Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 360 872

Количество 360 872

github логотип

GHSA-xg5r-fw9v-6664

около 4 лет назад

In handleAppLaunch of AppLaunchActivity.java, there is a possible arbitrary activity launch due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-174870704

EPSS: Низкий
github логотип

GHSA-xg5r-8j97-2wrj

больше 7 лет назад

Directory Traversal in restafary

EPSS: Низкий
github логотип

GHSA-xg5r-2pq7-4cq4

больше 4 лет назад

Microsoft Office 2016 for Mac allows an attacker to send a specially crafted email attachment to a user in an attempt to launch a social engineering attack, such as phishing, due to how Outlook for Mac displays encoded email addresses, aka "Spoofing Vulnerability in Microsoft Office for Mac."

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xg5q-q7c3-jvmv

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: char: xillybus: Check USB endpoints when probing device Ensure, as the driver probes the device, that all endpoints that the driver may attempt to access exist and are of the correct type. All XillyUSB devices must have a Bulk IN and Bulk OUT endpoint at address 1. This is verified in xillyusb_setup_base_eps(). On top of that, a XillyUSB device may have additional Bulk OUT endpoints. The information about these endpoints' addresses is deduced from a data structure (the IDT) that the driver fetches from the device while probing it. These endpoints are checked in setup_channels(). A XillyUSB device never has more than one IN endpoint, as all data towards the host is multiplexed in this single Bulk IN endpoint. This is why setup_channels() only checks OUT endpoints.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xg5q-c6fr-w959

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the Temporary Invitation module 5.x before 5.x-2.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via the Name field in an invitation.

EPSS: Низкий
github логотип

GHSA-xg5q-78jw-568v

около 4 лет назад

Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

EPSS: Низкий
github логотип

GHSA-xg5p-wxx4-rmwx

больше 4 лет назад

.NET Framework Denial of Service Vulnerability.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-xg5p-vw49-54vg

больше 4 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php and (2) datePicker.php in Easy PHP Calendar 6.x and 7.x before 7.0.13 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xg5p-8wg5-rhxm

больше 2 лет назад

Phone information disclosure vulnerability

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xg5m-r959-p6hh

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2011-4511.

EPSS: Низкий
github логотип

GHSA-xg5j-69w2-9h88

около 2 лет назад

The پلاگین پرداخت دلخواه WordPress plugin through 2.9.8 does not have CSRF check in place when resetting its form fields, which could allow attackers to make a logged in admin perform such action via a CSRF attack

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xg5j-3w2m-6rhx

больше 2 лет назад

The 10Web Booster WordPress plugin before 2.24.18 does not validate the option name given to some AJAX actions, allowing unauthenticated users to delete arbitrary options from the database, leading to denial of service.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xg5j-2463-7x9w

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in Nuked-Klan 1.7 allows remote attackers to inject arbitrary web script or HTML via the (1) Search module, (2) certain edit fields in Guestbook, (3) the title in the Forum module, and (4) Textbox.

EPSS: Низкий
github логотип

GHSA-xg5g-x87g-4w37

больше 4 лет назад

Unspecified vulnerability in the Management Console in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.0 before 6.2.0.9 has unknown impact and attack vectors, aka APAR IV03050.

EPSS: Низкий
github логотип

GHSA-xg5g-26x8-cvf4

26 дней назад

Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-xg5f-wh7f-vmrc

больше 4 лет назад

The Control and Provisioning of Wireless Access Points (CAPWAP) protocol implementation on Cisco Wireless LAN Controller (WLC) devices allows remote attackers to cause a denial of service via a crafted CAPWAP packet that triggers a buffer over-read, aka Bug ID CSCuh81880.

EPSS: Низкий
github логотип

GHSA-xg5f-vpcf-7chx

около 2 лет назад

all the Toshiba printers have programs containing a hardcoded key used to encrypt files. An attacker can decrypt the encrypted files using the hardcoded key. Insecure algorithm is used for the encryption. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score listed in the "Base Score" of this vulnerability. For detail on related other vulnerabilities, please ask to the below contact point. https://www.toshibatec.com/contacts/products/ As for the affected products/models/versions, see the reference URL.

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-xg5f-prh7-r529

около 4 лет назад

An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server allows for cross-origin requests from any domain, and the WebSocket server lacks authorization control. Any web site can execute JavaScript code (that accesses a user's data) via cross-origin requests.

EPSS: Низкий
github логотип

GHSA-xg5f-49f6-c8xv

около 4 лет назад

HP has identified a security vulnerability with the I.R.I.S. OCR (Optical Character Recognition) software available with HP PageWide and OfficeJet printer software installations that could potentially allow unauthorized local code execution.

EPSS: Низкий
github логотип

GHSA-xg5f-3339-xm6p

больше 4 лет назад

A denial of service vulnerability in Setup Wizard could allow a local malicious application to temporarily block access to an affected device. This issue is rated as Moderate because it may require a factory reset to repair the device. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1. Android ID: A-31554152.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xg5r-fw9v-6664

In handleAppLaunch of AppLaunchActivity.java, there is a possible arbitrary activity launch due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-174870704

0%
Низкий
около 4 лет назад
github логотип
GHSA-xg5r-8j97-2wrj

Directory Traversal in restafary

1%
Низкий
больше 7 лет назад
github логотип
GHSA-xg5r-2pq7-4cq4

Microsoft Office 2016 for Mac allows an attacker to send a specially crafted email attachment to a user in an attempt to launch a social engineering attack, such as phishing, due to how Outlook for Mac displays encoded email addresses, aka "Spoofing Vulnerability in Microsoft Office for Mac."

CVSS3: 6.5
6%
Низкий
больше 4 лет назад
github логотип
GHSA-xg5q-q7c3-jvmv

In the Linux kernel, the following vulnerability has been resolved: char: xillybus: Check USB endpoints when probing device Ensure, as the driver probes the device, that all endpoints that the driver may attempt to access exist and are of the correct type. All XillyUSB devices must have a Bulk IN and Bulk OUT endpoint at address 1. This is verified in xillyusb_setup_base_eps(). On top of that, a XillyUSB device may have additional Bulk OUT endpoints. The information about these endpoints' addresses is deduced from a data structure (the IDT) that the driver fetches from the device while probing it. These endpoints are checked in setup_channels(). A XillyUSB device never has more than one IN endpoint, as all data towards the host is multiplexed in this single Bulk IN endpoint. This is why setup_channels() only checks OUT endpoints.

CVSS3: 5.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-xg5q-c6fr-w959

Cross-site scripting (XSS) vulnerability in the Temporary Invitation module 5.x before 5.x-2.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via the Name field in an invitation.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xg5q-78jw-568v

Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

5%
Низкий
около 4 лет назад
github логотип
GHSA-xg5p-wxx4-rmwx

.NET Framework Denial of Service Vulnerability.

CVSS3: 3.3
3%
Низкий
больше 4 лет назад
github логотип
GHSA-xg5p-vw49-54vg

Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php and (2) datePicker.php in Easy PHP Calendar 6.x and 7.x before 7.0.13 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xg5p-8wg5-rhxm

Phone information disclosure vulnerability

CVSS3: 5.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xg5m-r959-p6hh

Cross-site scripting (XSS) vulnerability in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2011-4511.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xg5j-69w2-9h88

The پلاگین پرداخت دلخواه WordPress plugin through 2.9.8 does not have CSRF check in place when resetting its form fields, which could allow attackers to make a logged in admin perform such action via a CSRF attack

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-xg5j-3w2m-6rhx

The 10Web Booster WordPress plugin before 2.24.18 does not validate the option name given to some AJAX actions, allowing unauthenticated users to delete arbitrary options from the database, leading to denial of service.

CVSS3: 9.1
3%
Низкий
больше 2 лет назад
github логотип
GHSA-xg5j-2463-7x9w

Cross-site scripting (XSS) vulnerability in Nuked-Klan 1.7 allows remote attackers to inject arbitrary web script or HTML via the (1) Search module, (2) certain edit fields in Guestbook, (3) the title in the Forum module, and (4) Textbox.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xg5g-x87g-4w37

Unspecified vulnerability in the Management Console in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.0 before 6.2.0.9 has unknown impact and attack vectors, aka APAR IV03050.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xg5g-26x8-cvf4

Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution

CVSS3: 8.5
26 дней назад
github логотип
GHSA-xg5f-wh7f-vmrc

The Control and Provisioning of Wireless Access Points (CAPWAP) protocol implementation on Cisco Wireless LAN Controller (WLC) devices allows remote attackers to cause a denial of service via a crafted CAPWAP packet that triggers a buffer over-read, aka Bug ID CSCuh81880.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xg5f-vpcf-7chx

all the Toshiba printers have programs containing a hardcoded key used to encrypt files. An attacker can decrypt the encrypted files using the hardcoded key. Insecure algorithm is used for the encryption. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score listed in the "Base Score" of this vulnerability. For detail on related other vulnerabilities, please ask to the below contact point. https://www.toshibatec.com/contacts/products/ As for the affected products/models/versions, see the reference URL.

CVSS3: 6.2
0%
Низкий
около 2 лет назад
github логотип
GHSA-xg5f-prh7-r529

An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server allows for cross-origin requests from any domain, and the WebSocket server lacks authorization control. Any web site can execute JavaScript code (that accesses a user's data) via cross-origin requests.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xg5f-49f6-c8xv

HP has identified a security vulnerability with the I.R.I.S. OCR (Optical Character Recognition) software available with HP PageWide and OfficeJet printer software installations that could potentially allow unauthorized local code execution.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xg5f-3339-xm6p

A denial of service vulnerability in Setup Wizard could allow a local malicious application to temporarily block access to an affected device. This issue is rated as Moderate because it may require a factory reset to repair the device. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1. Android ID: A-31554152.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу