Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 043

Количество 358 043

github логотип

GHSA-xm5x-38fw-r6fq

больше 4 лет назад

Moxa IKS and EDS do not implement sufficient measures to prevent multiple failed authentication attempts, which may allow an attacker to discover passwords via brute force attack.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xm5w-g7hv-w7f6

около 4 лет назад

Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable integer overflow vulnerability in the XML Forms Architecture (XFA) engine, related to layout functionality. Successful exploitation could lead to arbitrary code execution.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xm5w-7vqw-w9rq

больше 2 лет назад

Kofax Power PDF JPG File Parsing Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JPG files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-20460.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-xm5v-9fv3-x7gp

больше 1 года назад

A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /customeredit.php. The manipulation of the argument id/address/fullname/phonenumber/email/city/comment leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xm5q-57c6-qx3w

около 4 лет назад

There is a local denial of service vulnerability in DaDa accelerator 5.6.19.816,, attackers can use constructed programs to cause computer crashes (BSOD).

EPSS: Низкий
github логотип

GHSA-xm5p-cw89-f4rg

больше 1 года назад

Smartwares cameras CIP-37210AT and C724IP, as well as others which share the same firmware in versions up to 3.3.0, might share same credentials for telnet service. Hash of the password can be retrieved through physical access to SPI connected memory. For the telnet service to be enabled, the inserted SD card needs to have a folder with a specific name created.  Two products were tested, but since the vendor has not replied to reports, patching status remains unknown, as well as groups of devices and firmware ranges in which the same password is shared. Newer firmware versions might be vulnerable as well.

EPSS: Низкий
github логотип

GHSA-xm5p-7w7v-qqr5

больше 2 лет назад

Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

CVSS3: 9.6
EPSS: Средний
github логотип

GHSA-xm5m-wgh2-rrg3

4 месяца назад

Sigstore Timestamp Authority has Improper Certificate Validation in verifier

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xm5m-7wr8-cvwh

около 4 лет назад

Erlang/OTP 22.3.x before 22.3.4.6 and 23.x before 23.1 allows Directory Traversal. An attacker can send a crafted HTTP request to read arbitrary files, if httpd in the inets application is used.

EPSS: Низкий
github логотип

GHSA-xm5j-qjxj-574h

почти 4 года назад

The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users and when a specific premium module is active, leading to a SQL injection

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xm5j-jff6-79cj

около 1 года назад

Marvell QConvergeConsole getFileFromURL Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the getFileFromURL method. The issue results from the lack of proper validation of user-supplied data, which can allow the upload of arbitrary files. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-24922.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xm5j-hmvj-wr75

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: drm/bridge: tc358767: Check if fully initialized before signalling HPD event via IRQ Make sure the connector is fully initialized before signalling any HPD events via drm_kms_helper_hotplug_event(), otherwise this may lead to NULL pointer dereference.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xm5j-2w65-39cm

около 4 лет назад

The XML parser in the management interface in Cisco Adaptive Security Appliance (ASA) Software 8.4 allows remote authenticated users to cause a denial of service (device crash) via a crafted XML document, aka Bug ID CSCut14223.

EPSS: Низкий
github логотип

GHSA-xm5h-r3m3-mqj4

больше 4 лет назад

Stack-based buffer overflow in Microsoft Office Access allows remote, user-assisted attackers to execute arbitrary code via a crafted Microsoft Access Database (.mdb) file. NOTE: due to the lack of details as of 20071210, it is not clear whether this issue is the same as CVE-2007-6026 or CVE-2005-0944.

EPSS: Средний
github логотип

GHSA-xm5h-pccr-wq9g

около 4 лет назад

In SapphireIMS 4097_1, the password in the database is stored in Base64 format.

EPSS: Низкий
github логотип

GHSA-xm5h-4r7m-2g3m

больше 4 лет назад

Unspecified vulnerability in HP ProCurve Threat Management Services zl Module (J9155A) ST.1.0.090213 and earlier allows remote attackers to cause a denial of service via unknown vectors, aka PR_39898, a different vulnerability than CVE-2009-1424 and CVE-2009-1425.

EPSS: Низкий
github логотип

GHSA-xm5g-hxq6-4594

8 месяцев назад

Missing Authorization vulnerability in NewClarity DMCA Protection Badge allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DMCA Protection Badge: from n/a through 2.2.0.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xm5g-27h5-6568

около 4 лет назад

Insufficient boundary checks when processing the JPEG APP12 block marker in the GD extension could allow access to out-of-bounds memory via a maliciously constructed invalid JPEG input. This issue affects HHVM versions prior to 3.30.9, all versions between 4.0.0 and 4.8.3, all versions between 4.9.0 and 4.15.2, and versions 4.16.0 to 4.16.3, 4.17.0 to 4.17.2, 4.18.0 to 4.18.1, 4.19.0, 4.20.0 to 4.20.1.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xm5f-r33j-c674

больше 4 лет назад

SQL injection vulnerability in the Tour Extension (pm_tour) extension before 0.0.13 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xm5f-hc9r-76f3

около 4 лет назад

PHP JOSE Library by Gree Inc. Uses a Broken or Risky Cryptographic Algorithm

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xm5x-38fw-r6fq

Moxa IKS and EDS do not implement sufficient measures to prevent multiple failed authentication attempts, which may allow an attacker to discover passwords via brute force attack.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-xm5w-g7hv-w7f6

Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable integer overflow vulnerability in the XML Forms Architecture (XFA) engine, related to layout functionality. Successful exploitation could lead to arbitrary code execution.

CVSS3: 7.8
5%
Низкий
около 4 лет назад
github логотип
GHSA-xm5w-7vqw-w9rq

Kofax Power PDF JPG File Parsing Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JPG files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-20460.

CVSS3: 3.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xm5v-9fv3-x7gp

A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /customeredit.php. The manipulation of the argument id/address/fullname/phonenumber/email/city/comment leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 6.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-xm5q-57c6-qx3w

There is a local denial of service vulnerability in DaDa accelerator 5.6.19.816,, attackers can use constructed programs to cause computer crashes (BSOD).

0%
Низкий
около 4 лет назад
github логотип
GHSA-xm5p-cw89-f4rg

Smartwares cameras CIP-37210AT and C724IP, as well as others which share the same firmware in versions up to 3.3.0, might share same credentials for telnet service. Hash of the password can be retrieved through physical access to SPI connected memory. For the telnet service to be enabled, the inserted SD card needs to have a folder with a specific name created.  Two products were tested, but since the vendor has not replied to reports, patching status remains unknown, as well as groups of devices and firmware ranges in which the same password is shared. Newer firmware versions might be vulnerable as well.

0%
Низкий
больше 1 года назад
github логотип
GHSA-xm5p-7w7v-qqr5

Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

CVSS3: 9.6
19%
Средний
больше 2 лет назад
github логотип
GHSA-xm5m-wgh2-rrg3

Sigstore Timestamp Authority has Improper Certificate Validation in verifier

CVSS3: 5.5
0%
Низкий
4 месяца назад
github логотип
GHSA-xm5m-7wr8-cvwh

Erlang/OTP 22.3.x before 22.3.4.6 and 23.x before 23.1 allows Directory Traversal. An attacker can send a crafted HTTP request to read arbitrary files, if httpd in the inets application is used.

3%
Низкий
около 4 лет назад
github логотип
GHSA-xm5j-qjxj-574h

The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users and when a specific premium module is active, leading to a SQL injection

CVSS3: 9.8
5%
Низкий
почти 4 года назад
github логотип
GHSA-xm5j-jff6-79cj

Marvell QConvergeConsole getFileFromURL Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the getFileFromURL method. The issue results from the lack of proper validation of user-supplied data, which can allow the upload of arbitrary files. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-24922.

CVSS3: 9.8
1%
Низкий
около 1 года назад
github логотип
GHSA-xm5j-hmvj-wr75

In the Linux kernel, the following vulnerability has been resolved: drm/bridge: tc358767: Check if fully initialized before signalling HPD event via IRQ Make sure the connector is fully initialized before signalling any HPD events via drm_kms_helper_hotplug_event(), otherwise this may lead to NULL pointer dereference.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-xm5j-2w65-39cm

The XML parser in the management interface in Cisco Adaptive Security Appliance (ASA) Software 8.4 allows remote authenticated users to cause a denial of service (device crash) via a crafted XML document, aka Bug ID CSCut14223.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xm5h-r3m3-mqj4

Stack-based buffer overflow in Microsoft Office Access allows remote, user-assisted attackers to execute arbitrary code via a crafted Microsoft Access Database (.mdb) file. NOTE: due to the lack of details as of 20071210, it is not clear whether this issue is the same as CVE-2007-6026 or CVE-2005-0944.

16%
Средний
больше 4 лет назад
github логотип
GHSA-xm5h-pccr-wq9g

In SapphireIMS 4097_1, the password in the database is stored in Base64 format.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xm5h-4r7m-2g3m

Unspecified vulnerability in HP ProCurve Threat Management Services zl Module (J9155A) ST.1.0.090213 and earlier allows remote attackers to cause a denial of service via unknown vectors, aka PR_39898, a different vulnerability than CVE-2009-1424 and CVE-2009-1425.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xm5g-hxq6-4594

Missing Authorization vulnerability in NewClarity DMCA Protection Badge allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DMCA Protection Badge: from n/a through 2.2.0.

CVSS3: 5.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-xm5g-27h5-6568

Insufficient boundary checks when processing the JPEG APP12 block marker in the GD extension could allow access to out-of-bounds memory via a maliciously constructed invalid JPEG input. This issue affects HHVM versions prior to 3.30.9, all versions between 4.0.0 and 4.8.3, all versions between 4.9.0 and 4.15.2, and versions 4.16.0 to 4.16.3, 4.17.0 to 4.17.2, 4.18.0 to 4.18.1, 4.19.0, 4.20.0 to 4.20.1.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-xm5f-r33j-c674

SQL injection vulnerability in the Tour Extension (pm_tour) extension before 0.0.13 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xm5f-hc9r-76f3

PHP JOSE Library by Gree Inc. Uses a Broken or Risky Cryptographic Algorithm

CVSS3: 7.5
1%
Низкий
около 4 лет назад

Уязвимостей на страницу