Количество 313 854
Количество 313 854
GHSA-xxrm-5v3v-6c86
The d8s-networking for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-user-agents package. The affected version of d8s-htm is 0.1.0.
GHSA-xxrj-j9r7-g9q6
In wolfSSL before 5.2.0, certificate validation may be bypassed during attempted authentication by a TLS 1.3 client to a TLS 1.3 server. This occurs when the sig_algo field differs between the certificate_verify message and the certificate message.
GHSA-xxrj-3q2m-w65m
The Check Point Gaia Portal's GUI Clients allowed authenticated administrators with permission for the GUI Clients settings to inject a command that would run on the Gaia OS.
GHSA-xxrh-w3xc-mv6f
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability.
GHSA-xxrg-mg63-qfpj
Jenkins AnchorChain Plugin Has a Cross-Site Scripting (XSS) Vulnerability
GHSA-xxrg-cc44-fcvc
A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka 'Microsoft Edge Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0645, CVE-2019-0650.
GHSA-xxrg-2j8c-797x
The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_logout_callback function in versions up to, and including, 4.2.10. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to logout a vctia connected account which would cause a denial of service on the appointment scheduler.
GHSA-xxrf-fc9m-h444
Unrestricted Upload of File with Dangerous Type vulnerability in aidraw I Draw allows Using Malicious Files. This issue affects I Draw: from n/a through 1.0.
GHSA-xxrc-mppm-r6mw
SurveyKing v0.2.0 was discovered to retain users' session cookies after logout, allowing attackers to login to the system and access data using the browser cache when the user exits the application.
GHSA-xxrc-69rc-659v
CuteNews 1.4.1 and possibly other versions allows remote attackers to obtain the installation path via unspecified vectors involving an invalid file path.
GHSA-xxr9-8j75-c68c
pci_change_irq_level in hw/pci/pci.c in QEMU before 5.1.1 has a NULL pointer dereference because pci_get_bus() might not return a valid pointer.
GHSA-xxr9-6j7m-9mvq
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 resets access control settings to the out of the box configuration during Combined Cumulative Fix (CF) installation. This can lead to security miss-configuration of the installation. IBM X-Force ID: 138950.
GHSA-xxr9-37w5-wgwc
stunnel before 5.00, when using fork threading, does not properly update the state of the OpenSSL pseudo-random number generator (PRNG), which causes subsequent children with the same process ID to use the same entropy pool and allows remote attackers to obtain private keys for EC (ECDSA) or DSA certificates.
GHSA-xxr9-34qv-3673
Dell PowerScale OneFS versions 9.1.0.3 and earlier contain a denial of service vulnerability. SmartConnect had an error condition that may be triggered to loop, using CPU and potentially preventing other SmartConnect DNS responses.
GHSA-xxr8-rx47-q5rr
Session fixation vulnerability in Jetbox CMS 2.1 SR1 allows remote attackers to hijack web sessions via a crafted link and the administrator section.
GHSA-xxr8-r558-393h
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_bcode_insert_offset at src/mjs_bcode.c. This vulnerability can lead to a Denial of Service (DoS).
GHSA-xxr8-hvgp-fvhc
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Compress WP Compress – Image Optimizer [All-In-One] allows Reflected XSS.This issue affects WP Compress – Image Optimizer [All-In-One]: from n/a through 6.20.13.
GHSA-xxr8-833v-c7wc
Cross-site Scripting vulnerability in i18n translations helper method
GHSA-xxr7-cchg-fr5v
Memory corruption in WLAN Firmware while parsing receieved GTK Keys in GTK KDE.
GHSA-xxr7-33fp-84c2
Avtec Outpost uses a default cryptographic key that can be used to decrypt sensitive information.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xxrm-5v3v-6c86 The d8s-networking for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-user-agents package. The affected version of d8s-htm is 0.1.0. | CVSS3: 9.8 | 1% Низкий | около 3 лет назад | |
GHSA-xxrj-j9r7-g9q6 In wolfSSL before 5.2.0, certificate validation may be bypassed during attempted authentication by a TLS 1.3 client to a TLS 1.3 server. This occurs when the sig_algo field differs between the certificate_verify message and the certificate message. | 0% Низкий | почти 4 года назад | ||
GHSA-xxrj-3q2m-w65m The Check Point Gaia Portal's GUI Clients allowed authenticated administrators with permission for the GUI Clients settings to inject a command that would run on the Gaia OS. | CVSS3: 6.7 | 0% Низкий | больше 3 лет назад | |
GHSA-xxrh-w3xc-mv6f Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability. | CVSS3: 8.8 | 1% Низкий | около 3 лет назад | |
GHSA-xxrg-mg63-qfpj Jenkins AnchorChain Plugin Has a Cross-Site Scripting (XSS) Vulnerability | CVSS3: 8 | 0% Низкий | 11 месяцев назад | |
GHSA-xxrg-cc44-fcvc A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka 'Microsoft Edge Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0645, CVE-2019-0650. | CVSS3: 7.5 | 6% Низкий | больше 3 лет назад | |
GHSA-xxrg-2j8c-797x The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_logout_callback function in versions up to, and including, 4.2.10. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to logout a vctia connected account which would cause a denial of service on the appointment scheduler. | CVSS3: 5.4 | 0% Низкий | больше 2 лет назад | |
GHSA-xxrf-fc9m-h444 Unrestricted Upload of File with Dangerous Type vulnerability in aidraw I Draw allows Using Malicious Files. This issue affects I Draw: from n/a through 1.0. | CVSS3: 9.1 | 0% Низкий | 10 месяцев назад | |
GHSA-xxrc-mppm-r6mw SurveyKing v0.2.0 was discovered to retain users' session cookies after logout, allowing attackers to login to the system and access data using the browser cache when the user exits the application. | CVSS3: 6.5 | 0% Низкий | почти 4 года назад | |
GHSA-xxrc-69rc-659v CuteNews 1.4.1 and possibly other versions allows remote attackers to obtain the installation path via unspecified vectors involving an invalid file path. | 0% Низкий | почти 4 года назад | ||
GHSA-xxr9-8j75-c68c pci_change_irq_level in hw/pci/pci.c in QEMU before 5.1.1 has a NULL pointer dereference because pci_get_bus() might not return a valid pointer. | 0% Низкий | больше 3 лет назад | ||
GHSA-xxr9-6j7m-9mvq IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 resets access control settings to the out of the box configuration during Combined Cumulative Fix (CF) installation. This can lead to security miss-configuration of the installation. IBM X-Force ID: 138950. | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
GHSA-xxr9-37w5-wgwc stunnel before 5.00, when using fork threading, does not properly update the state of the OpenSSL pseudo-random number generator (PRNG), which causes subsequent children with the same process ID to use the same entropy pool and allows remote attackers to obtain private keys for EC (ECDSA) or DSA certificates. | 0% Низкий | больше 3 лет назад | ||
GHSA-xxr9-34qv-3673 Dell PowerScale OneFS versions 9.1.0.3 and earlier contain a denial of service vulnerability. SmartConnect had an error condition that may be triggered to loop, using CPU and potentially preventing other SmartConnect DNS responses. | CVSS3: 5.3 | 0% Низкий | больше 3 лет назад | |
GHSA-xxr8-rx47-q5rr Session fixation vulnerability in Jetbox CMS 2.1 SR1 allows remote attackers to hijack web sessions via a crafted link and the administrator section. | 1% Низкий | почти 4 года назад | ||
GHSA-xxr8-r558-393h Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_bcode_insert_offset at src/mjs_bcode.c. This vulnerability can lead to a Denial of Service (DoS). | 0% Низкий | около 4 лет назад | ||
GHSA-xxr8-hvgp-fvhc Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Compress WP Compress – Image Optimizer [All-In-One] allows Reflected XSS.This issue affects WP Compress – Image Optimizer [All-In-One]: from n/a through 6.20.13. | CVSS3: 7.1 | 0% Низкий | больше 1 года назад | |
GHSA-xxr8-833v-c7wc Cross-site Scripting vulnerability in i18n translations helper method | 1% Низкий | больше 8 лет назад | ||
GHSA-xxr7-cchg-fr5v Memory corruption in WLAN Firmware while parsing receieved GTK Keys in GTK KDE. | CVSS3: 9.8 | 0% Низкий | больше 2 лет назад | |
GHSA-xxr7-33fp-84c2 Avtec Outpost uses a default cryptographic key that can be used to decrypt sensitive information. | CVSS3: 7.5 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу