Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 357 271

Количество 357 271

github логотип

GHSA-xp43-rj4q-98f6

около 4 лет назад

A consistency issue existed in the handling of application snapshots. The issue was addressed with improved handling of notes deletions. This issue affected versions prior to iOS 12.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-xp43-gqwv-mmjp

около 4 лет назад

Heimdal Thor Agent 2.5.17x before 2.5.173 does not verify X.509 certificates from TLS servers, which allows remote attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xp43-g5gh-f86x

3 месяца назад

A race condition was addressed with additional validation. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to access sensitive user data.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xp42-qr2q-c463

15 дней назад

Pivotick fails to sanitize attacker-controlled SVG markup supplied through the per-node style.svgIcon property before inserting it into the document. When rendering a graph node, the vulnerable code assigns the SVG icon markup directly to the innerHTML property of a live SVG element. An attacker able to influence graph data can provide crafted markup containing executable event handlers, such as an <image> element with an onerror attribute. When a victim loads or renders the malicious graph, the payload may execute arbitrary JavaScript in the security context of the application embedding Pivotick. Successful exploitation could allow the attacker to access application data available to the victim, modify displayed content, or perform actions using the victim’s authenticated session. Exploitation requires an application using Pivotick to render graph data that is controlled or modified by an attacker.

EPSS: Низкий
github логотип

GHSA-xp42-g4qq-8cg3

больше 4 лет назад

Buffer overflow in ISS BlackICE Defender 2.9 and earlier, BlackICE Agent 3.0 and 3.1, and RealSecure Server Sensor 6.0.1 and 6.5 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a flood of large ICMP ping packets.

EPSS: Низкий
github логотип

GHSA-xp42-838x-6m32

больше 1 года назад

During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that could lead to an incorrect user privilege level in the VAPIX service account D-Bus API.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xp42-65qj-mvgv

больше 4 лет назад

expect before 5.32 searches for its libraries in /var/tmp before other directories, which could allow local users to gain root privileges via a Trojan horse library that is accessed by mkpasswd.

EPSS: Низкий
github логотип

GHSA-xp3x-85w4-72px

больше 4 лет назад

Parallel::ForkManager module before 1.0.0 for Perl does not properly handle temporary files.

EPSS: Низкий
github логотип

GHSA-xp3x-5m3g-5cqj

около 1 года назад

IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to a stack-based buffer overflow in db2fm, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xp3x-24fv-qfpm

около 4 лет назад

The resolver in dnscache in Daniel J. Bernstein djbdns 1.05 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack.

EPSS: Низкий
github логотип

GHSA-xp3w-r5p5-63rr

3 месяца назад

rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs

EPSS: Низкий
github логотип

GHSA-xp3w-m47v-rv5p

больше 4 лет назад

A certain ActiveX control in NCTWavChunksEditor2.dll 2.6.1.148 in NCTAudioStudio (NCTAudioStudio2) 2.7, as used by Sienzo DMM and probably other products, allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the CreateFile method, a different product than CVE-2007-3400.

EPSS: Средний
github логотип

GHSA-xp3w-6f4f-gvg7

3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Clear Present bit before tearing down context entry When tearing down a context entry, the current implementation zeros the entire 128-bit entry using multiple 64-bit writes. This creates a window where the hardware can fetch a "torn" entry — where some fields are already zeroed while the 'Present' bit is still set — leading to unpredictable behavior or spurious faults. While x86 provides strong write ordering, the compiler may reorder writes to the two 64-bit halves of the context entry. Even without compiler reordering, the hardware fetch is not guaranteed to be atomic with respect to multiple CPU writes. Align with the "Guidance to Software for Invalidations" in the VT-d spec (Section 6.5.3.3) by implementing the recommended ownership handshake: 1. Clear only the 'Present' (P) bit of the context entry first to signal the transition of ownership from hardware to software. 2. Use dma_wmb() t...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xp3v-xrxh-vpv7

около 4 лет назад

Open redirect vulnerability in GroupSession version 4.7.0 and earlier allows an attacker to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xp3r-qr68-xr3w

6 месяцев назад

The Worry Proof Backup plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.2.4 via the backup upload functionality. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload a malicious ZIP archive with path traversal sequences to write arbitrary files anywhere on the server, including executable PHP files. This can lead to remote code execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xp3r-c9h3-vjc7

больше 4 лет назад

Incorrect default permissions in the installer for the Intel(R) oneAPI Rendering Toolkit before version 2021.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

EPSS: Низкий
github логотип

GHSA-xp3r-9wx8-q2mm

почти 4 года назад

Agent-to-controller security bypass vulnerabilities in Jenkins Compuware Topaz for Total Test Plugin

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xp3q-55jv-wpp2

около 4 лет назад

Dell Inspiron 7352 BIOS versions prior to A12 contain a UEFI BIOS Boot Services overwrite vulnerability. A local attacker with access to system memory may exploit this vulnerability by overwriting the EFI_BOOT_SERVICES structure to execute arbitrary code in System Management Mode (SMM).

EPSS: Низкий
github логотип

GHSA-xp3p-hpx6-m9q4

больше 1 года назад

: Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Lexmark International CX, XC, CS, et. Al. (Postscript interpreter modules) allows Resource Injection.This issue affects CX, XC, CS, et. Al.: from 001.001:0 through 081.231, from *.*.P001 through *.*.P233, from *.*.P001 through *.*.P759, from *.*.P001 through *.*.P836.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xp3p-gg4w-cp3f

больше 4 лет назад

SQL injection vulnerability in podcast.php in Loudblog before 0.42 allows remote attackers to execute arbitrary SQL commands via the id parameter.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xp43-rj4q-98f6

A consistency issue existed in the handling of application snapshots. The issue was addressed with improved handling of notes deletions. This issue affected versions prior to iOS 12.

CVSS3: 3.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-xp43-gqwv-mmjp

Heimdal Thor Agent 2.5.17x before 2.5.173 does not verify X.509 certificates from TLS servers, which allows remote attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVSS3: 9.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-xp43-g5gh-f86x

A race condition was addressed with additional validation. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to access sensitive user data.

CVSS3: 5.5
0%
Низкий
3 месяца назад
github логотип
GHSA-xp42-qr2q-c463

Pivotick fails to sanitize attacker-controlled SVG markup supplied through the per-node style.svgIcon property before inserting it into the document. When rendering a graph node, the vulnerable code assigns the SVG icon markup directly to the innerHTML property of a live SVG element. An attacker able to influence graph data can provide crafted markup containing executable event handlers, such as an <image> element with an onerror attribute. When a victim loads or renders the malicious graph, the payload may execute arbitrary JavaScript in the security context of the application embedding Pivotick. Successful exploitation could allow the attacker to access application data available to the victim, modify displayed content, or perform actions using the victim’s authenticated session. Exploitation requires an application using Pivotick to render graph data that is controlled or modified by an attacker.

0%
Низкий
15 дней назад
github логотип
GHSA-xp42-g4qq-8cg3

Buffer overflow in ISS BlackICE Defender 2.9 and earlier, BlackICE Agent 3.0 and 3.1, and RealSecure Server Sensor 6.0.1 and 6.5 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a flood of large ICMP ping packets.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-xp42-838x-6m32

During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that could lead to an incorrect user privilege level in the VAPIX service account D-Bus API.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-xp42-65qj-mvgv

expect before 5.32 searches for its libraries in /var/tmp before other directories, which could allow local users to gain root privileges via a Trojan horse library that is accessed by mkpasswd.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xp3x-85w4-72px

Parallel::ForkManager module before 1.0.0 for Perl does not properly handle temporary files.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xp3x-5m3g-5cqj

IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2 is vulnerable to a stack-based buffer overflow in db2fm, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-xp3x-24fv-qfpm

The resolver in dnscache in Daniel J. Bernstein djbdns 1.05 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xp3w-r5p5-63rr

rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs

0%
Низкий
3 месяца назад
github логотип
GHSA-xp3w-m47v-rv5p

A certain ActiveX control in NCTWavChunksEditor2.dll 2.6.1.148 in NCTAudioStudio (NCTAudioStudio2) 2.7, as used by Sienzo DMM and probably other products, allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the CreateFile method, a different product than CVE-2007-3400.

31%
Средний
больше 4 лет назад
github логотип
GHSA-xp3w-6f4f-gvg7

In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Clear Present bit before tearing down context entry When tearing down a context entry, the current implementation zeros the entire 128-bit entry using multiple 64-bit writes. This creates a window where the hardware can fetch a "torn" entry — where some fields are already zeroed while the 'Present' bit is still set — leading to unpredictable behavior or spurious faults. While x86 provides strong write ordering, the compiler may reorder writes to the two 64-bit halves of the context entry. Even without compiler reordering, the hardware fetch is not guaranteed to be atomic with respect to multiple CPU writes. Align with the "Guidance to Software for Invalidations" in the VT-d spec (Section 6.5.3.3) by implementing the recommended ownership handshake: 1. Clear only the 'Present' (P) bit of the context entry first to signal the transition of ownership from hardware to software. 2. Use dma_wmb() t...

CVSS3: 7.5
0%
Низкий
3 месяца назад
github логотип
GHSA-xp3v-xrxh-vpv7

Open redirect vulnerability in GroupSession version 4.7.0 and earlier allows an attacker to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-xp3r-qr68-xr3w

The Worry Proof Backup plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.2.4 via the backup upload functionality. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload a malicious ZIP archive with path traversal sequences to write arbitrary files anywhere on the server, including executable PHP files. This can lead to remote code execution.

CVSS3: 8.8
1%
Низкий
6 месяцев назад
github логотип
GHSA-xp3r-c9h3-vjc7

Incorrect default permissions in the installer for the Intel(R) oneAPI Rendering Toolkit before version 2021.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xp3r-9wx8-q2mm

Agent-to-controller security bypass vulnerabilities in Jenkins Compuware Topaz for Total Test Plugin

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-xp3q-55jv-wpp2

Dell Inspiron 7352 BIOS versions prior to A12 contain a UEFI BIOS Boot Services overwrite vulnerability. A local attacker with access to system memory may exploit this vulnerability by overwriting the EFI_BOOT_SERVICES structure to execute arbitrary code in System Management Mode (SMM).

0%
Низкий
около 4 лет назад
github логотип
GHSA-xp3p-hpx6-m9q4

: Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Lexmark International CX, XC, CS, et. Al. (Postscript interpreter modules) allows Resource Injection.This issue affects CX, XC, CS, et. Al.: from 001.001:0 through 081.231, from *.*.P001 through *.*.P233, from *.*.P001 through *.*.P759, from *.*.P001 through *.*.P836.

CVSS3: 7.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-xp3p-gg4w-cp3f

SQL injection vulnerability in podcast.php in Loudblog before 0.42 allows remote attackers to execute arbitrary SQL commands via the id parameter.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу