Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 267

Количество 359 267

github логотип

GHSA-xh5m-phq6-h38j

около 4 лет назад

Vulnerability in the Oracle AutoVue 3D Professional Advanced component of Oracle Supply Chain Products Suite (subcomponent: Format Handling - 2D). Supported versions that are affected are 21.0.0 and 21.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle AutoVue 3D Professional Advanced. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle AutoVue 3D Professional Advanced accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

EPSS: Низкий
github логотип

GHSA-xh5m-8qqp-c5x7

почти 3 года назад

Remote Denial of Service Vulnerability in Microsoft.Native.Quic.MsQuic.Schannel

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-xh5m-6qq3-59h2

больше 4 лет назад

Multiple stack-based buffer overflows in the Danske Bank e-Sec Control Module ActiveX control (DanskeSikker.ocx) 3.1.0.48, and possibly earlier versions, allow remote attackers to execute arbitrary code via long arguments to unspecified methods, which are not properly handled by a logging function.

EPSS: Низкий
github логотип

GHSA-xh5m-36r6-47m3

25 дней назад

PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xh5j-xjfq-qvvx

3 месяца назад

stigmem-node's federation peer token timestamp validation may reject valid peer tokens

EPSS: Низкий
github логотип

GHSA-xh5j-9mr3-45mv

больше 2 лет назад

Cross Site Scripting vulnerability in smpn1smg absis v.2017-10-19 and before allows a remote attacker to execute arbitrary code via the nama parameter in the lock/lock.php file.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xh5j-7f7g-7g5c

около 4 лет назад

An information leak vulnerability exists in Gerrit versions prior to 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where a missing access check on the branch REST API allows an attacker with only the default set of priviledges to read all other user's personal account data as well as sub-trees with restricted access.

EPSS: Низкий
github логотип

GHSA-xh5j-727m-w6gg

3 месяца назад

Budibase vulnerable to SSRF via trivial `.tar.gz` substring bypass in Plugin URL upload (`/api/plugin`)

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-xh5h-p8c5-4w4x

4 месяца назад

Duplicate Advisory: uutils coreutils has an Improper Handling of Unicode Encoding Issue

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-xh5h-c652-g9jr

5 месяцев назад

Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, and Firefox ESR < 140.9.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xh5f-m55p-f9q7

почти 2 года назад

Illustrator versions 28.6, 27.9.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xh59-j4jj-m2qp

больше 4 лет назад

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "InjectHTMLStream Use After Free Vulnerability."

EPSS: Средний
github логотип

GHSA-xh59-ff3m-c5w6

около 4 лет назад

IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information by allowing cross-window communication with unrestricted target origin via documentation frames.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xh59-6r4f-rjxg

больше 4 лет назад

hsolinkcontrol in hsolink 1.0.118 allows local users to gain privileges via shell metacharacters in command-line arguments, as demonstrated by the second argument in a down action.

EPSS: Низкий
github логотип

GHSA-xh59-2wmf-7vqp

почти 4 года назад

The Highlight Focus WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xh58-v5pj-37jw

больше 2 лет назад

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation). Supported versions that are affected are Prior to 6.2.4.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Agile Product Lifecycle Management for Process accessible data as well as unauthorized read access to a subset of Oracle Agile Product Lifecycle Management for Process accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile Product Lifecycle Management for Process. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xh58-mm4c-xcx4

больше 4 лет назад

The Razer Comms - Gaming Messenger (aka com.razerzone.comms) application 1.3.07 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-xh58-hgvj-wm3q

больше 4 лет назад

Unspecified vulnerability in the SSL implementation in Groupwise client system in the novell-groupwise-client package in SUSE Linux Enterprise Desktop 10 allows remote attackers to obtain credentials via a man-in-the-middle attack, a different vulnerability than CVE-2007-5195.

EPSS: Низкий
github логотип

GHSA-xh58-gg99-9cgg

больше 4 лет назад

Cisco AnyConnect Secure Mobility Client 3.0 before 3.0.08057 allows remote authenticated users to cause a denial of service (vpnagentd process crash) via a crafted packet, aka Bug ID CSCty01670.

EPSS: Низкий
github логотип

GHSA-xh58-g4x9-7m2f

больше 4 лет назад

Multiple buffer overflows in (1) tetrinet_inmessage, (2) speclist_add and (3) config-getthemeinfo of GTetrinet 0.4.3 and earlier allow remote attackers to casue a denial of service and possibly execute arbitrary code.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xh5m-phq6-h38j

Vulnerability in the Oracle AutoVue 3D Professional Advanced component of Oracle Supply Chain Products Suite (subcomponent: Format Handling - 2D). Supported versions that are affected are 21.0.0 and 21.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle AutoVue 3D Professional Advanced. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle AutoVue 3D Professional Advanced accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

1%
Низкий
около 4 лет назад
github логотип
GHSA-xh5m-8qqp-c5x7

Remote Denial of Service Vulnerability in Microsoft.Native.Quic.MsQuic.Schannel

CVSS3: 7.5
69%
Средний
почти 3 года назад
github логотип
GHSA-xh5m-6qq3-59h2

Multiple stack-based buffer overflows in the Danske Bank e-Sec Control Module ActiveX control (DanskeSikker.ocx) 3.1.0.48, and possibly earlier versions, allow remote attackers to execute arbitrary code via long arguments to unspecified methods, which are not properly handled by a logging function.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-xh5m-36r6-47m3

PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion

CVSS3: 7.5
1%
Низкий
25 дней назад
github логотип
GHSA-xh5j-xjfq-qvvx

stigmem-node's federation peer token timestamp validation may reject valid peer tokens

3 месяца назад
github логотип
GHSA-xh5j-9mr3-45mv

Cross Site Scripting vulnerability in smpn1smg absis v.2017-10-19 and before allows a remote attacker to execute arbitrary code via the nama parameter in the lock/lock.php file.

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xh5j-7f7g-7g5c

An information leak vulnerability exists in Gerrit versions prior to 2.15.21, 2.16.25, 3.0.15, 3.1.10, 3.2.5 where a missing access check on the branch REST API allows an attacker with only the default set of priviledges to read all other user's personal account data as well as sub-trees with restricted access.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xh5j-727m-w6gg

Budibase vulnerable to SSRF via trivial `.tar.gz` substring bypass in Plugin URL upload (`/api/plugin`)

CVSS3: 7.7
0%
Низкий
3 месяца назад
github логотип
GHSA-xh5h-p8c5-4w4x

Duplicate Advisory: uutils coreutils has an Improper Handling of Unicode Encoding Issue

CVSS3: 3.3
4 месяца назад
github логотип
GHSA-xh5h-c652-g9jr

Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, and Firefox ESR < 140.9.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-xh5f-m55p-f9q7

Illustrator versions 28.6, 27.9.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-xh59-j4jj-m2qp

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "InjectHTMLStream Use After Free Vulnerability."

18%
Средний
больше 4 лет назад
github логотип
GHSA-xh59-ff3m-c5w6

IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information by allowing cross-window communication with unrestricted target origin via documentation frames.

CVSS3: 5.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-xh59-6r4f-rjxg

hsolinkcontrol in hsolink 1.0.118 allows local users to gain privileges via shell metacharacters in command-line arguments, as demonstrated by the second argument in a down action.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xh59-2wmf-7vqp

The Highlight Focus WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS3: 4.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-xh58-v5pj-37jw

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation). Supported versions that are affected are Prior to 6.2.4.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Agile Product Lifecycle Management for Process accessible data as well as unauthorized read access to a subset of Oracle Agile Product Lifecycle Management for Process accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile Product Lifecycle Management for Process. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).

CVSS3: 7.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xh58-mm4c-xcx4

The Razer Comms - Gaming Messenger (aka com.razerzone.comms) application 1.3.07 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xh58-hgvj-wm3q

Unspecified vulnerability in the SSL implementation in Groupwise client system in the novell-groupwise-client package in SUSE Linux Enterprise Desktop 10 allows remote attackers to obtain credentials via a man-in-the-middle attack, a different vulnerability than CVE-2007-5195.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xh58-gg99-9cgg

Cisco AnyConnect Secure Mobility Client 3.0 before 3.0.08057 allows remote authenticated users to cause a denial of service (vpnagentd process crash) via a crafted packet, aka Bug ID CSCty01670.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xh58-g4x9-7m2f

Multiple buffer overflows in (1) tetrinet_inmessage, (2) speclist_add and (3) config-getthemeinfo of GTetrinet 0.4.3 and earlier allow remote attackers to casue a denial of service and possibly execute arbitrary code.

3%
Низкий
больше 4 лет назад

Уязвимостей на страницу