Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 355 704

Количество 355 704

github логотип

GHSA-xpxm-gwv9-2g2q

около 4 лет назад

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

EPSS: Низкий
github логотип

GHSA-xpxm-9vvw-pjc3

около 4 лет назад

There is a denial of service (DoS) vulnerability in eCNS280 versions V100R005C00, V100R005C10. Due to a design defect, remote unauthorized attackers send a large number of specific messages to affected devices, causing system resource exhaustion and web application DoS.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xpxj-gv5m-476x

около 2 месяцев назад

Subscriber Arbitrary File Upload in Grip <= 1.0.9 versions.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-xpxj-fcm9-9v47

больше 1 года назад

Missing Authorization vulnerability in Adnan Analytify allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Analytify: from n/a through 5.5.1.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xpxj-f2fm-rqch

11 дней назад

OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xpxj-28xv-5xh7

около 4 лет назад

Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the oname and oname2 parameters.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xpxh-fh9m-hf5v

около 4 лет назад

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated TGA file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

EPSS: Низкий
github логотип

GHSA-xpxg-5vmj-vx9g

около 3 лет назад

Thunderbird allowed the Text Direction Override Unicode Character in filenames. An email attachment could be incorrectly shown as being a document file, while in fact it was an executable file. Newer versions of Thunderbird will strip the character and show the correct file extension. This vulnerability affects Thunderbird < 115.0.1.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xpxf-p5mx-cq4f

больше 4 лет назад

It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-xpxf-4p9g-j69p

больше 4 лет назад

The SearchIQ WordPress plugin before 3.9 contains a flag to disable the verification of CSRF nonces, granting unauthenticated attackers access to the siq_ajax AJAX action and allowing them to perform Cross-Site Scripting attacks due to the lack of sanitisation and escaping in the customCss parameter

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xpxc-7j8q-3794

около 4 лет назад

Microsoft Windows 7 SP1 allows an attacker to execute arbitrary code in the context of the current user, due to how Microsoft browsers handle objects in memory, aka "Windows Shell Remote Code Execution Vulnerability".

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-xpx9-f724-2jfc

почти 2 года назад

Vulnerability in Scriptcase version 9.4.019 that consists of a Cross-Site Scripting (XSS), due to the lack of input validation, affecting the “id_form_msg_title” parameter, among others. This vulnerability could allow a remote user to send a specially crafted URL to a victim and retrieve their credentials.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xpx9-9jmc-8j4w

7 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webvitaly Extra Shortcodes allows Stored XSS.This issue affects Extra Shortcodes: from n/a through 2.2.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xpx8-wp93-8pmf

около 4 лет назад

The do_search function in ldap/servers/slapd/search.c in 389 Directory Server 1.2.x before 1.2.11.20 and 1.3.x before 1.3.0.5 does not properly restrict access to entries when the nsslapd-allow-anonymous-access configuration is set to rootdse and the BASE search scope is used, which allows remote attackers to obtain sensitive information outside of the rootDSE via a crafted LDAP search.

EPSS: Низкий
github логотип

GHSA-xpx8-32xv-57gm

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eugenio Petullà imaGenius allows Stored XSS.This issue affects imaGenius: from n/a through 1.7.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xpx7-q2q3-379g

около 4 лет назад

IBM OpenPages GRC Platform 7.2 and 7.3 with OpenPages Loss Event Entry (LEE) application could allow a user to obtain sensitive information including private APIs that could be used in further attacks against the system. IBM X-Force ID: 122201.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xpx7-hxr3-j5f5

около 4 лет назад

Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xpx7-g688-hrvx

около 1 года назад

IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26242.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xpx7-9mqm-5g6h

около 4 лет назад

WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via \admin\pages\sections_save.php namesection2 parameters.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xpx7-7hf6-5722

больше 3 лет назад

Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where certain PHP pages only validate when a valid connection is established with the database. However, these PHP pages do not verify the validity of a user. Attackers could leverage this lack of verification to read the state of outlets.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xpxm-gwv9-2g2q

WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.

3%
Низкий
около 4 лет назад
github логотип
GHSA-xpxm-9vvw-pjc3

There is a denial of service (DoS) vulnerability in eCNS280 versions V100R005C00, V100R005C10. Due to a design defect, remote unauthorized attackers send a large number of specific messages to affected devices, causing system resource exhaustion and web application DoS.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xpxj-gv5m-476x

Subscriber Arbitrary File Upload in Grip <= 1.0.9 versions.

CVSS3: 9.9
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xpxj-fcm9-9v47

Missing Authorization vulnerability in Adnan Analytify allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Analytify: from n/a through 5.5.1.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-xpxj-f2fm-rqch

OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)

CVSS3: 7.5
0%
Низкий
11 дней назад
github логотип
GHSA-xpxj-28xv-5xh7

Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the oname and oname2 parameters.

CVSS3: 6.1
4%
Низкий
около 4 лет назад
github логотип
GHSA-xpxh-fh9m-hf5v

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated TGA file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xpxg-5vmj-vx9g

Thunderbird allowed the Text Direction Override Unicode Character in filenames. An email attachment could be incorrectly shown as being a document file, while in fact it was an executable file. Newer versions of Thunderbird will strip the character and show the correct file extension. This vulnerability affects Thunderbird < 115.0.1.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-xpxf-p5mx-cq4f

It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack.

CVSS3: 3.7
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xpxf-4p9g-j69p

The SearchIQ WordPress plugin before 3.9 contains a flag to disable the verification of CSRF nonces, granting unauthenticated attackers access to the siq_ajax AJAX action and allowing them to perform Cross-Site Scripting attacks due to the lack of sanitisation and escaping in the customCss parameter

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xpxc-7j8q-3794

Microsoft Windows 7 SP1 allows an attacker to execute arbitrary code in the context of the current user, due to how Microsoft browsers handle objects in memory, aka "Windows Shell Remote Code Execution Vulnerability".

CVSS3: 7.5
14%
Средний
около 4 лет назад
github логотип
GHSA-xpx9-f724-2jfc

Vulnerability in Scriptcase version 9.4.019 that consists of a Cross-Site Scripting (XSS), due to the lack of input validation, affecting the “id_form_msg_title” parameter, among others. This vulnerability could allow a remote user to send a specially crafted URL to a victim and retrieve their credentials.

CVSS3: 6.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-xpx9-9jmc-8j4w

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webvitaly Extra Shortcodes allows Stored XSS.This issue affects Extra Shortcodes: from n/a through 2.2.

CVSS3: 6.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-xpx8-wp93-8pmf

The do_search function in ldap/servers/slapd/search.c in 389 Directory Server 1.2.x before 1.2.11.20 and 1.3.x before 1.3.0.5 does not properly restrict access to entries when the nsslapd-allow-anonymous-access configuration is set to rootdse and the BASE search scope is used, which allows remote attackers to obtain sensitive information outside of the rootDSE via a crafted LDAP search.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xpx8-32xv-57gm

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eugenio Petullà imaGenius allows Stored XSS.This issue affects imaGenius: from n/a through 1.7.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xpx7-q2q3-379g

IBM OpenPages GRC Platform 7.2 and 7.3 with OpenPages Loss Event Entry (LEE) application could allow a user to obtain sensitive information including private APIs that could be used in further attacks against the system. IBM X-Force ID: 122201.

CVSS3: 5.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-xpx7-hxr3-j5f5

Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-064.

CVSS3: 7.5
8%
Низкий
около 4 лет назад
github логотип
GHSA-xpx7-g688-hrvx

IrfanView CADImage Plugin DWG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DWG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26242.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-xpx7-9mqm-5g6h

WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via \admin\pages\sections_save.php namesection2 parameters.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-xpx7-7hf6-5722

Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where certain PHP pages only validate when a valid connection is established with the database. However, these PHP pages do not verify the validity of a user. Attackers could leverage this lack of verification to read the state of outlets.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу