Количество 314 375
Количество 314 375
GHSA-3xc3-235x-7q23
HP Linux Imaging and Printing (HPLIP) through 3.12.4 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/hpcupsfilterc_#.bmp, (2) /tmp/hpcupsfilterk_#.bmp, (3) /tmp/hpcups_job#.out, (4) /tmp/hpijs_#####.out, or (5) /tmp/hpps_job#.out temporary file, a different vulnerability than CVE-2011-2722.
GHSA-3xc2-jvpw-rv79
CWE-862: Missing Authorization vulnerability exists that could cause unauthorized access when enabled on the network and potentially impacting connected devices.
GHSA-3x9x-vhqj-cv27
Magento XML Injection vulnerability in the Widgets Update Layout
GHSA-3x9w-fg96-5j98
In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Fix VP8 stateless decoder smatch warning Fix a smatch static checker warning on vdec_vp8_req_if.c. Which leads to a kernel crash when fb is NULL.
GHSA-3x9v-m7wh-wv6x
Use-after-free vulnerability in the Zend engine in PHP before 5.2.15 and 5.3.x before 5.3.4 might allow context-dependent attackers to cause a denial of service (heap memory corruption) or have unspecified other impact via vectors related to use of __set, __get, __isset, and __unset methods on objects accessed by a reference.
GHSA-3x9v-482c-32cf
In macOS High Sierra before 10.13.5, a privacy issue in the handling of Open Directory records was addressed with improved indexing.
GHSA-3x9v-3chp-c9cc
Use after free in V8 in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Low)
GHSA-3x9q-xwx4-hhr3
Cross-Site Request Forgery (CSRF) vulnerability in Tusko Trush Advanced Custom Fields : CPT Options Pages acf-cpt-options-pages allows Object Injection.This issue affects Advanced Custom Fields : CPT Options Pages: from n/a through <= 2.0.9.
GHSA-3x9p-x3q5-7j89
Huawei AppGallery versions before 8.0.4.301 has an arbitrary Javascript running vulnerability. An attacker may set up a malicious network environment and trick user into accessing a malicious web page to bypass the whitelist mechanism, which make the malicious Javascript loaded and run in the smart phone.
GHSA-3x9p-wvg6-r63g
U-Office Force UserDefault page has insufficient filtering for special characters in the HTTP header fields. A remote attacker with general user privilege can exploit this vulnerability to inject JavaScript and perform XSS (Stored Cross-Site Scripting) attack.
GHSA-3x9p-6xxq-5rhj
The name_parse function in evdns.c in libevent before 2.1.6-beta allows remote attackers to have unspecified impact via vectors involving the label_len variable, which triggers an out-of-bounds stack read.
GHSA-3x9p-453g-p8w7
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the urls parameter at /goform/saveParentControlInfo.
GHSA-3x9m-x83w-55fq
The issue was addressed with improved UI handling. This issue is fixed in iOS 14.5 and iPadOS 14.5. A local user may be able to view sensitive information in the app switcher.
GHSA-3x9m-w4fr-frg2
OpenBSD 3.3 and 3.4 does not properly parse Accept and Deny rules without netmasks on big-endian 64-bit platforms such as SPARC64, which may allow remote attackers to bypass access restrictions.
GHSA-3x9m-qxj4-gff3
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks Database for Contact Form 7, WPforms, Elementor forms contact-form-entries allows SQL Injection.This issue affects Database for Contact Form 7, WPforms, Elementor forms: from n/a through 1.3.0.
GHSA-3x9m-3vf5-jwp2
The "Query Compiler, Rewrite, Optimizer" component in IBM DB2 UDB 9.5 before FP6a allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted query involving certain UNION ALL views, leading to an indefinitely large amount of compilation time.
GHSA-3x9j-wcg8-q9vx
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e6e.
GHSA-3x9j-7f53-54f5
This vulnerability exists in the Tinxy mobile app due to storage of logged-in user information in plaintext on the device database. An attacker with physical access to the rooted device could exploit this vulnerability by accessing its database leading to unauthorized access of user information such as username, email address and mobile number.
GHSA-3x9h-3p7m-33m7
Jenkins SonarQube Plugin Stores Passwords in Cleartext
GHSA-3x9g-xfj5-fq84
Duplicate Advisory: Cross-Site Request Forgery in Gradio
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3xc3-235x-7q23 HP Linux Imaging and Printing (HPLIP) through 3.12.4 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/hpcupsfilterc_#.bmp, (2) /tmp/hpcupsfilterk_#.bmp, (3) /tmp/hpcups_job#.out, (4) /tmp/hpijs_#####.out, or (5) /tmp/hpps_job#.out temporary file, a different vulnerability than CVE-2011-2722. | 0% Низкий | больше 3 лет назад | ||
GHSA-3xc2-jvpw-rv79 CWE-862: Missing Authorization vulnerability exists that could cause unauthorized access when enabled on the network and potentially impacting connected devices. | CVSS3: 9.8 | 0% Низкий | около 1 года назад | |
GHSA-3x9x-vhqj-cv27 Magento XML Injection vulnerability in the Widgets Update Layout | CVSS3: 7.2 | 11% Средний | больше 3 лет назад | |
GHSA-3x9w-fg96-5j98 In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Fix VP8 stateless decoder smatch warning Fix a smatch static checker warning on vdec_vp8_req_if.c. Which leads to a kernel crash when fb is NULL. | CVSS3: 5.5 | 0% Низкий | больше 1 года назад | |
GHSA-3x9v-m7wh-wv6x Use-after-free vulnerability in the Zend engine in PHP before 5.2.15 and 5.3.x before 5.3.4 might allow context-dependent attackers to cause a denial of service (heap memory corruption) or have unspecified other impact via vectors related to use of __set, __get, __isset, and __unset methods on objects accessed by a reference. | 1% Низкий | больше 3 лет назад | ||
GHSA-3x9v-482c-32cf In macOS High Sierra before 10.13.5, a privacy issue in the handling of Open Directory records was addressed with improved indexing. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-3x9v-3chp-c9cc Use after free in V8 in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Low) | CVSS3: 3.1 | 0% Низкий | 3 месяца назад | |
GHSA-3x9q-xwx4-hhr3 Cross-Site Request Forgery (CSRF) vulnerability in Tusko Trush Advanced Custom Fields : CPT Options Pages acf-cpt-options-pages allows Object Injection.This issue affects Advanced Custom Fields : CPT Options Pages: from n/a through <= 2.0.9. | CVSS3: 5.3 | 0% Низкий | 4 месяца назад | |
GHSA-3x9p-x3q5-7j89 Huawei AppGallery versions before 8.0.4.301 has an arbitrary Javascript running vulnerability. An attacker may set up a malicious network environment and trick user into accessing a malicious web page to bypass the whitelist mechanism, which make the malicious Javascript loaded and run in the smart phone. | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад | |
GHSA-3x9p-wvg6-r63g U-Office Force UserDefault page has insufficient filtering for special characters in the HTTP header fields. A remote attacker with general user privilege can exploit this vulnerability to inject JavaScript and perform XSS (Stored Cross-Site Scripting) attack. | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
GHSA-3x9p-6xxq-5rhj The name_parse function in evdns.c in libevent before 2.1.6-beta allows remote attackers to have unspecified impact via vectors involving the label_len variable, which triggers an out-of-bounds stack read. | CVSS3: 9.8 | 7% Низкий | больше 3 лет назад | |
GHSA-3x9p-453g-p8w7 Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the urls parameter at /goform/saveParentControlInfo. | CVSS3: 9.8 | 0% Низкий | больше 3 лет назад | |
GHSA-3x9m-x83w-55fq The issue was addressed with improved UI handling. This issue is fixed in iOS 14.5 and iPadOS 14.5. A local user may be able to view sensitive information in the app switcher. | 0% Низкий | больше 3 лет назад | ||
GHSA-3x9m-w4fr-frg2 OpenBSD 3.3 and 3.4 does not properly parse Accept and Deny rules without netmasks on big-endian 64-bit platforms such as SPARC64, which may allow remote attackers to bypass access restrictions. | 0% Низкий | почти 4 года назад | ||
GHSA-3x9m-qxj4-gff3 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks Database for Contact Form 7, WPforms, Elementor forms contact-form-entries allows SQL Injection.This issue affects Database for Contact Form 7, WPforms, Elementor forms: from n/a through 1.3.0. | CVSS3: 9.8 | 0% Низкий | больше 2 лет назад | |
GHSA-3x9m-3vf5-jwp2 The "Query Compiler, Rewrite, Optimizer" component in IBM DB2 UDB 9.5 before FP6a allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted query involving certain UNION ALL views, leading to an indefinitely large amount of compilation time. | 0% Низкий | больше 3 лет назад | ||
GHSA-3x9j-wcg8-q9vx IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e6e. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-3x9j-7f53-54f5 This vulnerability exists in the Tinxy mobile app due to storage of logged-in user information in plaintext on the device database. An attacker with physical access to the rooted device could exploit this vulnerability by accessing its database leading to unauthorized access of user information such as username, email address and mobile number. | 0% Низкий | около 1 года назад | ||
GHSA-3x9h-3p7m-33m7 Jenkins SonarQube Plugin Stores Passwords in Cleartext | 5% Низкий | больше 3 лет назад | ||
GHSA-3x9g-xfj5-fq84 Duplicate Advisory: Cross-Site Request Forgery in Gradio | CVSS3: 4.3 | почти 2 года назад |
Уязвимостей на страницу