Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 359 267

Количество 359 267

github логотип

GHSA-xgrq-27cp-45v2

почти 3 года назад

An open redirect vulnerability in the sanitize_url() parameter of CouchCMS v2.3 allows attackers to redirect a victim user to an arbitrary web site via a crafted URL.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xgrm-4fwx-7qm8

4 месяца назад

pgx contains memory-safety vulnerability

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xgrj-5fxr-f35m

4 месяца назад

Heap-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xgrh-89p6-c4pw

больше 4 лет назад

The debug console interface on Cisco Small Business SPA300 and SPA500 phones does not properly perform authentication, which allows local users to execute arbitrary debug-shell commands, or read or modify data in memory or a filesystem, via direct access to this interface, aka Bug ID CSCun77435.

EPSS: Низкий
github логотип

GHSA-xgrg-j85f-cmwr

больше 4 лет назад

An XSS issue was discovered in MyBiz MyProcureNet 5.0.0. This vulnerability within "ProxyPage.aspx" allows an attacker to inject malicious client side scripting which will be executed in the browser of users if they visit the manipulated site.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xgrg-cw4v-4h6g

больше 1 года назад

A vulnerability has been identified in Desigo CC (All versions if access from Installed Clients to Desigo CC server is allowed from networks outside of a highly protected zone), Desigo CC (All versions if access from Installed Clients to Desigo CC server is only allowed within highly protected zones). The affected server application fails to authenticate specific client requests. Modification of the client binary could allow an unauthenticated remote attacker to execute arbitrary SQL queries on the server database via the event port (default: 4998/tcp)

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xgrf-rhvw-h8mr

больше 3 лет назад

The multi-screen collaboration module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xgrf-pj3c-wvq6

больше 4 лет назад

Stack-based buffer overflow in Music Animation Machine MIDI Player 2006aug19 Release 035 and possibly other versions allows user-assisted remote attackers to execute arbitrary code via a long line in a .mamx file.

EPSS: Средний
github логотип

GHSA-xgrf-p9gx-vhq3

больше 4 лет назад

Buffer overflow in the process_abc function in abc.c for abc2mtex 1.6.1 allows remote attackers to execute arbitrary code via crafted ABC files.

EPSS: Низкий
github логотип

GHSA-xgrc-wxf2-c646

больше 4 лет назад

recorder_test.cgi on the D-Link DCS-2121 camera with firmware 1.04 allows remote attackers to execute arbitrary commands via shell metacharacters in the Password field, related to a "semicolon injection" vulnerability.

EPSS: Низкий
github логотип

GHSA-xgrc-mq5c-7xjc

больше 1 года назад

Improper Input Validation vulnerability in Progress LoadMaster allows : Buffer OverflowThis issue affects: * LoadMaster: 7.2.40.0 and above * ECS: All versions * Multi-Tenancy: 7.1.35.4 and above

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xgrc-85pp-86cg

больше 4 лет назад

Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, does not properly handle a right-to-left override (aka RLO or U+202E) Unicode character in a download filename, which allows remote attackers to spoof file extensions via a crafted filename, as demonstrated by displaying a non-executable extension for an executable file.

EPSS: Низкий
github логотип

GHSA-xgr9-pmph-722v

8 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in Peter Sterling Simple Archive Generator allows Stored XSS.This issue affects Simple Archive Generator: from n/a through 5.2.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xgr9-crfp-4qg4

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: bpf: avoid holding freeze_mutex during mmap operation We use map->freeze_mutex to prevent races between map_freeze() and memory mapping BPF map contents with writable permissions. The way we naively do this means we'll hold freeze_mutex for entire duration of all the mm and VMA manipulations, which is completely unnecessary. This can potentially also lead to deadlocks, as reported by syzbot in [0]. So, instead, hold freeze_mutex only during writeability checks, bump (proactively) "write active" count for the map, unlock the mutex and proceed with mmap logic. And only if something went wrong during mmap logic, then undo that "write active" counter increment. [0] https://lore.kernel.org/bpf/678dcbc9.050a0220.303755.0066.GAE@google.com/

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xgr9-8q24-v4ph

больше 4 лет назад

In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the ASN.1 BER dissector could crash. This was addressed in epan/dissectors/packet-ber.c by ensuring that length values do not exceed the maximum signed integer.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xgr9-7593-ff2p

больше 3 лет назад

Windows Distributed File System (DFS) Remote Code Execution Vulnerability

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-xgr8-wfr6-wmh2

больше 4 лет назад

IBM Rational Team Concert 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148615.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xgr8-mrxv-f3p6

27 дней назад

Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one workspace to access, delete, or duplicate assets belonging to another workspace by providing only the victim workspace slug and asset ID. The affected endpoints return presigned file URLs and enable destructive or duplicative actions without verifying that the requester is a member of the targeted workspace. This enables cross‑tenant data exposure, data deletion, and persistent exfiltration of files into an attacker‑controlled workspace.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xgr7-jgq3-mhmc

около 2 лет назад

Contract balance not updating correctly after interchain transaction

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xgr7-3fmq-x97v

почти 4 года назад

H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function debug_wlan_advance.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xgrq-27cp-45v2

An open redirect vulnerability in the sanitize_url() parameter of CouchCMS v2.3 allows attackers to redirect a victim user to an arbitrary web site via a crafted URL.

CVSS3: 6.1
0%
Низкий
почти 3 года назад
github логотип
GHSA-xgrm-4fwx-7qm8

pgx contains memory-safety vulnerability

CVSS3: 9.8
1%
Низкий
4 месяца назад
github логотип
GHSA-xgrj-5fxr-f35m

Heap-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code locally.

CVSS3: 7.8
0%
Низкий
4 месяца назад
github логотип
GHSA-xgrh-89p6-c4pw

The debug console interface on Cisco Small Business SPA300 and SPA500 phones does not properly perform authentication, which allows local users to execute arbitrary debug-shell commands, or read or modify data in memory or a filesystem, via direct access to this interface, aka Bug ID CSCun77435.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xgrg-j85f-cmwr

An XSS issue was discovered in MyBiz MyProcureNet 5.0.0. This vulnerability within "ProxyPage.aspx" allows an attacker to inject malicious client side scripting which will be executed in the browser of users if they visit the manipulated site.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xgrg-cw4v-4h6g

A vulnerability has been identified in Desigo CC (All versions if access from Installed Clients to Desigo CC server is allowed from networks outside of a highly protected zone), Desigo CC (All versions if access from Installed Clients to Desigo CC server is only allowed within highly protected zones). The affected server application fails to authenticate specific client requests. Modification of the client binary could allow an unauthenticated remote attacker to execute arbitrary SQL queries on the server database via the event port (default: 4998/tcp)

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-xgrf-rhvw-h8mr

The multi-screen collaboration module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xgrf-pj3c-wvq6

Stack-based buffer overflow in Music Animation Machine MIDI Player 2006aug19 Release 035 and possibly other versions allows user-assisted remote attackers to execute arbitrary code via a long line in a .mamx file.

16%
Средний
больше 4 лет назад
github логотип
GHSA-xgrf-p9gx-vhq3

Buffer overflow in the process_abc function in abc.c for abc2mtex 1.6.1 allows remote attackers to execute arbitrary code via crafted ABC files.

6%
Низкий
больше 4 лет назад
github логотип
GHSA-xgrc-wxf2-c646

recorder_test.cgi on the D-Link DCS-2121 camera with firmware 1.04 allows remote attackers to execute arbitrary commands via shell metacharacters in the Password field, related to a "semicolon injection" vulnerability.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-xgrc-mq5c-7xjc

Improper Input Validation vulnerability in Progress LoadMaster allows : Buffer OverflowThis issue affects: * LoadMaster: 7.2.40.0 and above * ECS: All versions * Multi-Tenancy: 7.1.35.4 and above

CVSS3: 4.3
5%
Низкий
больше 1 года назад
github логотип
GHSA-xgrc-85pp-86cg

Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, does not properly handle a right-to-left override (aka RLO or U+202E) Unicode character in a download filename, which allows remote attackers to spoof file extensions via a crafted filename, as demonstrated by displaying a non-executable extension for an executable file.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-xgr9-pmph-722v

Cross-Site Request Forgery (CSRF) vulnerability in Peter Sterling Simple Archive Generator allows Stored XSS.This issue affects Simple Archive Generator: from n/a through 5.2.

CVSS3: 7.1
0%
Низкий
8 месяцев назад
github логотип
GHSA-xgr9-crfp-4qg4

In the Linux kernel, the following vulnerability has been resolved: bpf: avoid holding freeze_mutex during mmap operation We use map->freeze_mutex to prevent races between map_freeze() and memory mapping BPF map contents with writable permissions. The way we naively do this means we'll hold freeze_mutex for entire duration of all the mm and VMA manipulations, which is completely unnecessary. This can potentially also lead to deadlocks, as reported by syzbot in [0]. So, instead, hold freeze_mutex only during writeability checks, bump (proactively) "write active" count for the map, unlock the mutex and proceed with mmap logic. And only if something went wrong during mmap logic, then undo that "write active" counter increment. [0] https://lore.kernel.org/bpf/678dcbc9.050a0220.303755.0066.GAE@google.com/

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xgr9-8q24-v4ph

In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the ASN.1 BER dissector could crash. This was addressed in epan/dissectors/packet-ber.c by ensuring that length values do not exceed the maximum signed integer.

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-xgr9-7593-ff2p

Windows Distributed File System (DFS) Remote Code Execution Vulnerability

CVSS3: 7.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xgr8-wfr6-wmh2

IBM Rational Team Concert 5.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 148615.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xgr8-mrxv-f3p6

Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one workspace to access, delete, or duplicate assets belonging to another workspace by providing only the victim workspace slug and asset ID. The affected endpoints return presigned file URLs and enable destructive or duplicative actions without verifying that the requester is a member of the targeted workspace. This enables cross‑tenant data exposure, data deletion, and persistent exfiltration of files into an attacker‑controlled workspace.

CVSS3: 6.5
0%
Низкий
27 дней назад
github логотип
GHSA-xgr7-jgq3-mhmc

Contract balance not updating correctly after interchain transaction

CVSS3: 7.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-xgr7-3fmq-x97v

H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function debug_wlan_advance.

CVSS3: 9.8
1%
Низкий
почти 4 года назад

Уязвимостей на страницу