Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 043

Количество 358 043

github логотип

GHSA-xjw6-6j27-9w6v

больше 3 лет назад

A stored cross-site scripting (XSS) vulnerability in identification.php of Piwigo v13.4.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the User-Agent.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xjw5-9f76-gvpv

6 месяцев назад

Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior use RC4 with a hard-coded key embedded in client-side JavaScript. Because the key is static and exposed, an attacker can decrypt protected values and defeat confidentiality protections.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xjw4-7jv6-2hqx

больше 4 лет назад

The passwd command in Solaris can be subjected to a denial of service.

EPSS: Низкий
github логотип

GHSA-xjw4-4v7f-682j

около 4 лет назад

ntfs in Apple OS X before 10.10.5 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xjw3-xjhw-33xq

около 4 лет назад

The dv_extract_audio function in libavcodec in FFmpeg 0.7.x before 0.7.12 and 0.8.x before 0.8.11 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted DV file.

EPSS: Низкий
github логотип

GHSA-xjw3-hcm5-85xf

больше 4 лет назад

A vulnerability in the Web Admin Interface of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient bound checks performed by the affected software. An attacker could exploit this vulnerability by sending a malicious HTTP packet to the affected system. A successful exploit could allow the attacker to cause a reload of the Web Admin Server. Cisco Bug IDs: CSCve89149.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xjw3-5r5c-m5ph

около 2 лет назад

typo3 Security fix for Flow Swift Mailer package

EPSS: Низкий
github логотип

GHSA-xjw2-6jm9-rf67

почти 3 года назад

Sandbox escape via various forms of "format".

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-xjvw-vc5c-qgj5

7 месяцев назад

RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow vulnerability in the tapslip6 utility. The vulnerability is caused by unsafe string concatenation in the devopen() function, which constructs a device path using unbounded user-controlled input. The utility uses strcpy() and strcat() to concatenate the fixed prefix '/dev/' with a user-supplied device name provided via the -s command-line option without bounds checking. This allows an attacker to supply an excessively long device name and overflow a fixed-size stack buffer, leading to process crashes and memory corruption.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xjvv-99gp-jgrm

больше 3 лет назад

In IFM Moneo Appliance with version up to 1.9.3 an unauthenticated remote attacker can reset the administrator password by only supplying the serial number.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xjvv-5w4r-hfmv

почти 3 года назад

Buffer Overflow vulnerability in function LoadPixelDataRLE8 in PluginBMP.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xjvr-j47h-mxhw

больше 4 лет назад

Buffer overflow in Musicqueue 1.2.0 allows local users to execute arbitrary code via a long language variable in the configuration file.

EPSS: Низкий
github логотип

GHSA-xjvr-9qhc-pmpg

около 4 лет назад

NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to utilize debug mechanisms with insufficient access control, which may lead to information disclosure.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-xjvr-8p9x-8pr9

около 4 лет назад

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated IFF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

EPSS: Низкий
github логотип

GHSA-xjvp-7243-rg9h

4 месяца назад

Wish has SCP Path Traversal that allows arbitrary file read/write

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-xjvp-4fhw-gc47

около 2 месяцев назад

runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-xjvm-vf2p-w3rh

около 4 лет назад

IBM MQ 9.1 LTS, 9.2 LTS, and 9.1 CD AMQP Channels could allow an authenticated user to cause a denial of service due to an issue processing messages. IBM X-Force ID: 191747.

EPSS: Низкий
github логотип

GHSA-xjvj-qvp3-h2cg

3 месяца назад

Insufficient validation of untrusted input in Input in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xjvg-m3fg-m9f8

около 4 лет назад

An information disclosure vulnerability exists in the confctl_get_guest_wlan functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to information disclosure. An attacker can send packets to trigger this vulnerability.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xjvg-3p2h-qwh5

больше 4 лет назад

Multiple buffer overflows in Quake II server before R1Q2, as used in multiple products, allow local users to cause a denial of service (application crash) via the server console or rcon.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xjw6-6j27-9w6v

A stored cross-site scripting (XSS) vulnerability in identification.php of Piwigo v13.4.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the User-Agent.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xjw5-9f76-gvpv

Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior use RC4 with a hard-coded key embedded in client-side JavaScript. Because the key is static and exposed, an attacker can decrypt protected values and defeat confidentiality protections.

CVSS3: 7.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-xjw4-7jv6-2hqx

The passwd command in Solaris can be subjected to a denial of service.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xjw4-4v7f-682j

ntfs in Apple OS X before 10.10.5 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xjw3-xjhw-33xq

The dv_extract_audio function in libavcodec in FFmpeg 0.7.x before 0.7.12 and 0.8.x before 0.8.11 and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted DV file.

3%
Низкий
около 4 лет назад
github логотип
GHSA-xjw3-hcm5-85xf

A vulnerability in the Web Admin Interface of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient bound checks performed by the affected software. An attacker could exploit this vulnerability by sending a malicious HTTP packet to the affected system. A successful exploit could allow the attacker to cause a reload of the Web Admin Server. Cisco Bug IDs: CSCve89149.

CVSS3: 5.3
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xjw3-5r5c-m5ph

typo3 Security fix for Flow Swift Mailer package

около 2 лет назад
github логотип
GHSA-xjw2-6jm9-rf67

Sandbox escape via various forms of "format".

CVSS3: 8.3
1%
Низкий
почти 3 года назад
github логотип
GHSA-xjvw-vc5c-qgj5

RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow vulnerability in the tapslip6 utility. The vulnerability is caused by unsafe string concatenation in the devopen() function, which constructs a device path using unbounded user-controlled input. The utility uses strcpy() and strcat() to concatenate the fixed prefix '/dev/' with a user-supplied device name provided via the -s command-line option without bounds checking. This allows an attacker to supply an excessively long device name and overflow a fixed-size stack buffer, leading to process crashes and memory corruption.

CVSS3: 9.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-xjvv-99gp-jgrm

In IFM Moneo Appliance with version up to 1.9.3 an unauthenticated remote attacker can reset the administrator password by only supplying the serial number.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xjvv-5w4r-hfmv

Buffer Overflow vulnerability in function LoadPixelDataRLE8 in PluginBMP.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file.

CVSS3: 7.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-xjvr-j47h-mxhw

Buffer overflow in Musicqueue 1.2.0 allows local users to execute arbitrary code via a long language variable in the configuration file.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-xjvr-9qhc-pmpg

NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to utilize debug mechanisms with insufficient access control, which may lead to information disclosure.

CVSS3: 4.4
0%
Низкий
около 4 лет назад
github логотип
GHSA-xjvr-8p9x-8pr9

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated IFF file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xjvp-7243-rg9h

Wish has SCP Path Traversal that allows arbitrary file read/write

CVSS3: 9.6
0%
Низкий
4 месяца назад
github логотип
GHSA-xjvp-4fhw-gc47

runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations

CVSS3: 3.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xjvm-vf2p-w3rh

IBM MQ 9.1 LTS, 9.2 LTS, and 9.1 CD AMQP Channels could allow an authenticated user to cause a denial of service due to an issue processing messages. IBM X-Force ID: 191747.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xjvj-qvp3-h2cg

Insufficient validation of untrusted input in Input in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 5.3
0%
Низкий
3 месяца назад
github логотип
GHSA-xjvg-m3fg-m9f8

An information disclosure vulnerability exists in the confctl_get_guest_wlan functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to information disclosure. An attacker can send packets to trigger this vulnerability.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xjvg-3p2h-qwh5

Multiple buffer overflows in Quake II server before R1Q2, as used in multiple products, allow local users to cause a denial of service (application crash) via the server console or rcon.

0%
Низкий
больше 4 лет назад

Уязвимостей на страницу