Количество 312 573
Количество 312 573
GHSA-3x9m-x83w-55fq
The issue was addressed with improved UI handling. This issue is fixed in iOS 14.5 and iPadOS 14.5. A local user may be able to view sensitive information in the app switcher.
GHSA-3x9m-w4fr-frg2
OpenBSD 3.3 and 3.4 does not properly parse Accept and Deny rules without netmasks on big-endian 64-bit platforms such as SPARC64, which may allow remote attackers to bypass access restrictions.
GHSA-3x9m-qxj4-gff3
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks Database for Contact Form 7, WPforms, Elementor forms contact-form-entries allows SQL Injection.This issue affects Database for Contact Form 7, WPforms, Elementor forms: from n/a through 1.3.0.
GHSA-3x9m-3vf5-jwp2
The "Query Compiler, Rewrite, Optimizer" component in IBM DB2 UDB 9.5 before FP6a allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted query involving certain UNION ALL views, leading to an indefinitely large amount of compilation time.
GHSA-3x9j-wcg8-q9vx
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e6e.
GHSA-3x9j-7f53-54f5
This vulnerability exists in the Tinxy mobile app due to storage of logged-in user information in plaintext on the device database. An attacker with physical access to the rooted device could exploit this vulnerability by accessing its database leading to unauthorized access of user information such as username, email address and mobile number.
GHSA-3x9h-3p7m-33m7
Jenkins SonarQube Plugin Stores Passwords in Cleartext
GHSA-3x9g-xfj5-fq84
Duplicate Advisory: Cross-Site Request Forgery in Gradio
GHSA-3x9f-jx2x-rgjh
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Woo Hoo woohoo allows PHP Local File Inclusion.This issue affects Woo Hoo: from n/a through <= 1.25.
GHSA-3x9f-jgfq-gjmx
A spoofing issue was addressed with improved truncation when displaying the fully qualified domain name This issue is fixed in Safari 18.5, macOS Sequoia 15.5. A website may be able to spoof the domain name in the title of a pop-up window.
GHSA-3x9f-9pxv-q52x
The DUBAI module has a double free vulnerability.Successful exploitation of this vulnerability may affect system availability.
GHSA-3x9f-74h4-2fqr
Denial of Service in SheetJS Pro
GHSA-3x9f-3c9h-x7gj
Windows Graphics Component Elevation of Privilege Vulnerability
GHSA-3x9c-53jf-h89x
LinuxServer.io Heimdall before 2.7.3 allows XSS via the q parameter.
GHSA-3x99-g65w-pxrx
Buffer overflow in the telnet service in Verso NetPerformer FRAD ACT SDM-95xx 7.xx (R1) and earlier, SDM-93xx 10.x.x (R2) and earlier, and SDM-92xx 9.x.x (R1) and earlier allows remote attackers to cause a denial of service (reboot) and possibly execute arbitrary code via a long username.
GHSA-3x98-xr5x-2c7r
Unspecified vulnerability in the CLA2 server in IBM Gentran Integration Suite 4.3, Sterling Integrator 5.0 and 5.1, and Sterling B2B Integrator 5.2, as used in IBM Sterling File Gateway 1.1 through 2.2 and other products, allows remote attackers to execute arbitrary commands via unknown vectors.
GHSA-3x98-fhcg-5wv3
Server receiving a malformed message based on a using the specified key values can cause a stack overflow vulnerability which could lead to an attacker performing remote code execution or causing a failure. See Honeywell Security Notification for recommendations on upgrading and versioning.
GHSA-3x97-q7pq-fx88
IBM Maximo Asset Management is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
GHSA-3x97-g7q3-p9h7
An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
GHSA-3x96-m42v-hvh5
Cross-site Scripting in Microweber
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3x9m-x83w-55fq The issue was addressed with improved UI handling. This issue is fixed in iOS 14.5 and iPadOS 14.5. A local user may be able to view sensitive information in the app switcher. | 0% Низкий | больше 3 лет назад | ||
GHSA-3x9m-w4fr-frg2 OpenBSD 3.3 and 3.4 does not properly parse Accept and Deny rules without netmasks on big-endian 64-bit platforms such as SPARC64, which may allow remote attackers to bypass access restrictions. | 0% Низкий | почти 4 года назад | ||
GHSA-3x9m-qxj4-gff3 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks Database for Contact Form 7, WPforms, Elementor forms contact-form-entries allows SQL Injection.This issue affects Database for Contact Form 7, WPforms, Elementor forms: from n/a through 1.3.0. | CVSS3: 9.8 | 0% Низкий | больше 2 лет назад | |
GHSA-3x9m-3vf5-jwp2 The "Query Compiler, Rewrite, Optimizer" component in IBM DB2 UDB 9.5 before FP6a allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted query involving certain UNION ALL views, leading to an indefinitely large amount of compilation time. | 0% Низкий | больше 3 лет назад | ||
GHSA-3x9j-wcg8-q9vx IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e6e. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-3x9j-7f53-54f5 This vulnerability exists in the Tinxy mobile app due to storage of logged-in user information in plaintext on the device database. An attacker with physical access to the rooted device could exploit this vulnerability by accessing its database leading to unauthorized access of user information such as username, email address and mobile number. | 0% Низкий | около 1 года назад | ||
GHSA-3x9h-3p7m-33m7 Jenkins SonarQube Plugin Stores Passwords in Cleartext | 5% Низкий | больше 3 лет назад | ||
GHSA-3x9g-xfj5-fq84 Duplicate Advisory: Cross-Site Request Forgery in Gradio | CVSS3: 4.3 | почти 2 года назад | ||
GHSA-3x9f-jx2x-rgjh Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Woo Hoo woohoo allows PHP Local File Inclusion.This issue affects Woo Hoo: from n/a through <= 1.25. | CVSS3: 8.1 | 0% Низкий | около 2 месяцев назад | |
GHSA-3x9f-jgfq-gjmx A spoofing issue was addressed with improved truncation when displaying the fully qualified domain name This issue is fixed in Safari 18.5, macOS Sequoia 15.5. A website may be able to spoof the domain name in the title of a pop-up window. | CVSS3: 4.3 | 0% Низкий | 3 месяца назад | |
GHSA-3x9f-9pxv-q52x The DUBAI module has a double free vulnerability.Successful exploitation of this vulnerability may affect system availability. | CVSS3: 7.5 | 0% Низкий | около 3 лет назад | |
GHSA-3x9f-74h4-2fqr Denial of Service in SheetJS Pro | CVSS3: 5.5 | 0% Низкий | больше 4 лет назад | |
GHSA-3x9f-3c9h-x7gj Windows Graphics Component Elevation of Privilege Vulnerability | CVSS3: 7.8 | 0% Низкий | больше 1 года назад | |
GHSA-3x9c-53jf-h89x LinuxServer.io Heimdall before 2.7.3 allows XSS via the q parameter. | CVSS3: 7.2 | 0% Низкий | 7 месяцев назад | |
GHSA-3x99-g65w-pxrx Buffer overflow in the telnet service in Verso NetPerformer FRAD ACT SDM-95xx 7.xx (R1) and earlier, SDM-93xx 10.x.x (R2) and earlier, and SDM-92xx 9.x.x (R1) and earlier allows remote attackers to cause a denial of service (reboot) and possibly execute arbitrary code via a long username. | 16% Средний | почти 4 года назад | ||
GHSA-3x98-xr5x-2c7r Unspecified vulnerability in the CLA2 server in IBM Gentran Integration Suite 4.3, Sterling Integrator 5.0 and 5.1, and Sterling B2B Integrator 5.2, as used in IBM Sterling File Gateway 1.1 through 2.2 and other products, allows remote attackers to execute arbitrary commands via unknown vectors. | 2% Низкий | больше 3 лет назад | ||
GHSA-3x98-fhcg-5wv3 Server receiving a malformed message based on a using the specified key values can cause a stack overflow vulnerability which could lead to an attacker performing remote code execution or causing a failure. See Honeywell Security Notification for recommendations on upgrading and versioning. | CVSS3: 8.1 | 2% Низкий | почти 2 года назад | |
GHSA-3x97-q7pq-fx88 IBM Maximo Asset Management is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-3x97-g7q3-p9h7 An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
GHSA-3x96-m42v-hvh5 Cross-site Scripting in Microweber | CVSS3: 6.1 | 28% Средний | больше 3 лет назад |
Уязвимостей на страницу