Количество 314 458
Количество 314 458
GHSA-3j5m-7mq9-mfj7
The Authorize.Net module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
GHSA-3j5m-4qj3-wjqr
In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
GHSA-3j5j-x7ph-c2r8
Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.12 and SeaMonkey before 1.1.8 might allow remote attackers to execute arbitrary code via a crafted external-body MIME type in an e-mail message, related to an incorrect memory allocation during message preview.
GHSA-3j5h-p2g7-9wc9
An XSS vulnerability stored in Repox has been identified, which allows a local attacker to store a specially crafted JavaScript payload on the server, due to the lack of proper sanitisation of field elements, allowing the attacker to trigger the malicious payload when the application loads.
GHSA-3j5h-f552-7rhh
An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Apache HTTP Server: from 2.4.30 before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.
GHSA-3j5g-pgw8-92vr
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143.
GHSA-3j5c-vvwf-m29h
ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
GHSA-3j5c-gqf5-5qv4
There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Make an Offer Widget v1.0.
GHSA-3j59-wr8c-7648
A vulnerability classified as critical was found in purpleparrots 491-Project. This vulnerability affects unknown code of the file update.php of the component Highscore Handler. The manipulation leads to sql injection. The name of the patch is a812a5e4cf72f2a635a716086fe1ee2b8fa0b1ab. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217648.
GHSA-3j58-p785-f27x
Cross-site Scripting in microweber
GHSA-3j58-p4j5-9hc3
An information disclosure vulnerability in Bluetooth could allow a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as Moderate due to details specific to the vulnerability. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34946955.
GHSA-3j57-8hvg-f4cv
In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox
GHSA-3j56-rc6g-pp7q
Heap-based buffer overflow vulnerability in Assimp versions prior to 5.4.3 allows a local attacker to execute arbitrary code by importing a specially crafted file into the product.
GHSA-3j56-76c6-9xf6
Information disclosure in modem due to buffer over-read while processing response from DNS server
GHSA-3j55-q2r8-vc2j
csLiveSupport.cgi in CGIScript.net csLiveSupport allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function.
GHSA-3j55-px9j-gc5p
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/catalog_edit.php.
GHSA-3j55-7hc5-m8vh
An issue in ZIONCOM (Hong Kong) Technology Limited A7000R v.4.1cu.4154 allows an attacker to execute arbitrary code via the cig-bin/cstecgi.cgi to the settings/setPasswordCfg function.
GHSA-3j54-wjw6-wg58
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/templets_one_edit.php
GHSA-3j54-rx6j-frg9
Multiple SQL injection vulnerabilities in RI Blog 1.1 allow remote attackers to execute arbitrary SQL command via the (1) username or (2) password fields.
GHSA-3j54-g484-c9vm
The gst_date_time_new_from_iso8601_string function in gst/gstdatetime.c in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a malformed datetime string.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3j5m-7mq9-mfj7 The Authorize.Net module in osCommerce does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | 0% Низкий | больше 3 лет назад | ||
GHSA-3j5m-4qj3-wjqr In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | CVSS3: 8.4 | 0% Низкий | около 1 года назад | |
GHSA-3j5j-x7ph-c2r8 Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.12 and SeaMonkey before 1.1.8 might allow remote attackers to execute arbitrary code via a crafted external-body MIME type in an e-mail message, related to an incorrect memory allocation during message preview. | 31% Средний | почти 4 года назад | ||
GHSA-3j5h-p2g7-9wc9 An XSS vulnerability stored in Repox has been identified, which allows a local attacker to store a specially crafted JavaScript payload on the server, due to the lack of proper sanitisation of field elements, allowing the attacker to trigger the malicious payload when the application loads. | CVSS3: 5.5 | 0% Низкий | около 2 лет назад | |
GHSA-3j5h-f552-7rhh An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Apache HTTP Server: from 2.4.30 before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue. | CVSS3: 7.5 | 0% Низкий | 2 месяца назад | |
GHSA-3j5g-pgw8-92vr Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143. | CVSS3: 7.8 | 0% Низкий | около 3 лет назад | |
GHSA-3j5c-vvwf-m29h ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution. | 46% Средний | больше 3 лет назад | ||
GHSA-3j5c-gqf5-5qv4 There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Make an Offer Widget v1.0. | CVSS3: 6.1 | 1% Низкий | больше 2 лет назад | |
GHSA-3j59-wr8c-7648 A vulnerability classified as critical was found in purpleparrots 491-Project. This vulnerability affects unknown code of the file update.php of the component Highscore Handler. The manipulation leads to sql injection. The name of the patch is a812a5e4cf72f2a635a716086fe1ee2b8fa0b1ab. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217648. | CVSS3: 9.8 | 0% Низкий | около 3 лет назад | |
GHSA-3j58-p785-f27x Cross-site Scripting in microweber | CVSS3: 5.4 | 7% Низкий | около 4 лет назад | |
GHSA-3j58-p4j5-9hc3 An information disclosure vulnerability in Bluetooth could allow a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as Moderate due to details specific to the vulnerability. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34946955. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-3j57-8hvg-f4cv In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox | CVSS3: 8 | 0% Низкий | около 1 года назад | |
GHSA-3j56-rc6g-pp7q Heap-based buffer overflow vulnerability in Assimp versions prior to 5.4.3 allows a local attacker to execute arbitrary code by importing a specially crafted file into the product. | CVSS3: 8.4 | 0% Низкий | больше 1 года назад | |
GHSA-3j56-76c6-9xf6 Information disclosure in modem due to buffer over-read while processing response from DNS server | CVSS3: 7.5 | 0% Низкий | почти 3 года назад | |
GHSA-3j55-q2r8-vc2j csLiveSupport.cgi in CGIScript.net csLiveSupport allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function. | 0% Низкий | почти 4 года назад | ||
GHSA-3j55-px9j-gc5p DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/catalog_edit.php. | CVSS3: 6.1 | 0% Низкий | почти 2 года назад | |
GHSA-3j55-7hc5-m8vh An issue in ZIONCOM (Hong Kong) Technology Limited A7000R v.4.1cu.4154 allows an attacker to execute arbitrary code via the cig-bin/cstecgi.cgi to the settings/setPasswordCfg function. | CVSS3: 9.8 | 0% Низкий | больше 2 лет назад | |
GHSA-3j54-wjw6-wg58 DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/templets_one_edit.php | CVSS3: 6.1 | 0% Низкий | почти 2 года назад | |
GHSA-3j54-rx6j-frg9 Multiple SQL injection vulnerabilities in RI Blog 1.1 allow remote attackers to execute arbitrary SQL command via the (1) username or (2) password fields. | 1% Низкий | почти 4 года назад | ||
GHSA-3j54-g484-c9vm The gst_date_time_new_from_iso8601_string function in gst/gstdatetime.c in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a malformed datetime string. | CVSS3: 7.5 | 3% Низкий | больше 3 лет назад |
Уязвимостей на страницу