Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 267

Количество 359 267

github логотип

GHSA-xh7v-965r-23f7

12 месяцев назад

Atlantis Exposes Service Version Publicly on /status API Endpoint

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xh7r-hcfv-6wpx

больше 3 лет назад

In SAP Host Agent (Windows) - versions 7.21, 7.22, an attacker who gains local membership to SAP_LocalAdmin could be able to replace executables with a malicious file that will be started under a privileged account. Note that by default all user members of SAP_LocaAdmin are denied the ability to logon locally by security policy so that this can only occur if the system has already been compromised.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-xh7q-hg94-4g3m

почти 3 года назад

An issue has been discovered in GitLab EE/CE affecting all versions starting before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1 which allows an attackers to block Sidekiq job processor.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xh7q-7r6g-64g2

больше 4 лет назад

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a crafted packets, aka "Windows SMB Information Disclosure Vulnerability."

CVSS3: 5.9
EPSS: Критический
github логотип

GHSA-xh7p-rgf9-78jv

около 1 года назад

An unauthenticated remote attacker can alter the device configuration in a way to get remote code execution as root with specific configurations.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xh7p-g3jr-x8p8

почти 4 года назад

In vow, there is a possible undefined behavior due to an API misuse. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07032604; Issue ID: ALPS07032604.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-xh7p-83h3-2grw

больше 4 лет назад

Multiple format string vulnerabilities in (1) the cdio_log_handler function in modules/access/cdda/access.c in the CDDA (libcdda_plugin) plugin, and the (2) cdio_log_handler and (3) vcd_log_handler functions in modules/access/vcdx/access.c in the VCDX (libvcdx_plugin) plugin, in VideoLAN VLC 0.7.0 through 0.8.6 allow user-assisted remote attackers to execute arbitrary code via format string specifiers in an invalid URI, as demonstrated by a udp://-- URI in an M3U file.

EPSS: Средний
github логотип

GHSA-xh7m-p996-h2f6

3 месяца назад

NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xh7j-p2mw-685q

больше 4 лет назад

IOKit SCSI in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via an app that provides an unspecified userclient type.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xh7j-grp8-cc5p

больше 2 лет назад

Multiple integer overflow vulnerabilities exist in the LXT2 facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the integer overflow when allocating the `value` array.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xh7h-xfm8-vvhp

около 4 лет назад

Adobe Animate version 21.0.6 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

EPSS: Низкий
github логотип

GHSA-xh7h-h275-6q2f

11 месяцев назад

Directory traversal vulnerability in Sync In server thru 1.1.1 allowing authenticated attackers to gain read and write access to the system via FilesManager.saveMultipart function in backend/src/applications/files/services/files-manager.service.ts, and FilesManager.compress function in backend/src/applications/files/services/files-manager.service.ts.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xh7h-8gq3-h9qj

около 3 лет назад

The Autochat Automatic Conversation WordPress plugin through 1.1.7 does not sanitise and escape user input before outputting it back on the page, leading to a cross-site Scripting attack.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xh7g-q5xg-vwh8

больше 4 лет назад

Cross-site request forgery (CSRF) vulnerability in Stoneware webNetwork before 6.0.8.0 allows remote attackers to hijack the authentication of unspecified victims for requests that modify user accounts.

EPSS: Низкий
github логотип

GHSA-xh7g-4q3q-78mv

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the frontend in Open-Xchange (OX) AppSuite 7.4.1 before 7.4.1-rev10 and 7.4.2 before 7.4.2-rev8 allows remote attackers to inject arbitrary web script or HTML via the subject of an email, involving 'the aria "tags" for screenreaders at the top bar'.

EPSS: Низкий
github логотип

GHSA-xh7g-3rfm-j232

больше 2 лет назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zoho Campaigns.This issue affects Zoho Campaigns: from n/a through 2.0.6.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-xh7f-q58h-38f6

больше 4 лет назад

An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xh7f-mchx-vxh4

больше 4 лет назад

Enhanced Simple PHP Gallery 1.7 allows remote attackers to obtain the full path of the application via a direct request to sp_helper_functions.php, which leaks the pathname in an error message.

EPSS: Низкий
github логотип

GHSA-xh7f-2c8g-37p4

больше 4 лет назад

The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in the wild in February and March 2022 for the TP240PhoneHome DDoS attack.

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-xh7c-xrrg-3jv2

около 4 лет назад

An Insecure Direct Object Reference (IDOR) vulnerability was found in Prestashop Opart devis < 4.0.2. Unauthenticated attackers can have access to any user's invoice and delivery address by exploiting an IDOR on the delivery_address and invoice_address fields.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xh7v-965r-23f7

Atlantis Exposes Service Version Publicly on /status API Endpoint

CVSS3: 7.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-xh7r-hcfv-6wpx

In SAP Host Agent (Windows) - versions 7.21, 7.22, an attacker who gains local membership to SAP_LocalAdmin could be able to replace executables with a malicious file that will be started under a privileged account. Note that by default all user members of SAP_LocaAdmin are denied the ability to logon locally by security policy so that this can only occur if the system has already been compromised.

CVSS3: 6.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xh7q-hg94-4g3m

An issue has been discovered in GitLab EE/CE affecting all versions starting before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1 which allows an attackers to block Sidekiq job processor.

CVSS3: 4.3
1%
Низкий
почти 3 года назад
github логотип
GHSA-xh7q-7r6g-64g2

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a crafted packets, aka "Windows SMB Information Disclosure Vulnerability."

CVSS3: 5.9
100%
Критический
больше 4 лет назад
github логотип
GHSA-xh7p-rgf9-78jv

An unauthenticated remote attacker can alter the device configuration in a way to get remote code execution as root with specific configurations.

CVSS3: 9.8
1%
Низкий
около 1 года назад
github логотип
GHSA-xh7p-g3jr-x8p8

In vow, there is a possible undefined behavior due to an API misuse. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07032604; Issue ID: ALPS07032604.

CVSS3: 6.7
0%
Низкий
почти 4 года назад
github логотип
GHSA-xh7p-83h3-2grw

Multiple format string vulnerabilities in (1) the cdio_log_handler function in modules/access/cdda/access.c in the CDDA (libcdda_plugin) plugin, and the (2) cdio_log_handler and (3) vcd_log_handler functions in modules/access/vcdx/access.c in the VCDX (libvcdx_plugin) plugin, in VideoLAN VLC 0.7.0 through 0.8.6 allow user-assisted remote attackers to execute arbitrary code via format string specifiers in an invalid URI, as demonstrated by a udp://-- URI in an M3U file.

12%
Средний
больше 4 лет назад
github логотип
GHSA-xh7m-p996-h2f6

NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

CVSS3: 7.8
0%
Низкий
3 месяца назад
github логотип
GHSA-xh7j-p2mw-685q

IOKit SCSI in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via an app that provides an unspecified userclient type.

CVSS3: 7.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-xh7j-grp8-cc5p

Multiple integer overflow vulnerabilities exist in the LXT2 facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the integer overflow when allocating the `value` array.

CVSS3: 7.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xh7h-xfm8-vvhp

Adobe Animate version 21.0.6 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xh7h-h275-6q2f

Directory traversal vulnerability in Sync In server thru 1.1.1 allowing authenticated attackers to gain read and write access to the system via FilesManager.saveMultipart function in backend/src/applications/files/services/files-manager.service.ts, and FilesManager.compress function in backend/src/applications/files/services/files-manager.service.ts.

CVSS3: 5.3
1%
Низкий
11 месяцев назад
github логотип
GHSA-xh7h-8gq3-h9qj

The Autochat Automatic Conversation WordPress plugin through 1.1.7 does not sanitise and escape user input before outputting it back on the page, leading to a cross-site Scripting attack.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-xh7g-q5xg-vwh8

Cross-site request forgery (CSRF) vulnerability in Stoneware webNetwork before 6.0.8.0 allows remote attackers to hijack the authentication of unspecified victims for requests that modify user accounts.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xh7g-4q3q-78mv

Cross-site scripting (XSS) vulnerability in the frontend in Open-Xchange (OX) AppSuite 7.4.1 before 7.4.1-rev10 and 7.4.2 before 7.4.2-rev8 allows remote attackers to inject arbitrary web script or HTML via the subject of an email, involving 'the aria "tags" for screenreaders at the top bar'.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xh7g-3rfm-j232

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zoho Campaigns.This issue affects Zoho Campaigns: from n/a through 2.0.6.

CVSS3: 8.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xh7f-q58h-38f6

An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xh7f-mchx-vxh4

Enhanced Simple PHP Gallery 1.7 allows remote attackers to obtain the full path of the application via a direct request to sp_helper_functions.php, which leaks the pathname in an error message.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xh7f-2c8g-37p4

The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in the wild in February and March 2022 for the TP240PhoneHome DDoS attack.

CVSS3: 9.8
87%
Высокий
больше 4 лет назад
github логотип
GHSA-xh7c-xrrg-3jv2

An Insecure Direct Object Reference (IDOR) vulnerability was found in Prestashop Opart devis < 4.0.2. Unauthenticated attackers can have access to any user's invoice and delivery address by exploiting an IDOR on the delivery_address and invoice_address fields.

CVSS3: 5.3
1%
Низкий
около 4 лет назад

Уязвимостей на страницу