Количество 314 458
Количество 314 458
GHSA-3w37-5p3p-jv92
Apache CXF vulnerable to Exposure of Sensitive Information
GHSA-3w36-wf5x-rjfv
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code.
GHSA-3w36-ppm5-2f9j
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
GHSA-3w34-xv7m-phqr
Insufficient validation of untrusted input in Blink in Google Chrome prior to 79.0.3945.79 allowed a local attacker to bypass same origin policy via crafted clipboard content.
GHSA-3w33-h749-fgfr
Inappropriate implementation in cryptohome in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker who had compromised the browser process to bypass discretionary access control via a malicious file.
GHSA-3w32-vr93-jm7m
An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The sort_by and start parameter can be used to perform an SQL injection attack. An attacker can use a browser to trigger these vulnerabilities, and no special tools are required.
GHSA-3w2x-jhm7-3gw3
Y.SAK allows remote attackers to execute arbitrary commands via shell metacharacters in the $no variable to (1) w_s3mbfm.cgi, (2) w_s3adix.cgi, or (3) w_s3sbfm.cgi.
GHSA-3w2x-9vcq-46w8
The IsPixelGray function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3-8 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted image file.
GHSA-3w2w-73h7-hq3v
Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the NodeName2 parameter.
GHSA-3w2w-5pxh-222c
dirapi.dll in Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2581, CVE-2010-4085, CVE-2010-4086, and CVE-2010-4088.
GHSA-3w2w-4v6h-c6q9
The xfs_fs_geometry function in fs/xfs/xfs_fsops.c in the Linux kernel before 2.6.38-rc6-git3 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an FSGEOMETRY_V1 ioctl call.
GHSA-3w2v-v5mv-qqrj
A command injection vulnerability exists in the download and convert report feature of the ScienceLogic SL1 that takes unsanitized user?controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system.
GHSA-3w2v-f8x7-qc92
Missing Authorization vulnerability in rtCamp rtMedia for WordPress, BuddyPress and bbPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects rtMedia for WordPress, BuddyPress and bbPress: from n/a through 4.6.14.
GHSA-3w2m-22gp-wc5v
phpProfiles before 2.1.1 uses world writable permissions for certain profile files and directories, which allows local users to modify or delete files, related to (1) users/include/do_makeprofile.inc.php and (2) users/include/copy.inc.php.
GHSA-3w2j-mvmp-4vx3
Transient DOS while processing DL NAS Transport message, as specified in 3GPP 24.501 v16.
GHSA-3w2j-jf2v-w2v3
The vivid_fb_ioctl function in drivers/media/platform/vivid/vivid-osd.c in the Linux kernel through 4.3.3 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory via a crafted application.
GHSA-3w2h-f87x-m6vp
Memory safety bugs present in Firefox 60 and Firefox ESR 60. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, and Firefox < 61.
GHSA-3w2h-8364-7v9m
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
GHSA-3w2h-6gvg-jj2v
Use after free in Extensions in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
GHSA-3w2f-j9r3-9h89
Microsoft Outlook Security Feature Bypass Vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3w37-5p3p-jv92 Apache CXF vulnerable to Exposure of Sensitive Information | CVSS3: 7.5 | 0% Низкий | около 3 лет назад | |
GHSA-3w36-wf5x-rjfv Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code. | CVSS3: 8.1 | 93% Критический | больше 3 лет назад | |
GHSA-3w36-ppm5-2f9j Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | CVSS3: 8.8 | 0% Низкий | почти 3 года назад | |
GHSA-3w34-xv7m-phqr Insufficient validation of untrusted input in Blink in Google Chrome prior to 79.0.3945.79 allowed a local attacker to bypass same origin policy via crafted clipboard content. | CVSS3: 8.8 | 2% Низкий | больше 3 лет назад | |
GHSA-3w33-h749-fgfr Inappropriate implementation in cryptohome in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker who had compromised the browser process to bypass discretionary access control via a malicious file. | 0% Низкий | больше 3 лет назад | ||
GHSA-3w32-vr93-jm7m An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The sort_by and start parameter can be used to perform an SQL injection attack. An attacker can use a browser to trigger these vulnerabilities, and no special tools are required. | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад | |
GHSA-3w2x-jhm7-3gw3 Y.SAK allows remote attackers to execute arbitrary commands via shell metacharacters in the $no variable to (1) w_s3mbfm.cgi, (2) w_s3adix.cgi, or (3) w_s3sbfm.cgi. | 2% Низкий | почти 4 года назад | ||
GHSA-3w2x-9vcq-46w8 The IsPixelGray function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3-8 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted image file. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-3w2w-73h7-hq3v Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the NodeName2 parameter. | 2% Низкий | больше 3 лет назад | ||
GHSA-3w2w-5pxh-222c dirapi.dll in Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2581, CVE-2010-4085, CVE-2010-4086, and CVE-2010-4088. | 6% Низкий | больше 3 лет назад | ||
GHSA-3w2w-4v6h-c6q9 The xfs_fs_geometry function in fs/xfs/xfs_fsops.c in the Linux kernel before 2.6.38-rc6-git3 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an FSGEOMETRY_V1 ioctl call. | 0% Низкий | больше 3 лет назад | ||
GHSA-3w2v-v5mv-qqrj A command injection vulnerability exists in the download and convert report feature of the ScienceLogic SL1 that takes unsanitized user?controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system. | CVSS3: 8.8 | 0% Низкий | больше 2 лет назад | |
GHSA-3w2v-f8x7-qc92 Missing Authorization vulnerability in rtCamp rtMedia for WordPress, BuddyPress and bbPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects rtMedia for WordPress, BuddyPress and bbPress: from n/a through 4.6.14. | CVSS3: 4.3 | 0% Низкий | около 1 года назад | |
GHSA-3w2m-22gp-wc5v phpProfiles before 2.1.1 uses world writable permissions for certain profile files and directories, which allows local users to modify or delete files, related to (1) users/include/do_makeprofile.inc.php and (2) users/include/copy.inc.php. | 0% Низкий | почти 4 года назад | ||
GHSA-3w2j-mvmp-4vx3 Transient DOS while processing DL NAS Transport message, as specified in 3GPP 24.501 v16. | CVSS3: 7.5 | 0% Низкий | почти 2 года назад | |
GHSA-3w2j-jf2v-w2v3 The vivid_fb_ioctl function in drivers/media/platform/vivid/vivid-osd.c in the Linux kernel through 4.3.3 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory via a crafted application. | CVSS3: 2.3 | 0% Низкий | больше 3 лет назад | |
GHSA-3w2h-f87x-m6vp Memory safety bugs present in Firefox 60 and Firefox ESR 60. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, and Firefox < 61. | CVSS3: 9.8 | 2% Низкий | больше 3 лет назад | |
GHSA-3w2h-8364-7v9m Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | 9 месяцев назад | |||
GHSA-3w2h-6gvg-jj2v Use after free in Extensions in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | CVSS3: 8.8 | 1% Низкий | больше 1 года назад | |
GHSA-3w2f-j9r3-9h89 Microsoft Outlook Security Feature Bypass Vulnerability | CVSS3: 8.8 | 0% Низкий | больше 2 лет назад |
Уязвимостей на страницу