Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 357 575

Количество 357 575

github логотип

GHSA-xmjx-29fm-9qh3

12 месяцев назад

In bnepu_check_send_packet of bnep_utils.cc, there is a possible way to achieve code execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-xmjw-8f7c-p37x

больше 2 лет назад

The Herd Effects WordPress plugin before 5.2.7 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting effects via CSRF attacks

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xmjv-mc2x-g7m6

больше 2 лет назад

Transient DOS while decoding the ToBeSignedMessage in Automotive Telematics.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xmjv-jv6c-x229

почти 4 года назад

Heap buffer overflow in Downloads in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xmjv-hhr3-54jq

2 дня назад

Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xmjv-g5m4-rc75

около 4 лет назад

Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous before 15.017.20050 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4191, CVE-2016-4192, CVE-2016-4193, CVE-2016-4194, CVE-2016-4196, CVE-2016-4197, CVE-2016-4198, CVE-2016-4199, CVE-2016-4200, CVE-2016-4201, CVE-2016-4202, CVE-2016-4203, CVE-2016-4204, CVE-2016-4205, CVE-2016-4206, CVE-2016-4207, CVE-2016-4208, CVE-2016-4211, CVE-2016-4212, CVE-2016-4213, CVE-2016-4214, CVE-2016-4250, CVE-2016-4251, CVE-2016-4252, and CVE-2016-4254.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xmjv-8g3f-2ppc

3 месяца назад

Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xmjv-5hmh-hg5p

больше 4 лет назад

CGI.pl in Bugzilla before 2.14.1, when using LDAP, allows remote attackers to obtain an anonymous bind to the LDAP server via a request that does not include a password, which causes a null password to be sent to the LDAP server.

EPSS: Низкий
github логотип

GHSA-xmjr-qq5c-jp94

больше 4 лет назад

The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbitrary JavaScript code with chrome privileges by using an IDL fragment to trigger a window.open call.

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-xmjq-j83c-q6g4

2 месяца назад

In a CVX cluster, an EOS switch connected to a CVX server is not resilient to certain malformed messages received from the connected CVX server. Similarly, the CVX server is not resilient to certain malformed messages received from the connected EOS switch. This leads to either a Sysdb agent crash on the EOS device causing a soft reset of the switch or agent crashes on the CVX server causing instability of the CVX cluster. An attacker could use this behavior to create a denial of service (DoS) scenario. Note that this would require the attacker to already have a high privilege access to the connected device to be able to send custom TCP packets. EOS switches that are not connected to a CVX server are not impacted.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xmjq-8xh6-q7gf

10 месяцев назад

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.6.3195 build 20250715 and later QuTS hero h5.2.6.3195 build 20250715 and later

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-xmjp-8ccm-cf6h

около 4 лет назад

OpenSSL 1.1.1 introduced a rewritten random number generator (RNG). This was intended to include protection in the event of a fork() system call in order to ensure that the parent and child processes did not share the same RNG state. However this protection was not being used in the default case. A partial mitigation for this issue is that the output from a high precision timer is mixed into the RNG state so the likelihood of a parent and child process sharing state is significantly reduced. If an application already calls OPENSSL_init_crypto() explicitly using OPENSSL_INIT_ATFORK then this problem does not occur at all. Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c).

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xmjp-848v-p77x

около 4 лет назад

Use after free in Performance Manager in Google Chrome prior to 102.0.5005.61 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xmjp-4jm4-9f5j

больше 4 лет назад

Unspecified vulnerability in the ClickHeat plugin, as used in phpMyVisites before 2.4, has unknown impact and attack vectors. NOTE: due to lack of details from the vendor, it is not clear whether this is related to CVE-2008-5793.

EPSS: Низкий
github логотип

GHSA-xmjm-q7mc-q87x

около 4 лет назад

An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36714120.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xmjm-86qv-g226

5 месяцев назад

AVideo Affected by Arbitrary File Deletion via Path Traversal in CloneSite deleteDump Parameter

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xmjj-rc4w-452x

больше 3 лет назад

D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the webpage parameter at /goform/formWlanGuestSetup.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xmjj-hvvj-3jr6

3 месяца назад

Craft CMS 5.9.5 and earlier contains a Missing Authorization vulnerability in the migrate endpoint (/actions/app/migrate).

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xmjj-hrw9-x35m

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: media: venus: fix use after free in vdec_close There appears to be a possible use after free with vdec_close(). The firmware will add buffer release work to the work queue through HFI callbacks as a normal part of decoding. Randomly closing the decoder device from userspace during normal decoding can incur a read after free for inst. Fix it by cancelling the work in vdec_close.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xmjj-3c76-5w84

больше 4 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in directus

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xmjx-29fm-9qh3

In bnepu_check_send_packet of bnep_utils.cc, there is a possible way to achieve code execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 8.4
0%
Низкий
12 месяцев назад
github логотип
GHSA-xmjw-8f7c-p37x

The Herd Effects WordPress plugin before 5.2.7 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting effects via CSRF attacks

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xmjv-mc2x-g7m6

Transient DOS while decoding the ToBeSignedMessage in Automotive Telematics.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xmjv-jv6c-x229

Heap buffer overflow in Downloads in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
2%
Низкий
почти 4 года назад
github логотип
GHSA-xmjv-hhr3-54jq

Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.

CVSS3: 5.5
0%
Низкий
2 дня назад
github логотип
GHSA-xmjv-g5m4-rc75

Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous before 15.017.20050 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4191, CVE-2016-4192, CVE-2016-4193, CVE-2016-4194, CVE-2016-4196, CVE-2016-4197, CVE-2016-4198, CVE-2016-4199, CVE-2016-4200, CVE-2016-4201, CVE-2016-4202, CVE-2016-4203, CVE-2016-4204, CVE-2016-4205, CVE-2016-4206, CVE-2016-4207, CVE-2016-4208, CVE-2016-4211, CVE-2016-4212, CVE-2016-4213, CVE-2016-4214, CVE-2016-4250, CVE-2016-4251, CVE-2016-4252, and CVE-2016-4254.

CVSS3: 8.8
4%
Низкий
около 4 лет назад
github логотип
GHSA-xmjv-8g3f-2ppc

Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.

CVSS3: 7.2
1%
Низкий
3 месяца назад
github логотип
GHSA-xmjv-5hmh-hg5p

CGI.pl in Bugzilla before 2.14.1, when using LDAP, allows remote attackers to obtain an anonymous bind to the LDAP server via a request that does not include a password, which causes a null password to be sent to the LDAP server.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xmjr-qq5c-jp94

The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbitrary JavaScript code with chrome privileges by using an IDL fragment to trigger a window.open call.

CVSS3: 9.8
82%
Высокий
больше 4 лет назад
github логотип
GHSA-xmjq-j83c-q6g4

In a CVX cluster, an EOS switch connected to a CVX server is not resilient to certain malformed messages received from the connected CVX server. Similarly, the CVX server is not resilient to certain malformed messages received from the connected EOS switch. This leads to either a Sysdb agent crash on the EOS device causing a soft reset of the switch or agent crashes on the CVX server causing instability of the CVX cluster. An attacker could use this behavior to create a denial of service (DoS) scenario. Note that this would require the attacker to already have a high privilege access to the connected device to be able to send custom TCP packets. EOS switches that are not connected to a CVX server are not impacted.

CVSS3: 6.5
0%
Низкий
2 месяца назад
github логотип
GHSA-xmjq-8xh6-q7gf

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.6.3195 build 20250715 and later QuTS hero h5.2.6.3195 build 20250715 and later

CVSS3: 4.9
0%
Низкий
10 месяцев назад
github логотип
GHSA-xmjp-8ccm-cf6h

OpenSSL 1.1.1 introduced a rewritten random number generator (RNG). This was intended to include protection in the event of a fork() system call in order to ensure that the parent and child processes did not share the same RNG state. However this protection was not being used in the default case. A partial mitigation for this issue is that the output from a high precision timer is mixed into the RNG state so the likelihood of a parent and child process sharing state is significantly reduced. If an application already calls OPENSSL_init_crypto() explicitly using OPENSSL_INIT_ATFORK then this problem does not occur at all. Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c).

CVSS3: 5.3
6%
Низкий
около 4 лет назад
github логотип
GHSA-xmjp-848v-p77x

Use after free in Performance Manager in Google Chrome prior to 102.0.5005.61 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xmjp-4jm4-9f5j

Unspecified vulnerability in the ClickHeat plugin, as used in phpMyVisites before 2.4, has unknown impact and attack vectors. NOTE: due to lack of details from the vendor, it is not clear whether this is related to CVE-2008-5793.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xmjm-q7mc-q87x

An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36714120.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-xmjm-86qv-g226

AVideo Affected by Arbitrary File Deletion via Path Traversal in CloneSite deleteDump Parameter

CVSS3: 8.1
1%
Низкий
5 месяцев назад
github логотип
GHSA-xmjj-rc4w-452x

D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the webpage parameter at /goform/formWlanGuestSetup.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xmjj-hvvj-3jr6

Craft CMS 5.9.5 and earlier contains a Missing Authorization vulnerability in the migrate endpoint (/actions/app/migrate).

CVSS3: 7.3
0%
Низкий
3 месяца назад
github логотип
GHSA-xmjj-hrw9-x35m

In the Linux kernel, the following vulnerability has been resolved: media: venus: fix use after free in vdec_close There appears to be a possible use after free with vdec_close(). The firmware will add buffer release work to the work queue through HFI callbacks as a normal part of decoding. Randomly closing the decoder device from userspace during normal decoding can incur a read after free for inst. Fix it by cancelling the work in vdec_close.

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-xmjj-3c76-5w84

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in directus

CVSS3: 8.8
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу