Количество 289 610
Количество 289 610
GHSA-27q2-f36g-hmv6
Unauth. Arbitrary File Download vulnerability in WatchTowerHQ plugin <= 3.6.15 on WordPress.
GHSA-27px-qpmj-qg38
Paste Script has improper group memberships permissions
GHSA-27px-4rjc-4chg
The following Yokogawa Electric products do not change the passwords of the internal Windows accounts from the initial configuration: CENTUM VP versions from R5.01.00 to R5.04.20 and versions from R6.01.00 to R6.08.0, Exaopc versions from R3.72.00 to R3.79.00.
GHSA-27pw-7wxg-pvx9
Improper access control vulnerability in Quick Share prior to 13.5.52.0 allows local attacker to access local files.
GHSA-27pw-27h4-97mx
net/ceph/auth_x.c in Ceph, as used in the Linux kernel before 3.16.3, does not properly validate auth replies, which allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via crafted data from the IP address of a Ceph Monitor.
GHSA-27pv-q55r-222g
Path traversal in github.com/ipfs/go-ipfs
GHSA-27pv-p83w-4xp4
Stack consumption vulnerability in the dissect_ber_unknown function in epan/dissectors/packet-ber.c in the BER dissector in Wireshark 1.4.x before 1.4.1 and 1.2.x before 1.2.12 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a long string in an unknown ASN.1/BER encoded packet, as demonstrated using SNMP.
GHSA-27pv-9qxj-gfj6
In RTTTL_Event of eas_rtttl.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-123700383
GHSA-27pv-53mj-ff4j
PHP remote file inclusion vulnerability in modules/rtmessageadd.php in LAN Management System (LMS) 1.5.3, and possibly 1.5.4, allows remote attackers to execute arbitrary PHP code via a URL in the _LIB_DIR parameter, a different vector than CVE-2007-1643.
GHSA-27pr-r7hm-c2rc
Missing permission check in Jenkins Dimensions Plugin allows enumerating credentials IDs
GHSA-27pr-43qm-8hmf
The LoadText method in the spreadsheet component in Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to read arbitrary files through Internet Explorer via a URL that redirects to the target file.
GHSA-27pq-p52w-4h65
Genesys PureConnect Interaction Web Tools Chat Service (up to at least 26- September- 2019) allows XSS within the Printable Chat History via the participant -> name JSON POST parameter.
GHSA-27pq-ccjc-wxmc
Sngrep v1.6.0 was discovered to contain a stack buffer overflow via the function packet_set_payload at /src/packet.c.
GHSA-27pp-94gr-r5v9
Cross-site scripting (XSS) vulnerability in vbshout.php in DragonByte Technologies vBShout module for vBulletin allows remote attackers to inject arbitrary web script or HTML via the shout parameter in a shout action.
GHSA-27pm-56m3-q426
TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘hour’ parameter of the setRebootScheCfg interface of the cstecgi .cgi.
GHSA-27ph-x57w-v4gm
Stack-based buffer overflow in the ast_uri_encode function in main/utils.c in Asterisk Open Source before 1.4.38.1, 1.4.39.1, 1.6.1.21, 1.6.2.15.1, 1.6.2.16.1, 1.8.1.2, 1.8.2.; and Business Edition before C.3.6.2; when running in pedantic mode allows remote authenticated users to execute arbitrary code via crafted caller ID data in vectors involving the (1) SIP channel driver, (2) URIENCODE dialplan function, or (3) AGI dialplan function.
GHSA-27pg-jvfh-7c97
Improper access control while doing XPU re-configuration dynamically can lead to unauthorized access to a secure resource in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wired Infrastructure and Networking
GHSA-27pg-f79j-mx3w
Memory corruption in WLAN HAL while passing command parameters through WMI interfaces.
GHSA-27pg-cfc8-4p42
Unspecified vulnerability in the Windows Media Player ActiveX control in Windows Media Player (WMP) 9 on Microsoft Windows 2000 SP4 and XP SP2 and SP3 allows remote attackers to execute arbitrary code via crafted media content, aka "Media Player Remote Code Execution Vulnerability."
GHSA-27pg-4cj6-8994
yuan1994 tpAdmin Unrestricted Upload of File with Dangerous Type vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-27q2-f36g-hmv6 Unauth. Arbitrary File Download vulnerability in WatchTowerHQ plugin <= 3.6.15 on WordPress. | CVSS3: 7.5 | 0% Низкий | почти 3 года назад | |
GHSA-27px-qpmj-qg38 Paste Script has improper group memberships permissions | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
GHSA-27px-4rjc-4chg The following Yokogawa Electric products do not change the passwords of the internal Windows accounts from the initial configuration: CENTUM VP versions from R5.01.00 to R5.04.20 and versions from R6.01.00 to R6.08.0, Exaopc versions from R3.72.00 to R3.79.00. | CVSS3: 9.8 | 0% Низкий | больше 3 лет назад | |
GHSA-27pw-7wxg-pvx9 Improper access control vulnerability in Quick Share prior to 13.5.52.0 allows local attacker to access local files. | CVSS3: 5.5 | 0% Низкий | почти 2 года назад | |
GHSA-27pw-27h4-97mx net/ceph/auth_x.c in Ceph, as used in the Linux kernel before 3.16.3, does not properly validate auth replies, which allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via crafted data from the IP address of a Ceph Monitor. | 5% Низкий | больше 3 лет назад | ||
GHSA-27pv-q55r-222g Path traversal in github.com/ipfs/go-ipfs | CVSS3: 7.7 | 2% Низкий | около 4 лет назад | |
GHSA-27pv-p83w-4xp4 Stack consumption vulnerability in the dissect_ber_unknown function in epan/dissectors/packet-ber.c in the BER dissector in Wireshark 1.4.x before 1.4.1 and 1.2.x before 1.2.12 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a long string in an unknown ASN.1/BER encoded packet, as demonstrated using SNMP. | 3% Низкий | больше 3 лет назад | ||
GHSA-27pv-9qxj-gfj6 In RTTTL_Event of eas_rtttl.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-123700383 | 0% Низкий | около 3 лет назад | ||
GHSA-27pv-53mj-ff4j PHP remote file inclusion vulnerability in modules/rtmessageadd.php in LAN Management System (LMS) 1.5.3, and possibly 1.5.4, allows remote attackers to execute arbitrary PHP code via a URL in the _LIB_DIR parameter, a different vector than CVE-2007-1643. | 5% Низкий | больше 3 лет назад | ||
GHSA-27pr-r7hm-c2rc Missing permission check in Jenkins Dimensions Plugin allows enumerating credentials IDs | CVSS3: 4.2 | 0% Низкий | около 2 лет назад | |
GHSA-27pr-43qm-8hmf The LoadText method in the spreadsheet component in Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to read arbitrary files through Internet Explorer via a URL that redirects to the target file. | 25% Средний | больше 3 лет назад | ||
GHSA-27pq-p52w-4h65 Genesys PureConnect Interaction Web Tools Chat Service (up to at least 26- September- 2019) allows XSS within the Printable Chat History via the participant -> name JSON POST parameter. | CVSS3: 6.1 | 0% Низкий | почти 3 года назад | |
GHSA-27pq-ccjc-wxmc Sngrep v1.6.0 was discovered to contain a stack buffer overflow via the function packet_set_payload at /src/packet.c. | CVSS3: 7.8 | 0% Низкий | больше 2 лет назад | |
GHSA-27pp-94gr-r5v9 Cross-site scripting (XSS) vulnerability in vbshout.php in DragonByte Technologies vBShout module for vBulletin allows remote attackers to inject arbitrary web script or HTML via the shout parameter in a shout action. | CVSS3: 6.1 | 1% Низкий | больше 3 лет назад | |
GHSA-27pm-56m3-q426 TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘hour’ parameter of the setRebootScheCfg interface of the cstecgi .cgi. | CVSS3: 9.8 | 0% Низкий | больше 1 года назад | |
GHSA-27ph-x57w-v4gm Stack-based buffer overflow in the ast_uri_encode function in main/utils.c in Asterisk Open Source before 1.4.38.1, 1.4.39.1, 1.6.1.21, 1.6.2.15.1, 1.6.2.16.1, 1.8.1.2, 1.8.2.; and Business Edition before C.3.6.2; when running in pedantic mode allows remote authenticated users to execute arbitrary code via crafted caller ID data in vectors involving the (1) SIP channel driver, (2) URIENCODE dialplan function, or (3) AGI dialplan function. | 1% Низкий | больше 3 лет назад | ||
GHSA-27pg-jvfh-7c97 Improper access control while doing XPU re-configuration dynamically can lead to unauthorized access to a secure resource in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wired Infrastructure and Networking | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-27pg-f79j-mx3w Memory corruption in WLAN HAL while passing command parameters through WMI interfaces. | CVSS3: 7.8 | 0% Низкий | почти 2 года назад | |
GHSA-27pg-cfc8-4p42 Unspecified vulnerability in the Windows Media Player ActiveX control in Windows Media Player (WMP) 9 on Microsoft Windows 2000 SP4 and XP SP2 and SP3 allows remote attackers to execute arbitrary code via crafted media content, aka "Media Player Remote Code Execution Vulnerability." | 61% Средний | больше 3 лет назад | ||
GHSA-27pg-4cj6-8994 yuan1994 tpAdmin Unrestricted Upload of File with Dangerous Type vulnerability | CVSS3: 7.2 | 0% Низкий | больше 2 лет назад |
Уязвимостей на страницу