Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 234

Количество 358 234

github логотип

GHSA-xjcr-jqgm-wxc5

около 1 месяца назад

Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xjcq-phj7-g2fh

больше 4 лет назад

user.php in BoastMachine 3.0 platinum allows remote authenticated users to gain privileges via a modified id parameter, as demonstrated by an edit_post action.

EPSS: Низкий
github логотип

GHSA-xjcq-2h6g-jf3c

больше 4 лет назад

ecryptfs-utils: suid helper does not restrict mounting filesystems with nosuid,nodev which creates a possible privilege escalation

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xjcp-9jxf-mc93

больше 2 лет назад

Information Disclosure while processing IOCTL request in FastRPC.

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-xjcm-w8fw-q3jw

больше 4 лет назад

Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

EPSS: Средний
github логотип

GHSA-xjcm-5xfx-c3pp

около 4 лет назад

There is an out-of-bounds read in Exiv2::MrwImage::readMetadata in mrwimage.cpp in Exiv2 through 0.27.2.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xjcj-rmfc-7q3p

почти 4 года назад

dproxy-nexgen (aka dproxy nexgen) re-uses the DNS transaction id (TXID) value from client queries, which allows attackers (able to send queries to the resolver) to conduct DNS cache-poisoning attacks because the TXID value is known to the attacker.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xjcj-m8p7-67rr

около 4 лет назад

The Blog module in Kentico CMS 5.5 R2 build 5.5.3996 allows SQL injection via the tagname parameter.

EPSS: Низкий
github логотип

GHSA-xjch-wqmw-fgcp

около 4 лет назад

Relution Enterprise Appstore Publisher Jenkins Plugin contains Cross-Site Request Forgery

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xjch-jhgj-g9w2

2 месяца назад

A lack of runtime integrity in GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass file system read-only protections and modify system files and binaries for the duration of a boot session via a bind-mount attack.

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-xjch-93pr-7c7c

8 дней назад

Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to HTTP header injection through the “cType” URL parameter, which allows arbitrary modification of the Content-Type header in HTTP responses. Because the parameter does not properly restrict control characters such as URL-encoded newlines (“%0a”) or colons, attackers can inject additional headers including extra Location headers into the server’s response. This results e.g. in an open redirect vulnerability. This issue affects TeamDavid through Rollout 524.

EPSS: Низкий
github логотип

GHSA-xjch-3r5f-vch2

около 4 лет назад

In all Qualcomm products with Android release from CAF using the Linux kernel, while processing fastboot boot command when verified boot feature is disabled, with length greater than boot image buffer, a buffer overflow can occur.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xjcg-4pp7-3cpv

больше 4 лет назад

Netwide Assembler (NASM) 2.14rc15 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for insufficient input.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xjcf-qhwg-v3mr

4 месяца назад

PilusCart 1.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'send' parameter. Attackers can submit POST requests to the comment submission endpoint with RLIKE-based boolean SQL injection payloads to extract sensitive database information.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-xjcf-jhr2-9x97

больше 1 года назад

gnuplot is affected by a heap buffer overflow at function utf8_copy_one.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-xjcf-j3c7-ppx8

больше 4 лет назад

Buffer overflow in Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to execute arbitrary code via a specially crafted file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xjcf-cqpg-j64p

больше 4 лет назад

A vulnerability in the conferencing component of Mitel ST 14.2, versions GA29 (19.49.9400.0) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for the signin.php page. A successful exploit could allow an attacker to execute arbitrary scripts.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xjcf-7v2j-xmr4

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M. Tuhin Ultimate Push Notifications allows Reflected XSS. This issue affects Ultimate Push Notifications: from n/a through 1.1.8.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xjcc-hff6-3h7r

около 4 лет назад

Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1045, CVE-2016-1046, CVE-2016-1047, CVE-2016-1048, CVE-2016-1049, CVE-2016-1050, CVE-2016-1051, CVE-2016-1052, CVE-2016-1053, CVE-2016-1054, CVE-2016-1055, CVE-2016-1056, CVE-2016-1057, CVE-2016-1058, CVE-2016-1059, CVE-2016-1061, CVE-2016-1065, CVE-2016-1066, CVE-2016-1067, CVE-2016-1068, CVE-2016-1069, CVE-2016-1070, CVE-2016-1075, CVE-2016-1094, CVE-2016-1121, CVE-2016-1122, CVE-2016-4102, and CVE-2016-4107.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xjcc-grx3-24p5

почти 3 года назад

An issue in IceWarp Mail Server Deep Castle 2 v.13.0.1.2 allows a remote attacker to execute arbitrary code via a crafted request to the URL.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xjcr-jqgm-wxc5

Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xjcq-phj7-g2fh

user.php in BoastMachine 3.0 platinum allows remote authenticated users to gain privileges via a modified id parameter, as demonstrated by an edit_post action.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xjcq-2h6g-jf3c

ecryptfs-utils: suid helper does not restrict mounting filesystems with nosuid,nodev which creates a possible privilege escalation

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xjcp-9jxf-mc93

Information Disclosure while processing IOCTL request in FastRPC.

CVSS3: 5.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xjcm-w8fw-q3jw

Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

21%
Средний
больше 4 лет назад
github логотип
GHSA-xjcm-5xfx-c3pp

There is an out-of-bounds read in Exiv2::MrwImage::readMetadata in mrwimage.cpp in Exiv2 through 0.27.2.

CVSS3: 6.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-xjcj-rmfc-7q3p

dproxy-nexgen (aka dproxy nexgen) re-uses the DNS transaction id (TXID) value from client queries, which allows attackers (able to send queries to the resolver) to conduct DNS cache-poisoning attacks because the TXID value is known to the attacker.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-xjcj-m8p7-67rr

The Blog module in Kentico CMS 5.5 R2 build 5.5.3996 allows SQL injection via the tagname parameter.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xjch-wqmw-fgcp

Relution Enterprise Appstore Publisher Jenkins Plugin contains Cross-Site Request Forgery

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-xjch-jhgj-g9w2

A lack of runtime integrity in GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass file system read-only protections and modify system files and binaries for the duration of a boot session via a bind-mount attack.

CVSS3: 4.6
0%
Низкий
2 месяца назад
github логотип
GHSA-xjch-93pr-7c7c

Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to HTTP header injection through the “cType” URL parameter, which allows arbitrary modification of the Content-Type header in HTTP responses. Because the parameter does not properly restrict control characters such as URL-encoded newlines (“%0a”) or colons, attackers can inject additional headers including extra Location headers into the server’s response. This results e.g. in an open redirect vulnerability. This issue affects TeamDavid through Rollout 524.

0%
Низкий
8 дней назад
github логотип
GHSA-xjch-3r5f-vch2

In all Qualcomm products with Android release from CAF using the Linux kernel, while processing fastboot boot command when verified boot feature is disabled, with length greater than boot image buffer, a buffer overflow can occur.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-xjcg-4pp7-3cpv

Netwide Assembler (NASM) 2.14rc15 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for insufficient input.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xjcf-qhwg-v3mr

PilusCart 1.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'send' parameter. Attackers can submit POST requests to the comment submission endpoint with RLIKE-based boolean SQL injection payloads to extract sensitive database information.

CVSS3: 8.2
0%
Низкий
4 месяца назад
github логотип
GHSA-xjcf-jhr2-9x97

gnuplot is affected by a heap buffer overflow at function utf8_copy_one.

CVSS3: 6.2
0%
Низкий
больше 1 года назад
github логотип
GHSA-xjcf-j3c7-ppx8

Buffer overflow in Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to execute arbitrary code via a specially crafted file.

CVSS3: 7.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xjcf-cqpg-j64p

A vulnerability in the conferencing component of Mitel ST 14.2, versions GA29 (19.49.9400.0) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for the signin.php page. A successful exploit could allow an attacker to execute arbitrary scripts.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xjcf-7v2j-xmr4

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M. Tuhin Ultimate Push Notifications allows Reflected XSS. This issue affects Ultimate Push Notifications: from n/a through 1.1.8.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-xjcc-hff6-3h7r

Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1045, CVE-2016-1046, CVE-2016-1047, CVE-2016-1048, CVE-2016-1049, CVE-2016-1050, CVE-2016-1051, CVE-2016-1052, CVE-2016-1053, CVE-2016-1054, CVE-2016-1055, CVE-2016-1056, CVE-2016-1057, CVE-2016-1058, CVE-2016-1059, CVE-2016-1061, CVE-2016-1065, CVE-2016-1066, CVE-2016-1067, CVE-2016-1068, CVE-2016-1069, CVE-2016-1070, CVE-2016-1075, CVE-2016-1094, CVE-2016-1121, CVE-2016-1122, CVE-2016-4102, and CVE-2016-4107.

CVSS3: 9.8
6%
Низкий
около 4 лет назад
github логотип
GHSA-xjcc-grx3-24p5

An issue in IceWarp Mail Server Deep Castle 2 v.13.0.1.2 allows a remote attacker to execute arbitrary code via a crafted request to the URL.

CVSS3: 6.1
1%
Низкий
почти 3 года назад

Уязвимостей на страницу