Количество 288 896
Количество 288 896
GHSA-269j-37ww-cmh3
Mezzanine CMS vulnerable to Cross-site Scripting
GHSA-269h-pcpx-q5mj
Use after free in Browser UI in Google Chrome on Chrome OS prior to 99.0.4844.74 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.
GHSA-269h-hc79-qjpf
LOYTEC electronics GmbH LINX-212 firmware 6.2.4 and LINX-151 Firmware 7.2.4 are vulnerable to Incorrect Access Control via registry.xml file. This vulnerability allows remote attackers to disclose sensitive information on LINX configuration.
GHSA-269h-2wf7-8247
The license-installation module on the Cisco Nexus 1000V switch 4.2(1)SV1(5.2b) and earlier for VMware vSphere, Cisco Nexus 1000V switch 5.2(1)SM1(5.1) for Microsoft Hyper-V, and Cisco Virtual Security Gateway 4.2(1)VSG1(1) for Nexus 1000V switches allows local users to gain privileges and execute arbitrary commands via crafted "install all iso" arguments, aka Bug ID CSCui21340.
GHSA-269g-pwp5-87pp
TemporaryFolder on unix-like systems does not limit access to created files
GHSA-269g-6r83-cfhc
Chamilo LMS version 1.11.8 contains XSS in main/social/group_view.php in the social groups tool, allowing authenticated users to affect other users, under specific conditions of permissions granted by administrators. This is considered "low risk" due to the nature of the feature it exploits.
GHSA-269f-h4cx-j3fr
An issue was discovered in the MediaWikiChat extension for MediaWiki through 1.42.1. CSRF can occur in API modules.
GHSA-269f-c6h8-6gv2
A vulnerability was found in saxman maps-js-icoads. It has been classified as problematic. Affected is an unknown function. The manipulation leads to exposure of information through directory listing. It is possible to launch the attack remotely. The name of the patch is 34b8b0cce2807b119f4cffda2ac48fc8f427d69a. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217644.
GHSA-269f-8j25-5mp2
An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. The "runtar" setuid root binary does not check for additional arguments supplied after --create, allowing users to manipulate commands and perform command injection as root.
GHSA-269c-5w5q-frxq
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme nectar Salient Core allows Stored XSS.This issue affects Salient Core: from n/a through 2.0.2.
GHSA-269c-4g57-c9vg
An issue was discovered in GitLab CE/EE affecting all versions starting from 12.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows for an attacker to cause a denial of service using a crafted OpenAPI file.
GHSA-2699-8r69-fq67
Amanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/rundump will execute /usr/sbin/dump as root with controlled arguments from the attacker which may lead to escalation of privileges, denial of service, and information disclosure.
GHSA-2698-gwhq-x693
IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to an "Error Code (0xe06d7363) starting at wow64!Wow64NotifyDebugger+0x000000000000001d."
GHSA-2697-j9w4-39rc
Windows Error Reporting Service Elevation of Privilege Vulnerability
GHSA-2697-96mv-3gfm
TeamPass does not properly check whether a folder is in a user's allowed folders list
GHSA-2697-5v76-cfvp
Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly initialize a memory address, aka "Windows Kernel Information Disclosure Vulnerability".
GHSA-2697-3jf6-rpjg
The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges via unspecified vectors.
GHSA-2696-m9wq-rxcm
Stack-based buffer overflow in Easy RM to MP3 Converter allows remote attackers to execute arbitrary code via a long filename in a playlist (.pls) file.
GHSA-2696-454c-76j5
Under certain conditions a malicious user provoking a Null Pointer dereference can prevent legitimate users from accessing the SAP Internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, and its services.
GHSA-2694-c6mx-8fhj
A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Service List Section in login panel.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-269j-37ww-cmh3 Mezzanine CMS vulnerable to Cross-site Scripting | CVSS3: 4.8 | 0% Низкий | 21 день назад | |
GHSA-269h-pcpx-q5mj Use after free in Browser UI in Google Chrome on Chrome OS prior to 99.0.4844.74 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page. | CVSS3: 9.6 | 1% Низкий | около 3 лет назад | |
GHSA-269h-hc79-qjpf LOYTEC electronics GmbH LINX-212 firmware 6.2.4 and LINX-151 Firmware 7.2.4 are vulnerable to Incorrect Access Control via registry.xml file. This vulnerability allows remote attackers to disclose sensitive information on LINX configuration. | CVSS3: 7.5 | 0% Низкий | больше 1 года назад | |
GHSA-269h-2wf7-8247 The license-installation module on the Cisco Nexus 1000V switch 4.2(1)SV1(5.2b) and earlier for VMware vSphere, Cisco Nexus 1000V switch 5.2(1)SM1(5.1) for Microsoft Hyper-V, and Cisco Virtual Security Gateway 4.2(1)VSG1(1) for Nexus 1000V switches allows local users to gain privileges and execute arbitrary commands via crafted "install all iso" arguments, aka Bug ID CSCui21340. | 0% Низкий | около 3 лет назад | ||
GHSA-269g-pwp5-87pp TemporaryFolder on unix-like systems does not limit access to created files | CVSS3: 4.4 | 0% Низкий | почти 5 лет назад | |
GHSA-269g-6r83-cfhc Chamilo LMS version 1.11.8 contains XSS in main/social/group_view.php in the social groups tool, allowing authenticated users to affect other users, under specific conditions of permissions granted by administrators. This is considered "low risk" due to the nature of the feature it exploits. | CVSS3: 5.4 | 0% Низкий | около 3 лет назад | |
GHSA-269f-h4cx-j3fr An issue was discovered in the MediaWikiChat extension for MediaWiki through 1.42.1. CSRF can occur in API modules. | CVSS3: 6.5 | 0% Низкий | около 1 года назад | |
GHSA-269f-c6h8-6gv2 A vulnerability was found in saxman maps-js-icoads. It has been classified as problematic. Affected is an unknown function. The manipulation leads to exposure of information through directory listing. It is possible to launch the attack remotely. The name of the patch is 34b8b0cce2807b119f4cffda2ac48fc8f427d69a. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217644. | CVSS3: 5.3 | 0% Низкий | больше 2 лет назад | |
GHSA-269f-8j25-5mp2 An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. The "runtar" setuid root binary does not check for additional arguments supplied after --create, allowing users to manipulate commands and perform command injection as root. | CVSS3: 7.8 | 0% Низкий | около 3 лет назад | |
GHSA-269c-5w5q-frxq Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme nectar Salient Core allows Stored XSS.This issue affects Salient Core: from n/a through 2.0.2. | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
GHSA-269c-4g57-c9vg An issue was discovered in GitLab CE/EE affecting all versions starting from 12.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows for an attacker to cause a denial of service using a crafted OpenAPI file. | CVSS3: 5.3 | 0% Низкий | около 1 года назад | |
GHSA-2699-8r69-fq67 Amanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/rundump will execute /usr/sbin/dump as root with controlled arguments from the attacker which may lead to escalation of privileges, denial of service, and information disclosure. | CVSS3: 7.8 | 0% Низкий | больше 2 лет назад | |
GHSA-2698-gwhq-x693 IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to an "Error Code (0xe06d7363) starting at wow64!Wow64NotifyDebugger+0x000000000000001d." | CVSS3: 7.8 | 0% Низкий | около 3 лет назад | |
GHSA-2697-j9w4-39rc Windows Error Reporting Service Elevation of Privilege Vulnerability | CVSS3: 7 | 0% Низкий | больше 2 лет назад | |
GHSA-2697-96mv-3gfm TeamPass does not properly check whether a folder is in a user's allowed folders list | CVSS3: 4.3 | 0% Низкий | 8 месяцев назад | |
GHSA-2697-5v76-cfvp Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly initialize a memory address, aka "Windows Kernel Information Disclosure Vulnerability". | CVSS3: 5.5 | 23% Средний | около 3 лет назад | |
GHSA-2697-3jf6-rpjg The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges via unspecified vectors. | CVSS3: 7.8 | 29% Средний | около 3 лет назад | |
GHSA-2696-m9wq-rxcm Stack-based buffer overflow in Easy RM to MP3 Converter allows remote attackers to execute arbitrary code via a long filename in a playlist (.pls) file. | 6% Низкий | больше 3 лет назад | ||
GHSA-2696-454c-76j5 Under certain conditions a malicious user provoking a Null Pointer dereference can prevent legitimate users from accessing the SAP Internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, and its services. | CVSS3: 6.5 | 0% Низкий | около 3 лет назад | |
GHSA-2694-c6mx-8fhj A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Service List Section in login panel. | 4% Низкий | больше 3 лет назад |
Уязвимостей на страницу