Количество 314 458
Количество 314 458
GHSA-3w95-3q7c-6v47
services/go.php in Horde Application Framework 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1 does not properly restrict its image proxy capability, which allows remote attackers to perform "Web tunneling" attacks and use the server as a proxy via (1) http, (2) https, and (3) ftp URL in the url parameter, which is requested from the server.
GHSA-3w94-w3gc-69pw
SQL injection vulnerability in sorter.php in the phpManufaktur kitForm extension 0.43 and earlier for the KeepInTouch (KIT) module allows remote attackers to execute arbitrary SQL commands via the sorter_value parameter.
GHSA-3w94-vq2x-v5wr
ethereum does not check transaction malleability for EIP-2930, EIP-1559 and EIP-7702 transactions
GHSA-3w94-4jxf-2v59
SQL injection vulnerability in gallery.php in MyCard 1.0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
GHSA-3w93-xggv-pqrq
IBM Jazz Foundation (IBM Rational Engineering Lifecycle Manager 5.0 through 6.0.6) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152740.
GHSA-3w8x-qf95-v2x7
Stack-based buffer overflow in Novell iPrint Client before 5.90 allows remote attackers to execute arbitrary code via unspecified vectors.
GHSA-3w8x-p539-469j
In query of DownloadManager.java, there is a possible read/write of arbitrary files due to a permissions bypass. This could lead to local information disclosure and file rewriting with no additional execution privileges needed. User interaction is not needed for exploitation.
GHSA-3w8x-76pc-54fp
The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-information page.
GHSA-3w8w-mhj7-j5rc
systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation methodology is to crash a binary calling the same function recursively, and put it in a deeply nested directory to make its backtrace large enough to cause the deadlock. This must be done 16 times when MaxConnections=16 is set for the systemd/units/systemd-coredump.socket file.
GHSA-3w8w-875g-xvfg
Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow a NULL pointer dereference when this.Span is used for oState of Collab.addStateModel, because this.Span.text can be NULL.
GHSA-3w8r-3jh9-89v9
xxl-job-admin vulnerable to Insecure Permissions
GHSA-3w8r-2x8f-g5jx
It was reported that watchman in openshift node-utils creates /var/run/watchman.pid and /var/log/watchman.ouput with world writable permission.
GHSA-3w8q-xq97-5j7x
Rhino has high CPU usage and potential DoS when passing specific numbers to `toFixed()` function
GHSA-3w8q-xg7c-33gv
syslogd in the syslog subsystem in Apple iOS before 8 and Apple TV before 7 allows local users to change the permissions of arbitrary files via a symlink attack on an unspecified file.
GHSA-3w8q-vg6g-cg46
In the Linux kernel, the following vulnerability has been resolved: crypto: lib/mpi - avoid null pointer deref in mpi_cmp_ui() During NVMeTCP Authentication a controller can trigger a kernel oops by specifying the 8192 bit Diffie Hellman group and passing a correctly sized, but zeroed Diffie Hellamn value. mpi_cmp_ui() was detecting this if the second parameter was 0, but 1 is passed from dh_is_pubkey_valid(). This causes the null pointer u->d to be dereferenced towards the end of mpi_cmp_ui()
GHSA-3w8q-3783-r4v7
A vulnerability classified as problematic was found in LitmusChaos Litmus up to 3.19.0. Affected by this vulnerability is an unknown functionality. The manipulation of the argument projectID leads to improper control of resource identifiers. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-3w8p-p9qm-vg44
crosh in Google Chrome OS before 33.0.1750.152 allows attackers to inject commands via unspecified vectors.
GHSA-3w8p-gqqp-6g99
Cross-site scripting (XSS) vulnerability in phpXplorer 0.9.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the address bar field.
GHSA-3w8p-5pg9-6v3j
Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
GHSA-3w8p-33h3-h7v6
Microsoft Excel Remote Code Execution Vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3w95-3q7c-6v47 services/go.php in Horde Application Framework 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1 does not properly restrict its image proxy capability, which allows remote attackers to perform "Web tunneling" attacks and use the server as a proxy via (1) http, (2) https, and (3) ftp URL in the url parameter, which is requested from the server. | 2% Низкий | почти 4 года назад | ||
GHSA-3w94-w3gc-69pw SQL injection vulnerability in sorter.php in the phpManufaktur kitForm extension 0.43 and earlier for the KeepInTouch (KIT) module allows remote attackers to execute arbitrary SQL commands via the sorter_value parameter. | 0% Низкий | больше 3 лет назад | ||
GHSA-3w94-vq2x-v5wr ethereum does not check transaction malleability for EIP-2930, EIP-1559 and EIP-7702 transactions | 0% Низкий | 7 месяцев назад | ||
GHSA-3w94-4jxf-2v59 SQL injection vulnerability in gallery.php in MyCard 1.0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter. | 0% Низкий | больше 3 лет назад | ||
GHSA-3w93-xggv-pqrq IBM Jazz Foundation (IBM Rational Engineering Lifecycle Manager 5.0 through 6.0.6) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152740. | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
GHSA-3w8x-qf95-v2x7 Stack-based buffer overflow in Novell iPrint Client before 5.90 allows remote attackers to execute arbitrary code via unspecified vectors. | 13% Средний | больше 3 лет назад | ||
GHSA-3w8x-p539-469j In query of DownloadManager.java, there is a possible read/write of arbitrary files due to a permissions bypass. This could lead to local information disclosure and file rewriting with no additional execution privileges needed. User interaction is not needed for exploitation. | CVSS3: 7.7 | 0% Низкий | около 1 года назад | |
GHSA-3w8x-76pc-54fp The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-information page. | CVSS3: 7.5 | 11% Средний | больше 3 лет назад | |
GHSA-3w8w-mhj7-j5rc systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation methodology is to crash a binary calling the same function recursively, and put it in a deeply nested directory to make its backtrace large enough to cause the deadlock. This must be done 16 times when MaxConnections=16 is set for the systemd/units/systemd-coredump.socket file. | CVSS3: 5.5 | 0% Низкий | около 3 лет назад | |
GHSA-3w8w-875g-xvfg Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow a NULL pointer dereference when this.Span is used for oState of Collab.addStateModel, because this.Span.text can be NULL. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-3w8r-3jh9-89v9 xxl-job-admin vulnerable to Insecure Permissions | CVSS3: 5.4 | 0% Низкий | около 2 лет назад | |
GHSA-3w8r-2x8f-g5jx It was reported that watchman in openshift node-utils creates /var/run/watchman.pid and /var/log/watchman.ouput with world writable permission. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-3w8q-xq97-5j7x Rhino has high CPU usage and potential DoS when passing specific numbers to `toFixed()` function | 0% Низкий | 2 месяца назад | ||
GHSA-3w8q-xg7c-33gv syslogd in the syslog subsystem in Apple iOS before 8 and Apple TV before 7 allows local users to change the permissions of arbitrary files via a symlink attack on an unspecified file. | 0% Низкий | больше 3 лет назад | ||
GHSA-3w8q-vg6g-cg46 In the Linux kernel, the following vulnerability has been resolved: crypto: lib/mpi - avoid null pointer deref in mpi_cmp_ui() During NVMeTCP Authentication a controller can trigger a kernel oops by specifying the 8192 bit Diffie Hellman group and passing a correctly sized, but zeroed Diffie Hellamn value. mpi_cmp_ui() was detecting this if the second parameter was 0, but 1 is passed from dh_is_pubkey_valid(). This causes the null pointer u->d to be dereferenced towards the end of mpi_cmp_ui() | 0% Низкий | 2 месяца назад | ||
GHSA-3w8q-3783-r4v7 A vulnerability classified as problematic was found in LitmusChaos Litmus up to 3.19.0. Affected by this vulnerability is an unknown functionality. The manipulation of the argument projectID leads to improper control of resource identifiers. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 4.3 | 0% Низкий | 6 месяцев назад | |
GHSA-3w8p-p9qm-vg44 crosh in Google Chrome OS before 33.0.1750.152 allows attackers to inject commands via unspecified vectors. | 0% Низкий | больше 3 лет назад | ||
GHSA-3w8p-gqqp-6g99 Cross-site scripting (XSS) vulnerability in phpXplorer 0.9.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the address bar field. | 0% Низкий | почти 4 года назад | ||
GHSA-3w8p-5pg9-6v3j Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | CVSS3: 5.5 | 0% Низкий | 7 месяцев назад | |
GHSA-3w8p-33h3-h7v6 Microsoft Excel Remote Code Execution Vulnerability | CVSS3: 7.8 | 7% Низкий | больше 3 лет назад |
Уязвимостей на страницу