Количество 314 458
Количество 314 458
GHSA-3x45-j72c-xqpj
Hitachi Vantara Pentaho Business Analytics Server versions before 10.1.0.0 and 9.3.0.7, including 8.3.x do not correctly protect the ACL service endpoint of the Pentaho User Console against XML External Entity Reference.
GHSA-3x44-c8w2-mxwg
The ptrace_setxregs function in arch/xtensa/kernel/ptrace.c in the Linux kernel before 3.1 does not validate user-space pointers, which allows local users to obtain sensitive information from kernel memory locations via a crafted PTRACE_SETXTREGS request.
GHSA-3x44-884c-cc67
PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the oldpass parameter in change-password.php.
GHSA-3x43-9cxq-4fwr
The Manager service in the management console in Symantec Endpoint Protection (SEP) 12.1 before 12.1 RU1-MP1 allows remote attackers to conduct file-insertion attacks and execute arbitrary code by leveraging exploitation of CVE-2012-0294.
GHSA-3x43-8h7p-m97w
IBM DataPower Gateway 2018.4.1.0, 7.6.0.0 through 7.6.0.11, 7.5.2.0 through 7.5.2.18, 7.5.1.0 through 7.5.1.18, 7.5.0.0 through 7.5.0.19, and 7.7.0.0 through 7.7.1.3 could allow an authenticated user to inject arbitrary messages that would be displayed on the UI. IBM X-Force ID: 144892.
GHSA-3x42-vgc3-7f6c
An exploitable integer overflow vulnerability exists when creating a new RGB Surface in SDL 2.0.5. A specially crafted file can cause an integer overflow resulting in too little memory being allocated which can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability.
GHSA-3x3x-vjcr-56cc
The Linux kernel before 6.5.4 has an es1 use-after-free in fs/ext4/extents_status.c, related to ext4_es_insert_extent.
GHSA-3x3x-gvp4-q59h
SAP NetWeaver AS ABAP (Banking Services), versions - 710, 711, 740, 750, 751, 752, 75A, 75B, 75C, 75D, 75E, does not perform necessary authorization checks for an authenticated user due to Missing Authorization Check, allowing wrong and unexpected change of individual conditions by a malicious user leading to wrong prices.
GHSA-3x3x-fgf2-hxxv
Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.2, 6.3, 6.3.1, 6.3.2, 6.3.3, and 6.3.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Data, Domain, and Function Security.
GHSA-3x3w-vcjx-7796
Cross-Site Request Forgery in easyii CMS
GHSA-3x3w-ffg6-mp27
Cisco NX-OS 7.1(1)N1(1) on Nexus 5500, 5600, and 6000 devices does not properly validate PDUs in SNMP packets, which allows remote attackers to cause a denial of service (SNMP application restart) via a crafted packet, aka Bug ID CSCut84645.
GHSA-3x3w-849q-423v
Xnx3 Wangmarket Cross-Site Scripting vulnerability
GHSA-3x3v-84v2-gwh2
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1.
GHSA-3x3r-mcv6-277v
The WiMAX dissector in Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (crash) via unknown vectors related to "unaligned access on some platforms."
GHSA-3x3q-ghcp-whf7
Template Secret leakage in logs in Scaffolder when using `fetch:template`
GHSA-3x3q-3ch4-c25f
A Privilege Escalation vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. Staff account users can access the admin resources and perform CRUD Operations.
GHSA-3x3q-3c9j-4x72
In the Linux kernel, the following vulnerability has been resolved: Input: iforce - invert valid length check when fetching device IDs syzbot is reporting uninitialized value at iforce_init_device() [1], for commit 6ac0aec6b0a6 ("Input: iforce - allow callers supply data buffer when fetching device IDs") is checking that valid length is shorter than bytes to read. Since iforce_get_id_packet() stores valid length when returning 0, the caller needs to check that valid length is longer than or equals to bytes to read.
GHSA-3x3p-75r6-3954
Stack consumption vulnerability in the ChildProcessSecurityPolicy::CanRequestURL function in browser/child_process_security_policy.cc in Google Chrome before 4.0.249.78 allows remote attackers to cause a denial of service (memory consumption and application crash) via a URL that specifies multiple protocols, as demonstrated by a URL that begins with many repetitions of the view-source: substring.
GHSA-3x3p-2fwv-2ppj
The HwPCAssistant module has the out-of-bounds read/write vulnerability. Successful exploitation of this vulnerability may affect confidentiality and integrity.
GHSA-3x3m-p2wx-g7cw
Unauthenticated File Read in PHP Proxy
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3x45-j72c-xqpj Hitachi Vantara Pentaho Business Analytics Server versions before 10.1.0.0 and 9.3.0.7, including 8.3.x do not correctly protect the ACL service endpoint of the Pentaho User Console against XML External Entity Reference. | CVSS3: 7.1 | 0% Низкий | больше 1 года назад | |
GHSA-3x44-c8w2-mxwg The ptrace_setxregs function in arch/xtensa/kernel/ptrace.c in the Linux kernel before 3.1 does not validate user-space pointers, which allows local users to obtain sensitive information from kernel memory locations via a crafted PTRACE_SETXTREGS request. | CVSS3: 6 | 0% Низкий | больше 3 лет назад | |
GHSA-3x44-884c-cc67 PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the oldpass parameter in change-password.php. | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
GHSA-3x43-9cxq-4fwr The Manager service in the management console in Symantec Endpoint Protection (SEP) 12.1 before 12.1 RU1-MP1 allows remote attackers to conduct file-insertion attacks and execute arbitrary code by leveraging exploitation of CVE-2012-0294. | 5% Низкий | почти 4 года назад | ||
GHSA-3x43-8h7p-m97w IBM DataPower Gateway 2018.4.1.0, 7.6.0.0 through 7.6.0.11, 7.5.2.0 through 7.5.2.18, 7.5.1.0 through 7.5.1.18, 7.5.0.0 through 7.5.0.19, and 7.7.0.0 through 7.7.1.3 could allow an authenticated user to inject arbitrary messages that would be displayed on the UI. IBM X-Force ID: 144892. | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
GHSA-3x42-vgc3-7f6c An exploitable integer overflow vulnerability exists when creating a new RGB Surface in SDL 2.0.5. A specially crafted file can cause an integer overflow resulting in too little memory being allocated which can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability. | CVSS3: 8.8 | 3% Низкий | больше 3 лет назад | |
GHSA-3x3x-vjcr-56cc The Linux kernel before 6.5.4 has an es1 use-after-free in fs/ext4/extents_status.c, related to ext4_es_insert_extent. | CVSS3: 7.8 | 0% Низкий | больше 2 лет назад | |
GHSA-3x3x-gvp4-q59h SAP NetWeaver AS ABAP (Banking Services), versions - 710, 711, 740, 750, 751, 752, 75A, 75B, 75C, 75D, 75E, does not perform necessary authorization checks for an authenticated user due to Missing Authorization Check, allowing wrong and unexpected change of individual conditions by a malicious user leading to wrong prices. | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
GHSA-3x3x-fgf2-hxxv Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.2, 6.3, 6.3.1, 6.3.2, 6.3.3, and 6.3.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Data, Domain, and Function Security. | 1% Низкий | больше 3 лет назад | ||
GHSA-3x3w-vcjx-7796 Cross-Site Request Forgery in easyii CMS | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
GHSA-3x3w-ffg6-mp27 Cisco NX-OS 7.1(1)N1(1) on Nexus 5500, 5600, and 6000 devices does not properly validate PDUs in SNMP packets, which allows remote attackers to cause a denial of service (SNMP application restart) via a crafted packet, aka Bug ID CSCut84645. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-3x3w-849q-423v Xnx3 Wangmarket Cross-Site Scripting vulnerability | CVSS3: 4.7 | 0% Низкий | около 2 лет назад | |
GHSA-3x3v-84v2-gwh2 A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1. | CVSS3: 7.5 | 10% Низкий | больше 3 лет назад | |
GHSA-3x3r-mcv6-277v The WiMAX dissector in Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (crash) via unknown vectors related to "unaligned access on some platforms." | 1% Низкий | почти 4 года назад | ||
GHSA-3x3q-ghcp-whf7 Template Secret leakage in logs in Scaffolder when using `fetch:template` | CVSS3: 2.6 | 0% Низкий | 6 месяцев назад | |
GHSA-3x3q-3ch4-c25f A Privilege Escalation vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. Staff account users can access the admin resources and perform CRUD Operations. | CVSS3: 7.2 | 2% Низкий | около 4 лет назад | |
GHSA-3x3q-3c9j-4x72 In the Linux kernel, the following vulnerability has been resolved: Input: iforce - invert valid length check when fetching device IDs syzbot is reporting uninitialized value at iforce_init_device() [1], for commit 6ac0aec6b0a6 ("Input: iforce - allow callers supply data buffer when fetching device IDs") is checking that valid length is shorter than bytes to read. Since iforce_get_id_packet() stores valid length when returning 0, the caller needs to check that valid length is longer than or equals to bytes to read. | CVSS3: 5.5 | 0% Низкий | 9 месяцев назад | |
GHSA-3x3p-75r6-3954 Stack consumption vulnerability in the ChildProcessSecurityPolicy::CanRequestURL function in browser/child_process_security_policy.cc in Google Chrome before 4.0.249.78 allows remote attackers to cause a denial of service (memory consumption and application crash) via a URL that specifies multiple protocols, as demonstrated by a URL that begins with many repetitions of the view-source: substring. | 1% Низкий | почти 4 года назад | ||
GHSA-3x3p-2fwv-2ppj The HwPCAssistant module has the out-of-bounds read/write vulnerability. Successful exploitation of this vulnerability may affect confidentiality and integrity. | CVSS3: 9.1 | 0% Низкий | почти 3 года назад | |
GHSA-3x3m-p2wx-g7cw Unauthenticated File Read in PHP Proxy | CVSS3: 7.5 | 80% Высокий | больше 3 лет назад |
Уязвимостей на страницу