Количество 354 500
Количество 354 500
GHSA-xvg3-g835-ccc9
An issue was discovered in Motorola CX2 1.01 and M2 1.01. There is a command injection in the function startRmtAssist in hnap, which leads to remote code execution via shell metacharacters in a JSON value.
GHSA-xvg3-935w-4mv9
The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'User-Agent' header in all versions up to, and including, 5.4.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The show_complete_user_agent_tooltip setting must be explicitly enabled by an administrator (disabled by default) for the stored payload to be rendered and executed.
GHSA-xvg3-58p8-whhm
The cs_validate_page function in bsd/kern/ubc_subr.c in the xnu kernel 1228.0 and earlier in Apple Mac OS X 10.5.1 allows local users to cause a denial of service (failed assertion and system crash) via a crafted signed Mach-O binary that causes the hashes function to return NULL.
GHSA-xvg2-wrv6-8v46
SQL injection vulnerability in index.php in Easy CafeEngine allows remote attackers to execute arbitrary SQL commands via the catid parameter, a different vector than CVE-2008-4604.
GHSA-xvg2-phf2-rwq7
PHP remote file inclusion vulnerability in modules/abook/foldertree.php in Leo West WEBO (aka weborganizer) 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter.
GHSA-xvg2-gfxv-qc4c
The CVS 1.10.8 client trusts pathnames that are provided by the CVS server, which allows the server to force the client to create arbitrary files.
GHSA-xvg2-cgv6-6h7v
netfoil: Incorrect block responses could lead to localhost traffic
GHSA-xvfx-x2hm-pgf5
Improper input validation in Active Directory Certificate Services (AD CS) allows an authorized attacker to deny service over a network.
GHSA-xvfw-xwr5-7xvc
Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Segment). Supported versions that are affected are 18.0 and 19.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Customer Management and Segmentation Foundation. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Retail Customer Management and Segmentation Foundation accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).
GHSA-xvfw-jjhx-vm37
The chain_reply function in process.c in smbd in Samba before 3.4.8 and 3.5.x before 3.5.2 allows remote attackers to cause a denial of service (NULL pointer dereference and process crash) via a Negotiate Protocol request with a certain 0x0003 field value followed by a Session Setup AndX request with a certain 0x8003 field value.
GHSA-xvfv-x947-hhgf
TeeKai Forum 1.2 uses weak encryption of web usage statistics in data/member_log.txt, which is stored under the web document root with insufficient access control, which allows remote attackers to identify IP's visiting the site by dividing each octet by the MD5 hash of '20'.
GHSA-xvfv-hp97-ff3g
Cross-site scripting vulnerability in User-friendly SVN (USVN) Version 1.0.7 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
GHSA-xvfr-r8m7-6v65
In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. This issue is similar to CVE-2018-6616.
GHSA-xvfr-h5h6-78m3
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the lastname parameter at /customer_support/ajax.php?action=save_user.
GHSA-xvfq-f68m-7mwg
In MailStore Outlook Add-in (and Email Archive Outlook Add-in) through 12.1.2, the login process does not validate the validity of the certificate presented by the server.
GHSA-xvfq-4q6q-gxx7
In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header
GHSA-xvfp-x78m-7x4j
A security feature bypass vulnerability exists when Windows Defender Firewall incorrectly applies firewall profiles to cellular network connections, aka 'Windows Defender Firewall Security Feature Bypass Vulnerability'.
GHSA-xvfp-4c8p-rwfv
AdvancePro Advanceware allows remote authenticated users to obtain sensitive information about arbitrary customers' orders via a modified id parameter.
GHSA-xvfm-vcfx-8599
The issue was addressed with improved bounds checks. This issue is fixed in macOS Tahoe 26.4. A buffer overflow may result in memory corruption and unexpected app termination.
GHSA-xvfj-9qc8-3jgp
A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.4, macOS Big Sur 11.7.7, macOS Monterey 12.6.6. An app may be able to gain root privileges
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xvg3-g835-ccc9 An issue was discovered in Motorola CX2 1.01 and M2 1.01. There is a command injection in the function startRmtAssist in hnap, which leads to remote code execution via shell metacharacters in a JSON value. | 4% Низкий | около 4 лет назад | ||
GHSA-xvg3-935w-4mv9 The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'User-Agent' header in all versions up to, and including, 5.4.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The show_complete_user_agent_tooltip setting must be explicitly enabled by an administrator (disabled by default) for the stored payload to be rendered and executed. | CVSS3: 7.2 | 0% Низкий | 2 месяца назад | |
GHSA-xvg3-58p8-whhm The cs_validate_page function in bsd/kern/ubc_subr.c in the xnu kernel 1228.0 and earlier in Apple Mac OS X 10.5.1 allows local users to cause a denial of service (failed assertion and system crash) via a crafted signed Mach-O binary that causes the hashes function to return NULL. | 1% Низкий | больше 4 лет назад | ||
GHSA-xvg2-wrv6-8v46 SQL injection vulnerability in index.php in Easy CafeEngine allows remote attackers to execute arbitrary SQL commands via the catid parameter, a different vector than CVE-2008-4604. | 1% Низкий | больше 4 лет назад | ||
GHSA-xvg2-phf2-rwq7 PHP remote file inclusion vulnerability in modules/abook/foldertree.php in Leo West WEBO (aka weborganizer) 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter. | 5% Низкий | больше 4 лет назад | ||
GHSA-xvg2-gfxv-qc4c The CVS 1.10.8 client trusts pathnames that are provided by the CVS server, which allows the server to force the client to create arbitrary files. | 1% Низкий | больше 4 лет назад | ||
GHSA-xvg2-cgv6-6h7v netfoil: Incorrect block responses could lead to localhost traffic | 7 дней назад | |||
GHSA-xvfx-x2hm-pgf5 Improper input validation in Active Directory Certificate Services (AD CS) allows an authorized attacker to deny service over a network. | CVSS3: 6.5 | 2% Низкий | около 1 года назад | |
GHSA-xvfw-xwr5-7xvc Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Segment). Supported versions that are affected are 18.0 and 19.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Customer Management and Segmentation Foundation. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Retail Customer Management and Segmentation Foundation accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N). | 1% Низкий | около 4 лет назад | ||
GHSA-xvfw-jjhx-vm37 The chain_reply function in process.c in smbd in Samba before 3.4.8 and 3.5.x before 3.5.2 allows remote attackers to cause a denial of service (NULL pointer dereference and process crash) via a Negotiate Protocol request with a certain 0x0003 field value followed by a Session Setup AndX request with a certain 0x8003 field value. | 4% Низкий | около 4 лет назад | ||
GHSA-xvfv-x947-hhgf TeeKai Forum 1.2 uses weak encryption of web usage statistics in data/member_log.txt, which is stored under the web document root with insufficient access control, which allows remote attackers to identify IP's visiting the site by dividing each octet by the MD5 hash of '20'. | 2% Низкий | больше 4 лет назад | ||
GHSA-xvfv-hp97-ff3g Cross-site scripting vulnerability in User-friendly SVN (USVN) Version 1.0.7 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-xvfr-r8m7-6v65 In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. This issue is similar to CVE-2018-6616. | CVSS3: 5.5 | 3% Низкий | около 4 лет назад | |
GHSA-xvfr-h5h6-78m3 Customer Support System v1 was discovered to contain a SQL injection vulnerability via the lastname parameter at /customer_support/ajax.php?action=save_user. | CVSS3: 8.8 | 1% Низкий | больше 2 лет назад | |
GHSA-xvfq-f68m-7mwg In MailStore Outlook Add-in (and Email Archive Outlook Add-in) through 12.1.2, the login process does not validate the validity of the certificate presented by the server. | CVSS3: 5.9 | 0% Низкий | около 4 лет назад | |
GHSA-xvfq-4q6q-gxx7 In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header | CVSS3: 6.5 | 0% Низкий | около 2 месяцев назад | |
GHSA-xvfp-x78m-7x4j A security feature bypass vulnerability exists when Windows Defender Firewall incorrectly applies firewall profiles to cellular network connections, aka 'Windows Defender Firewall Security Feature Bypass Vulnerability'. | CVSS3: 7.5 | 4% Низкий | около 4 лет назад | |
GHSA-xvfp-4c8p-rwfv AdvancePro Advanceware allows remote authenticated users to obtain sensitive information about arbitrary customers' orders via a modified id parameter. | 1% Низкий | около 4 лет назад | ||
GHSA-xvfm-vcfx-8599 The issue was addressed with improved bounds checks. This issue is fixed in macOS Tahoe 26.4. A buffer overflow may result in memory corruption and unexpected app termination. | CVSS3: 7.3 | 0% Низкий | 4 месяца назад | |
GHSA-xvfj-9qc8-3jgp A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.4, macOS Big Sur 11.7.7, macOS Monterey 12.6.6. An app may be able to gain root privileges | CVSS3: 7.8 | 0% Низкий | около 3 лет назад |
Уязвимостей на страницу