ultimate 2023 and earlier allow remote authenticated users to extract files into arbitrary directories via a crafted ZIP archive.

CVSS3: 6.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-xq43-hqr9-phrp

Dashlane might allow local users to gain privileges by placing a Trojan horse WINHTTP.dll in the %APPDATA%\Dashlane directory.

CVSS3: 7.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-xq42-vpp4-76jp

The default configuration of SQL-Ledger 2.8.24 allows remote attackers to perform unspecified administrative operations by providing an arbitrary password to the admin interface.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xq42-m8jp-gxh3

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS3: 4.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-xq42-73v3-g528

An issue was discoverered in in function edit_save_f in framework/admin/tpl_control.php in qinggan phpok 5.1, allows attackers to write arbitrary files or get a shell.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xq42-24vv-4rxr

In Sim, there is a possible way to evade mobile preference restrictions due to a permission bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-xq3x-grrj-fj6x

sjqzhang go-fastdfs vulnerable to path traversal

CVSS3: 9.8
4%
Низкий
больше 3 лет назад
github логотип
GHSA-xq3x-fm54-p4gq

A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the Creator property of the this.info object. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

CVSS3: 7.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-xq3x-7w9j-26jf

com/wavemaker/studio/StudioService.java in WaveMaker Studio 6.6 mishandles the studioService.download?method=getContent&inUrl= value, leading to disclosure of local files and SSRF.

CVSS3: 9.6
28%
Средний
около 4 лет назад
github логотип
GHSA-xq3w-v528-46rv

Denial of Service attack on windows app using netty

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xq3w-mm28-x95x

Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

CVSS3: 9.8
9%
Низкий
около 4 лет назад
github логотип
GHSA-xq3w-4qf4-4638

Unspecified vulnerability in the Oracle Warehouse Builder component in Oracle Database Server 10.2.0.5 (OWB) and 11.1.0.7 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Dimensional Data Modeling.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xq3v-xj62-r99v

FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large declared body length to force excessive memory allocation on the server.

CVSS3: 7.5
0%
Низкий
9 дней назад
github логотип
GHSA-xq3v-rpgq-hxm8

The Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, does not perform authentication for certain functionality, which allows remote attackers to obtain sensitive information and access restricted functionality via (1) the certificate installation utility, (2) unspecified scripts in the objects folder, (3) an "unnecessary default application," (4) unspecified scripts in the states folder, (5) an unspecified "default application" that lists server configuration, and (6) "full system help."

1%
Низкий
около 4 лет назад

Уязвимостей на страницу