Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 043

Количество 358 043

github логотип

GHSA-xjrh-qrc5-wr3p

около 1 года назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий
github логотип

GHSA-xjrh-8gjh-h7rm

около 4 лет назад

An issue was discovered in Zoho Application Control Plus before version 10.0.511. The Element Configuration feature (to configure elements included in the scope of elements managed by the product) allows an attacker to retrieve the entire list of the IP ranges and subnets configured in the product and consequently obtain information about the cartography of the internal networks to which the product has access.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xjrg-r453-wq45

больше 4 лет назад

The mintToken function of a smart contract implementation for TurdCoin, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xjrg-6fv9-6rjg

около 4 лет назад

Stored XSS vulnerability in Jenkins Build With Parameters Plugin

CVSS3: 5.4
EPSS: Высокий
github логотип

GHSA-xjrf-8x4f-43h4

больше 4 лет назад

Improper Neutralization of Input During Web Page Generation in Spring Framework

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xjrf-77wf-rm3r

больше 4 лет назад

Stack-based buffer overflow in magentservice.exe in HP Diagnostics Server 8.x through 8.07 and 9.x through 9.21 allows remote attackers to execute arbitrary code via a malformed message packet.

EPSS: Средний
github логотип

GHSA-xjr9-phw2-2wjx

больше 4 лет назад

Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with long arguments to unspecified JavaScript methods. NOTE: this issue might be subsumed by CVE-2008-0655.

CVSS3: 7.8
EPSS: Критический
github логотип

GHSA-xjr9-gg9q-jx3v

около 2 месяцев назад

CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-xjr9-2wf2-3v4w

больше 4 лет назад

Subrion CMS Cross-site scripting in search

EPSS: Низкий
github логотип

GHSA-xjr8-mfv3-96c3

около 4 лет назад

Integer underflow in libavcodec/cinepak.c in FFmpeg before 2.4.2 allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted Cinepak video data.

EPSS: Низкий
github логотип

GHSA-xjr7-3c3g-m763

7 месяцев назад

Renovate vulnerable to arbitrary command injection via gleam manager and malicious gleam.toml file

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-xjr6-xhwq-23jv

около 4 лет назад

NVIDIA Linux kernel distributions contain a vulnerability in FuSa Capture (VI/ISP), where integer underflow due to lack of input validation may lead to complete denial of service, partial integrity, and serious confidentiality loss for all processes in the system.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xjr6-jrh9-wc2p

5 месяцев назад

Missing Authorization vulnerability in E2Pdf e2pdf e2pdf allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects e2pdf: from n/a through <= 1.28.15.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xjr6-hx73-v76x

около 4 лет назад

Use after free in Dev Tools in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

EPSS: Низкий
github логотип

GHSA-xjr6-8999-vr65

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: tracing: Free buffers when a used dynamic event is removed After 65536 dynamic events have been added and removed, the "type" field of the event then uses the first type number that is available (not currently used by other events). A type number is the identifier of the binary blobs in the tracing ring buffer (known as events) to map them to logic that can parse the binary blob. The issue is that if a dynamic event (like a kprobe event) is traced and is in the ring buffer, and then that event is removed (because it is dynamic, which means it can be created and destroyed), if another dynamic event is created that has the same number that new event's logic on parsing the binary blob will be used. To show how this can be an issue, the following can crash the kernel: # cd /sys/kernel/tracing # for i in `seq 65536`; do echo 'p:kprobes/foo do_sys_openat2 $arg1:u32' > kprobe_events # done For every iteration...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xjr6-7qjw-pv8v

больше 4 лет назад

PHP remote file inclusion vulnerability in config.php for PhpDig 1.6.5 and earlier allows remote attackers to execute arbitrary PHP code by modifying the $relative_script_path parameter to reference a URL on a remote web server that contains the code.

EPSS: Низкий
github логотип

GHSA-xjr5-22cj-7cfp

больше 1 года назад

This issue was addressed with improved checks. This issue is fixed in watchOS 11.2, tvOS 18.2, macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An app may be able to access sensitive user data.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xjr4-f5wm-7r5m

около 4 лет назад

Use-after-free vulnerability in the plugin in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an HTML document with a crafted _qtactivex_ parameter in an OBJECT element.

EPSS: Низкий
github логотип

GHSA-xjr4-8c62-v64c

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Secure Data Space SDS-API before 3.5.7 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to api/v3/public/shares/downloads/, the (2) authType parameter to api/v3/auth/login, or the (3) login parameter to api/v3/auth/reset_password.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xjr3-qv95-pmw4

больше 1 года назад

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to cause unexpected system termination or corrupt kernel memory.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xjrh-qrc5-wr3p

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

около 1 года назад
github логотип
GHSA-xjrh-8gjh-h7rm

An issue was discovered in Zoho Application Control Plus before version 10.0.511. The Element Configuration feature (to configure elements included in the scope of elements managed by the product) allows an attacker to retrieve the entire list of the IP ranges and subnets configured in the product and consequently obtain information about the cartography of the internal networks to which the product has access.

CVSS3: 4.3
2%
Низкий
около 4 лет назад
github логотип
GHSA-xjrg-r453-wq45

The mintToken function of a smart contract implementation for TurdCoin, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xjrg-6fv9-6rjg

Stored XSS vulnerability in Jenkins Build With Parameters Plugin

CVSS3: 5.4
81%
Высокий
около 4 лет назад
github логотип
GHSA-xjrf-8x4f-43h4

Improper Neutralization of Input During Web Page Generation in Spring Framework

CVSS3: 5.4
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xjrf-77wf-rm3r

Stack-based buffer overflow in magentservice.exe in HP Diagnostics Server 8.x through 8.07 and 9.x through 9.21 allows remote attackers to execute arbitrary code via a malformed message packet.

11%
Средний
больше 4 лет назад
github логотип
GHSA-xjr9-phw2-2wjx

Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with long arguments to unspecified JavaScript methods. NOTE: this issue might be subsumed by CVE-2008-0655.

CVSS3: 7.8
94%
Критический
больше 4 лет назад
github логотип
GHSA-xjr9-gg9q-jx3v

CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation

CVSS3: 10
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xjr9-2wf2-3v4w

Subrion CMS Cross-site scripting in search

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xjr8-mfv3-96c3

Integer underflow in libavcodec/cinepak.c in FFmpeg before 2.4.2 allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted Cinepak video data.

3%
Низкий
около 4 лет назад
github логотип
GHSA-xjr7-3c3g-m763

Renovate vulnerable to arbitrary command injection via gleam manager and malicious gleam.toml file

CVSS3: 6.7
7 месяцев назад
github логотип
GHSA-xjr6-xhwq-23jv

NVIDIA Linux kernel distributions contain a vulnerability in FuSa Capture (VI/ISP), where integer underflow due to lack of input validation may lead to complete denial of service, partial integrity, and serious confidentiality loss for all processes in the system.

CVSS3: 7.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-xjr6-jrh9-wc2p

Missing Authorization vulnerability in E2Pdf e2pdf e2pdf allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects e2pdf: from n/a through <= 1.28.15.

CVSS3: 4.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-xjr6-hx73-v76x

Use after free in Dev Tools in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xjr6-8999-vr65

In the Linux kernel, the following vulnerability has been resolved: tracing: Free buffers when a used dynamic event is removed After 65536 dynamic events have been added and removed, the "type" field of the event then uses the first type number that is available (not currently used by other events). A type number is the identifier of the binary blobs in the tracing ring buffer (known as events) to map them to logic that can parse the binary blob. The issue is that if a dynamic event (like a kprobe event) is traced and is in the ring buffer, and then that event is removed (because it is dynamic, which means it can be created and destroyed), if another dynamic event is created that has the same number that new event's logic on parsing the binary blob will be used. To show how this can be an issue, the following can crash the kernel: # cd /sys/kernel/tracing # for i in `seq 65536`; do echo 'p:kprobes/foo do_sys_openat2 $arg1:u32' > kprobe_events # done For every iteration...

CVSS3: 7.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-xjr6-7qjw-pv8v

PHP remote file inclusion vulnerability in config.php for PhpDig 1.6.5 and earlier allows remote attackers to execute arbitrary PHP code by modifying the $relative_script_path parameter to reference a URL on a remote web server that contains the code.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xjr5-22cj-7cfp

This issue was addressed with improved checks. This issue is fixed in watchOS 11.2, tvOS 18.2, macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An app may be able to access sensitive user data.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xjr4-f5wm-7r5m

Use-after-free vulnerability in the plugin in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an HTML document with a crafted _qtactivex_ parameter in an OBJECT element.

4%
Низкий
около 4 лет назад
github логотип
GHSA-xjr4-8c62-v64c

Multiple cross-site scripting (XSS) vulnerabilities in Secure Data Space SDS-API before 3.5.7 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to api/v3/public/shares/downloads/, the (2) authType parameter to api/v3/auth/login, or the (3) login parameter to api/v3/auth/reset_password.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xjr3-qv95-pmw4

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to cause unexpected system termination or corrupt kernel memory.

CVSS3: 9.8
1%
Низкий
больше 1 года назад

Уязвимостей на страницу