Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 704

Количество 355 704

github логотип

GHSA-xq2f-wc3r-4q96

около 4 лет назад

Buffer overflow in the bGetPPS function in wordole.c in Antiword 0.37 allows remote attackers to cause a denial of service (crash) via a crafted document.

EPSS: Низкий
github логотип

GHSA-xq2f-h2vw-352p

около 4 лет назад

Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_sub_category.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xq2f-f4gq-58p8

около 1 года назад

The desktop application in Dot through 0.9.3 allows XSS and resultant command execution because user input and LLM output are appended to the DOM with innerHTML (in render.js), and because the Electron window can access Node.js APIs.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xq2c-xc9f-44f4

около 4 лет назад

SAP Enterprise Threat Detection, versions 1.0, 2.0, does not sufficiently encode error response pages in case of errors, allowing XSS payload reflecting in the response, leading to reflected Cross Site Scripting.

EPSS: Низкий
github логотип

GHSA-xq2c-w9r3-rwr6

7 дней назад

A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs when the `fcTL` width exceeds the `IHDR` width, leading to pixel data being written past the end of a heap allocation. Additionally, a heap-based buffer overflow exists in the DDS plug-in due to a BPP mismatch in the `load_layer()` function. Both vulnerabilities can be triggered by opening a specially crafted image file, potentially leading to code execution.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xq29-jcj7-xg86

около 4 лет назад

Webkit PDFs for TYPO3 allows remote attackers to execute arbitrary commands

EPSS: Низкий
github логотип

GHSA-xq29-76j5-j268

12 месяцев назад

A vulnerability was identified in PHPGurukul User Management System 1.0. This vulnerability affects unknown code of the file /signup.php. Such manipulation of the argument emailid leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xq29-5vxx-327w

около 4 лет назад

The application server component of TIBCO Software Inc.'s TIBCO Data Science for AWS, and TIBCO Spotfire Data Science contains a vulnerability that theoretically enables a user to spoof their account to look like a different user in the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Data Science for AWS: versions up to and including 6.4.0, and TIBCO Spotfire Data Science: versions up to and including 6.4.0.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xq28-w75v-29rr

около 4 лет назад

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1023, CVE-2020-1024.

EPSS: Средний
github логотип

GHSA-xq28-26p4-h63h

больше 2 лет назад

In telocom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xq27-8jmr-q96f

около 4 лет назад

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9650, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, and SD 850, in a WideVine API function, a buffer over-read can occur.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xq26-7392-p876

больше 4 лет назад

PHP-Nuke 5.1 stores user and administrator passwords in a base-64 encoded cookie, which could allow remote attackers to gain privileges by stealing or sniffing the cookie and decoding it.

EPSS: Низкий
github логотип

GHSA-xq25-vjqp-23mx

больше 4 лет назад

Multiple format string vulnerabilities in the FTP service in 3Com 3CDaemon 2.0 revision 10 allow remote attackers to cause a denial of service (application crash) via format string specifiers in (1) the username, (2) cd, (3) delete, (4) rename, (5) rmdir, (6) literal, (7) stat, or (8) CWD commands.

EPSS: Низкий
github логотип

GHSA-xq25-m329-6gr4

около 4 лет назад

Monkey HTTP Daemon 0.9.3 might allow local users to overwrite arbitrary files via a symlink attack on a PID file, as demonstrated by a pathname different from the default /var/run/monkey.pid pathname.

EPSS: Низкий
github логотип

GHSA-xq25-8g7f-6hc5

больше 4 лет назад

Stack buffer overflow issues were found in Opensc before version 0.22.0 in various places that could potentially crash programs using the library.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xq25-766f-47jc

около 4 лет назад

The Chat Room module 7.x-2.x before 7.x-2.2 for Drupal does not properly check permissions when setting up a websocket for chat messages, which allows remote attackers to bypass intended access restrictions and read messages from arbitrary Chat Rooms via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xq25-2qrx-43c4

около 4 лет назад

Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 allows remote attackers to inject arbitrary web script or HTML via vectors related to web messaging.

EPSS: Низкий
github логотип

GHSA-xq24-f354-mr59

около 4 лет назад

IBM WebSphere Application Server version 9.0.0.4 could provide weaker than expected security after using the PasswordUtil command to enable AES password encryption. IBM X-Force ID: 129579.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xq23-vw7c-wg89

около 4 лет назад

XML external entity vulnerability in PRTG Network Monitor before 16.2.23.3077/3078 allows remote authenticated users to read arbitrary files by creating a new HTTP XML/REST Value sensor that accesses a crafted XML file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xq22-wjfr-v6cf

больше 1 года назад

A vulnerability, which was classified as critical, has been found in Tenda FH1202 1.2.0.14(408). Affected by this issue is some unknown functionality of the file /default.cfg. The manipulation of the argument these leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xq2f-wc3r-4q96

Buffer overflow in the bGetPPS function in wordole.c in Antiword 0.37 allows remote attackers to cause a denial of service (crash) via a crafted document.

4%
Низкий
около 4 лет назад
github логотип
GHSA-xq2f-h2vw-352p

Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_sub_category.

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xq2f-f4gq-58p8

The desktop application in Dot through 0.9.3 allows XSS and resultant command execution because user input and LLM output are appended to the DOM with innerHTML (in render.js), and because the Electron window can access Node.js APIs.

CVSS3: 8.1
0%
Низкий
около 1 года назад
github логотип
GHSA-xq2c-xc9f-44f4

SAP Enterprise Threat Detection, versions 1.0, 2.0, does not sufficiently encode error response pages in case of errors, allowing XSS payload reflecting in the response, leading to reflected Cross Site Scripting.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xq2c-w9r3-rwr6

A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs when the `fcTL` width exceeds the `IHDR` width, leading to pixel data being written past the end of a heap allocation. Additionally, a heap-based buffer overflow exists in the DDS plug-in due to a BPP mismatch in the `load_layer()` function. Both vulnerabilities can be triggered by opening a specially crafted image file, potentially leading to code execution.

CVSS3: 7.3
0%
Низкий
7 дней назад
github логотип
GHSA-xq29-jcj7-xg86

Webkit PDFs for TYPO3 allows remote attackers to execute arbitrary commands

2%
Низкий
около 4 лет назад
github логотип
GHSA-xq29-76j5-j268

A vulnerability was identified in PHPGurukul User Management System 1.0. This vulnerability affects unknown code of the file /signup.php. Such manipulation of the argument emailid leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.

CVSS3: 7.3
0%
Низкий
12 месяцев назад
github логотип
GHSA-xq29-5vxx-327w

The application server component of TIBCO Software Inc.'s TIBCO Data Science for AWS, and TIBCO Spotfire Data Science contains a vulnerability that theoretically enables a user to spoof their account to look like a different user in the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Data Science for AWS: versions up to and including 6.4.0, and TIBCO Spotfire Data Science: versions up to and including 6.4.0.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-xq28-w75v-29rr

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1023, CVE-2020-1024.

15%
Средний
около 4 лет назад
github логотип
GHSA-xq28-26p4-h63h

In telocom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xq27-8jmr-q96f

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9650, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, and SD 850, in a WideVine API function, a buffer over-read can occur.

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xq26-7392-p876

PHP-Nuke 5.1 stores user and administrator passwords in a base-64 encoded cookie, which could allow remote attackers to gain privileges by stealing or sniffing the cookie and decoding it.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-xq25-vjqp-23mx

Multiple format string vulnerabilities in the FTP service in 3Com 3CDaemon 2.0 revision 10 allow remote attackers to cause a denial of service (application crash) via format string specifiers in (1) the username, (2) cd, (3) delete, (4) rename, (5) rmdir, (6) literal, (7) stat, or (8) CWD commands.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xq25-m329-6gr4

Monkey HTTP Daemon 0.9.3 might allow local users to overwrite arbitrary files via a symlink attack on a PID file, as demonstrated by a pathname different from the default /var/run/monkey.pid pathname.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xq25-8g7f-6hc5

Stack buffer overflow issues were found in Opensc before version 0.22.0 in various places that could potentially crash programs using the library.

CVSS3: 5.3
3%
Низкий
больше 4 лет назад
github логотип
GHSA-xq25-766f-47jc

The Chat Room module 7.x-2.x before 7.x-2.2 for Drupal does not properly check permissions when setting up a websocket for chat messages, which allows remote attackers to bypass intended access restrictions and read messages from arbitrary Chat Rooms via unspecified vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xq25-2qrx-43c4

Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 allows remote attackers to inject arbitrary web script or HTML via vectors related to web messaging.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xq24-f354-mr59

IBM WebSphere Application Server version 9.0.0.4 could provide weaker than expected security after using the PasswordUtil command to enable AES password encryption. IBM X-Force ID: 129579.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xq23-vw7c-wg89

XML external entity vulnerability in PRTG Network Monitor before 16.2.23.3077/3078 allows remote authenticated users to read arbitrary files by creating a new HTTP XML/REST Value sensor that accesses a crafted XML file.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xq22-wjfr-v6cf

A vulnerability, which was classified as critical, has been found in Tenda FH1202 1.2.0.14(408). Affected by this issue is some unknown functionality of the file /default.cfg. The manipulation of the argument these leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 5.3
10%
Низкий
больше 1 года назад

Уязвимостей на страницу