Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 154

Количество 359 154

github логотип

GHSA-xhqg-mp7v-6mrp

больше 4 лет назад

An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation has an infinite loop if no data is received.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xhqg-j6g5-rp58

около 3 лет назад

Hitron Technologies CODA-5310’s Telnet function transfers sensitive data in plaintext. An unauthenticated remote attacker can exploit this vulnerability to access credentials of normal users and administrator.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xhqg-f253-xfr4

около 4 лет назад

Unspecified vulnerability in Sun Integrated Lights-Out Manager (ILOM) 2.0.1.5 through 2.0.4.26 allows remote authenticated users to (1) access the service processor (SP) and cause a denial of service (shutdown or reboot), or (2) access the host operating system and have an unspecified impact, via unknown vectors.

EPSS: Низкий
github логотип

GHSA-xhqf-m659-g445

около 1 года назад

An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via a GET request to a UserService SOAP API endpoint to validate if a user exists.

EPSS: Низкий
github логотип

GHSA-xhqc-hq7h-65v2

больше 4 лет назад

Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xhqc-h9h8-cqrf

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in IBM Forms Experience Builder 8.5.0 and 8.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 97777.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xhqc-7m79-5gq4

около 4 лет назад

The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local spx_restservice gethelpdata_func function path traversal vulnerability.

EPSS: Низкий
github логотип

GHSA-xhq9-vwjj-93xv

около 4 лет назад

An exploitable command injection vulnerability exists in the /goform/WanParameterSetting functionality of Tenda AC9 Router AC1200 Smart Dual-Band Gigabit WiFi Route (AC9V1.0 Firmware V15.03.05.16multiTRU). A specially crafted HTTP POST request can cause a command injection in the DNS1 post parameters, resulting in code execution. An attacker can send HTTP POST request with command to trigger this vulnerability.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xhq9-9h5f-jcjw

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rhys Wynne WP Flipclock allows DOM-Based XSS. This issue affects WP Flipclock: from n/a through 1.9.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xhq9-58fw-859p

4 месяца назад

ApostropheCMS: publicApiProjection Bypass via project Query Builder in Piece-Type REST API

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xhq8-8cqj-q337

больше 4 лет назад

Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Adobe Reader 9.x before 9.4.4 and 10.x before 10.0.3 on Mac OS X, and Adobe Acrobat 9.x before 9.4.4 and 10.x before 10.0.3 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content; as demonstrated by a Microsoft Office document with an embedded .swf file that has a size inconsistency in a "group of included constants," object type confusion, ActionScript that adds custom functions to prototypes, and Date objects; and as exploited in the wild in April 2011.

CVSS3: 8.8
EPSS: Критический
github логотип

GHSA-xhq7-wg93-r5f3

почти 3 года назад

Heap buffer overflow vulnerability in FilePOSIX::read in File.cpp in audiofile 0.3.6 may cause denial-of-service via a crafted wav file, this bug can be triggered by the executable sfconvert.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xhq7-864q-xxj8

около 2 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in osdmap_decode() When decoding osd_state and osd_weight from an incoming osdmap in osdmap_decode(), both are decoded for each osd, i.e., map->max_osd times. The ceph_decode_need() check only accounts for sizeof(*map->osd_weight) once. This can potentially result in an out-of-bounds memory access if the incoming message is corrupted such that the max_osd value exceeds the actual content of the osdmap message. This patch fixes the issue by changing the corresponding part in the ceph_decode_need() check to account for map->max_osd*sizeof(*map->osd_weight).

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xhq5-7429-4hrv

почти 4 года назад

An issue in the handling of environment variables was addressed with improved validation. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. An app may be able to modify protected parts of the file system.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xhq5-45pm-2gjr

5 месяцев назад

OpenClaw: Nextcloud Talk room allowlist matched colliding room names instead of stable room tokens

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-xhq4-rjcc-mjrc

больше 4 лет назад

Microsoft Internet Explorer cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP response, related to lack of the HTTP Strict Transport Security (HSTS) includeSubDomains feature, aka a "cookie forcing" issue.

EPSS: Низкий
github логотип

GHSA-xhq4-r8xc-mr9f

больше 4 лет назад

Opera before 11.62 on Mac OS X allows remote attackers to spoof the address field and security dialogs via crafted styling that causes page content to be displayed outside of the intended content area.

EPSS: Низкий
github логотип

GHSA-xhq4-92wj-h688

2 месяца назад

A security vulnerability has been detected in Jinher OA 1.0. This affects an unknown function of the file nextselectplan.aspx. Such manipulation of the argument httpOID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xhq4-5269-2ffv

около 4 лет назад

In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits cannot be configured. This makes it easier for attackers to cause a denial of service (memory consumption).

EPSS: Низкий
github логотип

GHSA-xhq3-mvrq-qg9q

почти 2 года назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in wayneconnor Sliding Door allows Stored XSS.This issue affects Sliding Door: from n/a through 3.6.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xhqg-mp7v-6mrp

An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation has an infinite loop if no data is received.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xhqg-j6g5-rp58

Hitron Technologies CODA-5310’s Telnet function transfers sensitive data in plaintext. An unauthenticated remote attacker can exploit this vulnerability to access credentials of normal users and administrator.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-xhqg-f253-xfr4

Unspecified vulnerability in Sun Integrated Lights-Out Manager (ILOM) 2.0.1.5 through 2.0.4.26 allows remote authenticated users to (1) access the service processor (SP) and cause a denial of service (shutdown or reboot), or (2) access the host operating system and have an unspecified impact, via unknown vectors.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xhqf-m659-g445

An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via a GET request to a UserService SOAP API endpoint to validate if a user exists.

1%
Низкий
около 1 года назад
github логотип
GHSA-xhqc-hq7h-65v2

Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter.

CVSS3: 9.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-xhqc-h9h8-cqrf

Cross-site scripting (XSS) vulnerability in IBM Forms Experience Builder 8.5.0 and 8.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 97777.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xhqc-7m79-5gq4

The Baseboard Management Controller(BMC) in HPE Cloudline CL5800 Gen9 Server; HPE Cloudline CL5200 Gen9 Server; HPE Cloudline CL4100 Gen10 Server; HPE Cloudline CL3100 Gen10 Server; HPE Cloudline CL5800 Gen10 Server BMC firmware has a local spx_restservice gethelpdata_func function path traversal vulnerability.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xhq9-vwjj-93xv

An exploitable command injection vulnerability exists in the /goform/WanParameterSetting functionality of Tenda AC9 Router AC1200 Smart Dual-Band Gigabit WiFi Route (AC9V1.0 Firmware V15.03.05.16multiTRU). A specially crafted HTTP POST request can cause a command injection in the DNS1 post parameters, resulting in code execution. An attacker can send HTTP POST request with command to trigger this vulnerability.

CVSS3: 7.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-xhq9-9h5f-jcjw

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rhys Wynne WP Flipclock allows DOM-Based XSS. This issue affects WP Flipclock: from n/a through 1.9.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xhq9-58fw-859p

ApostropheCMS: publicApiProjection Bypass via project Query Builder in Piece-Type REST API

CVSS3: 5.3
1%
Низкий
4 месяца назад
github логотип
GHSA-xhq8-8cqj-q337

Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Adobe Reader 9.x before 9.4.4 and 10.x before 10.0.3 on Mac OS X, and Adobe Acrobat 9.x before 9.4.4 and 10.x before 10.0.3 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content; as demonstrated by a Microsoft Office document with an embedded .swf file that has a size inconsistency in a "group of included constants," object type confusion, ActionScript that adds custom functions to prototypes, and Date objects; and as exploited in the wild in April 2011.

CVSS3: 8.8
94%
Критический
больше 4 лет назад
github логотип
GHSA-xhq7-wg93-r5f3

Heap buffer overflow vulnerability in FilePOSIX::read in File.cpp in audiofile 0.3.6 may cause denial-of-service via a crafted wav file, this bug can be triggered by the executable sfconvert.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-xhq7-864q-xxj8

In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in osdmap_decode() When decoding osd_state and osd_weight from an incoming osdmap in osdmap_decode(), both are decoded for each osd, i.e., map->max_osd times. The ceph_decode_need() check only accounts for sizeof(*map->osd_weight) once. This can potentially result in an out-of-bounds memory access if the incoming message is corrupted such that the max_osd value exceeds the actual content of the osdmap message. This patch fixes the issue by changing the corresponding part in the ceph_decode_need() check to account for map->max_osd*sizeof(*map->osd_weight).

CVSS3: 9.1
1%
Низкий
около 2 месяцев назад
github логотип
GHSA-xhq5-7429-4hrv

An issue in the handling of environment variables was addressed with improved validation. This issue is fixed in Security Update 2022-005 Catalina, macOS Big Sur 11.6.8, macOS Monterey 12.5. An app may be able to modify protected parts of the file system.

CVSS3: 5.5
3%
Низкий
почти 4 года назад
github логотип
GHSA-xhq5-45pm-2gjr

OpenClaw: Nextcloud Talk room allowlist matched colliding room names instead of stable room tokens

CVSS3: 4.2
0%
Низкий
5 месяцев назад
github логотип
GHSA-xhq4-rjcc-mjrc

Microsoft Internet Explorer cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP response, related to lack of the HTTP Strict Transport Security (HSTS) includeSubDomains feature, aka a "cookie forcing" issue.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-xhq4-r8xc-mr9f

Opera before 11.62 on Mac OS X allows remote attackers to spoof the address field and security dialogs via crafted styling that causes page content to be displayed outside of the intended content area.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xhq4-92wj-h688

A security vulnerability has been detected in Jinher OA 1.0. This affects an unknown function of the file nextselectplan.aspx. Such manipulation of the argument httpOID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 7.3
0%
Низкий
2 месяца назад
github логотип
GHSA-xhq4-5269-2ffv

In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits cannot be configured. This makes it easier for attackers to cause a denial of service (memory consumption).

2%
Низкий
около 4 лет назад
github логотип
GHSA-xhq3-mvrq-qg9q

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in wayneconnor Sliding Door allows Stored XSS.This issue affects Sliding Door: from n/a through 3.6.

CVSS3: 6.5
0%
Низкий
почти 2 года назад

Уязвимостей на страницу