Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 154

Количество 359 154

github логотип

GHSA-xh95-f55m-82fw

17 дней назад

Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xh95-48w4-456m

больше 2 лет назад

Cross-site scripting (XSS) vulnerability in the entry overview tab in Devolutions Remote Desktop Manager 2023.3.36 and earlier on Windows allows an attacker with access to a data source to inject a malicious script via a specially crafted input in an entry.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xh94-49wq-7h2h

больше 2 лет назад

In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible

CVSS3: 9.8
EPSS: Критический
github логотип

GHSA-xh93-p895-vcfc

больше 4 лет назад

Microsoft Office Word 2000 SP3 and 2002 SP3 and Office 2004 for Mac allow remote attackers to execute arbitrary code via a Word document with a crafted lcbPlcfBkfSdt field in the File Information Block (FIB), which bypasses an initialization step and triggers an "arbitrary free," aka "Word Memory Corruption Vulnerability."

EPSS: Средний
github логотип

GHSA-xh92-w56h-3jjm

больше 3 лет назад

A heap-based buffer overflow in Fortinet FortiWeb version 7.0.0 through 7.0.1, FortiWeb version 6.3.0 through 6.3.19, FortiWeb 6.4 all versions, FortiWeb 6.2 all versions, FortiWeb 6.1 all versions allows attacker to escalation of privilege via specifically crafted arguments to existing commands.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xh92-vqm9-v66r

больше 1 года назад

Stack-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xh92-v267-m4gm

18 дней назад

Insufficient validation of untrusted input in Picture-in-Picture in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-xh92-rqrq-227v

11 месяцев назад

Mastra Docs MCP Server `@mastra/mcp-docs-server` Leads to Information Exposure

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xh92-g23r-644g

больше 4 лет назад

The d_path function in Linux kernel 2.2.20 and earlier, and 2.4.18 and earlier, truncates long pathnames without generating an error, which could allow local users to force programs to perform inappropriate operations on the wrong directories.

EPSS: Низкий
github логотип

GHSA-xh92-7747-9m8g

почти 4 года назад

Windows Storage Elevation of Privilege Vulnerability.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-xh8x-v85v-9297

больше 4 лет назад

Bugzilla 2.10 allows remote attackers to execute arbitrary commands via shell metacharacters in a username that is then processed by (1) the Bugzilla_login cookie in post_bug.cgi, or (2) the who parameter in process_bug.cgi.

EPSS: Низкий
github логотип

GHSA-xh8x-j8h3-m5ph

около 4 лет назад

Rancher Recreates Default User With Known Password Despite Deletion

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xh8w-m2v6-88j8

больше 4 лет назад

Stack-based buffer overflow in DVD X Player 4.1 Professional allows remote attackers to execute arbitrary code via a PLF playlist containing a long filename.

EPSS: Средний
github логотип

GHSA-xh8v-4c88-jfw8

около 4 лет назад

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit PhantomPDF 9.4.0.16811. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of HTML files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-7769.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xh8r-pw4r-9vx4

больше 4 лет назад

Directory traversal vulnerability in openpam_configure.c in OpenPAM before r478 on FreeBSD 8.1 allows local users to load arbitrary DSOs and gain privileges via a .. (dot dot) in the service_name argument to the pam_start function, as demonstrated by a .. in the -c option to kcheckpass.

EPSS: Низкий
github логотип

GHSA-xh8r-pv2v-rc22

4 дня назад

Craft CMS versions before 5.10.8 contain a stored cross-site scripting vulnerability in the control panel where draft names are rendered without HTML encoding in element chips and cards. A low-privilege user who can create element drafts can inject malicious JavaScript that executes in the browser of any higher-privileged user viewing the affected element, allowing account creation and other authenticated actions.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-xh8r-9824-53cf

около 1 года назад

Improper neutralization of newlines in pg_dump in PostgreSQL allows a user of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands inside a purpose-crafted object name. The same attacks can achieve SQL injection as a superuser of the restore target server. pg_dumpall, pg_restore, and pg_upgrade are also affected. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected. Versions before 11.20 are unaffected. CVE-2012-0868 had fixed this class of problem, but version 11.20 reintroduced it.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xh8q-x6hw-jhv5

около 2 месяцев назад

Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: High)

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xh8q-wvvw-q9w3

около 4 лет назад

Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a stored XSS vulnerability when creating Content Fragments. An authenticated attacker can send a malformed POST request to achieve server-side denial of service. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

EPSS: Низкий
github логотип

GHSA-xh8q-q4r3-6x29

больше 4 лет назад

In all versions of GitLab CE/EE starting version 14.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, the reset password token and new user email token are accidentally logged which may lead to information disclosure.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xh95-f55m-82fw

Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)

CVSS3: 7.5
17 дней назад
github логотип
GHSA-xh95-48w4-456m

Cross-site scripting (XSS) vulnerability in the entry overview tab in Devolutions Remote Desktop Manager 2023.3.36 and earlier on Windows allows an attacker with access to a data source to inject a malicious script via a specially crafted input in an entry.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xh94-49wq-7h2h

In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible

CVSS3: 9.8
100%
Критический
больше 2 лет назад
github логотип
GHSA-xh93-p895-vcfc

Microsoft Office Word 2000 SP3 and 2002 SP3 and Office 2004 for Mac allow remote attackers to execute arbitrary code via a Word document with a crafted lcbPlcfBkfSdt field in the File Information Block (FIB), which bypasses an initialization step and triggers an "arbitrary free," aka "Word Memory Corruption Vulnerability."

29%
Средний
больше 4 лет назад
github логотип
GHSA-xh92-w56h-3jjm

A heap-based buffer overflow in Fortinet FortiWeb version 7.0.0 through 7.0.1, FortiWeb version 6.3.0 through 6.3.19, FortiWeb 6.4 all versions, FortiWeb 6.2 all versions, FortiWeb 6.1 all versions allows attacker to escalation of privilege via specifically crafted arguments to existing commands.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xh92-vqm9-v66r

Stack-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.

CVSS3: 8.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-xh92-v267-m4gm

Insufficient validation of untrusted input in Picture-in-Picture in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 9.6
0%
Низкий
18 дней назад
github логотип
GHSA-xh92-rqrq-227v

Mastra Docs MCP Server `@mastra/mcp-docs-server` Leads to Information Exposure

CVSS3: 6.5
1%
Низкий
11 месяцев назад
github логотип
GHSA-xh92-g23r-644g

The d_path function in Linux kernel 2.2.20 and earlier, and 2.4.18 and earlier, truncates long pathnames without generating an error, which could allow local users to force programs to perform inappropriate operations on the wrong directories.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xh92-7747-9m8g

Windows Storage Elevation of Privilege Vulnerability.

CVSS3: 7
0%
Низкий
почти 4 года назад
github логотип
GHSA-xh8x-v85v-9297

Bugzilla 2.10 allows remote attackers to execute arbitrary commands via shell metacharacters in a username that is then processed by (1) the Bugzilla_login cookie in post_bug.cgi, or (2) the who parameter in process_bug.cgi.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xh8x-j8h3-m5ph

Rancher Recreates Default User With Known Password Despite Deletion

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-xh8w-m2v6-88j8

Stack-based buffer overflow in DVD X Player 4.1 Professional allows remote attackers to execute arbitrary code via a PLF playlist containing a long filename.

33%
Средний
больше 4 лет назад
github логотип
GHSA-xh8v-4c88-jfw8

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit PhantomPDF 9.4.0.16811. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of HTML files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-7769.

CVSS3: 5.5
3%
Низкий
около 4 лет назад
github логотип
GHSA-xh8r-pw4r-9vx4

Directory traversal vulnerability in openpam_configure.c in OpenPAM before r478 on FreeBSD 8.1 allows local users to load arbitrary DSOs and gain privileges via a .. (dot dot) in the service_name argument to the pam_start function, as demonstrated by a .. in the -c option to kcheckpass.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xh8r-pv2v-rc22

Craft CMS versions before 5.10.8 contain a stored cross-site scripting vulnerability in the control panel where draft names are rendered without HTML encoding in element chips and cards. A low-privilege user who can create element drafts can inject malicious JavaScript that executes in the browser of any higher-privileged user viewing the affected element, allowing account creation and other authenticated actions.

CVSS3: 6.4
0%
Низкий
4 дня назад
github логотип
GHSA-xh8r-9824-53cf

Improper neutralization of newlines in pg_dump in PostgreSQL allows a user of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands inside a purpose-crafted object name. The same attacks can achieve SQL injection as a superuser of the restore target server. pg_dumpall, pg_restore, and pg_upgrade are also affected. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected. Versions before 11.20 are unaffected. CVE-2012-0868 had fixed this class of problem, but version 11.20 reintroduced it.

CVSS3: 8.8
0%
Низкий
около 1 года назад
github логотип
GHSA-xh8q-x6hw-jhv5

Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: High)

CVSS3: 9.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-xh8q-wvvw-q9w3

Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a stored XSS vulnerability when creating Content Fragments. An authenticated attacker can send a malformed POST request to achieve server-side denial of service. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xh8q-q4r3-6x29

In all versions of GitLab CE/EE starting version 14.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, the reset password token and new user email token are accidentally logged which may lead to information disclosure.

0%
Низкий
больше 4 лет назад

Уязвимостей на страницу