Количество 373 528
Количество 373 528
GHSA-xxq9-94ff-354x
An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_subscribe_get_nl_params(), there is no input validation check on hal_req->num_intf_addr_present coming from userspace, which can lead to a heap overwrite.
GHSA-xxq8-w68p-wqxp
Improper exception handling in Samsung Pass prior to version 3.7.07.5 allows physical attacker to view the screen that is previously running without authentication
GHSA-xxq8-5mc3-63xg
IBM CICS TX 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. X-Force ID: 229449.
GHSA-xxq8-555q-w627
Unspecified "absolute path vulnerability" in umountall in IBM AIX 5.1 through 5.3 allows local users to cause unknown impact via unknown vectors.
GHSA-xxq7-hjr2-f27f
Verizon 4G LTE Network Extender GA4.38 - V0.4.038.2131 utilizes a weak default admin password generation algorithm which generates passwords that are accessible to unauthenticated attackers via the webUI login page.
GHSA-xxq5-xj37-9fx7
It was discovered that the fix for CVE-2017-12163 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.
GHSA-xxq5-c27j-953j
Microsoft Outlook for Mac Spoofing Vulnerability
GHSA-xxq4-jv5p-cfwc
In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any other users.
GHSA-xxq4-9c68-6533
Windows Authentication Information Disclosure Vulnerability
GHSA-xxq4-3742-3h28
Generation of Error Message Containing Sensitive Information in microweber
GHSA-xxq3-gj76-wh9v
PHP remote file inclusion vulnerability in core/videodb.class.xml.php in the VideoDB component for Mambo 0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
GHSA-xxq3-764r-q6rm
AdPlug 2.3.1 has a heap-based buffer overflow in CmkjPlayer::load() in mkj.cpp.
GHSA-xxq2-fm9w-xjv8
The Relevanssi WordPress plugin before 4.26.0, Relevanssi Premium WordPress plugin before 2.29.0 do not sanitize and escape a parameter before using it in a SQL statement, allowing contributor and above roles to perform SQL injection attacks
GHSA-xxq2-97gh-5p37
Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel memory access and in certain cases cause GPU UAF of arbitrary pages. Incorrect validation of array index can lead to OOB read and potentially to GPU UAF of arbitrary pages.
GHSA-xxq2-74hw-vg6m
Jenkins WSO2 Oauth Plugin Session Fixation vulnerability
GHSA-xxq2-62cv-vmcw
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in psicosi448 wp2syslog plugin <= 1.0.5 versions.
GHSA-xxpx-w698-q23j
When a user opens manipulated JPEG 2000 (.jp2, jp2k.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application. The file format details along with their CVE relevant information can be found below
GHSA-xxpx-f58m-683f
Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insufficient Resource Pool vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.
GHSA-xxpx-f366-4xpq
Craft CMS: Authorization bypass: view-only Categories user can modify category structure via structures/move-element
GHSA-xxpw-3xg9-qwph
The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access of protected files due to insufficient token validation in the `get_advance_file_by_url()` method in all versions up to, and including, 2.8.8.8 The method uses a SQL `LIKE` operator for token lookup without escaping wildcard characters via `$wpdb->esc_like()`. This makes it possible for unauthenticated attackers to bypass the private token requirement by supplying SQL wildcard characters (such as `%`) as the token value, matching any record in the plugin's file table and downloading any protected file.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xxq9-94ff-354x An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_subscribe_get_nl_params(), there is no input validation check on hal_req->num_intf_addr_present coming from userspace, which can lead to a heap overwrite. | CVSS3: 6.7 | 0% Низкий | больше 2 лет назад | |
GHSA-xxq8-w68p-wqxp Improper exception handling in Samsung Pass prior to version 3.7.07.5 allows physical attacker to view the screen that is previously running without authentication | CVSS3: 4.3 | 0% Низкий | больше 4 лет назад | |
GHSA-xxq8-5mc3-63xg IBM CICS TX 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. X-Force ID: 229449. | CVSS3: 3.1 | 1% Низкий | почти 4 года назад | |
GHSA-xxq8-555q-w627 Unspecified "absolute path vulnerability" in umountall in IBM AIX 5.1 through 5.3 allows local users to cause unknown impact via unknown vectors. | 0% Низкий | больше 4 лет назад | ||
GHSA-xxq7-hjr2-f27f Verizon 4G LTE Network Extender GA4.38 - V0.4.038.2131 utilizes a weak default admin password generation algorithm which generates passwords that are accessible to unauthenticated attackers via the webUI login page. | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
GHSA-xxq5-xj37-9fx7 It was discovered that the fix for CVE-2017-12163 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6. | CVSS3: 7.5 | 2% Низкий | больше 4 лет назад | |
GHSA-xxq5-c27j-953j Microsoft Outlook for Mac Spoofing Vulnerability | CVSS3: 5.3 | 1% Низкий | почти 3 года назад | |
GHSA-xxq4-jv5p-cfwc In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any other users. | CVSS3: 3.8 | 1% Низкий | больше 4 лет назад | |
GHSA-xxq4-9c68-6533 Windows Authentication Information Disclosure Vulnerability | CVSS3: 5.5 | 1% Низкий | около 2 лет назад | |
GHSA-xxq4-3742-3h28 Generation of Error Message Containing Sensitive Information in microweber | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад | |
GHSA-xxq3-gj76-wh9v PHP remote file inclusion vulnerability in core/videodb.class.xml.php in the VideoDB component for Mambo 0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | 3% Низкий | больше 4 лет назад | ||
GHSA-xxq3-764r-q6rm AdPlug 2.3.1 has a heap-based buffer overflow in CmkjPlayer::load() in mkj.cpp. | 2% Низкий | больше 4 лет назад | ||
GHSA-xxq2-fm9w-xjv8 The Relevanssi WordPress plugin before 4.26.0, Relevanssi Premium WordPress plugin before 2.29.0 do not sanitize and escape a parameter before using it in a SQL statement, allowing contributor and above roles to perform SQL injection attacks | CVSS3: 4.9 | 0% Низкий | 8 месяцев назад | |
GHSA-xxq2-97gh-5p37 Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel memory access and in certain cases cause GPU UAF of arbitrary pages. Incorrect validation of array index can lead to OOB read and potentially to GPU UAF of arbitrary pages. | CVSS3: 7.1 | 0% Низкий | около 1 месяца назад | |
GHSA-xxq2-74hw-vg6m Jenkins WSO2 Oauth Plugin Session Fixation vulnerability | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад | |
GHSA-xxq2-62cv-vmcw Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in psicosi448 wp2syslog plugin <= 1.0.5 versions. | CVSS3: 5.9 | 0% Низкий | больше 3 лет назад | |
GHSA-xxpx-w698-q23j When a user opens manipulated JPEG 2000 (.jp2, jp2k.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application. The file format details along with their CVE relevant information can be found below | CVSS3: 5.5 | 1% Низкий | около 4 лет назад | |
GHSA-xxpx-f58m-683f Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insufficient Resource Pool vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service. | CVSS3: 5.3 | 0% Низкий | больше 1 года назад | |
GHSA-xxpx-f366-4xpq Craft CMS: Authorization bypass: view-only Categories user can modify category structure via structures/move-element | 0% Низкий | около 1 месяца назад | ||
GHSA-xxpw-3xg9-qwph The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access of protected files due to insufficient token validation in the `get_advance_file_by_url()` method in all versions up to, and including, 2.8.8.8 The method uses a SQL `LIKE` operator for token lookup without escaping wildcard characters via `$wpdb->esc_like()`. This makes it possible for unauthenticated attackers to bypass the private token requirement by supplying SQL wildcard characters (such as `%`) as the token value, matching any record in the plugin's file table and downloading any protected file. | CVSS3: 5.3 | 0% Низкий | около 1 месяца назад |
Уязвимостей на страницу