Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 360 872

Количество 360 872

github логотип

GHSA-xg83-5qc9-wgf8

больше 4 лет назад

XSS exists in WUZHI CMS 2.0 via the index.php v or f parameter.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xg82-h5j4-q6gx

больше 4 лет назад

Multiple untrusted search path vulnerabilities in SUSE Linux 9.3 and 10.0, and possibly other distributions, cause the working directory to be added to LD_LIBRARY_PATH, which might allow local users to execute arbitrary code via (1) beagle, (2) tomboy, or (3) blam. NOTE: in August 2007, the tomboy vector was reported for other distributions.

EPSS: Низкий
github логотип

GHSA-xg82-2hrv-hf64

3 месяца назад

Snipe-IT has insecure permissions in file uploads

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xg7x-r7p4-phg6

больше 4 лет назад

c32web.exe in McMurtrey/Whitaker Cart32 before 6.4 allows remote attackers to read arbitrary files via the ImageName parameter in a GetImage action, by appending a NULL byte (%00) sequence followed by an image file extension, as demonstrated by a request for a ".txt%00.gif" file. NOTE: this might be a directory traversal vulnerability.

EPSS: Низкий
github логотип

GHSA-xg7x-2fjw-7652

больше 4 лет назад

The PlayMemories Online (aka jp.co.sony.tablet.PersonalSpace) application 4.2.0.05070 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-xg7w-gqvr-cp6v

больше 4 лет назад

Directory traversal vulnerability in compose.pl in @Mail 4.3 and earlier for Windows allows remote attackers to upload arbitrary files to arbitrary locations via a .. (dot dot) in the unique parameter.

EPSS: Низкий
github логотип

GHSA-xg7w-9w3p-gqx3

больше 4 лет назад

The Keybase Clients for macOS and Windows before version 5.9.0 fails to properly remove exploded messages initiated by a user. This can occur if the receiving user switches to a non-chat feature and places the host in a sleep state before the sending user explodes the messages. This could lead to disclosure of sensitive information which was meant to be deleted from a user’s filesystem.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-xg7v-rm2m-8m9c

больше 4 лет назад

A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37208566.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xg7r-h2rr-v552

больше 4 лет назад

The AXIS webapp in deploy-tomcat/axis in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2 and 7.2.0 through 7.2.1.4 allows remote attackers to obtain sensitive configuration information via a direct request, as demonstrated by happyaxis.jsp. IBM X-Force ID: 84354.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xg7r-7865-v6c7

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix data corruption in dsync block recovery for small block sizes The helper function nilfs_recovery_copy_block() of nilfs_recovery_dsync_blocks(), which recovers data from logs created by data sync writes during a mount after an unclean shutdown, incorrectly calculates the on-page offset when copying repair data to the file's page cache. In environments where the block size is smaller than the page size, this flaw can cause data corruption and leak uninitialized memory bytes during the recovery process. Fix these issues by correcting this byte offset calculation on the page.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xg7r-4m7r-jpfv

около 1 года назад

Rejected reason: Not used

EPSS: Низкий
github логотип

GHSA-xg7p-g635-vrg9

около 4 лет назад

An issue was discovered in JerryScript 2.4.0. There is a heap-use-after-free in ecma_bytecode_ref in ecma-helpers.c file.

EPSS: Низкий
github логотип

GHSA-xg7p-78j8-hfrp

больше 1 года назад

This issue was addressed through improved state management. This issue is fixed in visionOS 2.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. Password autofill may fill in passwords after failing authentication.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xg7m-xvh7-g9px

больше 1 года назад

A vulnerability was found in Tenda A15 15.13.07.09/15.13.07.13. It has been classified as critical. This affects an unknown part of the file /goform/multimodalAdd of the component HTTP POST Request Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xg7m-wjrf-p6rf

около 4 лет назад

Insufficient validation of untrusted input in downloads in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass download restrictions via a crafted HTML page.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xg7m-r4cx-cq66

больше 4 лет назад

Stack-based buffer overflow in Microsoft Windows Media Player 9 and 10 allows remote attackers to execute arbitrary code via a PNG image with a large chunk size.

EPSS: Средний
github логотип

GHSA-xg7j-vjpx-w8rq

около 4 лет назад

The Skaut bazar WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] in the ~/skaut-bazar.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.3.2.

EPSS: Низкий
github логотип

GHSA-xg7j-mpg2-2hvw

почти 4 года назад

A vulnerability was found in Axiomatic Bento4. It has been rated as problematic. This issue affects the function AP4_StsdAtom of the file Ap4StsdAtom.cpp of the component MP4fragment. The manipulation leads to null pointer dereference. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-212003.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xg7j-j7fr-8hhf

больше 1 года назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themifyme Themify Event Post allows PHP Local File Inclusion. This issue affects Themify Event Post: from n/a through 1.3.2.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xg7j-hjr6-42q2

около 4 лет назад

Improper Access Control vulnerability in the application authentication and authorization of Hitachi Energy Retail Operations, Counterparty Settlement and Billing (CSB) allows an attacker to execute a modified signed Java Applet JAR file. A successful exploitation may lead to data extraction or modification of data inside the application. This issue affects: Hitachi Energy Retail Operations 5.7.3 and prior versions. Hitachi Energy Counterparty Settlement and Billing (CSB) 5.7.3 prior versions.

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xg83-5qc9-wgf8

XSS exists in WUZHI CMS 2.0 via the index.php v or f parameter.

CVSS3: 6.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xg82-h5j4-q6gx

Multiple untrusted search path vulnerabilities in SUSE Linux 9.3 and 10.0, and possibly other distributions, cause the working directory to be added to LD_LIBRARY_PATH, which might allow local users to execute arbitrary code via (1) beagle, (2) tomboy, or (3) blam. NOTE: in August 2007, the tomboy vector was reported for other distributions.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xg82-2hrv-hf64

Snipe-IT has insecure permissions in file uploads

CVSS3: 9.8
0%
Низкий
3 месяца назад
github логотип
GHSA-xg7x-r7p4-phg6

c32web.exe in McMurtrey/Whitaker Cart32 before 6.4 allows remote attackers to read arbitrary files via the ImageName parameter in a GetImage action, by appending a NULL byte (%00) sequence followed by an image file extension, as demonstrated by a request for a ".txt%00.gif" file. NOTE: this might be a directory traversal vulnerability.

9%
Низкий
больше 4 лет назад
github логотип
GHSA-xg7x-2fjw-7652

The PlayMemories Online (aka jp.co.sony.tablet.PersonalSpace) application 4.2.0.05070 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xg7w-gqvr-cp6v

Directory traversal vulnerability in compose.pl in @Mail 4.3 and earlier for Windows allows remote attackers to upload arbitrary files to arbitrary locations via a .. (dot dot) in the unique parameter.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xg7w-9w3p-gqx3

The Keybase Clients for macOS and Windows before version 5.9.0 fails to properly remove exploded messages initiated by a user. This can occur if the receiving user switches to a non-chat feature and places the host in a sleep state before the sending user explodes the messages. This could lead to disclosure of sensitive information which was meant to be deleted from a user’s filesystem.

CVSS3: 3.7
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xg7v-rm2m-8m9c

A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37208566.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xg7r-h2rr-v552

The AXIS webapp in deploy-tomcat/axis in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2 and 7.2.0 through 7.2.1.4 allows remote attackers to obtain sensitive configuration information via a direct request, as demonstrated by happyaxis.jsp. IBM X-Force ID: 84354.

CVSS3: 5.3
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xg7r-7865-v6c7

In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix data corruption in dsync block recovery for small block sizes The helper function nilfs_recovery_copy_block() of nilfs_recovery_dsync_blocks(), which recovers data from logs created by data sync writes during a mount after an unclean shutdown, incorrectly calculates the on-page offset when copying repair data to the file's page cache. In environments where the block size is smaller than the page size, this flaw can cause data corruption and leak uninitialized memory bytes during the recovery process. Fix these issues by correcting this byte offset calculation on the page.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xg7r-4m7r-jpfv

Rejected reason: Not used

около 1 года назад
github логотип
GHSA-xg7p-g635-vrg9

An issue was discovered in JerryScript 2.4.0. There is a heap-use-after-free in ecma_bytecode_ref in ecma-helpers.c file.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xg7p-78j8-hfrp

This issue was addressed through improved state management. This issue is fixed in visionOS 2.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. Password autofill may fill in passwords after failing authentication.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-xg7m-xvh7-g9px

A vulnerability was found in Tenda A15 15.13.07.09/15.13.07.13. It has been classified as critical. This affects an unknown part of the file /goform/multimodalAdd of the component HTTP POST Request Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
5%
Низкий
больше 1 года назад
github логотип
GHSA-xg7m-wjrf-p6rf

Insufficient validation of untrusted input in downloads in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass download restrictions via a crafted HTML page.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-xg7m-r4cx-cq66

Stack-based buffer overflow in Microsoft Windows Media Player 9 and 10 allows remote attackers to execute arbitrary code via a PNG image with a large chunk size.

49%
Средний
больше 4 лет назад
github логотип
GHSA-xg7j-vjpx-w8rq

The Skaut bazar WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] in the ~/skaut-bazar.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.3.2.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xg7j-mpg2-2hvw

A vulnerability was found in Axiomatic Bento4. It has been rated as problematic. This issue affects the function AP4_StsdAtom of the file Ap4StsdAtom.cpp of the component MP4fragment. The manipulation leads to null pointer dereference. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-212003.

CVSS3: 5.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-xg7j-j7fr-8hhf

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themifyme Themify Event Post allows PHP Local File Inclusion. This issue affects Themify Event Post: from n/a through 1.3.2.

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-xg7j-hjr6-42q2

Improper Access Control vulnerability in the application authentication and authorization of Hitachi Energy Retail Operations, Counterparty Settlement and Billing (CSB) allows an attacker to execute a modified signed Java Applet JAR file. A successful exploitation may lead to data extraction or modification of data inside the application. This issue affects: Hitachi Energy Retail Operations 5.7.3 and prior versions. Hitachi Energy Counterparty Settlement and Billing (CSB) 5.7.3 prior versions.

CVSS3: 7.1
0%
Низкий
около 4 лет назад

Уязвимостей на страницу