9 results (0.007 seconds)

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

16 Jan 2025 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Login Watchdog allows Stored XSS. This issue affects Login Watchdog: from n/a through 1.0.4. The Login Watchdog plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they c... • https://patchstack.com/database/wordpress/plugin/login-watchdog/vulnerability/wordpress-login-watchdog-plugin-1-0-4-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 0

23 Apr 2024 — Watchdog Antivirus v1.6.415 is vulnerable to a Denial of Service vulnerability by triggering the 0x80002014 IOCTL code of the wsdk-driver.sys driver. Watchdog Antivirus v1.6.415 es afectado por una vulnerabilidad de denegación de servicio al activar el código IOCTL 0x80002014 del controlador wsdk-driver.sys. • https://fluidattacks.com/advisories/cole • CWE-476: NULL Pointer Dereference •

CVSS: 6.7EPSS: 1%CPEs: 2EXPL: 1

13 Jul 2023 — Certain Zemana products are vulnerable to Arbitrary code injection. This affects Watchdog Anti-Malware 4.1.422 and Zemana AntiMalware 3.2.28. • https://github.com/ReCryptLLC/CVE-2022-42045 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVSS: 7.1EPSS: 0%CPEs: 1EXPL: 1

17 Mar 2023 — A vulnerability was found in Watchdog Anti-Virus 1.4.214.0. It has been rated as critical. Affected by this issue is the function 0x80002008 in the library wsdk-driver.sys of the component IoControlCode Handler. The manipulation leads to improper access controls. Attacking locally is a requirement. • https://drive.google.com/file/d/1ivMk1uVAvPCCAxqiD2BW9gD1TsktQkpi/view • CWE-284: Improper Access Control •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 1

17 Mar 2023 — A vulnerability classified as problematic was found in Watchdog Anti-Virus 1.4.214.0. Affected by this vulnerability is the function 0x80002004/0x80002008 in the library wsdk-driver.sys of the component IoControlCode Handler. The manipulation leads to denial of service. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. • https://drive.google.com/file/d/1zjK_DMjHz41RMpfa0iLQ4GXKQwEr4z2T/view • CWE-404: Improper Resource Shutdown or Release CWE-476: NULL Pointer Dereference •

CVSS: 6.8EPSS: 0%CPEs: 1EXPL: 1

04 Nov 2022 — Incorrect access control in the anti-virus driver wsdkd.sys of Watchdog Antivirus v1.4.158 allows attackers to write arbitrary files. El control de acceso incorrecto en el controlador antivirus wsdkd.sys de Watchdog Antivirus v1.4.158 permite a los atacantes escribir archivos arbitrarios. • https://gist.github.com/420SmokeBigWeedHackBadDrivers/53de9ff97d95fc3e79307345fddb0a30 •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 1

16 Sep 2022 — Incorrect access control in Watchdog Anti-Virus v1.4.158 allows attackers to perform a DLL hijacking attack and execute arbitrary code via a crafted binary. El control de acceso incorrecto en Watchdog Anti-Virus versión v1.4.158, permite a atacantes llevar a cabo un ataque de secuestro de DLL y ejecutar código arbitrario por medio de un binario diseñado • https://gist.github.com/dru1d-foofus/835423de77c3522d53b9e7bdf5a28dfe •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 0

15 Jun 2015 — Cross-site request forgery (CSRF) vulnerability in the Watchdog Aggregator module for Drupal allows remote attackers to hijack the authentication of administrators for requests that enable or disable monitoring sites via unspecified vectors. Vulnerabilidad de CSRF en el módulo Watchdog Aggregator para Drupal permite a atacantes remotos secuestrar la autenticación de administradores para solicitudes que habilitan o deshabilitan sitios de monitorización a través de vectores no especificados. • http://www.openwall.com/lists/oss-security/2015/04/25/6 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

13 Apr 2015 — Buffer overflow in das_watchdog 0.9.0 allows local users to execute arbitrary code with root privileges via a large string in the XAUTHORITY environment variable. Desbordamiento de buffer en das_watchdog 0.9.0 permite a usuarios locales ejecutar código arbitrario con privilegios root a través de una cadena grande en la variable de entorno XAUTHORITY. Adam Sampson discovered a buffer overflow in the handling of the XAUTHORITY environment variable in das-watchdog, a watchdog daemon to ensure a realtime proces... • http://www.debian.org/security/2015/dsa-3221 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •