Количество 314 458
Количество 314 458
GHSA-3q76-8594-629m
** DISPUTED ** Cross-site scripting (XSS) vulnerability in member.php in vBulletin 3.5.x allows remote attackers to inject arbitrary web script or HTML via the u parameter. NOTE: the vendor has disputed this report, stating that they have been unable to replicate the issue and that "the userid parameter is run through our filtering system as an unsigned integer."
GHSA-3q75-rp5f-jff5
In Plesk Obsidian 18.0.69, unauthenticated requests to /login_up.php can reveal an AWS accessKeyId, secretAccessKey, region, and endpoint.
GHSA-3q75-gmh9-x7r6
IBM StoreIQ 7.6.0.0. through 7.6.0.18 could allow an authenticated user to obtain sensitive information that a privileged user should only be allowed to view. IBM X-Force ID: 158696.
GHSA-3q75-2gg2-99h4
The administration functionality in Wuzly 2.0 allows remote attackers to bypass authentication by setting the dXNlcm5hbWU cookie.
GHSA-3q74-vrwv-v9x3
Missing Authorization vulnerability in theDotstore Advance Menu Manager.This issue affects Advance Menu Manager: from n/a through 3.1.1.
GHSA-3q74-6f83-38mg
IBM Security Access Manager for Web allows web pages to be stored locally which can be read by another user on the system.
GHSA-3q72-ch8q-5j47
NTFS TmaxSoft JEUS 5 before Fix 26 allows remote attackers to read the source code for scripts by appending ::$DATA to the URL, which accesses the alternate data stream.
GHSA-3q6x-mjrg-68xw
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in TalentSoft Software UNIS allows Reflected XSS.This issue affects UNIS: before 42957.
GHSA-3q6x-j6f7-rvxv
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Website366.com WPSHARE247 Elementor Addons allows Stored XSS. This issue affects WPSHARE247 Elementor Addons: from n/a through 2.1.
GHSA-3q6x-gxwh-88p9
In the Linux kernel, the following vulnerability has been resolved: lib/test_hmm.c: handle src_pfns and dst_pfns allocation failure The kcalloc() in dmirror_device_evict_chunk() will return null if the physical memory has run out. As a result, if src_pfns or dst_pfns is dereferenced, the null pointer dereference bug will happen. Moreover, the device is going away. If the kcalloc() fails, the pages mapping a chunk could not be evicted. So add a __GFP_NOFAIL flag in kcalloc(). Finally, as there is no need to have physically contiguous memory, Switch kcalloc() to kvcalloc() in order to avoid failing allocations.
GHSA-3q6w-vp42-26vx
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay Sharma wordpress login form to anywhere allows Stored XSS. This issue affects wordpress login form to anywhere: from n/a through 0.2.
GHSA-3q6v-mwhw-45h2
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3. An app with root privileges may be able to execute arbitrary code with kernel privileges.
GHSA-3q6v-jv77-fpxc
KDE ktvision 0.1.1-271 and earlier allows local attackers to gain root privileges via a symlink attack on a user configuration file.
GHSA-3q6v-gv39-h4r6
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 could allow an authenticated attacker with specialized access to tables that they should not be permitted to view. IBM Reference #: 1999515.
GHSA-3q6r-ghxh-24g9
A denial of service vulnerability exists in the cgiserver.cgi session creation functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to prevent users from logging in. An attacker can send an HTTP request to trigger this vulnerability.
GHSA-3q6q-xxfm-fxqr
Buffer overflow in AIX xdat gives root access to local users.
GHSA-3q6q-qc68-x6pf
media/libmedia/IOMX.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not initialize a parameter data structure, which allows attackers to obtain sensitive information from process memory, and consequently bypass an unspecified protection mechanism, via unspecified vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26914474.
GHSA-3q6q-m779-9qvh
The EasyCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.
GHSA-3q6q-gxwr-7gqv
Pexip Infinity 35.0 through 37.2 before 38.0 has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a denial of service.
GHSA-3q6p-xqh5-xhx5
Unspecified vulnerability in the Data Store component in Oracle Berkeley DB 11.2.5.1.29, 11.2.5.2.42, 11.2.5.3.28, and 12.1.6.0.35 allows local users to affect integrity and availability via unknown vectors, a different vulnerability than CVE-2015-4774 and CVE-2015-4779.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3q76-8594-629m ** DISPUTED ** Cross-site scripting (XSS) vulnerability in member.php in vBulletin 3.5.x allows remote attackers to inject arbitrary web script or HTML via the u parameter. NOTE: the vendor has disputed this report, stating that they have been unable to replicate the issue and that "the userid parameter is run through our filtering system as an unsigned integer." | 7% Низкий | почти 4 года назад | ||
GHSA-3q75-rp5f-jff5 In Plesk Obsidian 18.0.69, unauthenticated requests to /login_up.php can reveal an AWS accessKeyId, secretAccessKey, region, and endpoint. | CVSS3: 5.8 | 0% Низкий | 7 месяцев назад | |
GHSA-3q75-gmh9-x7r6 IBM StoreIQ 7.6.0.0. through 7.6.0.18 could allow an authenticated user to obtain sensitive information that a privileged user should only be allowed to view. IBM X-Force ID: 158696. | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
GHSA-3q75-2gg2-99h4 The administration functionality in Wuzly 2.0 allows remote attackers to bypass authentication by setting the dXNlcm5hbWU cookie. | 0% Низкий | больше 3 лет назад | ||
GHSA-3q74-vrwv-v9x3 Missing Authorization vulnerability in theDotstore Advance Menu Manager.This issue affects Advance Menu Manager: from n/a through 3.1.1. | CVSS3: 7.1 | 0% Низкий | около 1 года назад | |
GHSA-3q74-6f83-38mg IBM Security Access Manager for Web allows web pages to be stored locally which can be read by another user on the system. | CVSS3: 4 | 0% Низкий | больше 3 лет назад | |
GHSA-3q72-ch8q-5j47 NTFS TmaxSoft JEUS 5 before Fix 26 allows remote attackers to read the source code for scripts by appending ::$DATA to the URL, which accesses the alternate data stream. | 10% Низкий | больше 3 лет назад | ||
GHSA-3q6x-mjrg-68xw Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in TalentSoft Software UNIS allows Reflected XSS.This issue affects UNIS: before 42957. | CVSS3: 5.4 | 0% Низкий | 2 месяца назад | |
GHSA-3q6x-j6f7-rvxv Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Website366.com WPSHARE247 Elementor Addons allows Stored XSS. This issue affects WPSHARE247 Elementor Addons: from n/a through 2.1. | CVSS3: 6.5 | 0% Низкий | 10 месяцев назад | |
GHSA-3q6x-gxwh-88p9 In the Linux kernel, the following vulnerability has been resolved: lib/test_hmm.c: handle src_pfns and dst_pfns allocation failure The kcalloc() in dmirror_device_evict_chunk() will return null if the physical memory has run out. As a result, if src_pfns or dst_pfns is dereferenced, the null pointer dereference bug will happen. Moreover, the device is going away. If the kcalloc() fails, the pages mapping a chunk could not be evicted. So add a __GFP_NOFAIL flag in kcalloc(). Finally, as there is no need to have physically contiguous memory, Switch kcalloc() to kvcalloc() in order to avoid failing allocations. | CVSS3: 5.5 | 0% Низкий | больше 1 года назад | |
GHSA-3q6w-vp42-26vx Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay Sharma wordpress login form to anywhere allows Stored XSS. This issue affects wordpress login form to anywhere: from n/a through 0.2. | CVSS3: 5.9 | 0% Низкий | 11 месяцев назад | |
GHSA-3q6v-mwhw-45h2 A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3. An app with root privileges may be able to execute arbitrary code with kernel privileges. | CVSS3: 6.7 | 0% Низкий | около 1 года назад | |
GHSA-3q6v-jv77-fpxc KDE ktvision 0.1.1-271 and earlier allows local attackers to gain root privileges via a symlink attack on a user configuration file. | 0% Низкий | почти 4 года назад | ||
GHSA-3q6v-gv39-h4r6 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 could allow an authenticated attacker with specialized access to tables that they should not be permitted to view. IBM Reference #: 1999515. | CVSS3: 3.1 | 0% Низкий | больше 3 лет назад | |
GHSA-3q6r-ghxh-24g9 A denial of service vulnerability exists in the cgiserver.cgi session creation functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to prevent users from logging in. An attacker can send an HTTP request to trigger this vulnerability. | CVSS3: 7.5 | 1% Низкий | около 4 лет назад | |
GHSA-3q6q-xxfm-fxqr Buffer overflow in AIX xdat gives root access to local users. | 0% Низкий | почти 4 года назад | ||
GHSA-3q6q-qc68-x6pf media/libmedia/IOMX.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not initialize a parameter data structure, which allows attackers to obtain sensitive information from process memory, and consequently bypass an unspecified protection mechanism, via unspecified vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26914474. | CVSS3: 9.8 | 13% Средний | больше 3 лет назад | |
GHSA-3q6q-m779-9qvh The EasyCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields. | 1% Низкий | почти 4 года назад | ||
GHSA-3q6q-gxwr-7gqv Pexip Infinity 35.0 through 37.2 before 38.0 has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a denial of service. | CVSS3: 7.5 | 0% Низкий | около 2 месяцев назад | |
GHSA-3q6p-xqh5-xhx5 Unspecified vulnerability in the Data Store component in Oracle Berkeley DB 11.2.5.1.29, 11.2.5.2.42, 11.2.5.3.28, and 12.1.6.0.35 allows local users to affect integrity and availability via unknown vectors, a different vulnerability than CVE-2015-4774 and CVE-2015-4779. | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу