Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 154

Количество 359 154

github логотип

GHSA-xhjw-g8c5-5cf5

больше 4 лет назад

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Serialization). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.01; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service w...

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-xhjw-95fp-8vgq

4 месяца назад

Traefik Kubernetes CRD allows unauthorized cross-namespace middleware binding

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-xhjw-7vh5-qxqm

больше 2 лет назад

LibOSDP RMAC revert to the beginning of the session

CVSS3: 5.1
EPSS: Низкий
github логотип

GHSA-xhjw-276v-rx4m

больше 4 лет назад

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16.6, RBK852 before 3.2.16.6, RBR850 before 3.2.16.6, and RBS850 before 3.2.16.6.

EPSS: Низкий
github логотип

GHSA-xhjv-p3gv-382p

около 2 лет назад

Microsoft Excel Remote Code Execution Vulnerability

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xhjr-gh4r-f8xr

около 3 лет назад

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing to decrypt an encrypted web application login password.

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-xhjr-crv3-4h3c

около 4 лет назад

In the SDK in Bento4 1.5.0-616, AP4_AtomSampleTable::GetSample in Core/Ap4AtomSampleTable.cpp contains a Read Memory Access Violation vulnerability. It is possible to exploit this vulnerability by opening a crafted .MP4 file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xhjq-xwvj-gxm6

8 месяцев назад

In ensureBound of RemotePrintService.java, there is a possible way for a background app to keep foreground permissions due to a permissions bypass. This could lead to local escalation of privilege with user execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-xhjq-w7xm-p8qj

больше 3 лет назад

golang.org/x/crypto/ssh Man-in-the-Middle attack

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xhjq-cgmp-6ppp

8 месяцев назад

Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Salesforce gf-salesforce-crmperks allows Object Injection.This issue affects WP Gravity Forms Salesforce: from n/a through <= 1.5.1.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xhjq-9gfc-7x74

около 4 лет назад

Absolute path traversal vulnerability in steps/mail/sendmail.inc in Roundcube Webmail before 0.7.3 and 0.8.x before 0.8.6 allows remote attackers to read arbitrary files via a full pathname in the _value parameter for the generic_message_footer setting in a save-perf action to index.php, as exploited in the wild in March 2013.

EPSS: Низкий
github логотип

GHSA-xhjp-r5qg-3389

23 дня назад

In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: avoid double free of pool->stack on AQ init failure otx2_pool_aq_init() frees pool->stack when mailbox sync or retry allocation fails, but leaves the pointer unchanged. Later, otx2_sq_aura_pool_init() unwinds the partial setup through otx2_aura_pool_free(), which frees pool->stack again. The CN20K-specific cn20k_pool_aq_init() implementation has the same bug in its corresponding error path. Set pool->stack to NULL immediately after the local free so the shared cleanup path does not free the same stack again while cleaning up partially initialized pool state. The bug was first flagged by an experimental analysis tool we are developing for kernel memory-management bugs while analyzing v6.13-rc1. The tool is still under development and is not yet publicly available. Manual inspection confirms that the bug is still present in v7.1-rc3. Runtime validation was not performed because reproducing this path...

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-xhjm-9p9r-cp2g

больше 4 лет назад

Monstaftp v2.10.3 was discovered to contain an arbitrary file upload which allows attackers to execute arbitrary code via a crafted file uploaded to the web server.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xhjj-qxf6-5q66

больше 4 лет назад

An XSS vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the form[nickname] parameter to the index.php?m=core&f=set&v=sendmail URI. When the administrator accesses the "system settings - mail server" screen, the XSS payload is triggered.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xhjj-qrrg-5524

больше 4 лет назад

GE UR firmware versions prior to version 8.1x supports web interface with read-only access. The device fails to properly validate user input, making it possible to perform cross-site scripting attacks, which may be used to send a malicious script. Also, UR Firmware web server does not perform HTML encoding of user-supplied strings.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xhjj-jg7j-pqrx

больше 4 лет назад

Sign extension error in the ReadDIBImage function in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code via a crafted width value in an image file, which triggers an integer overflow and a heap-based buffer overflow.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xhjj-46q7-2hx6

1 день назад

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix socket use-after-free during link group termination __smc_lgr_terminate() drops conns_lock after finding a connection in lgr->conns_all, but before taking a reference on its socket. The connection is embedded in the socket, and its registration reference protects it only while the connection remains in the tree. A concurrent close can unregister the connection and drop that reference, freeing the socket before the termination worker reaches sock_hold(). The race is reachable when close overlaps link group termination. Local stress testing reproduced the use-after-free and KASAN reported: BUG: KASAN: slab-use-after-free in __smc_lgr_terminate.part.0 [smc] Write of size 4 by task kworker/3:3 Workqueue: events smc_lgr_terminate_work [smc] __smc_lgr_terminate.part.0 [smc] The socket was allocated by smc_create(), freed through slab_free_after_rcu_debug(), and was followed by: refcount_t: ad...

EPSS: Низкий
github логотип

GHSA-xhjh-pmcv-23jw

3 месяца назад

Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-xhjh-m9vh-w983

около 4 лет назад

Directory traversal vulnerability in the web server in SpecView 2.5 build 853 and earlier allows remote attackers to read arbitrary files via a ... (dot dot dot) in a URI.

EPSS: Низкий
github логотип

GHSA-xhjh-662r-5x5g

больше 4 лет назад

Local users can perform a denial of service in NetBSD 1.3.3 and earlier versions by creating an unusual symbolic link with the ln command, triggering a bug in VFS.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xhjw-g8c5-5cf5

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Serialization). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.01; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service w...

CVSS3: 3.7
4%
Низкий
больше 4 лет назад
github логотип
GHSA-xhjw-95fp-8vgq

Traefik Kubernetes CRD allows unauthorized cross-namespace middleware binding

CVSS3: 6.4
0%
Низкий
4 месяца назад
github логотип
GHSA-xhjw-7vh5-qxqm

LibOSDP RMAC revert to the beginning of the session

CVSS3: 5.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xhjw-276v-rx4m

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16.6, RBK852 before 3.2.16.6, RBR850 before 3.2.16.6, and RBS850 before 3.2.16.6.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xhjv-p3gv-382p

Microsoft Excel Remote Code Execution Vulnerability

CVSS3: 7.1
1%
Низкий
около 2 лет назад
github логотип
GHSA-xhjr-gh4r-f8xr

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing to decrypt an encrypted web application login password.

CVSS3: 3.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-xhjr-crv3-4h3c

In the SDK in Bento4 1.5.0-616, AP4_AtomSampleTable::GetSample in Core/Ap4AtomSampleTable.cpp contains a Read Memory Access Violation vulnerability. It is possible to exploit this vulnerability by opening a crafted .MP4 file.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xhjq-xwvj-gxm6

In ensureBound of RemotePrintService.java, there is a possible way for a background app to keep foreground permissions due to a permissions bypass. This could lead to local escalation of privilege with user execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 6.7
0%
Низкий
8 месяцев назад
github логотип
GHSA-xhjq-w7xm-p8qj

golang.org/x/crypto/ssh Man-in-the-Middle attack

CVSS3: 8.1
3%
Низкий
больше 3 лет назад
github логотип
GHSA-xhjq-cgmp-6ppp

Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Salesforce gf-salesforce-crmperks allows Object Injection.This issue affects WP Gravity Forms Salesforce: from n/a through <= 1.5.1.

CVSS3: 9.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-xhjq-9gfc-7x74

Absolute path traversal vulnerability in steps/mail/sendmail.inc in Roundcube Webmail before 0.7.3 and 0.8.x before 0.8.6 allows remote attackers to read arbitrary files via a full pathname in the _value parameter for the generic_message_footer setting in a save-perf action to index.php, as exploited in the wild in March 2013.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xhjp-r5qg-3389

In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: avoid double free of pool->stack on AQ init failure otx2_pool_aq_init() frees pool->stack when mailbox sync or retry allocation fails, but leaves the pointer unchanged. Later, otx2_sq_aura_pool_init() unwinds the partial setup through otx2_aura_pool_free(), which frees pool->stack again. The CN20K-specific cn20k_pool_aq_init() implementation has the same bug in its corresponding error path. Set pool->stack to NULL immediately after the local free so the shared cleanup path does not free the same stack again while cleaning up partially initialized pool state. The bug was first flagged by an experimental analysis tool we are developing for kernel memory-management bugs while analyzing v6.13-rc1. The tool is still under development and is not yet publicly available. Manual inspection confirms that the bug is still present in v7.1-rc3. Runtime validation was not performed because reproducing this path...

CVSS3: 7
0%
Низкий
23 дня назад
github логотип
GHSA-xhjm-9p9r-cp2g

Monstaftp v2.10.3 was discovered to contain an arbitrary file upload which allows attackers to execute arbitrary code via a crafted file uploaded to the web server.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xhjj-qxf6-5q66

An XSS vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the form[nickname] parameter to the index.php?m=core&f=set&v=sendmail URI. When the administrator accesses the "system settings - mail server" screen, the XSS payload is triggered.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xhjj-qrrg-5524

GE UR firmware versions prior to version 8.1x supports web interface with read-only access. The device fails to properly validate user input, making it possible to perform cross-site scripting attacks, which may be used to send a malicious script. Also, UR Firmware web server does not perform HTML encoding of user-supplied strings.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xhjj-jg7j-pqrx

Sign extension error in the ReadDIBImage function in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code via a crafted width value in an image file, which triggers an integer overflow and a heap-based buffer overflow.

CVSS3: 7.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-xhjj-46q7-2hx6

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix socket use-after-free during link group termination __smc_lgr_terminate() drops conns_lock after finding a connection in lgr->conns_all, but before taking a reference on its socket. The connection is embedded in the socket, and its registration reference protects it only while the connection remains in the tree. A concurrent close can unregister the connection and drop that reference, freeing the socket before the termination worker reaches sock_hold(). The race is reachable when close overlaps link group termination. Local stress testing reproduced the use-after-free and KASAN reported: BUG: KASAN: slab-use-after-free in __smc_lgr_terminate.part.0 [smc] Write of size 4 by task kworker/3:3 Workqueue: events smc_lgr_terminate_work [smc] __smc_lgr_terminate.part.0 [smc] The socket was allocated by smc_create(), freed through slab_free_after_rcu_debug(), and was followed by: refcount_t: ad...

1 день назад
github логотип
GHSA-xhjh-pmcv-23jw

Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams

CVSS3: 3.7
0%
Низкий
3 месяца назад
github логотип
GHSA-xhjh-m9vh-w983

Directory traversal vulnerability in the web server in SpecView 2.5 build 853 and earlier allows remote attackers to read arbitrary files via a ... (dot dot dot) in a URI.

5%
Низкий
около 4 лет назад
github логотип
GHSA-xhjh-662r-5x5g

Local users can perform a denial of service in NetBSD 1.3.3 and earlier versions by creating an unusual symbolic link with the ln command, triggering a bug in VFS.

0%
Низкий
больше 4 лет назад

Уязвимостей на страницу