Количество 312 573
Количество 312 573
GHSA-3j54-wjw6-wg58
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/templets_one_edit.php
GHSA-3j54-rx6j-frg9
Multiple SQL injection vulnerabilities in RI Blog 1.1 allow remote attackers to execute arbitrary SQL command via the (1) username or (2) password fields.
GHSA-3j54-g484-c9vm
The gst_date_time_new_from_iso8601_string function in gst/gstdatetime.c in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a malformed datetime string.
GHSA-3j54-7r73-qgxr
Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0952 and CVE-2016-0953.
GHSA-3j54-7gqc-xjwp
The myMail app through 14.30 for iOS sends cleartext credentials in a situation where STARTTLS is expected by a server.
GHSA-3j53-j44c-wp43
In the Linux kernel, the following vulnerability has been resolved: kernel/irq/irqdomain.c: fix memory leak with using debugfs_lookup() When calling debugfs_lookup() the result must have dput() called on it, otherwise the memory will leak over time. To make things simpler, just call debugfs_lookup_and_remove() instead which handles all of the logic at once.
GHSA-3j52-m85f-mg6g
HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in department.php.
GHSA-3j52-86hv-pq9m
WebKit in Apple Safari before 4.0 does not properly initialize memory for Attr DOM objects, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document.
GHSA-3j4x-wh8q-39g3
A vulnerability was found in soerennb eXtplorer up to 2.1.12 and classified as critical. Affected by this issue is some unknown functionality of the component Directory Content Handler. The manipulation leads to path traversal. Upgrading to version 2.1.13 is able to address this issue. The name of the patch is b8fcb888f4ff5e171c16797a4b075c6c6f50bf46. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-217436.
GHSA-3j4x-9q9q-3277
Cross-site Scripting in JFinal
GHSA-3j4w-c76p-2jvh
Integer overflow in Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to cause a denial of service (daemon crash) via a crafted packet with a certain opcode that triggers an incorrect memory allocation and a buffer overflow.
GHSA-3j4v-h6mr-q2j9
The WavFileBase class in WavFile.cpp in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (heap corruption from size inconsistency) or possibly have unspecified other impact, as demonstrated by SoundStretch.
GHSA-3j4r-w3gq-96pw
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0699.
GHSA-3j4r-qx26-f2pp
SQL injection vulnerability in DBD::PgPP 0.05 and earlier
GHSA-3j4r-55jx-gvmw
CC Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry.
GHSA-3j4r-3gwf-p2pm
The About option on the Help menu in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Management Database (CCMDB) 6.2, 7.1, and 7.2 shows the username, which might allow remote authenticated users to have an unspecified impact via a targeted attack against the corresponding user account.
GHSA-3j4q-w64j-h3mx
This CVE is not valid.
GHSA-3j4q-r565-vcj9
In the Linux kernel, the following vulnerability has been resolved: block: fix rq-qos breakage from skipping rq_qos_done_bio() a647a524a467 ("block: don't call rq_qos_ops->done_bio if the bio isn't tracked") made bio_endio() skip rq_qos_done_bio() if BIO_TRACKED is not set. While this fixed a potential oops, it also broke blk-iocost by skipping the done_bio callback for merged bios. Before, whether a bio goes through rq_qos_throttle() or rq_qos_merge(), rq_qos_done_bio() would be called on the bio on completion with BIO_TRACKED distinguishing the former from the latter. rq_qos_done_bio() is not called for bios which wenth through rq_qos_merge(). This royally confuses blk-iocost as the merged bios never finish and are considered perpetually in-flight. One reliably reproducible failure mode is an intermediate cgroup geting stuck active preventing its children from being activated due to the leaf-only rule, leading to loss of control. The following is from resctl-bench protection s...
GHSA-3j4q-cm56-9492
Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the delno parameter in the fromPptpUserSetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
GHSA-3j4p-qc5m-wqgh
An issue was discovered in SchedMD Slurm 22.05.x and 23.02.x. There is Incorrect Access Control: an attacker can modified their extended group list that is used with the sbcast subsystem, and open files with an unauthorized set of extended groups. The fixed versions are 22.05.11 and 23.02.7.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3j54-wjw6-wg58 DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/templets_one_edit.php | CVSS3: 6.1 | 0% Низкий | почти 2 года назад | |
GHSA-3j54-rx6j-frg9 Multiple SQL injection vulnerabilities in RI Blog 1.1 allow remote attackers to execute arbitrary SQL command via the (1) username or (2) password fields. | 1% Низкий | почти 4 года назад | ||
GHSA-3j54-g484-c9vm The gst_date_time_new_from_iso8601_string function in gst/gstdatetime.c in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a malformed datetime string. | CVSS3: 7.5 | 3% Низкий | больше 3 лет назад | |
GHSA-3j54-7r73-qgxr Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0952 and CVE-2016-0953. | CVSS3: 9.8 | 18% Средний | больше 3 лет назад | |
GHSA-3j54-7gqc-xjwp The myMail app through 14.30 for iOS sends cleartext credentials in a situation where STARTTLS is expected by a server. | CVSS3: 7.5 | 0% Низкий | почти 3 года назад | |
GHSA-3j53-j44c-wp43 In the Linux kernel, the following vulnerability has been resolved: kernel/irq/irqdomain.c: fix memory leak with using debugfs_lookup() When calling debugfs_lookup() the result must have dput() called on it, otherwise the memory will leak over time. To make things simpler, just call debugfs_lookup_and_remove() instead which handles all of the logic at once. | CVSS3: 5.5 | 0% Низкий | 11 месяцев назад | |
GHSA-3j52-m85f-mg6g HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in department.php. | CVSS3: 9.8 | 0% Низкий | почти 4 года назад | |
GHSA-3j52-86hv-pq9m WebKit in Apple Safari before 4.0 does not properly initialize memory for Attr DOM objects, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document. | 6% Низкий | почти 4 года назад | ||
GHSA-3j4x-wh8q-39g3 A vulnerability was found in soerennb eXtplorer up to 2.1.12 and classified as critical. Affected by this issue is some unknown functionality of the component Directory Content Handler. The manipulation leads to path traversal. Upgrading to version 2.1.13 is able to address this issue. The name of the patch is b8fcb888f4ff5e171c16797a4b075c6c6f50bf46. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-217436. | CVSS3: 9.8 | 1% Низкий | около 3 лет назад | |
GHSA-3j4x-9q9q-3277 Cross-site Scripting in JFinal | CVSS3: 5.4 | 0% Низкий | около 2 лет назад | |
GHSA-3j4w-c76p-2jvh Integer overflow in Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to cause a denial of service (daemon crash) via a crafted packet with a certain opcode that triggers an incorrect memory allocation and a buffer overflow. | 8% Низкий | больше 3 лет назад | ||
GHSA-3j4v-h6mr-q2j9 The WavFileBase class in WavFile.cpp in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (heap corruption from size inconsistency) or possibly have unspecified other impact, as demonstrated by SoundStretch. | CVSS3: 8.8 | 2% Низкий | больше 3 лет назад | |
GHSA-3j4r-w3gq-96pw An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0699. | 1% Низкий | больше 3 лет назад | ||
GHSA-3j4r-qx26-f2pp SQL injection vulnerability in DBD::PgPP 0.05 and earlier | CVSS3: 9.8 | 0% Низкий | больше 3 лет назад | |
GHSA-3j4r-55jx-gvmw CC Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry. | 4% Низкий | почти 4 года назад | ||
GHSA-3j4r-3gwf-p2pm The About option on the Help menu in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Management Database (CCMDB) 6.2, 7.1, and 7.2 shows the username, which might allow remote authenticated users to have an unspecified impact via a targeted attack against the corresponding user account. | 0% Низкий | больше 3 лет назад | ||
GHSA-3j4q-w64j-h3mx This CVE is not valid. | около 3 лет назад | |||
GHSA-3j4q-r565-vcj9 In the Linux kernel, the following vulnerability has been resolved: block: fix rq-qos breakage from skipping rq_qos_done_bio() a647a524a467 ("block: don't call rq_qos_ops->done_bio if the bio isn't tracked") made bio_endio() skip rq_qos_done_bio() if BIO_TRACKED is not set. While this fixed a potential oops, it also broke blk-iocost by skipping the done_bio callback for merged bios. Before, whether a bio goes through rq_qos_throttle() or rq_qos_merge(), rq_qos_done_bio() would be called on the bio on completion with BIO_TRACKED distinguishing the former from the latter. rq_qos_done_bio() is not called for bios which wenth through rq_qos_merge(). This royally confuses blk-iocost as the merged bios never finish and are considered perpetually in-flight. One reliably reproducible failure mode is an intermediate cgroup geting stuck active preventing its children from being activated due to the leaf-only rule, leading to loss of control. The following is from resctl-bench protection s... | CVSS3: 5.5 | 0% Низкий | 4 месяца назад | |
GHSA-3j4q-cm56-9492 Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the delno parameter in the fromPptpUserSetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | CVSS3: 7.5 | 4% Низкий | больше 1 года назад | |
GHSA-3j4p-qc5m-wqgh An issue was discovered in SchedMD Slurm 22.05.x and 23.02.x. There is Incorrect Access Control: an attacker can modified their extended group list that is used with the sbcast subsystem, and open files with an unauthorized set of extended groups. The fixed versions are 22.05.11 and 23.02.7. | CVSS3: 8.2 | 0% Низкий | около 2 лет назад |
Уязвимостей на страницу