Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 357 575

Количество 357 575

github логотип

GHSA-xmp7-hhpr-wjgh

около 3 лет назад

An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to gain access to already freed memory. This affects Valhall r29p0 through r42p0 before r43p0, and Arm's GPU Architecture Gen5 r41p0 through r42p0 before r43p0.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xmp6-3vj6-r6rw

больше 2 лет назад

The EazyDocs WordPress plugin before 2.4.0 re-introduced CVE-2023-6029 (https://wpscan.com/vulnerability/7a0aaf85-8130-4fd7-8f09-f8edc929597e/) in 2.3.8, allowing any authenticated users, such as subscriber to delete arbitrary posts, as well as add and delete documents/sections. The issue was partially fixed in 2.3.9.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xmp5-h76r-9q95

около 4 лет назад

The Etoile Ultimate Product Catalog plugin 4.2.11 for WordPress has XSS in the Add Product Manually component.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xmp5-g5f6-23g3

больше 4 лет назад

mgetty 1.1.22 allows local users to overwrite arbitrary files via a symlink attack in some configurations.

EPSS: Низкий
github логотип

GHSA-xmp4-jqff-7hx8

около 4 лет назад

The issue was addressed with improved permissions logic. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to execute arbitrary code with system privileges.

EPSS: Низкий
github логотип

GHSA-xmp4-h2gm-vggg

около 4 лет назад

EMC Documentum TaskSpace (TSP) 6.7SP1 before P25 and 6.7SP2 before P11 allows remote authenticated users to read arbitrary files via a modified imaging-service URL.

EPSS: Низкий
github логотип

GHSA-xmp3-wh2p-c8cq

около 4 лет назад

Unspecified vulnerability in the Oracle Communications Messaging Server (Sun Java System Messaging Server) component in Oracle Sun Products Suite 6.0, 6.2, 6.3, and 7.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Web Mail.

EPSS: Низкий
github логотип

GHSA-xmp3-7745-g4vj

около 2 лет назад

ezsystems/ez-support-tools Failing access control in system info view

EPSS: Низкий
github логотип

GHSA-xmp3-76fc-6jhm

больше 4 лет назад

In Ifme, versions 1.0.0 to v.7.33.2 don’t properly invalidate a user’s session even after the user initiated logout. It makes it possible for an attacker to reuse the admin cookies either via local/network access or by other hypothetical attacks.

EPSS: Низкий
github логотип

GHSA-xmp2-p923-f7r4

около 4 лет назад

Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2051, CVE-2012-4147, CVE-2012-4148, CVE-2012-4149, CVE-2012-4150, CVE-2012-4151, CVE-2012-4153, CVE-2012-4154, CVE-2012-4155, CVE-2012-4156, CVE-2012-4157, CVE-2012-4158, CVE-2012-4159, and CVE-2012-4160.

EPSS: Низкий
github логотип

GHSA-xmp2-8crv-9642

около 4 лет назад

Cisco Mobility Services Engine (MSE) 8.0(110.0) allows remote authenticated users to discover the passwords of arbitrary users by (1) reading log files or (2) using an unspecified GUI feature, aka Bug ID CSCut24792.

EPSS: Низкий
github логотип

GHSA-xmmx-p598-4c34

больше 4 лет назад

Multiple PHP remote file inclusion vulnerabilities in myWebland myEvent 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the myevent_path parameter in (1) event.php and (2) initialize.php. NOTE: vector 2 was later reported to affect 1.4 as well.

EPSS: Низкий
github логотип

GHSA-xmmx-hv46-7cxp

больше 4 лет назад

An unauthenticated remote command execution exists in Aruba ClearPass Policy Manager on linked devices. The ClearPass OnConnect feature permits administrators to link other network devices into ClearPass for the purpose of collecting enhanced information about connected endpoints. A defect in the API could allow a remote attacker to execute arbitrary commands on one of the linked devices. This vulnerability is only applicable if credentials for devices have been supplied to ClearPass under Configuration -> Network -> Devices -> CLI Settings. Resolution: Fixed in 6.7.5 and 6.6.10-hotfix.

CVSS3: 9
EPSS: Низкий
github логотип

GHSA-xmmx-7jpf-fx42

около 2 лет назад

Moby (Docker Engine) is vulnerable to Ambiguous OCI manifest parsing

EPSS: Низкий
github логотип

GHSA-xmmw-wq4f-3pw5

около 4 лет назад

An issue was discovered in certain Verbatim drives through 2022-03-31. Due to an insecure design, they can be unlocked by an attacker who can then gain unauthorized access to the stored data. The attacker can simply use an undocumented IOCTL command that retrieves the correct password. This affects Executive Fingerprint Secure SSD GDMSFE01-INI3637-C VER1.1 and Fingerprint Secure Portable Hard Drive Part Number #53650.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-xmmw-q4pv-3gc3

около 4 лет назад

An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Installer Elevation of Privilege Vulnerability'.

EPSS: Низкий
github логотип

GHSA-xmmv-36rj-v7p3

около 4 лет назад

An information disclosure vulnerability in Fortinet FortiOS 6.0.1, 5.6.7 and below allows attacker to reveals serial number of FortiGate via hostname field defined in connection control setup packets of PPTP protocol.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xmmr-4rx9-36g5

почти 4 года назад

UPSMON PRO transmits sensitive data in cleartext over HTTP protocol. An unauthenticated remote attacker can exploit this vulnerability to access sensitive data.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xmmq-r9j8-c4xc

около 4 лет назад

An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Android ID: A-30907120. References: NVIDIA N-CVE-2016-6734.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xmmq-q6w3-q767

больше 4 лет назад

Incorrect handling of history on iOS in Navigation in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xmp7-hhpr-wjgh

An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to gain access to already freed memory. This affects Valhall r29p0 through r42p0 before r43p0, and Arm's GPU Architecture Gen5 r41p0 through r42p0 before r43p0.

CVSS3: 5.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-xmp6-3vj6-r6rw

The EazyDocs WordPress plugin before 2.4.0 re-introduced CVE-2023-6029 (https://wpscan.com/vulnerability/7a0aaf85-8130-4fd7-8f09-f8edc929597e/) in 2.3.8, allowing any authenticated users, such as subscriber to delete arbitrary posts, as well as add and delete documents/sections. The issue was partially fixed in 2.3.9.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xmp5-h76r-9q95

The Etoile Ultimate Product Catalog plugin 4.2.11 for WordPress has XSS in the Add Product Manually component.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-xmp5-g5f6-23g3

mgetty 1.1.22 allows local users to overwrite arbitrary files via a symlink attack in some configurations.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xmp4-jqff-7hx8

The issue was addressed with improved permissions logic. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to execute arbitrary code with system privileges.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xmp4-h2gm-vggg

EMC Documentum TaskSpace (TSP) 6.7SP1 before P25 and 6.7SP2 before P11 allows remote authenticated users to read arbitrary files via a modified imaging-service URL.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xmp3-wh2p-c8cq

Unspecified vulnerability in the Oracle Communications Messaging Server (Sun Java System Messaging Server) component in Oracle Sun Products Suite 6.0, 6.2, 6.3, and 7.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Web Mail.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xmp3-7745-g4vj

ezsystems/ez-support-tools Failing access control in system info view

около 2 лет назад
github логотип
GHSA-xmp3-76fc-6jhm

In Ifme, versions 1.0.0 to v.7.33.2 don’t properly invalidate a user’s session even after the user initiated logout. It makes it possible for an attacker to reuse the admin cookies either via local/network access or by other hypothetical attacks.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xmp2-p923-f7r4

Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2051, CVE-2012-4147, CVE-2012-4148, CVE-2012-4149, CVE-2012-4150, CVE-2012-4151, CVE-2012-4153, CVE-2012-4154, CVE-2012-4155, CVE-2012-4156, CVE-2012-4157, CVE-2012-4158, CVE-2012-4159, and CVE-2012-4160.

8%
Низкий
около 4 лет назад
github логотип
GHSA-xmp2-8crv-9642

Cisco Mobility Services Engine (MSE) 8.0(110.0) allows remote authenticated users to discover the passwords of arbitrary users by (1) reading log files or (2) using an unspecified GUI feature, aka Bug ID CSCut24792.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xmmx-p598-4c34

Multiple PHP remote file inclusion vulnerabilities in myWebland myEvent 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the myevent_path parameter in (1) event.php and (2) initialize.php. NOTE: vector 2 was later reported to affect 1.4 as well.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-xmmx-hv46-7cxp

An unauthenticated remote command execution exists in Aruba ClearPass Policy Manager on linked devices. The ClearPass OnConnect feature permits administrators to link other network devices into ClearPass for the purpose of collecting enhanced information about connected endpoints. A defect in the API could allow a remote attacker to execute arbitrary commands on one of the linked devices. This vulnerability is only applicable if credentials for devices have been supplied to ClearPass under Configuration -> Network -> Devices -> CLI Settings. Resolution: Fixed in 6.7.5 and 6.6.10-hotfix.

CVSS3: 9
3%
Низкий
больше 4 лет назад
github логотип
GHSA-xmmx-7jpf-fx42

Moby (Docker Engine) is vulnerable to Ambiguous OCI manifest parsing

около 2 лет назад
github логотип
GHSA-xmmw-wq4f-3pw5

An issue was discovered in certain Verbatim drives through 2022-03-31. Due to an insecure design, they can be unlocked by an attacker who can then gain unauthorized access to the stored data. The attacker can simply use an undocumented IOCTL command that retrieves the correct password. This affects Executive Fingerprint Secure SSD GDMSFE01-INI3637-C VER1.1 and Fingerprint Secure Portable Hard Drive Part Number #53650.

CVSS3: 4.6
0%
Низкий
около 4 лет назад
github логотип
GHSA-xmmw-q4pv-3gc3

An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Installer Elevation of Privilege Vulnerability'.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xmmv-36rj-v7p3

An information disclosure vulnerability in Fortinet FortiOS 6.0.1, 5.6.7 and below allows attacker to reveals serial number of FortiGate via hostname field defined in connection control setup packets of PPTP protocol.

CVSS3: 5.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-xmmr-4rx9-36g5

UPSMON PRO transmits sensitive data in cleartext over HTTP protocol. An unauthenticated remote attacker can exploit this vulnerability to access sensitive data.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-xmmq-r9j8-c4xc

An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Android ID: A-30907120. References: NVIDIA N-CVE-2016-6734.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xmmq-q6w3-q767

Incorrect handling of history on iOS in Navigation in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу