Количество 314 458
Количество 314 458
GHSA-3rcf-hxhh-73gh
Sendmail 8.6.9 allows remote attackers to execute root commands, using ident.
GHSA-3rcf-g93x-vh3q
Missing Authorization vulnerability in Jose Specific Content For Mobile allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Specific Content For Mobile: from n/a through 0.5.3.
GHSA-3rcc-385q-f2hc
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the getPageNthWordQuads method. By performing actions in JavaScript, an attacker can trigger a type confusion condition. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-6022.
GHSA-3rcc-2gfp-q4g4
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the category.php chid1 parameter.
GHSA-3rc9-qgq4-2p4w
There is a local privilege escalation vulnerability in Alfredo Milani Comparetti SpeedFan 4.52. Attackers can use constructed programs to increase user privileges
GHSA-3rc9-f2pv-xp95
After Effects versions 23.6.9, 24.6.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
GHSA-3rc9-46g7-hmvc
In modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed
GHSA-3rc8-xjj4-xjp5
OKI Configuration Tool 1.6.53 contains an unquoted service path vulnerability in the OKI Local Port Manager service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Okidata\Common\extend3\portmgrsrv.exe' to inject malicious executables and escalate privileges.
GHSA-3rc8-cff9-mc2h
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions that are affected are 10 and 11.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via NFS to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Solaris. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
GHSA-3rc7-xw9f-vv26
COYO 9.0.8, 10.0.11 and 12.0.4 has cross-site scripting (XSS) via URLs used by "iFrame" widgets.
GHSA-3rc6-mcgh-8jqq
WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled.
GHSA-3rc5-9269-w9hr
delete.php in Prozilla Top 100 1.2 allows remote authenticated users to delete statistics and accounts of arbitrary users via a modified s parameter.
GHSA-3rc5-4jr8-p23m
In the address bar, Firefox for Android truncated the display of URLs from the end instead of prioritizing the origin. This vulnerability affects Firefox < 141.
GHSA-3rc4-q7c3-jfpm
The XML parser in IBM Rational DOORS Next Generation 4.x before 4.0.7 iFix3 and 5.x before 5.0.2 and Rational Requirements Composer 2.x and 3.x before 3.0.1.6 iFix5 and 4.x before 4.0.7 iFix3 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
GHSA-3rc3-5g2j-xqjq
Integer Overflow or Wraparound vulnerability in MuntashirAkon AppManager (app/src/main/java/org/apache/commons/compress/archivers/tar modules). This vulnerability is associated with program files TarUtils.Java. This issue affects AppManager: before 4.0.4.
GHSA-3rc2-qxqr-p57v
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3/IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
GHSA-3rc2-78m3-cqmh
Best Practical Request Tracker (RT) before 4.4.9, 5.0.9, and 6.0.2 allows CSV Injection via ticket values when TSV export is used.
GHSA-3r9x-rvv2-cq7m
Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,".
GHSA-3r9x-mjrm-2725
Prototype pollution vulnerability in 'libnested'
GHSA-3r9x-86qj-c5f2
PHP remote file inclusion vulnerability in admin.treeg.php in the Flash Tree Gallery (com_treeg) component 1.0 for Joomla!, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the mosConfig_live_site parameter.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3rcf-hxhh-73gh Sendmail 8.6.9 allows remote attackers to execute root commands, using ident. | 3% Низкий | почти 4 года назад | ||
GHSA-3rcf-g93x-vh3q Missing Authorization vulnerability in Jose Specific Content For Mobile allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Specific Content For Mobile: from n/a through 0.5.3. | CVSS3: 4.3 | 0% Низкий | 11 месяцев назад | |
GHSA-3rcc-385q-f2hc This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the getPageNthWordQuads method. By performing actions in JavaScript, an attacker can trigger a type confusion condition. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-6022. | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад | |
GHSA-3rcc-2gfp-q4g4 PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the category.php chid1 parameter. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-3rc9-qgq4-2p4w There is a local privilege escalation vulnerability in Alfredo Milani Comparetti SpeedFan 4.52. Attackers can use constructed programs to increase user privileges | 0% Низкий | больше 3 лет назад | ||
GHSA-3rc9-f2pv-xp95 After Effects versions 23.6.9, 24.6.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | CVSS3: 7.8 | 0% Низкий | около 1 года назад | |
GHSA-3rc9-46g7-hmvc In modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed | CVSS3: 7.5 | 0% Низкий | 2 месяца назад | |
GHSA-3rc8-xjj4-xjp5 OKI Configuration Tool 1.6.53 contains an unquoted service path vulnerability in the OKI Local Port Manager service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Okidata\Common\extend3\portmgrsrv.exe' to inject malicious executables and escalate privileges. | CVSS3: 7.8 | 0% Низкий | 18 дней назад | |
GHSA-3rc8-cff9-mc2h Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions that are affected are 10 and 11.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via NFS to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Solaris. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). | CVSS3: 7.5 | 6% Низкий | больше 3 лет назад | |
GHSA-3rc7-xw9f-vv26 COYO 9.0.8, 10.0.11 and 12.0.4 has cross-site scripting (XSS) via URLs used by "iFrame" widgets. | CVSS3: 6.1 | 2% Низкий | больше 3 лет назад | |
GHSA-3rc6-mcgh-8jqq WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled. | CVSS3: 6.1 | 3% Низкий | больше 3 лет назад | |
GHSA-3rc5-9269-w9hr delete.php in Prozilla Top 100 1.2 allows remote authenticated users to delete statistics and accounts of arbitrary users via a modified s parameter. | 4% Низкий | почти 4 года назад | ||
GHSA-3rc5-4jr8-p23m In the address bar, Firefox for Android truncated the display of URLs from the end instead of prioritizing the origin. This vulnerability affects Firefox < 141. | CVSS3: 5.3 | 0% Низкий | 6 месяцев назад | |
GHSA-3rc4-q7c3-jfpm The XML parser in IBM Rational DOORS Next Generation 4.x before 4.0.7 iFix3 and 5.x before 5.0.2 and Rational Requirements Composer 2.x and 3.x before 3.0.1.6 iFix5 and 4.x before 4.0.7 iFix3 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564. | 1% Низкий | больше 3 лет назад | ||
GHSA-3rc3-5g2j-xqjq Integer Overflow or Wraparound vulnerability in MuntashirAkon AppManager (app/src/main/java/org/apache/commons/compress/archivers/tar modules). This vulnerability is associated with program files TarUtils.Java. This issue affects AppManager: before 4.0.4. | 0% Низкий | 12 дней назад | ||
GHSA-3rc2-qxqr-p57v Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3/IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). | CVSS3: 7.5 | 2% Низкий | почти 4 года назад | |
GHSA-3rc2-78m3-cqmh Best Practical Request Tracker (RT) before 4.4.9, 5.0.9, and 6.0.2 allows CSV Injection via ticket values when TSV export is used. | CVSS3: 2.6 | 0% Низкий | 23 дня назад | |
GHSA-3r9x-rvv2-cq7m Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,". | 5% Низкий | больше 3 лет назад | ||
GHSA-3r9x-mjrm-2725 Prototype pollution vulnerability in 'libnested' | CVSS3: 9.8 | 3% Низкий | больше 4 лет назад | |
GHSA-3r9x-86qj-c5f2 PHP remote file inclusion vulnerability in admin.treeg.php in the Flash Tree Gallery (com_treeg) component 1.0 for Joomla!, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the mosConfig_live_site parameter. | 21% Средний | больше 3 лет назад |
Уязвимостей на страницу