Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 357 575

Количество 357 575

github логотип

GHSA-xm6q-pww3-56gm

около 4 лет назад

Stack-based buffer overflow in fprintf in musl before 0.8.8 and earlier allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string to an unbuffered stream such as stderr.

EPSS: Низкий
github логотип

GHSA-xm6q-j5wx-7362

больше 4 лет назад

The InvertibleRWFunction::CalculateInverse function in rw.cpp in libcrypt++ 5.6.2 does not properly blind private key operations for the Rabin-Williams digital signature algorithm, which allows remote attackers to obtain private keys via a timing attack.

EPSS: Низкий
github логотип

GHSA-xm6q-84w2-rw7v

около 4 лет назад

A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability is different from those described in CVE-2017-0010, CVE-2017-0015, CVE-2017-0032, CVE-2017-0035, CVE-2017-0067, CVE-2017-0070, CVE-2017-0071, CVE-2017-0094, CVE-2017-0131, CVE-2017-0132, CVE-2017-0133, CVE-2017-0134, CVE-2017-0136, CVE-2017-0137, CVE-2017-0138, CVE-2017-0141, and CVE-2017-01...

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-xm6q-6v7q-65qv

больше 4 лет назад

Buffer overflow in calloc.c in the Microsoft Windows XP SP2 ntdll.dll system library, when used by the ILDASM disassembler in the Microsoft .NET 1.0 and 1.1 SDK, might allow user-assisted attackers to execute arbitrary code via a crafted .dll file with a large static method.

EPSS: Средний
github логотип

GHSA-xm6p-r726-3x76

около 4 лет назад

H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the ipqos_lanip_editlist interface at /goform/aspForm.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xm6p-38g9-7hh9

почти 2 года назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The CSSIgniter Team MaxSlider allows Path Traversal.This issue affects MaxSlider: from n/a through 1.2.3.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xm6m-vgxj-3m5c

больше 1 года назад

IBM Robotic Process Automation 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 could allow a remote attacker to obtain sensitive data that may be exposed through certain crypto-analytic attacks.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xm6m-mhj5-wwv5

около 4 лет назад

A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Remote Code Execution Vulnerability." This CVE ID is unique from CVE-2017-0162, CVE-2017-0180, and CVE-2017-0181.

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-xm6m-f95r-5x2c

около 2 лет назад

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.30), SICORE Base system (All versions < V1.3.0). The web interface of affected devices is vulnerable to command injection due to missing server side input sanitation. This could allow an authenticated privileged remote attacker to execute arbitrary code with root privileges.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xm6j-x342-gwq9

почти 7 лет назад

SilverStripe Versioned Files module Unpublished files are exposed publicly

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xm6j-mv8r-9mhp

около 4 лет назад

VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to gain privileges, or halt and remove virtual machines, via unspecified vectors.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-xm6j-g6w8-55mf

7 дней назад

The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price from the attacker-controlled quantity, allowing any authenticated user to create a completed booking for a paid event without making a payment.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xm6h-xrxm-vr76

7 месяцев назад

Improper validation of a login parameter may allow attackers to redirect users to malicious websites after authentication. This can lead to various risk including stealing credentials from unsuspecting users.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xm6h-r8xh-f9jf

около 4 лет назад

Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[sample_input] parameter to web/admin/problem/create or web/polygon/problem/update.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xm6h-7m2x-m892

8 месяцев назад

SpinetiX Fusion Digital Signage 3.4.8 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without proper request validation. Attackers can craft a malicious web page that automatically submits a form to create a new admin user with full system privileges when a logged-in user visits the page.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xm6h-364j-437g

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the management interface in Palo Alto Networks PAN-OS 7.x before 7.0.8 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xm6g-x36q-hxpx

около 4 лет назад

Directory traversal vulnerability in soup-uri.c in SoupServer in libsoup before 2.35.4 allows remote attackers to read arbitrary files via a %2e%2e (encoded dot dot) in a URI.

EPSS: Низкий
github логотип

GHSA-xm6g-crvf-pxf3

больше 4 лет назад

ThinkCMF X2.2.2 has SQL Injection via the function delete() in SlideController.class.php and is exploitable with the manager privilege via the ids[] parameter in a slide action.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xm6g-87mj-5cf7

больше 4 лет назад

Unspecified vulnerability in Collaborative Workspace in Oracle Collaboration Suite 10.1.2 has unknown impact and attack vectors, aka OCS01.

EPSS: Низкий
github логотип

GHSA-xm6f-xwr4-6jhh

около 1 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSearch wp-jobsearch allows Stored XSS.This issue affects JobSearch: from n/a through <= 3.2.9.

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xm6q-pww3-56gm

Stack-based buffer overflow in fprintf in musl before 0.8.8 and earlier allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string to an unbuffered stream such as stderr.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xm6q-j5wx-7362

The InvertibleRWFunction::CalculateInverse function in rw.cpp in libcrypt++ 5.6.2 does not properly blind private key operations for the Rabin-Williams digital signature algorithm, which allows remote attackers to obtain private keys via a timing attack.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xm6q-84w2-rw7v

A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability is different from those described in CVE-2017-0010, CVE-2017-0015, CVE-2017-0032, CVE-2017-0035, CVE-2017-0067, CVE-2017-0070, CVE-2017-0071, CVE-2017-0094, CVE-2017-0131, CVE-2017-0132, CVE-2017-0133, CVE-2017-0134, CVE-2017-0136, CVE-2017-0137, CVE-2017-0138, CVE-2017-0141, and CVE-2017-01...

CVSS3: 7.5
15%
Средний
около 4 лет назад
github логотип
GHSA-xm6q-6v7q-65qv

Buffer overflow in calloc.c in the Microsoft Windows XP SP2 ntdll.dll system library, when used by the ILDASM disassembler in the Microsoft .NET 1.0 and 1.1 SDK, might allow user-assisted attackers to execute arbitrary code via a crafted .dll file with a large static method.

14%
Средний
больше 4 лет назад
github логотип
GHSA-xm6p-r726-3x76

H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the ipqos_lanip_editlist interface at /goform/aspForm.

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xm6p-38g9-7hh9

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The CSSIgniter Team MaxSlider allows Path Traversal.This issue affects MaxSlider: from n/a through 1.2.3.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-xm6m-vgxj-3m5c

IBM Robotic Process Automation 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 could allow a remote attacker to obtain sensitive data that may be exposed through certain crypto-analytic attacks.

CVSS3: 5.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-xm6m-mhj5-wwv5

A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Remote Code Execution Vulnerability." This CVE ID is unique from CVE-2017-0162, CVE-2017-0180, and CVE-2017-0181.

CVSS3: 7.6
3%
Низкий
около 4 лет назад
github логотип
GHSA-xm6m-f95r-5x2c

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.30), SICORE Base system (All versions < V1.3.0). The web interface of affected devices is vulnerable to command injection due to missing server side input sanitation. This could allow an authenticated privileged remote attacker to execute arbitrary code with root privileges.

CVSS3: 7.2
2%
Низкий
около 2 лет назад
github логотип
GHSA-xm6j-x342-gwq9

SilverStripe Versioned Files module Unpublished files are exposed publicly

CVSS3: 5.3
1%
Низкий
почти 7 лет назад
github логотип
GHSA-xm6j-mv8r-9mhp

VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to gain privileges, or halt and remove virtual machines, via unspecified vectors.

CVSS3: 10
3%
Низкий
около 4 лет назад
github логотип
GHSA-xm6j-g6w8-55mf

The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price from the attacker-controlled quantity, allowing any authenticated user to create a completed booking for a paid event without making a payment.

CVSS3: 9.8
0%
Низкий
7 дней назад
github логотип
GHSA-xm6h-xrxm-vr76

Improper validation of a login parameter may allow attackers to redirect users to malicious websites after authentication. This can lead to various risk including stealing credentials from unsuspecting users.

CVSS3: 4.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-xm6h-r8xh-f9jf

Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[sample_input] parameter to web/admin/problem/create or web/polygon/problem/update.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-xm6h-7m2x-m892

SpinetiX Fusion Digital Signage 3.4.8 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without proper request validation. Attackers can craft a malicious web page that automatically submits a form to create a new admin user with full system privileges when a logged-in user visits the page.

CVSS3: 8.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-xm6h-364j-437g

Cross-site scripting (XSS) vulnerability in the management interface in Palo Alto Networks PAN-OS 7.x before 7.0.8 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xm6g-x36q-hxpx

Directory traversal vulnerability in soup-uri.c in SoupServer in libsoup before 2.35.4 allows remote attackers to read arbitrary files via a %2e%2e (encoded dot dot) in a URI.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xm6g-crvf-pxf3

ThinkCMF X2.2.2 has SQL Injection via the function delete() in SlideController.class.php and is exploitable with the manager privilege via the ids[] parameter in a slide action.

CVSS3: 7.2
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xm6g-87mj-5cf7

Unspecified vulnerability in Collaborative Workspace in Oracle Collaboration Suite 10.1.2 has unknown impact and attack vectors, aka OCS01.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xm6f-xwr4-6jhh

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSearch wp-jobsearch allows Stored XSS.This issue affects JobSearch: from n/a through <= 3.2.9.

CVSS3: 7.1
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу