Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 356 366

Количество 356 366

github логотип

GHSA-xpfg-jhxj-qw6x

больше 4 лет назад

The Next action in PEAR HTML_QuickForm_Controller 1.0.4 includes the SID in the URL even when session.use_only_cookies is configured, which allows remote attackers to obtain the SID via an HTTP Referer field and possibly other vectors.

EPSS: Низкий
github логотип

GHSA-xpfg-hqmq-gr2w

11 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: net: dsa: fix panic on shutdown if multi-chip tree failed to probe DSA probing is atypical because a tree of devices must probe all at once, so out of N switches which call dsa_tree_setup_routing_table() during probe, for (N - 1) of them, "complete" will return false and they will exit probing early. The Nth switch will set up the whole tree on their behalf. The implication is that for (N - 1) switches, the driver binds to the device successfully, without doing anything. When the driver is bound, the ->shutdown() method may run. But if the Nth switch has failed to initialize the tree, there is nothing to do for the (N - 1) driver instances, since the slave devices have not been created, etc. Moreover, dsa_switch_shutdown() expects that the calling @ds has been in fact initialized, so it jumps at dereferencing the various data structures, which is incorrect. Avoid the ensuing NULL pointer dereferences by simply c...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xpfg-cjj6-56wx

28 дней назад

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-xpff-gfqx-47wg

больше 4 лет назад

An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication. This vulnerability can allow attackers to execute phishing attacks or cause a Denial of Service (DoS).

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xpff-c35g-j3cr

около 2 лет назад

silverstripe/framework Privilege Escalation Risk in Member Edit form

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xpfc-p72p-hwch

около 4 лет назад

In Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the receiver object of an Unsafe call when accelerating it.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xpfc-cjr2-3j39

7 месяцев назад

The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the risk of unauthorized access. This represents a high risk to the integrity of the system.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xpfc-5pgf-2vp4

около 4 лет назад

PivotX before 2.3.11 does not validate the new file extension when renaming a file with multiple extensions, which allows remote attackers to execute arbitrary code by uploading a crafted file, as demonstrated by a file named foo.php.php.

EPSS: Низкий
github логотип

GHSA-xpf8-p6c2-qcp9

около 2 месяцев назад

The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_pay_for_order()` function in all versions up to, and including, 10.7.0 This is due to a missing order ownership or order_key verification when processing payment for an order via the `wc_stripe_pay_for_order` WC-AJAX endpoint. The function only validates a nonce (which is publicly available on any WooCommerce page where Express Checkout is enabled), but does not verify that the requesting user owns the target order and is allowed to modify it. This makes it possible for unauthenticated attackers to force any pending order into a failed status by providing a fake payment method, causing a payment exception that updates the order status to "failed" via sequential order ID enumeration.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xpf8-484v-j9w6

около 1 года назад

pyjwt v2.10.1 was discovered to contain weak encryption.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-xpf7-vhxr-qr93

1 день назад

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: Fix an error handling path in cfg80211_wext_siwscan() If the test against IEEE80211_MAX_SSID_LEN fails, then 'creq' leaks. Use the existing error handling path to fix it.

EPSS: Низкий
github логотип

GHSA-xpf7-vf54-5crr

около 4 лет назад

sfnt/ttload.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting the values, which allows remote attackers to cause a denial of service (integer overflow and out-of-bounds read) or possibly have unspecified other impact via a crafted SFNT table.

EPSS: Низкий
github логотип

GHSA-xpf6-m5rc-7966

больше 3 лет назад

An OS command injection vulnerability exists in the httpd logs/view.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xpf5-wwvx-w945

около 2 месяцев назад

Out-of-bounds write in SetSuitesHashSigAlgo when processing an oversized signature algorithms list, allowing a write past the bounds of the destination buffer.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xpf5-rhc4-rvvh

около 2 лет назад

A vulnerability, which was classified as critical, was found in itsourcecode Bike Delivery System 1.0. Affected is an unknown function of the file contact_us_action.php. The manipulation of the argument name leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273648.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xpf3-7cmq-j53r

около 4 лет назад

An issue was discovered on Epson WorkForce WF-2861 10.48 LQ22I3, 10.51.LQ20I6 and 10.52.LQ17IA devices. On the 'Air Print Setting' web page, if the data for 'Bonjour Service Location' at /PRESENTATION/BONJOUR is more than 251 bytes when sending data for Air Print Setting, then the device no longer functions until a reboot.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xpf3-5x9r-5xfw

около 1 года назад

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xpf3-392m-9g4x

около 4 лет назад

Unspecified vulnerability in the Oracle Marketing component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality via unknown vectors related to Deliverables.

EPSS: Низкий
github логотип

GHSA-xpf2-4v7h-fpcm

больше 3 лет назад

Failure to unmap certain SysHub mappings in error paths of the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious bootloader to exhaust the SysHub resources resulting in a potential denial of service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xpf2-2px9-cj3p

больше 4 лет назад

Multiple PHP remote file inclusion vulnerabilities in Bloq 0.5.4 allow remote attackers to execute arbitrary PHP code via a URL in the page[path] parameter to (1) index.php, (2) admin.php, (3) rss.php, (4) rdf.php, (5) rss2.php, or (6) files/mainfile.php.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xpfg-jhxj-qw6x

The Next action in PEAR HTML_QuickForm_Controller 1.0.4 includes the SID in the URL even when session.use_only_cookies is configured, which allows remote attackers to obtain the SID via an HTTP Referer field and possibly other vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xpfg-hqmq-gr2w

In the Linux kernel, the following vulnerability has been resolved: net: dsa: fix panic on shutdown if multi-chip tree failed to probe DSA probing is atypical because a tree of devices must probe all at once, so out of N switches which call dsa_tree_setup_routing_table() during probe, for (N - 1) of them, "complete" will return false and they will exit probing early. The Nth switch will set up the whole tree on their behalf. The implication is that for (N - 1) switches, the driver binds to the device successfully, without doing anything. When the driver is bound, the ->shutdown() method may run. But if the Nth switch has failed to initialize the tree, there is nothing to do for the (N - 1) driver instances, since the slave devices have not been created, etc. Moreover, dsa_switch_shutdown() expects that the calling @ds has been in fact initialized, so it jumps at dereferencing the various data structures, which is incorrect. Avoid the ensuing NULL pointer dereferences by simply c...

CVSS3: 5.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-xpfg-cjj6-56wx

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 9.6
1%
Низкий
28 дней назад
github логотип
GHSA-xpff-gfqx-47wg

An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication. This vulnerability can allow attackers to execute phishing attacks or cause a Denial of Service (DoS).

CVSS3: 9.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xpff-c35g-j3cr

silverstripe/framework Privilege Escalation Risk in Member Edit form

CVSS3: 6.5
около 2 лет назад
github логотип
GHSA-xpfc-p72p-hwch

In Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the receiver object of an Unsafe call when accelerating it.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-xpfc-cjr2-3j39

The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the risk of unauthorized access. This represents a high risk to the integrity of the system.

CVSS3: 7.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-xpfc-5pgf-2vp4

PivotX before 2.3.11 does not validate the new file extension when renaming a file with multiple extensions, which allows remote attackers to execute arbitrary code by uploading a crafted file, as demonstrated by a file named foo.php.php.

5%
Низкий
около 4 лет назад
github логотип
GHSA-xpf8-p6c2-qcp9

The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_pay_for_order()` function in all versions up to, and including, 10.7.0 This is due to a missing order ownership or order_key verification when processing payment for an order via the `wc_stripe_pay_for_order` WC-AJAX endpoint. The function only validates a nonce (which is publicly available on any WooCommerce page where Express Checkout is enabled), but does not verify that the requesting user owns the target order and is allowed to modify it. This makes it possible for unauthenticated attackers to force any pending order into a failed status by providing a fake payment method, causing a payment exception that updates the order status to "failed" via sequential order ID enumeration.

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xpf8-484v-j9w6

pyjwt v2.10.1 was discovered to contain weak encryption.

CVSS3: 7
0%
Низкий
около 1 года назад
github логотип
GHSA-xpf7-vhxr-qr93

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: Fix an error handling path in cfg80211_wext_siwscan() If the test against IEEE80211_MAX_SSID_LEN fails, then 'creq' leaks. Use the existing error handling path to fix it.

1 день назад
github логотип
GHSA-xpf7-vf54-5crr

sfnt/ttload.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting the values, which allows remote attackers to cause a denial of service (integer overflow and out-of-bounds read) or possibly have unspecified other impact via a crafted SFNT table.

3%
Низкий
около 4 лет назад
github логотип
GHSA-xpf6-m5rc-7966

An OS command injection vulnerability exists in the httpd logs/view.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.

CVSS3: 9.8
6%
Низкий
больше 3 лет назад
github логотип
GHSA-xpf5-wwvx-w945

Out-of-bounds write in SetSuitesHashSigAlgo when processing an oversized signature algorithms list, allowing a write past the bounds of the destination buffer.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xpf5-rhc4-rvvh

A vulnerability, which was classified as critical, was found in itsourcecode Bike Delivery System 1.0. Affected is an unknown function of the file contact_us_action.php. The manipulation of the argument name leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273648.

CVSS3: 7.3
1%
Низкий
около 2 лет назад
github логотип
GHSA-xpf3-7cmq-j53r

An issue was discovered on Epson WorkForce WF-2861 10.48 LQ22I3, 10.51.LQ20I6 and 10.52.LQ17IA devices. On the 'Air Print Setting' web page, if the data for 'Bonjour Service Location' at /PRESENTATION/BONJOUR is more than 251 bytes when sending data for Air Print Setting, then the device no longer functions until a reboot.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xpf3-5x9r-5xfw

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS3: 5.5
0%
Низкий
около 1 года назад
github логотип
GHSA-xpf3-392m-9g4x

Unspecified vulnerability in the Oracle Marketing component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality via unknown vectors related to Deliverables.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xpf2-4v7h-fpcm

Failure to unmap certain SysHub mappings in error paths of the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious bootloader to exhaust the SysHub resources resulting in a potential denial of service.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xpf2-2px9-cj3p

Multiple PHP remote file inclusion vulnerabilities in Bloq 0.5.4 allow remote attackers to execute arbitrary PHP code via a URL in the page[path] parameter to (1) index.php, (2) admin.php, (3) rss.php, (4) rdf.php, (5) rss2.php, or (6) files/mainfile.php.

3%
Низкий
больше 4 лет назад

Уязвимостей на страницу