Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 357 271

Количество 357 271

github логотип

GHSA-xmv4-xjjv-xxhf

больше 4 лет назад

Unknown vulnerability in AolSecurityPrivate.class in Oracle E-Business Suite 11i 11.1 through 11.6 allows remote attackers to bypass user authentication checks via unknown attack vectors.

EPSS: Низкий
github логотип

GHSA-xmv4-8r32-2jcg

больше 4 лет назад

The Secure Shell (SSH) Daemon (SSHD) in Sun Solaris 9 does not properly log IP addresses when SSHD is configured with the ListenAddress as 0.0.0.0, which makes it easier for remote attackers to hide the source of their activities.

EPSS: Низкий
github логотип

GHSA-xmv4-684g-76jm

почти 2 года назад

Windows Networking Denial of Service Vulnerability

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xmv4-4p35-4553

больше 4 лет назад

dump 0.4 b10 through b29 allows local users to cause a denial of service (execution prevention) by using flock() to lock the /etc/dumpdates file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xmv3-6frj-jrw8

больше 1 года назад

The Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.2. This is due to missing or incorrect nonce validation in class-wallet-user-table.php. This makes it possible for unauthenticated attackers to modify wallet balances via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xmv2-92jh-84fp

около 2 лет назад

The Tutor LMS plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on multiple functions in all versions up to, and including, 2.7.0. This makes it possible for unauthenticated attackers to add, modify, or delete data.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xmrx-vg29-jh4h

больше 1 года назад

A vulnerability has been found in Fujifilm Apeos C3070, Apeos C5570 and Apeos C6580 up to 24.8.28 and classified as critical. This vulnerability affects unknown code of the file /home/index.html#hashHome of the component Web Interface. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xmrx-pprf-648j

больше 1 года назад

An invalid memory access when handling the ProtocolIE_ID field of E-RAB Setup List Context SURes messages in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xmrx-grvp-76w7

6 месяцев назад

Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xmrw-rqq6-xq6g

почти 3 года назад

There is an unrestricted upload of file vulnerability in Generex CS141 below 2.06 version. An attacker could upload and/or delete any type of file, without any format restriction and without any authentication, in the "upload" directory.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xmrv-pmrh-hhx2

4 месяца назад

Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xmrv-59fp-82f5

больше 4 лет назад

Printer Setup in Apple Mac OS X 10.6 before 10.6.4 does not properly interpret character encoding, which allows remote attackers to cause a denial of service (printing failure) by deploying a printing device that has a Unicode character in its printing-service name.

EPSS: Низкий
github логотип

GHSA-xmrq-q3hv-6f55

около 4 лет назад

In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112661742

EPSS: Низкий
github логотип

GHSA-xmrp-mwjr-xmr4

больше 4 лет назад

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via vectors involving the MIRP instruction in a TrueType font.

EPSS: Низкий
github логотип

GHSA-xmrp-cj8j-54gr

около 4 лет назад

A vulnerability was discovered in NetIQ Sentinel Server 8.0 before 8.0.1 that may allow remote denial of service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xmrp-424f-vfpx

почти 2 года назад

SQLx Binary Protocol Misinterpretation caused by Truncating or Overflowing Casts

EPSS: Низкий
github логотип

GHSA-xmrm-qcgv-g7x6

около 4 лет назад

IBM BigFix Inventory v9 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xmrm-h387-3crm

около 4 лет назад

The web server in Wind River VxWorks 5.5 through 6.9 allows remote attackers to cause a denial of service (daemon crash) via a crafted URI.

EPSS: Низкий
github логотип

GHSA-xmrm-f5h6-fxm7

больше 4 лет назад

WFTPD Pro Server 3.21 Release 1, with the XeroxDocutech option enabled, allows local users to cause a denial of service (crash) via a (1) MKD or (2) XMKD command that causes an absolute path of 260 characters to be used, which overwrites a cookie with a null character, possibly due to an off-by-one error.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xmrj-wjpx-qx78

около 4 лет назад

A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Modicon X80 BMXNOR0200H RTU SV1.70 IR22 and prior that could cause information leak concerning the current RTU configuration including communication parameters dedicated to telemetry, when a specially crafted HTTP request is sent to the web server of the module.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xmv4-xjjv-xxhf

Unknown vulnerability in AolSecurityPrivate.class in Oracle E-Business Suite 11i 11.1 through 11.6 allows remote attackers to bypass user authentication checks via unknown attack vectors.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-xmv4-8r32-2jcg

The Secure Shell (SSH) Daemon (SSHD) in Sun Solaris 9 does not properly log IP addresses when SSHD is configured with the ListenAddress as 0.0.0.0, which makes it easier for remote attackers to hide the source of their activities.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xmv4-684g-76jm

Windows Networking Denial of Service Vulnerability

CVSS3: 6.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-xmv4-4p35-4553

dump 0.4 b10 through b29 allows local users to cause a denial of service (execution prevention) by using flock() to lock the /etc/dumpdates file.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xmv3-6frj-jrw8

The Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.2. This is due to missing or incorrect nonce validation in class-wallet-user-table.php. This makes it possible for unauthenticated attackers to modify wallet balances via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-xmv2-92jh-84fp

The Tutor LMS plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on multiple functions in all versions up to, and including, 2.7.0. This makes it possible for unauthenticated attackers to add, modify, or delete data.

CVSS3: 9.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-xmrx-vg29-jh4h

A vulnerability has been found in Fujifilm Apeos C3070, Apeos C5570 and Apeos C6580 up to 24.8.28 and classified as critical. This vulnerability affects unknown code of the file /home/index.html#hashHome of the component Web Interface. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-xmrx-pprf-648j

An invalid memory access when handling the ProtocolIE_ID field of E-RAB Setup List Context SURes messages in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xmrx-grvp-76w7

Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-xmrw-rqq6-xq6g

There is an unrestricted upload of file vulnerability in Generex CS141 below 2.06 version. An attacker could upload and/or delete any type of file, without any format restriction and without any authentication, in the "upload" directory.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-xmrv-pmrh-hhx2

Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder

CVSS3: 5.9
4 месяца назад
github логотип
GHSA-xmrv-59fp-82f5

Printer Setup in Apple Mac OS X 10.6 before 10.6.4 does not properly interpret character encoding, which allows remote attackers to cause a denial of service (printing failure) by deploying a printing device that has a Unicode character in its printing-service name.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xmrq-q3hv-6f55

In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112661742

1%
Низкий
около 4 лет назад
github логотип
GHSA-xmrp-mwjr-xmr4

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via vectors involving the MIRP instruction in a TrueType font.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-xmrp-cj8j-54gr

A vulnerability was discovered in NetIQ Sentinel Server 8.0 before 8.0.1 that may allow remote denial of service.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-xmrp-424f-vfpx

SQLx Binary Protocol Misinterpretation caused by Truncating or Overflowing Casts

почти 2 года назад
github логотип
GHSA-xmrm-qcgv-g7x6

IBM BigFix Inventory v9 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.

CVSS3: 5.9
1%
Низкий
около 4 лет назад
github логотип
GHSA-xmrm-h387-3crm

The web server in Wind River VxWorks 5.5 through 6.9 allows remote attackers to cause a denial of service (daemon crash) via a crafted URI.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xmrm-f5h6-fxm7

WFTPD Pro Server 3.21 Release 1, with the XeroxDocutech option enabled, allows local users to cause a denial of service (crash) via a (1) MKD or (2) XMKD command that causes an absolute path of 260 characters to be used, which overwrites a cookie with a null character, possibly due to an off-by-one error.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xmrj-wjpx-qx78

A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Modicon X80 BMXNOR0200H RTU SV1.70 IR22 and prior that could cause information leak concerning the current RTU configuration including communication parameters dedicated to telemetry, when a specially crafted HTTP request is sent to the web server of the module.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу