Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 353 883

Количество 353 883

github логотип

GHSA-xx47-vfr9-x3x7

6 месяцев назад

OKI Print Job Accounting 4.4.10 contains an unquoted service path vulnerability in the OkiJaSvc service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Okidata\Print Job Accounting\' to inject malicious executables and escalate privileges.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xx47-qq34-9xqq

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to insert arbitrary web script via the file parameter.

EPSS: Низкий
github логотип

GHSA-xx46-fhm6-qw2q

около 4 лет назад

Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 3.2.24, 4.0.26, 4.1.34, 4.2.26, and 4.3.14 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-2487.

EPSS: Низкий
github логотип

GHSA-xx46-cq25-6hgf

около 4 лет назад

An issue was discovered in the Infosysta "In-App & Desktop Notifications" app before 1.6.14_J8 for Jira. It is possible to obtain a list of all Jira projects without authentication/authorization via the plugins/servlet/nfj/ProjectFilter?searchQuery= URI.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xx45-rh3m-ccvq

около 4 лет назад

Buffer overflow in libstagefright in Mozilla Firefox before 36.0 allows remote attackers to execute arbitrary code via a crafted MP4 video that is improperly handled during playback.

EPSS: Низкий
github логотип

GHSA-xx45-f7pv-xj5x

больше 4 лет назад

SQL injection vulnerability in sign_in.aspx in Message Board / Threaded Discussion Forum Application Template allows remote attackers to execute arbitrary SQL commands via the Password parameter.

EPSS: Низкий
github логотип

GHSA-xx44-m54v-4pwc

около 4 лет назад

An exploitable local privilege elevation vulnerability exists in the file system permissions of Sytech XL Reporter v14.0.1 install directory. Depending on the vector chosen, an attacker can overwrite service executables and execute arbitrary code with privileges of user set to run the service or replace other files within the installation folder, which would allow for local privilege escalation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xx44-254w-m8vr

около 4 лет назад

A malicious or compromised UApp or ABL may be used by an attacker to send a malformed system call to the bootloader, resulting in out-of-bounds memory accesses.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xx43-h94m-wj64

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpsoul Greenshift allows Stored XSS. This issue affects Greenshift: from n/a through 11.0.2.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xx43-6j8m-vx2f

9 месяцев назад

Quipux 4.0.1 through e1774ac allows enumeration of usernames, and accessing the Ecuadorean identification number for all registered users via the Administracion/usuarios/cambiar_password_olvido_validar.php txt_login parameter.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xx42-xvv9-8p8p

около 4 лет назад

The compositor in Google Chrome before 22.0.1229.92 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xx3v-pjx9-qmj7

около 4 лет назад

Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The affected controllers utilize hard-coded credentials which may allow an attacker gain unauthorized access to the maintenance functions and obtain or modify information. This attack can be executed only during maintenance work.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xx3r-7m7h-68q2

около 4 лет назад

Siemens SIMATIC S7-300 Profinet-enabled CPU devices with firmware before 3.2.12 and SIMATIC S7-300 Profinet-disabled CPU devices with firmware before 3.3.12 allow remote attackers to cause a denial of service (defect-mode transition) via crafted (1) ISO-TSAP or (2) Profibus packets.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xx3r-74m7-rjg4

около 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: md/dm-raid: don't call md_reap_sync_thread() directly Currently md_reap_sync_thread() is called from raid_message() directly without holding 'reconfig_mutex', this is definitely unsafe because md_reap_sync_thread() can change many fields that is protected by 'reconfig_mutex'. However, hold 'reconfig_mutex' here is still problematic because this will cause deadlock, for example, commit 130443d60b1b ("md: refactor idle/frozen_sync_thread() to fix deadlock"). Fix this problem by using stop_sync_thread() to unregister sync_thread, like md/raid did.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xx3q-q45w-hjq8

12 месяцев назад

Group-Office versions prior to 6.8.119 and prior to 25.0.20 provided by Intermesh BV contain a path traversal vulnerability. If this vulnerability is exploited, information on the server hosting the product may be exposed.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xx3q-mvc5-c52f

около 4 лет назад

There is a NULL pointer dereference in the caseless_hash function in gxps-archive.c in libgxps 0.2.5. A crafted input will lead to a remote denial of service attack.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xx3p-ffq8-9pcp

около 4 лет назад

Icinga Web 2 has XSS via the /icingaweb2/monitoring/list/services dir parameter, the /icingaweb2/user/list query string, the /icingaweb2/monitoring/timeline query string, or the /icingaweb2/setup query string.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xx3p-5m4j-rhw8

почти 2 года назад

A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from a USB device. This flaw may allow a malicious unprivileged guest user to crash the QEMU process on the host and cause a denial of service condition.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-xx3m-p5mx-cgw5

больше 4 лет назад

Grok 9.5.0 has a heap-based buffer overflow in openhtj2k::T1OpenHTJ2K::decompress (called from std::__1::__packaged_task_func<std::__1::__bind<grk::T1DecompressScheduler::deco and std::__1::packaged_task<int).

EPSS: Низкий
github логотип

GHSA-xx3m-g78m-fjqh

около 4 лет назад

Cross-site scripting (XSS) vulnerability in header.php in Ganglia Web 3.5.8 and 3.5.10 allows remote attackers to inject arbitrary web script or HTML via the host_regex parameter to the default URI, which is processed by get_context.php.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xx47-vfr9-x3x7

OKI Print Job Accounting 4.4.10 contains an unquoted service path vulnerability in the OkiJaSvc service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Okidata\Print Job Accounting\' to inject malicious executables and escalate privileges.

CVSS3: 7.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-xx47-qq34-9xqq

Cross-site scripting (XSS) vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to insert arbitrary web script via the file parameter.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-xx46-fhm6-qw2q

Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 3.2.24, 4.0.26, 4.1.34, 4.2.26, and 4.3.14 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-2487.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xx46-cq25-6hgf

An issue was discovered in the Infosysta "In-App & Desktop Notifications" app before 1.6.14_J8 for Jira. It is possible to obtain a list of all Jira projects without authentication/authorization via the plugins/servlet/nfj/ProjectFilter?searchQuery= URI.

CVSS3: 5.3
2%
Низкий
около 4 лет назад
github логотип
GHSA-xx45-rh3m-ccvq

Buffer overflow in libstagefright in Mozilla Firefox before 36.0 allows remote attackers to execute arbitrary code via a crafted MP4 video that is improperly handled during playback.

6%
Низкий
около 4 лет назад
github логотип
GHSA-xx45-f7pv-xj5x

SQL injection vulnerability in sign_in.aspx in Message Board / Threaded Discussion Forum Application Template allows remote attackers to execute arbitrary SQL commands via the Password parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xx44-m54v-4pwc

An exploitable local privilege elevation vulnerability exists in the file system permissions of Sytech XL Reporter v14.0.1 install directory. Depending on the vector chosen, an attacker can overwrite service executables and execute arbitrary code with privileges of user set to run the service or replace other files within the installation folder, which would allow for local privilege escalation.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-xx44-254w-m8vr

A malicious or compromised UApp or ABL may be used by an attacker to send a malformed system call to the bootloader, resulting in out-of-bounds memory accesses.

CVSS3: 7.8
0%
Низкий
около 4 лет назад
github логотип
GHSA-xx43-h94m-wj64

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpsoul Greenshift allows Stored XSS. This issue affects Greenshift: from n/a through 11.0.2.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xx43-6j8m-vx2f

Quipux 4.0.1 through e1774ac allows enumeration of usernames, and accessing the Ecuadorean identification number for all registered users via the Administracion/usuarios/cambiar_password_olvido_validar.php txt_login parameter.

CVSS3: 5.3
0%
Низкий
9 месяцев назад
github логотип
GHSA-xx42-xvv9-8p8p

The compositor in Google Chrome before 22.0.1229.92 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xx3v-pjx9-qmj7

Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The affected controllers utilize hard-coded credentials which may allow an attacker gain unauthorized access to the maintenance functions and obtain or modify information. This attack can be executed only during maintenance work.

CVSS3: 8.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-xx3r-7m7h-68q2

Siemens SIMATIC S7-300 Profinet-enabled CPU devices with firmware before 3.2.12 and SIMATIC S7-300 Profinet-disabled CPU devices with firmware before 3.3.12 allow remote attackers to cause a denial of service (defect-mode transition) via crafted (1) ISO-TSAP or (2) Profibus packets.

CVSS3: 7.5
4%
Низкий
около 4 лет назад
github логотип
GHSA-xx3r-74m7-rjg4

In the Linux kernel, the following vulnerability has been resolved: md/dm-raid: don't call md_reap_sync_thread() directly Currently md_reap_sync_thread() is called from raid_message() directly without holding 'reconfig_mutex', this is definitely unsafe because md_reap_sync_thread() can change many fields that is protected by 'reconfig_mutex'. However, hold 'reconfig_mutex' here is still problematic because this will cause deadlock, for example, commit 130443d60b1b ("md: refactor idle/frozen_sync_thread() to fix deadlock"). Fix this problem by using stop_sync_thread() to unregister sync_thread, like md/raid did.

CVSS3: 5.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-xx3q-q45w-hjq8

Group-Office versions prior to 6.8.119 and prior to 25.0.20 provided by Intermesh BV contain a path traversal vulnerability. If this vulnerability is exploited, information on the server hosting the product may be exposed.

CVSS3: 4.3
0%
Низкий
12 месяцев назад
github логотип
GHSA-xx3q-mvc5-c52f

There is a NULL pointer dereference in the caseless_hash function in gxps-archive.c in libgxps 0.2.5. A crafted input will lead to a remote denial of service attack.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-xx3p-ffq8-9pcp

Icinga Web 2 has XSS via the /icingaweb2/monitoring/list/services dir parameter, the /icingaweb2/user/list query string, the /icingaweb2/monitoring/timeline query string, or the /icingaweb2/setup query string.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-xx3p-5m4j-rhw8

A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from a USB device. This flaw may allow a malicious unprivileged guest user to crash the QEMU process on the host and cause a denial of service condition.

CVSS3: 4.7
0%
Низкий
почти 2 года назад
github логотип
GHSA-xx3m-p5mx-cgw5

Grok 9.5.0 has a heap-based buffer overflow in openhtj2k::T1OpenHTJ2K::decompress (called from std::__1::__packaged_task_func<std::__1::__bind<grk::T1DecompressScheduler::deco and std::__1::packaged_task<int).

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xx3m-g78m-fjqh

Cross-site scripting (XSS) vulnerability in header.php in Ganglia Web 3.5.8 and 3.5.10 allows remote attackers to inject arbitrary web script or HTML via the host_regex parameter to the default URI, which is processed by get_context.php.

2%
Низкий
около 4 лет назад

Уязвимостей на страницу