Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 234

Количество 358 234

github логотип

GHSA-xj83-9856-x76g

почти 3 года назад

A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0009), Tecnomatix Plant Simulation V2302 (All versions < V2302.0003). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted SPP file. This could allow an attacker to execute code in the context of the current process.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xj83-6v6g-v838

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in top.php in CjLinkOut 1.0 allows remote attackers to inject arbitrary web script or HTML via the 123 parameter.

EPSS: Низкий
github логотип

GHSA-xj82-8xpc-8x9g

12 дней назад

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xj7w-r753-vj8v

почти 2 года назад

Exposure of vSphere's CPI and CSI credentials in Rancher

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xj7v-jxjg-9rw8

около 4 лет назад

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.4. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the prl_naptd process. The issue results from the lack of proper validation of user-supplied data, which can result in an integer underflow before writing to memory. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of the hypervisor. Was ZDI-CAN-11134.

EPSS: Низкий
github логотип

GHSA-xj7v-jqv6-v48w

4 месяца назад

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1.3.9.6. This is due to insufficient file type validation that occurs when custom blacklist types are configured, which replaces the default dangerous extension denylist instead of merging with it, and the wpcf7_antiscript_file_name() sanitization function being bypassed for filenames containing non-ASCII characters. This makes it possible for unauthenticated attackers to upload arbitrary files, such as PHP files, to the server, which can be leveraged to achieve remote code execution.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xj7v-c82w-92q2

около 4 лет назад

Argo Exposure of Sensitive Information

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xj7v-9hxp-phcq

больше 1 года назад

Permission verification bypass vulnerability in the notification module Impact: Successful exploitation of this vulnerability may affect availability.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-xj7v-4w7g-vg9f

около 4 лет назад

iDrive RemotePC before 7.6.48 on Windows allows information disclosure. A locally authenticated attacker can read the system's Personal Key in world-readable %PROGRAMDATA% log files.

EPSS: Низкий
github логотип

GHSA-xj7r-w8cv-6rrq

больше 4 лет назад

Cross-site request forgery (CSRF) vulnerability in ManageIQ Enterprise Virtualization Manager (EVM) allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xj7r-q24h-7jww

около 4 лет назад

Cisco NX-OS 1.1(1g) on Nexus 9000 devices allows remote authenticated users to discover cleartext passwords by leveraging the existence of a decryption mechanism, aka Bug ID CSCuu84391.

EPSS: Низкий
github логотип

GHSA-xj7q-q94c-6wr3

около 4 лет назад

Apache James Privilege Escalation

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xj7q-fm56-pfxj

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in gallery/thumb.php in Winged Gallery 1.0 allows remote attackers to inject arbitrary web script or HTML via the image parameter.

EPSS: Низкий
github логотип

GHSA-xj7q-4ppq-c7ch

около 4 лет назад

Insufficient data validation in downloads in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass download restrictions via a crafted HTML page.

EPSS: Низкий
github логотип

GHSA-xj7p-r5hp-mqw3

около 4 лет назад

In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while flashing a specially crafted UBI image, it is possible to corrupt memory, or access uninitialized memory.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xj7p-qq9q-4h6h

больше 4 лет назад

Buffer overflow in mkpath in bos.rte.methods in IBM AIX 5.2 and 5.3 allows local users to gain privileges via a long ODM name.

EPSS: Низкий
github логотип

GHSA-xj7p-j38q-7pq6

больше 2 лет назад

nGrinder before 3.5.9 allows an attacker to create or update webhook configuration due to lack of access control, which could be the cause of information disclosure and limited Server-Side Request Forgery.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xj7m-j8gx-jwq9

около 4 лет назад

A vulnerability in the Rate Limiting Network Address Translation (NAT) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause high CPU utilization in the Cisco QuantumFlow Processor of an affected device, resulting in a denial of service (DoS) condition. This vulnerability is due to mishandling of the rate limiting feature within the QuantumFlow Processor. An attacker could exploit this vulnerability by sending large amounts of traffic that would be subject to NAT and rate limiting through an affected device. A successful exploit could allow the attacker to cause the QuantumFlow Processor utilization to reach 100 percent on the affected device, resulting in a DoS condition.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-xj7j-g6fv-57mq

около 4 лет назад

A Command Execution vulnerability exists in Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which could let a remote malicious user execute arbitrary code. CVE-2014-5085 pertains to instances of fwrite in Sphider Plus, but do not exist in either Sphider or Sphider Pro.

EPSS: Низкий
github логотип

GHSA-xj7j-3mcr-9ppq

около 1 года назад

A vulnerability has been found in Radare2 5.9.9 and classified as problematic. This vulnerability affects the function r_cons_rainbow_free in the library /libr/cons/pal.c of the component radiff2. The manipulation of the argument -T leads to memory corruption. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The patch is identified as 5705d99cc1f23f36f9a84aab26d1724010b97798. It is recommended to apply a patch to fix this issue. The documentation explains that the parameter -T is experimental and "crashy". Further analysis has shown "the race is not a real problem unless you use asan". A new warning has been added.

CVSS3: 2.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xj83-9856-x76g

A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0009), Tecnomatix Plant Simulation V2302 (All versions < V2302.0003). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted SPP file. This could allow an attacker to execute code in the context of the current process.

CVSS3: 7.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-xj83-6v6g-v838

Cross-site scripting (XSS) vulnerability in top.php in CjLinkOut 1.0 allows remote attackers to inject arbitrary web script or HTML via the 123 parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xj82-8xpc-8x9g

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.

CVSS3: 5.4
0%
Низкий
12 дней назад
github логотип
GHSA-xj7w-r753-vj8v

Exposure of vSphere's CPI and CSI credentials in Rancher

CVSS3: 9.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-xj7v-jxjg-9rw8

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.4. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the prl_naptd process. The issue results from the lack of proper validation of user-supplied data, which can result in an integer underflow before writing to memory. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of the hypervisor. Was ZDI-CAN-11134.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xj7v-jqv6-v48w

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, 1.3.9.6. This is due to insufficient file type validation that occurs when custom blacklist types are configured, which replaces the default dangerous extension denylist instead of merging with it, and the wpcf7_antiscript_file_name() sanitization function being bypassed for filenames containing non-ASCII characters. This makes it possible for unauthenticated attackers to upload arbitrary files, such as PHP files, to the server, which can be leveraged to achieve remote code execution.

CVSS3: 8.1
4%
Низкий
4 месяца назад
github логотип
GHSA-xj7v-c82w-92q2

Argo Exposure of Sensitive Information

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xj7v-9hxp-phcq

Permission verification bypass vulnerability in the notification module Impact: Successful exploitation of this vulnerability may affect availability.

CVSS3: 8.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-xj7v-4w7g-vg9f

iDrive RemotePC before 7.6.48 on Windows allows information disclosure. A locally authenticated attacker can read the system's Personal Key in world-readable %PROGRAMDATA% log files.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xj7r-w8cv-6rrq

Cross-site request forgery (CSRF) vulnerability in ManageIQ Enterprise Virtualization Manager (EVM) allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xj7r-q24h-7jww

Cisco NX-OS 1.1(1g) on Nexus 9000 devices allows remote authenticated users to discover cleartext passwords by leveraging the existence of a decryption mechanism, aka Bug ID CSCuu84391.

3%
Низкий
около 4 лет назад
github логотип
GHSA-xj7q-q94c-6wr3

Apache James Privilege Escalation

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xj7q-fm56-pfxj

Cross-site scripting (XSS) vulnerability in gallery/thumb.php in Winged Gallery 1.0 allows remote attackers to inject arbitrary web script or HTML via the image parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xj7q-4ppq-c7ch

Insufficient data validation in downloads in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass download restrictions via a crafted HTML page.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xj7p-r5hp-mqw3

In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while flashing a specially crafted UBI image, it is possible to corrupt memory, or access uninitialized memory.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-xj7p-qq9q-4h6h

Buffer overflow in mkpath in bos.rte.methods in IBM AIX 5.2 and 5.3 allows local users to gain privileges via a long ODM name.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xj7p-j38q-7pq6

nGrinder before 3.5.9 allows an attacker to create or update webhook configuration due to lack of access control, which could be the cause of information disclosure and limited Server-Side Request Forgery.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xj7m-j8gx-jwq9

A vulnerability in the Rate Limiting Network Address Translation (NAT) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause high CPU utilization in the Cisco QuantumFlow Processor of an affected device, resulting in a denial of service (DoS) condition. This vulnerability is due to mishandling of the rate limiting feature within the QuantumFlow Processor. An attacker could exploit this vulnerability by sending large amounts of traffic that would be subject to NAT and rate limiting through an affected device. A successful exploit could allow the attacker to cause the QuantumFlow Processor utilization to reach 100 percent on the affected device, resulting in a DoS condition.

CVSS3: 8.6
1%
Низкий
около 4 лет назад
github логотип
GHSA-xj7j-g6fv-57mq

A Command Execution vulnerability exists in Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which could let a remote malicious user execute arbitrary code. CVE-2014-5085 pertains to instances of fwrite in Sphider Plus, but do not exist in either Sphider or Sphider Pro.

6%
Низкий
около 4 лет назад
github логотип
GHSA-xj7j-3mcr-9ppq

A vulnerability has been found in Radare2 5.9.9 and classified as problematic. This vulnerability affects the function r_cons_rainbow_free in the library /libr/cons/pal.c of the component radiff2. The manipulation of the argument -T leads to memory corruption. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The patch is identified as 5705d99cc1f23f36f9a84aab26d1724010b97798. It is recommended to apply a patch to fix this issue. The documentation explains that the parameter -T is experimental and "crashy". Further analysis has shown "the race is not a real problem unless you use asan". A new warning has been added.

CVSS3: 2.5
0%
Низкий
около 1 года назад

Уязвимостей на страницу