Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 267

Количество 359 267

github логотип

GHSA-xh28-g76m-j6rq

больше 4 лет назад

Buffer overflow in the register function in Ultra Star Reader ActiveX control in SSReader allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-xh27-gh58-w45h

больше 4 лет назад

WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2015-7048, CVE-2015-7095, CVE-2015-7096, CVE-2015-7097, CVE-2015-7098, CVE-2015-7099, CVE-2015-7100, CVE-2015-7101, and CVE-2015-7103.

EPSS: Низкий
github логотип

GHSA-xh27-567v-j74r

больше 3 лет назад

A use-after-free flaw was found in ndlc_remove in drivers/nfc/st-nci/ndlc.c in the Linux Kernel. This flaw could allow an attacker to crash the system due to a race problem.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-xh26-hc5r-c798

больше 4 лет назад

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the getVersionID method. By performing actions in JavaScript, an attacker can trigger a type confusion condition. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-6026.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xh25-q4c4-w86w

больше 1 года назад

In sg_remove_scat of scsi/sg.c, there is a possible memory corruption due to an unusual root cause. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-xh25-p8f3-4864

больше 4 лет назад

O2OA v6.4.7 was discovered to contain a remote code execution (RCE) vulnerability via /x_program_center/jaxrs/invoke.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-xh25-gx5f-4hqg

8 месяцев назад

Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated user to change a document's sharing type to "global," even though they do not have permission to do so, making it visible to everyone in the space via a crafted a HTTP request.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xh25-59hx-vfxx

около 4 лет назад

An issue was discovered on Samsung mobile devices with O(8.x) software. Bixby leaks the keyboard's learned words, and the clipboard contents, via the lock screen. The Samsung IDs are SVE-2018-12896, SVE-2018-12897 (May 2019).

EPSS: Низкий
github логотип

GHSA-xh24-4hr4-phwj

больше 1 года назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in NotFound Include URL allows Path Traversal. This issue affects Include URL: from n/a through 0.3.5.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xh24-4c7j-2rmj

около 4 лет назад

Heap buffer overflow in Bookmarks in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

EPSS: Низкий
github логотип

GHSA-xh23-mwfj-ffgr

около 4 лет назад

NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

EPSS: Низкий
github логотип

GHSA-xh23-4x72-vc94

9 месяцев назад

NVIDIA Triton Inference Server contains a vulnerability where an attacker may cause an improper check for unusual or exceptional conditions issue by sending extra large payloads. A successful exploit of this vulnerability may lead to denial of service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xh22-xj4j-gfvw

больше 4 лет назад

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.3, and 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 186283.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xh22-rmr9-74w8

больше 2 лет назад

Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xh22-fw58-56pp

больше 4 лет назад

Robocode Arbitrary Code Execution

EPSS: Низкий
github логотип

GHSA-xgxx-qjfr-x75f

больше 4 лет назад

Exponent CMS 2.6.0patch2 allows an authenticated admin user to inject persistent JavaScript code inside the "Site/Organization Name","Site Title" and "Site Header" parameters while updating the site settings on "/exponentcms/administration/configure_site"

EPSS: Низкий
github логотип

GHSA-xgxx-52g8-m9j3

больше 4 лет назад

SSH daemon version 1 (aka SSHD-1 or SSH-1) 1.2.30 and earlier does not log repeated login attempts, which could allow remote attackers to compromise accounts without detection via a brute force attack.

EPSS: Низкий
github логотип

GHSA-xgxv-9wxr-rp4c

около 1 года назад

A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vulnerability could allow a bypass of the application's XSS filter by submitting untrusted characters. HP has addressed the issue in the latest software update.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-xgxv-8rww-q966

около 4 лет назад

The "CLink4Service" service is installed with Corsair Link 4.9.7.35 with insecure permissions by default. This allows unprivileged users to take control of the service and execute commands in the context of NT AUTHORITY\SYSTEM, leading to total system takeover, a similar issue to CVE-2018-12441.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xgxv-6497-rf36

больше 4 лет назад

XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "User Mode Write AV near NULL starting at wow64!Wow64NotifyDebugger+0x000000000000001d."

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xh28-g76m-j6rq

Buffer overflow in the register function in Ultra Star Reader ActiveX control in SSReader allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xh27-gh58-w45h

WebKit in Apple iOS before 9.2, Safari before 9.0.2, and tvOS before 9.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2015-7048, CVE-2015-7095, CVE-2015-7096, CVE-2015-7097, CVE-2015-7098, CVE-2015-7099, CVE-2015-7100, CVE-2015-7101, and CVE-2015-7103.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xh27-567v-j74r

A use-after-free flaw was found in ndlc_remove in drivers/nfc/st-nci/ndlc.c in the Linux Kernel. This flaw could allow an attacker to crash the system due to a race problem.

CVSS3: 4.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xh26-hc5r-c798

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the getVersionID method. By performing actions in JavaScript, an attacker can trigger a type confusion condition. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-6026.

CVSS3: 8.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-xh25-q4c4-w86w

In sg_remove_scat of scsi/sg.c, there is a possible memory corruption due to an unusual root cause. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 6.7
0%
Низкий
больше 1 года назад
github логотип
GHSA-xh25-p8f3-4864

O2OA v6.4.7 was discovered to contain a remote code execution (RCE) vulnerability via /x_program_center/jaxrs/invoke.

CVSS3: 9.8
38%
Средний
больше 4 лет назад
github логотип
GHSA-xh25-gx5f-4hqg

Improper Authorization (CWE-285) in Kibana can lead to privilege escalation (CAPEC-233) by allowing an authenticated user to change a document's sharing type to "global," even though they do not have permission to do so, making it visible to everyone in the space via a crafted a HTTP request.

CVSS3: 4.3
0%
Низкий
8 месяцев назад
github логотип
GHSA-xh25-59hx-vfxx

An issue was discovered on Samsung mobile devices with O(8.x) software. Bixby leaks the keyboard's learned words, and the clipboard contents, via the lock screen. The Samsung IDs are SVE-2018-12896, SVE-2018-12897 (May 2019).

0%
Низкий
около 4 лет назад
github логотип
GHSA-xh24-4hr4-phwj

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in NotFound Include URL allows Path Traversal. This issue affects Include URL: from n/a through 0.3.5.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xh24-4c7j-2rmj

Heap buffer overflow in Bookmarks in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

3%
Низкий
около 4 лет назад
github логотип
GHSA-xh23-mwfj-ffgr

NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xh23-4x72-vc94

NVIDIA Triton Inference Server contains a vulnerability where an attacker may cause an improper check for unusual or exceptional conditions issue by sending extra large payloads. A successful exploit of this vulnerability may lead to denial of service.

CVSS3: 7.5
1%
Низкий
9 месяцев назад
github логотип
GHSA-xh22-xj4j-gfvw

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.3, and 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 186283.

CVSS3: 8.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xh22-rmr9-74w8

Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

CVSS3: 7.2
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xh22-fw58-56pp

Robocode Arbitrary Code Execution

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xgxx-qjfr-x75f

Exponent CMS 2.6.0patch2 allows an authenticated admin user to inject persistent JavaScript code inside the "Site/Organization Name","Site Title" and "Site Header" parameters while updating the site settings on "/exponentcms/administration/configure_site"

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xgxx-52g8-m9j3

SSH daemon version 1 (aka SSHD-1 or SSH-1) 1.2.30 and earlier does not log repeated login attempts, which could allow remote attackers to compromise accounts without detection via a brute force attack.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-xgxv-9wxr-rp4c

A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vulnerability could allow a bypass of the application's XSS filter by submitting untrusted characters. HP has addressed the issue in the latest software update.

CVSS3: 4.8
0%
Низкий
около 1 года назад
github логотип
GHSA-xgxv-8rww-q966

The "CLink4Service" service is installed with Corsair Link 4.9.7.35 with insecure permissions by default. This allows unprivileged users to take control of the service and execute commands in the context of NT AUTHORITY\SYSTEM, leading to total system takeover, a similar issue to CVE-2018-12441.

CVSS3: 7.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xgxv-6497-rf36

XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "User Mode Write AV near NULL starting at wow64!Wow64NotifyDebugger+0x000000000000001d."

CVSS3: 7.8
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу