Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 704

Количество 355 704

github логотип

GHSA-xq22-q558-rcg4

больше 4 лет назад

Bugzilla 2.17.x, 2.18 before 2.18.2, 2.19.x, and 2.20 before 2.20rc1 inserts a bug into the database before it is marked private, which introduces a race condition and allows attackers to access information about the bug via buglist.cgi before MySQL replication is complete.

EPSS: Низкий
github логотип

GHSA-xpxw-wxvf-889j

около 4 лет назад

A lock screen issue allowed access to contacts on a locked device. This issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1. A person with physical access to an iOS device may be able to access contacts from the lock screen.

EPSS: Низкий
github логотип

GHSA-xpxw-r4r3-r7qf

11 месяцев назад

IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) 8.1 before 8.1.2.2 could allow an authenticated user to obtain sensitive information about configuration on the system.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xpxw-jjgj-rr72

около 4 лет назад

Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.51, 8.52, and 8.53 allows remote attackers to affect confidentiality via unknown vectors related to Integration Broker.

EPSS: Низкий
github логотип

GHSA-xpxv-rfwh-rcfc

около 4 лет назад

A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulnerability is due to the incorrect handling of directory paths. An attacker could exploit this vulnerability by creating a malicious file and copying the file to a system directory. An exploit could allow the attacker to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks. To exploit this vulnerability, the attacker needs valid credentials on the Windows system.

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-xpxv-cx25-38p3

больше 2 лет назад

Insecure deserialization in ROS2 Foxy Fitzroy ROS_VERSION=2 and ROS_PYTHON_VERSION=3 allows attackers to execute arbitrary code via a crafted input.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xpxv-7rx3-wg5r

около 4 лет назад

Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4172, CVE-2016-4175, CVE-2016-4179, CVE-2016-4180, CVE-2016-4181, CVE-2016-4182, CVE-2016-4183, CVE-2016-4184, CVE-2016-4185, CVE-2016-4186, CVE-2016-4187, CVE-2016-4188, CVE-2016-4189, CVE-2016-4190, CVE-2016-4217, CVE-2016-4218, CVE-2016-4219, CVE-2016-4220, CVE-2016-4221, CVE-2016-4233, CVE-2016-4234, CVE-2016-4235, CVE-2016-4236, CVE-2016-4237, CVE-2016-4238, CVE-2016-4239, CVE-2016-4240, CVE-2016-4241, CVE-2016-4242, CVE-2016-4244, CVE-2016-4245, and CVE-2016-4246.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xpxv-6ccf-795w

около 4 лет назад

Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot, a different vulnerability than CVE-2016-5582.

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-xpxv-4wqh-mpjg

около 4 лет назад

An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xpxr-m6jm-3qph

около 4 лет назад

Insufficient policy enforcement in File System API in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to bypass file system policy via a crafted HTML page.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xpxr-6mr7-m8w3

около 4 лет назад

RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a crafted sample size in a RealAudio file.

EPSS: Низкий
github логотип

GHSA-xpxq-j6pj-5vxg

больше 4 лет назад

The RightFax web client uses predictable session numbers, which allows remote attackers to hijack user sessions.

EPSS: Низкий
github логотип

GHSA-xpxq-cp94-87j2

почти 4 года назад

A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-xpxq-44xv-wmh3

12 месяцев назад

A security flaw has been discovered in Portabilis i-Diario up to 1.5.0. Affected by this vulnerability is an unknown functionality of the file /password/email of the component Password Recovery Endpoint. The manipulation results in observable response discrepancy. It is possible to launch the attack remotely. This attack is characterized by high complexity. The exploitation appears to be difficult. The exploit has been released to the public and may be exploited.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-xpxq-36mx-cwhx

около 4 лет назад

An issue was discovered in OXID eShop Enterprise Edition before 5.3.8, 6.0.x before 6.0.3, and 6.1.x before 6.1.0; Professional Edition before 4.10.8, 5.x and 6.0.x before 6.0.3, and 6.1.x before 6.1.0; and Community Edition before 4.10.8, 5.x and 6.0.x before 6.0.3, and 6.1.x before 6.1.0. An attacker could gain access to the admin panel or a customer account when using the password reset function. To do so, it is required to own a domain name similar to the one the victim uses for their e-mail accounts.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xpxp-v33m-5jp9

около 4 лет назад

phpMyAdmin Unsafe Fetching of Javascript Code

EPSS: Низкий
github логотип

GHSA-xpxp-r8hf-wgf6

около 1 года назад

WSO2 products vulnerable to Cross-site Scripting

CVSS3: 5.2
EPSS: Низкий
github логотип

GHSA-xpxm-pf7g-2534

около 5 лет назад

Cross-site scripting in media2click

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-xpxm-p6f4-j2mf

3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: rtnetlink: add missing netlink_ns_capable() check for peer netns rtnl_newlink() lacks a CAP_NET_ADMIN capability check on the peer network namespace when creating paired devices (veth, vxcan, netkit). This allows an unprivileged user with a user namespace to create interfaces in arbitrary network namespaces, including init_net. Add a netlink_ns_capable() check for CAP_NET_ADMIN in the peer namespace before allowing device creation to proceed.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xpxm-j39p-5vcw

больше 4 лет назад

Vulnerability in gpm in Caldera Linux allows local users to delete arbitrary files or conduct a denial of service.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xq22-q558-rcg4

Bugzilla 2.17.x, 2.18 before 2.18.2, 2.19.x, and 2.20 before 2.20rc1 inserts a bug into the database before it is marked private, which introduces a race condition and allows attackers to access information about the bug via buglist.cgi before MySQL replication is complete.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xpxw-wxvf-889j

A lock screen issue allowed access to contacts on a locked device. This issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1. A person with physical access to an iOS device may be able to access contacts from the lock screen.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xpxw-r4r3-r7qf

IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) 8.1 before 8.1.2.2 could allow an authenticated user to obtain sensitive information about configuration on the system.

CVSS3: 4.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-xpxw-jjgj-rr72

Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.51, 8.52, and 8.53 allows remote attackers to affect confidentiality via unknown vectors related to Integration Broker.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xpxv-rfwh-rcfc

A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulnerability is due to the incorrect handling of directory paths. An attacker could exploit this vulnerability by creating a malicious file and copying the file to a system directory. An exploit could allow the attacker to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks. To exploit this vulnerability, the attacker needs valid credentials on the Windows system.

CVSS3: 6.5
27%
Средний
около 4 лет назад
github логотип
GHSA-xpxv-cx25-38p3

Insecure deserialization in ROS2 Foxy Fitzroy ROS_VERSION=2 and ROS_PYTHON_VERSION=3 allows attackers to execute arbitrary code via a crafted input.

CVSS3: 9.8
больше 2 лет назад
github логотип
GHSA-xpxv-7rx3-wg5r

Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4172, CVE-2016-4175, CVE-2016-4179, CVE-2016-4180, CVE-2016-4181, CVE-2016-4182, CVE-2016-4183, CVE-2016-4184, CVE-2016-4185, CVE-2016-4186, CVE-2016-4187, CVE-2016-4188, CVE-2016-4189, CVE-2016-4190, CVE-2016-4217, CVE-2016-4218, CVE-2016-4219, CVE-2016-4220, CVE-2016-4221, CVE-2016-4233, CVE-2016-4234, CVE-2016-4235, CVE-2016-4236, CVE-2016-4237, CVE-2016-4238, CVE-2016-4239, CVE-2016-4240, CVE-2016-4241, CVE-2016-4242, CVE-2016-4244, CVE-2016-4245, and CVE-2016-4246.

CVSS3: 9.8
4%
Низкий
около 4 лет назад
github логотип
GHSA-xpxv-6ccf-795w

Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot, a different vulnerability than CVE-2016-5582.

CVSS3: 8.3
3%
Низкий
около 4 лет назад
github логотип
GHSA-xpxv-4wqh-mpjg

An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xpxr-m6jm-3qph

Insufficient policy enforcement in File System API in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to bypass file system policy via a crafted HTML page.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-xpxr-6mr7-m8w3

RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a crafted sample size in a RealAudio file.

3%
Низкий
около 4 лет назад
github логотип
GHSA-xpxq-j6pj-5vxg

The RightFax web client uses predictable session numbers, which allows remote attackers to hijack user sessions.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xpxq-cp94-87j2

A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations.

CVSS3: 4.9
1%
Низкий
почти 4 года назад
github логотип
GHSA-xpxq-44xv-wmh3

A security flaw has been discovered in Portabilis i-Diario up to 1.5.0. Affected by this vulnerability is an unknown functionality of the file /password/email of the component Password Recovery Endpoint. The manipulation results in observable response discrepancy. It is possible to launch the attack remotely. This attack is characterized by high complexity. The exploitation appears to be difficult. The exploit has been released to the public and may be exploited.

CVSS3: 3.7
0%
Низкий
12 месяцев назад
github логотип
GHSA-xpxq-36mx-cwhx

An issue was discovered in OXID eShop Enterprise Edition before 5.3.8, 6.0.x before 6.0.3, and 6.1.x before 6.1.0; Professional Edition before 4.10.8, 5.x and 6.0.x before 6.0.3, and 6.1.x before 6.1.0; and Community Edition before 4.10.8, 5.x and 6.0.x before 6.0.3, and 6.1.x before 6.1.0. An attacker could gain access to the admin panel or a customer account when using the password reset function. To do so, it is required to own a domain name similar to the one the victim uses for their e-mail accounts.

CVSS3: 8.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-xpxp-v33m-5jp9

phpMyAdmin Unsafe Fetching of Javascript Code

1%
Низкий
около 4 лет назад
github логотип
GHSA-xpxp-r8hf-wgf6

WSO2 products vulnerable to Cross-site Scripting

CVSS3: 5.2
0%
Низкий
около 1 года назад
github логотип
GHSA-xpxm-pf7g-2534

Cross-site scripting in media2click

CVSS3: 6.4
1%
Низкий
около 5 лет назад
github логотип
GHSA-xpxm-p6f4-j2mf

In the Linux kernel, the following vulnerability has been resolved: rtnetlink: add missing netlink_ns_capable() check for peer netns rtnl_newlink() lacks a CAP_NET_ADMIN capability check on the peer network namespace when creating paired devices (veth, vxcan, netkit). This allows an unprivileged user with a user namespace to create interfaces in arbitrary network namespaces, including init_net. Add a netlink_ns_capable() check for CAP_NET_ADMIN in the peer namespace before allowing device creation to proceed.

CVSS3: 5.5
0%
Низкий
3 месяца назад
github логотип
GHSA-xpxm-j39p-5vcw

Vulnerability in gpm in Caldera Linux allows local users to delete arbitrary files or conduct a denial of service.

0%
Низкий
больше 4 лет назад

Уязвимостей на страницу