Количество 288 225
Количество 288 225
GHSA-22c8-wr9r-qr3j
Heap-based buffer overflow in the utf16_to_isolatin1 function in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allows remote attackers to execute arbitrary code via vectors that trigger a character-set conversion failure.
GHSA-22c8-79jr-rvwg
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command injection vulnerabilities via the ExternalPort, InternalPort, ProtocolNumber, and LocalIPAddress parameters in the SetVirtualServerSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.
GHSA-22c7-f2c3-8h35
A lack of CORS checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak limited cross-origin data via a crafted HTML page.
GHSA-22c7-cppf-fmqm
Internet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when opening it, which allows remote attackers to cause a denial of service (crash) by triggering a heap-based buffer overflow using invalid length codes during decompression, aka "Malformed PNG Image File Failure."
GHSA-22c7-32gx-23fj
Linear eMerge E3-Series devices have Cleartext Credentials in a Database.
GHSA-22c6-pmf5-543m
CRLF injection vulnerability in Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a MIME header.
GHSA-22c6-jwp4-wc87
Integer overflow in modules/MSADPCM.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file.
GHSA-22c6-3h88-26m3
Ignite Realtime Openfire allows Cross-site Scripting
GHSA-22c5-cpvr-cfvq
Withdrawn Advisory: undertow: information leakage via HTTP/2 request header reuse
GHSA-22c4-4rv3-jj9h
Stack-based buffer overflow in the demux_nsf_send_chunk function in src/demuxers/demux_nsf.c in xine-lib 1.1.12 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long NSF title.
GHSA-22c3-whjv-hrfm
Jenkins Folders Plugin cross-site request forgery vulnerability
GHSA-22c3-jmcx-576g
SQL injection vulnerability in login.asp for Cool Cafe (Cool Café) Chat 1.2.1 allows remote attackers to execute arbitrary SQL commands via the password.
GHSA-22c2-9gwg-mj59
Langroid has a Code Injection vulnerability in LanceDocChatAgent through vector_store
GHSA-229x-cgvj-5q56
Cross-site scripting (XSS) vulnerability in apps/user_webdavauth/settings.php in ownCloud 4.5.x before 4.5.2 allows remote attackers to inject arbitrary web script or HTML via arbitrary POST parameters.
GHSA-229x-53vm-m4f4
kernel drivers before version 4.17-rc1 are vulnerable to a weakness in the Linux kernel's implementation of random seed data. Programs, early in the boot sequence, could use the data allocated for the seed before it was sufficiently generated.
GHSA-229x-22xc-2f2w
Zendframework Local file disclosure via XXE injection in Zend_XmlRpc
GHSA-229w-w68g-gcf2
HP eSupportDiagnostics ActiveX control (hpediag.dll) 1.0.11.0 exports dangerous methods, which allows remote attackers to (1) read arbitrary files via the ReadTextFile method, or (2) read arbitrary registry values via the ReadValue method.
GHSA-229w-c447-wm6p
The faxrunq and faxrunqd in the mgetty package allows local users to create or modify arbitrary files via a symlink attack which creates a symlink in from /var/spool/fax/outgoing/.last_run to the target file.
GHSA-229w-7xcx-5jhf
The Magic Balloonman Marty Boone (aka com.app_martyboone.layout) application 1.400 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
GHSA-229v-p5vr-f583
Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100 version 9.0.0.3 and earlier.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-22c8-wr9r-qr3j Heap-based buffer overflow in the utf16_to_isolatin1 function in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allows remote attackers to execute arbitrary code via vectors that trigger a character-set conversion failure. | 6% Низкий | около 3 лет назад | ||
GHSA-22c8-79jr-rvwg D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command injection vulnerabilities via the ExternalPort, InternalPort, ProtocolNumber, and LocalIPAddress parameters in the SetVirtualServerSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request. | CVSS3: 8 | 1% Низкий | 10 месяцев назад | |
GHSA-22c7-f2c3-8h35 A lack of CORS checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak limited cross-origin data via a crafted HTML page. | CVSS3: 6.5 | 1% Низкий | около 3 лет назад | |
GHSA-22c7-cppf-fmqm Internet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when opening it, which allows remote attackers to cause a denial of service (crash) by triggering a heap-based buffer overflow using invalid length codes during decompression, aka "Malformed PNG Image File Failure." | 29% Средний | больше 3 лет назад | ||
GHSA-22c7-32gx-23fj Linear eMerge E3-Series devices have Cleartext Credentials in a Database. | 0% Низкий | около 3 лет назад | ||
GHSA-22c6-pmf5-543m CRLF injection vulnerability in Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a MIME header. | 0% Низкий | около 3 лет назад | ||
GHSA-22c6-jwp4-wc87 Integer overflow in modules/MSADPCM.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file. | CVSS3: 5.5 | 1% Низкий | около 3 лет назад | |
GHSA-22c6-3h88-26m3 Ignite Realtime Openfire allows Cross-site Scripting | CVSS3: 6.1 | 0% Низкий | около 3 лет назад | |
GHSA-22c5-cpvr-cfvq Withdrawn Advisory: undertow: information leakage via HTTP/2 request header reuse | CVSS3: 7.5 | 8 месяцев назад | ||
GHSA-22c4-4rv3-jj9h Stack-based buffer overflow in the demux_nsf_send_chunk function in src/demuxers/demux_nsf.c in xine-lib 1.1.12 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long NSF title. | 6% Низкий | больше 3 лет назад | ||
GHSA-22c3-whjv-hrfm Jenkins Folders Plugin cross-site request forgery vulnerability | CVSS3: 4.3 | 0% Низкий | почти 2 года назад | |
GHSA-22c3-jmcx-576g SQL injection vulnerability in login.asp for Cool Cafe (Cool Café) Chat 1.2.1 allows remote attackers to execute arbitrary SQL commands via the password. | 1% Низкий | больше 3 лет назад | ||
GHSA-22c2-9gwg-mj59 Langroid has a Code Injection vulnerability in LanceDocChatAgent through vector_store | 0% Низкий | 3 месяца назад | ||
GHSA-229x-cgvj-5q56 Cross-site scripting (XSS) vulnerability in apps/user_webdavauth/settings.php in ownCloud 4.5.x before 4.5.2 allows remote attackers to inject arbitrary web script or HTML via arbitrary POST parameters. | 0% Низкий | около 3 лет назад | ||
GHSA-229x-53vm-m4f4 kernel drivers before version 4.17-rc1 are vulnerable to a weakness in the Linux kernel's implementation of random seed data. Programs, early in the boot sequence, could use the data allocated for the seed before it was sufficiently generated. | CVSS3: 5.9 | 0% Низкий | около 3 лет назад | |
GHSA-229x-22xc-2f2w Zendframework Local file disclosure via XXE injection in Zend_XmlRpc | CVSS3: 8.6 | около 1 года назад | ||
GHSA-229w-w68g-gcf2 HP eSupportDiagnostics ActiveX control (hpediag.dll) 1.0.11.0 exports dangerous methods, which allows remote attackers to (1) read arbitrary files via the ReadTextFile method, or (2) read arbitrary registry values via the ReadValue method. | 9% Низкий | больше 3 лет назад | ||
GHSA-229w-c447-wm6p The faxrunq and faxrunqd in the mgetty package allows local users to create or modify arbitrary files via a symlink attack which creates a symlink in from /var/spool/fax/outgoing/.last_run to the target file. | 0% Низкий | больше 3 лет назад | ||
GHSA-229w-7xcx-5jhf The Magic Balloonman Marty Boone (aka com.app_martyboone.layout) application 1.400 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 0% Низкий | около 3 лет назад | ||
GHSA-229v-p5vr-f583 Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100 version 9.0.0.3 and earlier. | CVSS3: 7.5 | 94% Критический | около 3 лет назад |
Уязвимостей на страницу