Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 234

Количество 358 234

github логотип

GHSA-xj65-x7fm-g6w2

больше 4 лет назад

Format string vulnerability in the SMTP server component in Qbik WinGate 5.x and 6.x before 6.2.2 allows remote attackers to cause a denial of service (service crash) via format string specifiers in certain unexpected commands, which trigger a crash during error logging.

EPSS: Низкий
github логотип

GHSA-xj65-q394-f9p2

больше 4 лет назад

The lzw_add_to_dict function in imagew-gif.c in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted image.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xj65-pmm9-g4xv

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP Snoop page in Mort Bay Jetty 6.1.x through 6.1.21 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) jspsnoop/, (2) jspsnoop/ERROR/, and (3) jspsnoop/IOException/, and possibly the PATH_INFO to (4) snoop.jsp.

EPSS: Низкий
github логотип

GHSA-xj65-m9r8-w48c

больше 4 лет назад

Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerability. A remote malicious user with privileges may exploit this vulnerability to execute commands on the system.

EPSS: Низкий
github логотип

GHSA-xj65-c785-82wr

больше 4 лет назад

Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xj65-984f-7j58

около 3 лет назад

IceCMS v1.0.0 has Insecure Permissions. There is unauthorized access to the API, resulting in the disclosure of sensitive information.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xj65-3378-xxg3

около 4 лет назад

contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via a brute force attack.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xj64-3vx7-fw5x

больше 4 лет назад

A elevation of privilege vulnerability in the MediaTek lastbus. Product: Android. Versions: Android kernel. Android ID: A-36731602. References: M-ALPS03342072.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xj63-cgcm-5qj2

около 4 лет назад

In ome.services.graphs.GraphTraversal.findObjectDetails in Open Microscopy Environment OMERO.server 5.1.0 through 5.6.0, permissions on OMERO model objects may be circumvented during certain operations such as move and delete, because group permissions are mishandled.

EPSS: Низкий
github логотип

GHSA-xj63-95xc-jc4v

около 4 лет назад

Jenkins eggplant-plugin Plugin stores credentials in plain text

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xj63-5v6j-3xr7

около 4 лет назад

Improper Access Control in the RCP+ server of the Bosch Video Recording Manager (VRM) component allows arbitrary and unauthenticated access to a limited subset of certificates, stored in the underlying Microsoft Windows operating system. The fixed versions implement modified authentication checks. Prior releases of VRM software version 3.70 are considered unaffected. This vulnerability affects VRM v3.70.x, v3.71 < v3.71.0034 and v3.81 < 3.81.0050; DIVAR IP 5000 3.80 < 3.80.0039; BVMS all versions using VRM.

EPSS: Низкий
github логотип

GHSA-xj62-mqmw-wg9h

больше 4 лет назад

The DataCollector service in EIQ Networks Network Security Analyzer allows remote attackers to cause a denial of service (service crash) via a (1) &CONNECTSERVER& (2) &ADDENTRY& (3) &FIN& (4) &START& (5) &LOGPATH& (6) &FWADELTA& (7) &FWALOG& (8) &SETSYNCHRONOUS& (9) &SETPRGFILE&, or (10) &SETREPLYPORT& string to TCP port 10618, which triggers a NULL pointer dereference.

EPSS: Низкий
github логотип

GHSA-xj62-87pg-vcv3

больше 7 лет назад

Regular Expression Denial of Service in jshamcrest

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xj5x-pxr5-2gc6

25 дней назад

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xj5x-m3f3-5x3h

4 месяца назад

Electron: Service worker can spoof executeJavaScript IPC replies

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xj5x-4c9j-jr89

6 месяцев назад

Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, Windows) before build 41800.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-xj5x-39gp-65xc

около 1 года назад

A vulnerability classified as critical was found in PHPGurukul Land Record System 1.0. Affected by this vulnerability is an unknown functionality of the file /edit-property.php. The manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xj5x-22m5-2p88

около 2 лет назад

Incorrect default permissions in some Endurance Gaming Mode software installers before version 1.3.937.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-xj5v-6v4g-jfw6

больше 2 лет назад

Rack has possible DoS Vulnerability with Range Header

EPSS: Низкий
github логотип

GHSA-xj5r-xpmv-68j6

больше 4 лет назад

An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF before 9.3, a different vulnerability than CVE-2018-16291, CVE-2018-16292, CVE-2018-16293, CVE-2018-16294, CVE-2018-16295, and CVE-2018-16296. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xj65-x7fm-g6w2

Format string vulnerability in the SMTP server component in Qbik WinGate 5.x and 6.x before 6.2.2 allows remote attackers to cause a denial of service (service crash) via format string specifiers in certain unexpected commands, which trigger a crash during error logging.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xj65-q394-f9p2

The lzw_add_to_dict function in imagew-gif.c in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted image.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xj65-pmm9-g4xv

Multiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP Snoop page in Mort Bay Jetty 6.1.x through 6.1.21 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) jspsnoop/, (2) jspsnoop/ERROR/, and (3) jspsnoop/IOException/, and possibly the PATH_INFO to (4) snoop.jsp.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xj65-m9r8-w48c

Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerability. A remote malicious user with privileges may exploit this vulnerability to execute commands on the system.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xj65-c785-82wr

Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xj65-984f-7j58

IceCMS v1.0.0 has Insecure Permissions. There is unauthorized access to the API, resulting in the disclosure of sensitive information.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-xj65-3378-xxg3

contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via a brute force attack.

CVSS3: 7.5
4%
Низкий
около 4 лет назад
github логотип
GHSA-xj64-3vx7-fw5x

A elevation of privilege vulnerability in the MediaTek lastbus. Product: Android. Versions: Android kernel. Android ID: A-36731602. References: M-ALPS03342072.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xj63-cgcm-5qj2

In ome.services.graphs.GraphTraversal.findObjectDetails in Open Microscopy Environment OMERO.server 5.1.0 through 5.6.0, permissions on OMERO model objects may be circumvented during certain operations such as move and delete, because group permissions are mishandled.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xj63-95xc-jc4v

Jenkins eggplant-plugin Plugin stores credentials in plain text

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xj63-5v6j-3xr7

Improper Access Control in the RCP+ server of the Bosch Video Recording Manager (VRM) component allows arbitrary and unauthenticated access to a limited subset of certificates, stored in the underlying Microsoft Windows operating system. The fixed versions implement modified authentication checks. Prior releases of VRM software version 3.70 are considered unaffected. This vulnerability affects VRM v3.70.x, v3.71 < v3.71.0034 and v3.81 < 3.81.0050; DIVAR IP 5000 3.80 < 3.80.0039; BVMS all versions using VRM.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xj62-mqmw-wg9h

The DataCollector service in EIQ Networks Network Security Analyzer allows remote attackers to cause a denial of service (service crash) via a (1) &CONNECTSERVER& (2) &ADDENTRY& (3) &FIN& (4) &START& (5) &LOGPATH& (6) &FWADELTA& (7) &FWALOG& (8) &SETSYNCHRONOUS& (9) &SETPRGFILE&, or (10) &SETREPLYPORT& string to TCP port 10618, which triggers a NULL pointer dereference.

8%
Низкий
больше 4 лет назад
github логотип
GHSA-xj62-87pg-vcv3

Regular Expression Denial of Service in jshamcrest

CVSS3: 7.5
1%
Низкий
больше 7 лет назад
github логотип
GHSA-xj5x-pxr5-2gc6

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 9.8
0%
Низкий
25 дней назад
github логотип
GHSA-xj5x-m3f3-5x3h

Electron: Service worker can spoof executeJavaScript IPC replies

CVSS3: 5.9
0%
Низкий
4 месяца назад
github логотип
GHSA-xj5x-4c9j-jr89

Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, Windows) before build 41800.

CVSS3: 10
1%
Низкий
6 месяцев назад
github логотип
GHSA-xj5x-39gp-65xc

A vulnerability classified as critical was found in PHPGurukul Land Record System 1.0. Affected by this vulnerability is an unknown functionality of the file /edit-property.php. The manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 7.3
0%
Низкий
около 1 года назад
github логотип
GHSA-xj5x-22m5-2p88

Incorrect default permissions in some Endurance Gaming Mode software installers before version 1.3.937.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 6.7
0%
Низкий
около 2 лет назад
github логотип
GHSA-xj5v-6v4g-jfw6

Rack has possible DoS Vulnerability with Range Header

2%
Низкий
больше 2 лет назад
github логотип
GHSA-xj5r-xpmv-68j6

An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Reader before 9.3 and PhantomPDF before 9.3, a different vulnerability than CVE-2018-16291, CVE-2018-16292, CVE-2018-16293, CVE-2018-16294, CVE-2018-16295, and CVE-2018-16296. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

CVSS3: 7.8
3%
Низкий
больше 4 лет назад

Уязвимостей на страницу