Количество 290 064
Количество 290 064
GHSA-2cjm-j72p-vj2q
Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
GHSA-2cjm-cj9v-8j23
Cross-site scripting (XSS) vulnerability in index.php in phpLinks 2.1.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the term parameter.
GHSA-2cjm-39g8-5fv8
In Shanda MapleStory Online V160, the SdoKeyCrypt.sys driver allows privilege escalation to NT AUTHORITY\SYSTEM because of not validating the IOCtl 0x8000c01c input value, leading to an integer signedness error and a heap-based buffer underflow.
GHSA-2cjj-vh62-f62h
IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 through 6.0.6) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 145509.
GHSA-2cjj-7rx5-5hhq
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "Read Access Violation on Control Flow starting at Unknown Symbol @ 0x0000000003aa7cef called from Unknown Symbol @ 0x0000000004aa024d."
GHSA-2cjh-75gp-34gc
livewire Cross-Site Request Forgery vulnerability
GHSA-2cjg-pfcc-g8hr
In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related dissectors could crash. This was addressed in epan/dissectors/packet-ber.c by preventing a buffer overflow associated with excessive digits in time values.
GHSA-2cjg-6xm9-4wh6
IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 could allow remote attackers to bypass authentication via a direct request or forced browsing to a page other than URL intended. IBM X-Force ID: 142561.
GHSA-2cjf-w7c4-fhf6
Cross-site Scripting in Beanstalk console
GHSA-2cjf-q722-7gc5
SQL injection vulnerability in search_results.php in ABK-Soft AbleDating 2.4 allows remote attackers to execute arbitrary SQL commands via the keyword parameter.
GHSA-2cjf-4qjm-hh7v
An issue was discovered in Open Ticket Request System (OTRS) 6.0.x before 6.0.12. An attacker could send an e-mail message with a malicious link to an OTRS system or an agent. If a logged-in agent opens this link, it could cause the execution of JavaScript in the context of OTRS.
GHSA-2cjc-rgmp-x649
Traefik Missing Authentication
GHSA-2cjc-6xrh-7w5q
Missing Authorization vulnerability in ThemeSupport Hide Category by User Role for WooCommerce.This issue affects Hide Category by User Role for WooCommerce: from n/a through 2.1.1.
GHSA-2cjc-543p-gpj8
admin/default.php in PHPMyWind v5.5 has XSS via an HTTP Host header.
GHSA-2cj9-wjmr-5w57
An off-by-one error flaw was found in the udevListInterfacesByStatus() function in libvirt when the number of interfaces exceeds the size of the `names` array. This issue can be reproduced by sending specially crafted data to the libvirt daemon, allowing an unprivileged client to perform a denial of service attack by causing the libvirt daemon to crash.
GHSA-2cj9-r6h5-6jwg
ServerDocs Server in Apple OS X Server before 5.2 supports the RC4 cipher, which might allow remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.
GHSA-2cj8-f8jw-33qq
Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the key parameter to the getESRIExtraConfig task.
GHSA-2cj8-cg4w-q64p
Windows Kernel Elevation of Privilege Vulnerability
GHSA-2cj8-639j-6rq5
A vulnerability has been found in itwanger paicoding 1.0.3 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /article/app/post. The manipulation of the argument content leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
GHSA-2cj7-q7vw-gwx8
There is a path traversal vulnerability in ESRI ArcGIS Server versions 10.9.1 thru 11.3. Successful exploitation may allow a remote authenticated attacker with admin privileges to traverse the file system to access files outside of the intended directory. There is no impact to integrity or availability due to the nature of the files that can be accessed, but there is a potential high impact to confidentiality.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-2cjm-j72p-vj2q Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | CVSS3: 5.5 | 0% Низкий | почти 2 года назад | |
GHSA-2cjm-cj9v-8j23 Cross-site scripting (XSS) vulnerability in index.php in phpLinks 2.1.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the term parameter. | 0% Низкий | больше 3 лет назад | ||
GHSA-2cjm-39g8-5fv8 In Shanda MapleStory Online V160, the SdoKeyCrypt.sys driver allows privilege escalation to NT AUTHORITY\SYSTEM because of not validating the IOCtl 0x8000c01c input value, leading to an integer signedness error and a heap-based buffer underflow. | CVSS3: 7.8 | 2% Низкий | больше 3 лет назад | |
GHSA-2cjj-vh62-f62h IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 through 6.0.6) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 145509. | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
GHSA-2cjj-7rx5-5hhq STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "Read Access Violation on Control Flow starting at Unknown Symbol @ 0x0000000003aa7cef called from Unknown Symbol @ 0x0000000004aa024d." | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-2cjh-75gp-34gc livewire Cross-Site Request Forgery vulnerability | CVSS3: 8.8 | 2% Низкий | больше 1 года назад | |
GHSA-2cjg-pfcc-g8hr In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related dissectors could crash. This was addressed in epan/dissectors/packet-ber.c by preventing a buffer overflow associated with excessive digits in time values. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-2cjg-6xm9-4wh6 IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 could allow remote attackers to bypass authentication via a direct request or forced browsing to a page other than URL intended. IBM X-Force ID: 142561. | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
GHSA-2cjf-w7c4-fhf6 Cross-site Scripting in Beanstalk console | CVSS3: 6.3 | 0% Низкий | больше 3 лет назад | |
GHSA-2cjf-q722-7gc5 SQL injection vulnerability in search_results.php in ABK-Soft AbleDating 2.4 allows remote attackers to execute arbitrary SQL commands via the keyword parameter. | 0% Низкий | больше 3 лет назад | ||
GHSA-2cjf-4qjm-hh7v An issue was discovered in Open Ticket Request System (OTRS) 6.0.x before 6.0.12. An attacker could send an e-mail message with a malicious link to an OTRS system or an agent. If a logged-in agent opens this link, it could cause the execution of JavaScript in the context of OTRS. | CVSS3: 6.1 | 1% Низкий | больше 2 лет назад | |
GHSA-2cjc-rgmp-x649 Traefik Missing Authentication | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-2cjc-6xrh-7w5q Missing Authorization vulnerability in ThemeSupport Hide Category by User Role for WooCommerce.This issue affects Hide Category by User Role for WooCommerce: from n/a through 2.1.1. | CVSS3: 4.3 | 0% Низкий | 8 месяцев назад | |
GHSA-2cjc-543p-gpj8 admin/default.php in PHPMyWind v5.5 has XSS via an HTTP Host header. | CVSS3: 4.8 | 0% Низкий | больше 3 лет назад | |
GHSA-2cj9-wjmr-5w57 An off-by-one error flaw was found in the udevListInterfacesByStatus() function in libvirt when the number of interfaces exceeds the size of the `names` array. This issue can be reproduced by sending specially crafted data to the libvirt daemon, allowing an unprivileged client to perform a denial of service attack by causing the libvirt daemon to crash. | CVSS3: 5.5 | 0% Низкий | больше 1 года назад | |
GHSA-2cj9-r6h5-6jwg ServerDocs Server in Apple OS X Server before 5.2 supports the RC4 cipher, which might allow remote attackers to defeat cryptographic protection mechanisms via unspecified vectors. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-2cj8-f8jw-33qq Cross-Site Scripting (XSS) vulnerability in MicroStrategy Web SDK 10.11 and earlier, allows remote unauthenticated attackers to execute arbitrary code via the key parameter to the getESRIExtraConfig task. | CVSS3: 6.1 | 2% Низкий | больше 3 лет назад | |
GHSA-2cj8-cg4w-q64p Windows Kernel Elevation of Privilege Vulnerability | CVSS3: 7.8 | 6% Низкий | около 3 лет назад | |
GHSA-2cj8-639j-6rq5 A vulnerability has been found in itwanger paicoding 1.0.3 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /article/app/post. The manipulation of the argument content leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 3.5 | 0% Низкий | 4 месяца назад | |
GHSA-2cj7-q7vw-gwx8 There is a path traversal vulnerability in ESRI ArcGIS Server versions 10.9.1 thru 11.3. Successful exploitation may allow a remote authenticated attacker with admin privileges to traverse the file system to access files outside of the intended directory. There is no impact to integrity or availability due to the nature of the files that can be accessed, but there is a potential high impact to confidentiality. | CVSS3: 4.9 | 0% Низкий | 6 месяцев назад |
Уязвимостей на страницу