ARPSyndicate - Cyber & Open Source Intelligence
463 subscribers
31 photos
1 video
1 file
4.61K links
A Global Cyber Intelligence Company with hyperspecialization in Information Discovery, Shadow IT & Vulnerability Intelligence.

A.R.P. Syndicate [https://arpsyndicate.io/pricing.html]
Download Telegram
#ExploitObserverAlert

CVE-2022-2081

DESCRIPTION: Exploit Observer has 1 entries related to CVE-2022-2081. A vulnerability exists in the HCI Modbus TCP function included in the product versions listed above. If the HCI Modbus TCP is enabled and configured, an attacker could exploit the vulnerability by sending a specially crafted message to the RTU500 in a high rate, causing the targeted RTU500 CMU to reboot. The vulnerability is caused by a lack of flood control which eventually if exploited causes an internal stack overflow in the HCI Modbus TCP function.
#ExploitObserverAlert

CVE-2023-28502

DESCRIPTION: Exploit Observer has 5 entries related to CVE-2023-28502. Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow in the "udadmin" service that can lead to remote code execution as the root user.

FIRST-EPSS: 0.192980000
NVD-IS: 5.9
NVD-ES: 3.9
#ExploitObserverAlert

CVE-2023-49665

DESCRIPTION: Exploit Observer has 2 entries related to CVE-2023-49665. Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'quantity[]' parameter of the submit_delivery_list.php resource does not validate the characters received and they are sent unfiltered to the database.

NVD-IS: 5.9
NVD-ES: 3.9
#ExploitObserverAlert

CVE-2023-52267

DESCRIPTION: Exploit Observer has 4 entries related to CVE-2023-52267. ehttp 1.0.6 before 17405b9 has a simple_log.cpp _log out-of-bounds-read during error logging for long strings.

FIRST-EPSS: 0.000430000
#ExploitObserverAlert

CVE-2023-40084

DESCRIPTION: Exploit Observer has 3 entries related to CVE-2023-40084. In run of MDnsSdListener.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

FIRST-EPSS: 0.000420000
NVD-IS: 5.9
NVD-ES: 1.8
#ExploitObserverAlert

CVE-2017-12557

DESCRIPTION: Exploit Observer has 10 entries related to CVE-2017-12557. A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found.

FIRST-EPSS: 0.913440000
NVD-IS: 5.9
NVD-ES: 3.9
#ExploitObserverAlert

CVE-2018-19052

DESCRIPTION: Exploit Observer has 6 entries related to CVE-2018-19052. An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single directory above an alias target, with a specific mod_alias configuration where the matched alias lacks a trailing '/' character, but the alias target filesystem path does have a trailing '/' character.

FIRST-EPSS: 0.004420000
NVD-IS: 3.6
NVD-ES: 3.9
#ExploitObserverAlert

CVE-2016-1997

DESCRIPTION: Exploit Observer has 6 entries related to CVE-2016-1997. HPE Operations Orchestration 10.x before 10.51 and Operations Orchestration content before 1.7.0 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.

FIRST-EPSS: 0.003240000
NVD-IS: 5.9
NVD-ES: 3.9
#ExploitObserverAlert

CVE-2023-3726

DESCRIPTION: Exploit Observer has 2 entries related to CVE-2023-3726. OCSInventory allow stored email template with special characters that lead to a Stored cross-site Scripting.

NVD-IS: 3.6
NVD-ES: 1.2
#ExploitObserverAlert

CVE-2023-6992

DESCRIPTION: Exploit Observer has 2 entries related to CVE-2023-6992. Cloudflare version of zlib library was found to be vulnerable to memory corruption issues affecting the deflation algorithm implementation (deflate.c). The issues resulted from improper input validation and heap-based buffer overflow. A local attacker could exploit the problem during compression using a crafted malicious file potentially leading to denial of service of the software. Patches: The issue has been patched in commit 8352d10 https://github.com/cloudflare/zlib/commit/8352d108c05db1bdc5ac3bdf834dad641694c13c . The upstream repository is not affected.
#ExploitObserverAlert

CVE-2020-11110

DESCRIPTION: Exploit Observer has 10 entries related to CVE-2020-11110. Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot.

FIRST-EPSS: 0.005120000
NVD-IS: 2.7
NVD-ES: 2.3
#ExploitObserverAlert

CVE-2023-34327

DESCRIPTION: Exploit Observer has 1 entries related to CVE-2023-34327.
#ExploitObserverAlert

CVE-2016-10750

DESCRIPTION: Exploit Observer has 7 entries related to CVE-2016-10750. In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization. If an attacker can reach a listening Hazelcast instance with a crafted JoinRequest, and vulnerable classes exist in the classpath, the attacker can run arbitrary code.

FIRST-EPSS: 0.026100000
NVD-IS: 5.9
NVD-ES: 2.2
#ExploitObserverAlert

CVE-2016-2000

DESCRIPTION: Exploit Observer has 5 entries related to CVE-2016-2000. HPE Asset Manager 9.40, 9.41, and 9.50 and Asset Manager CloudSystem Chargeback 9.40 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

FIRST-EPSS: 0.003240000
NVD-IS: 5.9
NVD-ES: 3.9
#ExploitObserverAlert

CVE-2021-26914

DESCRIPTION: Exploit Observer has 7 entries related to CVE-2021-26914. NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in MvcUtil valueStringToObject.

FIRST-EPSS: 0.634780000
NVD-IS: 5.9
NVD-ES: 2.2
#ExploitObserverAlert

CVE-2023-28503

DESCRIPTION: Exploit Observer has 4 entries related to CVE-2023-28503. Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability, where a special username with a deterministic password can be leveraged to bypass authentication checks and execute OS commands as the root user.

FIRST-EPSS: 0.015220000
NVD-IS: 5.9
NVD-ES: 3.9
#ExploitObserverAlert

CVE-2017-15693

DESCRIPTION: Exploit Observer has 5 entries related to CVE-2017-15693. In Apache Geode before v1.4.0, the Geode server stores application objects in serialized form. Certain cluster operations and API invocations cause these objects to be deserialized. A user with DATA:WRITE access to the cluster may be able to cause remote code execution if certain classes are present on the classpath.

FIRST-EPSS: 0.010930000
NVD-IS: 5.9
NVD-ES: 1.6
#ExploitObserverAlert

CVE-2020-36254

DESCRIPTION: Exploit Observer has 4 entries related to CVE-2020-36254. scp.c in Dropbear before 2020.79 mishandles the filename of . or an empty filename, a related issue to CVE-2018-20685.

FIRST-EPSS: 0.002220000
NVD-IS: 5.9
NVD-ES: 2.2
#ExploitObserverAlert

CVE-2016-9498

DESCRIPTION: Exploit Observer has 8 entries related to CVE-2016-9498. ManageEngine Applications Manager 12 and 13 before build 13200, allows unserialization of unsafe Java objects. The vulnerability can be exploited by remote user without authentication and it allows to execute remote code compromising the application as well as the operating system. As Application Manager's RMI registry is running with privileges of system administrator, by exploiting this vulnerability an attacker gains highest privileges on the underlying operating system.

FIRST-EPSS: 0.023560000
NVD-IS: 5.9
NVD-ES: 3.9
#ExploitObserverAlert

CVE-2018-15381

DESCRIPTION: Exploit Observer has 6 entries related to CVE-2018-15381. A Java deserialization vulnerability in Cisco Unity Express (CUE) could allow an unauthenticated, remote attacker to execute arbitrary shell commands with the privileges of the root user. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a malicious serialized Java object to the listening Java Remote Method Invocation (RMI) service. A successful exploit could allow the attacker to execute arbitrary commands on the device with root privileges.

FIRST-EPSS: 0.885110000
NVD-IS: 5.9
NVD-ES: 3.9
#ExploitObserverAlert

CVE-2021-40367

DESCRIPTION: Exploit Observer has 1 entries related to CVE-2021-40367. A vulnerability has been identified in syngo fastView (All versions). The affected application lacks proper validation of user-supplied data when parsing DICOM files. This could result in an out-of-bounds write past the end of an allocated structure. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-15097)

NVD-IS: 5.9
NVD-ES: 1.8