Количество 314 458
Количество 314 458
GHSA-3j54-7r73-qgxr
Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0952 and CVE-2016-0953.
GHSA-3j54-7gqc-xjwp
The myMail app through 14.30 for iOS sends cleartext credentials in a situation where STARTTLS is expected by a server.
GHSA-3j53-j44c-wp43
In the Linux kernel, the following vulnerability has been resolved: kernel/irq/irqdomain.c: fix memory leak with using debugfs_lookup() When calling debugfs_lookup() the result must have dput() called on it, otherwise the memory will leak over time. To make things simpler, just call debugfs_lookup_and_remove() instead which handles all of the logic at once.
GHSA-3j52-m85f-mg6g
HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in department.php.
GHSA-3j52-86hv-pq9m
WebKit in Apple Safari before 4.0 does not properly initialize memory for Attr DOM objects, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document.
GHSA-3j4x-wh8q-39g3
A vulnerability was found in soerennb eXtplorer up to 2.1.12 and classified as critical. Affected by this issue is some unknown functionality of the component Directory Content Handler. The manipulation leads to path traversal. Upgrading to version 2.1.13 is able to address this issue. The name of the patch is b8fcb888f4ff5e171c16797a4b075c6c6f50bf46. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-217436.
GHSA-3j4x-9q9q-3277
Cross-site Scripting in JFinal
GHSA-3j4w-jcv6-fv59
ForensiT AppX Management Service 2.2.0.4 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSystem account permissions during service startup.
GHSA-3j4w-c76p-2jvh
Integer overflow in Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to cause a denial of service (daemon crash) via a crafted packet with a certain opcode that triggers an incorrect memory allocation and a buffer overflow.
GHSA-3j4v-h6mr-q2j9
The WavFileBase class in WavFile.cpp in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (heap corruption from size inconsistency) or possibly have unspecified other impact, as demonstrated by SoundStretch.
GHSA-3j4r-w3gq-96pw
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0699.
GHSA-3j4r-qx26-f2pp
SQL injection vulnerability in DBD::PgPP 0.05 and earlier
GHSA-3j4r-55jx-gvmw
CC Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry.
GHSA-3j4r-3gwf-p2pm
The About option on the Help menu in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Management Database (CCMDB) 6.2, 7.1, and 7.2 shows the username, which might allow remote authenticated users to have an unspecified impact via a targeted attack against the corresponding user account.
GHSA-3j4q-w64j-h3mx
This CVE is not valid.
GHSA-3j4q-r565-vcj9
In the Linux kernel, the following vulnerability has been resolved: block: fix rq-qos breakage from skipping rq_qos_done_bio() a647a524a467 ("block: don't call rq_qos_ops->done_bio if the bio isn't tracked") made bio_endio() skip rq_qos_done_bio() if BIO_TRACKED is not set. While this fixed a potential oops, it also broke blk-iocost by skipping the done_bio callback for merged bios. Before, whether a bio goes through rq_qos_throttle() or rq_qos_merge(), rq_qos_done_bio() would be called on the bio on completion with BIO_TRACKED distinguishing the former from the latter. rq_qos_done_bio() is not called for bios which wenth through rq_qos_merge(). This royally confuses blk-iocost as the merged bios never finish and are considered perpetually in-flight. One reliably reproducible failure mode is an intermediate cgroup geting stuck active preventing its children from being activated due to the leaf-only rule, leading to loss of control. The following is from resctl-bench protection s...
GHSA-3j4q-cm56-9492
Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the delno parameter in the fromPptpUserSetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
GHSA-3j4p-qc5m-wqgh
An issue was discovered in SchedMD Slurm 22.05.x and 23.02.x. There is Incorrect Access Control: an attacker can modified their extended group list that is used with the sbcast subsystem, and open files with an unauthorized set of extended groups. The fixed versions are 22.05.11 and 23.02.7.
GHSA-3j4p-7g9x-w28j
A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be downloadable when appending /download to the URL.
GHSA-3j4m-97f8-qmph
Cross-site scripting (XSS) vulnerability in the table feature in PmWiki 2.2.15 allows remote authenticated users to inject arbitrary web script or HTML via the width attribute.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3j54-7r73-qgxr Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0952 and CVE-2016-0953. | CVSS3: 9.8 | 18% Средний | больше 3 лет назад | |
GHSA-3j54-7gqc-xjwp The myMail app through 14.30 for iOS sends cleartext credentials in a situation where STARTTLS is expected by a server. | CVSS3: 7.5 | 0% Низкий | почти 3 года назад | |
GHSA-3j53-j44c-wp43 In the Linux kernel, the following vulnerability has been resolved: kernel/irq/irqdomain.c: fix memory leak with using debugfs_lookup() When calling debugfs_lookup() the result must have dput() called on it, otherwise the memory will leak over time. To make things simpler, just call debugfs_lookup_and_remove() instead which handles all of the logic at once. | CVSS3: 5.5 | 0% Низкий | 11 месяцев назад | |
GHSA-3j52-m85f-mg6g HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in department.php. | CVSS3: 9.8 | 0% Низкий | почти 4 года назад | |
GHSA-3j52-86hv-pq9m WebKit in Apple Safari before 4.0 does not properly initialize memory for Attr DOM objects, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document. | 6% Низкий | почти 4 года назад | ||
GHSA-3j4x-wh8q-39g3 A vulnerability was found in soerennb eXtplorer up to 2.1.12 and classified as critical. Affected by this issue is some unknown functionality of the component Directory Content Handler. The manipulation leads to path traversal. Upgrading to version 2.1.13 is able to address this issue. The name of the patch is b8fcb888f4ff5e171c16797a4b075c6c6f50bf46. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-217436. | CVSS3: 9.8 | 1% Низкий | около 3 лет назад | |
GHSA-3j4x-9q9q-3277 Cross-site Scripting in JFinal | CVSS3: 5.4 | 0% Низкий | около 2 лет назад | |
GHSA-3j4w-jcv6-fv59 ForensiT AppX Management Service 2.2.0.4 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSystem account permissions during service startup. | CVSS3: 7.8 | 0% Низкий | 12 дней назад | |
GHSA-3j4w-c76p-2jvh Integer overflow in Pro-face WinGP PC Runtime 3.1.00 and earlier, and ProServr.exe in Pro-face Pro-Server EX 1.30.000 and earlier, allows remote attackers to cause a denial of service (daemon crash) via a crafted packet with a certain opcode that triggers an incorrect memory allocation and a buffer overflow. | 8% Низкий | больше 3 лет назад | ||
GHSA-3j4v-h6mr-q2j9 The WavFileBase class in WavFile.cpp in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (heap corruption from size inconsistency) or possibly have unspecified other impact, as demonstrated by SoundStretch. | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
GHSA-3j4r-w3gq-96pw An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0699. | 1% Низкий | больше 3 лет назад | ||
GHSA-3j4r-qx26-f2pp SQL injection vulnerability in DBD::PgPP 0.05 and earlier | CVSS3: 9.8 | 0% Низкий | больше 3 лет назад | |
GHSA-3j4r-55jx-gvmw CC Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry. | 4% Низкий | почти 4 года назад | ||
GHSA-3j4r-3gwf-p2pm The About option on the Help menu in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5; IBM Tivoli Asset Management for IT 6.2, 7.1, and 7.2; IBM Tivoli Service Request Manager 7.1 and 7.2; IBM Maximo Service Desk 6.2; and IBM Tivoli Change and Configuration Management Database (CCMDB) 6.2, 7.1, and 7.2 shows the username, which might allow remote authenticated users to have an unspecified impact via a targeted attack against the corresponding user account. | 0% Низкий | больше 3 лет назад | ||
GHSA-3j4q-w64j-h3mx This CVE is not valid. | около 3 лет назад | |||
GHSA-3j4q-r565-vcj9 In the Linux kernel, the following vulnerability has been resolved: block: fix rq-qos breakage from skipping rq_qos_done_bio() a647a524a467 ("block: don't call rq_qos_ops->done_bio if the bio isn't tracked") made bio_endio() skip rq_qos_done_bio() if BIO_TRACKED is not set. While this fixed a potential oops, it also broke blk-iocost by skipping the done_bio callback for merged bios. Before, whether a bio goes through rq_qos_throttle() or rq_qos_merge(), rq_qos_done_bio() would be called on the bio on completion with BIO_TRACKED distinguishing the former from the latter. rq_qos_done_bio() is not called for bios which wenth through rq_qos_merge(). This royally confuses blk-iocost as the merged bios never finish and are considered perpetually in-flight. One reliably reproducible failure mode is an intermediate cgroup geting stuck active preventing its children from being activated due to the leaf-only rule, leading to loss of control. The following is from resctl-bench protection s... | CVSS3: 5.5 | 0% Низкий | 4 месяца назад | |
GHSA-3j4q-cm56-9492 Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the delno parameter in the fromPptpUserSetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | CVSS3: 7.5 | 4% Низкий | больше 1 года назад | |
GHSA-3j4p-qc5m-wqgh An issue was discovered in SchedMD Slurm 22.05.x and 23.02.x. There is Incorrect Access Control: an attacker can modified their extended group list that is used with the sbcast subsystem, and open files with an unauthorized set of extended groups. The fixed versions are 22.05.11 and 23.02.7. | CVSS3: 8.2 | 0% Низкий | около 2 лет назад | |
GHSA-3j4p-7g9x-w28j A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be downloadable when appending /download to the URL. | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
GHSA-3j4m-97f8-qmph Cross-site scripting (XSS) vulnerability in the table feature in PmWiki 2.2.15 allows remote authenticated users to inject arbitrary web script or HTML via the width attribute. | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу