Ben

6 exploits Active since Jul 2015
CVE-2022-29072 NOMISEC HIGH WRITEUP
7-Zip <21.07 - Privilege Escalation
7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>Contents area. This is caused by misconfiguration of 7z.dll and a heap overflow. The command runs in a child process under the 7zFM.exe process. NOTE: multiple third parties have reported that no privilege escalation can occur
8 stars
CVSS 7.8
CVE-2020-36830 WRITEUP MEDIUM WRITEUP
nescalante urlregex <0.5.1 - Info Disclosure
A vulnerability was found in nescalante urlregex up to 0.5.0 and classified as problematic. This issue affects some unknown processing of the file index.js of the component Backtracking. The manipulation leads to inefficient regular expression complexity. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 0.5.1 is able to address this issue. The identifier of the patch is e5a085afe6abfaea1d1a78f54c45af9ef43ca1f9. It is recommended to upgrade the affected component.
CVSS 4.3
CVE-2022-23603 WRITEUP CRITICAL WRITEUP
iTunesRPC-Remastered - Code Injection
iTunesRPC-Remastered is a discord rich presence application for use with iTunes & Apple Music. In code before commit 24f43aa user input is not properly sanitized and code injection is possible. Users are advised to upgrade as soon as is possible. There are no known workarounds for this issue.
CVSS 9.9
CVE-2022-23609 WRITEUP HIGH WRITEUP
Itunesrpc-remastered < 3.1.1 - Path Traversal
iTunesRPC-Remastered is a Discord Rich Presence for iTunes on Windows utility. In affected versions iTunesRPC-Remastered did not properly sanitize user input used to remove files leading to file deletion only limited by the process permissions. Users are advised to upgrade as soon as possible.
CVSS 8.3
CVE-2022-23611 WRITEUP HIGH WRITEUP
Itunesrpc-remastered - OS Command Injection
iTunesRPC-Remastered is a Discord Rich Presence for iTunes on Windows utility. In affected versions iTunesRPC-Remastered did not properly sanitize image file paths leading to OS level command injection. This issue has been patched in commit cdcd48b. Users are advised to upgrade.
CVSS 8.1
CVE-2015-3134 EXPLOITDB text WRITEUP
Adobe Flash Player <13.0.0.302 & 14.x-18.x - Memory Corruption
Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3117, CVE-2015-3123, CVE-2015-3130, CVE-2015-3133, and CVE-2015-4431.