Количество 288 388
Количество 288 388
GHSA-252h-69rw-g2rp
The str_buf_cat function in string.c in Ruby 1.9.3, 2.0.0, and 2.1 allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string.
GHSA-252h-2cmq-pmr6
easywebpack-cli Path Traversal vulnerability
GHSA-252g-gw8q-x2cc
OpenShift Container Platform before version 4.1.3 writes OAuth tokens in plaintext to the audit logs for the Kubernetes API server and OpenShift API server. A user with sufficient privileges could recover OAuth tokens from these audit logs and use them to access other resources.
GHSA-252g-9rpq-c6xw
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis VSS Doctor (Windows) before build 53
GHSA-252f-47x2-rgxx
A SQL injection vulnerability in a Trend Micro Email Encryption Gateway 5.5 policy script could allow an attacker to execute SQL commands to upload and execute arbitrary code that may harm the target system.
GHSA-252c-46fv-6xqv
ServerManagement master branch as of commit 49491cc6f94980e6be7791d17be947c27071eb56 is affected by a directory traversal vulnerability. This vulnerability can be used to extract credentials which can in turn be used to execute code.
GHSA-2529-rwp4-75f6
It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed article -> Website" or in the standard format of "View -> Feed article -> default format". This vulnerability affects Thunderbird < 52.5.2.
GHSA-2529-cmp4-x7vg
HP-UX aserver program allows local users to gain privileges via a symlink attack.
GHSA-2528-h86j-954v
In JetBrains TeamCity before 2021.1.3, a newly created project could take settings from an already deleted project.
GHSA-2527-g53r-vw26
In HarmfulAppWarningActivity of HarmfulAppWarningActivity.java, there is a possible way to trick victim to install harmful app due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-205595291
GHSA-2526-24jx-77pp
Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file. This is achieved through running a malicious script or program on the target machine.
GHSA-2524-6f4r-2jq9
SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious commands with root privileges in SAP Host Agent via SAP Landscape Management.
GHSA-2524-2jp2-r468
SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
GHSA-2523-xvgc-mmh8
Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability
GHSA-2523-vcxw-6v95
In libhidcommand_jni, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the USB service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111363077
GHSA-2523-v9j2-g44c
Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6) Vulnerable parameters: &post_title, &downloadable_file_version[0].
GHSA-2523-mx65-hm92
NASM 2.16 (development) is vulnerable to 476: Null Pointer Dereference via output/outaout.c.
GHSA-2522-v35m-2r22
jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall.
GHSA-2522-mrjc-m688
Apache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config used
GHSA-2522-8f97-8gg8
Unspecified vulnerability in Adobe Breeze 5 Licensed Server and Breeze 5.1 Licensed Server allows attackers to read arbitrary files via unknown vectors related to "URL parsing."
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-252h-69rw-g2rp The str_buf_cat function in string.c in Ruby 1.9.3, 2.0.0, and 2.1 allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string. | 0% Низкий | около 3 лет назад | ||
GHSA-252h-2cmq-pmr6 easywebpack-cli Path Traversal vulnerability | CVSS3: 5.3 | 0% Низкий | больше 2 лет назад | |
GHSA-252g-gw8q-x2cc OpenShift Container Platform before version 4.1.3 writes OAuth tokens in plaintext to the audit logs for the Kubernetes API server and OpenShift API server. A user with sufficient privileges could recover OAuth tokens from these audit logs and use them to access other resources. | 0% Низкий | около 3 лет назад | ||
GHSA-252g-9rpq-c6xw Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis VSS Doctor (Windows) before build 53 | 0% Низкий | больше 3 лет назад | ||
GHSA-252f-47x2-rgxx A SQL injection vulnerability in a Trend Micro Email Encryption Gateway 5.5 policy script could allow an attacker to execute SQL commands to upload and execute arbitrary code that may harm the target system. | CVSS3: 9.8 | 4% Низкий | около 3 лет назад | |
GHSA-252c-46fv-6xqv ServerManagement master branch as of commit 49491cc6f94980e6be7791d17be947c27071eb56 is affected by a directory traversal vulnerability. This vulnerability can be used to extract credentials which can in turn be used to execute code. | 1% Низкий | около 3 лет назад | ||
GHSA-2529-rwp4-75f6 It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed article -> Website" or in the standard format of "View -> Feed article -> default format". This vulnerability affects Thunderbird < 52.5.2. | CVSS3: 8.8 | 1% Низкий | около 3 лет назад | |
GHSA-2529-cmp4-x7vg HP-UX aserver program allows local users to gain privileges via a symlink attack. | 0% Низкий | больше 3 лет назад | ||
GHSA-2528-h86j-954v In JetBrains TeamCity before 2021.1.3, a newly created project could take settings from an already deleted project. | 0% Низкий | около 3 лет назад | ||
GHSA-2527-g53r-vw26 In HarmfulAppWarningActivity of HarmfulAppWarningActivity.java, there is a possible way to trick victim to install harmful app due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-205595291 | CVSS3: 7.3 | 0% Низкий | больше 3 лет назад | |
GHSA-2526-24jx-77pp Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file. This is achieved through running a malicious script or program on the target machine. | CVSS3: 6.3 | 0% Низкий | около 3 лет назад | |
GHSA-2524-6f4r-2jq9 SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious commands with root privileges in SAP Host Agent via SAP Landscape Management. | 0% Низкий | около 3 лет назад | ||
GHSA-2524-2jp2-r468 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | CVSS3: 8.8 | 5% Низкий | около 1 года назад | |
GHSA-2523-xvgc-mmh8 Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability | CVSS3: 7.8 | 1% Низкий | 10 месяцев назад | |
GHSA-2523-vcxw-6v95 In libhidcommand_jni, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the USB service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111363077 | CVSS3: 6.8 | 0% Низкий | около 3 лет назад | |
GHSA-2523-v9j2-g44c Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6) Vulnerable parameters: &post_title, &downloadable_file_version[0]. | CVSS3: 4.8 | 0% Низкий | больше 3 лет назад | |
GHSA-2523-mx65-hm92 NASM 2.16 (development) is vulnerable to 476: Null Pointer Dereference via output/outaout.c. | CVSS3: 5.5 | 0% Низкий | больше 2 лет назад | |
GHSA-2522-v35m-2r22 jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall. | CVSS3: 9.8 | 2% Низкий | больше 3 лет назад | |
GHSA-2522-mrjc-m688 Apache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config used | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-2522-8f97-8gg8 Unspecified vulnerability in Adobe Breeze 5 Licensed Server and Breeze 5.1 Licensed Server allows attackers to read arbitrary files via unknown vectors related to "URL parsing." | 3% Низкий | больше 3 лет назад |
Уязвимостей на страницу