Количество 291 062
Количество 291 062
GHSA-xvq8-f2vm-qf3p
Rejected reason: Not used
GHSA-xvq8-82jr-qr82
The newstatpress plugin before 1.0.4 for WordPress has XSS related to the Referer header.
GHSA-xvq8-2qwv-cr72
CubeCart 2.0.6 allows remote attackers to obtain sensitive information via an invalid (1) language parameter to index.php, (2) PHPSESSID parameter to index.php, (3) product parameter to tellafriend.php, (4) add parameter to view_cart.php, or (5) product parameter to view_product.php, which reveals the path in a PHP error message.
GHSA-xvq7-6cjq-gwh7
There is a possible out of bounds read due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-152647751
GHSA-xvq6-mh4q-2wm8
Multiple buffer overflows in realtime operating system (RTOS) 6.1.0 allows local users to execute arbitrary code via (1) a long ABLANG environment variable in phlocale or (2) a long -u option to pkg-installer.
GHSA-xvq6-h898-wcj8
Mattermost denial of service vulnerability
GHSA-xvq5-pp86-qj79
Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I9195 build I9195XXUCOL1 (Galaxy S4 mini LTE), and GT-I9505 build I9505XXUHOJ2 (Galaxy S4) devices have unintended availability of the modem in USB configuration number 2 within the secure lockscreen state, allowing an attacker to make phone calls, send text messages, or issue commands, aka SVE-2016-5301.
GHSA-xvq3-j3j3-hfjp
SQL injection vulnerability in login.php in Keld PHP-MySQL News Script 0.7.1 allows remote attackers to execute arbitrary SQL commands via the username parameter.
GHSA-xvpx-6hh8-7h72
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the 'City' field. An unauthenticated attacker can trigger a specially crafted script to achieve remote code execution.
GHSA-xvpw-j9f9-fw7v
Internet Explorer 3 records a history of all URL's that are visited by a user in DAT files located in the Temporary Internet Files and History folders, which are not cleared when the user selects the "Clear History" option, and are not visible when the user browses the folders because of tailored displays.
GHSA-xvpr-22g7-3fc2
The Debian apache2ctl script in the apache2 package squeeze before 2.2.16-6+squeeze11, wheezy before 2.2.22-13, and sid before 2.2.22-13 for the Apache HTTP Server on Debian GNU/Linux does not properly create the /var/lock/apache2 lock directory, which allows local users to gain privileges via an unspecified symlink attack.
GHSA-xvpq-v2cq-9v92
Buffer overflow vulnerability in Core FTP Server v2 Build 697, via a crafted username.
GHSA-xvpp-m96v-c2pr
D-Link DIR-655 C devices before 3.02B05 BETA03 allow remote attackers to execute arbitrary commands via shell metacharacters in the online_firmware_check.cgi check_fw_url parameter.
GHSA-xvpp-hhff-gp7v
In WAGO Unmanaged Switch (852-111/000-001) in firmware version 01 an undocumented configuration interface without authorization allows an remote attacker to read system information and configure a limited set of parameters.
GHSA-xvpp-959v-c63p
Unspecified vulnerability in NWFS.SYS in Novell Client for Windows 4.91 SP4 has unknown impact and attack vectors, possibly related to IOCTL requests that overwrite arbitrary memory.
GHSA-xvpp-5hc3-fp4m
Improper Access Control vulnerability in AcyMailing Enterprise component for Joomla. It allows the unauthorized removal of attachments from campaigns.
GHSA-xvpm-v9x9-vg99
Cross-site scripting (XSS) vulnerability in webglimpse.cgi in Webglimpse 2.14.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the ID parameter.
GHSA-xvpm-8w5j-p5mw
Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters). The supported version that is affected is 8.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology. Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS score depend on the software that uses the Outside In Technology code. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology code, but if data is not received over a network t...
GHSA-xvpj-rpwv-6v3h
Deserialization of Untrusted Data vulnerability in giuliopanda ADFO allows Object Injection. This issue affects ADFO: from n/a through 1.9.1.
GHSA-xvph-4wvx-cp6q
Path Disclosure Vulnerability in wordpress plugin MP3-jPlayer v2.3.2
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-xvq8-f2vm-qf3p Rejected reason: Not used | 28 дней назад | |||
GHSA-xvq8-82jr-qr82 The newstatpress plugin before 1.0.4 for WordPress has XSS related to the Referer header. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-xvq8-2qwv-cr72 CubeCart 2.0.6 allows remote attackers to obtain sensitive information via an invalid (1) language parameter to index.php, (2) PHPSESSID parameter to index.php, (3) product parameter to tellafriend.php, (4) add parameter to view_cart.php, or (5) product parameter to view_product.php, which reveals the path in a PHP error message. | 4% Низкий | больше 3 лет назад | ||
GHSA-xvq7-6cjq-gwh7 There is a possible out of bounds read due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-152647751 | 0% Низкий | больше 3 лет назад | ||
GHSA-xvq6-mh4q-2wm8 Multiple buffer overflows in realtime operating system (RTOS) 6.1.0 allows local users to execute arbitrary code via (1) a long ABLANG environment variable in phlocale or (2) a long -u option to pkg-installer. | 0% Низкий | больше 3 лет назад | ||
GHSA-xvq6-h898-wcj8 Mattermost denial of service vulnerability | CVSS3: 4.3 | 0% Низкий | почти 2 года назад | |
GHSA-xvq5-pp86-qj79 Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I9195 build I9195XXUCOL1 (Galaxy S4 mini LTE), and GT-I9505 build I9505XXUHOJ2 (Galaxy S4) devices have unintended availability of the modem in USB configuration number 2 within the secure lockscreen state, allowing an attacker to make phone calls, send text messages, or issue commands, aka SVE-2016-5301. | CVSS3: 6.8 | 0% Низкий | больше 3 лет назад | |
GHSA-xvq3-j3j3-hfjp SQL injection vulnerability in login.php in Keld PHP-MySQL News Script 0.7.1 allows remote attackers to execute arbitrary SQL commands via the username parameter. | 0% Низкий | больше 3 лет назад | ||
GHSA-xvpx-6hh8-7h72 Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the 'City' field. An unauthenticated attacker can trigger a specially crafted script to achieve remote code execution. | 31% Средний | больше 3 лет назад | ||
GHSA-xvpw-j9f9-fw7v Internet Explorer 3 records a history of all URL's that are visited by a user in DAT files located in the Temporary Internet Files and History folders, which are not cleared when the user selects the "Clear History" option, and are not visible when the user browses the folders because of tailored displays. | 1% Низкий | больше 3 лет назад | ||
GHSA-xvpr-22g7-3fc2 The Debian apache2ctl script in the apache2 package squeeze before 2.2.16-6+squeeze11, wheezy before 2.2.22-13, and sid before 2.2.22-13 for the Apache HTTP Server on Debian GNU/Linux does not properly create the /var/lock/apache2 lock directory, which allows local users to gain privileges via an unspecified symlink attack. | 0% Низкий | больше 3 лет назад | ||
GHSA-xvpq-v2cq-9v92 Buffer overflow vulnerability in Core FTP Server v2 Build 697, via a crafted username. | 0% Низкий | больше 3 лет назад | ||
GHSA-xvpp-m96v-c2pr D-Link DIR-655 C devices before 3.02B05 BETA03 allow remote attackers to execute arbitrary commands via shell metacharacters in the online_firmware_check.cgi check_fw_url parameter. | 21% Средний | больше 3 лет назад | ||
GHSA-xvpp-hhff-gp7v In WAGO Unmanaged Switch (852-111/000-001) in firmware version 01 an undocumented configuration interface without authorization allows an remote attacker to read system information and configure a limited set of parameters. | CVSS3: 9.1 | 0% Низкий | больше 2 лет назад | |
GHSA-xvpp-959v-c63p Unspecified vulnerability in NWFS.SYS in Novell Client for Windows 4.91 SP4 has unknown impact and attack vectors, possibly related to IOCTL requests that overwrite arbitrary memory. | 10% Низкий | больше 3 лет назад | ||
GHSA-xvpp-5hc3-fp4m Improper Access Control vulnerability in AcyMailing Enterprise component for Joomla. It allows the unauthorized removal of attachments from campaigns. | CVSS3: 4.3 | 0% Низкий | около 2 лет назад | |
GHSA-xvpm-v9x9-vg99 Cross-site scripting (XSS) vulnerability in webglimpse.cgi in Webglimpse 2.14.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the ID parameter. | 2% Низкий | больше 3 лет назад | ||
GHSA-xvpm-8w5j-p5mw Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters). The supported version that is affected is 8.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology. Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS score depend on the software that uses the Outside In Technology code. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology code, but if data is not received over a network t... | CVSS3: 7.1 | 2% Низкий | больше 3 лет назад | |
GHSA-xvpj-rpwv-6v3h Deserialization of Untrusted Data vulnerability in giuliopanda ADFO allows Object Injection. This issue affects ADFO: from n/a through 1.9.1. | CVSS3: 7.2 | 0% Низкий | 6 месяцев назад | |
GHSA-xvph-4wvx-cp6q Path Disclosure Vulnerability in wordpress plugin MP3-jPlayer v2.3.2 | CVSS3: 5.3 | 4% Низкий | больше 3 лет назад |
Уязвимостей на страницу