Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 267

Количество 359 267

github логотип

GHSA-xh4h-63x5-gr2f

4 месяца назад

An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control daemon (chassisd) of Juniper Networks Junos OS on SRX1600, SRX2300 and SRX4300 allows a local attacker with low privileges to cause a complete Denial of Service (DoS). When a specific 'show chassis' CLI command is executed, chassisd crashes and restarts which causes a momentary impact to all traffic until all modules are online again. This issue affects Junos OS on SRX1600, SRX2300 and SRX4300: * 24.4 versions before 24.4R1-S3, 24.4R2. This issue does not affect Junos OS versions before 24.4R1.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xh4g-c9p6-5jxg

почти 2 года назад

LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/app/Http/Controllers/Table/EditPortsController.php

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xh4g-88qm-9p7r

больше 4 лет назад

SmarterTools SmarterMail 16.x through 100.x before 100.0.7803 allows remote code execution.

EPSS: Низкий
github логотип

GHSA-xh4f-v933-c556

почти 3 года назад

FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xh4c-c9p9-cjx3

больше 4 лет назад

SQL injection vulnerability in products.php in CommodityRentals Trade Manager Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.

EPSS: Низкий
github логотип

GHSA-xh49-j9w7-xf24

больше 3 лет назад

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in impleCode Product Catalog Simple plugin <= 1.6.17 versions.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xh47-8qgr-7ww7

больше 3 лет назад

A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the availability of the web page.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-xh47-8887-mw3h

около 4 лет назад

The Synergy Systems & Solutions (SSS) HUSKY RTU 6049-E70, with firmware Versions 5.0 and prior, has a Missing Authentication for Critical Function (CWE-306) vulnerability. The affected product does not require authentication for TELNET access, which may allow an attacker to change configuration or perform other malicious activities.

EPSS: Низкий
github логотип

GHSA-xh46-6cwm-rgh4

больше 4 лет назад

The Solution Manager in SAP NetWeaver does not properly restrict access, which allows remote attackers to obtain sensitive information via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xh45-57vp-7gw8

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1 before IF6, 10.1.1 before IF5, 10.2 before IF7, 10.2.1 before IF4, and 10.2.1.1 before IF4 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter that is not properly handled during use of the Back button.

EPSS: Низкий
github логотип

GHSA-xh44-f8rg-h6h3

больше 4 лет назад

The Extended Control List (ECL) feature of the Java Virtual Machine (JVM) in Lotus Notes Client R5 allows malicious web site operators to determine the existence of files on the client by measuring delays in the execution of the getSystemResource method.

EPSS: Низкий
github логотип

GHSA-xh44-8w9g-3p27

больше 4 лет назад

McAfee IntruShield Security Management System allows remote authenticated users to access the "Generate Reports" feature and modify alerts by setting the Access option to true, as demonstrated using the (1) fullAccess or (2) fullAccessRight parameter in reports-column-center.jsp, or (3) fullAccess parameter to SystemEvent.jsp.

EPSS: Низкий
github логотип

GHSA-xh44-7m8v-gqg4

больше 3 лет назад

A use-of-uninitialized-pointer vulnerability exists in the Forward Open connection_management_entry functionality of EIP Stack Group OpENer development commit 58ee13c. A specially-crafted EtherNet/IP request can lead to use of a null pointer, causing the server to crash. An attacker can send a series of EtherNet/IP requests to trigger this vulnerability.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xh43-g2fq-wjrj

6 месяцев назад

Angular SSR has an Open Redirect via X-Forwarded-Prefix

EPSS: Низкий
github логотип

GHSA-xh42-fcvq-34r9

около 4 лет назад

Unbound before 1.9.5 allows an integer overflow in the regional allocator via the ALIGN_UP macro.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xh42-8p9x-c4x4

больше 4 лет назад

Unspecified vulnerability in dtterm in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code with root privileges via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xh3x-wrg7-2m5m

больше 4 лет назад

mediaserver in Android 5.x before 5.1.1 LMY48T and 6.0 before 2015-10-01 allows attackers to gain privileges via a crafted application, aka internal bug 19573085, a different vulnerability than CVE-2015-6596.

EPSS: Низкий
github логотип

GHSA-xh3w-v58r-2jxm

около 4 лет назад

Possible out of bounds read due to incorrect validation of incoming buffer length in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xh3w-9cjp-3cf8

больше 1 года назад

The Data Services Management Console does not sufficiently encode user-controlled inputs, allowing an attacker to inject malicious script. When a targeted victim, who is already logged in, clicks on the compromised link, the injected script gets executed within the scope of victim�s browser. This potentially leads to an impact on confidentiality and integrity. Availability is not impacted.

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-xh3v-6f9j-wxw3

около 4 лет назад

Drupal core Information Disclosure vulnerability

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xh4h-63x5-gr2f

An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control daemon (chassisd) of Juniper Networks Junos OS on SRX1600, SRX2300 and SRX4300 allows a local attacker with low privileges to cause a complete Denial of Service (DoS). When a specific 'show chassis' CLI command is executed, chassisd crashes and restarts which causes a momentary impact to all traffic until all modules are online again. This issue affects Junos OS on SRX1600, SRX2300 and SRX4300: * 24.4 versions before 24.4R1-S3, 24.4R2. This issue does not affect Junos OS versions before 24.4R1.

CVSS3: 5.5
0%
Низкий
4 месяца назад
github логотип
GHSA-xh4g-c9p6-5jxg

LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/app/Http/Controllers/Table/EditPortsController.php

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-xh4g-88qm-9p7r

SmarterTools SmarterMail 16.x through 100.x before 100.0.7803 allows remote code execution.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xh4f-v933-c556

FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-xh4c-c9p9-cjx3

SQL injection vulnerability in products.php in CommodityRentals Trade Manager Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xh49-j9w7-xf24

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in impleCode Product Catalog Simple plugin <= 1.6.17 versions.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xh47-8qgr-7ww7

A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the availability of the web page.

CVSS3: 4.7
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xh47-8887-mw3h

The Synergy Systems & Solutions (SSS) HUSKY RTU 6049-E70, with firmware Versions 5.0 and prior, has a Missing Authentication for Critical Function (CWE-306) vulnerability. The affected product does not require authentication for TELNET access, which may allow an attacker to change configuration or perform other malicious activities.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xh46-6cwm-rgh4

The Solution Manager in SAP NetWeaver does not properly restrict access, which allows remote attackers to obtain sensitive information via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xh45-57vp-7gw8

Cross-site scripting (XSS) vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1 before IF6, 10.1.1 before IF5, 10.2 before IF7, 10.2.1 before IF4, and 10.2.1.1 before IF4 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter that is not properly handled during use of the Back button.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xh44-f8rg-h6h3

The Extended Control List (ECL) feature of the Java Virtual Machine (JVM) in Lotus Notes Client R5 allows malicious web site operators to determine the existence of files on the client by measuring delays in the execution of the getSystemResource method.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xh44-8w9g-3p27

McAfee IntruShield Security Management System allows remote authenticated users to access the "Generate Reports" feature and modify alerts by setting the Access option to true, as demonstrated using the (1) fullAccess or (2) fullAccessRight parameter in reports-column-center.jsp, or (3) fullAccess parameter to SystemEvent.jsp.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xh44-7m8v-gqg4

A use-of-uninitialized-pointer vulnerability exists in the Forward Open connection_management_entry functionality of EIP Stack Group OpENer development commit 58ee13c. A specially-crafted EtherNet/IP request can lead to use of a null pointer, causing the server to crash. An attacker can send a series of EtherNet/IP requests to trigger this vulnerability.

CVSS3: 7.5
8%
Низкий
больше 3 лет назад
github логотип
GHSA-xh43-g2fq-wjrj

Angular SSR has an Open Redirect via X-Forwarded-Prefix

0%
Низкий
6 месяцев назад
github логотип
GHSA-xh42-fcvq-34r9

Unbound before 1.9.5 allows an integer overflow in the regional allocator via the ALIGN_UP macro.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-xh42-8p9x-c4x4

Unspecified vulnerability in dtterm in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code with root privileges via unspecified vectors.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xh3x-wrg7-2m5m

mediaserver in Android 5.x before 5.1.1 LMY48T and 6.0 before 2015-10-01 allows attackers to gain privileges via a crafted application, aka internal bug 19573085, a different vulnerability than CVE-2015-6596.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xh3w-v58r-2jxm

Possible out of bounds read due to incorrect validation of incoming buffer length in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

CVSS3: 7.1
0%
Низкий
около 4 лет назад
github логотип
GHSA-xh3w-9cjp-3cf8

The Data Services Management Console does not sufficiently encode user-controlled inputs, allowing an attacker to inject malicious script. When a targeted victim, who is already logged in, clicks on the compromised link, the injected script gets executed within the scope of victim�s browser. This potentially leads to an impact on confidentiality and integrity. Availability is not impacted.

CVSS3: 4.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-xh3v-6f9j-wxw3

Drupal core Information Disclosure vulnerability

CVSS3: 7.5
1%
Низкий
около 4 лет назад

Уязвимостей на страницу