Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 374 825

Количество 374 825

github логотип

GHSA-xx33-73cr-ffp7

больше 4 лет назад

vmware-mount in VMware Workstation 8.x and 9.x and VMware Player 4.x and 5.x, on systems based on Debian GNU/Linux, allows host OS users to gain host OS privileges via a crafted lsb_release binary in a directory in the PATH, related to use of the popen library function.

EPSS: Низкий
github логотип

GHSA-xx33-26x2-m77p

больше 4 лет назад

In sourcecodetester Engineers Online Portal as of 10-21-21, an attacker can manipulate the Host header as seen by the web application and cause the application to behave in unexpected ways. Very often multiple websites are hosted on the same IP address. This is where the Host Header comes in. This header specifies which website should process the HTTP request. The web server uses the value of this header to dispatch the request to the specified website. Each website hosted on the same IP address is called a virtual host. And It's possible to send requests with arbitrary Host Headers to the first virtual host.

EPSS: Низкий
github логотип

GHSA-xx32-ww4m-ppfp

около 1 месяца назад

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formDebugDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host field, resulting in command execution with root privileges.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xx2w-rcmq-q3gc

почти 3 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Ciprian Popescu Block for Font Awesome.This issue affects Block for Font Awesome: from n/a through 1.4.0.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xx2w-hg3f-6w9g

8 месяцев назад

Xmind 2020 contains a cross-site scripting vulnerability that allows attackers to inject malicious payloads into mind mapping files or custom headers. Attackers can craft malicious files with embedded JavaScript that execute system commands when opened, enabling remote code execution through mouse interactions or file opening.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xx2v-j2rm-5c42

больше 2 лет назад

TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanIp parameter’ of the setLanConfig interface of the cstecgi .cgi.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xx2v-hw92-qxmx

4 месяца назад

Integer overflow in Fonts in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xx2r-xrgj-fm3f

больше 2 лет назад

The vulnerability allows a remote attacker to inject arbitrary HTTP response headers or manipulate HTTP response bodies inside a victim’s session via a crafted URL or HTTP request.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xx2r-x7vm-xjjj

больше 4 лет назад

A local authentication restriction bypass vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xx2r-f4xg-6rg7

больше 3 лет назад

Malwarebytes AdwCleaner 8.4.0 runs as Administrator and performs an insecure file delete operation on C:\AdwCleaner\Logs\AdwCleaner_Debug.log in which the target location is user-controllable, allowing a non-admin user to escalate privileges to SYSTEM via a symbolic link.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xx2r-34w4-h84r

больше 4 лет назад

Microsoft Office 2013 and 2013 RT allows remote attackers to discover authentication tokens via a crafted response to a file-open request for an Office file on a web site, as exploited in the wild in 2013, aka "Token Hijacking Vulnerability."

EPSS: Средний
github логотип

GHSA-xx2r-2w7h-qwpc

больше 2 лет назад

Microsoft Defender for IoT Remote Code Execution Vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xx2q-wc64-gcw2

больше 1 года назад

Unrestricted Upload of File with Dangerous Type vulnerability in SoftClever Limited Sync Posts allows Upload a Web Shell to a Web Server. This issue affects Sync Posts: from n/a through 1.0.

CVSS3: 9.9
EPSS: Низкий
github логотип

GHSA-xx2q-9jcq-97m8

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted Cascading Style Sheets (CSS) token sequence in a post.

EPSS: Низкий
github логотип

GHSA-xx2q-9cgc-6xvc

больше 4 лет назад

The (1) v9fs_create and (2) v9fs_lcreate functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow local guest OS privileged users to cause a denial of service (file descriptor or memory consumption) via vectors related to an already in-use fid.

CVSS3: 6
EPSS: Низкий
github логотип

GHSA-xx2q-52g7-vmx5

больше 4 лет назад

Cross-site scripting vulnerability in addevent.php in myEvent 1.x allows remote attackers to inject arbitrary web script or HTML via the event_desc parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: Низкий
github логотип

GHSA-xx2p-7x2v-j239

больше 4 лет назад

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, tvOS 12.3, watchOS 5.2.1. A remote attacker may be able to cause arbitrary code execution.

EPSS: Средний
github логотип

GHSA-xx2p-5w38-cw49

больше 4 лет назад

The scm_send function in the scm layer for Linux kernel 2.4.x up to 2.4.28, and 2.6.x up to 2.6.9, allows local users to cause a denial of service (system hang) via crafted auxiliary messages that are passed to the sendmsg function, which causes a deadlock condition.

EPSS: Низкий
github логотип

GHSA-xx2p-3xq8-p2xm

больше 4 лет назад

The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file that triggers a free of invalid data.

EPSS: Низкий
github логотип

GHSA-xx2h-vg66-mpr3

больше 4 лет назад

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0890, CVE-2019-0891, CVE-2019-0893, CVE-2019-0894, CVE-2019-0895, CVE-2019-0896, CVE-2019-0897, CVE-2019-0898, CVE-2019-0899, CVE-2019-0900, CVE-2019-0901, CVE-2019-0902.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xx33-73cr-ffp7

vmware-mount in VMware Workstation 8.x and 9.x and VMware Player 4.x and 5.x, on systems based on Debian GNU/Linux, allows host OS users to gain host OS privileges via a crafted lsb_release binary in a directory in the PATH, related to use of the popen library function.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-xx33-26x2-m77p

In sourcecodetester Engineers Online Portal as of 10-21-21, an attacker can manipulate the Host header as seen by the web application and cause the application to behave in unexpected ways. Very often multiple websites are hosted on the same IP address. This is where the Host Header comes in. This header specifies which website should process the HTTP request. The web server uses the value of this header to dispatch the request to the specified website. Each website hosted on the same IP address is called a virtual host. And It's possible to send requests with arbitrary Host Headers to the first virtual host.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xx32-ww4m-ppfp

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formDebugDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host field, resulting in command execution with root privileges.

CVSS3: 9.8
2%
Низкий
около 1 месяца назад
github логотип
GHSA-xx2w-rcmq-q3gc

Cross-Site Request Forgery (CSRF) vulnerability in Ciprian Popescu Block for Font Awesome.This issue affects Block for Font Awesome: from n/a through 1.4.0.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-xx2w-hg3f-6w9g

Xmind 2020 contains a cross-site scripting vulnerability that allows attackers to inject malicious payloads into mind mapping files or custom headers. Attackers can craft malicious files with embedded JavaScript that execute system commands when opened, enabling remote code execution through mouse interactions or file opening.

CVSS3: 6.1
0%
Низкий
8 месяцев назад
github логотип
GHSA-xx2v-j2rm-5c42

TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanIp parameter’ of the setLanConfig interface of the cstecgi .cgi.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xx2v-hw92-qxmx

Integer overflow in Fonts in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-xx2r-xrgj-fm3f

The vulnerability allows a remote attacker to inject arbitrary HTTP response headers or manipulate HTTP response bodies inside a victim’s session via a crafted URL or HTTP request.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xx2r-x7vm-xjjj

A local authentication restriction bypass vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xx2r-f4xg-6rg7

Malwarebytes AdwCleaner 8.4.0 runs as Administrator and performs an insecure file delete operation on C:\AdwCleaner\Logs\AdwCleaner_Debug.log in which the target location is user-controllable, allowing a non-admin user to escalate privileges to SYSTEM via a symbolic link.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xx2r-34w4-h84r

Microsoft Office 2013 and 2013 RT allows remote attackers to discover authentication tokens via a crafted response to a file-open request for an Office file on a web site, as exploited in the wild in 2013, aka "Token Hijacking Vulnerability."

13%
Средний
больше 4 лет назад
github логотип
GHSA-xx2r-2w7h-qwpc

Microsoft Defender for IoT Remote Code Execution Vulnerability

CVSS3: 8.8
3%
Низкий
больше 2 лет назад
github логотип
GHSA-xx2q-wc64-gcw2

Unrestricted Upload of File with Dangerous Type vulnerability in SoftClever Limited Sync Posts allows Upload a Web Shell to a Web Server. This issue affects Sync Posts: from n/a through 1.0.

CVSS3: 9.9
1%
Низкий
больше 1 года назад
github логотип
GHSA-xx2q-9jcq-97m8

Cross-site scripting (XSS) vulnerability in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted Cascading Style Sheets (CSS) token sequence in a post.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xx2q-9cgc-6xvc

The (1) v9fs_create and (2) v9fs_lcreate functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow local guest OS privileged users to cause a denial of service (file descriptor or memory consumption) via vectors related to an already in-use fid.

CVSS3: 6
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xx2q-52g7-vmx5

Cross-site scripting vulnerability in addevent.php in myEvent 1.x allows remote attackers to inject arbitrary web script or HTML via the event_desc parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xx2p-7x2v-j239

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, tvOS 12.3, watchOS 5.2.1. A remote attacker may be able to cause arbitrary code execution.

13%
Средний
больше 4 лет назад
github логотип
GHSA-xx2p-5w38-cw49

The scm_send function in the scm layer for Linux kernel 2.4.x up to 2.4.28, and 2.6.x up to 2.6.9, allows local users to cause a denial of service (system hang) via crafted auxiliary messages that are passed to the sendmsg function, which causes a deadlock condition.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xx2p-3xq8-p2xm

The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file that triggers a free of invalid data.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-xx2h-vg66-mpr3

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0890, CVE-2019-0891, CVE-2019-0893, CVE-2019-0894, CVE-2019-0895, CVE-2019-0896, CVE-2019-0897, CVE-2019-0898, CVE-2019-0899, CVE-2019-0900, CVE-2019-0901, CVE-2019-0902.

20%
Средний
больше 4 лет назад

Уязвимостей на страницу