Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 357 575

Количество 357 575

github логотип

GHSA-xm9m-2vj8-fmfr

почти 5 лет назад

Uninitialized memory access in toodee

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xm9j-x4hp-v2x3

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: drm/nouveau/kms/nv50-: fix file release memory leak When using single_open() for opening, single_release() should be called, otherwise the 'op' allocated in single_open() will be leaked.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xm9j-54hw-p785

больше 3 лет назад

A potential memory vulnerability due to insufficient input validation in PDFXEditCore.x64.dll in PDF-XChange Editor version 9.3 by Tracker Software may allow attackers to execute code when a user opens a crafted PDF file. The issue occurs when handling a large number of objects in a PDF file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xm9j-3ggw-w823

больше 4 лет назад

IBM AIX 5.3, 6.1, 7.1, and 7.2 contains a vulnerability in the rmsock command that may be used to expose kernel memory. IBM X-Force ID: 144748.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xm9h-x34f-j9hj

4 месяца назад

Improper input validation in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xm9h-q2f5-rq5x

около 4 лет назад

A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for macOS could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The openvpn_launcher binary is setuid root. This program is called during the connection process and executes several operating system utilities to configure the system. The networksetup utility is called using relative paths. A local unprivileged user can execute arbitrary commands as root by creating a networksetup trojan which will be executed during the connection process. This is possible because the PATH environment variable is not reset prior to executing the OS utility.

EPSS: Низкий
github логотип

GHSA-xm9h-gvgh-crf7

больше 4 лет назад

The Logging Server (ftplogsrv.exe) 7.9.14.0 and earlier in IPSwitch WS_FTP 6.1 allows remote attackers to cause a denial of service (loss of responsiveness) via a large number of large packets to port 5151/udp, which causes the listening socket to terminate and prevents log commands from being recorded, a different vulnerability than CVE-2007-3823.

EPSS: Низкий
github логотип

GHSA-xm9g-m236-mvcw

около 1 года назад

Missing Authorization vulnerability in fraudlabspro FraudLabs Pro for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FraudLabs Pro for WooCommerce: from n/a through 2.22.11.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xm9g-8m49-7qpg

около 4 лет назад

Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.0.4, 12.0.5, 12.0.6, 12.1.1, 12.1.2, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality and integrity via unknown vectors related to List of Values.

EPSS: Низкий
github логотип

GHSA-xm9g-6f9f-23pj

2 дня назад

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xm9g-3p7c-jr4h

больше 1 года назад

The Filestack Official plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'fstab' and 'filestack_options' parameters in all versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xm9f-vxmx-4m58

почти 5 лет назад

Data Flow Sanitation Issue Fix

EPSS: Низкий
github логотип

GHSA-xm9f-p78g-g8cf

около 4 лет назад

Product: AndroidVersions: Android kernelAndroid ID: A-207116951References: N/A

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xm9f-jp6r-h9h7

больше 4 лет назад

Unrestricted file upload vulnerability in Opial 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension as a User Image, then accessing it via a request to the file in userimages, related to register.php.

EPSS: Низкий
github логотип

GHSA-xm9f-gqc6-828p

больше 4 лет назад

SQL injection vulnerability in out.php in E-topbiz Link ADS 1 allows remote attackers to execute arbitrary SQL commands via the linkid parameter.

EPSS: Низкий
github логотип

GHSA-xm9f-fph8-8369

больше 3 лет назад

In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-220302519

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xm9f-5xv9-93pc

около 4 лет назад

Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xm9f-3ph3-v8p6

больше 3 лет назад

Unauthenticated Java deserialization vulnerability in Serviceguard Manager

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xm9c-pm26-gfwx

больше 3 лет назад

Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter at /admin/ajax.php?action=login.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xm99-mgxp-q9jf

6 месяцев назад

Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the organization parameter. Attackers can send POST requests to the korugan/cmclient endpoint with script payloads in the organization parameter to execute arbitrary JavaScript in users' browsers.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xm9m-2vj8-fmfr

Uninitialized memory access in toodee

CVSS3: 7.5
1%
Низкий
почти 5 лет назад
github логотип
GHSA-xm9j-x4hp-v2x3

In the Linux kernel, the following vulnerability has been resolved: drm/nouveau/kms/nv50-: fix file release memory leak When using single_open() for opening, single_release() should be called, otherwise the 'op' allocated in single_open() will be leaked.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-xm9j-54hw-p785

A potential memory vulnerability due to insufficient input validation in PDFXEditCore.x64.dll in PDF-XChange Editor version 9.3 by Tracker Software may allow attackers to execute code when a user opens a crafted PDF file. The issue occurs when handling a large number of objects in a PDF file.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xm9j-3ggw-w823

IBM AIX 5.3, 6.1, 7.1, and 7.2 contains a vulnerability in the rmsock command that may be used to expose kernel memory. IBM X-Force ID: 144748.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xm9h-x34f-j9hj

Improper input validation in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.

CVSS3: 7.5
1%
Низкий
4 месяца назад
github логотип
GHSA-xm9h-q2f5-rq5x

A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for macOS could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The openvpn_launcher binary is setuid root. This program is called during the connection process and executes several operating system utilities to configure the system. The networksetup utility is called using relative paths. A local unprivileged user can execute arbitrary commands as root by creating a networksetup trojan which will be executed during the connection process. This is possible because the PATH environment variable is not reset prior to executing the OS utility.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xm9h-gvgh-crf7

The Logging Server (ftplogsrv.exe) 7.9.14.0 and earlier in IPSwitch WS_FTP 6.1 allows remote attackers to cause a denial of service (loss of responsiveness) via a large number of large packets to port 5151/udp, which causes the listening socket to terminate and prevents log commands from being recorded, a different vulnerability than CVE-2007-3823.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-xm9g-m236-mvcw

Missing Authorization vulnerability in fraudlabspro FraudLabs Pro for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FraudLabs Pro for WooCommerce: from n/a through 2.22.11.

CVSS3: 5.3
0%
Низкий
около 1 года назад
github логотип
GHSA-xm9g-8m49-7qpg

Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.0.4, 12.0.5, 12.0.6, 12.1.1, 12.1.2, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality and integrity via unknown vectors related to List of Values.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xm9g-6f9f-23pj

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVSS3: 5.5
0%
Низкий
2 дня назад
github логотип
GHSA-xm9g-3p7c-jr4h

The Filestack Official plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'fstab' and 'filestack_options' parameters in all versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-xm9f-vxmx-4m58

Data Flow Sanitation Issue Fix

1%
Низкий
почти 5 лет назад
github логотип
GHSA-xm9f-p78g-g8cf

Product: AndroidVersions: Android kernelAndroid ID: A-207116951References: N/A

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xm9f-jp6r-h9h7

Unrestricted file upload vulnerability in Opial 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension as a User Image, then accessing it via a request to the file in userimages, related to register.php.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-xm9f-gqc6-828p

SQL injection vulnerability in out.php in E-topbiz Link ADS 1 allows remote attackers to execute arbitrary SQL commands via the linkid parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xm9f-fph8-8369

In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-220302519

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xm9f-5xv9-93pc

Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CVSS3: 6.5
9%
Низкий
около 4 лет назад
github логотип
GHSA-xm9f-3ph3-v8p6

Unauthenticated Java deserialization vulnerability in Serviceguard Manager

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xm9c-pm26-gfwx

Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter at /admin/ajax.php?action=login.

CVSS3: 7.2
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xm99-mgxp-q9jf

Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the organization parameter. Attackers can send POST requests to the korugan/cmclient endpoint with script payloads in the organization parameter to execute arbitrary JavaScript in users' browsers.

CVSS3: 6.1
0%
Низкий
6 месяцев назад

Уязвимостей на страницу