Количество 375 453
Количество 375 453
GHSA-xvch-q88g-j649
The Cut the Rope: Time Travel (aka com.zeptolab.timetravel.free.google) application 1.3.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
GHSA-xvch-pp92-23j8
Windows Installer Elevation of Privilege Vulnerability
GHSA-xvch-fv6q-gx5m
Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.7.32 and prior and 8.0.22 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Client. CVSS 3.1 Base Score 5.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).
GHSA-xvch-5gv4-984h
Prototype Pollution in minimist
GHSA-xvcg-x6pj-6267
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/manage-tickets.php by adding a question mark (?) followed by the payload.
GHSA-xvcg-hv6h-729g
PackLinuxElf64::unpack in p_lx_elf.cpp in UPX 3.95 allows remote attackers to cause a denial of service (double free), limit the ability of a malware scanner to operate on the entire original data, or possibly have unspecified other impact via a crafted file.
GHSA-xvcg-ff9f-p7x7
SQL injection vulnerability in home.html in Xpoze Pro 4.10 allows remote attackers to execute arbitrary SQL commands via the menu parameter.
GHSA-xvcg-crx7-qcjv
Weaver Ecology v9* was discovered to contain a SQL injection vulnerability.
GHSA-xvcg-2q82-r87j
Panic mishandled in libpulse-binding
GHSA-xvcc-h99r-vm8p
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.
GHSA-xvcc-fffc-h2p4
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.
GHSA-xvcc-cxhc-j68h
Wondershare PDFelement 5.2.9 contains a privilege escalation vulnerability due to an unquoted service path in the WsAppService Windows service. Local attackers can place a malicious executable in the service path and execute code with LocalSystem privileges upon service restart or system reboot.
GHSA-xvc9-xwgj-4cq9
Duplicate Advisory: Integer Overflow in HeaderMap::reserve() can cause Denial of Service
GHSA-xvc9-v5hw-8v8j
An information disclosure issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 18.1 and iPadOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, macOS Ventura 13.7.1, macOS Sonoma 14.7.1, watchOS 11.1, visionOS 2.1. A sandboxed app may be able to access sensitive user data in system logs.
GHSA-xvc8-c6gw-4q63
An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the setup routine that regenerates credentials will expose that component's administrative interface to anyone aware of the default value.
GHSA-xvc7-7qxh-qw3m
A stack overflow in the mk_http_index_lookup function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.
GHSA-xvc5-jg6r-264j
Azure Network Watcher VM Agent Elevation of Privilege Vulnerability
GHSA-xvc4-xc7h-xwp4
Cross-site scripting (XSS) vulnerability in the Rules Link module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer rules links" permission to inject arbitrary web script or HTML via unspecified vectors, which are not properly handled in the (1) question and (2) description strings in a confirmation form for a triggering Rules link.
GHSA-xvc4-r5fw-47j4
The connection_edge_process_relay_cell function in or/relay.c in Tor before 0.2.3.25 maintains circuits even if an unexpected SENDME cell arrives, which might allow remote attackers to cause a denial of service (memory consumption or excessive cell reception rate) or bypass intended flow-control restrictions via a RELAY_COMMAND_SENDME command.
GHSA-xvc4-h3h9-rjwx
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Noor-E-Alam Amazing Hover Effects allows Stored XSS.This issue affects Amazing Hover Effects: from n/a through 2.4.9.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xvch-q88g-j649 The Cut the Rope: Time Travel (aka com.zeptolab.timetravel.free.google) application 1.3.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 0% Низкий | больше 4 лет назад | ||
GHSA-xvch-pp92-23j8 Windows Installer Elevation of Privilege Vulnerability | CVSS3: 7.8 | 0% Низкий | около 3 лет назад | |
GHSA-xvch-fv6q-gx5m Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.7.32 and prior and 8.0.22 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Client. CVSS 3.1 Base Score 5.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H). | CVSS3: 5.9 | 3% Низкий | больше 4 лет назад | |
GHSA-xvch-5gv4-984h Prototype Pollution in minimist | CVSS3: 9.8 | 5% Низкий | больше 4 лет назад | |
GHSA-xvcg-x6pj-6267 The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/manage-tickets.php by adding a question mark (?) followed by the payload. | CVSS3: 4.8 | 1% Низкий | больше 4 лет назад | |
GHSA-xvcg-hv6h-729g PackLinuxElf64::unpack in p_lx_elf.cpp in UPX 3.95 allows remote attackers to cause a denial of service (double free), limit the ability of a malware scanner to operate on the entire original data, or possibly have unspecified other impact via a crafted file. | CVSS3: 7.8 | 2% Низкий | больше 4 лет назад | |
GHSA-xvcg-ff9f-p7x7 SQL injection vulnerability in home.html in Xpoze Pro 4.10 allows remote attackers to execute arbitrary SQL commands via the menu parameter. | 1% Низкий | больше 4 лет назад | ||
GHSA-xvcg-crx7-qcjv Weaver Ecology v9* was discovered to contain a SQL injection vulnerability. | CVSS3: 9.8 | 1% Низкий | почти 2 года назад | |
GHSA-xvcg-2q82-r87j Panic mishandled in libpulse-binding | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
GHSA-xvcc-h99r-vm8p An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. | 1% Низкий | больше 4 лет назад | ||
GHSA-xvcc-fffc-h2p4 A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version. | CVSS3: 8.8 | 6% Низкий | больше 4 лет назад | |
GHSA-xvcc-cxhc-j68h Wondershare PDFelement 5.2.9 contains a privilege escalation vulnerability due to an unquoted service path in the WsAppService Windows service. Local attackers can place a malicious executable in the service path and execute code with LocalSystem privileges upon service restart or system reboot. | CVSS3: 7.8 | 0% Низкий | 3 месяца назад | |
GHSA-xvc9-xwgj-4cq9 Duplicate Advisory: Integer Overflow in HeaderMap::reserve() can cause Denial of Service | CVSS3: 7.5 | больше 4 лет назад | ||
GHSA-xvc9-v5hw-8v8j An information disclosure issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 18.1 and iPadOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, macOS Ventura 13.7.1, macOS Sonoma 14.7.1, watchOS 11.1, visionOS 2.1. A sandboxed app may be able to access sensitive user data in system logs. | CVSS3: 5.5 | 0% Низкий | почти 2 года назад | |
GHSA-xvc8-c6gw-4q63 An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the setup routine that regenerates credentials will expose that component's administrative interface to anyone aware of the default value. | 0% Низкий | 10 дней назад | ||
GHSA-xvc7-7qxh-qw3m A stack overflow in the mk_http_index_lookup function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server. | CVSS3: 7.5 | 1% Низкий | 8 месяцев назад | |
GHSA-xvc5-jg6r-264j Azure Network Watcher VM Agent Elevation of Privilege Vulnerability | CVSS3: 7.1 | 1% Низкий | около 2 лет назад | |
GHSA-xvc4-xc7h-xwp4 Cross-site scripting (XSS) vulnerability in the Rules Link module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer rules links" permission to inject arbitrary web script or HTML via unspecified vectors, which are not properly handled in the (1) question and (2) description strings in a confirmation form for a triggering Rules link. | 1% Низкий | больше 4 лет назад | ||
GHSA-xvc4-r5fw-47j4 The connection_edge_process_relay_cell function in or/relay.c in Tor before 0.2.3.25 maintains circuits even if an unexpected SENDME cell arrives, which might allow remote attackers to cause a denial of service (memory consumption or excessive cell reception rate) or bypass intended flow-control restrictions via a RELAY_COMMAND_SENDME command. | 3% Низкий | больше 4 лет назад | ||
GHSA-xvc4-h3h9-rjwx Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Noor-E-Alam Amazing Hover Effects allows Stored XSS.This issue affects Amazing Hover Effects: from n/a through 2.4.9. | CVSS3: 6.5 | 0% Низкий | около 2 лет назад |
Уязвимостей на страницу