Количество 315 253
Количество 315 253
GHSA-xrpr-pc4j-r3pr
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Contempoinc Real Estate 7 WordPress theme <= 3.3.1 versions.
GHSA-xrpr-mm6f-2gg7
PHPRAP 1.0.4 through 1.0.8 has SQL Injection via the application/home/controller/project.php search() function.
GHSA-xrpr-8xpg-cf34
In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541757.
GHSA-xrpq-x3c2-8r2w
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 11.3, tvOS 11.3, watchOS 4.3, Safari 11.1, iTunes 12.7.4 for Windows, iCloud for Windows 7.4.
GHSA-xrpq-wjfc-cj2f
NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which an input data size is not validated, which may lead to tampering or denial of service. This affects vGPU version 8.x (prior to 8.4), version 9.x (prior to 9.4) and version 10.x (prior to 10.3).
GHSA-xrpq-r56p-r4mq
GPAC 0.7.1 has a buffer overflow issue in gf_import_message() in media_import.c.
GHSA-xrpq-63mp-9vcw
phpMyAdmin HTTP Response Splitting Vulnerability
GHSA-xrpq-4g9w-qrwj
Jenkins Health Advisor by CloudBees Plugin Vulnerable to Cross-Site Scripting
GHSA-xrpp-vwp4-q9hp
An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the bootp_input() function and could occur while processing a udp packet that is smaller than the size of the 'bootp_t' structure. A malicious guest could use this flaw to leak 10 bytes of uninitialized heap memory from the host. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.
GHSA-xrpp-vm79-f74q
Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Oct-2021 Release 1 allows attackers to write file as system UID via BT remote socket.
GHSA-xrpp-3rf6-w42j
Docker Desktop before 4.12.0 is vulnerable to RCE via a crafted extension description or changelog. This issue affects Docker Desktop: before 4.12.0.
GHSA-xrpm-hccg-28x7
Improper Input Validation in nocodb
GHSA-xrpm-74v3-f6fq
The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1; and Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2; does not properly restrict use of OleLoadFromStream in instantiating objects from data streams, which allows remote attackers to execute arbitrary code via a crafted HTML document with an ATL (1) component or (2) control, related to ATL headers and bypassing security policies, aka "ATL COM Initialization Vulnerability."
GHSA-xrpj-f9v6-2332
CSV injection in Craft CMS
GHSA-xrph-fg7m-g22g
NDMP server in Veritas NetBackup 5.1 allows attackers to cause a denial of service via a CONFIG message with an out-of-range timestamp, which triggers a null dereference.
GHSA-xrph-cp3c-jgmh
In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Fix a race between readers and resize checks The reader code in rb_get_reader_page() swaps a new reader page into the ring buffer by doing cmpxchg on old->list.prev->next to point it to the new page. Following that, if the operation is successful, old->list.next->prev gets updated too. This means the underlying doubly-linked list is temporarily inconsistent, page->prev->next or page->next->prev might not be equal back to page for some page in the ring buffer. The resize operation in ring_buffer_resize() can be invoked in parallel. It calls rb_check_pages() which can detect the described inconsistency and stop further tracing: [ 190.271762] ------------[ cut here ]------------ [ 190.271771] WARNING: CPU: 1 PID: 6186 at kernel/trace/ring_buffer.c:1467 rb_check_pages.isra.0+0x6a/0xa0 [ 190.271789] Modules linked in: [...] [ 190.271991] Unloaded tainted modules: intel_uncore_frequency(E):1 skx_edac(...
GHSA-xrph-4qjj-gj25
parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disabled, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted XML document containing a large number of nested entity references, a variant of the "billion laughs" attack.
GHSA-xrpg-qv3x-v75v
An issue was discovered in COINS Construction Cloud 11.12. In several locations throughout the application, JavaScript code is passed as a URL parameter. Attackers can trivially alter this code to cause malicious behaviour. The application is therefore vulnerable to reflected XSS via malicious URLs.
GHSA-xrpf-jjp4-8pmh
Spoon::Cookie in the Spoon module 0.24 for Perl does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via a crafted request, which is not properly handled when it is deserialized.
GHSA-xrpf-f2q9-273m
While processing a debug log event from firmware in all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-07-05, an integer underflow and/or buffer over-read can occur.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xrpr-pc4j-r3pr Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Contempoinc Real Estate 7 WordPress theme <= 3.3.1 versions. | CVSS3: 6.1 | 0% Низкий | почти 3 года назад | |
GHSA-xrpr-mm6f-2gg7 PHPRAP 1.0.4 through 1.0.8 has SQL Injection via the application/home/controller/project.php search() function. | CVSS3: 9.8 | 0% Низкий | больше 3 лет назад | |
GHSA-xrpr-8xpg-cf34 In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541757. | CVSS3: 4.4 | 0% Низкий | почти 2 года назад | |
GHSA-xrpq-x3c2-8r2w Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 11.3, tvOS 11.3, watchOS 4.3, Safari 11.1, iTunes 12.7.4 for Windows, iCloud for Windows 7.4. | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
GHSA-xrpq-wjfc-cj2f NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which an input data size is not validated, which may lead to tampering or denial of service. This affects vGPU version 8.x (prior to 8.4), version 9.x (prior to 9.4) and version 10.x (prior to 10.3). | 0% Низкий | больше 3 лет назад | ||
GHSA-xrpq-r56p-r4mq GPAC 0.7.1 has a buffer overflow issue in gf_import_message() in media_import.c. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-xrpq-63mp-9vcw phpMyAdmin HTTP Response Splitting Vulnerability | 1% Низкий | почти 4 года назад | ||
GHSA-xrpq-4g9w-qrwj Jenkins Health Advisor by CloudBees Plugin Vulnerable to Cross-Site Scripting | CVSS3: 8.8 | 0% Низкий | 9 месяцев назад | |
GHSA-xrpp-vwp4-q9hp An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the bootp_input() function and could occur while processing a udp packet that is smaller than the size of the 'bootp_t' structure. A malicious guest could use this flaw to leak 10 bytes of uninitialized heap memory from the host. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0. | CVSS3: 3.8 | 0% Низкий | больше 3 лет назад | |
GHSA-xrpp-vm79-f74q Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Oct-2021 Release 1 allows attackers to write file as system UID via BT remote socket. | 0% Низкий | больше 3 лет назад | ||
GHSA-xrpp-3rf6-w42j Docker Desktop before 4.12.0 is vulnerable to RCE via a crafted extension description or changelog. This issue affects Docker Desktop: before 4.12.0. | CVSS3: 9.8 | 0% Низкий | больше 2 лет назад | |
GHSA-xrpm-hccg-28x7 Improper Input Validation in nocodb | CVSS3: 6.5 | 1% Низкий | больше 2 лет назад | |
GHSA-xrpm-74v3-f6fq The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1; and Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2; does not properly restrict use of OleLoadFromStream in instantiating objects from data streams, which allows remote attackers to execute arbitrary code via a crafted HTML document with an ATL (1) component or (2) control, related to ATL headers and bypassing security policies, aka "ATL COM Initialization Vulnerability." | 42% Средний | почти 4 года назад | ||
GHSA-xrpj-f9v6-2332 CSV injection in Craft CMS | CVSS3: 8.8 | больше 4 лет назад | ||
GHSA-xrph-fg7m-g22g NDMP server in Veritas NetBackup 5.1 allows attackers to cause a denial of service via a CONFIG message with an out-of-range timestamp, which triggers a null dereference. | 0% Низкий | почти 4 года назад | ||
GHSA-xrph-cp3c-jgmh In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Fix a race between readers and resize checks The reader code in rb_get_reader_page() swaps a new reader page into the ring buffer by doing cmpxchg on old->list.prev->next to point it to the new page. Following that, if the operation is successful, old->list.next->prev gets updated too. This means the underlying doubly-linked list is temporarily inconsistent, page->prev->next or page->next->prev might not be equal back to page for some page in the ring buffer. The resize operation in ring_buffer_resize() can be invoked in parallel. It calls rb_check_pages() which can detect the described inconsistency and stop further tracing: [ 190.271762] ------------[ cut here ]------------ [ 190.271771] WARNING: CPU: 1 PID: 6186 at kernel/trace/ring_buffer.c:1467 rb_check_pages.isra.0+0x6a/0xa0 [ 190.271789] Modules linked in: [...] [ 190.271991] Unloaded tainted modules: intel_uncore_frequency(E):1 skx_edac(... | CVSS3: 4.7 | 0% Низкий | больше 1 года назад | |
GHSA-xrph-4qjj-gj25 parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disabled, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted XML document containing a large number of nested entity references, a variant of the "billion laughs" attack. | 4% Низкий | больше 3 лет назад | ||
GHSA-xrpg-qv3x-v75v An issue was discovered in COINS Construction Cloud 11.12. In several locations throughout the application, JavaScript code is passed as a URL parameter. Attackers can trivially alter this code to cause malicious behaviour. The application is therefore vulnerable to reflected XSS via malicious URLs. | CVSS3: 6.1 | 0% Низкий | около 4 лет назад | |
GHSA-xrpf-jjp4-8pmh Spoon::Cookie in the Spoon module 0.24 for Perl does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via a crafted request, which is not properly handled when it is deserialized. | 2% Низкий | больше 3 лет назад | ||
GHSA-xrpf-f2q9-273m While processing a debug log event from firmware in all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-07-05, an integer underflow and/or buffer over-read can occur. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу