Количество 288 308
Количество 288 308
GHSA-24pr-9rc2-6xv5
The Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.1-12 didn’t mimic the permissions of the JVM being patched, allowing it to escalate privileges.
GHSA-24pq-phfq-785f
Linear eMerge E3-Series devices allow Command Injections.
GHSA-24pq-f9c8-764p
ganglia-web (aka Ganglia Web Frontend) through 3.7.5 allows XSS via the header.php cs parameter.
GHSA-24pq-9mvp-239w
Untrusted pointer dereference in some Intel(R) Graphics Drivers before versions 15.33.51.5146, 15.45.32.5145, 15.36.39.5144 and 15.40.46.5143 may allow an authenticated user to potentially denial of service via local access.
GHSA-24pm-f3f4-m533
Authorized users of the openbuildservice before 2.9.4 could delete packages by using a malicious request against projects having the OBS:InitializeDevelPackage attribute, a similar issue to CVE-2018-7689.
GHSA-24pm-ccpf-9wgw
SICK Package Analytics software up to and including version V04.0.0 are vulnerable due to incorrect default permissions settings. An unauthorized attacker could read sensitive data from the system by querying for known files using the REST API directly.
GHSA-24pj-f32f-p9j2
This CVE has been rejected.
GHSA-24pj-648p-4mq2
The searchterms-tagging-2 plugin through 1.535 for WordPress has XSS via the wp-admin/options-general.php count parameter.
GHSA-24pg-vqrw-x656
Azure Stack Hyperconverged Infrastructure (HCI) Elevation of Privilege Vulnerability
GHSA-24pg-vq4j-g2g2
D-Link Go-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Buffer Overflow via authenticationcgi_main.
GHSA-24pg-mpvf-gg4c
Cross Site Scripting (XSS) in the contact page of Group Office CRM 6.4.196 by uploading a crafted svg file.
GHSA-24pg-m258-76qq
Apache 1.3.20 on Windows servers allows remote attackers to bypass the default index page and list directory contents via a URL with a large number of / (slash) characters.
GHSA-24pf-jwjh-vhjw
Serialized-object interfaces in VMware vRealize Orchestrator 6.x, vCenter Orchestrator 5.x, vRealize Operations 6.x, vCenter Operations 5.x, and vCenter Application Discovery Manager (vADM) 7.x allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
GHSA-24pf-h82m-5vvv
An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A stack out-of-bounds write in onigenc_unicode_get_case_fold_codes_by_str() occurs during regular expression compilation. Code point 0xFFFFFFFF is not properly handled in unicode_unfold_key(). A malformed regular expression could result in 4 bytes being written off the end of a stack buffer of expand_case_fold_string() during the call to onigenc_unicode_get_case_fold_codes_by_str(), a typical stack buffer overflow.
GHSA-24pf-7g6m-7wcx
Insufficient policy enforcement in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass content security policy via a crafted HTML page.
GHSA-24pc-pxxr-h3mc
SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla
GHSA-24pc-7pxr-jg3q
SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via the Content-Disposition header.
GHSA-24p8-x4mp-cq86
urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist file: URIs, as demonstrated by triggering a urllib.urlopen('local_file:///etc/passwd') call.
GHSA-24p8-72r9-6qxg
A stack write overflow in WhatsApp for Android prior to v2.20.35, WhatsApp Business for Android prior to v2.20.20, WhatsApp for iPhone prior to v2.20.30, and WhatsApp Business for iPhone prior to v2.20.30 could have allowed arbitrary code execution when playing a specially crafted push to talk message.
GHSA-24p7-v3fm-63vm
Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3 while editing an existing monitor field named "signal check color" (monitor.php). There exists no input validation or output filtration, leaving it vulnerable to HTML Injection and an XSS attack.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-24pr-9rc2-6xv5 The Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.1-12 didn’t mimic the permissions of the JVM being patched, allowing it to escalate privileges. | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад | |
GHSA-24pq-phfq-785f Linear eMerge E3-Series devices allow Command Injections. | CVSS3: 10 | 94% Критический | около 3 лет назад | |
GHSA-24pq-f9c8-764p ganglia-web (aka Ganglia Web Frontend) through 3.7.5 allows XSS via the header.php cs parameter. | 0% Низкий | около 3 лет назад | ||
GHSA-24pq-9mvp-239w Untrusted pointer dereference in some Intel(R) Graphics Drivers before versions 15.33.51.5146, 15.45.32.5145, 15.36.39.5144 and 15.40.46.5143 may allow an authenticated user to potentially denial of service via local access. | 0% Низкий | около 3 лет назад | ||
GHSA-24pm-f3f4-m533 Authorized users of the openbuildservice before 2.9.4 could delete packages by using a malicious request against projects having the OBS:InitializeDevelPackage attribute, a similar issue to CVE-2018-7689. | CVSS3: 6.5 | 0% Низкий | около 3 лет назад | |
GHSA-24pm-ccpf-9wgw SICK Package Analytics software up to and including version V04.0.0 are vulnerable due to incorrect default permissions settings. An unauthorized attacker could read sensitive data from the system by querying for known files using the REST API directly. | 0% Низкий | около 3 лет назад | ||
GHSA-24pj-f32f-p9j2 This CVE has been rejected. | 10 месяцев назад | |||
GHSA-24pj-648p-4mq2 The searchterms-tagging-2 plugin through 1.535 for WordPress has XSS via the wp-admin/options-general.php count parameter. | CVSS3: 6.1 | 0% Низкий | около 3 лет назад | |
GHSA-24pg-vqrw-x656 Azure Stack Hyperconverged Infrastructure (HCI) Elevation of Privilege Vulnerability | CVSS3: 8.8 | 0% Низкий | 10 месяцев назад | |
GHSA-24pg-vq4j-g2g2 D-Link Go-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Buffer Overflow via authenticationcgi_main. | CVSS3: 9.8 | 0% Низкий | почти 3 года назад | |
GHSA-24pg-mpvf-gg4c Cross Site Scripting (XSS) in the contact page of Group Office CRM 6.4.196 by uploading a crafted svg file. | 0% Низкий | около 3 лет назад | ||
GHSA-24pg-m258-76qq Apache 1.3.20 on Windows servers allows remote attackers to bypass the default index page and list directory contents via a URL with a large number of / (slash) characters. | 2% Низкий | больше 3 лет назад | ||
GHSA-24pf-jwjh-vhjw Serialized-object interfaces in VMware vRealize Orchestrator 6.x, vCenter Orchestrator 5.x, vRealize Operations 6.x, vCenter Operations 5.x, and vCenter Application Discovery Manager (vADM) 7.x allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library. | CVSS3: 7.3 | 2% Низкий | около 3 лет назад | |
GHSA-24pf-h82m-5vvv An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A stack out-of-bounds write in onigenc_unicode_get_case_fold_codes_by_str() occurs during regular expression compilation. Code point 0xFFFFFFFF is not properly handled in unicode_unfold_key(). A malformed regular expression could result in 4 bytes being written off the end of a stack buffer of expand_case_fold_string() during the call to onigenc_unicode_get_case_fold_codes_by_str(), a typical stack buffer overflow. | CVSS3: 9.8 | 0% Низкий | около 3 лет назад | |
GHSA-24pf-7g6m-7wcx Insufficient policy enforcement in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass content security policy via a crafted HTML page. | 0% Низкий | около 3 лет назад | ||
GHSA-24pc-pxxr-h3mc SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla | CVSS3: 7.2 | 2% Низкий | около 3 лет назад | |
GHSA-24pc-7pxr-jg3q SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via the Content-Disposition header. | 80% Высокий | около 3 лет назад | ||
GHSA-24p8-x4mp-cq86 urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist file: URIs, as demonstrated by triggering a urllib.urlopen('local_file:///etc/passwd') call. | CVSS3: 9.1 | 1% Низкий | около 3 лет назад | |
GHSA-24p8-72r9-6qxg A stack write overflow in WhatsApp for Android prior to v2.20.35, WhatsApp Business for Android prior to v2.20.20, WhatsApp for iPhone prior to v2.20.30, and WhatsApp Business for iPhone prior to v2.20.30 could have allowed arbitrary code execution when playing a specially crafted push to talk message. | 1% Низкий | около 3 лет назад | ||
GHSA-24p7-v3fm-63vm Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3 while editing an existing monitor field named "signal check color" (monitor.php). There exists no input validation or output filtration, leaving it vulnerable to HTML Injection and an XSS attack. | CVSS3: 6.1 | 0% Низкий | около 3 лет назад |
Уязвимостей на страницу