Количество 314 529
Количество 314 529
GHSA-4223-qj94-7x9p
elFinder command injection vulnerability in the PHP connector
GHSA-4222-x45c-hh2q
A vulnerability was found in FFmpeg 2.0. It has been rated as critical. Affected by this issue is the function decode_slice_header of the file libavcodec/h64.c. The manipulation leads to memory corruption. The attack may be launched remotely. It is recommended to apply a patch to fix this issue.
GHSA-4222-4jfx-7q2p
Heap-based buffer overflow in IN_MOD.DLL (aka the Module Decoder Plug-in) in Winamp before 5.57, and libmikmod 3.1.12, might allow remote attackers to execute arbitrary code via an Ultratracker file.
GHSA-3xxx-crf3-jm97
Unspecified vulnerability in the olch2x32 ActiveX control in IBM SPSS SamplePower 3.0 before 3.0-IM-S3SAMPC-WIN32-FP001 allows remote attackers to execute arbitrary code via unknown vectors.
GHSA-3xxx-9v43-6x26
APIIDA API Gateway Manager for Broadcom Layer7 v2023.2.2 is vulnerable to Host Header Injection.
GHSA-3xxw-cpf8-x9hq
A vulnerability classified as critical has been found in jshERP up to 3.5. Affected is an unknown function of the file /user/delete of the component Account Handler. The manipulation of the argument ID leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
GHSA-3xxw-5cqg-mq5w
Stack-based buffer overflow vulnerability exists in SEIKO EPSON Web Config. Specially crafted data input by a logged-in user may execute arbitrary code. As for the details of the affected products and versions, see the information provided by the vendor under [References].
GHSA-3xxw-4ppg-gf75
On BIG-IP version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x and 12.1.x, when a message routing type virtual server is configured with both Diameter Session and Router Profiles, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
GHSA-3xxv-p78r-4fc6
Cross-site Scripting in Apache Airflow
GHSA-3xxr-x7rp-pc4x
Improper access control vulnerability in Samsung keyboard version prior to SMR Feb-2021 Release 1 allows physically proximate attackers to change in arbitrary settings during Initialization State.
GHSA-3xxr-vfgj-3gw3
In updateState of LocationServicesWifiScanningPreferenceController.java, there is a possible admin restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228315529
GHSA-3xxr-729f-x6v9
IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to server-side request forgery, caused by improper input of application server registration function. A remote attacker could exploit this vulnerability using the host address and port fields of the application server registration form in the portal UI to enumerate and attack services that are running on those hosts. IBM X-Force ID: 214441.
GHSA-3xxp-73wf-27cp
DotNetNuke (DNN) 9.9.1 CMS is vulnerable to a Stored Cross-Site Scripting vulnerability in the user profile biography section which allows remote authenticated users to inject arbitrary code via a crafted payload.
GHSA-3xxm-pww7-gf82
In nfa_hci_handle_admin_gate_rsp of nfa_hci_act.cc, there is a possible out of bound write due to missing bounds checks. This could lead to local escalation of privilege with system execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-124524315
GHSA-3xxm-cx7p-m4p6
joyplus-cms 1.6.0 has CSRF, as demonstrated by adding an administrator account via a manager/admin_ajax.php?action=save&tab={pre}manager request.
GHSA-3xxm-3g3c-w579
Moodle Code Injection vulnerability
GHSA-3xxj-wpwj-gxhm
An Improper Check for Unusual or Exceptional Conditions (CWE-754) vulnerability exists in Modicon Quantum 140 NOE771x1 version 6.9 and earlier, which could cause denial of service when the module receives an IP fragmented packet with a length greater than 65535 bytes. The module then requires a power cycle to recover.
GHSA-3xxj-rfjr-w6h5
Cross-Site Request Forgery (CSRF) vulnerability in plainware.Com ShiftController Employee Shift Scheduling plugin <= 4.9.23 versions.
GHSA-3xxj-pcr2-rvh7
NULL Pointer Dereference in Homebrew mruby prior to 3.2.
GHSA-3xxh-w577-324m
The Spectra WordPress plugin before 1.15.0 does not sanitize user input as it reaches its style HTML attribute, allowing contributors to conduct stored XSS attacks via the plugin's Gutenberg blocks.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4223-qj94-7x9p elFinder command injection vulnerability in the PHP connector | CVSS3: 9.8 | 93% Критический | больше 3 лет назад | |
GHSA-4222-x45c-hh2q A vulnerability was found in FFmpeg 2.0. It has been rated as critical. Affected by this issue is the function decode_slice_header of the file libavcodec/h64.c. The manipulation leads to memory corruption. The attack may be launched remotely. It is recommended to apply a patch to fix this issue. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-4222-4jfx-7q2p Heap-based buffer overflow in IN_MOD.DLL (aka the Module Decoder Plug-in) in Winamp before 5.57, and libmikmod 3.1.12, might allow remote attackers to execute arbitrary code via an Ultratracker file. | 10% Низкий | почти 4 года назад | ||
GHSA-3xxx-crf3-jm97 Unspecified vulnerability in the olch2x32 ActiveX control in IBM SPSS SamplePower 3.0 before 3.0-IM-S3SAMPC-WIN32-FP001 allows remote attackers to execute arbitrary code via unknown vectors. | 6% Низкий | больше 3 лет назад | ||
GHSA-3xxx-9v43-6x26 APIIDA API Gateway Manager for Broadcom Layer7 v2023.2.2 is vulnerable to Host Header Injection. | CVSS3: 6.1 | 0% Низкий | около 2 лет назад | |
GHSA-3xxw-cpf8-x9hq A vulnerability classified as critical has been found in jshERP up to 3.5. Affected is an unknown function of the file /user/delete of the component Account Handler. The manipulation of the argument ID leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 5.4 | 0% Низкий | 7 месяцев назад | |
GHSA-3xxw-5cqg-mq5w Stack-based buffer overflow vulnerability exists in SEIKO EPSON Web Config. Specially crafted data input by a logged-in user may execute arbitrary code. As for the details of the affected products and versions, see the information provided by the vendor under [References]. | CVSS3: 7.2 | 0% Низкий | около 2 месяцев назад | |
GHSA-3xxw-4ppg-gf75 On BIG-IP version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x and 12.1.x, when a message routing type virtual server is configured with both Diameter Session and Router Profiles, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 1% Низкий | около 4 лет назад | ||
GHSA-3xxv-p78r-4fc6 Cross-site Scripting in Apache Airflow | CVSS3: 6.1 | 4% Низкий | больше 4 лет назад | |
GHSA-3xxr-x7rp-pc4x Improper access control vulnerability in Samsung keyboard version prior to SMR Feb-2021 Release 1 allows physically proximate attackers to change in arbitrary settings during Initialization State. | CVSS3: 2.4 | 0% Низкий | больше 3 лет назад | |
GHSA-3xxr-vfgj-3gw3 In updateState of LocationServicesWifiScanningPreferenceController.java, there is a possible admin restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228315529 | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-3xxr-729f-x6v9 IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to server-side request forgery, caused by improper input of application server registration function. A remote attacker could exploit this vulnerability using the host address and port fields of the application server registration form in the portal UI to enumerate and attack services that are running on those hosts. IBM X-Force ID: 214441. | CVSS3: 6.5 | 0% Низкий | почти 4 года назад | |
GHSA-3xxp-73wf-27cp DotNetNuke (DNN) 9.9.1 CMS is vulnerable to a Stored Cross-Site Scripting vulnerability in the user profile biography section which allows remote authenticated users to inject arbitrary code via a crafted payload. | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
GHSA-3xxm-pww7-gf82 In nfa_hci_handle_admin_gate_rsp of nfa_hci_act.cc, there is a possible out of bound write due to missing bounds checks. This could lead to local escalation of privilege with system execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-124524315 | 0% Низкий | больше 3 лет назад | ||
GHSA-3xxm-cx7p-m4p6 joyplus-cms 1.6.0 has CSRF, as demonstrated by adding an administrator account via a manager/admin_ajax.php?action=save&tab={pre}manager request. | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад | |
GHSA-3xxm-3g3c-w579 Moodle Code Injection vulnerability | CVSS3: 4.7 | 2% Низкий | около 2 лет назад | |
GHSA-3xxj-wpwj-gxhm An Improper Check for Unusual or Exceptional Conditions (CWE-754) vulnerability exists in Modicon Quantum 140 NOE771x1 version 6.9 and earlier, which could cause denial of service when the module receives an IP fragmented packet with a length greater than 65535 bytes. The module then requires a power cycle to recover. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-3xxj-rfjr-w6h5 Cross-Site Request Forgery (CSRF) vulnerability in plainware.Com ShiftController Employee Shift Scheduling plugin <= 4.9.23 versions. | CVSS3: 5.4 | 0% Низкий | около 2 лет назад | |
GHSA-3xxj-pcr2-rvh7 NULL Pointer Dereference in Homebrew mruby prior to 3.2. | 0% Низкий | почти 4 года назад | ||
GHSA-3xxh-w577-324m The Spectra WordPress plugin before 1.15.0 does not sanitize user input as it reaches its style HTML attribute, allowing contributors to conduct stored XSS attacks via the plugin's Gutenberg blocks. | CVSS3: 5.4 | 0% Низкий | почти 3 года назад |
Уязвимостей на страницу