Количество 306 694
Количество 306 694
GHSA-3hp3-228q-23gq
Rejected reason: Not used
GHSA-3hp2-jg96-579w
Trimble SketchUp SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SKP files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-23530.
GHSA-3hmx-7w48-9wcc
User enumeration vulnerability in Password Recovery plugin 1.2 version for Roundcube, which could allow a remote attacker to create a test script against the password recovery function to enumerate all users in the database.
GHSA-3hmx-5jq6-252x
The Aladdin Knowledge Systems eToken device allows attackers with physical access to the device to obtain sensitive information without knowing the PIN of the owner by resetting the PIN in the EEPROM.
GHSA-3hmw-h9hw-mx39
A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-CheckSimpleIoC instruction. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of elevated commands on devices connected to the platform.
GHSA-3hmw-9rrw-4ppp
The nonet and nointernet sandbox profiles in Apple Mac OS X 10.5.x do not propagate restrictions to all created processes, which allows remote attackers to access network resources via a crafted application, as demonstrated by use of launchctl to trigger the launchd daemon's execution of a script file, a related issue to CVE-2011-1516.
GHSA-3hmv-gr4c-qpjc
Russcom PHPImages allows remote attackers to upload files of arbitrary types by uploading a file with a .gif extension. NOTE: due to lack of specific information about attack vectors do not depend on the existence of another vulnerability, it is not clear whether this is a vulnerability.
GHSA-3hmr-jrgj-vchc
Multiple buffer overflows in the dtt_load function in loaders/dtt_load.c Extended Module Player (XMP) 2.5.1 and earlier allow remote attackers to execute arbitrary code via unspecified vectors related to an untrusted length value and the (1) pofs and (2) plen arrays.
GHSA-3hmr-hpmw-7p9r
The Easy Digital Downloads (EDD) Recommended Products extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
GHSA-3hmr-948v-5qgq
Moodle Cross-Site Request Forgery (CSRF)
GHSA-3hmq-wx9v-vfjw
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Prime Security Manager (PRSM) 9.2(.1-2) and earlier allow remote attackers to inject arbitrary web script or HTML via crafted input to the (1) Dashboard or (2) Configure Realm page, aka Bug ID CSCuo94808.
GHSA-3hmq-m636-vcvh
In VideoLAN VLC media player 3.0.7.1, there is a NULL pointer dereference at the function SeekPercent of demux/asf/asf.c that will lead to a denial of service attack.
GHSA-3hmq-7955-4976
IBM WebSphere MQ 7.5, 8.0, and 9.0 through 9.0.4 could allow a local user to obtain highly sensitive information via trace logs in IBM WebSphere MQ Managed File Transfer. IBM X-Force ID: 137042.
GHSA-3hmq-5gjv-x3xg
In aee, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07909204; Issue ID: ALPS07909204.
GHSA-3hmp-qggx-jm2c
The ERP WordPress plugin before 1.12.4 does not properly sanitise and escape the `type` parameter in the `erp/v1/accounting/v1/people` REST API endpoint before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.
GHSA-3hmp-mj77-wcxf
In Godot through 3.1, remote code execution is possible due to the deserialization policy not being applied correctly.
GHSA-3hmp-hq97-xvfh
Deserialization of Untrusted Data vulnerability in designthemes Crafts & Arts allows Object Injection. This issue affects Crafts & Arts: from n/a through 2.5.
GHSA-3hmp-fwjp-mm5f
Stack-based buffer overflow in vxWeb 1.1.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.
GHSA-3hmm-fj7j-6c8j
Multiple cross-site scripting (XSS) vulnerabilities in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allow remote attackers to inject arbitrary web script or HTML via a (1) GET parameter, (2) POST parameter, or (3) Referer HTTP header.
GHSA-3hmm-5fqm-mg46
emlog 2.1.9 is vulnerable to Arbitrary file deletion via admin\template.php.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3hp3-228q-23gq Rejected reason: Not used | 8 месяцев назад | |||
GHSA-3hp2-jg96-579w Trimble SketchUp SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SKP files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-23530. | CVSS3: 7.8 | 0% Низкий | около 1 года назад | |
GHSA-3hmx-7w48-9wcc User enumeration vulnerability in Password Recovery plugin 1.2 version for Roundcube, which could allow a remote attacker to create a test script against the password recovery function to enumerate all users in the database. | CVSS3: 5.3 | 0% Низкий | больше 2 лет назад | |
GHSA-3hmx-5jq6-252x The Aladdin Knowledge Systems eToken device allows attackers with physical access to the device to obtain sensitive information without knowing the PIN of the owner by resetting the PIN in the EEPROM. | 0% Низкий | больше 3 лет назад | ||
GHSA-3hmw-h9hw-mx39 A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Explorer-TachyonCore-CheckSimpleIoC instruction. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of elevated commands on devices connected to the platform. | CVSS3: 7.2 | 0% Низкий | 9 дней назад | |
GHSA-3hmw-9rrw-4ppp The nonet and nointernet sandbox profiles in Apple Mac OS X 10.5.x do not propagate restrictions to all created processes, which allows remote attackers to access network resources via a crafted application, as demonstrated by use of launchctl to trigger the launchd daemon's execution of a script file, a related issue to CVE-2011-1516. | 4% Низкий | больше 3 лет назад | ||
GHSA-3hmv-gr4c-qpjc Russcom PHPImages allows remote attackers to upload files of arbitrary types by uploading a file with a .gif extension. NOTE: due to lack of specific information about attack vectors do not depend on the existence of another vulnerability, it is not clear whether this is a vulnerability. | 0% Низкий | больше 3 лет назад | ||
GHSA-3hmr-jrgj-vchc Multiple buffer overflows in the dtt_load function in loaders/dtt_load.c Extended Module Player (XMP) 2.5.1 and earlier allow remote attackers to execute arbitrary code via unspecified vectors related to an untrusted length value and the (1) pofs and (2) plen arrays. | 5% Низкий | больше 3 лет назад | ||
GHSA-3hmr-hpmw-7p9r The Easy Digital Downloads (EDD) Recommended Products extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | CVSS3: 6.1 | 1% Низкий | больше 3 лет назад | |
GHSA-3hmr-948v-5qgq Moodle Cross-Site Request Forgery (CSRF) | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
GHSA-3hmq-wx9v-vfjw Multiple cross-site scripting (XSS) vulnerabilities in Cisco Prime Security Manager (PRSM) 9.2(.1-2) and earlier allow remote attackers to inject arbitrary web script or HTML via crafted input to the (1) Dashboard or (2) Configure Realm page, aka Bug ID CSCuo94808. | 0% Низкий | больше 3 лет назад | ||
GHSA-3hmq-m636-vcvh In VideoLAN VLC media player 3.0.7.1, there is a NULL pointer dereference at the function SeekPercent of demux/asf/asf.c that will lead to a denial of service attack. | 0% Низкий | больше 3 лет назад | ||
GHSA-3hmq-7955-4976 IBM WebSphere MQ 7.5, 8.0, and 9.0 through 9.0.4 could allow a local user to obtain highly sensitive information via trace logs in IBM WebSphere MQ Managed File Transfer. IBM X-Force ID: 137042. | CVSS3: 4.4 | 0% Низкий | больше 3 лет назад | |
GHSA-3hmq-5gjv-x3xg In aee, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07909204; Issue ID: ALPS07909204. | CVSS3: 6.7 | 0% Низкий | около 2 лет назад | |
GHSA-3hmp-qggx-jm2c The ERP WordPress plugin before 1.12.4 does not properly sanitise and escape the `type` parameter in the `erp/v1/accounting/v1/people` REST API endpoint before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin. | CVSS3: 7.2 | 27% Средний | больше 2 лет назад | |
GHSA-3hmp-mj77-wcxf In Godot through 3.1, remote code execution is possible due to the deserialization policy not being applied correctly. | CVSS3: 9.8 | 7% Низкий | больше 3 лет назад | |
GHSA-3hmp-hq97-xvfh Deserialization of Untrusted Data vulnerability in designthemes Crafts & Arts allows Object Injection. This issue affects Crafts & Arts: from n/a through 2.5. | CVSS3: 8.8 | 0% Низкий | 7 месяцев назад | |
GHSA-3hmp-fwjp-mm5f Stack-based buffer overflow in vxWeb 1.1.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request. | 2% Низкий | больше 3 лет назад | ||
GHSA-3hmm-fj7j-6c8j Multiple cross-site scripting (XSS) vulnerabilities in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allow remote attackers to inject arbitrary web script or HTML via a (1) GET parameter, (2) POST parameter, or (3) Referer HTTP header. | 1% Низкий | больше 3 лет назад | ||
GHSA-3hmm-5fqm-mg46 emlog 2.1.9 is vulnerable to Arbitrary file deletion via admin\template.php. | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад |
Уязвимостей на страницу