Writeup Exploits

60,918 exploits tracked across all sources.

Sort: Activity Stars
CVE-2023-0799 WRITEUP MEDIUM
libtiff < 4.4.0 - Use-After-Free in tiffcrop
LibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in tools/tiffcrop.c:3701, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit afaabc3e.
CVSS 6.8
CVE-2023-0800 WRITEUP MEDIUM
libtiff < 4.4.0 - Out-of-bounds Write in tiffcrop
LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3502, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 33aee127.
CVSS 6.8
CVE-2023-0800 WRITEUP MEDIUM
libtiff < 4.4.0 - Out-of-bounds Write in tiffcrop
LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3502, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 33aee127.
CVSS 6.8
CVE-2023-0801 WRITEUP MEDIUM
libtiff < 4.4.0 - Out-of-bounds Write in tiffcrop
LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in libtiff/tif_unix.c:368, invoked by tools/tiffcrop.c:2903 and tools/tiffcrop.c:6778, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 33aee127.
CVSS 6.8
CVE-2023-0801 WRITEUP MEDIUM
libtiff < 4.4.0 - Out-of-bounds Write in tiffcrop
LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in libtiff/tif_unix.c:368, invoked by tools/tiffcrop.c:2903 and tools/tiffcrop.c:6778, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 33aee127.
CVSS 6.8
CVE-2023-0802 WRITEUP MEDIUM
libtiff < 4.4.0 - Out-of-bounds Write in tiffcrop
LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3724, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 33aee127.
CVSS 6.8
CVE-2023-0802 WRITEUP MEDIUM
libtiff < 4.4.0 - Out-of-bounds Write in tiffcrop
LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3724, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 33aee127.
CVSS 6.8
CVE-2023-0803 WRITEUP MEDIUM
libtiff < 4.4.0 - Out-of-bounds Write in tiffcrop
LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3516, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 33aee127.
CVSS 6.8
CVE-2023-0803 WRITEUP MEDIUM
libtiff < 4.4.0 - Out-of-bounds Write in tiffcrop
LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3516, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 33aee127.
CVSS 6.8
CVE-2023-0804 WRITEUP MEDIUM
LibTIFF < 4.4.0 - Out-of-bounds Write in tiffcrop
LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3609, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 33aee127.
CVSS 6.8
CVE-2023-0804 WRITEUP MEDIUM
LibTIFF < 4.4.0 - Out-of-bounds Write in tiffcrop
LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3609, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 33aee127.
CVSS 6.8
CVE-2023-0805 WRITEUP MEDIUM
GitLab 15.2-15.9.5, 15.10-15.10.4, 15.11 - Missing Authorization for Banned Group Members
An issue has been discovered in GitLab EE affecting all versions starting from 15.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. A malicious group member may continue to have access to the public projects of a public group even after being banned from the public group by the owner.
CVSS 4.9
CVE-2023-1001 WRITEUP LOW
vxe-table < 3.7.10 - Cross-Site Scripting via inputValue Argument in vxe-textarea
A vulnerability, which was classified as problematic, has been found in xuliangzhan vxe-table up to 3.7.9. This issue affects the function export of the file packages/textarea/src/textarea.js of the component vxe-textarea. The manipulation of the argument inputValue leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 3.7.10 is able to address this issue. The patch is named d70b0e089740b65a22c89c106ebc4627ac48a22d. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-266123.
CVSS 3.5
CVE-2023-1161 WRITEUP MEDIUM
Wireshark 3.6.0-3.6.11 and 4.0.0-4.0.3 - Denial of Service via ISO 15765 and ISO 10681 Dissector
ISO 15765 and ISO 10681 dissector crash in Wireshark 4.0.0 to 4.0.3 and 3.6.0 to 3.6.11 allows denial of service via packet injection or crafted capture file
CVSS 6.3
CVE-2023-1178 WRITEUP MEDIUM
GitLab 8.6-15.9.5, 15.10-15.10.4, 15.11 - File Integrity Compromise via Tag or Release Reference
An issue has been discovered in GitLab CE/EE affecting all versions from 8.6 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. File integrity may be compromised when source code or installation packages are pulled from a tag or from a release containing a ref to another commit.
CVSS 5.7
CVE-2023-1204 WRITEUP MEDIUM
GitLab 10.1-15.10.7, 15.11-15.11.6, 16.0-16.0.1 - Cryptographic Signature Verification Bypass
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.1 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A user could use an unverified email as a public email and commit email by sending a specifically crafted request on user update settings.
CVSS 4.3
CVE-2023-1265 WRITEUP MEDIUM
GitLab <15.9.6-15.11.1 - Info Disclosure
An issue has been discovered in GitLab affecting all versions starting from 11.9 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The condition allows for a privileged attacker, under certain conditions, to obtain session tokens from all users of a GitLab instance.
CVSS 5.4
CVE-2023-1494 WRITEUP MEDIUM
IBOS 4.5.5 - SQL Injection via Emailids Parameter in ApiController.php
A vulnerability classified as critical has been found in IBOS 4.5.5. Affected is an unknown function of the file ApiController.php. The manipulation of the argument emailids leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-223380.
CVSS 6.3
CVE-2023-1501 WRITEUP MEDIUM
RockOA 2.3.2 - Unrestricted Upload of File with Dangerous Type via fileid Argument
A vulnerability, which was classified as critical, was found in RockOA 2.3.2. This affects the function runAction of the file acloudCosAction.php.SQL. The manipulation of the argument fileid leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-223401 was assigned to this vulnerability.
CVSS 6.3
CVE-2023-1684 WRITEUP MEDIUM
HadSky 7.7.16 - Unrestricted Upload
A vulnerability was found in HadSky 7.7.16. It has been classified as problematic. This affects an unknown part of the file upload/index.php?c=app&a=superadmin:index. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-224241 was assigned to this vulnerability.
CVSS 4.7
CVE-2023-1685 WRITEUP MEDIUM
HadSky < 7.11.8 - Remote Command Injection via Installation Interface
A vulnerability was found in HadSky up to 7.11.8. It has been declared as critical. This vulnerability affects unknown code of the file /install/index.php of the component Installation Interface. The manipulation leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-224242 is the identifier assigned to this vulnerability.
CVSS 6.3
CVE-2023-1685 WRITEUP MEDIUM
HadSky < 7.11.8 - Remote Command Injection via Installation Interface
A vulnerability was found in HadSky up to 7.11.8. It has been declared as critical. This vulnerability affects unknown code of the file /install/index.php of the component Installation Interface. The manipulation leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-224242 is the identifier assigned to this vulnerability.
CVSS 6.3
CVE-2023-1739 WRITEUP MEDIUM
SourceCodester Simple and Beautiful Shopping Cart System 1.0 - Unre...
A vulnerability was found in SourceCodester Simple and Beautiful Shopping Cart System 1.0 and classified as critical. This issue affects some unknown processing of the file upload.php. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-224627.
CVSS 6.3
CVE-2023-1742 WRITEUP MEDIUM
IBOS < 4.5.5 - SQL Injection via Report Search API
A vulnerability was found in IBOS 4.5.5. It has been rated as critical. Affected by this issue is some unknown functionality of the file /?r=report/api/getlist of the component Report Search. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-224630 is the identifier assigned to this vulnerability.
CVSS 6.3
CVE-2023-1744 WRITEUP MEDIUM
ibos < 4.5.5 - Unrestricted File Upload via htaccess Handler
A vulnerability classified as critical was found in IBOS 4.5.5. This vulnerability affects unknown code of the component htaccess Handler. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-224632.
CVSS 6.3