Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 357 575

Количество 357 575

github логотип

GHSA-xmc6-5pwj-wqwj

около 4 лет назад

The Tightrope Media Carousel Seneca HDn Windows-based appliance 7.0.4.104 is shipped with a default local administrator username and password. This can be found by a limited user account in an "unattend.xml" file left over on the C: drive from the Sysprep process. An attacker with this username and password can leverage it to gain administrator-level access on the system.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xmc5-7cww-2h26

больше 4 лет назад

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could allow a remote code execution when a file is saved. Affected Product: C-Bus Toolkit (V1.15.9 and prior), C-Gate Server (V2.11.7 and prior)

EPSS: Низкий
github логотип

GHSA-xmc5-26p9-v4x6

около 4 лет назад

WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions and then using host requests to redirect script loads to a malicious site. This allows a malicious extension to then install additional extensions without explicit user permission. This vulnerability affects Firefox < 51.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xmc4-vj3p-mc7g

около 4 лет назад

accounts/ValidateAnswers in the security-questions implementation in ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 makes it easier for remote attackers to reset user passwords, and consequently obtain access to arbitrary user accounts, via a modified (1) Hide_Captcha or (2) quesList parameter in a validateAll action.

EPSS: Низкий
github логотип

GHSA-xmc4-rjq5-7xw2

около 4 лет назад

The CoreGraphics component in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2015-5925.

EPSS: Низкий
github логотип

GHSA-xmc3-9m9j-w9x4

больше 3 лет назад

cocagne pysrp vulnerable to side channel leaks

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xmc3-8wf5-r59w

больше 2 лет назад

Memory corruption in Boot while running a ListVars test in UEFI Menu during boot.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xmc2-qrxf-m6gc

около 4 лет назад

The vips-7.22 script in VIPS 7.22.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

EPSS: Низкий
github логотип

GHSA-xmc2-ppwc-cgqq

около 4 лет назад

Microsoft Internet Explorer 11 and Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2447.

EPSS: Средний
github логотип

GHSA-xmc2-gfmw-wmhg

больше 4 лет назад

Buffer overflow in the (1) oracle and (2) oracleO programs in Oracle 9i Database 9.0.x and 9.2.x before 9.2.0.4 allows local users to execute arbitrary code via a long command line argument.

EPSS: Низкий
github логотип

GHSA-xm9x-vjcf-6hvv

11 месяцев назад

Wi-SUN unexpected 4- Way Handshake packet receptions may lead to predictable keys and potentially leading to Man in the middle (MitM) attack

EPSS: Низкий
github логотип

GHSA-xm9w-v2cj-mwmg

больше 4 лет назад

admin/radera/tabort.asp in Hogstorps hogstorp guestbook 2.0 does not verify user credentials, which allows remote attackers to delete arbitrary posts via a modified delID parameter.

EPSS: Низкий
github логотип

GHSA-xm9w-228p-45pp

около 1 года назад

An issue was discovered on KuWFi GC111 GC111-GL-LM321_V3.0_20191211 devices. The TELNET service is enabled by default and exposed over the WAN interface without authentication.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xm9v-wf8j-hjg7

около 4 лет назад

A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in filter_frame at libavfilter/vf_fieldorder.c, which might lead to memory corruption and other potential consequences.

EPSS: Низкий
github логотип

GHSA-xm9v-fg48-44v7

около 2 лет назад

HCL DRYiCE Optibot Reset Station is impacted by a missing Strict Transport Security Header.  This could allow an attacker to intercept or manipulate data during redirection.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-xm9r-hq6w-wmg8

почти 4 года назад

An out-of-bounds read vulnerability was discovered in linux kernel in the smc protocol stack, causing remote dos.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xm9q-wvh7-2637

больше 4 лет назад

PostMaster 1.0 in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL.

EPSS: Низкий
github логотип

GHSA-xm9p-q7g6-fm6p

около 4 лет назад

The AcquireDaemonLock function in ipcdUnix.cpp in Sun Innotek VirtualBox before 2.0.6 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/.vbox-$USER-ipc/lock temporary file.

EPSS: Низкий
github логотип

GHSA-xm9p-57xv-vxwc

22 дня назад

Stored XSS via TLS peer-certificate DN in stream-management UI (sibling of V-11)

EPSS: Низкий
github логотип

GHSA-xm9m-jhp8-mhhx

4 месяца назад

The Website LLMs.txt plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVSS3: 4.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xmc6-5pwj-wqwj

The Tightrope Media Carousel Seneca HDn Windows-based appliance 7.0.4.104 is shipped with a default local administrator username and password. This can be found by a limited user account in an "unattend.xml" file left over on the C: drive from the Sysprep process. An attacker with this username and password can leverage it to gain administrator-level access on the system.

CVSS3: 8.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xmc5-7cww-2h26

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could allow a remote code execution when a file is saved. Affected Product: C-Bus Toolkit (V1.15.9 and prior), C-Gate Server (V2.11.7 and prior)

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xmc5-26p9-v4x6

WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions and then using host requests to redirect script loads to a malicious site. This allows a malicious extension to then install additional extensions without explicit user permission. This vulnerability affects Firefox < 51.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-xmc4-vj3p-mc7g

accounts/ValidateAnswers in the security-questions implementation in ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 makes it easier for remote attackers to reset user passwords, and consequently obtain access to arbitrary user accounts, via a modified (1) Hide_Captcha or (2) quesList parameter in a validateAll action.

4%
Низкий
около 4 лет назад
github логотип
GHSA-xmc4-rjq5-7xw2

The CoreGraphics component in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2015-5925.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xmc3-9m9j-w9x4

cocagne pysrp vulnerable to side channel leaks

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xmc3-8wf5-r59w

Memory corruption in Boot while running a ListVars test in UEFI Menu during boot.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xmc2-qrxf-m6gc

The vips-7.22 script in VIPS 7.22.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xmc2-ppwc-cgqq

Microsoft Internet Explorer 11 and Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2447.

16%
Средний
около 4 лет назад
github логотип
GHSA-xmc2-gfmw-wmhg

Buffer overflow in the (1) oracle and (2) oracleO programs in Oracle 9i Database 9.0.x and 9.2.x before 9.2.0.4 allows local users to execute arbitrary code via a long command line argument.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xm9x-vjcf-6hvv

Wi-SUN unexpected 4- Way Handshake packet receptions may lead to predictable keys and potentially leading to Man in the middle (MitM) attack

0%
Низкий
11 месяцев назад
github логотип
GHSA-xm9w-v2cj-mwmg

admin/radera/tabort.asp in Hogstorps hogstorp guestbook 2.0 does not verify user credentials, which allows remote attackers to delete arbitrary posts via a modified delID parameter.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xm9w-228p-45pp

An issue was discovered on KuWFi GC111 GC111-GL-LM321_V3.0_20191211 devices. The TELNET service is enabled by default and exposed over the WAN interface without authentication.

CVSS3: 9.8
0%
Низкий
около 1 года назад
github логотип
GHSA-xm9v-wf8j-hjg7

A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in filter_frame at libavfilter/vf_fieldorder.c, which might lead to memory corruption and other potential consequences.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xm9v-fg48-44v7

HCL DRYiCE Optibot Reset Station is impacted by a missing Strict Transport Security Header.  This could allow an attacker to intercept or manipulate data during redirection.

CVSS3: 3.7
0%
Низкий
около 2 лет назад
github логотип
GHSA-xm9r-hq6w-wmg8

An out-of-bounds read vulnerability was discovered in linux kernel in the smc protocol stack, causing remote dos.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-xm9q-wvh7-2637

PostMaster 1.0 in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xm9p-q7g6-fm6p

The AcquireDaemonLock function in ipcdUnix.cpp in Sun Innotek VirtualBox before 2.0.6 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/.vbox-$USER-ipc/lock temporary file.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xm9p-57xv-vxwc

Stored XSS via TLS peer-certificate DN in stream-management UI (sibling of V-11)

22 дня назад
github логотип
GHSA-xm9m-jhp8-mhhx

The Website LLMs.txt plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVSS3: 4.4
0%
Низкий
4 месяца назад

Уязвимостей на страницу