Количество 375 453
Количество 375 453
GHSA-xv7q-j96c-5r6v
Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 139 and Firefox ESR < 128.11.
GHSA-xv7q-6jr5-mw96
An issue in MongoDB Server's query execution engine could allow an authenticated user with read and write privileges to cause an internal reference to be used after the underlying memory has been freed, when running certain queries against time-series collections. This could result in a server crash or disclosure of freed memory contents within query results.
GHSA-xv7q-66p6-r28c
Cross-Site Request Forgery (CSRF) vulnerability in wp.Insider, wpaffiliatemgr Affiliates Manager.This issue affects Affiliates Manager: from n/a through 2.9.31.
GHSA-xv7q-36g9-3jc5
The Scalable Vector Graphics (SVG) WordPress plugin through 3.4 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.
GHSA-xv7p-vwj6-p73h
Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
GHSA-xv7p-mvh6-j6cp
A cross-site request forgery (CSRF) vulnerability in the Management Console of BlackBerry UEM versions earlier than 12.9.1 could allow an attacker to make modifications to the UEM settings in the context of a Management Console administrator.
GHSA-xv7p-mcp9-w898
UploaderService in SnagIT 2019.1.2 allows elevation of privilege by placing an invalid presentation file in %PROGRAMDATA%\TechSmith\TechSmith Recorder\QueuedPresentations and then creating a symbolic link in %PROGRAMDATA%\Techsmith\TechSmith Recorder\InvalidPresentations that points to an arbitrary folder with an arbitrary file name. TechSmith Relay Classic Recorder prior to 5.2.1 on Windows is vulnerable. The vulnerability was introduced in SnagIT Windows 12.4.1.
GHSA-xv7p-jw46-8r85
Cross-site Scripting in JFinalcms
GHSA-xv7j-wg82-2r7g
The Bookster WordPress plugin through 1.1.0 allows adding sensitive parameters when validating appointments allowing attackers to manipulate the data sent when booking an appointment (the request body) to change its status from pending to approved.
GHSA-xv7j-v722-h5vx
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability located in the deviceName parameter of the formSetDeviceName function.
GHSA-xv7j-qvp8-927h
Bitrix Site Manager 4.1.x stores updater.log under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information.
GHSA-xv7j-jr8q-mhmm
Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling.
GHSA-xv7j-8v8v-h429
The ELF file parser in eSafe 7.0.17.0, Prevx 3.0, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified abiversion field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations.
GHSA-xv7j-2v4w-cjvh
OpenStack Glance logs user name and password in cleartext
GHSA-xv7h-qpjm-g3jp
In NetworkStackNotifier, there is a possible permissions bypass due to an unsafe implicit PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157475111
GHSA-xv7h-95r7-595j
Incorrect implementation of lockout feature in Keycloak
GHSA-xv7h-8h3f-m34f
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 allows remote attackers to affect integrity via unknown vectors related to Fluid Core.
GHSA-xv7h-524v-h227
In the Linux kernel, the following vulnerability has been resolved: ksmbd: not allow guest user on multichannel This patch return STATUS_NOT_SUPPORTED if binding session is guest.
GHSA-xv7g-x679-jf4c
A potential security vulnerability has been identified for the HP OfficeJet 7110 Wide Format ePrinter that enables Cross-Site Scripting (XSS).
GHSA-xv7f-hrp6-5mhh
Stack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges via an application that leverages /dev/msm_acdb access and provides a large size value in an ioctl argument.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xv7q-j96c-5r6v Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 139 and Firefox ESR < 128.11. | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
GHSA-xv7q-6jr5-mw96 An issue in MongoDB Server's query execution engine could allow an authenticated user with read and write privileges to cause an internal reference to be used after the underlying memory has been freed, when running certain queries against time-series collections. This could result in a server crash or disclosure of freed memory contents within query results. | CVSS3: 7.1 | 0% Низкий | около 1 месяца назад | |
GHSA-xv7q-66p6-r28c Cross-Site Request Forgery (CSRF) vulnerability in wp.Insider, wpaffiliatemgr Affiliates Manager.This issue affects Affiliates Manager: from n/a through 2.9.31. | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
GHSA-xv7q-36g9-3jc5 The Scalable Vector Graphics (SVG) WordPress plugin through 3.4 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads. | CVSS3: 5.4 | 0% Низкий | больше 2 лет назад | |
GHSA-xv7p-vwj6-p73h Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. | CVSS3: 8.8 | 1% Низкий | почти 4 года назад | |
GHSA-xv7p-mvh6-j6cp A cross-site request forgery (CSRF) vulnerability in the Management Console of BlackBerry UEM versions earlier than 12.9.1 could allow an attacker to make modifications to the UEM settings in the context of a Management Console administrator. | CVSS3: 6.5 | 0% Низкий | больше 4 лет назад | |
GHSA-xv7p-mcp9-w898 UploaderService in SnagIT 2019.1.2 allows elevation of privilege by placing an invalid presentation file in %PROGRAMDATA%\TechSmith\TechSmith Recorder\QueuedPresentations and then creating a symbolic link in %PROGRAMDATA%\Techsmith\TechSmith Recorder\InvalidPresentations that points to an arbitrary folder with an arbitrary file name. TechSmith Relay Classic Recorder prior to 5.2.1 on Windows is vulnerable. The vulnerability was introduced in SnagIT Windows 12.4.1. | CVSS3: 7.8 | 2% Низкий | больше 4 лет назад | |
GHSA-xv7p-jw46-8r85 Cross-site Scripting in JFinalcms | CVSS3: 5.4 | 0% Низкий | почти 3 года назад | |
GHSA-xv7j-wg82-2r7g The Bookster WordPress plugin through 1.1.0 allows adding sensitive parameters when validating appointments allowing attackers to manipulate the data sent when booking an appointment (the request body) to change its status from pending to approved. | CVSS3: 6.5 | 0% Низкий | около 2 лет назад | |
GHSA-xv7j-v722-h5vx Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability located in the deviceName parameter of the formSetDeviceName function. | CVSS3: 9.8 | 1% Низкий | больше 2 лет назад | |
GHSA-xv7j-qvp8-927h Bitrix Site Manager 4.1.x stores updater.log under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information. | 2% Низкий | больше 4 лет назад | ||
GHSA-xv7j-jr8q-mhmm Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling. | 5% Низкий | больше 4 лет назад | ||
GHSA-xv7j-8v8v-h429 The ELF file parser in eSafe 7.0.17.0, Prevx 3.0, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified abiversion field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different ELF parser implementations. | 63% Средний | больше 4 лет назад | ||
GHSA-xv7j-2v4w-cjvh OpenStack Glance logs user name and password in cleartext | 3% Низкий | больше 4 лет назад | ||
GHSA-xv7h-qpjm-g3jp In NetworkStackNotifier, there is a possible permissions bypass due to an unsafe implicit PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157475111 | 0% Низкий | больше 4 лет назад | ||
GHSA-xv7h-95r7-595j Incorrect implementation of lockout feature in Keycloak | CVSS3: 7.5 | 1% Низкий | около 4 лет назад | |
GHSA-xv7h-8h3f-m34f Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 allows remote attackers to affect integrity via unknown vectors related to Fluid Core. | 2% Низкий | больше 4 лет назад | ||
GHSA-xv7h-524v-h227 In the Linux kernel, the following vulnerability has been resolved: ksmbd: not allow guest user on multichannel This patch return STATUS_NOT_SUPPORTED if binding session is guest. | CVSS3: 5.5 | 0% Низкий | около 1 года назад | |
GHSA-xv7g-x679-jf4c A potential security vulnerability has been identified for the HP OfficeJet 7110 Wide Format ePrinter that enables Cross-Site Scripting (XSS). | 2% Низкий | больше 4 лет назад | ||
GHSA-xv7f-hrp6-5mhh Stack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges via an application that leverages /dev/msm_acdb access and provides a large size value in an ioctl argument. | CVSS3: 8.4 | 2% Низкий | больше 4 лет назад |
Уязвимостей на страницу