Количество 322 820
Количество 322 820
GHSA-xxqf-cf9x-9rwq
lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the unauthenticated triggering of a submission-login infinite loop.
GHSA-xxqf-46rv-f5hw
There is a Null pointer dereference vulnerability in the camera module in smartphones. Successful exploitation of this vulnerability may affect service integrity.
GHSA-xxqc-wcch-833f
A vulnerability has been found in JAdmin-JAVA JAdmin 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /memoAjax/save. The manipulation of the argument ID leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
GHSA-xxqc-84hc-65cr
CSRF in the anti-csrf decorator in xunfeng 0.2.0 allows an attacker to modify the configuration via a Flash file because views/lib/AntiCSRF.py can overwrite the request.host value with the content of the X-Forwarded-Host HTTP header.
GHSA-xxqc-5rhp-jfq2
In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix race by not overwriting udev->descriptor in hub_port_init() Syzbot reported an out-of-bounds read in sysfs.c:read_descriptors(): BUG: KASAN: slab-out-of-bounds in read_descriptors+0x263/0x280 drivers/usb/core/sysfs.c:883 Read of size 8 at addr ffff88801e78b8c8 by task udevd/5011 CPU: 0 PID: 5011 Comm: udevd Not tainted 6.4.0-rc6-syzkaller-00195-g40f71e7cd3c6 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/27/2023 Call Trace: <TASK> __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0xd9/0x150 lib/dump_stack.c:106 print_address_description.constprop.0+0x2c/0x3c0 mm/kasan/report.c:351 print_report mm/kasan/report.c:462 [inline] kasan_report+0x11c/0x130 mm/kasan/report.c:572 read_descriptors+0x263/0x280 drivers/usb/core/sysfs.c:883 ... Allocated by task 758: ... __do_kmalloc_node mm/slab_common.c:966 [inline] __kmalloc+0x5e/0x190 mm/slab_common.c:97...
GHSA-xxq9-94ff-354x
An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_subscribe_get_nl_params(), there is no input validation check on hal_req->num_intf_addr_present coming from userspace, which can lead to a heap overwrite.
GHSA-xxq8-w68p-wqxp
Improper exception handling in Samsung Pass prior to version 3.7.07.5 allows physical attacker to view the screen that is previously running without authentication
GHSA-xxq8-5mc3-63xg
IBM CICS TX 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. X-Force ID: 229449.
GHSA-xxq8-555q-w627
Unspecified "absolute path vulnerability" in umountall in IBM AIX 5.1 through 5.3 allows local users to cause unknown impact via unknown vectors.
GHSA-xxq7-hjr2-f27f
Verizon 4G LTE Network Extender GA4.38 - V0.4.038.2131 utilizes a weak default admin password generation algorithm which generates passwords that are accessible to unauthenticated attackers via the webUI login page.
GHSA-xxq5-xj37-9fx7
It was discovered that the fix for CVE-2017-12163 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.
GHSA-xxq5-c27j-953j
Microsoft Outlook for Mac Spoofing Vulnerability
GHSA-xxq4-jv5p-cfwc
In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any other users.
GHSA-xxq4-9c68-6533
Windows Authentication Information Disclosure Vulnerability
GHSA-xxq4-3742-3h28
Generation of Error Message Containing Sensitive Information in microweber
GHSA-xxq3-gj76-wh9v
PHP remote file inclusion vulnerability in core/videodb.class.xml.php in the VideoDB component for Mambo 0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
GHSA-xxq3-764r-q6rm
AdPlug 2.3.1 has a heap-based buffer overflow in CmkjPlayer::load() in mkj.cpp.
GHSA-xxq2-fm9w-xjv8
The Relevanssi WordPress plugin before 4.26.0, Relevanssi Premium WordPress plugin before 2.29.0 do not sanitize and escape a parameter before using it in a SQL statement, allowing contributor and above roles to perform SQL injection attacks
GHSA-xxq2-74hw-vg6m
Jenkins WSO2 Oauth Plugin Session Fixation vulnerability
GHSA-xxq2-62cv-vmcw
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in psicosi448 wp2syslog plugin <= 1.0.5 versions.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xxqf-cf9x-9rwq lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the unauthenticated triggering of a submission-login infinite loop. | 1% Низкий | почти 4 года назад | ||
GHSA-xxqf-46rv-f5hw There is a Null pointer dereference vulnerability in the camera module in smartphones. Successful exploitation of this vulnerability may affect service integrity. | 0% Низкий | около 4 лет назад | ||
GHSA-xxqc-wcch-833f A vulnerability has been found in JAdmin-JAVA JAdmin 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /memoAjax/save. The manipulation of the argument ID leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 3.5 | 0% Низкий | 11 месяцев назад | |
GHSA-xxqc-84hc-65cr CSRF in the anti-csrf decorator in xunfeng 0.2.0 allows an attacker to modify the configuration via a Flash file because views/lib/AntiCSRF.py can overwrite the request.host value with the content of the X-Forwarded-Host HTTP header. | CVSS3: 6.5 | 0% Низкий | почти 4 года назад | |
GHSA-xxqc-5rhp-jfq2 In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix race by not overwriting udev->descriptor in hub_port_init() Syzbot reported an out-of-bounds read in sysfs.c:read_descriptors(): BUG: KASAN: slab-out-of-bounds in read_descriptors+0x263/0x280 drivers/usb/core/sysfs.c:883 Read of size 8 at addr ffff88801e78b8c8 by task udevd/5011 CPU: 0 PID: 5011 Comm: udevd Not tainted 6.4.0-rc6-syzkaller-00195-g40f71e7cd3c6 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/27/2023 Call Trace: <TASK> __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0xd9/0x150 lib/dump_stack.c:106 print_address_description.constprop.0+0x2c/0x3c0 mm/kasan/report.c:351 print_report mm/kasan/report.c:462 [inline] kasan_report+0x11c/0x130 mm/kasan/report.c:572 read_descriptors+0x263/0x280 drivers/usb/core/sysfs.c:883 ... Allocated by task 758: ... __do_kmalloc_node mm/slab_common.c:966 [inline] __kmalloc+0x5e/0x190 mm/slab_common.c:97... | CVSS3: 6.4 | 0% Низкий | больше 1 года назад | |
GHSA-xxq9-94ff-354x An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_subscribe_get_nl_params(), there is no input validation check on hal_req->num_intf_addr_present coming from userspace, which can lead to a heap overwrite. | CVSS3: 6.7 | 0% Низкий | почти 2 года назад | |
GHSA-xxq8-w68p-wqxp Improper exception handling in Samsung Pass prior to version 3.7.07.5 allows physical attacker to view the screen that is previously running without authentication | CVSS3: 4.3 | 0% Низкий | почти 4 года назад | |
GHSA-xxq8-5mc3-63xg IBM CICS TX 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. X-Force ID: 229449. | CVSS3: 3.1 | 0% Низкий | больше 3 лет назад | |
GHSA-xxq8-555q-w627 Unspecified "absolute path vulnerability" in umountall in IBM AIX 5.1 through 5.3 allows local users to cause unknown impact via unknown vectors. | 0% Низкий | почти 4 года назад | ||
GHSA-xxq7-hjr2-f27f Verizon 4G LTE Network Extender GA4.38 - V0.4.038.2131 utilizes a weak default admin password generation algorithm which generates passwords that are accessible to unauthenticated attackers via the webUI login page. | CVSS3: 7.5 | 1% Низкий | почти 4 года назад | |
GHSA-xxq5-xj37-9fx7 It was discovered that the fix for CVE-2017-12163 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6. | CVSS3: 7.5 | 0% Низкий | почти 4 года назад | |
GHSA-xxq5-c27j-953j Microsoft Outlook for Mac Spoofing Vulnerability | CVSS3: 5.3 | 1% Низкий | больше 2 лет назад | |
GHSA-xxq4-jv5p-cfwc In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any other users. | CVSS3: 3.8 | 0% Низкий | почти 4 года назад | |
GHSA-xxq4-9c68-6533 Windows Authentication Information Disclosure Vulnerability | CVSS3: 5.5 | 0% Низкий | больше 1 года назад | |
GHSA-xxq4-3742-3h28 Generation of Error Message Containing Sensitive Information in microweber | CVSS3: 6.5 | 0% Низкий | около 4 лет назад | |
GHSA-xxq3-gj76-wh9v PHP remote file inclusion vulnerability in core/videodb.class.xml.php in the VideoDB component for Mambo 0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | 9% Низкий | почти 4 года назад | ||
GHSA-xxq3-764r-q6rm AdPlug 2.3.1 has a heap-based buffer overflow in CmkjPlayer::load() in mkj.cpp. | 1% Низкий | почти 4 года назад | ||
GHSA-xxq2-fm9w-xjv8 The Relevanssi WordPress plugin before 4.26.0, Relevanssi Premium WordPress plugin before 2.29.0 do not sanitize and escape a parameter before using it in a SQL statement, allowing contributor and above roles to perform SQL injection attacks | CVSS3: 4.9 | 0% Низкий | 3 месяца назад | |
GHSA-xxq2-74hw-vg6m Jenkins WSO2 Oauth Plugin Session Fixation vulnerability | CVSS3: 8.8 | 0% Низкий | почти 3 года назад | |
GHSA-xxq2-62cv-vmcw Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in psicosi448 wp2syslog plugin <= 1.0.5 versions. | CVSS3: 5.9 | 0% Низкий | почти 3 года назад |
Уязвимостей на страницу