Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 154

Количество 359 154

github логотип

GHSA-xhg6-xj8v-hx9v

больше 4 лет назад

Vulnerability in the Oracle iStore component of Oracle E-Business Suite (subcomponent: Merchant UI). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iStore, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iStore accessible data as well as unauthorized update, insert or delete access to some of Oracle iStore accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-xhg6-f482-fr7w

около 4 лет назад

ElephantDrive does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

EPSS: Низкий
github логотип

GHSA-xhg6-9j5j-w4vf

почти 2 года назад

DotNetZip Directory Traversal vulnerability

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xhg6-78jc-3cwf

больше 2 лет назад

TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by Key Recreation.This issue affects Gecko SDK through v4.4.0.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-xhg5-m3mp-pf34

больше 2 лет назад

A vulnerability classified as critical has been found in Tenda AC8 16.03.34.09. Affected is the function fromAdvSetMacMtuWan of the file /goform/AdvSetMacMtuWan. The manipulation of the argument wanMTU/wanSpeed/cloneType/mac/serviceName/serverName leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-261792. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xhg5-7962-f335

4 месяца назад

The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'marker_name' and 'file_color_list' shortcode attribute of the [osm_map_v3] shortcode in all versions up to and including 6.1.15. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-xhg5-42rf-296r

около 3 лет назад

notation-go's verification bypass can cause users to verify the wrong artifact

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xhg3-wf98-646c

около 4 лет назад

GitLab 8.10 and later through 12.9 is vulnerable to an SSRF in a project import note feature.

EPSS: Низкий
github логотип

GHSA-xhg3-q2f6-w8cg

около 1 месяца назад

A vulnerability has been identified in SIMATIC S7-PLCSIM Advanced (All versions). Affected devices do not properly handle high-volume multicast network traffic, which can exhaust available memory resources in the affected application. This could allow an unauthenticated attacker on the local network segment to cause a denial-of-service condition of the affected application. The affected application becomes inaccessible and requires a manual restart; no project data is lost. Successful exploitation requires a specific project configuration to be already active on the targeted instance.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-xhg3-p7wr-4hrx

около 4 лет назад

Mozilla developers and community members reported memory safety bugs present in Firefox 67 and Firefox ESR 60.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xhg2-vjrc-jqj8

больше 4 лет назад

repository/s3/S3.php in the Amazon S3 library in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to an incorrect CURLOPT_SSL_VERIFYHOST value.

EPSS: Низкий
github логотип

GHSA-xhg2-rvm8-w2jh

около 5 лет назад

Rancher Vulnerable to Cross-site Request Forgery (CSRF)

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-xhg2-hhrv-v2x2

почти 2 года назад

A vulnerability classified as critical has been found in Guangzhou Tuchuang Computer Software Development Interlib Library Cluster Automation Management System up to 2.0.1. This affects an unknown part of the file /interlib/admin/SysLib?cmdACT=inputLIBCODE&mod=batchXSL&xsl=editLIBCODE.xsl&libcodes=&ROWID=. The manipulation of the argument sql leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-xhfx-rm8q-c3xv

около 4 лет назад

Moodle Vulnerable to Reflected Cross-site Scripting

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xhfx-hgmf-v6vp

больше 5 лет назад

October CMS vulnerable to Potential Host Header Poisoning on misconfigured servers

EPSS: Низкий
github логотип

GHSA-xhfw-wjjc-4j5h

больше 4 лет назад

Moodle Cross-site Scripting

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xhfw-qhxr-hjhq

больше 3 лет назад

An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.6.8, 2.7 before 2.7.1. There are 5 bytes left uninitialized in the connection buffer when encoding the FCGI_BEGIN_REQUEST record. Sensitive data may be disclosed to configured FastCGI backends in an unexpected way.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xhfv-xvjm-pqh5

около 4 лет назад

CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/singer/del.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xhfv-px5v-xvpj

больше 4 лет назад

Orenosv 0.5.9f allows remote attackers to cause a denial of service (crash) via a long HTTP GET request.

EPSS: Низкий
github логотип

GHSA-xhfv-25pm-fp3g

больше 4 лет назад

Mozilla Firefox before 39.0 on OS X includes native key press information during the logging of crashes, which allows remote attackers to obtain sensitive information by leveraging access to a crash-reporting data stream.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xhg6-xj8v-hx9v

Vulnerability in the Oracle iStore component of Oracle E-Business Suite (subcomponent: Merchant UI). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iStore, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iStore accessible data as well as unauthorized update, insert or delete access to some of Oracle iStore accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).

CVSS3: 8.2
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xhg6-f482-fr7w

ElephantDrive does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xhg6-9j5j-w4vf

DotNetZip Directory Traversal vulnerability

CVSS3: 9.8
2%
Низкий
почти 2 года назад
github логотип
GHSA-xhg6-78jc-3cwf

TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by Key Recreation.This issue affects Gecko SDK through v4.4.0.

CVSS3: 6.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xhg5-m3mp-pf34

A vulnerability classified as critical has been found in Tenda AC8 16.03.34.09. Affected is the function fromAdvSetMacMtuWan of the file /goform/AdvSetMacMtuWan. The manipulation of the argument wanMTU/wanSpeed/cloneType/mac/serviceName/serverName leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-261792. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
2%
Низкий
больше 2 лет назад
github логотип
GHSA-xhg5-7962-f335

The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'marker_name' and 'file_color_list' shortcode attribute of the [osm_map_v3] shortcode in all versions up to and including 6.1.15. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
4 месяца назад
github логотип
GHSA-xhg5-42rf-296r

notation-go's verification bypass can cause users to verify the wrong artifact

CVSS3: 8.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-xhg3-wf98-646c

GitLab 8.10 and later through 12.9 is vulnerable to an SSRF in a project import note feature.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xhg3-q2f6-w8cg

A vulnerability has been identified in SIMATIC S7-PLCSIM Advanced (All versions). Affected devices do not properly handle high-volume multicast network traffic, which can exhaust available memory resources in the affected application. This could allow an unauthenticated attacker on the local network segment to cause a denial-of-service condition of the affected application. The affected application becomes inaccessible and requires a manual restart; no project data is lost. Successful exploitation requires a specific project configuration to be already active on the targeted instance.

CVSS3: 7.4
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xhg3-p7wr-4hrx

Mozilla developers and community members reported memory safety bugs present in Firefox 67 and Firefox ESR 60.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-xhg2-vjrc-jqj8

repository/s3/S3.php in the Amazon S3 library in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to an incorrect CURLOPT_SSL_VERIFYHOST value.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xhg2-rvm8-w2jh

Rancher Vulnerable to Cross-site Request Forgery (CSRF)

CVSS3: 8.7
1%
Низкий
около 5 лет назад
github логотип
GHSA-xhg2-hhrv-v2x2

A vulnerability classified as critical has been found in Guangzhou Tuchuang Computer Software Development Interlib Library Cluster Automation Management System up to 2.0.1. This affects an unknown part of the file /interlib/admin/SysLib?cmdACT=inputLIBCODE&mod=batchXSL&xsl=editLIBCODE.xsl&libcodes=&ROWID=. The manipulation of the argument sql leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 4.7
1%
Низкий
почти 2 года назад
github логотип
GHSA-xhfx-rm8q-c3xv

Moodle Vulnerable to Reflected Cross-site Scripting

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-xhfx-hgmf-v6vp

October CMS vulnerable to Potential Host Header Poisoning on misconfigured servers

2%
Низкий
больше 5 лет назад
github логотип
GHSA-xhfw-wjjc-4j5h

Moodle Cross-site Scripting

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xhfw-qhxr-hjhq

An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.6.8, 2.7 before 2.7.1. There are 5 bytes left uninitialized in the connection buffer when encoding the FCGI_BEGIN_REQUEST record. Sensitive data may be disclosed to configured FastCGI backends in an unexpected way.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xhfv-xvjm-pqh5

CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/singer/del.

CVSS3: 7.2
1%
Низкий
около 4 лет назад
github логотип
GHSA-xhfv-px5v-xvpj

Orenosv 0.5.9f allows remote attackers to cause a denial of service (crash) via a long HTTP GET request.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-xhfv-25pm-fp3g

Mozilla Firefox before 39.0 on OS X includes native key press information during the logging of crashes, which allows remote attackers to obtain sensitive information by leveraging access to a crash-reporting data stream.

2%
Низкий
больше 4 лет назад

Уязвимостей на страницу