Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 361 446

Количество 361 446

github логотип

GHSA-xg3m-c464-j5fh

5 месяцев назад

An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or session structures allows an attacker who can modify the serialized structures to induce memory corruption, leading to arbitrary code execution. This is caused by Incorrect Use of Privileged APIs.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xg3m-8gjx-5q73

больше 4 лет назад

SQL injection vulnerability in browse.asp in A+ Store E-Commerce allows remote attackers to execute arbitrary SQL commands via the ParentID parameter.

EPSS: Низкий
github логотип

GHSA-xg3m-85r2-236x

9 месяцев назад

Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addresses

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-xg3m-83f6-pq94

около 4 лет назад

A path traversal vulnerability in the Juniper Networks SRX and vSRX Series may allow an authenticated J-web user to read sensitive system files. This issue affects Juniper Networks Junos OS on SRX and vSRX Series: 19.3 versions prior to 19.3R2-S6, 19.3R3-S1; 19.4 versions prior to 19.4R2-S4, 19.4R3; 20.1 versions prior to 20.1R1-S4, 20.1R2; 20.2 versions prior to 20.2R1-S3, 20.2R2; This issue does not affect Juniper Networks Junos OS versions prior to 19.3R1.

EPSS: Низкий
github логотип

GHSA-xg3j-xgc2-3jfh

почти 4 года назад

Bypass vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xg3j-x27h-qh5w

больше 4 лет назад

Alien Arena 2007 6.10 and earlier allows remote attackers to cause a denial of service (client disconnect) by sending a client_connect command in a forged packet from the server to a client. NOTE: client IP addresses are available via product-specific queries.

EPSS: Низкий
github логотип

GHSA-xg3j-rjx9-fch2

больше 4 лет назад

Alcatel OmniSwitch 7700/7800 switches running AOS 5.1.1 contains a back door telnet server that was intended for development but not removed before distribution, which allows remote attackers to gain administrative privileges.

EPSS: Низкий
github логотип

GHSA-xg3j-c7q4-f9ph

2 месяца назад

Canonical MicroCeph: path traversal issue in the remote-import AP

EPSS: Низкий
github логотип

GHSA-xg3h-xcrg-r6h9

8 месяцев назад

IceWarp gmaps Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of IceWarp. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of a parameter passed to the gmaps webpage. The issue results from the lack of proper validation of user-supplied data, which can lead to the injection of an arbitrary script. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-25441.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xg3h-r232-6rmw

больше 4 лет назад

Windows Kernel Information Disclosure Vulnerability

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xg3h-q5gf-6gg9

почти 3 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Joakim Ling Remove slug from custom post type plugin <= 1.0.3 versions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xg3h-4ffh-v7h3

около 1 года назад

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 5). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xg3g-rj7r-vm56

больше 1 года назад

Dell Update Package Framework, versions prior to 22.01.02, contain(s) a Local Privilege Escalation Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary remote scripts on the server. Exploitation may lead to a denial of service by an attacker.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-xg3g-pprg-2wqw

больше 4 лет назад

Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integration Broker). Supported versions that are affected are 8.54 and 8.55. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.0 Base Score 6.5 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L).

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-xg3g-f9vj-3chq

больше 4 лет назад

In Zillya! Antivirus 3.0.2230.0, the driver file (zef.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9C40242C.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xg3g-7232-qg4v

больше 4 лет назад

Heap-based buffer overflow in the pnm_get_chunk function for xine 0.99.2, and other packages such as MPlayer that use the same code, allows remote attackers to execute arbitrary code via long PNA_TAG values, a different vulnerability than CVE-2004-1188.

EPSS: Низкий
github логотип

GHSA-xg3f-wmmq-xc35

больше 4 лет назад

The read_new_config_info function in open_utils.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xg3f-ph47-c5jv

4 месяца назад

In the Linux kernel, the following vulnerability has been resolved: misc: ti_fpc202: fix a potential memory leak in probe function Use for_each_child_of_node_scoped() to simplify the code and ensure the device node reference is automatically released when the loop scope ends.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xg3f-6866-fpvf

больше 1 года назад

The Debug Log Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the auto-refresh debug log in all versions up to, and including, 2.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xg3c-5p4v-jf24

около 4 лет назад

In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to stale pointer. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-144351324

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xg3m-c464-j5fh

An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or session structures allows an attacker who can modify the serialized structures to induce memory corruption, leading to arbitrary code execution. This is caused by Incorrect Use of Privileged APIs.

CVSS3: 9.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-xg3m-8gjx-5q73

SQL injection vulnerability in browse.asp in A+ Store E-Commerce allows remote attackers to execute arbitrary SQL commands via the ParentID parameter.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xg3m-85r2-236x

Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addresses

CVSS3: 9.1
1%
Низкий
9 месяцев назад
github логотип
GHSA-xg3m-83f6-pq94

A path traversal vulnerability in the Juniper Networks SRX and vSRX Series may allow an authenticated J-web user to read sensitive system files. This issue affects Juniper Networks Junos OS on SRX and vSRX Series: 19.3 versions prior to 19.3R2-S6, 19.3R3-S1; 19.4 versions prior to 19.4R2-S4, 19.4R3; 20.1 versions prior to 20.1R1-S4, 20.1R2; 20.2 versions prior to 20.2R1-S3, 20.2R2; This issue does not affect Juniper Networks Junos OS versions prior to 19.3R1.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xg3j-xgc2-3jfh

Bypass vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-xg3j-x27h-qh5w

Alien Arena 2007 6.10 and earlier allows remote attackers to cause a denial of service (client disconnect) by sending a client_connect command in a forged packet from the server to a client. NOTE: client IP addresses are available via product-specific queries.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xg3j-rjx9-fch2

Alcatel OmniSwitch 7700/7800 switches running AOS 5.1.1 contains a back door telnet server that was intended for development but not removed before distribution, which allows remote attackers to gain administrative privileges.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-xg3j-c7q4-f9ph

Canonical MicroCeph: path traversal issue in the remote-import AP

0%
Низкий
2 месяца назад
github логотип
GHSA-xg3h-xcrg-r6h9

IceWarp gmaps Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of IceWarp. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of a parameter passed to the gmaps webpage. The issue results from the lack of proper validation of user-supplied data, which can lead to the injection of an arbitrary script. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-25441.

CVSS3: 8.8
1%
Низкий
8 месяцев назад
github логотип
GHSA-xg3h-r232-6rmw

Windows Kernel Information Disclosure Vulnerability

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xg3h-q5gf-6gg9

Cross-Site Request Forgery (CSRF) vulnerability in Joakim Ling Remove slug from custom post type plugin <= 1.0.3 versions.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-xg3h-4ffh-v7h3

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 5). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.

CVSS3: 7.8
0%
Низкий
около 1 года назад
github логотип
GHSA-xg3g-rj7r-vm56

Dell Update Package Framework, versions prior to 22.01.02, contain(s) a Local Privilege Escalation Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary remote scripts on the server. Exploitation may lead to a denial of service by an attacker.

CVSS3: 8.2
0%
Низкий
больше 1 года назад
github логотип
GHSA-xg3g-pprg-2wqw

Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integration Broker). Supported versions that are affected are 8.54 and 8.55. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.0 Base Score 6.5 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L).

CVSS3: 6.5
51%
Средний
больше 4 лет назад
github логотип
GHSA-xg3g-f9vj-3chq

In Zillya! Antivirus 3.0.2230.0, the driver file (zef.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9C40242C.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xg3g-7232-qg4v

Heap-based buffer overflow in the pnm_get_chunk function for xine 0.99.2, and other packages such as MPlayer that use the same code, allows remote attackers to execute arbitrary code via long PNA_TAG values, a different vulnerability than CVE-2004-1188.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-xg3f-wmmq-xc35

The read_new_config_info function in open_utils.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file.

CVSS3: 5.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xg3f-ph47-c5jv

In the Linux kernel, the following vulnerability has been resolved: misc: ti_fpc202: fix a potential memory leak in probe function Use for_each_child_of_node_scoped() to simplify the code and ensure the device node reference is automatically released when the loop scope ends.

CVSS3: 5.5
0%
Низкий
4 месяца назад
github логотип
GHSA-xg3f-6866-fpvf

The Debug Log Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the auto-refresh debug log in all versions up to, and including, 2.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 7.2
0%
Низкий
больше 1 года назад
github логотип
GHSA-xg3c-5p4v-jf24

In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to stale pointer. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-144351324

0%
Низкий
около 4 лет назад

Уязвимостей на страницу