Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 357 271

Количество 357 271

github логотип

GHSA-xp6v-qx65-4pp7

почти 5 лет назад

Data races in gfwx

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-xp6v-frx8-276h

около 4 лет назад

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web management portal. The issue lies in the lack of proper validation of user data before executing a system call. An attacker could leverage this vulnerability to execute code with root privileges. Was ZDI-CAN-4892.

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-xp6v-2px2-m727

больше 4 лет назад

Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 on Windows XP SP2 and SP3, and 6 on Windows Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka "Uninitialized Memory Corruption Vulnerability."

EPSS: Средний
github логотип

GHSA-xp6r-hhmh-jgfj

около 4 лет назад

Multiple unspecified vulnerabilities in phpns before 2.1.1beta1 have unknown impact and attack vectors.

EPSS: Низкий
github логотип

GHSA-xp6r-8pcc-xv5p

3 месяца назад

BillaBear is Vulnerable to SQL Injection in the EventRepository

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xp6r-5ghh-6w2m

больше 4 лет назад

Directory traversal vulnerability in editconfig_gedcom.php for phpGedView 2.65.1 and earlier allows remote attackers to read arbitrary files or execute arbitrary PHP programs on the server via .. (dot dot) sequences in the gedcom_config parameter.

EPSS: Низкий
github логотип

GHSA-xp6r-3p5r-p29g

около 4 лет назад

The dissect_capwap_data function in epan/dissectors/packet-capwap.c in the CAPWAP dissector in Wireshark 1.6.x before 1.6.16 and 1.8.x before 1.8.8 incorrectly uses a -1 data value to represent an error condition, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

EPSS: Средний
github логотип

GHSA-xp6q-cm7h-qg74

около 3 лет назад

An issue was discovered in the Linux kernel through 6.1-rc8. dpu_crtc_atomic_check in drivers/gpu/drm/msm/disp/dpu1/dpu_crtc.c lacks check of the return value of kzalloc() and will cause the NULL Pointer Dereference.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xp6q-4ch5-xqhr

7 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: ext4: refuse to create ea block when umounted The ea block expansion need to access s_root while it is already set as NULL when umount is triggered. Refuse this request to avoid panic.

EPSS: Низкий
github логотип

GHSA-xp6q-36fr-27p3

больше 2 лет назад

The GeneratePress Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom meta output in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-xp6p-29w5-vq4h

около 4 лет назад

Windows Print Configuration Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xp6m-95m6-gvf5

почти 4 года назад

Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /clearance/clearance.php.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xp6m-4hv5-x9xm

около 4 лет назад

Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system. One of the SQL injection vulnerabilities that affects Unified CM IM&P also affects Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) and could allow an attacker to conduct SQL injection attacks on an affected system. For more information about these vulnerabilities, see the Details section of this advisory.

EPSS: Низкий
github логотип

GHSA-xp6j-92jr-gwc5

около 3 лет назад

Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter time at /goform/PowerSaveSet.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-xp6j-2qr8-4336

больше 4 лет назад

Null Pointer Dereference Caused Segmentation Fault in GitHub repository gpac/gpac prior to 2.1.0-DEV.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-xp6h-v5w9-gwqx

около 4 лет назад

A vulnerability has been identified in SICAM GridEdge Essential ARM (All versions), SICAM GridEdge Essential Intel (All versions < V2.7.3), SICAM GridEdge Essential with GDS ARM (All versions), SICAM GridEdge Essential with GDS Intel (All versions < V2.7.3). Affected software uses an improperly protected file to import SSH keys. Attackers with access to the filesystem of the host on which SICAM GridEdge runs, are able to inject a custom SSH key to that file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xp6h-p4cj-42w8

около 2 лет назад

An issue was discovered in linqi before 1.4.0.1 on Windows. There is LDAP injection.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xp6g-r6xf-wr5c

почти 3 года назад

Xpand IT Write-back manager v2.3.1 uses a hardcoded salt in license class configuration which leads to the generation of a hardcoded and predictable symmetric encryption keys for license generation and validation.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xp6f-qvg9-mcgm

около 4 лет назад

The kernel module has the race condition vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-xp6f-p933-2gqg

6 месяцев назад

Galaxy FDS Android SDK (XiaoMi/galaxy-fds-sdk-android) version 3.0.8 and prior disable TLS hostname verification when HTTPS is enabled (the default configuration). In GalaxyFDSClientImpl.createHttpClient(), the SDK configures Apache HttpClient with SSLSocketFactory.ALLOW_ALL_HOSTNAME_VERIFIER, which accepts any valid TLS certificate regardless of hostname mismatch. Because HTTPS is enabled by default in FDSClientConfiguration, all applications using the SDK with default settings are affected. This vulnerability allows a man-in-the-middle attacker to intercept and modify SDK communications to Xiaomi FDS cloud storage endpoints, potentially exposing authentication credentials, file contents, and API responses. The XiaoMi/galaxy-fds-sdk-android open source project has reached end-of-life status.

CVSS3: 7.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xp6v-qx65-4pp7

Data races in gfwx

CVSS3: 7
0%
Низкий
почти 5 лет назад
github логотип
GHSA-xp6v-frx8-276h

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web management portal. The issue lies in the lack of proper validation of user data before executing a system call. An attacker could leverage this vulnerability to execute code with root privileges. Was ZDI-CAN-4892.

CVSS3: 9.8
88%
Высокий
около 4 лет назад
github логотип
GHSA-xp6v-2px2-m727

Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 on Windows XP SP2 and SP3, and 6 on Windows Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka "Uninitialized Memory Corruption Vulnerability."

29%
Средний
больше 4 лет назад
github логотип
GHSA-xp6r-hhmh-jgfj

Multiple unspecified vulnerabilities in phpns before 2.1.1beta1 have unknown impact and attack vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xp6r-8pcc-xv5p

BillaBear is Vulnerable to SQL Injection in the EventRepository

CVSS3: 8.8
0%
Низкий
3 месяца назад
github логотип
GHSA-xp6r-5ghh-6w2m

Directory traversal vulnerability in editconfig_gedcom.php for phpGedView 2.65.1 and earlier allows remote attackers to read arbitrary files or execute arbitrary PHP programs on the server via .. (dot dot) sequences in the gedcom_config parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xp6r-3p5r-p29g

The dissect_capwap_data function in epan/dissectors/packet-capwap.c in the CAPWAP dissector in Wireshark 1.6.x before 1.6.16 and 1.8.x before 1.8.8 incorrectly uses a -1 data value to represent an error condition, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

61%
Средний
около 4 лет назад
github логотип
GHSA-xp6q-cm7h-qg74

An issue was discovered in the Linux kernel through 6.1-rc8. dpu_crtc_atomic_check in drivers/gpu/drm/msm/disp/dpu1/dpu_crtc.c lacks check of the return value of kzalloc() and will cause the NULL Pointer Dereference.

CVSS3: 5.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-xp6q-4ch5-xqhr

In the Linux kernel, the following vulnerability has been resolved: ext4: refuse to create ea block when umounted The ea block expansion need to access s_root while it is already set as NULL when umount is triggered. Refuse this request to avoid panic.

0%
Низкий
7 месяцев назад
github логотип
GHSA-xp6q-36fr-27p3

The GeneratePress Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom meta output in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xp6p-29w5-vq4h

Windows Print Configuration Elevation of Privilege Vulnerability

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xp6m-95m6-gvf5

Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /clearance/clearance.php.

CVSS3: 7.2
1%
Низкий
почти 4 года назад
github логотип
GHSA-xp6m-4hv5-x9xm

Multiple vulnerabilities in Cisco Unified Communications Manager IM &amp; Presence Service (Unified CM IM&amp;P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system. One of the SQL injection vulnerabilities that affects Unified CM IM&amp;P also affects Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) and could allow an attacker to conduct SQL injection attacks on an affected system. For more information about these vulnerabilities, see the Details section of this advisory.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xp6j-92jr-gwc5

Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter time at /goform/PowerSaveSet.

CVSS3: 6.7
0%
Низкий
около 3 лет назад
github логотип
GHSA-xp6j-2qr8-4336

Null Pointer Dereference Caused Segmentation Fault in GitHub repository gpac/gpac prior to 2.1.0-DEV.

CVSS3: 5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xp6h-v5w9-gwqx

A vulnerability has been identified in SICAM GridEdge Essential ARM (All versions), SICAM GridEdge Essential Intel (All versions < V2.7.3), SICAM GridEdge Essential with GDS ARM (All versions), SICAM GridEdge Essential with GDS Intel (All versions < V2.7.3). Affected software uses an improperly protected file to import SSH keys. Attackers with access to the filesystem of the host on which SICAM GridEdge runs, are able to inject a custom SSH key to that file.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-xp6h-p4cj-42w8

An issue was discovered in linqi before 1.4.0.1 on Windows. There is LDAP injection.

CVSS3: 9.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-xp6g-r6xf-wr5c

Xpand IT Write-back manager v2.3.1 uses a hardcoded salt in license class configuration which leads to the generation of a hardcoded and predictable symmetric encryption keys for license generation and validation.

CVSS3: 6.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-xp6f-qvg9-mcgm

The kernel module has the race condition vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.

CVSS3: 4.7
0%
Низкий
около 4 лет назад
github логотип
GHSA-xp6f-p933-2gqg

Galaxy FDS Android SDK (XiaoMi/galaxy-fds-sdk-android) version 3.0.8 and prior disable TLS hostname verification when HTTPS is enabled (the default configuration). In GalaxyFDSClientImpl.createHttpClient(), the SDK configures Apache HttpClient with SSLSocketFactory.ALLOW_ALL_HOSTNAME_VERIFIER, which accepts any valid TLS certificate regardless of hostname mismatch. Because HTTPS is enabled by default in FDSClientConfiguration, all applications using the SDK with default settings are affected. This vulnerability allows a man-in-the-middle attacker to intercept and modify SDK communications to Xiaomi FDS cloud storage endpoints, potentially exposing authentication credentials, file contents, and API responses. The XiaoMi/galaxy-fds-sdk-android open source project has reached end-of-life status.

CVSS3: 7.4
0%
Низкий
6 месяцев назад

Уязвимостей на страницу