Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 358 234

Количество 358 234

github логотип

GHSA-xj4f-h5gm-5gh9

больше 4 лет назад

Unspecified vulnerability in the SNMPv2c implementation in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.3) and Cisco ACE 4710 Application Control Engine Appliance before A3(2.1) allows remote attackers to cause a denial of service (device reload) via a crafted SNMPv1 packet.

EPSS: Низкий
github логотип

GHSA-xj4f-8jjg-vx4q

3 месяца назад

OpenMRS has Stored Velocity SSTI to RCE via ConceptReferenceRange

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xj4c-cq8p-ghhc

больше 4 лет назад

In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::alternatives in prelexer.hpp.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xj4c-7w4q-9gwv

около 1 месяца назад

ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Successful exploitation could allow arbitrary file upload.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xj4c-3gx9-2cc7

около 4 лет назад

Multiple SQL injection vulnerabilities in EMC Document Sciences xPression 4.1 SP1 before Patch 47, 4.2 before Patch 26, and 4.5 before Patch 05, as used in Documentum Edition, Enterprise Edition Publish Engine, and Enterprise Edition Compuset Engine, allow remote authenticated users to execute arbitrary SQL commands via unspecified input to a (1) xAdmin or (2) xDashboard form.

EPSS: Низкий
github логотип

GHSA-xj4c-3fvq-w5pg

около 4 лет назад

An issue was discovered on Samsung mobile devices with software through 2016-09-13 (Exynos AP chipsets). There is a stack-based buffer overflow in the OTP TrustZone trustlet. The Samsung IDs are SVE-2016-7173 and SVE-2016-7174 (December 2016).

EPSS: Низкий
github логотип

GHSA-xj49-px59-gh64

10 месяцев назад

A weakness has been identified in code-projects Online Complaint Site 1.0. Impacted is an unknown function of the file /cms/users/complaint-details.php. Executing manipulation of the argument cid can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be exploited.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-xj48-mr94-q545

около 4 лет назад

An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. A system service allows local retrieval of the user's password. The LG ID is LVE-SMP-190009 (August 2019).

EPSS: Низкий
github логотип

GHSA-xj48-9vrg-vxxc

больше 4 лет назад

SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, allows remote attackers to execute arbitrary commands via a crafted message that is not properly handled when invoking spamd with the virtual pop username.

EPSS: Высокий
github логотип

GHSA-xj47-w234-57fj

3 месяца назад

Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xj47-998q-qjgw

больше 3 лет назад

In vdsp service, there is a missing permission check. This could lead to local denial of service in vdsp service.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xj46-w22p-wj4j

больше 3 лет назад

A vulnerability, which was classified as problematic, was found in Boston Sleep slice up to 84.2.0. Affected is an unknown function of the component Layout Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 85.0.0 is able to address this issue. The name of the patch is 6523bb17d889e2ab13d767f38afefdb37083f1d0. It is recommended to upgrade the affected component. VDB-216174 is the identifier assigned to this vulnerability.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xj46-h769-7fq6

около 4 лет назад

omr-admin.py in openmptcprouter-vps-admin 0.57.3 and earlier compares the user provided password with the original password in a length dependent manner, which allows remote attackers to guess the password via a timing attack.

EPSS: Низкий
github логотип

GHSA-xj44-pxrh-gchm

19 дней назад

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Parsing a maliciously crafted file may lead to an unexpected app termination.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xj43-wmvf-8v5w

около 4 лет назад

Use-after-free vulnerability in the PDF functionality in Google Chrome before 19.0.1084.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via an invalid encrypted document.

EPSS: Низкий
github логотип

GHSA-xj43-gc98-hg3f

около 4 лет назад

Insufficient policy enforcement in site isolation in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass site isolation via a crafted HTML page.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xj42-qw4g-758r

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in view.php in AzDGDatingPlatinum 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

EPSS: Низкий
github логотип

GHSA-xj42-657g-8r4w

8 месяцев назад

Missing Authorization vulnerability in Bob Watu Quiz watu allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Watu Quiz: from n/a through <= 3.4.5.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xj42-37ff-2c9q

около 4 лет назад

Unspecified vulnerability in the Oracle Discoverer component in Oracle Fusion Middleware 11.1.1.7.0 allows remote attackers to affect confidentiality via vectors related to Viewer.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xj3x-8j85-rxjv

больше 1 года назад

Deserialization of Untrusted Data vulnerability in empik EmpikPlace for Woocommerce allows Object Injection. This issue affects EmpikPlace for Woocommerce: from n/a through 1.4.2.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xj4f-h5gm-5gh9

Unspecified vulnerability in the SNMPv2c implementation in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.3) and Cisco ACE 4710 Application Control Engine Appliance before A3(2.1) allows remote attackers to cause a denial of service (device reload) via a crafted SNMPv1 packet.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xj4f-8jjg-vx4q

OpenMRS has Stored Velocity SSTI to RCE via ConceptReferenceRange

CVSS3: 9.1
0%
Низкий
3 месяца назад
github логотип
GHSA-xj4c-cq8p-ghhc

In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::alternatives in prelexer.hpp.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xj4c-7w4q-9gwv

ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Successful exploitation could allow arbitrary file upload.

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xj4c-3gx9-2cc7

Multiple SQL injection vulnerabilities in EMC Document Sciences xPression 4.1 SP1 before Patch 47, 4.2 before Patch 26, and 4.5 before Patch 05, as used in Documentum Edition, Enterprise Edition Publish Engine, and Enterprise Edition Compuset Engine, allow remote authenticated users to execute arbitrary SQL commands via unspecified input to a (1) xAdmin or (2) xDashboard form.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xj4c-3fvq-w5pg

An issue was discovered on Samsung mobile devices with software through 2016-09-13 (Exynos AP chipsets). There is a stack-based buffer overflow in the OTP TrustZone trustlet. The Samsung IDs are SVE-2016-7173 and SVE-2016-7174 (December 2016).

0%
Низкий
около 4 лет назад
github логотип
GHSA-xj49-px59-gh64

A weakness has been identified in code-projects Online Complaint Site 1.0. Impacted is an unknown function of the file /cms/users/complaint-details.php. Executing manipulation of the argument cid can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be exploited.

CVSS3: 6.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-xj48-mr94-q545

An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. A system service allows local retrieval of the user's password. The LG ID is LVE-SMP-190009 (August 2019).

0%
Низкий
около 4 лет назад
github логотип
GHSA-xj48-9vrg-vxxc

SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, allows remote attackers to execute arbitrary commands via a crafted message that is not properly handled when invoking spamd with the virtual pop username.

75%
Высокий
больше 4 лет назад
github логотип
GHSA-xj47-w234-57fj

Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

CVSS3: 9.1
0%
Низкий
3 месяца назад
github логотип
GHSA-xj47-998q-qjgw

In vdsp service, there is a missing permission check. This could lead to local denial of service in vdsp service.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xj46-w22p-wj4j

A vulnerability, which was classified as problematic, was found in Boston Sleep slice up to 84.2.0. Affected is an unknown function of the component Layout Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 85.0.0 is able to address this issue. The name of the patch is 6523bb17d889e2ab13d767f38afefdb37083f1d0. It is recommended to upgrade the affected component. VDB-216174 is the identifier assigned to this vulnerability.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xj46-h769-7fq6

omr-admin.py in openmptcprouter-vps-admin 0.57.3 and earlier compares the user provided password with the original password in a length dependent manner, which allows remote attackers to guess the password via a timing attack.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xj44-pxrh-gchm

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Parsing a maliciously crafted file may lead to an unexpected app termination.

CVSS3: 7.1
0%
Низкий
19 дней назад
github логотип
GHSA-xj43-wmvf-8v5w

Use-after-free vulnerability in the PDF functionality in Google Chrome before 19.0.1084.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via an invalid encrypted document.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xj43-gc98-hg3f

Insufficient policy enforcement in site isolation in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass site isolation via a crafted HTML page.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-xj42-qw4g-758r

Cross-site scripting (XSS) vulnerability in view.php in AzDGDatingPlatinum 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xj42-657g-8r4w

Missing Authorization vulnerability in Bob Watu Quiz watu allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Watu Quiz: from n/a through <= 3.4.5.

CVSS3: 8.1
0%
Низкий
8 месяцев назад
github логотип
GHSA-xj42-37ff-2c9q

Unspecified vulnerability in the Oracle Discoverer component in Oracle Fusion Middleware 11.1.1.7.0 allows remote attackers to affect confidentiality via vectors related to Viewer.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-xj3x-8j85-rxjv

Deserialization of Untrusted Data vulnerability in empik EmpikPlace for Woocommerce allows Object Injection. This issue affects EmpikPlace for Woocommerce: from n/a through 1.4.2.

CVSS3: 9.8
1%
Низкий
больше 1 года назад

Уязвимостей на страницу